Privacy Policy
Werol Privacy
Last updated: June 28, 2026
Werol is an app for creating shared photo rolls for private events. This policy explains what data we process when an organizer creates an event or when an invited participant joins with a link or QR code.
Events are designed for trusted groups: they are visible only to the organizer and participants who joined the event, but photo reveal is a user-interface effect and not a cryptographic security boundary.
Data we collect
For organizers, we process the data needed to sign in with Apple or Google, such as account identifiers, name, and email address when provided by the authentication provider. For invited participants, we process the data needed to join a specific event, such as invite code, guest session, display name or nickname shown in the photo roll, and participation status.
We also process event data: title, settings, maximum participants, photos available per camera, camera style, reveal policy, and usage counters. Uploaded photos include the image file, the author attributed within the event, upload date, and technical information needed to store and display them.
Before upload, the app is designed to remove EXIF/GPS metadata from the image file. We may process technical logs, IP addresses, device information, and error data for security, diagnostics, and abuse prevention.
How we use data
We use data to create and manage events, let invited participants join, enforce participant and photo limits, display the shared photo roll, attribute photos to authors, and keep the service secure and operational.
If an event uses a non-instant reveal policy, Werol may show blurred photos or countdowns until the chosen reveal time. This logic is a product experience: an authorized event participant may still receive temporary URLs to access the original file.
For organizers, we may process purchase data or subscription status received from RevenueCat, Apple, or Google to confirm payments and activate purchased features.
Sharing within events
Photos and event information are accessible to the organizer and participants who joined that same event. We do not make the storage bucket public, and image access is handled through application permissions and temporary URLs.
Anyone who receives a valid link or QR code may try to join the event within the limits configured by the organizer. Participants and organizers are responsible for sharing the invite only with people they actually want to include in the event.
Service providers
We use technical providers to operate Werol, including services for infrastructure, authentication, databases, storage, notifications, payments, and diagnostics. Depending on the service configuration, these may include Cloudflare, Neon, RevenueCat, Apple, and Google.
Providers process data on behalf of Werol or under their own terms when acting as independent providers, for example for purchases managed by app stores.
Retention
We keep account, event, and photo data for as long as needed to provide the service, comply with legal obligations, resolve disputes, prevent abuse, and maintain operational backups. Technical logs are retained for a limited period compatible with security and diagnostics.
When an event or account is deleted, we remove or make the related data unavailable within a reasonable time, except for temporary backup copies or obligations that require further retention.
Rights and choices
To the extent provided by applicable law, you may request access, correction, export, or deletion of your data, or object to certain processing activities. You can also revoke device permissions, such as camera or notifications, from iOS settings.
For privacy requests, use the contact channels listed in the app or app store listing. We may ask for additional information to verify the request and connect it to the correct event or account.
Children
Werol is not designed for children to use independently. Organizers and participants must have the right to upload and share event photos, including any images where minors appear.
Security and changes
We protect the service with per-event membership checks, short-lived signed URLs, non-public storage, and secret management practices. No system is completely immune from risk, especially when participants can view and download shared content.
We may update this policy when the product, infrastructure, or legal requirements change. The version published on this page always shows the latest update date.