You upload other people’s weddings, other people’s children, other people’s homes. We store them and serve them to whoever you allow — that is our entire role. We don’t train anything on them, don’t analyse faces, and don’t make money from what’s in them.
This page explains how it works technically. The legal version: privacy policy and terms with the data processing agreement.
Password and link-only galleries don’t go to Google. Only what you mark as public can be indexed.
On previews and thumbnails, never on the original. A screenshot of a proofing gallery is useless.
SilverAlbum’s admin panel shows no photos or thumbnails from client galleries. Titles and sizes are enough to handle a ticket.
Deleting a gallery or an account removes the files from storage, not just rows from a list.
The market is going the other way — finding guests by face is becoming a premium feature. We skip it deliberately: a face scan is biometric data, and family and school sessions are mostly children. A photographer using such a feature takes on Article 9 GDPR obligations, usually without knowing it.
In SilverAlbum a likeness stays an ordinary photo: no biometric templates, no face index, no “who is who” database. Less impressive on a feature list — one worry fewer when a parent asks what happens to their child’s photo.
You have the consents and contracts with the couple, the parents, the school. You decide who gets the link, the password and for how long.
We store and serve files, nothing more. The data processing agreement isn’t a separate PDF to dig up — it’s § 12 of the terms and covers every account from day one.
The couple doesn’t create an account with us. They get a link and a password from you, and when selecting photos they leave an email address at most — so the selection is signed and you know whose it is.
Privacy isn’t only about servers. It’s also about the in-laws, who don’t need to see every getting-ready shot.
Main password — for the client — sees the whole gallery, hidden frames included.
Extra passwords — e.g. “Guests” — a separate password that doesn’t show frames marked as hidden.
Hidden frames — one switch on the photo in your dashboard; a hidden frame doesn’t exist for restricted access — not in the grid, not at the file URL, not in the ZIP.
Gallery log — every visit and every download with the file name — when a client says “I never got anything”, you have an answer, not a hunch.