1. Who we are
Huddled is a private, shared media service operated by Callo Apps LTD, a company registered in England & Wales (Company No. 17194575), registered office 66 Paul Street, London, EC2A 4NA ("Callo Apps", "we", "us", "our"). Callo Apps is the data controller for the personal data described in this policy. For any privacy question or request, contact us at support@huddled.cloud.
2. Scope
This policy explains what personal data we collect when you use the Huddled app, websites, and API (the "Service"), how we use and share it, and the rights you have. It applies to registered account holders, members of shared spaces, guests who join without an account, and developers who use our API.
3. Information we collect
- Account & identity. When you sign up we (through our authentication provider, WorkOS) collect your name, email address, whether your email is verified, and an optional avatar and bio. If you sign in with Google or Apple, we receive basic profile information from that provider.
- Your content. The photos, videos, files, captions, comments, and reactions that you and the members of your spaces upload or create, together with related metadata such as file name, type, and size.
- Payment data. Paid plans are processed by Stripe acting as merchant of record. We do not receive or store your card number or other full payment details — we store only your plan, subscription status, and the identifiers Stripe returns to us.
- Device & technical data. Information needed to run and secure the Service, such as IP address, browser/device type, and log data. For API keys we record the IP address last used with the key.
- Website usage data. When you visit huddled.cloud, including the blog and the web app, we record cookieless, aggregated analytics about the visit with a self-hosted copy of Plausible Analytics. Section 6 describes exactly what is recorded.
- Push subscriptions. If you enable browser notifications, we store the push endpoint and keys your browser provides so we can deliver notifications.
- Support communications. Messages you send us and their contents.
- Face data (optional). If you turn on the optional "Find Me" feature, we collect the face data described in Section 4. We never collect face data without your explicit consent.
- Guest data. If you join a space as a guest without an account, we store a display name you choose and an anonymous session token; we do not collect an email for guests.
- Developer & integration data. If you use our API or connect a third-party storage or photo account (e.g. Google Drive, Google Photos, Dropbox, OneDrive), we store scoped, encrypted access credentials and the account label you connect. For Google Drive we can access only files you pick or files Huddled creates; for Google Photos we can access only the items you pick in Google's own picker and items Huddled saves for you.
We do not intentionally collect special-category data, and we ask that you do not use free-text fields to share it.
4. Face data — the "Find Me" feature
Find Me is an optional feature. It finds photos that you appear in, inside your own spaces. It is off until you enroll. This section explains exactly what we collect, why, and when we delete it.
Consent comes first. We collect face data only after you give explicit consent on a dedicated consent screen. This consent is separate from these terms and from any other agreement. We record the date and time of your consent. You can withdraw it at any time by un-enrolling in the Huddled app (Settings → Find Me).
What we collect:
- A face template. When you enroll with a photo or a guided scan, we convert your face into a numeric representation (a vector of numbers, called an embedding). This template is what we compare photos against. It cannot be reversed into a picture of your face.
- Your enrollment photo. If you enroll with a single photo, we keep that photo until you un-enroll or replace it. If you enroll with the guided scan, every captured frame is deleted immediately after processing — we keep no scan images at all.
- Match results. A private list of the photos our system believes you appear in, with a confidence score.
How matching works, and who can see it:
- Matching is strictly self-search. Photos in your spaces are compared against your template only, to find you. Results are visible only to you — not to space admins, not to other members, not to anyone else.
- Faces of people who have not enrolled are processed transiently in memory during matching and are never stored.
- If you mark a match as "not me", we store that choice (which photo you rejected — it contains no face data) so the photo is never suggested again.
- Matching runs only in spaces where the feature is enabled by the space's plan or by your own plan.
Where processing happens. All face detection and matching runs on infrastructure we operate with our hosting sub-processors (Cloudflare and Convex, Section 7). We do not use any third-party facial-recognition service, and we do not use face data to identify you to anyone, for advertising, or for any purpose other than showing you your own photos.
Retention and deletion schedule. We delete face data when the first of these happens:
- You un-enroll: your template, your enrollment photo, and every match are deleted immediately.
- You delete your account: everything above is deleted, including your "not me" choices.
- A photo is deleted, or you leave a space: the matches tied to that photo or space are deleted.
- We upgrade the matching model: your old template stops being used and is replaced only if you re-enroll.
We never sell, lease, trade, or otherwise profit from face data, and we do not disclose it except to the hosting sub-processors above acting on our instructions, or where the law requires.
Legal bases. In the UK and EEA, face data used to identify a person is special-category biometric data; we process it only with your explicit consent (UK/EU GDPR Article 9(2)(a)), which you may withdraw at any time as described above. In US states with biometric privacy laws, the consent screen is our written notice and release, and the schedule above is our retention and destruction schedule.
5. How we use your data and our legal bases
Under the UK GDPR and EU GDPR we rely on the following legal bases:
- To provide the Service (performance of a contract): creating your account, storing and displaying your media to members of your spaces, enabling comments and reactions, sending service emails (verification codes, password resets, invites), and processing your subscription.
- To secure and improve the Service (legitimate interests): preventing abuse and fraud, enforcing our Terms, maintaining reliability and security, and understanding how the Service is used, including measuring visits to our website with cookieless, aggregated analytics (Section 6). We balance these interests against your rights.
- With your consent: sending browser push notifications, connecting optional third-party integrations, and processing face data for the Find Me feature (explicit consent — see Section 4). You can withdraw consent at any time.
- To meet legal obligations: tax and accounting, and responding to lawful requests from authorities.
