GatherRoll

Effective August 23, 2026

Privacy without the fine-print fog.

GatherRoll is operated by Binary Data Technology. It is a private event-camera service: hosts create invitation-only rolls and guests add photos through a roll link. This policy explains the data needed to provide that service.

Information we collect

For hosts, GatherRoll collects an email address, a Firebase user identifier, event names and schedules, roll settings, participant and shot counts, reports, and export or deletion requests. For guests, it collects an anonymous Firebase identifier, a display alias, a consent record, an app-generated device/session proof, submitted photos and the metadata needed to validate and process them, and any reports they submit. If you contact support, we also receive the email address, message, and diagnostic details you choose to provide.

How we use it

We use this information to authenticate hosts, issue private invitations, enforce event and shot rules, accept and recover uploads, process and reveal albums, prevent abuse, respond to reports, support users, and carry out export or deletion requests. We do not sell personal information. The launch service has no advertising, behavioral profiling, or paid billing.

Photos and reveal

Photos upload to private Google Cloud storage. Before the scheduled reveal, GatherRoll does not issue readable photo URLs to hosts, guests, support staff, or administrators. Processing removes embedded EXIF metadata and creates web-ready copies. After reveal, only viewers allowed by the host’s album setting can access ready, non-removed photos through short-lived links.

Temporary data on a guest device

A photo waiting for upload can be held in the browser’s private storage with retry information. GatherRoll does not show a post-shot preview. After the server confirms the upload, the temporary browser copy is removed. Favorites are stored only on that device.

What we do not request

GatherRoll does not request location, contacts, microphone access, advertising identifiers, face recognition, biometric grouping, or photo-content analytics. The guest camera is requested only after a guest chooses to start it. A phone-camera file fallback may be used instead.

Service providers and sharing

Firebase and Google Cloud provide authentication, database, storage, hosting, server processing, and abuse prevention. The guest website uses reCAPTCHA Enterprise App Check, and the Android host app uses Google Play Integrity, to produce short-lived device and app-integrity tokens. These services may process device, app, network, and interaction signals under Google’s terms. Photos and aliases are shared with the host and invited viewers according to the roll’s reveal time and visibility setting. Reports are available only to the people responsible for moderating that roll and providing support.

Retention, export, and deletion

Temporary upload sources are removed after safe processing. At launch, sanitized album and thumbnail copies remain available until the host requests deletion of the roll or account; GatherRoll does not promise a separate automatic event-expiry schedule. Downloadable export archives expire after 24 hours. Hosts can request an account export, delete a roll, or request account deletion in the app. A verified deletion request is scheduled for permanent execution after a seven-day delay and covers the account and owned event data, subject only to information that must be retained for security, legal, or fraud-prevention obligations. A web request is also available on the account deletion page.

Security and private links

Data is transmitted over HTTPS and stored behind authorization rules. Invitation and capability secrets are treated as credentials and protected in server records. Do not publish a roll link or send private photos to support. No online service can promise absolute security, so rotate an invitation if it may have been exposed.

Young people and consent

GatherRoll is not directed to children under 13. Events may include young people, so hosts and guests must have permission to photograph and share every person shown, including any consent required from a parent or guardian. A photo can be reported for privacy or lack of consent.

Questions

Email binarydatatechnology151@gmail.com. Include the event name and approximate time, but never include an invitation link, authentication code, or private photo.