PicTofuStart Booth ✦

Privacy at PicTofu

Privacy Policy

PicTofu is designed so the core photobooth can work without an account and without uploading your captured photos to a PicTofu photo server.

Last updated: August 15, 2026

Your photos stay with you.

In the current PicTofu MVP, camera frames, captured shots, filters, strip composition, and PNG export are processed in your browser. PicTofu does not maintain a cloud photo gallery or account-based photo history.

1. Scope

This policy describes the privacy practices for the PicTofu website and browser-based photobooth. It covers the current public MVP and the analytics services described below. If PicTofu later adds accounts, cloud photo storage, payments, advertising, or other material data processing, this policy will be updated before those features are treated as part of the normal service.

2. Camera access and photo processing

PicTofu asks your browser for camera permission only when a camera experience needs it. Your browser and operating system control that permission. You can deny or revoke camera access through your browser or device settings.

In the current MVP, captured image bytes and the final composed photo strip stay in browser memory while you use the booth. PicTofu does not intentionally transmit captured photos, camera frames, Blob URLs, base64 image data, or the generated PNG to analytics providers. If you download or share an image, the resulting file is handled by your browser, device, or the destination you choose.

3. Information we may process

PicTofu may process limited technical and usage information needed to operate, secure, and understand the site. Depending on which analytics services are enabled, this can include page paths, timestamps, referrer information, approximate location, browser type, operating system, device class, and product interaction events such as starting the booth or completing an export.

Product analytics are designed to use small, structured event fields. They must not include your photo content, camera frames, exported image bytes, Blob URLs, base64 data, or free-form text taken from your images.

4. Analytics

Vercel Web Analytics

PicTofu may use Vercel Web Analytics for aggregated traffic measurement, such as page views, referrers, general location, browser, operating system, and device information. Vercel describes its Web Analytics product as privacy-focused, cookie-free for visitor analytics, and based on anonymous aggregated data rather than persistent cross-site identifiers.

Google Analytics 4

Google Analytics 4 (GA4) is optional and is not required for the photobooth to function. When GA4 is configured, PicTofu uses a conservative analytics-consent gate: the Google Analytics tag is not loaded until you choose Allow analytics. If you decline, the core photobooth remains usable without GA4.

After analytics consent is granted, GA4 can collect usage information such as user and session statistics, approximate geolocation, browser/device information, page views, and the structured product events described above. Google Analytics can use a first-party identifier such as the _ga cookie when analytics storage is allowed. Advertising storage, ad personalization, and remarketing remain disabled in the current setup.

You can reopen PicTofu's Privacy settings and change the analytics choice. If a previously granted choice is revoked, PicTofu stores the denied state and reloads the page so the next page lifecycle starts without loading the Google Analytics tag.

5. Cookies and local browser storage

The core PicTofu booth does not require an account cookie or a cloud photo-session cookie. When GA4 is configured, PicTofu stores your analytics-consent choice in first-party browser storage under a small preference key so it can be remembered on later visits. Optional analytics providers may use browser storage or first-party cookies only according to their enabled configuration and the consent state that applies.

6. Third-party infrastructure

PicTofu uses third-party infrastructure to deliver the website. Vercel hosts and serves the application and may also provide privacy-focused traffic analytics when enabled. Google Analytics may provide optional product and acquisition measurement after the analytics-consent gate allows it. Those providers process technical information under their own terms and privacy documentation.

PicTofu does not authorize analytics providers to receive captured photo bytes as part of the current MVP analytics contract.

7. Data retention

PicTofu does not maintain a server-side library of your captured photos in the current MVP. Temporary browser objects used during a booth session are intended to disappear when the page/session is cleared, while files you choose to download remain under your control on your device.

Aggregated analytics data, when enabled, is retained according to the configured analytics provider and PicTofu's account settings with that provider. PicTofu does not use analytics retention to reconstruct or store your photo content.

8. International processing

PicTofu is available over the internet and may rely on service providers that operate infrastructure in multiple countries. As a result, limited technical or analytics information may be processed outside the country where you are located, subject to the safeguards and terms offered by the relevant provider.

9. Your privacy choices and rights

Depending on where you live, privacy law may give you rights concerning personal information, which can include access, correction, deletion, restriction, objection, portability, or withdrawal of consent. PicTofu currently has no user account or cloud photo library, so many requests involving photos can be resolved directly by clearing the browser session or deleting files you saved to your own device.

Where GA4 is configured, you can reopen the visible Privacy settings control to allow, decline, or withdraw analytics consent. The preference is stored in your browser rather than in a PicTofu user account.

10. Children and minors

PicTofu is a general-audience creative tool and is not designed specifically for children. The current MVP does not ask users to create accounts or submit profile information. Parents or guardians should supervise camera and sharing use where appropriate for the user's age and local requirements.

11. Changes to this policy

We may update this policy as PicTofu changes. Material additions such as cloud photo storage, accounts, payments, targeted advertising, or materially different analytics will require the policy to be reviewed and updated before those capabilities are treated as part of the normal production service. The date at the top of this page shows the latest revision.

12. Contact

A dedicated public privacy contact route is being added to PicTofu's site information pages before this policy is promoted as the final production legal contact point. Until that route is published, this section intentionally does not invent an email address or contact form that may not be monitored.