Skip to main content

Your data stays yours.

We built photoloft because we didn't want our own event photos on someone else's servers. Here is exactly how we protect yours.

Encrypted the moment it arrives

Every photo is encrypted with its own unique key the moment it reaches our servers and stays encrypted at rest. Those keys are managed separately from the images in a dedicated key service, and the overarching master key is split into several parts kept in separate locations. So the security of your photos doesn't hinge on any single key or server.

Stored in Germany, stays in Europe

Your photos live exclusively on servers within the EU, including encrypted backups. Nothing ever leaves the European Union. GDPR compliance is the baseline we build on, not something we added later.

No ads, no data sale, ever

photoloft is a one-time purchase. We have no ads and no advertising partners. We don't train AI models on your photos. We don't sell your data, your metadata, or your usage patterns — to anyone. The only money we ever see from you is the price of your event.

You know exactly how long we keep it

Your photos are stored for the lifetime of your plan. Before it expires, you'll get an email with a download link for the full original album. After expiry, the encryption keys are permanently destroyed — the photos become mathematically unrecoverable. Not even we can bring them back.

Your gallery stays private

Every event gallery is reachable only via your own link and after signing in with an email address, and only by the guests of your event. Galleries are not public and are not indexed by search engines. The contents of different events are strictly separated from one another.

Delete everything, any time

You can request full deletion of your event with one click in your dashboard. We destroy the encryption keys, which makes your photos unreadable and irrecoverable on every server and in every backup. We confirm the deletion within 72 hours.

We're an open book

Our security and privacy measures are documented internally. When we make changes that affect how your data is handled, we tell you about them.