Section 01
Plain-language summary
Your RAW files, local previews, culling decisions, and ordinary desktop work stay on your machine. Cullibrate does not upload them as part of culling.
When you deliberately create a Client Gallery, Cullibrate uploads one privacy-scrubbed source JPEG and four responsive JPEG renditions per photo, plus the small Gallery settings needed to deliver them. You choose open-link or shared-password access, whether downloads are off, web-size, or original, and when to delete the Gallery.
Section 02
Data we collect
Account data: your email, profile, plan and entitlement state, and authentication-provider identifiers. Cullibrate does not receive your Clerk password.
Website analytics: aggregated page views, performance metrics, error reports. We do not sell or share this data.
Desktop app: ordinary culling does not transmit file paths, filenames, previews, RAW data, or photo contents. A Gallery upload sends only the selected completed JPEG content, its four prepared JPEG renditions, opaque identifiers, and the small settings required to publish it.
Gallery service: Cloudflare holds photo, object, upload, progress, delivery, and recovery material. Convex holds only the account-owned Gallery control record and aggregate counts or byte totals; it does not store per-photo or per-object material.
Partner programme: if you participate, we collect registered promotion post URLs and notes, plus payout contact details and the legal and tax evidence needed to administer payouts.
Section 03
How we use that data
To deliver builds and notify you of new releases.
To answer your support emails.
To create, secure, deliver, manage, recover, and delete the Client Galleries you request.
To improve the website experience (loading speed, broken pages, accessibility).
Section 04
Gallery media and metadata
Before upload, Cullibrate applies orientation, converts display output to sRGB, and re-encodes a source JPEG plus 640, 1280, 2560, and 3840 pixel JPEG renditions. This removes EXIF, GPS, camera-owner, embedded thumbnail, editing, and comment metadata from the uploaded copies.
Gallery media is stored in private Cloudflare R2 storage and coordinated by Cloudflare Workers and Durable Objects. Clients receive only capability-checked, short-lived access through the Gallery media service; storage buckets and object listings are never public.
Anyone with the link can open an open-link Gallery and can forward that link. Shared-password Galleries require the separately supplied password. Search-engine directives are not treated as access control.
Section 05
Gallery client data
Clients do not need an account. After open-link or shared-password admission, the browser receives a separate random session for that Gallery only. It expires within seven days, grants no access by itself, and is not linked to an email address, Cullibrate account, IP address, User-Agent, or device fingerprint. A client may add reversible Favorites and plain-text Comments with a chosen display name to photographs. The photographer sees bounded page-open and download-start estimates, Favorite counts, and Comment content, display name, photograph position, date, and moderation state, but no client session identifier; page opens are not unique-client counts. The client can permanently erase the current browser session and its page-open history, download-start history, Favorites, and Comments; reopening creates a new unrelated session.
When the photographer enables downloads, a client can download a privacy-scrubbed 2560-pixel web-size JPEG or privacy-scrubbed source JPEG according to the Gallery policy. If the photographer separately enables Download all, Cullibrate can asynchronously prepare a Gallery ZIP from those permitted copies. A completed ZIP is available for 24 hours; partial and expired packages are not exposed.
Unpublish, expiry, and trash revoke client access. Trash retains a seven-day owner recovery window; permanent deletion removes active media and retains encrypted recovery copies only until their deletion deadline.
Section 06
Third parties
Clerk provides account authentication and identity sessions.
Netlify hosts the website and authenticated Gallery management shell.
Convex stores account ownership and thin Gallery control records with aggregate counts and byte totals only.
Cloudflare Workers, Durable Objects, and private R2 buckets own Gallery photo objects, upload progress, admission, delivery, deletion, and delayed recovery cleanup.
Our analytics and error-monitoring providers receive bounded product, performance, and error events. We exclude Gallery passwords, signed links, photo contents, filenames, and unnecessary client identity.
Section 07
Your rights
You can request a copy of your account data, ask us to delete it, or correct it at any time.
Gallery clients can ask the photographer or contact Cullibrate about Gallery access or deletion without creating an account.
Email contact@cullibrate.com and we'll respond directly.
Section 08
Contact
contact@cullibrate.com for any privacy question, request, or complaint.