Legal

Privacy Policy

Lenzl is built for photographers and the people they work with. We take your privacy seriously and believe you should only have to share what's necessary for the app to work well. This policy explains what data we collect, why we collect it, how we protect it, and the choices you have.

We will never sell your personal data to third parties, use it for advertising, or share it beyond what is described below.

1. Who we are

Lenzl is a photography platform. References to “Lenzl”, “we”, “us”, or “our” in this policy refer to Lenzl. If you have questions about this policy, contact us at hello@lenzl.com.

2. Information we collect

Account information

When you create an account we collect your email address, a display name, and a password (hashed — we never store it in plain text). You may optionally add a profile photo and a short bio. We also record which account type you chose (Photographer or Viewer) so we can show you the right features.

Photographer gallery

Photographers can create a public-facing gallery with a custom URL slug. We store the gallery title, description, albums, and the photos you upload. Photos are stored in Supabase object storage and never processed or analysed beyond generating thumbnails for display.

Albums have visibility settings (public or private). Private album content is only accessible to you while signed in. We also store a “published” snapshot each time you publish your gallery so you can track when it went live.

Portal sessions

Portal is a feature that lets photographers create short-lived client-access sessions. For each session we store:

  • Session name, date, and optional description
  • Location name and coordinates (latitude/longitude) — only if you choose to add them
  • Access mode (open, code-protected, or request-based)
  • Photos you upload into the session
  • A short access code used to generate a QR code for your clients
  • Expiry and close timestamps

Location data is optional. If you set a location it may be shown on the public explore map, depending on your “Public map” setting for that session.

Portal events

Events group multiple sessions together (for example, a wedding day or a sport meet). We store the event name, description, date, and optional location. Public events appear on the explore map. Private events are only visible to you.

Client access and viewer data

When a viewer accesses a portal session, we create an access record that links their account (or a temporary identifier) to that session. This lets us show the photographer how many people are viewing a session and lets viewers save photos. We store the access status (active, approved, pending) and timestamps. We do not collect identifiable device fingerprints or behavioural tracking data.

Uploaded photos

Photos you upload are stored in Supabase secure object storage. Access URLs are time-limited signed URLs — they expire after one hour and cannot be guessed or scraped. We do not analyse the content of your photos on our servers using AI or machine learning, and we do not share photos with any third party. The one thing that ever examines the content of a photograph is described under “Find photos of me” below, and it runs on the viewer's own device, never on ours.

Push notifications

If you enable push notifications we store a device push token associated with your account. This is used only to deliver notifications relevant to your sessions (for example, when a viewer requests access or a session receives a new upload). You can revoke notification permission in your device settings at any time.

Gallery customisation

Photographers can customise their gallery appearance (colours, fonts, layout). These preferences are stored against your account and used solely to render your gallery.

Usage and analytics

We collect basic platform analytics to understand how the app is used — for example, page view counts and session activity events. This data is aggregated and not linked to personally identifiable information. Visitor analytics are cookieless: we store nothing on a visitor's device, and unique visitors are counted with an anonymous identifier that is derived on our servers and changes every day, so it cannot follow anyone over time or across sites. Visitor analytics (views, unique visitors, referral sources) visible on the Gallery Analytics page are derived from your gallery's traffic only and are not shared with other users.

Location data

Location data is always opt-in. When you create a session or event you may enter a location manually or use your device's location to pre-fill the coordinates. We do not collect your location passively in the background. Location data attached to a session or event is used only to display pins on the explore map and in session detail views.

Face matching — “Find photos of me”

Lenzl offers an optional way to find yourself in a set of photographs. It is off unless you switch it on, it is never switched on by accepting our terms, and your photographer cannot switch it on for you or for anyone else.

If you turn it on, you choose a photo of your own face. That photo is stored in your own browser, on the device you are using. It is never uploaded to Lenzl, and neither is anything measured from it. When you search, your browser compares it against the pictures it has already downloaded in order to display them to you. The comparison happens on your device. We are not told that you searched, what you searched for, or what matched.

Nothing is created or kept about anybody else in the photographs. Other people's faces are read from images already on your screen, compared, and discarded when you leave the page. Lenzl holds no record of who appears in any photograph, builds no index of faces, and cannot search photographs for a person — neither can your photographer, and neither can we on anyone else's behalf.

The only thing we store on our servers is the fact that you agreed: your account, the date and time, and which version of the in-app notice you were shown. That is what lets us show you what you were told. It contains no biometric information.

