Fotara
Privacy policy
Last updated: August 25, 2026
This policy describes what data Fotara processes, why, who it is shared with and for how long. It is written against what the product does today.
1 Who is responsible
The data controller is Duribe Tech, trading name of David Adrian Uribe Soto, with registered address at Turbaco, Bolívar, Colombia, owner of the service published at fotara.app.
For anything related to your personal data: duribe@fotara.app.
2 What data we process
Only what the service needs in order to work:
- Host account: a verified email address and, if you enter one, a display name.
- Sign-in identity: the stable identifier Google or Apple returns when you sign in with them. We never receive or store your password for those services. Apple lets you hide your real address and hand over a relay one; if you use it, that is the address we store.
- Sign-in codes: if you use the six-digit code, we store its hash — never the code itself —, the address it was sent to, its expiry and the number of attempts.
- Sessions: a hash of the session token, its expiry and the date it was last used.
- Albums: name, event date, plan, design and settings.
- Memories: the photos and videos uploaded, their derivatives (thumbnail, web version and video poster) and technical data such as size, dimensions and duration.
- Guests: a random identifier created in their own browser and, only if the person types one, a display name shown next to their uploads.
- Payments: the order identifier, the plan purchased, the amount and the email associated with the purchase, as reported by the payment provider.
3 Guests have no account
Whoever gets the link or scans the QR uploads straight from the browser without signing up: we ask for no email, no phone number and no password. The only thing that tells them apart is a random identifier stored in their own browser, which exists so they can delete what they uploaded.
Typing a name is optional: it lets the host know whose photos are whose, it is asked after the first upload and it can be skipped.
4 What we use the data for
- Running the service: creating the album, receiving the files, processing them and showing them to whoever has access.
- Identifying you: sending the sign-in code, verifying your email and keeping your session open.
- Charging for the plan and keeping a record of the purchase.
- Writing to you about operational matters concerning the service.
- Protecting the service: preventing abuse, fraud and automated use.
- Meeting legal and accounting obligations.
5 Legal basis
Where the GDPR or an equivalent law applies to you, the bases are: performance of the contract (running the service and your account), legitimate interest (security, abuse prevention and maintenance), compliance with legal obligations (accounting and invoicing) and your consent where we ask for it explicitly.
We do not process your data for advertising, and we do not sell it to anyone.
6 When you arrive from InvitiApp
Fotara and InvitiApp are sibling products with separate accounts. If you ask, from your InvitiApp invitation, to create your album on Fotara, InvitiApp hands us — only at that moment and only because you asked — your name, your email, your language and the identifier, title, date and payment status of that invitation.
With that we create or recover your Fotara account, create the album with the event name and date, and register the discount it entitles you to.
InvitiApp does not hand us its session cookie or your Google or Apple tokens, and we do not hand back your photos or the list of your guests.
7 Who we share it with
We do not sell your data and we do not pass it to advertisers. It is only processed by the providers we need in order to operate, solely to provide us that service and under our instructions.
We may also disclose it when required by a competent authority under the law, or where necessary to defend our rights or those of others.
8 Providers that process data for us
This is the complete list as of today:
- Amazon Web Services (United States, us-east-1 region): servers, database, storage for photos and videos, delivery network, processing queues and credential custody.
- Amazon SES: sending the email with your sign-in code and service notices.
- Lemon Squeezy: the payment gateway, which also acts as merchant of record. Your card details are handled on their platform and never reach our servers.
- Google and Apple: only if you choose to sign in with them, and only to verify your identity.
- InvitiApp: only if you come from an invitation and ask to create the album, as described above.
- Fotara uses no third-party analytics, no advertising pixels and no tracking networks.
9 International transfers
The infrastructure is in the United States (AWS, us-east-1 region). If you write to us from another country, your data is processed there.
Where the law requires it, those transfers rely on standard contractual clauses or another valid mechanism offered by the provider.
10 How long we keep it
Every album is created with a retention date calculated from the event day according to its plan: 30 days on Free, 365 days on Plus and 1,095 days on Max. That is the period during which we keep the album and its memories; beyond it they are no longer guaranteed and may be deleted.
Deletion of expired albums is not automatic today, so an album may still exist after that date. If you want it gone at a specific moment, delete it yourself.
The account and its email are kept for as long as the account exists. Sessions last at most 400 days. Sign-in codes expire after ten minutes. Payment records are kept for as long as accounting rules require.
11 Deleting your data
You can delete a single album from “Your albums”, and your entire account from your profile.
Deleting the account removes the account, its albums, every memory with its derivatives, open sessions and the files held in storage. It is immediate and cannot be undone.
Traces may remain for a while in backups, and in payment records for as long as the law requires them to be kept.
12 Your rights
Depending on where you live, you may:
- Access the personal data we process about you.
- Correct anything inaccurate.
- Delete it, using the deletion tools already in the product or by writing to us.
- Object to a processing activity or ask that it be restricted.
- Receive your data in a portable format.
- Withdraw your consent where the processing relies on it.
- Lodge a complaint with the data protection authority in your country.
13 Security
Traffic travels encrypted. Photos and videos live in private storage and are served through signed URLs that expire: they are not public, permanent addresses.
Session tokens and sign-in codes are stored as hashes, never in the clear, and codes cap the number of attempts.
No system is infallible: we do what is reasonable, but we cannot guarantee absolute security.
14 Children
Fotara is not aimed at children under 13 and we do not knowingly create accounts for them.
Children do appear in the photos of a family event: whoever runs the album and whoever uploads are responsible for having their parents’ or guardians’ permission. If you believe content of a child should not be published, write to us and we will take it down.
15 Changes to this policy
If we update this policy we publish the new version here, with its date. If the change is material, we notify active accounts by email.
16 Contact
Duribe Tech, trading name of David Adrian Uribe Soto — Turbaco, Bolívar, Colombia.
Email for privacy matters: duribe@fotara.app.