Legal
Privacy Policy
Last updated: June 7, 2026
PixlyShots ("we", "us") helps event organizers collect photos from their guests via a QR code. This policy explains what we collect, why, and the choices you have. By using PixlyShots you agree to the practices described here.
Who this applies to
PixlyShots has two kinds of users: organizers, who create an account and manage events, and guests, who upload photos to an event without creating an account.
What we collect
- Organizer accounts: your email, display name, and a securely hashed password.
- Photos & messages: the images guests upload and any optional name or message they add.
- Guest sessions: a random session token (cookie) and a one-way hash of the IP address, used to group a guest's uploads and to limit abuse. We do not store raw IP addresses or require guest accounts.
- Basic technical data: standard request logs needed to operate and secure the service.
- RSVPs and invitation passes: when an event uses a digital invitation, the guest's name, attendance and party size, plus an optional contact detail if the organizer requests it. Organizers may also register guest names (and optionally a phone number) to issue personal passes. These details are only visible to that event's organizer.
- Newsletter: your email address and language, only if you subscribe on our site. Every email we send includes an unsubscribe link, and you can opt out at any time.
How we use it
- To run events: store and display uploaded photos to the people the organizer shares the link with.
- To let organizers moderate, download, and manage their galleries.
- To protect the service against spam and abuse.
We do not sell your data, and we do not use uploaded photos for advertising.
Who can see the photos
Visibility is controlled by the organizer. Galleries can be public (anyone with the link) or private (archive only the organizer can view). Organizers can require approval before any photo appears. Only people with the event link or QR code can reach an event page.
Retention & deletion
Photos and event data are kept while the event is active. Free events are kept for a limited time after the event (currently 14 days), after which their photos are automatically deleted; a paid Event Pass extends this window (currently 30 days). Organizers can also delete individual photos, messages, or an entire event at any time, which removes the associated files. If you want your account and all related data deleted, contact us at the address below.
Security
Passwords are hashed with bcrypt and never stored in plain text. Access to organizer data requires authentication. We use parameterized database queries and standard web security practices.
Your choices
- Guests can choose not to add a name or message when uploading.
- Organizers can edit their profile, change their password, or close/delete events at any time.
- You can request access to or deletion of your data by contacting us.
Automated content screening
To protect events and their guests, uploaded photos may be automatically screened for explicit, unsafe, or clearly out-of-place content. Screening uses a third-party AI provider (Anthropic): only a reduced-resolution copy of the photo is sent to generate a safety verdict, it is not used to train their models, and we store only the resulting safety label — not the transmitted copy. Photos flagged as clearly explicit are held for the organizer to review and are never shown publicly. Screening labels are deleted together with the event on the schedule above. Illegal content (including child sexual abuse material) is handled through a separate legal process and may be reported to the appropriate authorities.
Service providers
We rely on a few trusted providers to operate: a payment processor (MercadoPago) for Event Pass purchases, an email provider (Resend) for account and notification emails, and an AI provider (Anthropic) for the content screening described above. Each processes data only as needed to provide its part of the service.
Contact
Questions about this policy? Email privacy@pixlyshots.com.