What we collect
- —Photos — images you upload, resized to a thumbnail and stored in Supabase Storage. We do not retain your original full-resolution files on our servers.
- —GPS coordinates — extracted from your photo EXIF data to identify the museum or city where you photographed each artwork. Stored alongside the photo record.
- —Email address — collected at sign-up via Firebase Authentication. Used to identify your account and send transactional emails (e.g. password reset).
- —Name — first and last name provided at sign-up, used to display your public collection.
- —Usage data — enrichment count and tier tier stored to enforce the free plan limit. No behavioural analytics or ad tracking.
How we use your data
- —Photo thumbnails and metadata are sent to Google Vision API and Google Gemini to identify the artwork, artist, and movement. These are third-party AI services with their own data policies.
- —GPS coordinates are sent to Nominatim (OpenStreetMap) to reverse-geocode your museum location. No account or API key is required; this service is privacy-respecting and does not store queries.
- —Your data is never sold to third parties and is never used for advertising.
Data storage
Your photos and account data are stored in Supabase (hosted on AWS us-east-1). The application is served via Vercel. Authentication is managed by Firebase Authentication (Google). All data is encrypted at rest and in transit.
Your rights
- —Delete photos — you can delete any individual photo from the gallery at any time. This removes the thumbnail from storage and all associated metadata.
- —Delete your account — email us to request full deletion of your account and all associated data.
- —Access your data — email us to request an export of your data.