On Android? SnapSync is in testing on Google Play. Join in three steps:
- Join the testers' group with the Google account your phone's Play Store uses.
- Become a tester on Google Play. It can take a few minutes to apply.
- Install SnapSync from Google Play.



Just join
No account, no sign-up, no password. Scan the QR code or tap the link, and you're in. Even someone who joins late gets every photo from the event.
Every photo, in your gallery
The group's photos land in the gallery you already use, next to your own, exactly as they were taken. Only photos taken during the event are shared; screenshots and photos saved from chats stay out.
For a day out, a party or a holiday
Quick enough for a spontaneous afternoon, long enough for a two-week holiday.
Private by design
Only your group, only photos from the event.
No account
No email, no password, no profile.
Anonymous
No name, email or phone number is ever asked for.
Only event photos
Screenshots and photos saved from chats stay out.
Legal
Privacy Policy
SnapSync ("we", "the app") is an independent project that lets people share the photos from an event with each other. This policy explains what data the app processes and why. We designed SnapSync to collect as little as possible: there are no accounts, and we never ask for your name, email, phone number, or contacts.
Who is responsible
The data controller for SnapSync is the project's operator, reachable at stefanh+snapsync@posteo.de. Please use this address for any privacy question or request.
What we process, and why
- Photos you share. When you join an event with sharing on, the photos in your library that were taken within the event's dates (or the narrower range you choose when joining) are uploaded so the other people in that event can receive them. Screenshots, screen recordings, low-resolution images and videos (such as pictures saved from chats), and photos in messaging-app albums are never uploaded. Anyone who holds the event's invite link or QR code can join it or download its photos in a browser, so share the invite only with people you want to have them. A photo is shared exactly as it was taken, including the details it carries, such as where it was taken, if your camera recorded that. Photos are stored to make sharing work and are deleted with the event (see below). In an event created with SnapSync 0.6 or later, every photo is stored encrypted, with a key that exists only on the phones in the event and in the event's invite link; our service is never given that key, so it cannot open the stored photos. The one exception is an iPhone that uploads photos in the background through the system's own photo uploader: there, each photo reaches our service unencrypted together with a key that opens only that photo, and our service encrypts it as it arrives and keeps neither the key nor the unencrypted photo. Legal basis: performance of the service you asked for (GDPR Art. 6(1)(b)).
- A random device ID. Each install generates a random identifier so the service can tell devices apart within an event. It is not linked to your identity and we cannot use it to contact you.
- A record of when the photo list is read. When the app fetches an event's list of photos, our service records the random device ID of the install that fetched it, why it did (for example, the app was opened, or woken because a new photo arrived), when, and how many photos it was given. When a browser fetches the list, it records only that a browser did and when — nothing that identifies the visitor. We use this record to keep photo delivery working and efficient, only we can see it, and it is deleted together with the event's photos. Legal basis: our legitimate interest in keeping the service working (GDPR Art. 6(1)(f)).
- A push token. Each time the app starts, your phone's platform gives it a token for silent wake-ups (Apple on iPhone; Google, through Firebase Cloud Messaging, on Android) — the app never shows notifications and never asks to. We use the token only to wake your device when new photos are ready in your event. Legal basis: performance of the service you asked for (GDPR Art. 6(1)(b)).
- An app-integrity check. The app proves to our server that it is a genuine, unmodified copy of SnapSync: on iPhone through Apple App Attest; on Android through a key that the phone's secure hardware certifies, which our server checks against Google's public list of revoked certificates (the app sends Google nothing for it). This checks the app, not you, and carries no personal information. Legal basis: our legitimate interest in preventing abuse of the service (GDPR Art. 6(1)(f)).
- Automatic crash and error reports. In versions from the App Store, TestFlight or Google Play, when the app crashes, hits an error, or freezes until the system closes it, a technical report (what went wrong, the app's recent activity leading up to it, device model, operating system version, app version, and how its previous runs ended) is sent to our error-monitoring service so we can find and fix the problem. A report may contain the random identifiers of your device, the event and the photos involved, so we can find what a problem affected; it never contains the event's key (the part of the invite that opens its photos) or anything that identifies you. Each report also carries one random per-install identifier, created by the reporting itself, so we can tell how many devices an error affects. Legal basis: our legitimate interest in keeping the app working (GDPR Art. 6(1)(f)).
