Your photos, your data.
Last updated: 14 May 2026
MakeAlbum (operated from Lisbon, Portugal) builds custom photo albums. To do that we have to receive your photographs and a few basic personal details. This page explains what we do with them — and, just as important, what we don’t.
What we collect
- Photographs you upload to your album, plus the technical metadata they contain (EXIF: camera, time, GPS if you didn’t strip it).
- Account details: your email and display name. If you sign in with Google, we receive your email + basic profile from Google’s OAuth API (no Drive, no calendar, no contacts).
- Order details: shipping address, the price you paid, and a Stripe payment reference. We never see or store your card number — Stripe handles that.
- Basic usage & first-party analytics: how often you log in, when you last edited the album, and privacy-respecting visit analytics — the pages you view, the site that referred you, your device type, and an approximate country (derived from your IP at the edge, which we don’t store). This uses our own first-party cookie only — no third-party trackers, ad pixels, fingerprinting, or session-replay tools.
Where it lives
Your original photographs and the final print-production files are kept in private storage in the EU — not reachable from the open web. To make the editor fast, we also generate downscaled previews of your photos; these are served from a CDN via long, unguessable URLs and may be cached there for up to 24 hours. The application database (Postgres) and our queue workers run on a server in Germany. Payments flow through Stripe (EU entity). Our print-production partner receives only the approved production file and the shipping address — not your full uploaded photo pool.
Who processes your data
We rely on a small number of service providers (sub-processors) to run MakeAlbum. Each one only receives what it needs for its job:
- Cloudflare — hosting, CDN, and R2 object storage for photos, previews and production files (EU).
- Hetzner — the servers that run the application, database and workers (Germany).
- OpenAI — AI curation of your photos and album text. Photos are sent to the OpenAI API, which does not train on API data.
- Amazon Web Services (Rekognition) — face and image-quality detection used to pick and crop frames (EU region).
- Saal Digital GmbH — printing and shipping of your album (Germany). Receives the production file and the delivery address.
- Stripe — payment processing. Card details go to Stripe directly and never touch our servers.
- Google — optional Google sign-in, and Google Analytics only if you accept analytics cookies.
- Migadu — transactional email (verification, order updates).
- Telegram — internal operations notifications to our team (for example “new order placed”). No customer photos are ever sent.
What we never do
- We never sell or share your photographs with anyone.
- We never use your photographs to train AI models — ours or anyone else’s. The model that curates your album was trained on a separate licensed photography corpus.
- We don’t embed advertising trackers or fingerprinting scripts, and we never sell or share your data. Alongside our own first-party stats, we use Google Analytics (GA4) to understand traffic and Microsoft Clarity to see where pages confuse people — but only if you accept analytics cookies in the banner; decline and both stay off. IP addresses are anonymized, and we use this in aggregate, never to profile or identify you. Clarity records how a page is used — clicks, scrolling, the path through the editor — with your photographs masked out: they are never part of a recording.
How long we keep things
Photographs you upload are kept while your album is in progress so we can reprint if there’s a defect. We delete originals and previews 90 days after your order ships, or when you delete the album. You can ask us to delete sooner (or to keep longer) by writing to info@makealbum.com.
Account details and order records are retained for as long as the account exists, plus 6 years for tax/accounting purposes (Portuguese law).
Your rights
Under GDPR (and equivalent regimes elsewhere) you can ask us at any time to:
- Tell you what we hold about you.
- Correct anything inaccurate.
- Delete your account and all associated data.
- Export your data in a portable format.
Write to info@makealbum.com and we’ll get back to you within five working days.
Contact
MakeAlbum — Aleksandr Belov, NIF 319455580
Lisbon, Portugal
info@makealbum.com
Complaints & dispute resolution
Livro de Reclamações: https://www.livroreclamacoes.pt
EU online dispute resolution platform: https://ec.europa.eu/consumers/odr