TRUST & SECURITY

Built to be trusted with the work that can’t be re-shot.

A wedding happens once. A gallery you’ve delivered has to still be there next year. Here’s exactly how we protect it — the architecture and the guarantees — in plain terms.

EU DATA RESIDENCY RESUMABLE UPLOADS WE DON’T DELETE DELIVERED WORK GDPR-NATIVE
The guarantees

Four promises, each built into the system — not the marketing.

Uploads that resume

Every upload is a resumable, multipart transfer. Drop off Wi-Fi mid-upload and it picks up where it left off, instead of starting the file over.

Delivered galleries stay live

Once a gallery has a live share link, it is excluded from every automated quota and retention job. We don’t take delivered work down — the purge job filters those galleries out before it deletes anything.

Stays in the EU

Files are stored and served from EU-jurisdiction infrastructure, with an EU-hosted database. Your clients’ data does not leave the region — usable by organisations a US consumer tool can’t serve.

No client login

Clients open a gallery from a private link — with an optional PIN — and never create an account or hand over personal data to view or download.

The delivered-gallery invariant

We don’t take down a gallery you’ve delivered.

The failure that has burned photographers elsewhere — a host silently deleting an already-delivered gallery over a storage policy — does not happen here. Purge candidates exclude any gallery with a live share. If a storage limit is ever reached, we block new uploads and tell you in-app first; delivered content always stays live.

NO AUTOMATED JOB REMOVES A DELIVERED GALLERY

CuratePics is a delivery platform, not a backup. We don’t delete delivered galleries — no automated quota or retention job removes one. But we keep a working copy of your files, not an archive: keep your own backup of your originals. A 3-2-1 setup — three copies, two kinds of media, one off-site — is the standard, and nothing here replaces it.

Data & security

Where your data lives, and how it’s protected.

  • EU region, end to end. Object storage in the EU jurisdiction, an EU-hosted application database, and EU email delivery (Resend, Ireland).
  • No client accounts. Galleries open from a capability-token link — clients never create logins or hand over personal data to view.
  • Encrypted in transit & at rest. TLS everywhere; storage encrypted at rest by default.
  • Private by default. PIN-gating and download controls available on every gallery.
  • Soft-delete & retention. Deletions are recoverable within the retention window; nothing is hard-purged on a whim.
  • Audit trail. Key access and delivery events are logged.
  • Zero-egress economics. We never meter your clients’ downloads, so there’s no incentive to throttle or expire.
  • Founder-answered support. A real person, fast — plus a help centre and docs.
Sub-processors

The short, EU-first list.

We keep the chain deliberately small. This is the full list.

Provider
Purpose
Region
Cloudflare R2
Object storage & edge delivery
EU JURISDICTION
Supabase
Application database & auth
EU (FRA)
Resend
Delivery & notification emails
US — SEE NOTE
Stripe
Payments & billing
US — SEE NOTE

This list is maintained here and updated before any change takes effect. Your photographs and your database stay in the EU — Cloudflare R2 (EU jurisdiction) and Supabase (Frankfurt). Resend and Stripe are US companies and handle only email delivery and payment details, never your images. We are confirming the transfer safeguards for both; ask us before you rely on it.

Compliance

GDPR-native, built EU-first.

We’re built for the EU from the ground up — not retrofitted.

Data Processing Agreement

Our processor terms are with our solicitor. If your organisation needs a DPA, email legal@curatepics.app with your timeline and we’ll tell you where they stand.

Privacy & terms

Read how we handle data and the terms of service in plain language.

Privacy Policy Terms