Your data, your spots
Updated August 19, 2026
Your email address, which is how you sign in and the only way we can reach you about your account. The photos you upload and the basics that come with them (timestamp, image dimensions, which camera you told us they came from). The names you type — cameras, properties, bucks. Operational logs that record what the system did (a sort ran, an upload finished) without your photos or personal details in them.
How you sign in, and what that means for what we hold. There are three ways in: a password, a link emailed to you, or your Google account. If you set a password we never store the password itself — only a one-way hash that cannot be turned back into it. If you choose Continue with Google, Google confirms who you are and passes us your email address, whether Google has verified it, your name, a link to your Google profile picture, and an account identifier. We keep that alongside your account so you can sign back in. We do not show your name or picture anywhere in the app today, and neither can ever appear on a share card — the same rule that covers your locations. Signing in with Google gives us no access to your Gmail, Drive, contacts, or anything else in your Google account, and we never ask for it.
About location, precisely. Every photo is re-encoded from its pixels in your own browser before it is uploaded, so the file we store carries no GPS tag, no camera serial, nothing — a photo you download or share from here cannot give a spot away. Separately: if one of your photos arrived with GPS in it, we read those coordinates and keep them in your account so the map can offer to place that camera for you. Trail cameras almost never record GPS; phone photos usually do. Those coordinates, and any pin you place yourself, are locked to your account and never appear on a share card, a public link, or an image we generate.
When paid plans launch, payments are handled by Stripe — your card number goes to Stripe, never to us.
Your location.The site cannot read your device’s GPS at all — the browser is instructed to refuse it. Some competitors require latitude and longitude before you can upload anything; we never make you enter a coordinate, and a map pin is always optional. Tracking. No advertising trackers, no third-party analytics cookies, no session recording. Your card. Card numbers go to Stripe and never reach us, so we hold nothing a thief would want.
Photos are stored with Cloudflare (R2 object storage). Account data lives in Supabase (Postgres). The site runs on Vercel. Photo sorting runs on Modal’s GPU infrastructure while a batch is being processed. Payments are handled by Stripe. These providers process data on our behalf and none of them may use your content for their own purposes.
Google is different, and only if you use it. If you sign in with Google, Google knows you signed in here, and its own privacy policy governs what it does with that. It is not processing data on our behalf the way the providers above are — it is confirming your identity to us. If you would rather Google not know, use a password or an emailed link instead; every part of the product works the same either way.
Two things leave for weather and maps, and only as coordinates. To tell you what the wind was doing at a camera rather than at the nearest airport, we ask public weather archives — NOAA and Unidata, a university-run service — for the conditions at that point. If you open the map, tile and place-search requests go to our map provider. Those requests carry a location and nothing else: no name, no email, no account, nothing tying the point to you. We never look up an address for a coordinate, and we never work out where you are from your IP.
We do not use your photos to train models unless you explicitly opt in. Confirming or correcting a sort inside your own library only affects your library.
Nothing is shared unless you create a share card yourself. Cards carry no coordinates, no map thumbnails, and no property names — ever. That rule has no exceptions and no settings toggle, on purpose.
Delete a photo or a buck from inside the app and it is gone from live systems immediately — the photo bytes, the derived data, the lot. There is no undo and no recycle bin on our side.
Closing your account is a button, on the account screen. It erases the account and everything in it — photos, buck pages, every season of history. There is a 7-day window first: the account locks straight away, no photos are deleted until the window ends, and you can stop it at any point before then. Export stays open the whole time. If you are on a paid plan, closing cancels it immediately, and keeping the account afterwards does not restore it. Backups exist for disaster recovery, stored privately and encrypted at rest by our storage provider, and age out on a fixed schedule; deleted data is not restored from them except in the disaster they exist for, so a closed account can persist in a backup until that backup ages out.
You can export your whole library and correct your data any time from inside the app, and delete photos, bucks, or the whole account yourself — see the note above. We do not sell or share personal information as those terms are defined under California law, so there is no “do not sell” toggle to need.
If this policy changes in a way that matters, we say so on this page and, for anything significant, by email. Questions: support@getbucked.app.