Privacy Policy
Preparing for publication: this describes the current features and data handling. Operator details, retention periods and reasons, and the support process still require confirmation before public release.
Web deletion portal (pre-release)
The Web uses Google identity and email verification only for deletion. It does not create a general login session or a new ito account. Only owned/joined album counts needed for deletion are displayed. Users who own albums can submit a deletion request recording the verified email, user ID, album counts, receipt time and status. Receipt is not deletion completion. Operator processing, notification procedures and retention of intake records require approval before release.
Account deletion safety checks
Dedicated deletion verification records the target account and sessions, verification method and time, expiry and usage state on the server to prevent reuse and duplicate execution. This verification record does not store Google access tokens. Deletion permission expires after 10 minutes. Expired verification records are eligible for cleanup, but records for interrupted deletions are not immediately erased because their execution status needs investigation. Operational cleanup and incident handling for these records also require confirmation before public release.
Account information
When you sign in with Google, we receive information such as your Google identifier, name, email address, verification status and profile image. ito stores the connection information, authentication tokens, login sessions and language preference. Sessions may include IP addresses and browser information. ito does not receive your Google password.
Albums, submissions and sharing
We store album information, memberships, invitations and transfers, submitter names, photos, videos, messages and associated information. Submission links can be used without an ito account. Depending on permissions and sharing settings, administrators, members and people with a sharing link can view or download content. PC display uses a separate link from ordinary sharing. Take care when distributing links.
Usage, purchases and diagnostics
We aggregate submission counts, storage usage, shared views and downloads. If you use purchasing features, records include transaction IDs, products, status, albums and payer IDs. We also process hashes derived from information such as IP addresses to limit abusive attempts, authentication/API logs and operator records. No third-party advertising or behavioral analytics SDK was found in the reviewed app code; hosting logs and configuration are managed separately.
Purposes and service providers
This information supports authentication, submissions, album sharing, display and downloads, membership and permissions, purchase and capacity management, limiting abusive attempts and troubleshooting. We use Google authentication and Cloudflare Web/API hosting, databases and media storage. Where in-app purchases are available, purchase information is also exchanged with Apple or Google stores. Those providers' policies also apply to their processing.
Storage, retention and account deletion
Deletion removes the ito user, sessions and OAuth connections, and runs cleanup for non-owner memberships and join requests. Some cleanup records may remain if an operation fails. You cannot delete an account that still owns albums. Active invitations and incoming transfers are stopped, but names, emails and user IDs in their history are not automatically anonymized. Purchase history including payer IDs, usage totals and operator records are not deleted by this action. Retention periods and reasons, infrastructure logs and backups still require review before public release. This does not assert an established statutory retention period.
Submissions to other albums and saved copies
Submissions are not stored against an account ID, so photos, videos, messages and submitter names in other people's albums cannot be deleted in bulk by account. Ask the album administrator about deletion. Account deletion does not remove files downloaded by other people or copies saved on devices.
Contact / unable to use the app
The public operator contact channel is being prepared. See the dedicated account deletion page. Processing and notification procedures, and handling individual content or retained-record requests, still require confirmation before release. You can also ask the album administrator about content deletion.