Current policyv1

Privacy Policy

Published
Effective

Dates use Japan Standard Time (JST).

2shot.io helps people exchange photos taken together in person and revisit those encounters. This Policy explains how personal information is collected, used, shared, and retained through the 2shot.io website and progressive web app (the “Service”), and the choices available to you. It also covers information about people who receive photos without an account or appear in photos taken by other users.

This Policy distinguishes current information handling from planned features. Features marked “planned” are not yet available. Their introduction will be announced separately, with any consent or other procedures required by law.

1. Operator and contact

The Service is operated by an individual. The individual operating the Service (the “Operator”) is responsible for its handling of personal information.

The Operator will provide their legal name and address without delay to individuals requesting this information through the contact above, in accordance with Article 32 of Japan’s Act on the Protection of Personal Information (“APPI”).

2. Information collected and its purposes

CategoryInformationMain purposes
Account and profileEmail address, user ID, display name, profile image URL, registration and update dates, authentication informationAccount creation, authentication, profile display, account management
Google sign-inIdentifiers, email address, name or display name, profile image, and other basic profile information authorized during sign-inSign-in, account creation and linking, initial profile setup
Photos and exchange historyUploaded photos, links to the photographer and recipients, capture and receipt times, photo counts, recipient counts, receipt links and tokens, sharing statusStoring, delivering, and displaying photos; identifying exchange connections; providing the timeline; planned activity display of photo-taking times and counts and photo visibility settings
Guest receiptPhoto association, reserved recipient slot, token and expiry for linking a photo to an accountDisplaying photos before sign-in and linking them to an account after sign-in
Optional locationLatitude and longitude supplied by the browser, and the resulting place labelRecording a place with a photo so it can be revisited
EventsEvent name and dates, organizer and participant associations, join codes, joining times, photo-sharing status and the time that setting was recordedCreating and joining events, displaying event photos, providing photos to organizers (including for payment), organizer-controlled venue slideshows
Connection and operational informationIP address, browser and device information, requested URLs, access times, authentication and processing results, errorsCommunication, authentication, troubleshooting, preventing misuse, reliable operation
InquiriesReply address, inquiry or request contents, information supplied to identify the relevant account or photo, response recordsHandling inquiries, complaints, and rights requests; necessary fact-checking

Google sign-in is the normal sign-in method in production. The Operator does not receive your Google account password. If you use email and password authentication, those credentials are handled for authentication.

Your Google name may become your initial display name in the Service. If you do not want to display your real name, check and change your display name in account settings before exchanging photos.

The Operator also uses information as necessary to meet legal obligations, address infringements of rights, and resolve disputes.

3. Camera, location, and processing on your device

Camera

Taking a photo requires browser permission to use your camera. The preview is displayed on your device, and the still image generated when you take a photo is uploaded. The Service does not record audio or stream your camera feed. It currently has no feature that reads your device’s photo library or contacts.

Location

When you open the camera screen, the Service requests your current location subject to your browser’s permission. If permission has been remembered, your location may be obtained on later visits without another prompt. You can take photos without allowing location access.

The Service’s server rounds latitude and longitude to two decimal places before sending them to the OpenStreetMap Foundation’s Nominatim service to obtain a place label. Photos, names, email addresses, and user IDs are not sent to this place-lookup service. This happens before you take a photo and can therefore occur even if you leave without taking one. If you save a photo, the available coordinates before rounding and the place label are stored with it. Coordinates may be stored even if the place lookup fails.

The information stored is not limited to a place label. It includes coordinates that may identify a precise location. Location information, including coordinates, is sent to the devices of the photographer and recipients who can view the photo details. Even when coordinate numbers are not displayed on screen, sharing is not limited to the place label.

This feature does not continuously track your movements in the background. To stop future collection, disable location access for the site in your browser or operating system. Changing permission does not delete locations already saved; contact the privacy address if you want them removed.

Processing on your device

The effect that speeds up photo development when you shake a supported device processes motion readings on your device. Those readings are not sent to or stored on a server. Collages are also generated on your device and are not automatically uploaded to the Service.

4. Information displayed or shared with others

Profiles and photo receipt

Profile information such as display names is used for photo exchanges and the timeline and may be accessed by other signed-in users. Email addresses are not published as display fields in photos or the timeline.

Photos are displayed to their photographer and recipients. Guests can receive, view, and save photos through valid receipt links. If a receipt link or QR code reaches someone else, that person may be able to receive or view the photo. Check whom you share these links with.

Current timeline

The photographer and recipients whose accounts are linked to the same photo are treated as exchange connections with one another. The current timeline shows photos enabled for timeline sharing that have been received by an account holder, where the viewer is not a participant and at least two of the viewer’s exchange connections participate. The photographer does not have to be the viewer’s exchange connection, and unfamiliar people may also appear in a photo.

