PhotoLister

Privacy Policy

Updated September 10, 2026. This policy covers the PhotoLister website and mobile app.

Information we use

We receive the photos and custom backgrounds you select, filenames, image dimensions, processing choices, batch history, and resulting images. The app keeps local draft copies for interrupted uploads and requests Photos access when you choose or save images. We do not require access to your entire photo library.

We automatically create a guest account so your app can track free use, purchases, and batches, even before you buy anything. We store an account identifier, session access, usage, purchase and refund records, and any recovery email you verify. Website sign-in may also provide your name and email. Recovery links are single use.

Photo processing and service providers

PhotoLister operates its own photo-processing software, including a background-removal model running inside our deployed worker on RunPod GPU infrastructure. RunPod provides computing infrastructure for that worker; we do not send photos to a separate third-party AI model service. Northflank hosts our API, photo-finishing worker, and database. Cloudflare R2 stores uploaded photos, masks, results, previews, and saved backgrounds. These infrastructure providers process or store data to deliver PhotoLister’s service. PhotoLister does not use customer photos to train AI models.

When you choose to create listing photos or upload a background, you instruct PhotoLister to upload and process the selected files for that purpose. Selecting product photos alone keeps them on your device until you start processing. You can remove a selection before uploading or choose not to start another upload. Work already submitted, including an interrupted upload you started, may resume and finish. Use Delete account in Settings to request removal of previously uploaded content.

Vercel hosts our website. Clerk provides website authentication. Resend delivers access and service emails and receives the destination address and email content. Cloudflare Turnstile helps prevent automated abuse when verification is required. These services receive the information necessary to perform their roles, including network and service diagnostics.

Mobile and website purchases

Apple processes iOS Photo Pack payments. RevenueCat connects the app to Apple purchase services and receives an opaque PhotoLister purchase identifier, product and transaction information, purchase status, and SDK/device diagnostics. PhotoLister records verified purchases, usage, refunds, and revocations to maintain your balance. Stripe processes website payments and receives checkout and billing information. PhotoLister does not receive your full payment card number. Purchases and account access use this information independently of whether you choose to upload photos.

Analytics and security

We keep internal product analytics for screen and workflow activity, processing timings and failures, purchases, recovery, and campaign attribution. Events are associated with account/session or installation identifiers and may include app version, platform, product choice, and safe diagnostic codes. Our analytics do not include photo contents or recovery credentials. The API hashes IP and user-agent signals for abuse prevention; infrastructure providers may keep network logs. These records help us improve the product, diagnose errors, and prevent misuse. We do not sell your personal information or use your photos for advertising.

On supported iPhones, Apple DeviceCheck helps us check whether a device has already received the free photo offer. We send Apple a device-generated verification value, retain a hashed replay-prevention record with your account, and store the eligibility decision. This check does not send Apple your photos. Apple’s device-level offer flag can remain after reinstalling the app or deleting your PhotoLister account; deletion does not reset free-offer eligibility.

Retention and deletion

Uploaded photos, results, batch history, saved backgrounds, and account and usage records are retained to support history, downloads, restyling, and recovery until account deletion. There is currently no automatic age-based purge for ordinary photo batches or internal analytics. Expiration of an access link or guest session does not mean the associated photos have been deleted. Abandoned or removed custom-background uploads that have never been referenced by a batch become eligible for worker cleanup after 24 hours; referenced backgrounds remain available for existing batch history.

Our deletion process must also address provider copies and backups. Backup and operational-log retention depends on the provider and configured service. We do not promise that session expiry, uninstalling the app, or removing a background from the picker erases those copies. If a legal obligation requires particular records to remain, we restrict them to that purpose and explain the exception when confirming deletion.

In the iOS app, open Settings, choose Delete account, review the scope, and confirm your request. This works for automatically created accounts, including accounts that have never purchased. Your current account access verifies ownership; you do not need to call or email support to initiate deletion.

We manually complete requests within 30 days. Your request includes all linked PhotoLister devices, uploaded and finished photos, batch history, saved backgrounds, recovery details, account access, and unused photo balance. Save any photos you want to keep before requesting deletion. Copies saved to your device are not removed. You can check your request reference, deadline, and completion in Settings on the requesting installation.

Account access remains available until deletion is completed. Please avoid new uploads or purchases while your request is pending. Deletion is permanent. It ends access to paid features and unused photos and does not automatically refund purchases. Apple handles refund requests for Apple purchases at reportaproblem.apple.com. Statutory refund rights are unaffected.

We retain only transaction information required for tax, accounting, disputes, or other legal obligations and a minimal record of the deletion request and its completion. Retained transaction records must not restore your deleted account, photos, or balance. Provider-held payment records may remain subject to their own legal duties. For website-only accounts or privacy questions, contact hello@photolister.com.

Your choices and contact

You keep ownership of your photos. Upload only content you have permission to use. To request access, correction, or help exercising privacy rights, email hello@photolister.com. We may verify ownership before releasing or changing account data. We will update this page when our practices change.