Last changed 1 August 2026
This describes what happens to information in Ahlchemy Snap — both the operator running a booth and the guests standing in front of it. It is written to be read rather than to be survived, and it describes what the software actually does.
Photographs stay on the tablet unless the operator switches on Collect by QR, and then they go to that operator's own storage — not ours. Face detection for props runs entirely on the device and nothing about a face is stored or sent anywhere. We do not use advertising trackers, and we do not sell anything about anybody.
Two different people are involved, and they carry different responsibilities.
| Who | What they are responsible for |
|---|---|
| The operator whoever runs the booth |
The photographs of their guests. They decide what is taken, whether it is uploaded, how long it is kept and who may see it. In data-protection terms they are the controller. |
| Ahlchemy Author Company us |
The software, the operator's own account, and the storage the operator has connected. We process what the operator's settings tell us to. |
If you were photographed at an event and want your picture removed, the operator of that booth is the person to ask. They can remove it, and we can help them if they need it.
A photograph taken by the booth is stored on the tablet that took it, in the browser's own storage. It stays there until the operator deletes it or clears the archive.
If the operator has turned on Collect by QR, each photograph is also uploaded so a guest can scan a code and keep their own copy. That upload goes to the operator's own Cloudflare R2 storage, under their own account. We do not hold a copy.
A guest link is unguessable rather than secret: anyone holding the link can open the photograph, the page is marked not to be indexed by search engines, and there is no way to list an event's photographs without a key the operator holds. Treat a link as something that can be shared, because guests will share it.
On the tablet, until the operator removes them.
In storage, until the retention rule expires them. We recommend 30 days and every operator is asked to set one. Guests collect within a day or two; keeping a wedding's photographs indefinitely is a liability rather than a feature.
The rule applies to everything perishable and nothing else — the photographs, the link that finds one from a code, and the list a second screen reads. An operator's layouts, frames and backgrounds are untouched by it.
Before that happens, an operator can take the whole event away in one file: Gallery → Download the album, which writes every photograph and a list of when each was taken. That file does not expire, and what they then do with it is theirs.
The props feature needs to know where a face is on the screen. This is worth being exact about:
Backgrounds work the same way: replacing a green cloth is arithmetic on the pixels in front of the camera, done on the device, with nothing sent anywhere and nothing kept.
Signing in uses Cloudflare Access, which emails a one-time code. We never see or store a password because there is not one. What we hold against an account:
An operator's own device settings — the operator code, the chosen camera, the upload token — stay on the device and are never backed up or sent.
A guest may ask for their own photograph to be sent to them. Nobody is asked to; the code beside the photograph does the same thing without giving anything away.
By email. The address is typed by the guest on the booth's screen, used once to send that photograph, and not written down. The message carries the picture itself as an attachment, and the moving picture with it where there is one, so it survives the link expiring.
By text. The mobile number is typed by the guest on the booth's screen, used once to send a link to that photograph, and not written down. One message per photograph. Every message says Reply STOP to opt out, and stopping is immediate and permanent for that number. Message and data rates may apply — those are between a guest and their own carrier and nothing to do with us.
No list is kept, and none is sold. There is no marketing, no newsletter, and no second message. An address or a number is used for the one photograph it was given for and then it is gone. The booth keeps a count of how many were sent in a day, and nothing else — not who to, not what was said.
Neither is offered unless whoever runs the booth has switched it on, and both need the photograph to have finished uploading, because that is where it is sent from.
If you send feedback from inside the app, we receive your message, the address you signed in with, which build the booth is running, the screen size and the browser. Nothing about your guests goes with it: no photographs, no addresses, not even the event's name.
The site and the software are served by Cloudflare. An operator's uploaded photographs and library live in Cloudflare R2 storage under that operator's own account, in the region they chose when they created it. Sign-in is handled by Cloudflare Access.
The booth is not aimed at children and we do not knowingly hold information about them from any source other than an operator photographing guests at their own event. Where children are photographed, the operator is responsible for having whatever permission their event and their jurisdiction require.
If this changes in a way that matters, operators will be told in the app before it takes effect, and the date at the top will change.
Use the feedback form in the app, or write to Ahlchemy Author Company at the address on the terms page.
This policy describes the software accurately, but it has not yet been reviewed by a lawyer. Photographing people creates obligations that vary sharply by place — several US states regulate anything touching facial data specifically, and the UK and EU treat photographs of identifiable people as personal data. Before charging for this, have somebody qualified read it against where you and your operators actually work.