Skip to content

Privacy Policy

Last updated: 25 August 2026

Introduction

This policy explains what Melora does with your information, in the order you are likely to care about it: who we are, what we hold, why we are allowed to hold it, who else touches it, and what you can make us do about it. It covers this website, the host dashboard and every event gallery.

Who is responsible for your data

Melora is run from Croatia by one independent developer, and that person is the data controller for everything described here. There is no registered company behind the Service yet; when there is, its name, address and registration number will replace this paragraph. Until then there is no privacy department to route you through. Write to [email protected] and the person responsible reads it. If you think we have handled your data badly you can also complain to a data protection authority, which in Croatia is AZOP, the Personal Data Protection Agency.

Information we collect

Account information

  • Email address
  • Name, if you give one
  • Password, stored only as a salted hash
  • Which events you own, and what you have done with them

Event information

  • Event name, date and description
  • Photos, video and voice notes uploaded by you and your guests
  • The name a guest types when they arrive, if they type one
  • Whether a photo has been approved, rejected or liked

Technical information

  • IP address, used to apply rate limits and to block abuse
  • Browser and device details, sent by your browser with every request
  • Which page was viewed, stored without anything that identifies you (see below)
  • Error and access logs kept on our own server

Why we are allowed to hold it

Under the GDPR every use of your data needs a legal basis. Ours are:

  • Running your event and your account, which is the contract between us
  • Taking payment, and keeping the records that tax law requires of us
  • Keeping the Service secure and stopping abuse, which is our legitimate interest and yours
  • Anything optional, such as a message you choose to receive, which is your consent and which you can withdraw at any time

Your event, and your guests' photos

For an event you create, you decide who gets the code, what stays in the gallery and when it goes. We hold that material and act on your instructions, which under data protection law makes you the controller for it and us the processor. If a guest asks us to remove something they uploaded, we will pass it to you as the host, and we will act ourselves where the law requires it. If you are a guest and cannot reach the host, write to us anyway.

How we use your information

We use your information to:

  • Run your event and show your gallery to the people you shared it with
  • Process your payment and send you a receipt
  • Send the emails the Service has to send: verification, password resets, event links
  • Answer you when you write to us
  • Find and fix faults, and see which pages people read
  • Detect and prevent fraud or abuse

Photo storage and processing

Photos uploaded to Melora are:

  • Stored on servers and object storage in Germany, inside the EU
  • Processed to create the smaller versions the gallery displays
  • Reachable only through your gallery code or a link you shared, never listed publicly and never indexed
  • Never used for advertising, never sold, and never used to train anything
  • Kept until you ask us to remove them — we do not delete them automatically

How we count visits

We measure traffic on our own marketing pages, and we do it without following anyone. There is no cookie, no advertising network and no third-party script: the counting happens on our own server. A visit is recorded as a one-way hash of your IP address and browser details with the current date mixed into the key, so the same person counts differently tomorrow and the records cannot be joined up across days, even by us. We store which page was read, with the language prefix stripped, and nothing else. It is why we cannot tell whether you have been here before, and we think that is the right trade.

Who else touches your data

We do not sell your personal information and we do not share it for anyone else's marketing. To run the Service we rely on these companies, and no others:

  • Stripe: takes the payment. Your card details go to Stripe, not to us, and we never see or store a card number.
  • Hetzner (Germany): provides the servers, the object storage and the backups. Your photos, your account and the database live here, in the EU.
  • Cloudflare: sits in front of the site to protect it from attacks and to serve images quickly, so traffic passes through it.
  • Titan: delivers the email we send you, and hosts our own mailbox.
  • Legal requirements: we will hand over data where the law genuinely requires it, and we will tell you unless we are forbidden to.
  • A future sale of the business: if Melora is ever sold or merged, this data would move with it, under this same policy until you are told otherwise.

Where your data is

Your photos, your account and our backups are in Germany and stay in the EU. Two of the providers above, Stripe and Cloudflare, are part of international groups and some of their processing can happen outside the EU; where it does, it is covered by the European Commission's standard contractual clauses. We do not move your photographs out of the EU for any other reason.

How long we keep it

Different things have different lifespans:

  • Photos and event data: for the gallery period in your plan, and after that until you ask us to remove them. Nothing is deleted automatically.
  • Your account: for as long as you keep it. Delete it and we close it and end every session immediately.
  • Payment and invoice records: for as long as tax and accounting law requires us to keep them, which is longer than the rest and is not something we can shorten.
  • Server logs: a short rolling window, kept for security and for debugging.
  • Visit counts: indefinitely, because after the hashing described above they are no longer about a person.

Data security

We implement appropriate security measures to protect your information, including:

  • Encrypted connections (HTTPS) for everything you and your guests send us
  • Passwords stored only as salted hashes, never in a form anyone can read
  • Galleries reachable only through your own code or link, never listed publicly
  • Rate limiting and abuse protection on sign-in and uploads
  • Servers and backups in the EU (Germany)

Your rights

The GDPR gives you the rights below, and you exercise all of them by writing to [email protected]. We answer within a month, usually the same week, and we do not charge for it.

  • See what we hold about you
  • Correct anything that is wrong
  • Have your data deleted, and your account closed with it
  • Get a copy of your photos and your data to take elsewhere
  • Object to a use we have based on our legitimate interest, or ask us to restrict it
  • Withdraw consent you gave, without that affecting what was done before
  • Complain to a supervisory authority, which in Croatia is AZOP

Cookies

We use three cookies and none of them follow you. One keeps you signed in, one remembers whether you chose English or Croatian, and Stripe sets its own on the payment step to detect fraud. There is no advertising cookie, no analytics cookie and no third-party tracker, which is also why this site does not greet you with a consent banner.

Children's privacy

Melora is not for children. You must be at least 16 to create an account. A guest uploading to a gallery does not create one, and we do not knowingly collect anything from a child. If you believe a child's data has ended up with us, write to us and we will remove it.

Changes to this policy

We may update this policy. If a change matters to you we will tell you by email or in the app before it takes effect, and the date at the top of this page always says when it was last touched.

Contact us

For any question about this policy, or to exercise any of the rights above, write to [email protected].