hejclewCreate an event

PRIVACY

How we handle your photos

Last updated 29 August 2026. This is the policy for Hej Clew at hejclew.com, including the Android app. It is written in plain language on purpose.

What this product is

You open an event, sort photographs on your phone, and choose which ones to add to a shared chronological story. We keep contributed copies. We do not run a marketplace, a social feed, likes, comments, or face recognition.

What we collect

  • Photos you choose to contribute to an event. Photographs that stay in My Photos on the phone are not uploaded merely because they exist.
  • A first name, and an email if you type one.
  • Event details the creator enters (name, date, optional place, visibility).
  • A session cookie so the same browser or app stays signed in as you.
  • Product events we store ourselves (opened an event, uploaded, contributed). We do not send these to an ad network.

What we keep

After processing, we keep curated files: your shortlist selections and any photos you explicitly add to the event story. The shared story only includes photos someone chose to contribute. Event creators can share a link (and a private event needs an invite link).

What we delete

Raw camera-roll uploads are temporary. Photos we do not keep as curated copies are deleted after processing. Rejected originals are removed promptly; leftover working files expire after our retention window (24 hours on the production host). Hourly cleanup removes those expired temps. We do not keep a public dump of everyone's full roll.

Android app

The shipping Android app is native. It stores an opaque session token in encrypted preferences and sends Authorization: Bearer. Photographs you add stay on the phone while you sort them. Only the photographs you choose to contribute are uploaded. The older Capacitor WebView wrap is not shipping.

Cookies

We set an HTTP-only session cookie (event_platform_sid) with Secure and SameSite=Lax. It lasts about 30 days. It is how we know which photos are yours. We do not use advertising cookies.

Who can see an event

Public events can be opened by anyone. Private events need an invite. A finished private event may have an unlisted album at /h/<token> — viewing that album is not the same as joining or uploading. Turning the album link off hides it.

Processors

Hosting, database, and private object storage run on DigitalOcean. Email to hello@hejclew.com is routed through our domain provider. We do not sell your photos or use them to train a public model.

Your requests

Email hello@hejclew.com to ask what we hold, to correct a name or email, or to delete your photos and session. We are OBSIDIAN DYNAMICS LIMITED (company 16663833), England and Wales.