Last updated: 3 August 2026 · Applies to the FreeUp Photos Android app and the freeup.photos website.
The controller of your personal data, within the meaning of Article 4(7) of the General Data Protection Regulation (GDPR), is Tomasz Kapelak Atomweb.pl, ul. Spokojna 11, 62-300 Września, Poland, NIP (EU VAT): PL7891605948.
Because we are established in Poland, this policy is governed by the GDPR together with the Polish Personal Data Protection Act of 10 May 2018. Our supervisory authority is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
You can reach us about anything in this policy at support@freeup.photos. We have not appointed a Data Protection Officer, as we are not required to; your message goes straight to the people who run the service.
FreeUp Photos exists to copy files off your phone and onto storage that belongs to you. That shapes everything below: most of the data we handle is the content you deliberately send us, and the rest is the minimum needed to give you an account, a place to put it and a way to pay for it.
The app reads photos and videos from your phone's media library and uploads them to your storage account. It uploads files as they are - we do not re-encode or strip anything, which means the embedded metadata travels with them: camera model, timestamps and, if your camera saved it, the GPS location where the photo was taken. If you would rather not store location data, turn location tagging off in your camera app before taking photos; we do not remove it, because removing it would alter your originals.
The app also records the file name, size, modification date and folder of each backed-up file. Only the folder structure and file names reach the server, as part of the upload itself; the rest stays on your phone (see 2.6).
You sign in with Google. The app receives a Google ID token, and our server verifies it
with Google and stores two things: your e-mail address and the
stable identifier Google assigns to your account (sub). We
never receive your Google password, and we ask for no access to any other Google service -
no Gmail, no Drive, no Google Photos.
Each phone gets a short name such as Pixel-8-3f9c2a1b - your phone's model,
plus eight characters derived from an identifier Android assigns to the app. It becomes
the name of that phone's folder on the server, which is how two phones on one account keep
their libraries apart. It is generated once and stored on the phone. It cannot identify
you on its own, but because it sits next to your account it counts as personal data, so we
list it here.
Subscriptions run entirely through Google Play. When you buy one, the app sends our server the purchase token and product identifier issued by Google Play; the server checks them against the Google Play Developer API and records which plan you are on, its status and its expiry date. Google also notifies our server when a subscription renews or is cancelled. Your payment details never reach us - card numbers and billing addresses are handled by Google, and we never see them.
To show you how much space you are using and to keep the storage pool sized correctly, our server periodically measures how many bytes your account occupies. This counts bytes; it does not open or read files.
Some data never leaves your device and never reaches us: the local register of what has already been backed up (used to avoid uploading the same file twice), and your storage credentials, which are held in encrypted storage with the key kept in the Android Keystore. We mention them because they are your data, not because we receive them.
Our server and the storage servers keep ordinary technical logs of connections, which include IP addresses, timestamps and the operation performed. They exist to keep the service running and to investigate abuse or faults.
| Data | Purpose | Legal basis (GDPR Art. 6) |
|---|---|---|
| Photos, videos and their metadata | Storing and returning the files you ask us to store | 6(1)(b) - performance of our contract with you |
| E-mail address, Google account identifier | Creating your account, letting you sign in, contacting you about the service | 6(1)(b) - performance of our contract with you |
| Device identifier | Keeping each phone's files in its own folder | 6(1)(b) - performance of our contract with you |
| Subscription data | Confirming your plan, applying its limits | 6(1)(b) - performance of our contract with you |
| Billing records | Meeting accounting and tax obligations under Polish law | 6(1)(c) - compliance with a legal obligation |
| Storage usage figures | Showing your usage, planning capacity | 6(1)(b) and 6(1)(f) - our legitimate interest in running the service |
| Technical logs | Security, abuse prevention, diagnosing faults | 6(1)(f) - our legitimate interest in a secure service |
| Correspondence with us | Answering you and keeping a record of what was agreed | 6(1)(b) and 6(1)(f) - our legitimate interest in handling enquiries |
Where we rely on a legitimate interest, you have the right to object - see Your rights.
We use two outside providers. Both act as processors under Article 28 of the GDPR, under a data processing agreement, and neither may use your data for their own purposes.
Your files are stored on a Storage Box rented from Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany), in their data centres in Falkenstein, Germany or Helsinki, Finland. Both are inside the European Union, so storing your files involves no transfer to a third country. Hetzner is an EU company operating under EU law, ISO 27001 certified for its data centre operations.
