Privacy Policy
Last updated: September 6, 2026
This Privacy Policy explains what personal data we collect when you use the Blue Hour mobile application, the website at bluehour.events and its subdomains, and the services provided through them (together, the “Service”), why we collect it, with whom we share it, how long we keep it, and what rights you have. In short: we collect what is needed to run a shared camera for events and to bill through Apple, and we may use cookies and similar technologies on our website and in our marketing to understand how people find us; we do not sell your data. By using the Service you confirm that you have read this Policy. If you do not agree with it, do not use the Service.
1. Personal data controller
The controller of your personal data is Mykhailo Yemchura, an individual entrepreneur registered in Ukraine (“we”, “us”, “our”). You can reach us at hello@bluehour.events. We have not appointed a data protection officer; privacy requests are handled by the operator directly.
2. Categories of personal data we collect
We process data (i) you provide directly, (ii) we receive from Apple when you sign in or pay, and (iii) we collect automatically when you use the Service.
Data you provide
- Identifiers. The name you choose to show to others; the name a guest types when joining a film; your email address if you contact us.
- Film data. Film titles, dates, reveal settings, chosen looks, capacity settings and invitation settings.
- User content. The photos and short videos you take inside a film, together with who took them and when. The app uses the camera only when you press the shutter and never reads your photo library. Photos from the browser are stripped of embedded metadata (including location) before they are stored.
- Correspondence. Anything you include when you write to us, including survey answers if you choose to give them.
Data we receive from Apple
- Sign in with Apple. A stable user identifier and, if you choose to share them, your name and email address. Apple lets you hide your email, in which case we receive a relay address.
- Purchases. Apple’s transaction record for what you bought: product, price tier, time and a transaction identifier. We never receive your card details.
Data we collect automatically
- Device identifiers. A random key generated on your device that ties it to your account (we store only a one-way hash of it), a random guest token for each film a guest joins, and installation identifiers used by our crash-reporting and analytics tools. We do not collect the advertising identifier (IDFA).
- Device and usage data. Device model, operating system version, app version, language, time zone, which features are used and whether actions such as uploads succeed.
- Diagnostics. Crash reports and performance data. Crash reports are not linked to your identity.
- Activity in a film. When you join, when you take photos, when you open the gallery. This is used to run the film and to measure whether the Service works.
- Website. The website stores a guest token in your browser’s local storage so you stay inside the films you joined, and may use the cookies and similar technologies described below.
- Advertising identifiers. Where we run advertising campaigns, we and our partners may receive advertising identifiers or hashed identifiers from ad platforms to measure whether a campaign led to an install. In the app we do not request permission to track you across other companies’ apps and websites, and we do not read the advertising identifier (IDFA) without that permission.
Cookies and similar technologies. Our website and marketing pages may use cookies, pixels, software development kits and similar technologies. They fall into four categories:
- Strictly necessary — required for the Service to work: keeping you inside the films you joined, remembering your preferences, loading content quickly and keeping the Service secure. These cannot be switched off.
- Functional — remembering choices you made, such as language, so you do not have to make them again.
- Performance — measuring how the website and app are used: which pages are visited, where visitors come from, which features are popular. This helps us decide what to improve.
- Targeting — used by us and our advertising partners to show you relevant ads for Blue Hour on other platforms and to measure whether those ads work. If you decline these, you may still see our ads, but they will be less relevant.
Where the law requires it, non-essential technologies are used only with your consent, which you can give or withdraw through the cookie banner or privacy settings on our website. You can also limit tracking in your browser and device settings.
3. Purposes and legal bases for processing
We process personal data for the purposes below. Where the GDPR or a similar law applies, the legal basis is shown for each.
| Purpose | What it involves | Data | Legal basis |
|---|---|---|---|
| Providing the Service | Creating films, letting guests join, storing and developing photos, delivering each photo to the right people at the time the host chose, enforcing film settings and limits, showing you your account. | All categories | Performance of our contract with you |
| Billing | Confirming a purchase with Apple before capacity is added to a film; keeping records of purchases. | Purchases, identifiers | Performance of our contract; legal obligation (tax and accounting) |
| Communicating with you | Notifications about your films (for example when guests join or a film reveals), replies to your messages, notices about changes to the Service or these documents. | Identifiers, film data, device identifiers | Performance of our contract; legitimate interest in keeping you informed |
| Keeping the Service working | Finding and fixing crashes, measuring whether uploads and reveals succeed, understanding which features are used so we know what to improve. | Device and usage data, diagnostics, activity in a film | Legitimate interest in maintaining and improving the Service |
| Research | Asking hosts a short question after an event, if they choose to answer, to understand whether the Service is useful. | Correspondence, film data | Consent (answering is voluntary) |
| Marketing communications | Sending you news and offers about Blue Hour by email or notification, if you agreed to receive them. You can unsubscribe at any time using the link in each message. | Identifiers | Consent, or legitimate interest where the law allows contacting existing customers |
| Advertising and measurement | Showing ads for Blue Hour on other platforms, choosing who sees them, and measuring whether an ad led to a visit or an install. | Advertising identifiers, device and usage data, cookies and similar technologies | Consent where the law requires it; otherwise legitimate interest in promoting the Service |
| Safety and abuse prevention | Detecting misuse, enforcing the Terms of Use, acting on reports about content. | All categories | Legitimate interest in protecting users and the Service |
| Legal compliance | Complying with tax, accounting and data protection law; responding to lawful requests from authorities; establishing or defending legal claims. | All categories | Legal obligation; legitimate interest in defending our rights |
Where we rely on legitimate interests, we have balanced them against your rights and concluded that the processing is what you would reasonably expect from a shared event camera and does not override your interests. You may object to processing based on legitimate interests (Section 5).
