Privacy Policy
Last updated: July 16, 2026
This policy describes what Albomara ("we," "us") collects when you use the Albomara Android app or web viewer (together, the "Service"), and why. If something here doesn't match what the app actually does, the app's behavior is a bug — let us know.
Information we collect
Account information
Albomara only supports signing in with your Google account. When you sign in, we receive and store your name, email address, and profile photo from Google. We don't have or support any other login method, and we never see your Google password.
Photos and videos
The core of the Service is sharing photos and videos inside events you create or join. Anything you upload — whether taken with the in-app camera, synced automatically from your device's camera roll while auto-share is turned on for an event, or added manually from your device — is stored on our infrastructure and made visible to the other members of that event, according to your role (owner, member, or viewer) and that event's settings.
Camera-roll auto-share only ever runs for an event you've explicitly turned it on for, and only looks at media taken during that event's active window. You can turn it off at any time from event settings. The app never scans or uploads anything from a device that isn't a member's, and viewers never have their camera roll accessed at all.
Usage and diagnostic data
We use a small number of third-party services to keep the Service working and to fix things when they break:
- Firebase Analytics (Google) — basic app usage and interaction data, to understand which features are actually used.
- Sentry (self-hosted by us) — crash reports and error diagnostics from the Android app, so we can find and fix bugs.
- Google Mobile Ads (AdMob) — shows a banner ad in the app; Google may use an advertising identifier for this, subject to Google's own privacy policy.
Event analytics
Event owners can see anonymized visit analytics for their event's shared album — total views, unique viewers, and a breakdown by country/city — so they know who's actually looking at the album. We resolve a visitor's approximate location (country and city, not a precise address) from their IP address at the time of the visit; the IP address itself is not stored against that visit record. A small internal cache keeps a copy of previously-seen IP addresses purely to avoid repeat lookups; it is not visible to event owners and is used for no other purpose.
How we use this information
- To run the Service: authenticate you, show you the events you're part of, and deliver the photos/videos those events contain to the people who should see them.
- To keep the Service reliable: diagnosing crashes and errors, understanding usage patterns.
- To give event owners visibility into their own event's activity (see "Event analytics" above).
- To show ads that help support the Service.
We do not sell your personal information, and we do not use your photos or videos for anything other than showing them to the event you shared them in.
Who can see your content
Photos and videos you contribute to an event are visible to that event's other members and viewers, per the event owner's settings (for example, whether viewers can download full-resolution originals). An event owner can also generate a view-only web link for an event; anyone with that link can preview the event's name and contributor/photo/video counts, and must sign in with Google to actually browse the album. Owners can rotate that link at any time to revoke access.
Data retention and deletion
Events and their contents persist until deleted. Any member can remove (soft-delete) a photo or video they can see; an event owner or an administrator can permanently delete content. Soft-deleted content is recoverable by the event owner for a period of time before it may be permanently purged.
To delete your account and associated data, email albomara@aralel.com from the address associated with your account. We will delete your account, remove you from any events, and delete content you own that isn't part of another member's shared event history, within a reasonable time. This request works whether or not you still have the app installed.
Security
Data in transit between the app, our servers, and our storage provider is encrypted (HTTPS). Media files are stored on Cloudflare R2 and served through short-lived signed URLs rather than being made permanently public.
Children
Albomara is not directed at children, and we don't knowingly collect information from children. Signing in requires a Google account.
Changes to this policy
If we make material changes to this policy, we'll update the "Last updated" date above. Continued use of the Service after a change means you accept the updated policy.
Contact
Questions about this policy or your data: albomara@aralel.com.