The short version
- Your photos are yours. Nobody else can see them, and nothing you upload appears anywhere public.
- Every photo is re-encoded in your browser before upload, so the file we store carries no GPS tag — a photo shared from here cannot give a spot away. Coordinates you choose to keep, like a map pin, stay locked to your account.
- We run no ad trackers and sell no data. Cookies keep you signed in, and a first-party cookie or two briefly remember which link brought you here — no one else can read them, and nothing follows you around the web.
- Deleting something deletes it. There is no recycle bin on our side — only short-lived disaster-recovery backups, which are kept for up to 30 days and then deleted.
What we collect
Your email address, which is how you sign in and the only way we can reach you about your account. The photos you upload and the basics that come with them (timestamp, image dimensions, which camera you told us they came from). The names you type — cameras, properties, bucks. What you write to us — feedback and reports are kept with your account so we can read them in context and reply. Operational logs that record what the system did (a sort ran, an upload finished) without your photos or personal details in them. And to slow down password-guessing and form spam, a salted one-way fingerprint of the network address a sign-in attempt or a waitlist signup came from — the fingerprint, not the address itself, and we never use it to work out where you are.
How you found us. If you arrive through a tagged link or a shared card, a cookie remembers that for up to 90 days so that if you sign up we know which link deserves the credit. It holds the link’s tags, not anything about you; no other site can read it, and it is deleted once it has done its job. We also count page views with a cookieless service that sees a page, a referrer, a country, and a device class — never who you are, and it cannot be joined to your account.
How you sign in, and what that means for what we hold. There are three ways in: a password, a link emailed to you, or your Google account. If you set a password we never store the password itself — only a one-way hash that cannot be turned back into it. If you choose Continue with Google, Google confirms who you are and passes us your email address, whether Google has verified it, your name, a link to your Google profile picture, and an account identifier. We keep that alongside your account so you can sign back in. We do not show your name or picture anywhere in the app today, and neither can ever appear on a share card — the same rule that covers your locations. Signing in with Google gives us no access to your Gmail, Drive, contacts, or anything else in your Google account, and we never ask for it.
About location, precisely. Every photo is re-encoded from its pixels in your own browser before it is uploaded, so the file we store carries no GPS tag, no camera serial, nothing — a photo you download or share from here cannot give a spot away. Separately: if one of your photos arrived with GPS in it, we read those coordinates and keep them in your account so the map can offer to place that camera for you. Trail cameras almost never record GPS; phone photos usually do. Those coordinates, and any pin you place yourself, are locked to your account and never appear on a share card, a public link, or an image we generate.
Billing. Payments are handled by Stripe. Buying a plan gives Stripe your email address, card number, and billing details; the card number never reaches us.
What we deliberately do not collect
Your location. The site cannot read your device’s GPS at all — the browser is instructed to refuse it. Some competitors require latitude and longitude before you can upload anything; we never make you enter a coordinate, and a map pin is always optional. Tracking. No advertising trackers, no third-party analytics cookies, no session recording. Your card. Card numbers go to Stripe and never reach us, so we hold nothing a thief would want.
Where your data lives
Photos are stored with Cloudflare (R2 object storage). Account data lives in Supabase (Postgres). The site runs on Vercel. Photo sorting runs on Modal’s GPU infrastructure while a batch is being processed. Payments are handled by Stripe. Email we send you — sign-in links, receipts, account notices — goes out through Resend, which receives your address and the message. When you click a link in one of our emails, it passes through our own site first so we can count the click: we record which email it was and whether you were on a phone or a computer, never your IP address. Email you send to support is handled through Google Workspace, like most companies’ mail. These providers process data on our behalf and none of them may use your content for their own purposes.
And the honest footnote. GetBucked is run by a real person, and running the service means being able to reach the database that stores it. “Locked to your account” means no other hunter can ever see your data — it does not mean no human technically can. We look at account data only to operate the service or when you ask for help, and never at more than the question needs.
When something breaks, we get a crash report. If the app hits an error, a report goes to Sentry so we can find and fix it. It carries what broke and where in our code — never your photos, never a location, never your email, and never anything that identifies your account. Web addresses in the report are reduced to the shape of the page (“a buck page”, not which buck), and we do not record your screen.
Google is different, and only if you use it. If you sign in with Google, Google knows you signed in here, and its own privacy policy governs what it does with that. It is not processing data on our behalf the way the providers above are — it is confirming your identity to us. If you would rather Google not know, use a password or an emailed link instead; every part of the product works the same either way.
Two things leave for weather and maps, and only as coordinates. To tell you what the wind was doing at a camera rather than at the nearest airport, we ask public weather archives — NOAA and Unidata, a university-run service — for the conditions at that point. If you open the map, tile and place-search requests go to Mapbox, our map provider. Those requests carry a location and nothing else: no name, no email, no account, nothing tying the point to you. We never look up an address for a coordinate, and we never work out where you are from your IP.
Your photos are never training data without your say-so
We do not use your photos to train models unless you explicitly opt in. Confirming or correcting a sort inside your own library only affects your library.
Sharing is opt-in and location-sterile
Nothing is shared unless you create a share card yourself. Cards carry no coordinates, no map thumbnails, and no property names — ever. That rule has no exceptions and no settings toggle, on purpose.
Deletion is real
Delete a photo or a buck from inside the app and it is gone from live systems immediately — the photo bytes, the derived data, the lot. There is no undo and no recycle bin on our side.
Closing your account is a button, on the account screen. It erases the account and everything in it — photos, buck pages, every season of history. There is a 7-day window first: the account locks straight away, no photos are deleted until the window ends, and you can stop it at any point before then. Export stays open the whole time. If you are on a paid plan, closing cancels it immediately, and keeping the account afterwards does not restore it. Backups exist for disaster recovery, stored privately and encrypted at rest by our storage provider, and age out on a fixed schedule; deleted data is not restored from them except in the disaster they exist for, so a closed account can persist in a backup until that backup ages out.
A few records outlive a closed account, always with your identity detached: billing records, because a business must keep its books; reports of abuse and what we did about them, so closing an account cannot erase the record that something happened; and anonymous operational counters. Everything that says who you are is erased — including your email address itself, which is why nothing of ours can write to it afterwards.
Your rights
You can export your whole library and correct your data any time from inside the app, and delete photos, bucks, or the whole account yourself — see the note above. We do not sell or share personal information as those terms are defined under California law, so there is no “do not sell” toggle to need.
Children
This service is for adults: you must be 18 or older to hold an account, and we do not knowingly collect information from children. If you believe a child has given us information, email us and we will delete it.
Changes and contact
If this policy changes in a way that matters, we say so on this page and change the date at the top. Questions: support@getbucked.app.