Privacy Policy
Effective date: September 1, 2026 · Version v1.1-2026
Draft prepared for counsel review. Do not treat as final legal advice.
Unseen Roll (unseenroll.com) is a photo platform for events, operated by Necati Atahan, an individual doing business as Unseen Roll. This policy explains what we collect, why, and your choices. Contact: [email protected] · 9528 Miramar Rd #1225, San Diego, CA 92126 (mailing and contact address).
1. What we collect
You provide: account email and name from Apple/Google sign-in; a display name if you set one; consent selections (stored with version and timestamp); photos you capture; captions; an optional notification email; for Enterprise guests, a phone number; support messages; Enterprise inquiries you send through our site, including your name, work email, organization, expected guest count, event date, and message. We use Enterprise inquiry information to respond to your inquiry and discuss the event you are planning.
Automatically: server logs (IP address, user agent, timestamps) for security and abuse prevention; capture metadata we generate (server capture time, event, roll); anonymous product-usage measurement of our own event-setup flow — which step you reached, on mobile or desktop, tied to a random identifier that lasts for that visit only and is not linked to you, your account, or any advertising. We strip EXIF metadata — including GPS location — from every uploaded photo before storage. We do not run facial recognition and we do not build biometric profiles.
From third parties: payment status from Stripe (we never see full card numbers); delivery status from our email (Resend) and SMS providers.
2. How we use it
To run the product (develop and reveal rolls, show galleries to the right people), send transactional messages (reveal notices, retention warnings, one-time codes), process payments, prevent abuse (rate limiting, moderation — including CSAM hash-matching, see below), and comply with law. We do not sell personal information and we do not use your photos to train AI models or for advertising.
3. Photos and who sees them
Photos are visible only to the event's participants and host, after the reveal — except: the host may hide photos; where the host enables a portfolio listing, a single cover photo becomes public (guests consent to this possibility at capture); Enterprise galleries follow the event contract. Downloads follow the rules published on the pricing page.
4. When we process photo content
Photo content is processed by automated systems to operate the service: develop and reveal processing (variants, aesthetic presets), storage and delivery, security scanning, and moderation — including hash-matching against known child sexual abuse material (CSAM) and nudity screening. An automated flag hides a photo pending review; it is a signal for review, not a determination. Human access to photo content is limited to your own support requests, review of content flagged by moderation or reported by users, and what the law requires. We do not use photo content to train AI models, and we do not use it for advertising or marketing without a separate explicit opt-in. Reports to NCMEC's CyberTipline are made when required by applicable law, and related material is preserved as the law requires.
5. Sharing
Service providers under contract: Cloudflare (hosting, storage, CSAM scanning tool), Stripe (payments; merchant of record where Managed Payments applies), Resend (email), our SMS providers (Enterprise messages), and bah.is (short-link service; invitation links use go.unseenroll.com). Legal: we disclose when required by valid legal process, and we notify affected users when the law allows. Business transfer: if we are acquired, data transfers with the service under this policy.
6. Retention
Photos: the event's retention period, then a 30-day grace, then permanent deletion (raw and processed copies). Consent and audit records: up to 7 years. Payment records: as required by tax law. SMS and email logs: 12 months. Support messages and Enterprise inquiries: 12 months. Anonymous product-usage measurement: 90 days. Backups purge on their own cycle within 35 days.
7. Your rights
Email [email protected] to access, correct, export, or delete your data. Deleting your account removes your photos from future reveals and your personal data, subject to the participant-consent reality of shared rolls: photos already delivered to other participants' devices cannot be recalled. Where applicable law provides privacy rights (such as the California Consumer Privacy Act, for businesses it covers), we honor them as required. Unseen Roll also voluntarily extends the following controls to all users, regardless of whether a particular privacy law applies to us or to you: know what we hold about you, correct it, export it, delete it, and equal service either way. We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of. Our site does not respond to browser "Do Not Track" signals; there is no third-party tracking to turn off. EEA/UK residents: our legal bases are contract (running your event), legitimate interest (security), consent (marketing, if ever), and legal obligation (child-safety reporting); you may lodge complaints with your supervisory authority.
8. Children
The service is 18+. We do not knowingly collect data from children. Event photos may incidentally include minors photographed by adult guests; hosts are responsible for appropriate photography at their events, and anyone may ask for removal via [email protected].
9. Security
Transport encryption everywhere, secrets in managed stores, EXIF stripping, one-time tokens, signed sessions, audit logging. No system is perfect; report issues to [email protected].
10. Changes
We version this policy (v1.1-2026), date changes, and re-prompt consent where a change is material. The current version is always at https://unseenroll.com/legal/privacy.