Last updated: 25 July 2026
Privacy Policy
This policy describes the personal data used by the current free beta, why it is used, who receives it, and how long the application keeps it.
Controller
Lorenz Greyer, sole proprietor, operating as No Preview Club
Viktoriaweg 27
Stiege 3, Tür 3
9020 Klagenfurt am Wörthersee
Austria
Email: hello@nopreviewclub.com
Technical access and server data
When you open or use the service, the application and its infrastructure providers necessarily process connection and request data such as IP address, date and time, requested URL, request method, response status, referring page, and browser/device information. This is needed to deliver the site, diagnose failures, protect the service, and prevent abuse.
For application rate limits, a network identifier derived from the IP address is protected with a keyed hash. The application does not place the raw IP address or a complete user-agent string in its own roll records. Infrastructure security and access logs may nevertheless contain ordinary request data.
Roll identifiers and browser storage
Starting or visiting a roll creates a random anonymous roll token in the technically necessary no_preview_roll HttpOnly cookie. The database stores only a SHA-256 hash of that token together with the roll identifier, status, counts, and operational timestamps. The cookie is limited to 48 hours.
The application does not use Local Storage, Session Storage, IndexedDB, or advertising cookies. Supabase browser authentication is configured without a persistent user session. The aggregate website and product statistics described below do not add an application tracking cookie.
Aggregate website and product statistics
Vercel Web Analytics provides aggregate website-usage statistics such as page views. The application uses Vercel's official Next.js integration and does not add its own analytics cookie or send custom product events to Vercel.
A separate internal funnel records only that a roll was started, development was submitted, a reveal email was accepted or delivered, the gallery was first opened, or the ZIP was first requested successfully. Each event is counted at most once per roll. The analytics table stores only the event name, UTC timestamps, and a one-way SHA-256 pseudonym derived from the random roll identifier. It has no field for an email address, IP address, reveal token, URL, user agent, photo, filename, storage path, or other photo metadata.
Funnel reporting is aggregate, grouped using the Europe/Vienna time zone, and starts only when the feature is activated. Earlier activity is not backfilled.
Photos, metadata, and people depicted
A roll contains between five and 27 uploaded JPEG photos. The application records their sequence, byte size, dimensions, storage location, and operational timestamps. The browser redraws each camera frame and creates a new JPEG before upload, so metadata from the original camera file—such as EXIF device or GPS metadata—is not included in the uploaded image.
Photos may identify you or other people shown in them. They are used only to operate the requested private roll, including validation, private storage, development, reveal, download, security, and deletion. The application does not perform facial recognition, biometric identification, AI image analysis, or unrelated reuse. You must have the necessary rights and, where required, inform or obtain permission from people depicted.
Development email and Brevo
When you request development, the application stores the delivery email address and uses Brevo’s Transactional Email API to send the transactional reveal message. Brevo receives the recipient address, sender details, subject, message content, reveal link, and technical delivery information. The reveal link contains a high-entropy token and must be treated as private.
The reveal email is used only to deliver the roll. It is not consent to a newsletter, advertising, or any other marketing use. For the internal funnel, the application accepts only Brevo's transactional delivered webhook for a stored reveal message ID. It ignores open, click, bounce, and other mail events, and does not store Brevo webhook email addresses or complete payloads in the analytics table.
Contact form and Reply-To
If you use the contact form, the application processes your reply email, message, request metadata used for security, and an empty anti-spam field. It sends the message to the operator through Brevo and places your address in the email’s Reply-To field so the operator can respond. The email and message are not added to an application contact or marketing database, but they are present in the relevant Brevo transactional systems and the operator’s mailbox.
Reveal access and ZIP downloads
The reveal token arrives in the URL fragment, is removed from the visible URL after exchange, and is stored in the database only as a hash. Removing the fragment from one browser does not invalidate the original mail link. The same secret link can be exchanged repeatedly, including in another browser or on another device, until the fixed deadline 30 days after the roll became ready.
Each successful exchange can create the signed, technically necessary np_reveal HttpOnly cookie, limited to the private reveal API and the roll’s deletion deadline. The cookie is an additional way for that browser to reopen the gallery; it does not replace or consume the mail link. The cookie authorizes the gallery, individual photo delivery, and ZIP download. Private photo URLs remain short-lived, and the ZIP is assembled on demand rather than kept as a separate archive.
