posa

Privacy

posa is a shared disposable camera: whoever hosts an event creates a roll, guests shoot, and the photos develop all together. This page says which data that takes, where it lives and how to delete it.

Updated September 18, 2026

Who handles your data

Data controller: --. For any question about your data, write to hello@posa-app.com.

What we collect

Account. If you sign in with Apple or Google we receive the account identifier, the email and, if you share it, your name. With Apple's Hide My Email we only receive a relay address. If you join as a guest from an invite we ask for nothing: you get an anonymous identifier and choose the name the others will see in the roll.

What you put in the roll: the photos you take, voice messages, hearts on photos and reports.

Purchases. Payments go through Apple or Google via RevenueCat: we never see card details. We keep the outcome of the purchase, the price and the event it belongs to.

Notifications. If you turn them on, we store the device token and language, to tell you when the roll develops.

App usage. We record usage events such as “roll opened” or “photo taken”, tied to an internal identifier and never to a name, email, content or invite code. On this site we count visits in aggregate, without cookies.

Why

To run the service you asked for: the roll, invites, developing, purchases (performance of a contract).

To keep it safe: reports, photo removal, abuse prevention (legitimate interest).

To understand what works, with usage statistics that identify no one (legitimate interest).

We don't sell data and we don't run ads.

Who sees your photos

Only the people in the same roll, and only after it develops: until then they stay veiled for everyone. The event host can remove a reported photo.

Who we rely on

Supabase (database and files, servers in the European Union, Frankfurt) · RevenueCat (purchases) · Apple and Google (sign-in, payments, notifications) · Expo (notification delivery) · PostHog (usage statistics, servers in the European Union) · Vercel (this site).

When a provider handles data outside the European Union it does so with the safeguards the GDPR requires, such as standard contractual clauses.

How long we keep it

A roll's photos and voice messages stay online for the period chosen for the event: 90 days, 1 year or 10 years. We warn everyone a week before, so anyone can save them. Then the files are deleted; only the record of who took part and how many photos they took remains.

Your account stays until you delete it.

Deleting everything

If you sign in with Apple or Google: in the app, Account → Delete account. We delete the account, the events you created and every photo and voice message you left. If you joined as a guest, or no longer have the app, write to hello@posa-app.com: instructions are at posa-app.com/delete-account.

Your rights

You can ask to see, correct, delete or receive a copy of your data, and object to or restrict its use, by writing to hello@posa-app.com. You can also complain to your data protection authority; in Italy, the Garante per la protezione dei dati personali (garanteprivacy.it).

Children

posa is not meant for anyone under 14.