Skip to content
MaziFlow

How we look after your memories

Your event is yours.Here is exactly how we keep it that way.

Plain answers to the questions people ask before they upload the photos of their wedding, their child's birthday or their company's party. Nothing on this page is a marketing promise: each point describes something that is built, switched on and tested.

  1. One event, one private place

    Every event lives in its own space. Its photos and videos are tied to that event, and only that event's QR or link opens it. Nothing is listed anywhere; search engines are told to stay away from event pages, and they carry no public address a stranger could guess.

    The organiser decides who gets the QR. Guests need no app and no account; they also get no way into anyone else's event.

  2. The organiser is in control

    From the dashboard the organiser can hide or restore any photo or video, pause guest uploads, close the event early, and download everything in original quality. Guests see only what the organiser allows to be seen.

    Access to the dashboard is personal: a signed-in session on the organiser's own device. Signing out ends it; changing the password ends it on every other device too.

  3. Secure connections, private storage

    Everything between your phone, our servers and the storage travels over HTTPS. Photos and videos are stored in private object storage in the European Union (OVHcloud, France). The storage is not public: there is no listing and no permanent public address for a file.

    A phone uploads straight to that storage with a signed, single-use permission that names one file, one size and one event, and that expires. A link to view a file is signed and short-lived as well. A guessed or altered link opens nothing.

  4. What we keep, and for how long

    Photos and videos stay available for 30 days after the event date (longer only if the organiser buys an extension). We remind the organiser before the end. After it, the files are deleted from our storage by an automatic job, and the deletion is recorded.

    We keep account and order records for as long as the law requires us to. The full picture, with every period, is in the Data Retention & Deletion Policy.

  5. Backups and recovery

    The database that holds accounts, events and settings is backed up every day, encrypted before it leaves the server, and stored in a separate location (OVHcloud, Italy). A backup is counted as good only after it has been restored into a test database — a check that runs every week, automatically.

    Photos and videos live in storage built for durability, separately from that database. What we do and do not promise about recovering them is written in the retention policy, not implied.

  6. Your personal information

    We process the little we need: the organiser's email address, the event's details, the order. Guests are not asked for an account; a guest's name, if they type one, stays with their uploads inside the event.

    We use no advertising trackers and no analytics cookies. We never use anyone's photos in our own marketing without a separate, written permission from the people entitled to give it. The Privacy Policy describes every purpose and every right you have, and how to exercise it.

  7. When something is wrong

    A photo that should not be there, a privacy concern, a copyright issue: the Report a problem form reaches a person, and the content-reporting procedure says what happens next and how fast.

    Questions about your data go to the privacy address in the policy. Everything else goes to Support, from the button on every page.

What we do not claim

No system is perfectly secure, and we will not say ours is. We will say what we have built and tested, keep this page in step with the product, and tell you promptly if something ever goes wrong with your data.