Every customer gets their own subaccount, isolated from other customers, with its own credentials and its own directory.
Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) and its affiliates provide the sign-in you use to identify yourself, and Google Play handles subscriptions and payments. When you sign in or buy a plan, Google processes that interaction as an independent controller under its own privacy policy, which we have no control over.
The service that issues accounts and records subscriptions runs on infrastructure at Hetzner Online GmbH, Germany. It holds the account records described in section 2 - not your files, which go directly from your phone to your storage account.
Beyond this, we disclose data only where the law requires it - for example to a court or a public authority acting within its powers.
Your files never leave the European Union. They are written to storage in Germany or Finland and stay there.
Account and subscription data can reach Google servers outside the EEA, because that is how Google's sign-in and payment infrastructure works. Google carries out those transfers under the European Commission's Standard Contractual Clauses and, for the United States, the EU–US Data Privacy Framework. This is the only category of data for which a third-country transfer arises.
| Data | Kept for |
|---|---|
| Your files | While your account is open: until you delete them - the app erases them from the server on any plan - or until 30 days after you ask us to close your account. Filling up the plan you are paying for removes nothing; it only pauses new uploads. If a paid subscription ends and is not renewed, and what you store is more than the free 1 GB allowance, we may close the account and delete the files 90 days after the subscription expired. We will tell you before that happens, and throughout those 90 days you can still download everything or take up a plan again, which cancels the deletion. Accounts that fit within the free allowance are not affected. |
| Account data | For as long as you have an account, then 30 days. |
| Billing records | 5 years from the end of the tax year they concern, as required by Polish accounting and tax law. |
| Technical logs | 3 months, then deleted. |
| Correspondence | Up to 3 years, matching the general limitation period for claims. |
The 30-day window after account closure is deliberate: it is there so that an accidental deletion, or an account closed by mistake, can still be undone.
What we do:
And the limit you should know about: this is not end-to-end encryption. Your files are encrypted while moving, but they are stored in readable form, and the credentials to your storage account are issued by us. That means we are technically capable of accessing your files, and so, in principle, is Hetzner as the operator of the hardware. We do not do so - see section 3 - but you should choose a service knowing what it can do, not only what it promises. If you need storage that even the operator cannot read, encrypt your files yourself before they are uploaded.
If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will report it to the President of the Personal Data Protection Office within 72 hours, and tell you directly where the risk is high, as required by Articles 33 and 34 of the GDPR.
Under the GDPR you have the right to:
Erasure you can carry out yourself on any plan, the free one included: the app deletes your files from the server, either this phone's folder or the whole account. On a paid plan access and portability are in your hands too - your storage is a standard account reachable over SFTP, WebDAV or Samba, so you can connect with any client and download everything, in the original files, at any time. On the free plan the app restores any file back to your phone, and for a copy of everything in some other form, just ask. All of these are your rights under the GDPR, exercising them is free, and we will never require a paid plan for any of them.
For anything else, write to support@freeup.photos. We answer within one month, and will tell you if we need longer - the GDPR allows up to three months for complex requests. Exercising these rights is free; we may charge a reasonable fee only for requests that are manifestly unfounded or excessive.
If you think we have handled your data wrongly, you can complain to the President of the Personal Data Protection Office, ul. Stawki 2, 00-193 Warsaw, Poland - uodo.gov.pl. If you live in another EU country, you can complain to your local authority instead.
This site sets no cookies and runs no analytics. It stores a single value in your browser's local storage - the language you picked, so the site opens in the same language next time. It is not shared with anyone and is strictly necessary to provide a feature you asked for. You can clear it by clearing your browser's site data.
Every file this page needs - styles, images, the "Get it on Google Play" badge - is served from our own domain. Opening this site sends no request to any third party, so nobody else learns your IP address or which page you read. There are no embedded fonts, no tag managers and no social widgets.
Our hosting provider keeps server logs, including IP addresses, for security and diagnosis, on the basis of our legitimate interest under Article 6(1)(f). We also compute aggregate visit statistics from those logs, after anonymising the IP addresses - nothing extra runs in your browser and nothing is shared with anyone.
The service is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.
When we change this policy we update the date at the top. If a change materially affects how we handle your data, we will tell you in the app or by e-mail before it takes effect, rather than relying on you to re-read the page.
support@freeup.photos - for privacy questions, requests under section 8, or anything else about this policy.