Unseen Roll Legal

Privacy Policy

Effective date: [SEPTEMBER 1, 2026] · Version v1.0-2026

Draft prepared for counsel review. Do not treat as final legal advice.

Unseen Roll (unseenroll.com) is a photo platform for events. This policy explains what we collect, why, and your choices. Contact: legal@unseenroll.com · 9528 Miramar Rd #1225, San Diego, CA 92126.

1. What we collect

You provide: account email and name from Apple/Google sign-in; a display name if you set one; consent selections (stored with version and timestamp); photos you capture; captions; an optional notification email; for Enterprise guests, a phone number; support messages.

Automatically: server logs (IP address, user agent, timestamps) for security and abuse prevention; capture metadata we generate (server capture time, event, roll). We strip EXIF metadata — including GPS location — from every uploaded photo before storage. We do not run facial recognition and we do not build biometric profiles.

From third parties: payment status from Stripe (we never see full card numbers); delivery status from our email (Resend) and SMS providers.

2. How we use it

To run the product (develop and reveal rolls, show galleries to the right people), send transactional messages (reveal notices, retention warnings, one-time codes), process payments, prevent abuse (rate limiting, moderation — including CSAM hash-matching, see below), and comply with law. We do not sell personal information and we do not use your photos to train AI models or for advertising.

3. Photos and who sees them

Photos are visible only to the event's participants and host, after the reveal — except: the host may hide photos; where the host enables a portfolio listing, a single cover photo becomes public (guests consent to this possibility at capture); Enterprise galleries follow the event contract. Downloads follow the rules published on the pricing page.

4. CSAM screening and reporting

Uploaded images are checked with automated tooling, including hash-matching against known child sexual abuse material via our infrastructure provider. Apparent CSAM is blocked and reported to NCMEC as US law requires. This is the one purpose for which we will access photo content without a support request.

5. Sharing

Service providers under contract: Cloudflare (hosting, storage, CSAM scanning tool), Stripe (payments; merchant of record where Managed Payments applies), Resend (email), our SMS providers (Enterprise messages). Legal: we disclose when required by valid legal process, and we notify affected users when the law allows. Business transfer: if we are acquired, data transfers with the service under this policy.

6. Retention

Photos: the event's retention period, then a 30-day grace, then permanent deletion (raw and processed copies). Consent and audit records: up to 7 years. Payment records: as required by tax law. SMS and email logs: 12 months. Backups purge on their own cycle within 35 days.

7. Your rights

Email legal@unseenroll.com to access, correct, export, or delete your data. Deleting your account removes your photos from future reveals and your personal data, subject to the participant-consent reality of shared rolls: photos already delivered to other participants' devices cannot be recalled. California residents have CCPA/CPRA rights (know, delete, correct, no discrimination; we do not sell or share data for cross-context ads, so there is nothing to opt out of). EEA/UK residents: our legal bases are contract (running your event), legitimate interest (security), consent (marketing, if ever), and legal obligation (CSAM reporting); you may lodge complaints with your supervisory authority.

8. Children

The service is 18+. We do not knowingly collect data from children. Event photos may incidentally include minors photographed by adult guests; hosts are responsible for appropriate photography at their events, and anyone may ask for removal via legal@unseenroll.com.

9. Security

Transport encryption everywhere, secrets in managed stores, EXIF stripping, one-time tokens, signed sessions, audit logging. No system is perfect; report issues to legal@unseenroll.com.

10. Changes

We version this policy (v1.0-2026), date changes, and re-prompt consent where a change is material. The current version is always at https://unseenroll.com/legal/privacy.