Privacy Policy
Last updated: July 13, 2026
This policy covers https://recap.camera, the Recap iOS app, the Recap Live Activity extension, and the Recap App Clip when available (together, “Recap,” “we,” or “the Service”).
Megogigo LLC operates Recap. We collect only what we need to run the Service, and we do not sell your personal information for advertising.
1) Data we collect
Account and identifiers
- Email address - when you sign in with Apple or Google (Apple may provide a private relay address)
- Display name - from your profile; on first Apple sign-in, from the credential Apple shares once; on Google sign-in, from the verified Google ID token
- Social login identifiers - Apple or Google provider user IDs stored on our servers to recognize your account across sessions
- Recap user ID - our internal account identifier
- API session token - issued after sign-in, stored in the iOS Keychain on your device
- Apple user identifier - stored locally in the Keychain to detect revoked Sign in with Apple credentials
- How you heard about Recap - optional one-time choice during profile setup (for example App Store, Instagram, TikTok, Google, Reddit, X, or Other)
User content
- Photos you upload - full-resolution images (re-encoded before upload, which typically removes embedded metadata such as GPS) and generated thumbnails stored on our cloud storage
- Event details you create or join - title, type, cover image, invite code, guest and photo limits, photo availability rules, start and end times, and upload permissions
- Event membership - which events you created or joined and when you joined
- Invite links and QR codes - generated from your event invite codes; you may save QR images to your photo library or copy invite codes to the clipboard
Purchases
- In-app purchase activity - product identifiers, purchase amounts, currency, and entitlement status validated through RevenueCat and Apple App Store on your device
- Purchase analytics - purchase events sent to PostHog and Meta (Facebook) App Events for product measurement (not for third-party ads in Recap)
- Recap’s servers do not store Apple receipts; guest-capacity entitlements are enforced via RevenueCat on your device
Push notifications
When you enable notifications, we collect and store:
- APNs device token (encrypted on our servers)
- App install device ID - a random UUID generated on your device
- Platform, bundle ID, app version, and environment (
sandboxorproduction) - Notification preference - whether backend delivery is enabled for that install
We send push alerts for events such as new photos in an event or a guest joining your event. Push payloads may include event and photo identifiers, participant display names, and deep-link URLs.
Usage and diagnostics
- Product analytics via PostHog, including sign-in/out, onboarding, profile setup, event creation and joining, photo capture and upload, paywall and purchase steps, profile updates, and share actions
- User properties in PostHog when signed in - Recap user ID, display name, email (if available), platform, and last auth provider
- App lifecycle events - PostHog captures standard application lifecycle events (session replay is not enabled)
- Meta (Facebook) App Events - automatic app events and explicit purchase logging; advertiser identifier collection is enabled in the SDK configuration and may use advertising-related identifiers when permitted by your device settings
- Device and app context - operating system, app version, and general device characteristics included in analytics and API requests
- Server logs - authentication, uploads, notifications, and operational diagnostics (may include IP address and request metadata)
Website and invite pages
- Invite lookup - visiting or scanning
https://recap.camera/join/{CODE}may show public event preview information (such as event name, cover image, guest count, and photo count) before you sign in - Public event lookup API - returns event metadata for a valid invite code without authentication
- Rate limiting - anonymous and authenticated invite lookups are rate-limited using your IP address or account identifier
- Standard web server logs - IP address, user agent, and request path for pages served at recap.camera
Camera and photos (on-device permissions)
- Camera - used when you capture a photo or scan an event QR code
- Photo library (read) - used only when you choose photos to upload or select a cover image
- Photo library (add) - used only when you save a QR code or save a photo to your library
- Permissions require your device OS approval and are not used in the background for these features
Live Activities
Live Activities may show event status on your Lock Screen or Dynamic Island while an event is active. This information is displayed on-device; the app may refresh counts from our servers while the activity is visible.
Local storage on your device
Recap stores data locally to improve performance and keep you signed in:
- Keychain - API token, Apple user identifier, and cached profile fields
- UserDefaults - onboarding completion, notification settings, photo grid preference, and push registration data
- Caches - API responses and downloaded event/photo images
- Google Sign-In session - maintained by the Google Sign-In SDK until you sign out
2) How we use data
We use collected data to:
- Provide and operate the Service (accounts, events, invites, photo upload and viewing, notifications)
- Authenticate you via Apple and Google and maintain secure API sessions
- Process in-app purchases and apply guest-capacity entitlements
- Deliver push notifications you opt into
- Measure product usage, reliability, and conversion (PostHog and Meta App Events)
- Prevent abuse (rate limits, fraud prevention, support)
- Comply with law and enforce our Terms
Legal bases (EEA/UK): performance of a contract, legitimate interests (security, analytics, product improvement), consent where required (notifications, tracking-related SDK behavior), and legal obligation.
