PicToFuStart Booth ✦

Privacy at PicToFu

Privacy Policy

PicToFu is designed so the core photobooth can work without an account and without uploading your captured or device-selected photos to a PicToFu photo server.

Last updated: September 12, 2026

Your photos stay with you.

In the current PicToFu service, camera frames, captured shots, photos you select from your device, filters, strip composition, and PNG export are processed in your browser. PicToFu does not maintain a cloud photo gallery or account-based photo history.

1. Scope

This policy describes the privacy practices for the PicToFu website and browser-based photobooth. It covers the current public service and the analytics services described below. If PicToFu later adds accounts, cloud photo storage, payments, advertising, or other material data processing, this policy will be updated before those features are treated as part of the normal service.

2. Camera, local uploads, and photo processing

PicToFu asks your browser for camera permission only when a camera experience needs it. Your browser and operating system control that permission. You can deny or revoke camera access through your browser or device settings. You can also choose existing photos from your device without enabling the camera.

In the current service, captured image bytes, device-selected photo files, and the final composed photo strip stay in browser memory while you use the booth. Local photo selection uses browser object URLs so the selected images can be previewed and cropped without a PicToFu media-upload request. PicToFu does not intentionally transmit captured or selected photos, camera frames, Blob URLs, base64 image data, or the generated PNG to analytics providers. If you download or share an image, the resulting file is handled by your browser, device, or the destination you choose.

3. Information we may process

PicToFu may process limited technical and usage information needed to operate, secure, and understand the site. Depending on the measurement service, your region, and your analytics choice, this can include page paths, bounded acquisition labels, device class, referrer category, cohort date, and product interaction stages such as starting the booth or completing an export.

Product measurement uses small, structured fields. It must not include your photo content, camera frames, exported image bytes, Blob URLs, base64 data, filenames, or free-form text taken from your images.

4. Analytics and product measurement

Vercel Web Analytics

PicToFu uses Vercel Web Analytics for aggregated website traffic measurement, such as page visits and general traffic context provided by the hosting analytics service. This is separate from the PicToFu product-funnel counters described below.

Privacy-minimized product funnel counters

PicToFu records privacy-minimized daily funnel counters so we can understand whether visitors reach stages such as landing, opening the booth, granting camera access, completing capture or local photo selection, exporting, downloading, or sharing. These counters are aggregated by bounded dimensions such as page path, preset, device class, referrer category, and campaign labels such as UTM source/content.

The aggregate growth store does not store a PicToFu user ID, analytics session ID, IP address, photo media, filenames, or free-form text. The browser uses session storage only to avoid counting the same funnel stage repeatedly during one browser session; that session marker is not included in the aggregate payload. PicToFu's current aggregate counter infrastructure is hosted with Supabase.

Optional first-party rolling retention

If you explicitly choose Allow analytics, PicToFu can store a small first-party cohort record in local browser storage so we can estimate whether the same browser profile returns after one, seven, or thirty days. The record contains the cohort date, bounded first-touch acquisition context, device class, and which rolling retention milestones have already been counted. It does not contain a PicToFu user ID, analytics session ID, fingerprint, photo media, or free-form text.

The server receives only aggregate cohort dimensions and a bucket such as new browser, rolling D1, rolling D7, or rolling D30. For this measurement, D7 means the browser returned seven or more days after the cohort date, and D30 means it returned thirty or more days after the cohort date. The aggregate retention store does not receive the browser-local cohort record itself or any identifier that lets PicToFu reconstruct a person-level visit history.

Google Analytics 4

Google Analytics 4 (GA4) is additional measurement and is not required for the photobooth to function. When GA4 is configured, PicToFu uses Google Consent Mode with regional analytics-storage defaults. Analytics storage stays denied by default for visitors in the European Economic Area, the United Kingdom, and Switzerland. For visitors outside those regions, analytics storage may default to granted so PicToFu can obtain standard first-party GA4 measurement unless the browser has a saved denied choice.

When analytics storage is denied, Google Analytics cookies are not read or written, but Google can receive limited cookieless measurement pings for basic measurement and modeling. When analytics storage is granted by a regional default or an explicit choice, GA4 may use first-party analytics cookies such as _ga, along with page views and structured product events. PicToFu keeps advertising storage, ad user data, ad personalization, Google signals, and ad-personalization signals disabled in the current setup. PicToFu also strips its internal analytics session marker and event timestamp before forwarding structured product events to Google, and page-view URLs sent by PicToFu omit query strings.

