Pic Jar — Privacy Policy
Last updated: 12 September 2026
Pic Jar ("the app", "we", "us") lets a group of people pool the photos and
videos they take during a shared event into one shared album. This policy
explains what data we collect, why, and how it is handled. Pic Jar is
developed by UseFull Apps.
Information we collect
- Account information (Google Sign-In): your name, email
address, and profile photo, used to identify you to other members of events
you join and to secure your account.
- Photos and videos: when you enable auto-add or manually
add media, camera photos and videos you took during an event's date range are
uploaded to that event's shared album so other members can view and download
them. We do not scan or upload screenshots, downloads, or media from other
apps.
- Location: if a photo you add contains GPS location data
in its metadata, that location is stored with the photo and shown to event
members (for example, on the photo details and map). We do not track your
device's live location.
- Event data: event names, dates, membership, and who has
downloaded which photos.
- Notifications: a device notification token so we can send
you push notifications about your events (for example, that someone asked to
join an event you own, or that a member added new photos).
- Usage and diagnostics: we use Google Firebase Analytics
and Crashlytics to understand which features are used and to detect and fix
crashes. This includes app-usage events and, on a crash, technical details
such as the error and device state. We do not collect an
advertising identifier and we show no ads.
How we use your information
- To operate the core feature: sharing your event photos and videos with the
members of the events you belong to.
- To authenticate you and manage event membership and owner approvals.
- To send you notifications about activity in your events, and optional
reminders to download shared photos.
- To understand how the app is used and to diagnose and fix crashes, so we
can improve Pic Jar.
Sharing and storage
Photos, videos, and event data are stored on Google Cloud Platform (Google
Cloud Storage and Cloud Firestore). Your content is visible only to approved
members of the events you join. We do not sell your data, and we
do not show advertising. We do not share your data with third
parties except the cloud, analytics, and crash-reporting providers (Google) used
to run and improve the app.
How we protect your data
We use the following safeguards to protect your personal and sensitive
data, including your photos, videos, location metadata, and any data received
from Google APIs:
- Encryption in transit: all communication between the
app, our servers, Google Cloud, and Google APIs uses HTTPS (TLS). We do not
accept unencrypted connections.
- Encryption at rest: photos, videos, and event data are
stored in Google Cloud Storage and Cloud Firestore, which encrypt all data at
rest.
- Extra encryption for Google access grants: the Google
Photos refresh token is additionally encrypted by our server with AES-256-GCM
before it is stored, using a key kept in Google Cloud Secret Manager and
never stored alongside the data. Short-lived Google access tokens are held in
server memory only while a transfer runs and are never written to storage.
The encrypted token cannot be read by the app or by any user.
- Authentication: every request to our servers must carry
a verified Firebase Authentication sign-in token; requests without one are
rejected.
- Access control: database security rules and server-side
membership checks ensure that only approved members of an event can see its
photos, videos, and details, and that users can only read their own account
data. Photo and video files are not publicly accessible: they can only be
reached through signed links that are issued to event members and expire
automatically (within 15 minutes for uploads and 60 minutes for
downloads).
- Limited internal access: access to production systems
and stored user data is restricted to the developer, and is used only when
needed to operate the app, provide support you request, or meet legal
obligations. We do not have access to your Google Photos library.
- Data minimisation: we request only the permissions
needed for the features you use. For Google Photos we request add-only access
and store only what is needed to complete the transfer.
- Deletion: when you disconnect Google Photos or delete
your account, the stored grant is revoked with Google and deleted from our
systems.
No method of transmission or storage is completely secure, but we work to
protect your data and will notify affected users as required by law if we
become aware of a security incident affecting their data.
Google Photos (optional)
If you choose Send to Google Photos for an event, you
connect a Google account and allow Pic Jar to create albums and add photos and
videos to that account's Google Photos library
(photoslibrary.appendonly). This is add-only access: Pic Jar
cannot see, change, or delete any photos, videos, or albums in your Google
Photos library.
- We use this access only to create an album for the event and copy the
event's photos and videos into it when you ask us to. We do not share your
albums with anyone.
- To run the transfer in the background, we store an encrypted access grant
(a refresh token), the email address of the connected Google account, and a
record of which items were already sent.
- Items sent to Google Photos count toward that Google account's storage
and stay there if you disconnect or delete your Pic Jar account.
- You can disconnect at any time in the app (Account → Google Photos
→ Disconnect) or at
myaccount.google.com/permissions.
Disconnecting or deleting your Pic Jar account revokes the grant and deletes
the stored token.
- Pic Jar's use and transfer of information received from Google APIs
adheres to the
Google
API Services User Data Policy, including the Limited Use requirements.
Data retention and deletion
- The photos and videos you add to an event remain in that event's shared
album until you remove them, the event's owner removes them, or the owner
deletes the event.
- You can remove photos you added at any time from within the app.
- You can delete your account and its data at any time from within
the app (Account → Delete account). This removes your account,
every event you created together with its photos and videos, and the photos
you added to events created by others. You can also request deletion by
emailing us (see Contact); for details see
our
account-deletion page.
Permissions
The app requests access to your photos and videos (to find event media),
media location (so photo GPS can be shown), and notifications (for event
activity and reminders). You can decline or change these in your device
settings; some features will be limited without them.
Children
Pic Jar is not directed to children under 13, and we do not knowingly
collect data from them.
Changes
We may update this policy; material changes will be reflected by the "Last
updated" date above.
Contact
Questions or data-deletion requests: usefullaps@gmail.com