Scope
This notice describes the information handled when someone uses the POVE iPhone app, the POVE App Clip, an invitation link, or the public pages at pove.app. In this notice, an “Event” is a private, invitation-based space created by a Host, and a “Memory” is the Event gallery made available after Reveal.
Apple, a device operator, and websites or services reached through an external link may handle information under their own notices. POVE does not control those independent services.
Information POVE handles
Depending on how you use POVE, the service handles:
- an anonymous Guest identity, or a durable Host identity created through Sign in with Apple, and related authentication data;
- Event details such as the Event name, type, roll and Reveal settings, status, invitation records and cover choice;
- Event participation records and an Event display name if one is provided;
- photos and cover images submitted to an Event, including display and master versions;
- photo details needed to order, upload and display a Memory, such as capture time, capture order, dimensions, file size, upload state and POVE identifiers;
- report, hide and Event-level block records, including a selected report reason;
- for paid Events, purchase intent, App Store transaction and redemption records, and the opaque POVE Host identifier used with RevenueCat;
- and app data kept on the device, such as session information, queued uploads, cached Event media, reveal state and an optional local reminder.
Guests do not need an account and may provide an optional Event display name. Hosts use Sign in with Apple. POVE does not use the Host's Apple profile fields as a RevenueCat identity; it uses an opaque POVE user identifier. The app does not intentionally request a telephone number, postal address or precise location. Photos may, of course, depict people, places or other personal information chosen by the photographer.
How POVE uses information
POVE handles information to:
- create, join and operate private Events;
- apply roll limits and Reveal settings;
- upload, store, organize and display Event photos;
- authorize access for the Host and Event participants;
- verify and redeem a consumable purchase for one paid Event;
- restore an Event experience on the same app installation;
- process deletion, report, hide, block and Host-removal actions;
- protect the service, diagnose faults and prevent misuse; and
- serve and secure the public website and invitation routes.
POVE does not use Event photos for advertising, cross-service tracking, facial recognition, or training generative AI models.
Private Events and access
An invitation link is a private capability: anyone who receives it may be able to resolve and join the associated Event while the invitation remains active. Hosts and participants should share links only with intended recipients and avoid posting them publicly.
Event media is designed to remain limited to the Host and authorized participants. Before Reveal, photos are not shown in the ordinary participant Gallery. After Reveal, authorized Event participants may view the shared Memory. Reveal does not make an Event or its photos public on the web.
People with authorized access can save, share or capture copies on their devices. POVE cannot control a copy after another person has exported it from the service.
Photos and other content
Photographers and other rightsholders keep their rights in content they submit. POVE processes that content only as needed to provide the Event experience: receiving it, creating practical display versions, storing it, protecting access, presenting it to authorized participants and carrying out the controls described in this notice.
Before submitting or sharing content, make sure you are allowed to do so and respect the privacy, consent and intellectual-property rights of people shown in it. A Host can begin removing a photo from the shared Memory. That action is different from hiding or reporting it.
Reports, hiding and blocking
An authorized user can report a photo and hide it from their own view. A report records the selected reason. Reporting does not automatically delete the photo for everyone.
A Host can begin removing a photo from the Event and can restrict a participant’s access to that Event. The Host may also choose to remove that participant’s existing Event photos. These controls are Event-specific; they are not platform-wide public profile actions.
For practical steps, see the support guidance for reporting content.
Notifications and device features
Notifications are off by default. For an Event with a scheduled Reveal, a user may ask POVE to add a local reminder on that device. POVE asks for notification permission only after that choice and attempts to schedule the reminder when device permission allows. Manual Reveals do not use a background remote-push promise.
Camera access is used for taking Event photos. Saving a revealed photo to the Photos library happens only after the user chooses that action. Copies saved to Photos or shared through another app are controlled through the device and the receiving service, not through POVE’s deletion controls.
Service providers and processing locations
POVE relies on Vercel for website hosting and network delivery; Supabase for authentication, database operations, private media storage and server-side product functions; RevenueCat for paid-Event purchase verification and purchase-history coordination; and Apple for Sign in with Apple, App Store payment processing, app distribution, device permissions, notifications and Photos interfaces. Those providers process information to deliver and protect the service.
