Privacy Policy
Last updated 21 August 2026
This policy explains what UX Mate collects when you use FotoFind, why, and what you and your guests can do about it. It is written to meet India's Digital Personal Data Protection Act, 2023.
The short version
- Face recognition runs on the photographer's own computer. We never receive or store face images for recognition on our servers.
- We store only the mathematical descriptors needed to match a guest to photos — not photographs of guests' faces, and not anything from which a face can be reconstructed.
- Guests consent before anything is stored, and can erase their data from the gallery at any time.
- We do not sell personal data, and we do not use your photographs to train machine-learning models.
Who is responsible
For photographers' account data, UX Mate is the data fiduciary. For the photographs and guest data within an event, the photographer is the data fiduciary and we act as their data processor, handling that data only on their instructions.
What we collect from photographers
- Account details — name, studio name, email address, and a hashed password. Passwords are never stored in a readable form.
- Event details — event names, dates, venues, and settings you enter.
- Photographs you upload, at the sizes your settings specify. By default only web-size copies are uploaded; full-resolution originals stay on your machine unless you turn that on.
- Billing records — your plan, subscription status and payment history. Card details are handled by our payment gateway and never reach our servers.
- Technical logs — IP address, browser, and timestamps, kept for security and troubleshooting.
What we collect from guests
When a guest opens an event gallery and chooses to find their photos, we store their consent record, the face descriptors used for matching, and optionally a name or phone number if the photographer's event asks for one. A face descriptor is a set of numbers; it is not a photograph, and a face cannot be reconstructed from it.
Guests' selfies are processed in their browser to produce that descriptor and are not retained afterwards.
Why we process it
To provide the service: authenticating you, storing and delivering photographs, matching guests to the photos they appear in, taking payment, keeping the service secure, and meeting our legal obligations.
Sharing
We share data only with the processors that make the service work — our hosting provider, our payment gateway, and our email provider — and only to the extent each needs. We disclose data to authorities only where the law requires it. We do not sell personal data to anyone.
Retention
Photographs and guest data are retained while the event gallery is live, per your plan's gallery duration, and are deleted after it expires. Deleted photos sit in a recoverable trash for a short window before being removed permanently. Account and billing records are kept for as long as the law requires us to keep them.
Security
Traffic is encrypted in transit. Passwords are hashed. Access to galleries requires the event's access token, and photographers can add a gallery password. Devices you pair can be revoked at any time from your dashboard, which invalidates their access immediately.
Your rights
You may ask us to access, correct, or erase your personal data, or withdraw consent where processing rests on it. Guests can erase their own data from an event gallery themselves using the option in the gallery, or by asking the photographer. To exercise a right, or to raise a grievance, write to hello@fotofinds.app. We respond within 30 days.
Children
FotoFind accounts are for adults. Where photographs of children are processed, the photographer is responsible for obtaining the consent of a parent or guardian as the law requires.
Changes
We will post any update to this policy on this page and, where the change is material, notify account holders by email.
Contact
UX Mate
C9, Arun Plaza, Pune, Maharashtra, India
hello@fotofinds.app