Photos in the current timeline are not blurred. Photo-taking times, exchange connections’ display names, and participant counts may also be displayed. New photos taken using the current camera feature are enabled for timeline sharing. Existing photos excluded from timeline sharing are not automatically enabled. There is not yet a screen for users to change photo sharing. Contact the privacy address to request that sharing stop.

Eligibility is determined using exchange connections at the time of viewing, so new connections may make past photos enabled for sharing visible. Exchange history from photos excluded from timeline sharing also identifies connections. Guest recipients are included after linking a photo to an account. Timeline responses do not include stored location information or receipt tokens.

Planned: activity display, blurred previews, and photographer-controlled visibility

The following describes features planned for a future update. These rules do not yet apply to the current timeline. Present-tense descriptions below, such as “displays” and “can change,” explain how the features will work after introduction.

The photographer and recipients whose accounts are linked to the same photo are treated as exchange connections with one another. These connections are derived from exchange history, not contact imports or facial recognition.

The timeline displays activity information, including a photographer’s display name, photo-taking times, and photo counts, to that photographer’s exchange connections. Photo previews are blurred by default. Photo-taking times and counts remain visible to exchange connections even when the photo itself is not shared on the timeline. There is no ordinary setting to turn off activity display alone. Blurring does not hide who took photos, when, or how many.

The photographer can change timeline visibility for each photo. When the photographer enables sharing, their exchange connections, including those who did not receive the photo, can view it without blurring. This setting shares the photo with the photographer’s exchange connections, not with all users or the public internet. Recipients do not have a feature to change the photographer’s visibility setting, but can contact the privacy address to request that display of a photo of themselves stop or to raise other concerns.

Making a photo private on the timeline does not stop the photographer or recipients from viewing the original photo or stop event-organizer sharing under its separate setting. Exchange history is used to identify exchange connections regardless of the photo’s visibility setting. Guest recipients are included after linking a photo to an account.

Before introducing the feature, the Operator will explain which past activity is included and what history newly established exchange connections can see. Publishing this Policy alone does not expand the audience for existing photos or activity.

Timeline responses do not include stored location information or receipt tokens. However, a photo’s contents may reveal a location or who was together. Contact the privacy address with concerns about information handling, including activity display, or to make legally available requests to stop use or delete information.

Event organizers and venue displays

In event mode, the camera setting indicating that the photo will also be shared with the organizer is initially ON. You can switch it OFF before taking the photo. If it remains ON, the organizer can view the photo and show it on a venue screen before anyone completes receipt. People at the venue may see it without having a Service account.

For photos with organizer sharing enabled, the organizer may also be able to access associated location information, including coordinates.

The Operator provides event organizers with photos designated for organizer sharing. The Operator may receive payment from the event organizer for this provision. Whether paid or free, the recipient, photos and associated information, purposes, and scope of display and storage will be explained in advance, and information will be provided within the scope of consent required by law.

The current organizer features allow viewing photos and displaying them on venue screens. If features such as organizer downloads or distribution to participants are introduced, their scope will be explained in advance and any required consent obtained. Organizer sharing or paid provision alone does not grant blanket permission for publication on an organizer’s social media, advertising or publicity, or further disclosure to sponsors or others. Such uses will be explained separately from ordinary event sharing, and necessary permissions and consent obtained.

Joining an event does not by itself give participants access to all other participants’ photos. Organizer sharing and timeline sharing are separate; stopping one does not necessarily stop the other. An event ending does not by itself end organizer access or the slideshow.

There is currently no screen for users to revoke organizer sharing after taking a photo. Contact the privacy address to request that display stop.

Saving and external sharing

Users can save photos or collages to their devices and send them to other services using device sharing features. Settings changes or deletion within the Service cannot retrieve screenshots or copies saved elsewhere.

Checks before sharing and the Operator’s response

Users who take or share photos are responsible for explaining the intended use and audience to people pictured and other rights holders and obtaining any necessary consent and permissions before sharing. When a photographer expands the audience, they must also make the necessary checks for that scope. Agreeing to be photographed or receiving a photo alone is not treated as agreeing to a later expansion of its audience.

The Operator handles information according to the display rules and visibility settings described in this Policy and fulfills its obligations under applicable law. Requiring users to make checks before sharing does not exempt the Operator from its own responsibilities. People without accounts can also contact the Operator about photos of themselves. The Operator will review the relevant facts and address deletion, cessation of display, and other requests in accordance with applicable law.

