This page describes how Confetti Albums is actually built today. It's a plain-language summary, not a substitute for our Privacy Policy or Terms of Service, which govern the relationship.
Confetti Albums handles a wedding's most personal data: the photos themselves, who's in them, and (if you opt in) the face data used to group people automatically. Here's exactly what that means in practice.
Confetti never takes custody of your photo library. Your originals live in your own Google Drive, the whole time, before, during, and after you use the app. Confetti reads the folder you connect so it can display, organize, and tag those photos. The albums you build are organized and stored as definitions inside Confetti, then viewed and shared through the app; Confetti does not modify anything in your Drive.
Confetti runs today on a single, read-only Google Drive scope:
drive.readonly: read-only access, used only to read the photos in the folder you select. Confetti cannot create, modify, or delete anything in your Drive with this permission, and does not use it to browse the rest of your Drive.Because Confetti's live scope is read-only, it does not and cannot write back to your Drive. (Google offers a separate drive.file scope that would let an app manage only the files it creates itself; Confetti does not use that scope today, so no write-back to your Drive happens.)
Because drive.readonly is classed by Google as a "restricted" scope, it requires additional Google verification, including a third-party security assessment (CASA), before it's available without limits to every new user. That verification is in progress. Today, read-only Drive access works for invited test accounts while we complete it; this doesn't change what data Confetti can access, only when the "unverified app" warning goes away for the general public. We'll update this line the day that clears.
Only the organizing layer: tags, the people you've named, album definitions, and (only with your explicit opt-in) the numeric face data used to group people across photos. Confetti does not store a duplicate copy of your photo library.
Face grouping works by computing a numeric description of each face ("an embedding"), not by storing a picture of the face on its own. This is processed only with your explicit consent; you can decline and still use the rest of the app. We use face data only to group people within your own photo set, we don't sell it, and we delete it when you delete the related content or your account. See how face tagging works for the full explanation.
Confetti uses SSO (currently Google) for sign-in. We never ask for or store a password, there is no password table to breach. Identity comes from the verified Google token; Confetti authorizes access based on your account membership and role.
X-Content-Type-Options, X-Frame-Options, a strict Referrer-Policy, and HSTS.Payments are processed by Stripe. Confetti does not store full card numbers.
We're a small, honest team, not a large enterprise vendor. We do not currently hold SOC 2, ISO 27001, or a completed third-party penetration-test report, and we won't claim otherwise. If and when that changes, we'll list it here with a way to verify it.
Closing your account removes the metadata Confetti stored, tags, people, album definitions, and face data, from our systems. Your photos were never in our custody, so they simply stay exactly where they always were, in your own Google Drive.
For anything not covered here, see the full Privacy Policy, or reach us at privacy@confettialbums.com.