Privacy Policy

Last updated: January 2025

This privacy policy explains how your personal information is collected, used, and protected on photos.kellisfamily.org, a private photo sharing site operated by Spencer Kellis for close friends and family.

Information We Collect

Account Information

When you are invited to join this site, we collect:

  • Your name
  • Your email address
  • A password (stored securely using industry-standard hashing)

Photos and Content

When you upload photos or import them from Google Photos:

  • The photo files themselves
  • Photo metadata (dimensions, file size, upload date)
  • Any descriptions or tags you add
  • Comments you leave on photos

Google Photos Integration

If you choose to import photos from Google Photos:

  • We request read-only access to photos you explicitly select
  • Selected photos are downloaded and stored on our servers (Cloudflare R2 storage)
  • We do not retain access to your Google Photos library after import
  • Photos are copied, not linked — deleting from Google Photos does not affect copies here

How We Use Your Information

Your information is used solely to:

  • Provide access to the photo sharing features
  • Display your name alongside comments you leave
  • Send you notifications about new collections (if you opt in)
  • Authenticate your account

Data Storage and Security

Your data is stored using the following services:

  • Account data: Supabase (PostgreSQL database with row-level security)
  • Photo files: Cloudflare R2 (encrypted object storage)
  • Authentication: Supabase Auth with secure session management

All connections use HTTPS encryption. Passwords are hashed and never stored in plain text.

Data Sharing

This is a private site for friends and family. Your information is:

  • Never sold to third parties
  • Never used for advertising
  • Only visible to other invited members of this site

Your Rights

You can:

  • Update your account information at any time
  • Delete photos you have uploaded
  • Delete comments you have made
  • Request deletion of your account and all associated data

Cookies

We use essential cookies only:

  • Authentication session cookies (required to stay logged in)
  • Temporary Google OAuth tokens (when importing from Google Photos)

We do not use tracking cookies, analytics, or advertising cookies.

Contact

If you have questions about your data or this privacy policy, contact Spencer Kellis at spencer@kellisfamily.org.

Changes to This Policy

This policy may be updated occasionally. Significant changes will be communicated to registered users via email.