Account & identifiers
- Email address (for account signup or claiming a guest account)
- Profile: name
- Device identifier or guest token (for guest participation persistence)
User content
- Photos you upload
- Film details you create (title, description, dates, settings)
Purchases
Purchase receipts and product IDs validated via RevenueCat
Usage & diagnostics
- App and website analytics events, general location (city/region), device/OS, performance metrics, crash logs
- Optional session replay via PostHog (screen interactions for product improvement; sensitive fields masked where possible)
Website cookies
Basic cookies for authentication and analytics on https://once.film
Camera & photos
- Camera access only when you use the capture feature
- Photo library access only when you choose a photo
- Access requires your device permission and is not used in the background
App Store privacy labels (summary)
Data linked to you: Identifiers (email), Purchases, User Content (photos), Usage Data, Diagnostics.
Data used for tracking: **None**. Third‑party advertising: **None**.
Account & identifiers
- Provide and operate the Service (create films, invite participants, upload and view photos)
- Process purchases and prevent fraud
- Communicate with you (invites, uploads, reveal times, support, service updates)
- Improve reliability and performance (analytics, diagnostics, session replay if enabled)
- Comply with law and enforce our terms
Legal bases (EEA/UK): performance of a contract, legitimate interests, consent (where required), and legal obligation.
We do not sell personal information. We do not allow cross‑app tracking.
Within a film
- Film title/details and photos are visible to invited participants according to the film’s settings
- Your display name may be shown to other participants
Service providers (processors)
- **Supabase** – database, authentication, storage
- **RevenueCat** – purchase validation and entitlements
- **PostHog** – analytics and optional session replay
- **Vercel** – web hosting and APIs
Providers access data only to perform services for us and must protect it.
- Account data: kept while your account is active
- Deleted accounts: personal data removed within **30 days**
- Photos: kept until the film is deleted or your account is closed
If you delete your account, photos you uploaded to others’ films may remain in those films; your attribution will be anonymized
- Purchase records: kept for up to **7 years** for tax/legal reasons
- Aggregated or anonymized analytics may be kept longer
- Encryption in transit (HTTPS/TLS)
- Encryption at rest provided by our cloud vendors
- Role‑based access and monitoring
No security method is perfect. We cannot guarantee absolute security.
Security incidents
If a breach involves your personal data, we will notify you and regulators when legally required.
In‑app controls
- Delete account: **Settings → Delete Account** (permanent within 30 days)
- Manage push notifications in your device settings
- Manage email notifications in app settings
- Disable session replay in app settings
Requests
Contact hello@once.film to access, correct, export, or delete your personal data. We may keep limited data to meet legal requirements, prevent abuse, or maintain backups.
Region‑specific rights
- **California (CCPA/CPRA):** right to know, delete, correct, and opt‑out of sale/share (we do not sell or share); no discrimination for exercising rights
- **EEA/UK (GDPR):** rights to access, rectification, erasure, portability, objection, and restriction; you may lodge a complaint with your local authority
Once is not for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided data, contact hello@once.film and we will delete it.
We operate primarily in the United States, and your data may be processed in the U.S. and other countries. Where required, we use appropriate safeguards for international transfers.
The App Clip uses minimal data to let guests join a film and upload a photo with your permission. It uses camera and network access only while in use and follows this policy.
We will update this page when we change the policy and will notify you of material changes in‑app or by email. Continued use of the Service after changes take effect means you accept the new policy.
Email:
hello@once.film
Response time:
we aim to respond within 48 hours
For urgent privacy concerns, include “URGENT – Privacy Request” in the subject line.