We do not sell your personal data, we do not use it for third-party advertising, and we do not run ads.
6. Cookies and similar technologies
Huddled uses only strictly necessary, first-party cookies and local storage — for example to keep you signed in, remember your theme preference, and protect sign-in against cross-site request forgery. We do not use advertising cookies, and our website analytics (below) store and read nothing on your device, so no cookie-consent banner is required.
Website analytics (Plausible). To understand how our website is used, such as which pages are visited and how people arrive at them, huddled.cloud (including the blog and the web app) uses Plausible Analytics. We run our own copy of Plausible on a server we rent in the EU (see Section 7), so this data is not sent to Plausible Insights OÜ, and it is never used for advertising or combined with your account.
- No cookies or device identifiers. Plausible does not use cookies, local storage, or any other identifier stored on your device, and it does not track you across other websites.
- What is recorded for each visit: the page address, the referring website, any campaign tags in the link (such as
utm_source), your browser, operating system and device type, your country, region and city, and how long a page stays open and how far you scroll. Your location is estimated from your IP address. - What is removed first. Before an event reaches Plausible, our server removes invite links and Space identifiers from the page address (for example,
/join/<invite code>is recorded as/join/:token) and drops every query parameter except campaign tags. - Unique visitors. To count unique visitors without identifying you, Plausible combines your IP address and browser information with a random value that is replaced every 24 hours, and keeps only the resulting one-way hash. The hash cannot be used to recognise you on a later day or on another website. Your IP address itself is not stored.
- Aggregate only. The analytics are only ever reported as totals. We cannot use them to see what an individual visitor did.
- Where it runs. Only on our website. The Huddled mobile apps do not use Plausible or any other analytics.
We rely on our legitimate interest in understanding and improving our website (Section 5). You can object at any time by emailing us, or block the analytics with any content blocker without affecting the Service.
7. How we share your data
Your content is visible only to members of the spaces it belongs to, according to the roles you assign. Beyond that, we share personal data with the service providers (sub-processors) that help us run Huddled, each acting only on our instructions:
- WorkOS — authentication, single sign-on, and directory sync.
- Convex — application database and real-time backend.
- Cloudflare — hosting, network delivery, media storage (R2), transactional email, and video processing.
- Time4VPS (Lithuania, EU) — the server that runs our self-hosted website analytics (Section 6).
- Stripe — payment processing as merchant of record.
- Browser push services (Google, Apple, Mozilla, Microsoft) — to deliver notifications you enable.
- Storage and photo providers you connect (e.g. Google Drive, Google Photos, Dropbox, OneDrive) — only when you authorise an integration.
Google user data. Huddled's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: data we receive from Google Drive or Google Photos is used only to provide the import and export features you ask for — we do not use it for advertising, do not sell it, and do not let humans read it except with your consent, for security, or to comply with the law.
We may also disclose data where required by law, to protect our rights or users, or in connection with a merger, acquisition, or sale of assets. We do not sell your personal data.
8. International data transfers
We are based in the UK and some of our sub-processors are located in the United States and elsewhere. Where we transfer personal data outside the UK or EEA, we rely on an appropriate safeguard — such as an adequacy decision, the UK International Data Transfer Agreement (IDTA) or Addendum, or the EU Standard Contractual Clauses.
9. Data retention
We keep your content while your account and spaces are active. When you delete media it is soft-deleted and permanently purged from storage around 30 days later. When you delete your account we erase your personal data and login identity (see below); content you contributed to other people's shared spaces may remain there so that one member's deletion does not remove a shared album, but your access is removed. Residual copies may persist briefly in backups before being overwritten. Website analytics (Section 6) are kept only as aggregated statistics that do not identify you; the daily value used to count unique visitors is deleted after 24 hours.
10. Your rights (UK & EU)
If you are in the UK or EEA you have the right to access, correct, erase, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. You can delete your account and associated personal data from Settings → Account, or exercise any right by emailing support@huddled.cloud. We aim to respond within one month. You also have the right to complain to your local supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk).
11. US privacy rights (California and other states)
We collect the categories of personal information described in Section 3 (identifiers, biometric information (Section 4), account and commercial information, internet/network activity, and user content) for the business purposes described in Sections 4 and 5. In the past 12 months we have not sold or "shared" personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA), and we do not knowingly do so. If you are a California resident — or a resident of another US state with similar laws — you may request to know, access, delete, or correct your personal information, and you will not be discriminated against for exercising these rights. Submit a request to support@huddled.cloud; you may use an authorised agent to act on your behalf.
12. Security
We protect data with encryption in transit (TLS), scoped access controls, hashing of API keys, encryption of stored integration tokens, and reputable infrastructure providers. No system is perfectly secure, but we work to protect your data and to notify you and regulators of a qualifying breach where the law requires.
13. Children
Huddled is not intended for children under 13, and under 16 in the United Kingdom, the EEA, and other regions where a higher age applies. We do not knowingly collect personal data from children below the applicable age. If you believe a child has provided us personal data, contact support@huddled.cloud and we will delete it.
14. Guests
Spaces may allow people to join as guests without an account. For guests we store only a chosen display name and an anonymous session token kept in the guest's browser; guest uploads are held for review by a space administrator before they become visible. A space owner may ask guests to accept a consent notice before joining.
15. Changes to this policy
We may update this policy from time to time. If we make material changes we will notify you in-app or by email and update the "last updated" date above.
16. Contact
Callo Apps LTD, 66 Paul Street, London, EC2A 4NA, United Kingdom. Email support@huddled.cloud.