You can withdraw at any time in Settings, in one step. Withdrawing deletes your photo from the device you are using and deletes the record of your agreement from our database — the record is removed, not marked inactive. If you have used the feature on another phone or computer, the photo stored there is deleted the next time you open Lenzl on it. Deleting your Lenzl account removes all of it as well.

A photograph of a face used to identify someone is treated by UK and EU data protection law as a special category of personal data. Lenzl does not process it: you do, on your own device, about your own face, having been told what happens and having chosen it. That is why the feature is built this way rather than as something we run over everybody's albums.

Custom domains

If you set a custom domain for your gallery, we store that domain name and use it to route requests to your gallery. We do not collect any additional data via your custom domain beyond what is described in this policy.

3. How we use your information

We use the data we collect to:

  • Provide and operate the Lenzl service
  • Authenticate you and keep your account secure
  • Display your gallery, albums, and photos to the audience you choose
  • Enable client-access portal sessions and manage viewer requests
  • Show session and event pins on the public explore map (only when you opt in)
  • Send push notifications relevant to your account activity (only if you opt in)
  • Display photographer analytics on your own dashboard
  • Record that you agreed to on-device face matching, and when (only if you opt in) — we never receive the photo itself or anything derived from it
  • Improve the reliability and performance of the platform
  • Respond to support requests you send us

We do not use your data to serve ads, build behavioural profiles, or train AI models.

4. Who we share data with

We only share data with the sub-processors required to operate the service:

  • Supabase — database, authentication, and file storage. Your data is held in Supabase-managed infrastructure.
  • Cloudflare — hosting and edge delivery of the web application, storage and resizing of your photographs, and cookieless traffic measurement. Cloudflare Web Analytics sets no cookies and builds no cross-site profile.
  • Stripe — payments. When you subscribe, buy a domain, or a client pays you through a gallery, Stripe receives the details needed to take that payment. We never see or store full card numbers.
  • Google Analytics — only on Lenzl's own marketing pages, and only if you accept it when asked. It is never loaded on a photographer's published gallery or on a client portal link, so a photographer's own visitors are never sent to it.

We do not share your personal data with advertising networks or data brokers, we do not sell it, and we do not use it to train AI models. If the list above ever changes, we will update this policy and notify you.

5. Data retention

We keep your data for as long as your account is active. If you delete your account, the deletion happens straight away: your personal information, gallery content and uploaded photos are removed as part of that request, not queued for later. There is no grace period and no way for us to undo it, so please be certain before you confirm. Copies may persist briefly in our providers' routine encrypted backups until those roll over. Some anonymised aggregate data (such as aggregated page view counts) is retained for longer as it cannot be linked back to you.

Portal sessions have optional expiry dates. Once a session expires or is closed, the session data remains in your account history until you delete it, but the session is no longer accessible to viewers.

6. Security

All data is transmitted over HTTPS. Passwords are hashed using industry-standard algorithms — we never store plain-text passwords. Photo URLs are generated as short-lived signed URLs (valid for one hour) so that even if a URL is shared it cannot be used indefinitely. Access to our database is restricted to authenticated services using least-privilege roles.

No system is completely immune to security incidents. If we become aware of a breach that affects your data, we will notify you promptly and take all reasonable steps to limit the impact.

7. Your rights

You have the right to:

  • Access a copy of the personal data we hold about you
  • Correct any inaccurate data
  • Request deletion of your account and all associated data
  • Withdraw consent for push notifications at any time via your device settings
  • Opt out of your sessions or events appearing on the public explore map
  • Export your photos before deleting your account

To exercise any of these rights, email us at hello@lenzl.com. We will respond within 30 days.

8. Cookies and local storage

Lenzl uses browser local storage and session storage to remember your authentication state and temporary UI preferences (for example, redirect targets after login). We do not use third-party tracking cookies or advertising cookies. No cookie consent banner is shown because we do not place non-essential cookies.

9. Children's privacy

Lenzl is not directed at children under the age of 13. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

10. Changes to this policy

We may update this policy from time to time. If we make material changes we will notify you by email or via an in-app notice before the changes take effect. The “Last updated” date at the top of this page always reflects the current version.

11. Contact

Questions, concerns, or requests about this privacy policy should be sent to hello@lenzl.com.

© 2026 Lenzl. All rights reserved.