Last updated: 31 August 2026
This Privacy Policy explains how Allshots collects, uses, and protects your information when you use the Allshots mobile application and the guest web app (together, the “App”).
The controller for the processing described here is Boz Apps, proprietor Berk Özdoruk, Halilim Street No 5, Bodrum, Türkiye. Contact: allshots.app@gmail.com. Full contact details are on our imprint page.
Each event has a host who creates it, invites guests and decides why photos are collected at that event.
We do not sell your personal data, and we do not use your photos for advertising.
Permissions are requested at the moment a feature needs them and can be revoked any time in your device Settings.
Content you upload to an event is visible to the event host and, depending on the gallery mode the host has chosen, to other guests of that same event. In open mode guests see each other’s content; in private mode each guest sees only their own uploads while the host sees all of it.
The gallery mode is a visibility setting within the service; it is not a form of encryption. Content is not published, is not indexed by search engines, and is not searchable outside the event.
Allshots is a hosted service. Content is stored on managed cloud infrastructure and is encrypted in transit and while stored. It is not end-to-end encrypted.
As the operator of that infrastructure we hold administrative credentials and are therefore technically able to access stored files. We do not access event content routinely, and the App gives us no feature for browsing user galleries. We access content only where it is necessary:
Any other use is excluded. We do not use content for advertising, analytics, profiling or machine-learning training.
We use the following providers to operate the App. Each processes data on our behalf under its own security and privacy commitments:
We will update this list before adding a new provider.
We advertise Allshots on platforms like Facebook and Instagram. To understand whether those ads work, we share limited app events (for example: app installed, event created, purchase completed) with Meta, together with device information. Your photos, videos, voice recordings, notes and event content are never shared with advertising partners.
On iOS, sharing that can be used to identify your device across other companies’ apps only happens if you tap Allow on the App Tracking Transparency prompt. If you decline, we only receive aggregated, privacy-preserving measurement (such as Apple’s SKAdNetwork), and your advertising identifier is not collected.
Content and account data are stored with Google Firebase, across more than one region:
eur3 multi-region, in the European Union.us-east1 region, in the United States.us-central1 region, in the United States.Transfers to the United States are covered by Google’s Cloud Data Processing Addendum, including the EU Standard Contractual Clauses it contains, and by Google LLC’s certification under the EU–US Data Privacy Framework.
Crash and error diagnostics are processed by Sentry in the European Union, on servers in Germany.
We are based in Türkiye and access the infrastructure administratively from there, within the limits described in section 7.
We may introduce a maximum retention period for paid events. If we do, we will give hosts at least 30 days’ notice and the opportunity to download their album beforehand.
You can delete your account and associated data at any time from Settings → Delete account & data inside the App. For hosts, this deletes your events and their content. For guests, this removes your uploaded content and your account identifier. You can also email us to request deletion.
Guests at an event take photos and upload them to a private gallery held by the organiser of that event. If you appear in one of these photos, the organiser of the event decides why the photos are collected; we provide the technical service.
The photos are not public, are not indexed by search engines, and are visible only within that event. We do not run facial recognition and do not identify anyone in them.
You can object to a photo being kept and ask for it to be removed, without having an account. Write to allshots.app@gmail.com with the event code if you have it, or a description of the event and roughly when it took place. You can also contact the organiser of the event directly. We aim to respond within seven days.
The App is not directed to children under 16, or under the higher minimum age required in your country. We do not knowingly collect data from children under that age. This concerns the age required to use our service; whether children may be photographed at an event is a matter for the host and the parents or guardians concerned.
Depending on where you live, you may have the right to access your personal data, to have it corrected or deleted, to receive a copy of it, to restrict or object to certain processing, and to withdraw a consent you have given. To exercise any of these, write to allshots.app@gmail.com.
If you are in the European Union, the United Kingdom or Switzerland, you also have the right to lodge a complaint with your national data protection supervisory authority.
We do not make automated decisions that produce legal effects for you, and we do not profile you.
We disclose content or account data to an authority only where we receive a legally valid, written request from a body competent to make it, and only to the extent that request requires. We keep a record of such requests and, where we are legally permitted to do so, we inform the affected host.
If a security incident affects your personal data, we will assess it without delay, notify the competent supervisory authority where we are required to, and inform affected users where the incident is likely to result in a high risk to them.
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above, and, where a change materially affects your rights, by notice in the App.
Questions about privacy? Email us at allshots.app@gmail.com.