5. External services and disclosures

The Service uses the following external services. Where the Operator entrusts processing to a provider, information is limited to what is needed for that work and appropriate handling is required. External services such as Google sign-in and place lookup may also process information under their own policies.

ServicePurposeMain information handled
SupabaseAuthentication, database, photo storage and deliveryAccounts, photos, locations, exchange and event information, authentication records
VercelWebsite hosting, server processing, delivery, troubleshootingConnection information such as IP addresses, request and error records, photos and locations passing through server processing
GoogleGoogle account sign-inSign-in requests, authentication information, authorized basic profile information
ResendAccount-related email deliveryRecipient addresses, email contents and authentication links, delivery records
OpenStreetMap Foundation / NominatimConverting coordinates to place labelsCoordinates rounded to two decimal places, lookup requests, connection information from the Service’s server

In addition to the sharing described in Section 4, necessary information may be disclosed with your consent, when required by law, or where otherwise permitted by law, including to protect a person’s life, physical safety, or property.

Provision to event organizers under Section 4 may be paid. Receiving payment does not allow information to be provided beyond the scope explained and consented to.

The Operator does not currently use users’ photos as the Operator’s advertising material, to infer interests or attributes for advertising, to identify people through facial recognition, or to train AI models. Before introducing such uses, the Operator will explain the information involved, purposes, recipients, and other relevant details and obtain necessary permissions and consent. This Policy does not seek blanket consent for such uses. If you send photos to another service yourself, consult that service’s policy for its practices.

6. Processing outside Japan

The Service primarily serves users in Japan, but external services may store or process information outside Japan. Even when a server is located in Japan, support access or log processing may occur abroad.

ServiceStorage, processing locations, and activities
SupabaseThe primary storage location for accounts, photos, and related data is Japan (Tokyo region). The provider is Supabase Pte. Ltd. in Singapore; support and other operations by affiliates and subprocessors may take place abroad. Data processing terms
VercelA US provider. The Service specifies Tokyo for its main server processing, but delivery, connection records, support, and related operations may also take place abroad, including in the United States. Privacy information
ResendRecipient addresses, email contents and authentication links, delivery records, and related information are stored in the United States. Selecting Tokyo as the sending region does not move storage to Japan. Storage explanation
GoogleInformation involved in Google sign-in may be processed on servers around the world, including in the United States. Data transfer explanation
OpenStreetMap Foundation / NominatimFor information such as place-lookup requests, the Foundation describes storage in the United Kingdom and the Netherlands, with backups in the EU. Storage explanation

A provider’s country of establishment is not necessarily where data is stored or processed. Locations may vary with delivery routes, support, and subprocessors; all processing is not confined to one country.

The Operator reviews contractual terms and safeguards for overseas processing and uses measures such as limiting the information transmitted, encrypted connections, and access restrictions. The Operator will provide information, obtain consent, and take other measures required by applicable law for disclosures to third parties outside Japan. When relying on contractual or other measures equivalent to those required under the APPI, the Operator periodically checks their implementation and any legal framework that could affect their continuity, and takes measures such as stopping provision if they can no longer be maintained. Contact the privacy address for an explanation of processing countries, their legal frameworks, and safeguards.

7. Retention and deletion

InformationRetention and deletion
Photos with no recipient linked to an accountThe receipt deadline is 24 hours after capture. After expiry, a daily cleanup deletes the photo file and associated records. This normally occurs within about 48 hours of capture, but failures can cause delays. It does not mean complete erasure at exactly 24 hours.
Photos received by at least one account-linked recipientRetained for continued access to the shared memory. There is currently no automatic deletion after a fixed number of days. Locations and exchange history are retained with the photo.
Guest receipt recordsTokens are valid until the receipt deadline. A record is deleted after successful account linking. Unused expired records are deleted by a daily cleanup, regardless of whether the photo itself is retained. Failures can cause delays.
Account and event informationRetained while necessary to provide the Service. Account closure and deletion requests are handled as described below.
Inquiry and request recordsRetained to handle requests and verify relevant facts. After handling is complete, information is deleted as it ceases to be needed. Identity-verification materials are deleted after verification once no longer needed.
Connection, authentication, and error logsRetained for service operation, troubleshooting, and preventing misuse under each provider’s contract, plan, and retention settings, and deleted or rotated as those retention periods end. Records extracted by the Operator for a specific investigation are deleted when no longer needed for that investigation or response.
Backups and temporary delivery copiesCopies for recovery or delivery may remain under each provider’s retention and rotation cycles or cache expiry settings. Erasure may occur later than deletion in the primary system; all copies are not necessarily erased immediately.

Guest receipt alone does not count as account-linked receipt. However, if someone else links the same photo to an account, the photo is retained.