- Bug reports you send. "Report a problem" in the app's menu opens a sheet that says what will be sent and asks you to describe the problem. Nothing is sent unless you write a description and tap Send. A bug report contains your description, the app's and its background uploader's recent activity logs, the app's sync state and photo counts (including the counts the screen showed, and how many photos you selected if you gave the app access to selected photos only), and the state of your device at that moment: whether it was online and on mobile data or another restricted network, whether power saving was on, whether the system allowed the app to work in the background, the battery level and whether it was charging, how hot the device was, and its time zone — with event, device and photo identifiers left in, so we can find the event and photos affected. A bug report never contains your photos, your location beyond the time zone, your contacts, other apps' data, your free storage or your device's name. It goes to the same error-monitoring service. Apart from bug reports and the stripped-down activity attached to automatic reports, the app's activity logs never leave your phone. Legal basis: your consent (GDPR Art. 6(1)(a)), given by sending the report.
- The event page. An invite link contains the event's identifier, which is the key to the event. Opening it in a browser sends that identifier to our service, which shows the event's name, its dates and how many members it has, and, if you download, the photos from our storage. The same happens when a messaging app builds a preview of the link. Treat the link like a key: anyone holding it can see this and download the photos. The identifier goes only to our own service, and the page tells your browser not to pass its address on to any other site. The page sets no cookies, runs no tracking, and does not make you a member of the event. Our service notes only that a browser read the event's photo list, and when (see above). For an encrypted event, the link also carries the event's key, after a "#", which your browser never sends anywhere; the page uses it to open the photos in your browser, and without it the page shows no photos.
- Getting the app on Android from an invite. If you follow the Google Play button on an event page, the page hands that event's invite to Google Play, so that SnapSync can open the invite once it is installed on your phone. Google Play then receives the invite, which is the key to the event: anyone holding it can see the event's photos. For an encrypted event, the invite handed over includes the event's key, and only when the page was opened with it. Nothing is handed over unless you follow that button; the button on this landing page never carries an invite, and neither does the page for an invalid or expired link. Google's handling of it is covered by Google's own privacy policy. Legal basis: your consent (GDPR Art. 6(1)(a)), given by following the button.
We do not use analytics, advertising, or tracking of any kind — in the app or on this website.
Who processes it for us
We rely on four service providers to run SnapSync:
- Bunny.net — hosting, storage, and content delivery for the photos and the service.
- Apple — on iPhone: silent push wake-ups, the app-integrity check, and app distribution through the App Store.
- Google — on Android: silent push wake-ups (Firebase Cloud Messaging) and app distribution through Google Play.
- Bugsink — error monitoring: receives the automatic crash and error reports (never with an event's key) and the bug reports you choose to send.
How long we keep photos
Photos are stored only to enable sharing within an event. Once an event has ended and every member has received its photos, the photos shared to it are deleted — and in any case about three days after the last photo reached it once its dates have passed, and never later than 30 days after it was created or after its start date, whichever is later (each at the latest about a day after that). A photo you also shared to another event stays until that event's photos are deleted too. Photos already received into someone's photo library stay there. If you want data associated with your device removed sooner, email us at the address above.
Your rights
Under the GDPR you can request access to, correction of, or deletion of your personal data, and you can lodge a complaint with a supervisory authority. Because we hold no name or email for you, we may need your device's identifier to act on a request — email us and we'll help.
Changes
We may update this policy; the "last updated" date above always reflects the current version.
Legal
Terms of Use
By using SnapSync you agree to these terms. If you do not agree, please do not use the app.
Beta software
SnapSync is early, in-development software provided "as is" and "as available", without warranties of any kind. Features may change or break, and photos or other data may be lost. Do not rely on SnapSync as your only copy of any photo.
Your photos
You keep all rights to the photos you share. By sharing a photo to an event, you grant us the limited permission needed to store, transmit, and deliver it to the other members of that event, and you confirm you have the right to share it.
Acceptable use
You agree not to use SnapSync to share unlawful content, to share images of people without the consent required where you are, or to interfere with, abuse, or attempt to circumvent the service or its integrity checks.
Liability
To the fullest extent permitted by law, we are not liable for any indirect or consequential loss, or for loss of data, arising from your use of this beta software.
Apple App Store terms
The following apply when you obtain SnapSync through the Apple App Store:
- These terms are between you and us only, not with Apple; we, not Apple, are solely responsible for the app and its content.
- Your licence to use SnapSync is the non-transferable licence described in Apple's Licensed Application End User License Agreement, as supplemented by these terms.
- Apple has no obligation to provide support or maintenance for SnapSync. Apple is not responsible for any product warranties, product or third-party claims, or intellectual-property claims relating to the app.
- Apple and its subsidiaries are third-party beneficiaries of these terms and may enforce them against you.
- You confirm you are not located in a country subject to a U.S. Government embargo or designated as terrorist-supporting, and are not on any U.S. Government list of prohibited or restricted parties.
Contact
Questions about these terms: stefanh+snapsync@posteo.de.