Anyone who receives the secret reveal link may access the photos during the availability period. Do not forward or share it unless you intend to give that person access.
Automated processing and cleanup
A protected scheduled processor changes developed rolls to ready status, queues and sends reveal emails, retries operational failures, and runs deletion jobs. These are rule-based service operations. The application does not make decisions producing legal or similarly significant effects about you.
Purposes and legal bases
- Roll, photo, delivery-email, development, reveal, and download processing is necessary to provide the service you request and administer the Terms (Article 6(1)(b) GDPR).
- Contact messages are processed to answer your request and, where applicable, take steps before a contract (Article 6(1)(b)); otherwise the basis is the legitimate interest in responding to genuine enquiries (Article 6(1)(f)).
- Rate limits, necessary logs, fraud and abuse controls, operational troubleshooting, aggregate service statistics, and legal-claim records rely on legitimate interests in securing, understanding, and operating the service and protecting users (Article 6(1)(f)).
- Data is processed where necessary to comply with a legal obligation (Article 6(1)(c)).
Where data is required to provide a requested roll or answer a message, not providing it means that function cannot be completed. No GDPR consent is requested merely by acknowledging this Privacy Policy.
Processors, recipients, and international transfers
- Supabase: application database and private object storage.
- Vercel: application hosting, delivery, infrastructure logs, and Web Analytics.
- Brevo: transactional reveal and contact-form email delivery and reveal-delivery webhooks.
- The operator’s mailbox provider: receipt and storage of contact messages and service correspondence.
These providers may engage subprocessors. Processing can occur outside Austria and the EEA. Where a transfer requires an Article 46 GDPR safeguard, the relevant provider’s data-processing terms may use the European Commission’s Standard Contractual Clauses; an adequacy decision may apply in other cases. Supabase and Vercel publish DPAs containing transfer safeguards. The exact project regions, current Brevo account contracting setup, enabled subprocessors, and mailbox-provider configuration are not determined by this repository and should be confirmed from the live account contracts and settings.
Retention
- Capture is available for 24 hours. If development is not requested, the roll expires at 48 hours and its photos are then claimed by the recurring cleanup job for deletion.
- A developed roll becomes ready no earlier than one hour after submission. Ready photos, reveal tokens, email-event records, the delivery address, and related application records are automatically scheduled for deletion 30 days after readiness. The recurring cleanup job may physically delete them shortly after that deadline, depending on its run interval.
- A minimal roll tombstone containing operational status and timestamps remains in the database after photo cleanup. The current code does not define a later automatic deletion period for that tombstone.
- Application rate-limit rows expire for enforcement purposes, but the current code does not define a separate physical deletion schedule for those rows.
- Pseudonymous funnel events are retained as aggregate service history independently of roll cleanup. The current code does not define an automatic deletion period for those events.
- Contact messages remain in Brevo’s transactional systems and the operator’s mailbox as needed to answer and handle the request. No exact deletion period is configured in this repository.
- Providers may retain security logs, delivery events, and backups under their account settings, contracts, and legal obligations. Their exact live retention settings cannot be established from the application code.
Strictly necessary cookies
The roll and reveal cookies described above are used only to resume an anonymous roll and authorize a private reveal. The private admin area uses a signed, time-limited HttpOnly session cookie that is not used for public-user tracking. The website does not set advertising, marketing, or application analytics cookies, so no cookie consent banner is shown.
No newsletter or unrelated use
The current service has no active newsletter or marketing signup. Dormant database fields or schema definitions for possible future consent functions are not used by the current application. Reveal and contact email addresses are not used for marketing without a separate valid legal basis and, where required, separate consent.
Your rights
Subject to the GDPR’s requirements and exceptions, you may request access, rectification, erasure, restriction of processing, and data portability. You may object to processing based on legitimate interests. Where processing were based on consent, you could withdraw that consent for the future; the current roll flow does not rely on consent as its legal basis. You also have the right not to be subject to qualifying solely automated decisions.
To exercise a right, email hello@nopreviewclub.com or use the contact form. We may need enough information to verify your identity and locate the relevant data without weakening another person’s privacy.
You may lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, Austria, email dsb@dsb.gv.at, or with another competent supervisory authority.