WeDidThis — Privacy Policy
Last updated: 13 July 2026
This Privacy Policy explains how WeDidThis ("WeDidThis", "we", "us", or "our") collects, uses, stores, and shares information when you use the WeDidThis mobile application (the "App"). It is written to comply with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and applicable data protection laws.
Data controller: Dion Jones, sole trader, United Kingdom. Contact: dion@dionjonesdev.com
By downloading, accessing, or using the App you confirm that you have read and understood this Privacy Policy. If you do not agree with it, do not use the App.
1. Summary (the short version)
- We do not require an email address, phone number, password, real name, or any account to use the App.
- We collect the minimum needed to run a shared-photo event: a display name you choose, the photos you take in the App, an anonymous device identifier, and (if you allow it) a push-notification token.
- Photos are automatically deleted from our servers 24 hours after an event ends.
- Photos you have viewed are also cached inside the App on your own device so your past albums keep working after the server copy is deleted. This in-App copy is removed when you uninstall the App. Any photo you separately choose to save to your photo library is your own copy and stays on your device even after uninstalling.
- We do not sell your data, show ads, or use third-party advertising or tracking analytics.
2. Who this applies to
The App is intended for users aged 13 or over (or the minimum digital-consent age in your country, whichever is higher). It is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has provided us information, contact us and we will delete it.
3. What we collect and why
We only process the following categories of personal data:
| Data | What it is | Why we process it | Lawful basis (UK GDPR) |
|---|---|---|---|
| Display name | The name you type when creating or joining an event. Need not be your real name. | So other members of your event can see who took each photo. | Legitimate interests (Art. 6(1)(f)) — running the shared-album feature you asked for. |
| Photos | Images you capture in the App during your turn. | To share within your event and assemble the group album. | Legitimate interests; and your consent by choosing to take and submit each photo. |
| Anonymous device ID | A random identifier issued to your device on first launch (via anonymous authentication). No email, phone, or password is involved. | To recognise your device across your own events and to enforce access controls (so only members of an event can see its content). | Legitimate interests — security and core functionality. |
| Push-notification token | An identifier issued by Apple/Expo if you allow notifications. | To alert you when it is your turn to take a photo, and about your event. | Consent — you grant or deny notification permission. |
| Content reports | If you report a photo, we record which photo, who reported it, and any reason. | To review and remove content that breaches our Terms. | Legitimate interests, and compliance with our legal and platform obligations. |
| Technical/diagnostic data | Standard connection metadata (e.g. IP address at the network level, timestamps) processed transiently by our infrastructure provider to deliver requests. | To operate, secure, and debug the service. | Legitimate interests. |
We do not collect: your email address, phone number, real name (unless you choose to type it as your display name), contacts, precise GPS location, biometric data, or payment information. The App contains no third-party advertising SDKs and no third-party behavioural-tracking analytics.
Photos may incidentally contain personal data of other people (faces, surroundings). You are responsible for only photographing people who are content to be photographed — see our Terms of Use.
4. How photos are stored, and the 24-hour deletion
-
During and shortly after an event, photos are stored by our hosting provider (Supabase) so members can view the shared album.
-
We automatically and permanently delete all event photos from our servers 24 hours after the event ends. This is enforced by an automated job; it is not optional and requires no action from you.
-
We retain a limited amount of event metadata after that point — the event name, the list of moments (who took a photo or missed their turn, and when), and display names — so that your event history remains meaningful. The photographs themselves are gone from our servers. There are two different kinds of copy that may exist on your own device. They are not the same thing:
-
(a) The App's private cache. When you view an album, the App stores a copy of the photos you see inside its own private storage on your device, so that your past albums keep working after the 24-hour server deletion. This copy is never sent back to us, is not accessible to other apps, and is deleted automatically when you uninstall the App.
-
(b) Photos you save to your photo library. If you use the App's "save" feature, a copy is placed in your device's own photo library (camera roll). That copy is yours. It is not controlled or accessed by us, it is not deleted when the 24-hour server deletion happens, and it is not deleted if you uninstall the App. Removing it is entirely up to you, using your device's Photos app.
In short: uninstalling the App removes the App's own cached copy (a), but does not remove anything you deliberately saved to your photo library (b).
5. Who we share data with
We do not sell your personal data and we do not share it for advertising. We share data only with the service providers that make the App work ("processors"), each bound to protect it:
| Provider | Purpose | Location | Their policy |
|---|---|---|---|
| Supabase Inc. | Database, photo storage, and anonymous authentication | EU (eu-west-2, London region) | https://supabase.com/privacy |
| Expo (Expo/EAS) & Apple Push Notification service | Delivery of push notifications | USA / global | https://expo.dev/privacy · https://www.apple.com/legal/privacy |
We may also disclose information if required to do so by law, court order, or a valid request from a public authority, or to protect the rights, safety, or property of our users or others.
Where data is transferred outside the UK/EEA (for example, push delivery via Expo/Apple in the USA), such transfers are made under appropriate safeguards, including the providers' standard contractual clauses and equivalent mechanisms.
6. How long we keep data
| Data | Retention |
|---|---|
| Event photos (on our servers) | Deleted 24 hours after the event ends. |
| Event metadata (name, moments, display names) | Retained to preserve your history; deleted on account/data-deletion request. |
| Push-notification token | Removed when the related event's photos are purged, or on request. |
| Content reports | Retained while needed for moderation and any related legal purpose. |
| App's private on-device cache | Deleted automatically when you uninstall the App. |
| Photos you saved to your photo library | Yours, kept on your device indefinitely; not controlled or deleted by us. Remove them via your device's Photos app. |
7. Your rights
Under UK GDPR you have the right to: access your data; have it corrected; have it erased; restrict or object to its processing; data portability; and to withdraw consent (e.g. by turning off notifications) at any time.
Because we deliberately do not collect email addresses or account credentials, we identify your data by your anonymous device identifier. To exercise any right, email dion@dionjonesdev.com from the device in question or provide information that lets us locate your data. We will respond within one month. Note that most of your personal data (photos) is already deleted automatically within 24 hours of each event ending.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at https://ico.org.uk.
8. Security
We protect your data with, among other measures: encryption in transit (HTTPS/TLS); row-level security so that only members of an event can access that event's data; authenticated, membership-scoped access to photo storage (no public directory listing); and automatic deletion that minimises how long data exists. No system is perfectly secure, but we take reasonable and appropriate technical and organisational measures to protect your information.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by the "Last updated" date above and, where appropriate, notified in the App. Continued use of the App after a change constitutes acceptance of the updated policy.
10. Contact
Questions, requests, or complaints:
Dion Jones — dion@dionjonesdev.com