Data Retention & Deletion
We do not want your data forever. Our systems are designed to process, deliver, and delete.
- Facial Embeddings: When you upload a selfie, we convert it into a mathematical string (an embedding). The original selfie image is deleted immediately. The mathematical embedding is automatically deleted 30 days after the event concludes.
- Event Photos: Event galleries expire based on the timeline set by the organizer or photographer (typically 30 to 90 days). Once expired, high-resolution source files are securely purged from our servers.
Privacy by Design
Entephoto was built to be more private than traditional event photography methods.
Traditionally, photographers share a massive Google Drive or Dropbox folder containing thousands of photos of every guest. Anyone with the link can download anyone else's photos.
With Entephoto, you only receive photos in which our AI has identified you. You cannot browse other guests' private galleries. This ensures that sensitive or private moments (especially at family events like weddings) remain restricted to the people involved.
Infrastructure Security
- Encryption: All data in transit is encrypted using industry-standard TLS. All photos stored on our servers are encrypted at rest using AES-256.
- Cloud Providers: We host our infrastructure on leading cloud providers (AWS/GCP) that maintain SOC 2 Type II, ISO 27001, and PCI-DSS compliance.
- No Third-Party Selling: We have never, and will never, sell guest data, phone numbers, or facial biometrics to third-party advertisers or data brokers.
Compliance
Our processing systems are built to align with the European Union's GDPR (General Data Protection Regulation) and India's DPDP Act (Digital Personal Data Protection Act). Guest registration requires explicit, active consent before any face matching occurs.