Legal
Privacy Policy
Last updated: September 2026.
Who we are
This service (“Keepsake”, “we”) is operated by khaldoun.dev, Vienna, Austria, contactable at [email protected]. We are the data controller for the personal data described here.
What we collect
- Account data for event owners: name, email address, and a hashed password. If you sign in with Google, we receive your name, email address, Google account identifier, and profile picture from Google instead of a password.
- Event content: photos, written messages, and hand-drawn signatures that guests submit, along with the guest name they enter.
- Payment data: payments are processed by Stripe (see “Payments” below). We never receive or store card numbers; we store only the purchased plan, the payment status, and Stripe reference identifiers.
- Technical data: limited request metadata (such as IP address, browser user agent, and timestamp) attached to guest contributions and server logs, used for security, abuse prevention, and rate limiting.
- A guest device identifier: see the dedicated section below.
How we use it
We use this data only to provide the service: to run your event, collect and display contributions, build your memory book, process upgrade purchases, send the emails the service needs (such as receipts, password resets, and storage reminders), and keep the service secure. We do not sell personal data and we do not use it for advertising.
Guest contributions and consent
Guests are shown a short notice before contributing and choose what to submit. Event owners are responsible for having an appropriate basis to collect and keep their guests' contributions.
The guest device identifier
To keep the photo album fair, each guest device stores a small random identifier in the browser's local storage for the event being contributed to. It is used only to apply the per-guest photo limit. It is not used for tracking or advertising, it is not linked across events, and it can be cleared at any time by clearing the browser's site data.
Payments
Paid upgrades are one-time payments processed by Stripe Payments Europe, Ltd. When you buy an upgrade you are taken to Stripe's checkout page; your card or payment details go to Stripe directly and are handled under Stripe's privacy policy. Stripe may also send you the payment receipt. We receive and store only the purchased plan, payment status, and Stripe reference identifiers for the event you upgraded.
Where data and photos are stored
Account data, written messages, and signatures are stored on infrastructure located in the European Union (Hetzner Online GmbH, Germany, including Hetzner Object Storage in Falkenstein). Encrypted database backups are kept on the same EU object storage for a limited number of days and then rotated out.
Photos are handled in two parts. When a guest adds a photo, we generate and keep two smaller copies on our EU object storage: a thumbnail (around 400 px) and a display-sized version (around 1600 px). These power the memory book. They are kept on private storage and shown only through short-lived signed links, so they are not publicly browsable. The full-resolution original is uploaded to the event owner's own Google Drive if the owner has connected one. If Drive is not connected, or an upload does not succeed, the original is held on our storage for a limited period (about 60 days) and then automatically deleted, while the two smaller copies remain so the book keeps working.
For Google Drive we request only the limited drive.file permission,
which lets us add files to (and later remove them from) the single per-event folder
we create. We cannot see or access any of your other Drive files. Your use of
Google Drive and Google sign-in is also governed by
Google's privacy policy.
Service providers
We use a small number of processors to run the service: Hetzner (hosting and object storage, EU), Cloudflare (content delivery and security; traffic to the site passes through it), Stripe (payments), Google (sign-in and Drive, only when you choose to use them), and an email delivery provider for the transactional emails described above. Where a provider processes data outside the EU/EEA, recognised safeguards such as adequacy decisions or standard contractual clauses apply.
Analytics
We measure site usage with a self-hosted instance of Umami, a privacy-friendly analytics tool. It uses no cookies, stores no personal profiles, and does not track you across other sites. We do not use third-party advertising or tracking services.
Retention and deletion
Owners can delete any contribution or an entire event at any time, which removes the associated media, including offloaded originals in the event's Drive folder. Closing your account removes your personal data, subject to any legal retention obligations. Held originals are deleted on the schedule described above, and server logs are kept only for a short operational period.
Your rights
Under the GDPR you may request access, correction, deletion, restriction, or portability of your personal data, and you may object to certain processing. Contact [email protected] to exercise these rights. You may also lodge a complaint with your local supervisory authority; in Austria this is the Datenschutzbehörde (dsb.gv.at).
Cookies
We use only essential cookies needed to sign in and keep the application working (session and security cookies), plus the local-storage identifier described above. There are no advertising or third-party tracking cookies.
Changes
If this policy changes in a material way, we will note it here with a new date.
Contact
Questions about this policy: [email protected].