Sharing with an event organizer alone does not count as account-linked receipt. Event photos currently follow the same receipt deadline and retention conditions in the table. If services with separate organizer retention periods or storage limits are introduced, those conditions and how changes will be handled will be explained in advance.

Contact the privacy address for account closure, photo deletion, or location deletion. Removing or replacing profile information on account closure is separate from deleting a shared photo. Photos may remain for other participants, and removing or changing a profile name does not remove a face from a photo. The Operator will consider the request, other people’s rights, and legal obligations and take necessary action to delete information or stop display. Retaining shared memories for other participants does not override legally required erasure or cessation of disclosure.

Hiding an item from a list, stopping sharing, closing an account, and completely deleting data are different actions. There are currently no dedicated self-service screens for hiding photos, closing accounts, or exporting account data.

Photo access URLs are generally valid for 15 minutes after issue. An already-issued URL may continue to work until it expires after sharing is stopped. Copies already saved by other users are outside the Operator’s control.

If additional retention is necessary for legal compliance, a specific investigation of misuse, or a dispute, it is limited to information needed for that purpose. Information that is no longer needed is deleted or otherwise appropriately handled.

8. Cookies, similar technologies, and advertising

The Service uses cookies, browser storage, and caches for sign-in sessions, authentication, language preferences, remembering the selected event, interface settings, and PWA functionality.

The Service may display advertisements or sponsorship messages that are not selected based on users’ behavioral history or interests. It currently has no system for advertising targeted on that basis, tracking users across sites for advertising, or recording interaction sessions.

Before introducing external services for advertising, measurement, or usage analytics, the Operator will review the information actually collected or transmitted, whether or not targeting is involved, and explain the recipients, information types, purposes, and other relevant details in this Policy or related notices. Information will be provided and consent obtained as required by applicable law.

If advertising based on behavioral history or interests is introduced, users will be able to allow or reject it through a banner or similar interface. Collection, use, and external transmission for that purpose will begin only after consent. A way to withdraw consent later will also be provided.

You can delete cookies and site data through browser settings. Doing so can remove your session or settings and affect functionality. Deleting data on your device does not delete accounts or photos on the server.

9. Safeguards and Operator access

The Service uses encrypted connections, authentication and authorization checks, private photo storage, and time-limited access URLs to protect information. Administrative privileges are used as necessary to provide and manage the Service.

The Service does not use end-to-end encryption that prevents the Operator from decrypting or viewing photos. The Operator may inspect photos and related information when needed to handle inquiries, address infringements of rights, troubleshoot issues, or meet legal obligations. Access and use unrelated to those purposes are not permitted.

In the event of a data breach or similar incident, the Operator will address containment, investigation, and prevention of recurrence and make reports and notify affected individuals as required by law.

10. Requests concerning your information

Under the APPI and other applicable laws, you may request notification of purposes of use; disclosure of your information or third-party provision records; correction, addition, or deletion; cessation of use or erasure; and cessation of provision to third parties. The contact also accepts account-data export requests and concerns about photos.

Email privacy@2shot.io with the action you want and enough information to identify the relevant account or photo, where known. Requests from people without accounts and authorized representatives are also accepted. Do not send passwords or active receipt tokens.

To avoid disclosing information to someone else, the Operator will use verification proportionate to the request, such as confirmation through a registered email address, and verify representative authority where needed. Requests for Operator details are handled separately from requests for personal photos or other personal data.

Requests are handled without delay as required by law. You will be informed if verification takes additional time. If a request cannot be granted or a different measure is taken, the Operator will explain why.

There is no fee for inquiries or requests under this section, or for requesting the Operator’s name and address.

11. Use by minors

The Service is not intended for children under 13.

If you are a minor and are unsure whether you understand this Policy, particularly who can receive your photos or location information, review it with a parent, guardian, or another trusted adult before using the Service.

Where applicable law requires consent from a parent or other legal guardian for the handling of personal information, obtain that consent. Parents and guardians concerned about their child’s information can contact the privacy address. The Operator will review the relevant facts and respond appropriately.

A child under 13 appearing in a photo is different from that child using the Service. When taking or sharing photos of children, explain the use to their parent or guardian and obtain consent where needed. Concerns about photos of children are accepted regardless of age or whether they have an account.

12. Changes and languages

This Policy will be updated when the Service or its information practices change. Material changes will be communicated through an appropriate method, such as a notice in the Service, and prior consent will be obtained where legally required. Publication of this Policy or continued use alone is not treated as providing any separately required consent.

This Policy is available in Japanese and English. The English version explains the same practices as the Japanese version and does not limit your legal rights. Translation discrepancies will be reviewed and corrected.