Effective 2026-07-29 · Version 2026-07-29
We collect only what is needed to provide Heapo: account identifiers and sign-in details; uploaded photos, videos and their metadata; family, invitation, album and sharing-link details; comments, hearts and reports; storage usage, deletion requests, device notification tokens, IP addresses and service logs. Passwords are handled by Firebase Authentication and are not stored by us.
We use this information to authenticate accounts, operate private family albums, process media, manage invitations and access, provide sharing links and reactions, prevent duplicates and abuse, answer support requests, and administer storage and subscriptions.
Account data and user content are deleted after the 30-day account-deletion grace period. Trashed media is deleted after 30 days. Expired-plan overage may be deleted after the notified grace period. Revoked links stop working immediately; related audit records are retained only as needed for security and legal obligations.
We do not sell personal information. We disclose it only with consent, when required by law, or when necessary to protect a person from imminent harm. Content is shown only to the family members or link recipients selected by the user.
We use Firebase for identity and notifications and Hetzner Object Storage for encrypted media storage and delivery. They process information only to provide the contracted service and under appropriate safeguards.
Identity data may be processed by Google Firebase in the United States, and media may be stored by Hetzner in Germany. Transfers occur continuously while the service is used, for authentication, notifications, storage and delivery, and last only for the retention periods described above.
The service is intended for parents and guardians sharing family media, not for children to create accounts. The uploader must have authority to share a child’s image. We promptly review reports involving child safety or unauthorized images.
You may request access, correction, deletion, suspension of processing or withdrawal of consent by using account deletion or contacting support. We may verify identity and will respond as required by applicable law. Revoking a sharing link takes effect immediately.
Electronic records are securely erased so they cannot be restored; storage objects and derived thumbnails or streams are deleted together. Records that law requires us to keep are isolated and deleted when that period ends.
We use access controls, short-lived signed media URLs, individually revocable recipient links, encrypted transport, restricted operator access, backups and logging. Public album pages use noindex and a no-referrer policy.
Privacy officer: kim-jun-young (operator), juny3738@gmail.com. You may contact this address for any privacy request or complaint.
You may also seek help from the Personal Information Infringement Report Center (118), the Personal Information Dispute Mediation Committee, the police or other competent authority in your country.
Operator: june; representative: kim-jun-young; business registration number: 371-07-03738; support: juny3738@gmail.com.
We will announce changes before they take effect. Material changes affecting your rights will receive prominent advance notice. The Korean policy is the controlling version if a translation differs.