5. Your privacy rights and how to exercise them
In the app. You can change your displayed name, leave a film, delete a photo you took, turn notifications off in your device settings, and delete your account. Account deletion is described in Section 8.
By email. Write to hello@bluehour.events to:
- access the personal data we hold about you and receive a copy in a machine-readable format;
- correct inaccurate data;
- delete your data, subject to records we must keep by law;
- restrict or object to processing based on legitimate interests;
- withdraw consent where processing is based on consent, without affecting processing before withdrawal.
We respond within 30 days. To protect your data we may ask you to confirm the request from the email address linked to your account or from the device you use with the Service. You may authorise someone to act on your behalf; we may ask for proof of that authority.
EEA, UK and Switzerland. You have the rights above under the GDPR and equivalent laws, and the right to lodge a complaint with a supervisory authority, in particular in the country where you live or work. We would appreciate the chance to address your concern first.
United States. If you live in a state with a comprehensive privacy law (including California, Colorado, Connecticut, Texas, Virginia and others), you have the rights to know, access, correct, delete and obtain a copy of your personal data, and to opt out of sale, sharing and targeted advertising. To opt out of sharing for targeted advertising, use the cookie banner or privacy settings on our website where available, adjust ad settings on your device, or email us with “Do not share my personal information” in the subject line; we honour recognised opt-out preference signals where our website supports them. We do not engage in profiling with legal or similarly significant effects. We will not discriminate against you for exercising your rights. If we decline a request, you may appeal by replying to our decision with “Privacy appeal” in the subject line; we will respond within 45 days. California residents may also request, once a year, information about disclosures to third parties for their direct marketing purposes.
Advertising choices. On iPhone and iPad, you can limit ad tracking and reset your advertising identifier in Settings → Privacy & Security → Tracking and → Apple Advertising. You can also opt out of interest-based advertising from many networks at optout.aboutads.info and youronlinechoices.eu.
6. Age limitation
The Service is not intended for children under 13, or under the age set by the law of your country where that is higher. We do not knowingly collect personal data from children below that age. If you believe a child has provided us with personal data, contact us at hello@bluehour.events and we will delete it.
7. International data transfers
Our providers may process personal data in countries other than the one where it was collected, including countries whose data protection laws differ from those of your country. Where personal data of people in the EEA, the UK or Switzerland is transferred to such countries, we rely on safeguards recognised by law, such as the European Commission’s standard contractual clauses and the UK addendum, or on adequacy decisions where they exist. You may ask us for information about the safeguards used.
8. Data retention and account deletion
We keep personal data only as long as necessary for the purposes described in this Policy, then delete or anonymise it. In particular:
| Data | Kept until |
|---|---|
| Photos and videos in a film | The film is deleted by its host, or the account that hosts it is deleted and the deletion period has passed |
| Raw browser photos awaiting development | Development, typically within hours; then replaced by the developed photo |
| Account (identifier, name, email) | 30 days after you request deletion |
| Guest name and token | The film they belong to is deleted, or the guest leaves the film |
| Purchase records | As long as tax and accounting law requires, typically several years |
| Diagnostics and usage data | A limited period, after which they are deleted or aggregated |
| Correspondence | As long as needed to handle your request and to keep a record of it |
Deleting your account. You can delete your account in the app. Your access ends immediately. Within 30 days your identifiers, name and email are erased, the photos you took are deleted from storage, and your name is removed from the films you hosted. Those films stay with their guests: their photos are their data, not yours. If you sign in again within the 30 days, the deletion is cancelled. Records we must keep by law (such as purchase records) are retained for the required period and then deleted.
9. Security
Data travels between your device and our servers encrypted, and is stored by providers that encrypt data at rest. Secrets such as device keys and guest tokens are stored only as one-way hashes, so a copy of our database does not open anyone’s film. Access to production systems is limited to what running the Service requires. No system is perfectly secure; if a breach affects your personal data we will notify you and the competent authorities as the law requires.
10. Changes to this Privacy Policy
We may update this Policy from time to time. The date at the top tells you which version you are reading. If a change materially affects how we use your personal data, we will tell you in the app or by email before it takes effect. Continuing to use the Service after the change takes effect means you accept the updated Policy.
11. Contact us
For any question about this Policy, our data practices or your rights, or to exercise a right, contact us at hello@bluehour.events. Earlier versions of this Policy are available on request.