You can reopen PicToFu's Privacy settings and explicitly allow analytics or switch this browser to cookieless mode. A saved explicit choice overrides the regional default on later visits. If a previously granted choice is revoked, PicToFu clears the browser-local retention cohort record, updates Google Consent Mode back to analytics-storage denied, clears accessible GA cookies, and continues only with the storage-denied measurement behavior described above.

5. Cookies and local browser storage

The core PicToFu booth does not require an account cookie or a cloud photo-session cookie. PicToFu stores an explicit analytics choice in first-party browser storage so it can override the regional default on later visits. When analytics storage is permitted by the applicable regional default or by an explicit allow choice, GA4 may set first-party analytics cookies. PicToFu's separate browser-local D1/D7/D30 retention cohort is created only after an explicit Allow analytics choice. When analytics storage is explicitly denied, PicToFu keeps GA4 in storage-denied Consent Mode and clears accessible GA analytics cookies.

The browser-local acquisition context and one-per-session growth-stage markers are kept in session storage and contain no photo media. PicToFu's internal analytics session marker is not included in the aggregate growth or retention payloads and is stripped before structured product events are forwarded to Google Analytics.

6. Third-party infrastructure

PicToFu uses third-party infrastructure to deliver and understand the website. Vercel hosts and serves the application and may provide aggregated traffic analytics. Supabase hosts the privacy-minimized daily product-funnel counters and aggregate retention counters. Google Analytics may provide additional acquisition and product measurement using region-aware Consent Mode; GA analytics storage can be enabled by the applicable regional default or by an explicit allow choice, while PicToFu's browser-local rolling retention requires an explicit allow choice.

PicToFu does not authorize these measurement services to receive captured or device-selected photo bytes as part of the current analytics contract.

7. Data retention

PicToFu does not maintain a server-side library of your captured or device-selected photos in the current service. Temporary browser objects used during a booth session are intended to disappear when the page/session is cleared, while files you choose to download remain under your control on your device.

The PicToFu growth and retention stores retain aggregate counts rather than user/session event histories. If you explicitly allow analytics, the browser-local retention cohort record can remain in local storage so later D1/D7/D30 returns can be counted once; it is removed when you turn analytics off or when you clear the relevant browser storage. Other aggregated analytics data, when enabled by the applicable regional default or your explicit choice, is retained according to the configured provider and PicToFu's account settings with that provider. PicToFu does not use analytics retention to reconstruct or store your photo content.

8. International processing

PicToFu is available over the internet and may rely on service providers that operate infrastructure in multiple countries. As a result, limited technical or analytics information may be processed outside the country where you are located, subject to the safeguards and terms offered by the relevant provider.

9. Your privacy choices and rights

Depending on where you live, privacy law may give you rights concerning personal information, which can include access, correction, deletion, restriction, objection, portability, or withdrawal of consent. PicToFu currently has no user account or cloud photo library, so many requests involving photos can be resolved directly by clearing the browser session or deleting files you saved to your own device.

You can reopen the visible Privacy settings control to explicitly allow analytics storage or switch this browser to cookieless storage-denied mode. A saved explicit choice overrides the regional default. The preference and any PicToFu retention cohort marker are stored in your browser rather than in a PicToFu user account.

10. Children and minors

PicToFu is a general-audience creative tool and is not designed specifically for children. The current service does not ask users to create accounts or submit profile information. Parents or guardians should supervise camera, local photo selection, and sharing use where appropriate for the user's age and local requirements.

11. Changes to this policy

We may update this policy as PicToFu changes. Material additions such as cloud photo storage, accounts, payments, targeted advertising, or materially different analytics will require the policy to be reviewed and updated before those capabilities are treated as part of the normal production service. The date at the top of this page shows the latest revision.

12. Contact

For privacy questions or requests, email fxbin123@gmail.com. You can also use the PicToFu contact page for general questions and product feedback.

Because the current PicToFu service has no user account system or cloud photo library, please do not send photo content unless you intentionally choose to attach it and it is necessary to explain your request.