clyqr

Privacy Policy

Effective August 5, 2026

clyqr (“clyqr,” “we,” “us”) is operated by Matuod Labs LLC. This policy explains what we collect, why, and what you can do about it.

What we collect

  • Hosts (people who create albums): your email address, used only for magic-link sign-in — we never see or store a password.
  • Guests (people who upload to an album): the display name you type in and a session token stored in your browser. No account, email, or phone number required.
  • Photos and videos you upload, including embedded metadata (timestamp, and location if your device includes it) used to organize the album’s timeline.
  • Payment information, if a host buys an album — handled entirely by Stripe; we never see or store card numbers.
  • Basic technical data (IP address, request logs) used for abuse prevention, like rate-limiting repeated passcode attempts.

How we use it

To run the album: store and display photos, organize them by time and uploader, send hosts email notifications (a photo was reported, storage is nearly full), and process payments when someone buys an album. We do not sell your data, and we do not use your photos to train AI models — not ours, and not anyone else’s.

We do run automated processing on your photos to organize your album: reading the date they were taken, generating thumbnails, and detecting near-identical shots so they can be grouped together. That’s software reading your photos to build your album, not learning from them for anything else.

Who we share it with

We use a small number of service providers to run clyqr:

  • Supabase — database, authentication, and file storage (hosted in the US)
  • Resend — sending transactional email
  • Stripe — payment processing
  • Railway — application hosting

We only share what each provider needs to do its job. We do not sell data to advertisers or data brokers, and there’s no third-party tracking on the upload flow.

Illegal content: if a photo is reported and a host escalates it as apparent child sexual abuse material, we’re legally required to preserve it and may report it to the National Center for Missing & Exploited Children (NCMEC). See “Content moderation” in our Terms of Service for how that works.

How long we keep it

  • A free album stops taking new uploads after 30 days with nothing added, and its full-size original files are archived 60 days after the last photo is added, or six months after the album was created, whichever comes first. We email you first. The gallery keeps working, and every photo stays viewable and downloadable at viewing resolution.
  • A paid album keeps its original files for a year from the day the album becomes paid, then they are archived the same way. Not paying does not delete an album.
  • Nothing is kept forever. If nobody opens an album at all for two years, we email the host and then remove it.
  • If a host deletes an album, everything in it is deleted within 24 hours.
  • A photo that’s been reported and escalated as apparent CSAM is preserved for 1 year regardless of the above, as required by law.

Your choices

Hosts can delete their album at any time, which deletes all photos and guest data in it, and can export a full-quality copy of every photo before doing so.

Guests can undo an upload immediately after making it, from the same browser session. To request deletion of an upload after that, or to ask what data we have about you, email us at support@clyqr.com.

Cookies

clyqr uses a session cookie or token to keep you signed in (hosts) or recognized within an album (guests). We don’t use third-party advertising or tracking cookies.

Changes

We’ll update this page if what we collect or how we use it changes, and update the effective date above.

Contact

Questions about this policy: support@clyqr.com