Privacy · Last updated August 25, 2026
Your photos are personal data, not marketing inventory.
This policy explains the product's intended data handling. PhysicalAlbum processes information needed to create, save, purchase, produce and support the photo book you request.
What we collect
We process the photos and filenames you upload, image dimensions and selected metadata such as capture time, the edits and cover choices in your project, contact and shipping information you provide, and order/payment status. Card details are collected by the payment provider rather than stored by PhysicalAlbum.
How photos are used
Customer photos are used to upload, analyze, arrange, preview, render, print and support the specific album you request. They are not used to train general-purpose AI models or placed into advertising without separate permission.
Private storage & temporary links
Original files are designed to remain in private object storage. The application generates short-lived signed URLs when the browser, renderer or approved fulfillment workflow needs temporary file access. Signed links should not be treated as permanent public photo URLs.
Automatic image processing
The service may read orientation, dimensions and capture time, create thumbnails and normalized derivatives, calculate print-resolution estimates, crop/resize images for chosen frames and, when you explicitly request enhancement, create a higher-resolution render derivative. Enhancement does not change the native source-quality rating.
Retention
Unsaved guest projects are scheduled for deletion after the configured guest-retention period, which defaults to 14 days. Saving a project or placing an order cancels that abandoned-project deletion so the project can be resumed, fulfilled and supported. You can request deletion of a saved, unpurchased project; ordered records may need to be retained for fulfillment, remakes, fraud prevention, accounting or legal obligations.
Service providers
The service relies on infrastructure providers for private storage and application hosting, a payment processor for checkout, an email provider when transactional email is enabled, and a print/fulfillment provider for orders. Each provider receives only the data needed for its role.
Security
The application uses project authorization checks, row-level database security, private storage, expiring signed URLs, rate limits, verified payment webhooks and restricted server credentials. No online system can promise zero risk, but secret server keys are not intended to be exposed to browser code.
Your choices
You can leave an unsaved project to expire, request deletion of an eligible saved project, or contact support about access/correction/deletion questions. A paid personalized order may require some transaction and production records to remain even after photos are removed.
Contact
Privacy and deletion requests can be sent to support@physicalalbum.com. Include the project/order email and enough information to locate the record without sending passwords or payment-card data.
Privacy laws differ by jurisdiction. Before a broad commercial launch, the operating business should have this policy reviewed against the countries in which it sells.