Legal
Privacy Policy
Last updated October 3, 2026
This policy explains what Lensdrop collects, why, and your choices. In plain terms: we are a delivery tool. We store the galleries you upload so your clients can view and download them. We don't sell your data and we never handle your clients' payments.
What we collect
- Account data: your email and, optionally, your studio name, used to sign you in and brand your galleries. If you sign in with Google or Apple, that provider shares your email address with us, and Google also shares your name and profile photo. If you choose Apple's Hide My Email, we receive a private relay address that forwards our emails to you.
- Gallery content: the photos and videos you upload and gallery settings (name, PIN, delivery state).
- Client testimonials: if a client chooses to leave a note from a gallery, the name and short message they type, and an email address if they choose to leave one so you can reply. It's stored for you. A note shows publicly once it is approved: by you, or automatically when it reads as a kind note (see "AI features" below). The email address is never shown.
- Usage data: basic, optional analytics to improve the product (you control this; see our Cookie Policy).
How we use it
To run the service: store and deliver galleries, authenticate you, send essential emails (sign-in codes, expiry reminders), and improve Lensdrop. We also use automated tools that check delivered images against known databases of illegal content, and we may review content when we have reason to believe our Terms of Service are being violated; matches involving illegal content are reported to the relevant authorities. We do not sell personal data.
Third-party services we use
We rely on a small set of trusted providers to run Lensdrop. They process data only to provide their service to us, under agreements that limit how it can be used:
- Supabase: authentication and database (your account and gallery settings).
- Cloudflare: gallery storage, delivery (CDN), email forwarding, and the AI processing that powers Auto clean-up and Find my photos (see "AI features" below). Photos are processed only to provide these features and are not used to train any AI models.
- Anthropic: the AI model behind the suggestions made from a gallery's photos (a cover, a name and details, section names, the best shot among near-identical ones, and the photos for a reel), and that reads a client's note to tell a kind note from a question (see "AI features" below). It is shown small preview images from the gallery and the text of each new note. Its API does not use them to train models.
- Vercel: application hosting.
- Amazon Web Services: a relay in Mumbai that receives photos from cameras sending over FTP and forwards them straight into gallery storage. It holds a photo only for the moment it takes to pass it on, and only if you connect a camera.
- Upstash: a background job queue and a fast cache that keep gallery processing and delivery responsive (they hold gallery and job data briefly, never your photos).
- Resend: sending essential and transactional emails.
- Dodo Payments: our Merchant of Record, which processes payments and billing for all customers, in INR for customers in India and in USD elsewhere.
- PostHog: product analytics and session replay to understand usage and improve Lensdrop. Session replay records your interactions and on-screen content, including images and what you type in most form fields; sensitive fields (passwords, gallery PINs, and sign-in codes) are always masked, and payment details are entered in our payment provider's own checkout, which session replay cannot see. It can run anywhere in Lensdrop, including shared gallery pages (where we record only a sample), and loads only if you opt in (see our Cookie Policy).
Some of these providers are based outside your country, so your data may be processed internationally under appropriate safeguards.
Clients
Clients view galleries via a shared link without creating an account. We don't collect client payment information. Lensdrop is never part of the payment between you and your clients.
Leaving a testimonial is optional and client-initiated. A client who does provides their name and message themselves, and is told before sending that the note may be shown on the gallery. A note that reads as a kind review is shown on the photographer's galleries and public testimonials page automatically, unless the photographer has turned that off; any other note waits for the photographer to decide. The photographer can hide any note at any time. A client who wants a displayed note removed can ask the photographer, or contact us.
AI features
Lensdrop includes optional AI tools that help photographers work faster. Some run on our own infrastructure (Cloudflare); others send small previews of photos, or the text of a client's note, to an AI model run by Anthropic. Both are listed with our providers above, and each tool below says which it uses. Photos and notes are not used to train AI models and are never sold. AI judgements can be wrong, which is why each tool only suggests, or can be undone.
- Auto clean-up: an optional tool that scans a gallery's photos to flag shots the photographer would probably drop (blurry, closed eyes, over- or under-exposed, and near-duplicates) so the photographer can review them. It only flags photos; nothing is deleted without the photographer's action.
- Find my photos: an optional face-search feature, described in the next section.
- Photo search: to let a gallery be searched by what its photos show ("cake", "first dance"), each photo is summarised as a list of numbers on our infrastructure (Cloudflare, listed above). The summary describes the picture, not a person, is never shown to anyone, and is deleted with the photo or the gallery.
- Cover, name and detail suggestions: after an upload, a dozen small previews from the gallery are shown to an AI model (Anthropic, listed above) to suggest a cover photo, a few names, the venue if it is visible in the photos, and a one-line description. Along with the previews, the model is told the gallery's current name and the dates the photos were taken, and nothing else about you or your clients. They are suggestions only: the photographer chooses. Turning off "Suggestions from the photos" in Account preferences turns this off.
- Sections, best shots and reel photos: to suggest names for groups of photos, two small previews from each group are shown to the AI model (Anthropic) with the times they were taken. To pick the best frame among near-identical shots, and to choose the photos for a highlight reel, small previews of those photos are shown to it after Auto clean-up runs. Nothing is deleted: the other shots stay in the gallery and the photographer can change every choice. Turning off "Suggestions from the photos" turns these off.
- Client notes: when a client leaves a note, its text, the name they signed it with, the gallery's name and the studio name are shown to an AI model (Anthropic, listed above), which says whether it is a kind note or something else, such as a question or a complaint. A kind note is shown on the photographer's galleries straight away and the photographer is emailed so they can hide it; everything else waits for the photographer. The client's email address is never sent. Turning off "Approve kind notes automatically" in Notes, or "Suggestions from the photos" in Account preferences, turns this off, and every note then waits for the photographer.
Find my photos and face data
Find my photos is an optional feature that is off by default and that a photographer turns on for a specific gallery. When it is on, Lensdrop creates a numeric representation (a "face embedding") of the faces in that gallery's photos so a guest can find the photos they appear in. A guest who chooses to use it takes a selfie; we create a temporary embedding of that selfie, compare it only to that gallery, and return the matching photos. Face data is biometric data, and we handle it with care:
- Consent: the feature is off unless a photographer enables it, and by enabling it the photographer confirms they have the consent of the people in the gallery. A guest uses it only by actively choosing to take a selfie.
- The selfie is never stored: it is used only to compute a match and is discarded immediately afterwards.
- Used only within one gallery: embeddings are matched only within the gallery they came from. We do not build a face database across galleries, identify anyone by name, or sell or share face data.
- Retention: a gallery's face embeddings are deleted as soon as the photographer turns the feature off, and otherwise when the gallery expires or is deleted, along with its photos.
- Where it's available: because biometric laws differ by region, Find my photos is not offered to gallery visitors in the EU/EEA, the UK, Switzerland, or the US states whose biometric-privacy law restricts it; there it appears as coming soon.
If you appear in a gallery that uses this feature and want your face data removed, ask the photographer to turn it off or delete the gallery, or contact us at privacy@lensdrop.app.
Retention
Galleries stay active for their window (currently 6 months for a paid gallery, 30 days for a free one), then are archived and permanently deleted 7 days later unless you extend them. You can delete a gallery, and its photos, at any time, which begins purging the stored files right away. Any face embeddings created for Find my photos are deleted at the same time.
Contact
Questions about your data? Email privacy@lensdrop.app.