We do not sell personal information or use Recap to build cross-app advertising profiles.
3) How we share data
We do not sell personal information.
Within an event
- Event details and photos are visible to participants who joined that event according to its settings
- Your display name may be shown to other participants (for example on uploaded photos and join notifications)
Public invite previews
- Anyone with an invite link, QR code, or invite code may see limited preview information on recap.camera before joining
Service providers (processors)
| Provider | Purpose |
|---|---|
| Laravel Cloud / hosting infrastructure | API, web pages, database, queues |
| Amazon Web Services (S3) | Photo and event image storage |
| Apple Push Notification service (APNs) | Delivering push notifications |
| Apple Sign in with Apple | Authentication |
| Google Sign-In | Authentication |
| RevenueCat | Purchase validation and entitlements |
| PostHog | Product analytics |
| Meta (Facebook SDK) | App event and purchase measurement |
| Apple App Store / StoreKit | Payment processing |
Providers access data only to perform services for us and must protect it under their terms and applicable law.
Legal and safety
We may disclose information if required by law, to protect users and the Service, or in connection with a merger or acquisition (with notice when legally required).
4) Data retention
- Account data: kept while your account is active
- Deleted accounts: we aim to remove personal data within 30 days of a verified deletion request
- Photos: kept until the event is deleted, the photo is deleted, or your account is closed subject to the notes below
- If you delete your account: photos you uploaded to others’ events may remain in those events; we will anonymize your attribution where feasible
- Push tokens: revoked when you disable notifications, log out, or delete your account
- Purchase records: handled by Apple and RevenueCat under their retention policies
- Aggregated or anonymized analytics may be kept longer
- Local caches on your device persist until cleared by the app, OS, or uninstall
5) Security
- Encryption in transit (HTTPS/TLS) for API and web traffic
- Encryption at rest for sensitive server fields (including APNs tokens) and via our cloud vendors
- Access controls on production systems
No security method is perfect. We cannot guarantee absolute security.
If a breach involves your personal data, we will notify you and regulators when legally required.
6) Your choices and rights
In-app controls
- Profile: update your display name in Settings
- Push notifications: manage in Recap Settings and in iOS Settings → Recap
- Photo library and camera: manage in iOS Settings → Recap
- Sign out: Settings → Log Out (revokes the current API token on the server)
- Tracking: manage App Tracking Transparency in iOS Settings when available for your OS version
Account deletion
You can delete your account and associated personal data in Recap by going to Settings, tapping your name, selecting Delete my data, and confirming the deletion. We will process deletion within 30 days, subject to legal retention requirements.
Recap’s guest-capacity purchases are consumable in-app purchases, not subscriptions, so there is no recurring subscription to cancel when you delete your account.
Other requests
Contact info@recap.camera to access, correct, export, or object to processing of your personal data. We may retain limited data to meet legal requirements, prevent abuse, or maintain backups.
Region-specific rights
- California (CCPA/CPRA): right to know, delete, correct, and opt out of sale/share (we do not sell or share for cross-context behavioral advertising); no discrimination for exercising rights
- EEA/UK (GDPR): rights to access, rectification, erasure, portability, objection, and restriction; you may lodge a complaint with your local supervisory authority
- India (DPDP): rights to access, correction, erasure, and grievance redressal via info@recap.camera
7) Children
Recap is not for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided data, contact info@recap.camera and we will delete it.
8) International transfers
We operate primarily in the United States. Your data may be processed in the U.S. and other countries where our providers operate. Where required, we use appropriate safeguards for international transfers.
9) App Clip notes
When the Recap App Clip is available, it uses minimal data to let guests preview and join an event and upload photos with your permission. It uses camera and network access only while in use and follows this policy.
10) Changes to this policy
We will update this page when we change the policy and will notify you of material changes in-app or by email when appropriate. Continued use after changes take effect means you accept the updated policy.
11) Contact
Megogigo LLC
Email: info@recap.camera