Privacy, in plain words πŸ”

Jamboree is one person's party site, not a platform. There is no ad network in here, nothing is sold, and nothing is shared with anybody who wasn't invited. Here is the whole of it β€” the comfortable parts and the awkward ones.

What this party knows about you πŸ“‡

  • Your name and email address. The host put them on the guest list β€” that is how your personal invite link found you.
  • Your answer to "are you coming?" β€” if the host switched RSVPs on for this party.
  • Anything you write: your profile blurb, your links, your comments and reactions on photos, and anything you post on the party's comment board. Board comments and reactions are stored with your account and erased the moment you delete it β€” and you can delete your own comment yourself, any time, with nothing left behind.
  • The photos and videos you upload, exactly as your phone sent them. Camera files carry hidden extras β€” the time, the camera, sometimes the location. We keep that file for the gallery's downloads, and only people at this party can reach it.
  • A login cookie. One cookie, and its only job is remembering that it's you. No analytics, no trackers, no third-party scripts β€” the pages you open here are nobody's business but this server's.
  • Knocking on a curated door: if a party asks you to knock before joining, we store your name, email and your answer to the host's question, and the host reads it to decide. If they say no, that knock is deleted 30 days later. If they say yes, you're in β€” and the host keeps your answer alongside the guest list, so they can remember who you are. Delete your account and your knocks go with it, answered or not.

Who gets to see it πŸ‘€

Guests of the same party, and nobody else. Every gallery, guest list, comment and download sits behind the same check: are you on this party's list? Search engines aren't, strangers with the URL aren't, and other parties on this server aren't.

The host sees more, because somebody has to run the thing: the full guest list including people who haven't opened their invite yet, who RSVP'd what, every photo (including ones that were taken down), and the reports guests send.

One exception worth knowing about: the host can put the gallery on a projector with a special wall link. Anything on that screen is visible to whoever is in the room, and anyone holding that link can open the wall without logging in. The host can kill the link at any time.

Face search 🀳

Take a selfie and we look for your face in a party’s photos, then show you the ones you are in. A face signature counts as biometric data, which EU and German law (GDPR Art. 9) treats as especially sensitive β€” so it is off unless you personally say yes on the consent screen, and the host cannot say yes for you.

  • πŸ”’ Your selfie becomes a "face signature" β€” a list of numbers describing your face. We keep the signature so the search has something to compare against, and throw the picture itself away.
  • πŸ–ΌοΈ Unless you ask us to keep it. Once the selfie is taken β€” camera or a chosen photo β€” we ask, picture in hand: "use this as your profile pic?". Say yes and it's stored as your avatar, the same as one you upload on your profile page; say no thanks and the picture is gone the moment the signature is made. You can change or remove an avatar from your profile page whenever you like.
  • πŸ”’ Only you see your results. We never build a browsable directory of faces, and results only ever cover parties you are a guest of.
  • πŸ—‘οΈ One tap deletes it, any time β€” from the results screen or from your profile page. Your face signature goes and the search stops working everywhere.
  • πŸ€– The honest bit: when a host turns face search on, the server measures the faces in that party's photos into anonymous numbers so a search has something to compare against. Those measurements carry no name, are never shown to anyone β€” not even the host β€” and never get grouped into "people". They are geometry, and they exist whether or not you ever search.

Getting a photo taken down πŸ™ˆ

Every guest can hide any photo β€” no explanation needed, no argument with whoever posted it. Tap "take it down" and it leaves the gallery, the projector wall, the downloads and the search results straight away, for everyone but the host. It lands on the host's moderation desk, and they can put it back or delete it for good.

What hiding cannot do, and we would rather say it than let you find out: a guest who already opened that photo may still have a copy in their browser's cache until they reload, and anyone who already downloaded or shared it has it on their own device, where this server has no reach. Hiding stops the picture going any further. It cannot travel backwards.

Your rights, and the buttons that do them ✊

GDPR gives you the right to see your data, correct it, and have it deleted. Two of those are buttons, not emails:

  • Your profile page shows what is stored about you and lets you rewrite any of it β€” name, photo, blurb, links β€” and lists every party you are on.
  • Delete your account yourself, from that same page. It takes your profile, your photo, your comments, your reactions, your place on every guest list and your face signature β€” the picture file included, not just the row that pointed at it. Nobody has to approve it and it cannot be undone.
  • Your uploads are a separate choice. By default the photos and videos you brought stay with the party β€” they belong to everyone who was there β€” with your name taken off them ("a former guest"). Tick the box while deleting and they go too.
  • Photos of you that you didn't upload: hide them (above). That is the practical version of "I'd rather not be seen".

Anything else β€” a copy of your data, a correction you can't make yourself, an objection, a complaint β€” goes to the host, who is the person legally responsible for all of this. You can also complain to your data protection authority; in Germany that is the one for the state your host lives in.

Posting pictures of other people πŸ“£

A note for hosts and for anybody with an itchy share button, because German law is specific here: under the KUG (Β§22 Kunsturhebergesetz), publishing a recognisable picture of someone generally needs their say-so. A private, invite-only gallery among the people who were at the party is not publishing. Putting that same picture on Instagram is.

Jamboree's share button hands you a watermarked copy β€” what happens next is on you, not on the server. Ask the people in the frame first. It takes five seconds and saves a friendship. πŸ’›

Where all this lives πŸ‡©πŸ‡ͺ

On your host's own server, which for this Jamboree stands in Germany. Photos, faces, comments, everything: it never goes to another company's cloud, and the face matching runs on that same machine rather than at some API somewhere.

The one thing that leaves is email β€” invites, login links, party announcements β€” which goes out through the host's mail provider, because that is what sending mail means. There is no other processor, no analytics service, no ad network.

Almost nothing is deleted on a timer: the party's photos stay until the host takes them down or you delete your account. The one exception is a knock the host turned down β€” that one goes by itself, 30 days later.

Who to talk to πŸ’Œ

Your host β€” the person who invited you and whose name is on the party. They run this server, they decide what happens to the data on it, and they are who to reply to on any invite mail with a question, a correction or a "please take that one down". No ticket system, no support queue. Just ask them.

If something on this page turns out not to match what the software actually does, that is a bug and the host wants to hear about it.