FreeUp Photos
Why Features Open access Pricing FAQ
EN PL DE ES FR

Privacy Policy

Last updated: 3 August 2026 · Applies to the FreeUp Photos Android app and the freeup.photos website.

The short version

  • Your photos and videos are stored on a storage account rented for you at Hetzner in Germany or Finland - inside the EU, never outside it.
  • We do not look inside your files: nothing is scanned, indexed, analysed for content or used to train anything.
  • There is no analytics SDK, no advertising SDK and no tracker in the app. We do not sell or share your data with data brokers.
  • Files are encrypted in transit (SFTP over SSH), on the way between your phone and your storage.
  • You can take everything with you at any time - with any SFTP, WebDAV or Samba client on a paid plan, or by asking us on the free one - and the app erases the lot from the server whenever you want, on any plan.
  1. Who is responsible
  2. What we process
  3. What we never do
  4. Who else is involved
  5. Transfers outside the EEA
  6. How long we keep it
  7. Security
  8. Your rights
  9. The website itself
  10. Children
  11. Changes
  12. Contact

1. Who is responsible for your data

The controller of your personal data, within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR), is Tomasz Kapelak Atomweb.pl, ul. Spokojna 11, 62-300 Września, Poland, NIP (EU VAT): PL7891605948.

Because we are established in Poland, this policy is governed by the GDPR together with the Polish Personal Data Protection Act of 10 May 2018. Our supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).

You can reach us about anything in this policy at support@freeup.photos. We have not appointed a Data Protection Officer, as we are not required to; your message goes straight to the people who run the service.

2. What we process, and why

FreeUp Photos exists to copy files off your phone and onto storage that belongs to you. That shapes everything below: most of the data we handle is the content you deliberately send us, and the rest is the minimum needed to give you an account, a place to put it and a way to pay for it.

2.1 Your photos and videos

The app reads photos and videos from your phone's media library and uploads them to your storage account. It uploads files as they are - we do not re-encode or strip anything, which means the embedded metadata travels with them: camera model, timestamps and, if your camera saved it, the GPS location where the photo was taken. If you would rather not store location data, turn location tagging off in your camera app before taking photos; we do not remove it, because removing it would alter your originals.

The app also records the file name, size, modification date and folder of each backed-up file. Only the folder structure and file names reach the server, as part of the upload itself; the rest stays on your phone (see 2.6).

2.2 Your account

You sign in with Google. The app receives a Google ID token, and our server verifies it with Google and stores two things: your e-mail address and the stable identifier Google assigns to your account (sub). We never receive your Google password, and we ask for no access to any other Google service - no Gmail, no Drive, no Google Photos.

2.3 Your device identifier

Each phone gets a short name such as Pixel-8-3f9c2a1b - your phone's model, plus eight characters derived from an identifier Android assigns to the app. It becomes the name of that phone's folder on the server, which is how two phones on one account keep their libraries apart. It is generated once and stored on the phone. It cannot identify you on its own, but because it sits next to your account it counts as personal data, so we list it here.

2.4 Your subscription

Subscriptions run entirely through Google Play. When you buy one, the app sends our server the purchase token and product identifier issued by Google Play; the server checks them against the Google Play Developer API and records which plan you are on, its status and its expiry date. Google also notifies our server when a subscription renews or is cancelled. Your payment details never reach us - card numbers and billing addresses are handled by Google, and we never see them.

2.5 Storage usage

To show you how much space you are using and to keep the storage pool sized correctly, our server periodically measures how many bytes your account occupies. This counts bytes; it does not open or read files.

2.6 What stays on your phone

Some data never leaves your device and never reaches us: the local register of what has already been backed up (used to avoid uploading the same file twice), and your storage credentials, which are held in encrypted storage with the key kept in the Android Keystore. We mention them because they are your data, not because we receive them.

2.7 Technical logs

Our server and the storage servers keep ordinary technical logs of connections, which include IP addresses, timestamps and the operation performed. They exist to keep the service running and to investigate abuse or faults.

