Sowarly

Privacy Policy

Effective

Sowarly is a tool photographers use to deliver photographs to their clients. This page explains what we collect, what we deliberately do not, who else processes it, and how long anything is kept. It is written to be specific enough to check.

Two different roles

This distinction runs through everything below, so it comes first. For your own account information — your email address, your studio details, your subscription — Sowarly is the data controller. For the photographs you upload and the people in them, you are the controller and Sowarly is a processor acting on your instructions. We do not decide who sees your clients’ photographs; you do, by choosing what to publish and who to send a link to.

That means your own agreements with your clients govern their photographs. If a client asks you to delete their gallery, the deletion is yours to make, and the tools to make it are in your dashboard.

What we collect about you

When you create an account

  • Your email address, and a password that is hashed by our authentication provider before storage. We never receive or store a readable copy of it.
  • If you choose Sign in with Google instead, your Google account’s email address and display name. We do not receive your Google password, and we request no access to any other Google service.

What you can add to your profile, all optional

A display name, a studio name, a studio handle, a contact email address, a contact phone number, a website address, and Instagram and Facebook links. Every one of these is optional and blank until you fill it in.

Some of them are published deliberately: if you claim a studio handle, your studio page at sowarly.com/studio/your-handle is a public page, and the contact details and social links you have filled in appear on it and on the galleries you publish. That is the point of the feature — it is how a client reaches you — but it means those particular fields are visible to anyone, including search engines. Leave them empty if you do not want them published.

Your subscription

Your plan, your storage allowance, and identifiers linking your account to your subscription with our payment provider. Card details are entered with Paddle and never reach Sowarly’s servers — we cannot see your card number, and we could not charge it ourselves if we wanted to.

What you upload

  • The photo files themselves, at the resolution you uploaded them, plus two smaller preview versions that are generated in your own browser before upload rather than on our servers.
  • Their filenames, sizes and upload times, and the order and cover photo you choose.
  • Gallery settings: the title, the web address, an optional client name for your own reference, whether it is published, any expiry date, and a hash of any password you set. Gallery passwords are stored only as a slow one-way hash, so we cannot tell you or anybody else what a gallery’s password is.

What we record about your clients

Almost nothing, and this is a deliberate design choice rather than an omission. When someone opens a password-protected gallery and enters the password, we store a row containing a hash of a random session token, the gallery it belongs to, an optional label you may have given the guest link, and two timestamps. That row is what lets them re-open the gallery without typing the password again.

It contains no IP address, no device or browser information, and no name or email address for the visitor. There is no analytics script on a gallery page and no per-visitor logging, so we cannot tell you who viewed a gallery or how many times, and neither can anybody else.

Two qualifications, because the sentence above should not be read more broadly than it is true. First, Cloudflare — which serves every request — processes IP addresses in order to route traffic and absorb attacks, as any host must. Second, if you use Sowarly to email a gallery link to a client, that email address is handled by our email provider in order to deliver the message.

What we do not collect

  • No analytics or product-usage tracking of any kind. There is no Google Analytics, no Meta pixel, no session recorder and no heatmap tool on any page of this site, including your clients’ galleries.
  • No advertising identifiers, and no data sold or shared for advertising.
  • No fonts or scripts loaded from third-party servers. The typefaces are downloaded and served from our own domain when the site is built, so your visitors’ browsers make no request to a font provider.
  • No special-category data is asked for. Photographs can of course reveal a great deal about the people in them, which is exactly why access is yours to control.

Cookies

Sowarly sets two cookies, both strictly necessary for the site to work. There is no consent banner because there is nothing optional to consent to — we set no analytics or advertising cookies at all.

  • Your sign-in session. Set when you log in, so that each page knows it is you. It is readable by JavaScript on our own domain because the browser needs to refresh your session before it expires; it is sent only to sowarly.com, over HTTPS.
  • A gallery session. Set for a client who has entered a gallery password, holding a random token. It is scoped to the gallery paths only, so it is never sent with an image request, and it expires after 30 days of inactivity.

