Legal
Privacy Policy
Last updated 1 September 2026
The short version. TableCam stores the photographs your guests take and copies them into your own Google Photos library. We do not sell your data, do not use photographs to train machine learning models, and run no advertising or third-party tracking. We can only see the photographs our own app created in your Google Photos — never the rest of your library.
1Who we are
TableCam (“we”, “us”) is operated by [LEGAL ENTITY NAME]. This policy explains what we collect when you use tablecam.party, why, and what control you have over it. It sits alongside our Terms of Service.
2What we collect from hosts
- Your email address, used to sign you in and to contact you about your events.
- Your name and profile picture, only if you choose to sign in with Google.
- Event settings you create: event name, dates, guest and photo limits, colours, header image and the instructions shown to guests.
- Your Google connection, if you connect one: the Google account’s email address and identifier, and an encrypted token that lets us add photographs to your library.
3What we collect from guests
Guests never create an account and are never asked for an email address, phone number or password. When someone scans an event code we create an anonymous session so their device can be recognised across page loads, and we store:
- a display name, only if they choose to type one — it may be left blank;
- the photographs they take through the app;
- basic photo details: when the shutter was pressed, image dimensions and file size, and how many photographs they have taken against their limit.
Photographs are taken through the browser camera and re-encoded before upload. That process removes EXIF metadata, so GPS coordinates, device identifiers and camera settings are not collected or stored.
While a photograph is waiting to upload it is held in the guest’s own browser storage on their device, so a poor connection does not lose it. That copy is removed once the upload succeeds.
4Google user data
Connecting a Google account is optional and separate from signing in. If you connect one, we request only these permissions:
photoslibrary.appendonly
Create a TableCam album in your library and add your event's photographs to it. This is the core purpose of the connection.
photoslibrary.readonly.appcreateddata
Read back only the media our own app created, so the dashboard can confirm a photograph actually arrived. It does not give us access to any other photo or album in your library.
openid, userinfo.email
Identify which Google account is connected, so you can tell them apart and disconnect the right one.
We cannot browse, search, download or delete the photographs already in your Google Photos library. The permissions above do not allow it.
TableCam’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not use Google user data for advertising, do not sell it, do not transfer it to third parties except as needed to provide the service or where required by law, and do not use it to train machine learning or artificial intelligence models. Human access is limited to what is necessary for security, to fix a fault, or where you have asked us for support.
5How we protect it
- Your Google refresh token is encrypted with AES-256-GCM before it is written to the database. The encryption key is held separately from the stored data, so a copy of the database alone does not grant access to anyone’s Google account.
- Photographs live in a private store. They are never publicly listable and are shown only through links that expire after a short period.
- Access is enforced by database-level security rules, not application code, so a guest can only ever reach their own photographs and — once the host releases the album — that event’s photographs.
- All traffic is served over HTTPS.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your data we will notify you promptly.
6Who else is involved
We use a small number of providers to run the service:
- Supabase — database, authentication and photo storage, hosted in the United States.
- Google — only where you have connected a Google account, to store photographs in your library.
- Cloudflare — network and delivery.
We do not sell personal information, and we run no advertising networks, tracking pixels or third-party analytics on this site.
7How long we keep things
- Photographs are kept for as long as the event exists. Deleting an event removes its records immediately; stored image files are deleted on a short delay so an accidental deletion can be recovered.
- Your Google token is deleted as soon as you disconnect the account, and we ask Google to revoke it at the same time.
- Host accounts are kept until you ask us to delete them.
Photographs already copied into a host’s Google Photos library, downloaded, or shared elsewhere are outside our control. Deleting them from TableCam does not remove those copies — they must be removed where they now live.
8Your choices and rights
Depending on where you live you may have rights to access, correct, export or delete the personal information we hold, to object to or restrict how we use it, and to withdraw consent. We honour these requests regardless of where you live.
- Hosts can delete events and photographs from the dashboard, and disconnect Google at any time. You can also revoke our access from your Google account security settings.
- Guests who want a photograph of them removed should ask the event host, who can remove it directly. If you cannot reach them, contact us at [email protected] and we will help.
For anything else, write to [email protected]. We will respond within a reasonable period, and within any timeframe the law requires.
9Children
TableCam is not directed at children and we do not knowingly create accounts for anyone under 13. Children may of course appear in photographs taken at an event; the host is responsible for obtaining any consent required before photographing them. If you believe we hold information about a child that should be removed, contact us at[email protected] and we will delete it.
10International transfers
Our infrastructure is located in the United States. If you use TableCam from elsewhere, your information will be transferred to and processed there, which may have different data protection laws than your own country.
11Changes to this policy
We may update this policy. The date at the top of this page always reflects the current version, and for material changes we will make reasonable efforts to notify hosts directly.
12Contact
Questions about privacy, or a request about your data, can be sent to [email protected].