Privacy Policy
Last updated 5 September 2026
Draft for early testing with invited groups. To be finalized with legal review (including biometric-data law) before public launch.
SaanZh is a photo-sharing service for events, made by VN Tech Inc. (“we”, “us”). This policy explains what we collect, why, and the controls you have. The short version: we collect the minimum needed to run the service, face recognition only ever runs with your explicit consent, we never sell your data, and you can delete your account at any time.
1. What we collect
When you create an account:
- Email address — used to sign you in with a one-time code and to send you notifications about events you belong to.
- Phone number (with country code) — used only so an event host can find and invite you. It is never shown to other members.
- Display name, and optionally a place (free text) and a profile photo.
When you use events:
- Photos you upload, and photos other members upload to events you have joined, along with basic details such as upload time and file size.
- Event membership and activity — which events you accepted, which photos you viewed full-screen or downloaded, and requests you make (for example, a deletion request). Activity records are used to run the service and are not shown to other members.
Only if you choose to enable “My Photos”:
- Face data— a numeric representation (an “embedding”) of your face, generated from at least three photos you provide of yourself. This is biometric data and is covered in detail below.
We do not collect your location, your contacts, or advertising identifiers, and we do not use third-party analytics or tracking in this version.
2. Face recognition is optional, and how it works
SaanZh can find the photos you appear in. This only happens if you enroll your face, confirm you are 18 or older, and explicitly consent. Skip it and SaanZh works as a plain shared album.
- Enrollment. You provide three or more photos containing only your face. We create an embedding from them and store it with your account.
- Per-event consent.Matching runs only in events you have explicitly accepted. Accepting an event that uses face matching is your consent to be matched in that event’s photos, including photos uploaded before you accepted.
- Anonymous processing of uploads. In events with face matching turned on, we detect faces in uploaded photos and store embeddings linked to the photo, not to any person. A face is connected to an identity only when it matches an enrolled member who accepted that event. Faces of people who have not enrolled are never linked to a name.
- Events without face matching. A host can turn face matching off for an event. In those events no face detection runs on uploads. You may opt in individually to search for yourself; that processing affects only you.
- Withdrawal. You can remove your face enrollment at any time in Settings. We delete the embedding, and future matching stops. Existing match records are deleted with it.
3. Children
You must be 18 or older to create an account and to enroll your own face. A parent or legal guardian may enroll a child under 18 as a linked profile under their own account, after confirming they are the parent or guardian and consenting on the child’s behalf. The parent can remove the child’s enrollment at any time, which deletes the child’s face data.
4. How we use your information
- To sign you in, run events, deliver photos, and send notifications about events you belong to.
- To let hosts invite you by phone number or email.
- To find photos of you, only under the consent rules in section 2.
- To keep the service secure, prevent abuse, and fix problems.
We do not sell your data, we do not show advertising, and we do not use your photos or face data to train models for anyone else.
5. Who can see what
- Other members of an event see the photos in that event and your display name and profile photo. They never see your email or phone number.
- Event hosts additionally see the last digits of a phone number when inviting you, so they can confirm they have the right person.
- Nobody outside the event can see event photos. Photos are stored privately and served through time-limited links.
Your controls over individual photos:
- Hide any photo from your own view.
- Mark as private a photo in which you are the only person, so other members no longer see it.
- Request deletion of any photo. The host or uploader decides; SaanZh does not force removal, because the uploader already holds the original.
- Leave an event, or block a person so they can no longer invite you.
6. Service providers
We run SaanZh on a small number of infrastructure providers who process data on our behalf and under our instructions: database and sign-in (Supabase), application hosting (Render), photo storage and network (Cloudflare), and transactional email (Resend). Data is hosted in the United States. We do not share your data with anyone else except when the law requires it.
7. How long we keep things
- Event photos and their face data are deleted automatically after an event closes, following the retention period shown on the event (30 days for free events) plus a short grace period.
- Your account information and face enrollment are kept until you delete them.
- Records of your consent (terms acceptance, face-recognition consent) are kept while your account exists, so we can show what you agreed to and when.
8. Deleting your account
You can delete your account from Settings at any time. Deletion removes your profile, face enrollment and all embeddings, match records, trust and block lists, and your event memberships, and frees your email and phone number for reuse. Photos you uploaded remain in their events but are no longer attributed to you. During early testing, deletion is immediate. At public launch we plan a short recovery window before the final purge, and face data is always removed first.
9. Your rights
Depending on where you live you may have rights to access, correct, export, or delete your personal data, or to object to certain processing. You can exercise most of these directly in the app; for anything else, email us and we will respond within 30 days.
10. Security
All traffic is encrypted in transit. Photos are stored in private buckets with access only through the SaanZh service. Face embeddings are stored in the database with access restricted to the service, never in public storage. No system is perfectly secure; if we learn of a breach affecting your data we will tell you.
11. Changes to this policy
We will update this policy as SaanZh evolves. If the changes are material we will ask you to review and accept them the next time you sign in. The date at the top tells you which version you are reading.
12. Contact
VN Tech Inc., operator of SaanZh. Questions or requests about your data: support@saanzh.app.