Privacy Policy
Last updated: July 20, 2026
PicMeUp Photo Sharing ("PicMeUp", "we") lets event organizers collect photos, videos, and written messages from their guests directly into the organizer's own Google Photos library or OneDrive, with a live slideshow for the event. This policy explains what information the service handles and how.
Information we collect
- From guests: the name you enter on an event page, the photos and videos you choose to upload, any guestbook message you write, and — only if you request album access — your email address.
- From organizers: your email address and name from the account you sign in with (Google or Microsoft), and the events you configure.
- Automatically: standard technical records (IP address, browser user-agent, timestamps) kept in a security audit log for up to 180 days, after which they are deleted automatically.
How photos and videos flow
Media you upload is transmitted from your device directly to Google Photos or Microsoft OneDrive, and stored in the event owner's own account. PicMeUp does not keep copies of your photos or videos on its own servers, and the bytes never pass through them.
Use of Google and Microsoft user data
When an event owner connects an account, PicMeUp requests only the permissions it needs to operate. With either provider, the app is confined to what it created itself and can see nothing else in the account:
- Google Photos (append): to create the event album and let guests add photos to it. Guest upload sessions are restricted to append-only access — they cannot view, download, or delete anything.
- Google Photos (read app-created data): to display the photos this app added to the album in the event's protected live slideshow. PicMeUp cannot see any other part of your library.
- OneDrive (app folder only): if the owner chooses
OneDrive, PicMeUp is granted access to a single folder it creates, at
/Apps/PicMeUp. It cannot read, list, or search anything else in that OneDrive — we have verified this against a live account. Guests receive a one-time upload link for a single file and never hold a credential of any kind. - Gmail (send): used only by the service's own sender account to deliver notification emails (access requests, approvals, guestbook digests). PicMeUp cannot read any mailbox.
PicMeUp's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the features described above; it is never sold, never used for advertising, and never transferred except as necessary to provide those features, to comply with law, or as part of the service's security operations.
Sharing
Photos and messages you submit are visible to the event's organizers. Album access is only ever granted when the event owner personally approves a request, which sends the album link to the requester by email. We do not sell or rent any personal information to anyone.
Storage and revocation
Event configuration, guest names, guestbook messages, and access requests are stored in Google Firebase (Firestore). Connected accounts are stored as revocable tokens; deleting an event removes its owner's connection when no other event uses it. Owners can revoke PicMeUp's access at any time — Google at myaccount.google.com/permissions, Microsoft at account.live.com/consent/Manage.
Deletion requests
To have a guestbook message, access request, or your audit records removed — or to ask any question about this policy — use our contact form. Photos live in the event owner's own Google Photos or OneDrive account, so photo removal requests go to the event organizer.