Privacy Policy
Effective 6 August 2026
The short version
- Face recognition runs entirely on your phone. Your camera roll is never uploaded for scanning, and face data (the numerical face templates the app computes) never leaves the device that created it.
- Photos and videos delivered through SeenAt are end-to-end encrypted. Our servers store ciphertext we cannot read.
- We collect the minimum needed to run the service: your phone number, a display name, the reference face photos you choose to share, and delivery metadata.
- We show no ads, sell no data, and use no third-party advertising or analytics trackers.
Who we are
SeenAt ("we", "us") is a photo-sharing service for families, available as an iPhone app. You can reach us at hello@seenat.app.
Information we collect
Account information
Your phone number (used to sign in and to recover your account on a new phone) and the display name you enter. Phone verification is handled by Google Firebase Authentication.
Reference photos
To receive photos of your family, you choose a small set of face photos ("reference photos"). These are uploaded to our servers and shown to the people you invite so they can see exactly whose photos they would be sharing before agreeing. Reference photos are the one category of photo content our service can see — a deliberate design, limited to the handful of faces you explicitly choose to share for identification.
Delivered photos and videos
When someone who has agreed to share with you takes a photo that matches your reference photos, their phone encrypts it and uploads it for delivery to you. Delivered photos, Live Photos, and videos are end-to-end encrypted on the sender's phone before upload: the encryption keys exist only on the sender's and receiver's devices, and our servers store only ciphertext. We cannot view this content.
Face data
The app computes numerical face templates ("embeddings") on your device — from your own photo library and from the reference photos of people you've agreed to share with — in order to find matches. These templates are computed on-device, stay on-device, and are never transmitted to our servers. We do not operate any server-side face recognition.
Metadata
Records needed to operate the service: who has agreed to share with whom, event membership, delivery records (timestamps, file identifiers, delivery status), and encrypted-key material we cannot open.
Device information
A push notification token for your device (so we can tell you when photos arrive) and basic diagnostic logs from our servers.
What we do not collect
- Your photo library. Matching runs locally; unmatched photos never leave your phone.
- Face templates or any biometric identifiers — these never leave the device that computed them.
- Your contacts, location history, or browsing activity.
- Advertising identifiers. There are no ads and no third-party analytics or tracking SDKs in the app.
How we use information
Solely to provide the service: authenticating you, showing reference photos to the people you invite, storing and delivering encrypted media, sending notifications when photos arrive, and keeping the service secure and reliable. We do not sell or rent personal information, and we do not use it for advertising.
Consent is built in
Nothing is matched or delivered without explicit agreement on both sides. Senders see and approve the reference photos before any matching starts, review matches before they're sent (unless they choose automatic sending for someone they trust), and either side can end an agreement at any time — which stops delivery immediately.
Service providers
We use Google Firebase (authentication, database, server functions, hosting — Google Cloud, primarily US data centres) and Cloudflare R2 (storage of encrypted media and reference photos). These providers store data on our behalf and do not use it for their own purposes. We may also disclose information if required by law.
Retention and deletion
- Delivered media is retained so the recipient can access it. When a sharing agreement is declined, revoked, or expires, its media and reference photos are deleted from our servers.
- Reference photos are deleted when no active or pending agreement uses them.
- To delete your account and all associated data, contact hello@seenat.app. We complete deletion requests within 30 days.
Security
Delivered media is protected by end-to-end encryption (per-object keys wrapped to the sender's and receiver's device keys). All traffic uses TLS. Media storage is accessible only through short-lived signed URLs issued after the server verifies you are a party to the delivery. Because content is end-to-end encrypted, if you lose access to your devices and your iCloud Keychain, we cannot recover previously delivered media for you.
Children
SeenAt accounts are for adults and teens aged 13 or older. Children commonly appear in photos shared through SeenAt — that sharing is initiated and controlled by the family members and trusted adults involved, and the consent model above applies to every share.
Your rights
Depending on where you live (including under the Australian Privacy Act and the GDPR), you may have rights to access, correct, export, or delete your personal information, and to complain to a privacy regulator. Contact us at hello@seenat.app and we will help.
Changes
If we change this policy, we'll update this page and the effective date, and for material changes we'll notify you in the app.