Confetti Albums
Features Guides Blog Pricing Get started free

Security & Privacy

Last updated: 9 July 2026

This page describes how Confetti Albums is actually built today. It's a plain-language summary, not a substitute for our Privacy Policy or Terms of Service, which govern the relationship.

Confetti Albums handles a wedding's most personal data: the photos themselves, who's in them, and (if you opt in) the face data used to group people automatically. Here's exactly what that means in practice.

Your photos stay in your own Google Drive

Confetti never takes custody of your photo library. Your originals live in your own Google Drive, the whole time, before, during, and after you use the app. Confetti reads the folder you connect so it can display, organize, and tag those photos. The albums you build are organized and stored as definitions inside Confetti, then viewed and shared through the app; Confetti does not modify anything in your Drive.

What permission does Confetti actually request?

Confetti runs today on a single, read-only Google Drive scope:

  • drive.readonly: read-only access, used only to read the photos in the folder you select. Confetti cannot create, modify, or delete anything in your Drive with this permission, and does not use it to browse the rest of your Drive.

Because Confetti's live scope is read-only, it does not and cannot write back to your Drive. (Google offers a separate drive.file scope that would let an app manage only the files it creates itself; Confetti does not use that scope today, so no write-back to your Drive happens.)

Because drive.readonly is classed by Google as a "restricted" scope, it requires additional Google verification, including a third-party security assessment (CASA), before it's available without limits to every new user. That verification is in progress. Today, read-only Drive access works for invited test accounts while we complete it; this doesn't change what data Confetti can access, only when the "unverified app" warning goes away for the general public. We'll update this line the day that clears.

What Confetti stores on its own servers

Only the organizing layer: tags, the people you've named, album definitions, and (only with your explicit opt-in) the numeric face data used to group people across photos. Confetti does not store a duplicate copy of your photo library.

Face data, opt-in and limited

Face grouping works by computing a numeric description of each face ("an embedding"), not by storing a picture of the face on its own. This is processed only with your explicit consent; you can decline and still use the rest of the app. We use face data only to group people within your own photo set, we don't sell it, and we delete it when you delete the related content or your account. See how face tagging works for the full explanation.

Sign-in and account security

Confetti uses SSO (currently Google) for sign-in. We never ask for or store a password, there is no password table to breach. Identity comes from the verified Google token; Confetti authorizes access based on your account membership and role.

Application hardening

  • Security headers on every response, including a Content Security Policy, X-Content-Type-Options, X-Frame-Options, a strict Referrer-Policy, and HSTS.
  • Rate limiting on write and expensive endpoints.
  • User-supplied text is HTML-escaped before rendering, to prevent script injection.
  • Every request to build or save an album is scoped to the signed-in account; each account's data is isolated from every other account's.
  • The app runs behind an HTTPS reverse proxy; it is never directly exposed to the internet on its own.

Payments

Payments are processed by Stripe. Confetti does not store full card numbers.

What we don't claim

We're a small, honest team, not a large enterprise vendor. We do not currently hold SOC 2, ISO 27001, or a completed third-party penetration-test report, and we won't claim otherwise. If and when that changes, we'll list it here with a way to verify it.

Deleting your account

Closing your account removes the metadata Confetti stored, tags, people, album definitions, and face data, from our systems. Your photos were never in our custody, so they simply stay exactly where they always were, in your own Google Drive.

Questions

For anything not covered here, see the full Privacy Policy, or reach us at privacy@confettialbums.com.

Guides Pricing Privacy Terms Security
© Confetti Albums · your most precious moments, in albums worth keeping.