PhotoDove is built so that we can't see your photos, not merely that we promise not to. This page explains what that means in plain language. It's an expression of how the product works, not a liability shield.
PhotoDove is operated by We Remagine One AB (Swedish company registration 559316-0228), Karlstad, Sweden. For anything covered by data-protection law, we are the data controller. Contact: we@remagine.one.
There is no sign-up. No email, no phone number, no name, no contacts access. Your app has an anonymous installation identifier used only to enforce limits and measure aggregate health, and it is never tied to who you are. On Android it is deleted when you uninstall. On iOS it lives in the system keychain, which survives deleting the app — so reinstalling on the same phone is recognised as the same installation, which is why Premium is simply still there afterwards, with no account and nothing to restore. It is never synced to iCloud, and never shared with our other apps.
When you send photos, they are encrypted on your phone before they leave it. The decryption key travels inside the QR code or link you hand to the recipient — it never reaches our servers. What we relay through the cloud is encrypted data we have no ability to read, scan, or open. The recipient's app decrypts on their phone.
The encrypted files live in the cloud storage region nearest you that we run for at most one hour, and are deleted the moment the transfer completes — usually within minutes. (The one exception: a download already in flight when the hour strikes is allowed to finish, never more than 30 minutes past it — we don't cut a landing dove out of the sky.) Deletion is real removal, not hiding or flagging. If a send is never received, it is still erased within the hour, unconditionally. The sender can also delete it sooner.
PhotoDove never requests your location, and it never rewrites your photos. What your phone hands over is what we carry, so any EXIF or GPS data in it is preserved — you are sending your own photo to someone you chose, and it arrives as your phone handed it over. (One exception, and it is rare: some apps share a rendered image rather than the original file. When that happens, what arrives carries only what the sharing app put in it. Sharing from your photo library always hands over the original.) Since everything is encrypted end-to-end, we cannot read that metadata either.
You can set a name so your transfers arrive as “from Anna” rather than from nobody. It is not an account: there is still no registration, no password and no profile. The name lives on your phone, you can change or remove it at any time, and it travels sealed inside the encrypted transfer — so our servers receive it as unreadable data, exactly like your photos, and it is gone when the transfer is. We never store it, and we could not tell you who sent what even if we were asked. The same is true of the label you can give a single transfer.
We cannot see your photos, their contents, filenames, the name you give a transfer, or the name you give yourself (all of those are encrypted too). To move the files and enforce limits, our servers do handle a small amount of non-content information: the number and byte-size of files, whether each is a photo or video, timestamps, the anonymous installation identifier of the sender, and the country a transfer was released or received from — a two-letter country code we derive by a lookup in our own systems from your IP address, used only in that moment and kept instead of (never alongside) the IP itself, which is still never stored and never sent to anyone else. No city, no coordinates, no precise location. None of this is the content of your photos.
To keep PhotoDove working and understand its health, the app sends a small stream of anonymous events — such as the app being opened, a dove released, received, or landed, or the Premium screen being viewed — with basic technical context (platform, OS, and app version). If the app hits an error, an anonymous crash report is sent: the error type, a short capped message, and the top of the stack trace, plus whether it was fatal. Both are handled by us on our own servers — no third-party analytics or advertising SDKs in the app, no tracking, nothing sold — and neither carries the content of your photos or ties to who you are. These installation-level records are kept for 90 days, then age out.
The website is a separate thing, so it gets its own sentence: it counts page views with Vercel's analytics — no cookies, nothing stored on your device, no profile, and no following you across days or sites. Aggregate counts of which pages people reach, nothing more. It runs on the front page and the not-found page only: this privacy policy, the terms, and every dove link load no analytics at all.
The transfer itself — the encrypted files and the coordination data used to move them — is deleted as described above. What remains is limited to three things: the transfer's coordination record for up to 3 days (see Abuse reports below), the anonymous diagnostic and analytics events above, which age out after 90 days, and permanent aggregate statistics — plain counts such as how many transfers happened, how many bytes moved, and the countries transfers were sent and received from, with no identifiers, no names, and no content. Neither can be traced back to you or to a specific transfer. (If you buy Premium, the store's transaction identifier is also kept — see Payments below.)
Because transfers are end-to-end encrypted, we cannot scan content — the report path is the safety control, so we keep it usable for longer than the transfer itself. A transfer can be reported from within the app — from its receipt under "My doves", for up to 3 days after it lands — or by email at we@remagine.one. Reporting freezes the transfer and deletes anything still in the clouds.
To make late reports actionable, the transfer's coordination record — sizes, timestamps, and the sender's anonymous installation identifier; never content, never names, never who received it — is kept for up to 3 days after the transfer ends, then deleted. The encrypted files themselves are still deleted within the hour, exactly as described above, and the record of who received a transfer still dies with the hour. For a reported transfer we retain that same minimal record for up to 7 days from the report to respond and, where legally required, to cooperate with law enforcement. We do not capture the reporter's or the sender's IP address.
PhotoDove is free for photos. If you buy Premium, the purchase is handled entirely by Apple or Google through their app stores — we never see or store your card or payment details. To recognise your Premium status we keep only the store's transaction identifier, tied to your anonymous installation, never to your name.
PhotoDove is not directed at children and keeps no accounts or profiles of anyone.
Under the GDPR you have rights of access, rectification, and erasure. Because we hold no account and no content — and delete transfers within the hour — there is in practice almost nothing to request. For any question, contact we@remagine.one. You may also complain to the Swedish Authority for Privacy Protection (IMY).
If you are in the EEA (including Norway, Iceland, and Liechtenstein), the GDPR applies as described throughout this notice. If you are in Switzerland, the same protections apply and the Swiss Federal Act on Data Protection (FADP) governs; the rights above can be exercised the same way.
Everything that could read anything happens in the EU — the coordination records, the configuration, our own tools. That half does not move.
The encrypted files are the part that travels: we relay them through the storage region nearest you, so a handover between two people in the same part of the world no longer crosses the planet twice. That region may be outside the EU. It changes nothing about what anyone there can see — the files are encrypted on your phone before they leave it, the key never reaches us, and they are deleted within the hour in every region alike. We rely on a small number of cloud infrastructure sub-processors; they only ever handle encrypted data and non-content coordination information, and a current list is available on request. To route, secure, and rate-limit requests, these providers (and we, for rate limiting) may process your device's IP address transiently — it is never stored. Where a provider is based outside the EU, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses.
If this policy changes, we'll update the date above. Material changes will be reflected in the app.