Provider infrastructure can process information in more than one country. POVE does not promise that every request or service operation stays within a single country or region.
Retention
POVE keeps Event and participation information while it is needed to operate the relevant Event. Photos, covers and their working metadata are kept while they are needed for the Event and Memory. Moderation records are kept while needed to apply Event controls, address safety or abuse concerns, and protect the service.
Local app data remains on the device until it is cleared by an app action, removal of the app, or the device’s own storage management. Hosting and security providers may keep limited request, diagnostic, recovery or security records according to their service settings and applicable obligations.
POVE does not currently apply a published automatic time limit after which every Event expires. The main retention boundaries are the life of the Event and the deletion choices described below.
Deletion
POVE provides separate controls for different scopes:
- a Host can begin removing one photo from an Event;
- a Host can request deletion of an Event they own;
- a participant can request deletion of their participation and contributions;
- a user can request deletion of their current POVE identity and associated POVE data; and
- a user can clear local app data without deleting server-held Event data.
When you request remote deletion, POVE begins removing the relevant Event, participation, content or service data. Limited records or copies may remain where needed for security, abuse prevention, technical recovery, the rights of others, or legal obligations. Deletion cannot remove copies another participant previously saved or shared outside POVE.
Host-account deletion also asks RevenueCat to erase the linked customer record and, where possible, revokes the Sign in with Apple authorization. A verified but unused consumable purchase is not transferred, restored, refunded or converted into an Event when an account is deleted. POVE may retain non-personal transaction evidence needed to prevent that purchase from being reused and to meet legal, accounting or security obligations.
Clearing local data, deleting the app, or losing the device session can remove your access without deleting remote Event data. Use the appropriate remote deletion control first when you want POVE-held data removed.
The exact in-app paths and the difference between remote deletion and local clearing are set out in the deletion support guide.
Your choices and rights
You can choose whether to join an Event, take or submit photos, enable a local Reveal reminder, save a photo to the Photos library, or share an exported copy. The app provides deletion and moderation choices as described above.
Depending on the law that applies, you may also have rights to ask for access, correction, deletion, restriction, objection or portability, and to withdraw consent where processing relies on consent. These rights are not absolute and may depend on the circumstances. Begin with the in-app controls or follow the current guidance on the support page.
You may have the right to complain to the data-protection authority where you live or work, or where you believe an issue occurred.
This website
POVE does not add analytics, advertising trackers, tracking pixels or non-essential cookies to the privacy, terms or support pages. These pages do not create a POVE app identity, join an Event, request camera access or load Event photos.
Like ordinary hosted websites, pove.app is delivered through network and hosting infrastructure that receives request information such as IP address, requested path, timestamp, browser or device details, request identifiers and security signals. That information is used to deliver, cache, troubleshoot and protect the site.
A POVE invitation route is separate from these legal and support pages. When opened, it may send the private invitation value to POVE’s service to resolve limited Event details. Invitation pages are excluded from search indexing and are not designed to expose Event photographs.
Security
POVE uses access controls intended to limit Event data and private media to authorized people, keeps invitation values out of ordinary public pages, and separates privileged server operations from the app. The website also limits browser capabilities that its public pages do not need.
No online service can promise absolute security. Protect invitation links and your device, keep the operating system current, and use the report or deletion controls if something is wrong.
Children and young people
POVE is not a public discovery service. A Host chooses whom to invite to a private Event. Do not use POVE if you cannot lawfully agree to the applicable terms or submit the content involved. A parent or guardian should decide whether participation is appropriate where a young person cannot make that decision independently.
If a photo involving a child or young person creates a privacy or safety concern, use the in-app report and Host controls described above. This notice does not set a numeric age threshold.
Changes and support
This notice may change when POVE’s features, providers or legal obligations change. The date at the top shows the latest revision. Material changes should be presented in a way appropriate to the service and the people affected.
For product help, deletion steps, privacy requests or a content concern, use the POVE support page or email hello@pove.app.