2.8 The legal basis for each of these

DataPurposeLegal basis (GDPR Art. 6)
Photos, videos and their metadata Storing and returning the files you ask us to store 6(1)(b) - performance of our contract with you
E-mail address, Google account identifier Creating your account, letting you sign in, contacting you about the service 6(1)(b) - performance of our contract with you
Device identifier Keeping each phone's files in its own folder 6(1)(b) - performance of our contract with you
Subscription data Confirming your plan, applying its limits 6(1)(b) - performance of our contract with you
Billing records Meeting accounting and tax obligations under Polish law 6(1)(c) - compliance with a legal obligation
Storage usage figures Showing your usage, planning capacity 6(1)(b) and 6(1)(f) - our legitimate interest in running the service
Technical logs Security, abuse prevention, diagnosing faults 6(1)(f) - our legitimate interest in a secure service
Correspondence with us Answering you and keeping a record of what was agreed 6(1)(b) and 6(1)(f) - our legitimate interest in handling enquiries

Where we rely on a legitimate interest, you have the right to object - see Your rights.

3. What we never do

  • We do not look inside your files. Nothing is scanned for content, indexed, run through image recognition, or used to train a model. The only thing our systems do with your files is count their bytes and, during a server-side move, verify checksums.
  • We do not profile you and make no automated decisions that produce legal effects for you, within the meaning of Article 22 of the GDPR.
  • We do not sell, rent or share your data with data brokers, advertisers or anyone building marketing profiles.
  • The app contains no analytics, advertising or attribution SDK. There is no Firebase, no Crashlytics, no third-party crash reporter. The app talks to our server, to your storage server and to Google Play, and to nothing else.

4. Who else is involved

We use two outside providers. Both act as processors under Article 28 of the GDPR, under a data processing agreement, and neither may use your data for their own purposes.

Hetzner - where your files live

Your files are stored on a Storage Box rented from Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany), in their data centres in Falkenstein, Germany or Helsinki, Finland. Both are inside the European Union, so storing your files involves no transfer to a third country. Hetzner is an EU company operating under EU law, ISO 27001 certified for its data centre operations.

Every customer gets their own subaccount, isolated from other customers, with its own credentials and its own directory.

Google - sign-in and payments

Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) and its affiliates provide the sign-in you use to identify yourself, and Google Play handles subscriptions and payments. When you sign in or buy a plan, Google processes that interaction as an independent controller under its own privacy policy, which we have no control over.

Our own server

The service that issues accounts and records subscriptions runs on infrastructure at Hetzner Online GmbH, Germany. It holds the account records described in section 2 - not your files, which go directly from your phone to your storage account.

Beyond this, we disclose data only where the law requires it - for example to a court or a public authority acting within its powers.

5. Transfers outside the EEA

Your files never leave the European Union. They are written to storage in Germany or Finland and stay there.

Account and subscription data can reach Google servers outside the EEA, because that is how Google's sign-in and payment infrastructure works. Google carries out those transfers under the European Commission's Standard Contractual Clauses and, for the United States, the EU–US Data Privacy Framework. This is the only category of data for which a third-country transfer arises.

6. How long we keep it

DataKept for
Your files While your account is open: until you delete them - the app erases them from the server on any plan - or until 30 days after you ask us to close your account. Filling up the plan you are paying for removes nothing; it only pauses new uploads.

If a paid subscription ends and is not renewed, and what you store is more than the free 1 GB allowance, we may close the account and delete the files 90 days after the subscription expired. We will tell you before that happens, and throughout those 90 days you can still download everything or take up a plan again, which cancels the deletion. Accounts that fit within the free allowance are not affected.
Account data For as long as you have an account, then 30 days.
Billing records 5 years from the end of the tax year they concern, as required by Polish accounting and tax law.
Technical logs 3 months, then deleted.
Correspondence Up to 3 years, matching the general limitation period for claims.

