Privacy Policy
Last updated: 16 September 2026
Roger & Mary is a private photo-sharing service for families. You share photos in private circles that people join by invitation. Keeping the photos you share private is the reason the service exists. This policy explains what we collect, why, who can see it, and the choices you have.
This policy covers the Roger & Mary website (www.rogerandmary.com), its French edition Hubert & Odette (www.hubertetodette.fr), and the Roger & Mary mobile app for Android and iOS. Together we call them the Service. We, us and our mean the operator of Roger & Mary, which is the data controller for your personal data.
1. Information we collect
Account information
- Your first name, last name and email address.
- Your password. We only store it in a hashed (encrypted) form and can never read it.
- Your preferred language.
Profile information you choose to add
- Gender, date of birth, postal address (street, postcode, city) and phone number.
- A profile picture.
- Family relationships with other members (for example, "sister" or "grandfather").
Content you share
- Photos you upload, and the circles you share them with.
- Details you or other members add to a photo: date or period, place name, event name, and the people tagged on it.
- Comments.
- Photo files can contain information recorded by the camera or phone (EXIF metadata), such as the date taken, the device model and, if location tagging was on, where the photo was taken. The mobile app never asks for your location. But if the file you choose already contains this information, it may be stored with the photo.
Information about other people
When you invite a relative or tag someone on a photo, you may give us their first and last name, email address, phone number, gender and family relationship. We use this only to invite that person, send them the notifications the Service needs, and show who appears on a photo. Only share someone's details if you are entitled to do so. Anyone whose details were added this way can contact us to have them removed.
Device and technical information
- Push notification token: if you allow notifications, the app registers a token with Google Firebase Cloud Messaging so we can send you alerts about new photos and comments.
- Device identifier: when you open a sign-in link in the app, we use an identifier generated by your device to check that the link is used securely.
- Sign-in tokens: the app keeps your session tokens, user ID and email address on your device so that you stay signed in. They are removed when you sign out.
- Server logs: like most online services, our servers record technical data such as IP address, browser or device type, the pages or features requested, and the date and time. We use these logs for security and troubleshooting.
Messages you send us
If you send feedback, a support request or an account deletion request, we receive your message together with your name, email address, user ID (if you are signed in), IP address and device/browser type.
What we do not collect
We do not access your contacts. We do not track your location, and we do not use advertising identifiers. The app contains no analytics, advertising or crash-reporting tools.
Device permissions
- Photos / camera: used only when you choose a picture to upload or take a profile photo.
- Notifications: used to alert you about activity in your circles. You can turn them off at any time in your device settings, or mute a single circle in the app.
2. How we use your information
- To provide the Service: create and secure your account, store your photos, and show them to members of the circles you share them with. We also let members tag, date, locate and comment on photos.
- To communicate with you: send invitations, sign-in and password-reset links, activity notifications and summary emails, and replies to your messages.
- To keep the Service safe: prevent fraud and abuse, investigate problems and enforce our Terms of Use.
- To improve the Service: using the feedback you choose to send us.
- To meet legal obligations: for example, responding to lawful requests from authorities.
We do not sell your personal data. We do not use it for advertising, and we do not make automated decisions about you that have legal or similarly significant effects.
3. Legal bases (EU and UK users)
- Contract: to provide the Service you signed up for.
- Legitimate interests: to keep the Service secure, to prevent abuse, and to improve it based on feedback.
- Consent: for push notifications and access to your photos or camera. You can withdraw consent at any time in your device settings.
- Legal obligation: where the law requires us to keep or disclose information.
4. Who can see your information
Other members
- Photos, and the details attached to them, are shown only to members of the circles the photo is shared with, according to each member's role in that circle. For example, a "friend" of a circle only sees photos they are tagged on or have posted.
- Comments are visible to people who share a circle with both the photo and the comment's author.
- Your name, profile picture and shared circles are visible to members of your circles. Profile details such as your email address, date of birth, postal address and relationships may also be visible to them.
- Photo files are delivered from our cloud storage through direct links. Please do not copy these links outside the Service, as anyone who has a link may be able to open that image.
Service providers
We use a small number of providers who process data on our behalf, only as needed to run the Service:
- Amazon Web Services hosts our servers, stores photos in its Paris (EU) region, and delivers files.
- Google Firebase Cloud Messaging delivers push notifications to your device.
- Our email delivery provider sends invitations, sign-in links and notifications.
Legal reasons
We may disclose information if the law requires it, or to protect the rights, property or safety of our users, the public or us.
5. Where your data is stored
Your data is stored in the European Union. Some providers, such as Google for push notifications, may process limited data outside the EU. Where they do, they rely on safeguards approved by the European Commission, such as Standard Contractual Clauses.
6. How long we keep your data
- We keep your account and content for as long as your account is active.
- Photos or comments you delete are removed from the Service straight away.
- When your account is deleted, we delete your personal data as described on our account deletion page. We action deletion requests within 7 working days.
- Copies held in backups and server logs are removed as those backups and logs are routinely overwritten.
- We keep a minimal record of the deletion request (email address, date and reference) to show that we handled it. We may also keep data where the law requires it.
7. Your rights
Depending on where you live, you have the right to:
- access your personal data and receive a copy of it;
- correct inaccurate data (you can edit most of your profile yourself in the app or on the website);
- have your data deleted;
- object to or restrict certain processing;
- receive your data in a portable format;
- withdraw consent at any time.
To exercise these rights, email thomasjestin@gmail.com. We may ask you to confirm your identity before acting on your request. You also have the right to complain to your data protection authority, such as the CNIL in France (www.cnil.fr) or the ICO in the United Kingdom (ico.org.uk).
8. Deleting your account
You can ask us to delete your account and associated data, or only some of your data, at any time using the form at https://staging.rogerandmary.com/delete-account. Every request is reviewed and actioned within 7 working days. You can also remove individual photos and comments yourself at any time.
9. Security
We use encrypted connections (HTTPS), store passwords only in hashed form, and use expiring access tokens for the app. Only authorised people can access our systems. No online service can guarantee complete security, so please keep your password private and tell us straight away if you think your account has been compromised.
10. Children
You must be at least 16 years old to create an account. Families often share photos of children. If you post a photo of a child, you are responsible for making sure you have the right to share it, for example as a parent or with a parent's permission. A parent or guardian can ask us to remove a photo of their child at any time.
11. Changes to this policy
We may update this policy from time to time. When we do, we will change the "Last updated" date above. If the changes are significant, we will let you know by email or in the Service before they take effect.
12. Contact us
For any question about this policy or your personal data, email thomasjestin@gmail.com.