Who else processes your data

Sowarly is a small product built on a handful of infrastructure providers. These are all of them:

ProviderWhat it doesWhat it processesWhere
CloudflareApplication hosting, photo storage (R2), DNS and CDNPhoto files and previews; connection data such as IP address, which Cloudflare processes to route and protect requestsGlobal edge network
SupabaseDatabase and authenticationAccount records, profile fields, gallery and photo metadata, gallery password hashes, gallery session recordsLondon, United Kingdom (eu-west-2)
PaddlePayments, as merchant of recordBilling name, email, country, payment details and invoices. Card numbers are entered with Paddle and never reach SowarlyUnited Kingdom and European Union
ResendTransactional email, when configuredRecipient email address and the contents of the message — for example a gallery link sent to your clientUnited States
GoogleSign in with Google, only if you choose itYour Google account email address and display nameGlobal

Account and gallery records are held in a database in London. Photo files are held in Cloudflare’s object storage and cached at edge locations worldwide so that a gallery opens quickly wherever your client is — which means photo data does cross borders in the course of being delivered to the person you sent it to.

How long things are kept

  • Your photos and galleries: until you delete them, or until your account is closed. Nothing expires on its own, and nothing is deleted because a subscription lapsed.
  • Gallery sessions: deleted automatically 30 days after the last time they were used.
  • Payment event records from our payment provider: deleted 90 days after processing. Paddle keeps its own invoice records for as long as tax law requires of it.
  • A closed account: held for 30 days and then erased. The delay is a grace period, so that a deletion asked for in error can be undone.

What deletion actually does, precisely

When you delete a gallery or a photo, its records are removed immediately and it stops being reachable through the application. The underlying files are then removed from object storage by a separate clean-up process. There is a window between the two.

One consequence deserves stating plainly, because it is a property of how galleries load quickly rather than an oversight. Image links carry a signature in the address that is valid for between 12 and 24 hours, and the signature is what authorises the request. So a link that was already issued to a browser — or copied out of one — continues to work until it expires, even after you unpublish or delete the gallery. Unpublishing stops new links being minted; it cannot retract links already handed out. If you need an immediate, absolute cut-off, contact us and we can invalidate every outstanding image link at once.

Security

  • All traffic is served over HTTPS.
  • Every database table enforces row-level access rules, so one photographer’s query cannot return another’s rows even if the application asked it to.
  • Gallery passwords are stored as slow one-way hashes, never in a form that could be read back.
  • Image addresses are signed and time-limited rather than guessable.

The honest limitation: a gallery link is a secret, and anyone who has the link — plus the password, if you set one — can see the gallery. Treat the link the way you would treat a key, set a password on anything sensitive, and set an expiry date if the gallery should not be open indefinitely.

If we ever discover a breach affecting your data, we will tell you what happened, what was affected and what we have done, and we will notify the relevant authority where the law requires it.

Your rights

Depending on where you live, you may have the right to see the data we hold about you, correct it, receive a copy of it, have it erased, object to how it is used, or complain to your data protection authority. To exercise any of them, email privacy@sowarly.com. We aim to answer within 30 days and we will not charge you for it.

You can edit your profile and delete your galleries and photos yourself at any time from your dashboard. Closing your account is currently done by asking us — email support@sowarly.com and we will begin the 30-day deletion described above. A self-service button is coming; until it exists, this is the route, and it works.

If a request concerns photographs of a person rather than a Sowarly account, the photographer who uploaded them is the one who can act on it, and we will help you reach them.

Children

Sowarly is a tool for professionals and is not intended for use by anyone under 18. We do not knowingly collect account information from children. Photographs of children uploaded by a photographer are governed by that photographer’s own agreements and consents, which are theirs to obtain.

Changes to this policy

If this policy changes in a way that affects you, we will update the effective date at the top and, for anything material, tell account holders by email. Continuing to use Sowarly after a change means the updated policy applies.

Contact

Privacy questions and data requests: privacy@sowarly.com. Anything else: support@sowarly.com. See also our Terms of Service.