The 30-day window after account closure is deliberate: it is there so that an accidental deletion, or an account closed by mistake, can still be undone.

7. Security - and its honest limits

What we do:

  • Everything the app sends travels over SFTP (SSH) between your phone and your storage, and over HTTPS between the app and our server - nothing the app sends goes unencrypted. WebDAV, if you switch it on, runs over HTTPS too. Samba/SMB is the exception, which is why it stays off until you turn it on yourself.
  • The app remembers your server's host key on first connection and refuses to connect if it later changes, which is what stops someone from impersonating your storage server.
  • Storage credentials on your phone are held in encrypted storage with the key in the Android Keystore, not in plain settings.
  • Each customer has an isolated storage subaccount with credentials that reach only their own directory.
  • Deleting a photo from your phone through the app happens only after the app has compared SHA-256 checksums and confirmed the copy on the server is byte-for-byte identical.

And the limit you should know about: this is not end-to-end encryption. Your files are encrypted while moving, but they are stored in readable form, and the credentials to your storage account are issued by us. That means we are technically capable of accessing your files, and so, in principle, is Hetzner as the operator of the hardware. We do not do so - see section 3 - but you should choose a service knowing what it can do, not only what it promises. If you need storage that even the operator cannot read, encrypt your files yourself before they are uploaded.

If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will report it to the President of the Personal Data Protection Office within 72 hours, and tell you directly where the risk is high, as required by Articles 33 and 34 of the GDPR.

8. Your rights

Under the GDPR you have the right to:

  • Access your data and receive a copy (Art. 15).
  • Rectify anything inaccurate (Art. 16).
  • Erasure - have your data deleted (Art. 17).
  • Restrict how we process it (Art. 18).
  • Portability - receive your data in a machine-readable format, or have it sent to another provider (Art. 20).
  • Object to processing based on our legitimate interest (Art. 21).
  • Complain to a supervisory authority (Art. 77).

Erasure you can carry out yourself on any plan, the free one included: the app deletes your files from the server, either this phone's folder or the whole account. On a paid plan access and portability are in your hands too - your storage is a standard account reachable over SFTP, WebDAV or Samba, so you can connect with any client and download everything, in the original files, at any time. On the free plan the app restores any file back to your phone, and for a copy of everything in some other form, just ask. All of these are your rights under the GDPR, exercising them is free, and we will never require a paid plan for any of them.

For anything else, write to support@freeup.photos. We answer within one month, and will tell you if we need longer - the GDPR allows up to three months for complex requests. Exercising these rights is free; we may charge a reasonable fee only for requests that are manifestly unfounded or excessive.

If you think we have handled your data wrongly, you can complain to the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland - uodo.gov.pl. If you live in another EU country, you can complain to your local authority instead.

9. The website itself

This site sets no cookies and runs no analytics. It stores a single value in your browser's local storage - the language you picked, so the site opens in the same language next time. It is not shared with anyone and is strictly necessary to provide a feature you asked for. You can clear it by clearing your browser's site data.

Every file this page needs - styles, images, the "Get it on Google Play" badge - is served from our own domain. Opening this site sends no request to any third party, so nobody else learns your IP address or which page you read. There are no embedded fonts, no tag managers and no social widgets.

Our hosting provider keeps server logs, including IP addresses, for security and diagnosis, on the basis of our legitimate interest under Article 6(1)(f). We also compute aggregate visit statistics from those logs, after anonymising the IP addresses - nothing extra runs in your browser and nothing is shared with anyone.

10. Children

The service is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.

11. Changes to this policy

When we change this policy we update the date at the top. If a change materially affects how we handle your data, we will tell you in the app or by e-mail before it takes effect, rather than relying on you to re-read the page.

12. Contact

support@freeup.photos - for privacy questions, requests under section 8, or anything else about this policy.

© 2026 FreeUp Photos
Home Contact Google Play Polski Deutsch Español Français