RAW Moments
PrivacyTermsCommunitySupport

RAW · PUBLIC INFORMATION

Privacy Policy

Last updated 7 August 2026

RAW is a social photo service operated by Ien Meier in Switzerland. This policy describes how the mobile app, public moment viewer, and support channels handle personal information. Contact support@rawmoments.app with privacy questions or requests.

Information RAW handles

  • Account and profile: email, username, account ID, bio, avatar, profile styling, settings, follows, followers, Close Circle membership, blocks, and recorded legal consents.
  • Content and activity: in-app camera photos, previews, capture and sharing times, captions, comments, likes, reposts, unlock grants, visibility choices, reports, and moderation records.
  • Messages: direct-message text, shared-moment references, reactions, participants, and timestamps. Messages are not end-to-end encrypted.
  • Location: after foreground permission, precise coordinates are used transiently on the device through Apple location services to derive a city-and-country label. RAW stores the label with the capture, not latitude or longitude. Provider and network logs may still contain technical request data.
  • Notifications and identifiers: Expo push token, platform, notification preferences, Supabase user ID, username, and ordinary service/security logs such as IP address, user agent, timestamps, and request URLs.
  • Device-only data: the optional camera-level guide processes motion readings on the device; RAW does not intentionally upload or store those readings. App preferences and cached images or signed URLs may remain locally until cleared, replaced, expired, or the account is deleted.

Photos and authenticity

Shareable moments start with RAW’s in-app camera; the app does not offer camera-roll upload for moments. RAW does technically crop, rotate, resize, compress, mirror, and create previews where needed. RAW therefore does not promise that files are completely unedited or unchanged.

How RAW uses information

  • Create and secure accounts; authenticate users; provide feeds, profiles, audience controls, messages, notifications, reports, blocks, unlocks, streaks, credits, and cosmetics.
  • Store, format, transmit, and display content according to user choices; create signed media links; and show eligible Public moments through public HTTPS links.
  • Prevent abuse, investigate reports, enforce rules, maintain service reliability, answer support/privacy requests, and comply with law.
  • Personalize the For You feed using activity such as follows, likes, comments, reposts, profile visits, feed impressions, and blocks. RAW does not use third-party advertising trackers in the audited release.

Who receives information

Content is shown to the audience selected by the user: Public, Followers, Close Circle, a message conversation, or a named unlock recipient. Public-link viewers may see the photo, preview, username, avatar, caption, timestamps, and attribution. Recipients can make screenshots or off-service copies.

  • Supabase provides authentication, an EU-hosted PostgreSQL database, private object storage, Edge Functions, and realtime transport.
  • Expo provides app update/build infrastructure and push-notification relay; Apple provides iOS, permission controls, notification delivery, camera/location platform services, and reverse geocoding.
  • OpenAI Sites hosts the public viewer and uses Cloudflare and other disclosed subprocessors for web hosting, infrastructure, security, content delivery, and support. They may process request URLs, IP addresses, device or browser information, caching data, security signals, and ordinary usage logs needed to operate the viewer.
  • Support/email providers, professional advisers, authorities when legally required, and a successor in a properly notified business transfer may receive necessary information.

Retention and deletion

Active account/profile/content and messages remain until the user deletes the item or account, unless a shorter product rule applies. Push tokens are removed on account deletion and replaced when refreshed. Closed reports, enforcement and support records are retained for up to 24 months; security and public-viewer logs for up to 90 days; and rotating backups for up to 35 days, subject to the provider’s configured operation and any narrower legal requirement.

In-app account deletion is at Profile → Edit profile → Account → Delete account. After the user types DELETE, RAW first removes account-owned cloud photos and avatars, then deletes the Auth user; database rows linked by cascading deletion are removed. The app then clears RAW-prefixed local cache and session keys. Deletion may not erase copies made by recipients, information already lawfully retained by others, provider backups until they rotate, or narrowly retained legal/safety/security records. If deletion fails, the account remains and the user is asked to retry.

Choices and requests

Users can change profile details and audiences, manage notifications and blocks, revoke iOS permissions, delete supported content, and delete the account in-app. To request access, correction, export, restriction, objection, or deletion where applicable, email support@rawmoments.app from the account email and state the request. RAW will verify identity using existing account information, acknowledge requests, and respond within the period required by applicable law (normally within one month where GDPR applies). RAW will explain any lawful refusal and available appeal or regulator route. Do not send passwords or identity documents unless specifically and securely requested.

Age

RAW is intended only for people aged 16 or older and requires every new user to declare that they are at least 16. RAW records the declaration and policy versions, not a date of birth. RAW does not offer parental-consent signup. If RAW reasonably learns an account belongs to someone under 16, it may restrict the account, request proportionate age confirmation, and delete the account and associated information, subject to required safety/legal preservation.

International processing, security, and changes

Ien Meier is the data controller for RAW. Supabase, OpenAI Sites, Cloudflare, Expo, Apple, and other service providers process information to provide their respective services. RAW’s primary Supabase project is hosted in the European Union (Ireland). Other providers and subprocessors may process information outside the user’s country. Where required, RAW relies on provider data-processing terms and contractual transfer safeguards. RAW uses authenticated access, row-level policies, private media storage, signed URLs, and other reasonable safeguards, but no service guarantees absolute security. Material policy changes will be communicated where required.

© 2026 Ien Meier · Support and Safety