Privacy policy
Last updated 1 October 2026
About this policy
Twistcam is an AI photo booth for events. Guests scan a QR code at the event, take a selfie on their own phone, and get it back as an AI-made portrait that also appears on the event's big screen. Twistcam is run by WW Solutions LLC, 75 E 3rd St, Sheridan, WY 82801, USA ("we"). This policy explains what we collect when you visit this website, run an event, or take a photo at one, what we do with it, who helps us, and how long we keep it.
Twistcam is not open yet. At the moment only this website is online. Visiting it does not create an account, and we set no cookies and run no analytics or tracking scripts on it. The rest of this policy describes the service as it will work when it opens, so that organisers and guests can read it before then.
Who is responsible
WW Solutions LLC is responsible for the personal data described here. You can reach us about anything in this policy at [email protected].
The organiser of an event decides to use Twistcam there and invites the guests. The organiser is responsible for having their guests' permission, including a parent's or guardian's permission for children.
What we collect
If you organise an event
- You sign in with Google. Google tells us your name, your email address and your profile picture. We do not receive your Google password, and we ask Google for nothing else, so we have no access to your contacts, calendar, files or email.
- The events you create and their settings.
- The email address of anyone you invite to help run an event, so that we can send them the invitation.
- A record of each purchase: what you bought, the amount, the date, and Stripe's reference for it. Stripe handles the payment itself, and we never see your full card number.
If you take a photo at an event
Guests never create an account or sign up.
- Your browser creates a random identifier and keeps it on your phone. We store it only in a scrambled form (a keyed hash) that is different for every event, so your photos at one event cannot be linked to your photos at another. We still treat it as personal data.
- The selfie you take, which we use only to make your portrait.
- Your portrait, and the name and note you type to go with it. They appear together on the event's screen and are visible to the organiser and the people helping them.
If you visit this website
We store nothing about you. Cloudflare delivers the website and sees your IP address and browser details in doing so; see Cloudflare in the list of providers below. We do not store IP addresses or use them for anything.
What we use it for
- To run the service: signing you in, running your events, turning selfies into portraits, showing them on the event screen, and letting guests download and share their own portraits and organisers download all of an event's portraits.
- To stop automated abuse of the free photos, using the scrambled device identifier and Cloudflare Turnstile.
- To send the emails the service needs, such as invitations and a reminder before an event's photos are deleted. We do not send marketing email.
- To take payments and keep the records that tax law requires.
- To count things for the organiser's dashboard and our own totals, such as photos taken and credits spent.
We do not sell personal data, show advertising, or use third-party analytics. We do not use your photos to train AI models. We use the information Google gives us only to sign you in and to contact you about your events.
If you are in the European Union or the United Kingdom, the law asks us to name the legal basis for each use. We use organisers' data to perform our contract with them. We use guests' data to make the portrait they asked for at an event they chose to join, and to keep the service safe from abuse, which are our legitimate interests. We keep purchase records because the law requires it.
Companies that process data for us
These companies handle personal data on our behalf, each for one part of the service:
- Google provides sign-in for organisers. Google's privacy policy.
- Cloudflare delivers this website and stores photos in the European Union. Its Turnstile check, which tells people from bots, sees your IP address and details about your browser and device. Cloudflare's privacy policy and Turnstile privacy addendum.
- fal.ai, in the United States, runs the AI model that turns a selfie into a portrait. We ask fal to delete its copies of every selfie and portrait after one hour and not to store our requests. fal's privacy policy.
- OVHcloud hosts our servers and database in Frankfurt, Germany. OVHcloud's privacy policy.
- Stripe takes payments. Stripe's privacy policy.
- Resend sends our emails. Resend's privacy policy.
Some of these companies are in the United States, so your data may be processed there. Each of them offers legal safeguards for such transfers, such as the European Union's standard contractual clauses.
How long we keep it
- Selfies are deleted as soon as their portrait is finished, or as soon as making it has failed. A daily clean-up removes anything left behind within two days.
- fal deletes its copies within one hour.
- Portraits, with their names and notes, are kept for 90 days after each photo was taken and then deleted automatically. Seven days before an event's first photos are due to be deleted, we email the organiser, who can download them all.
- The scrambled device identifier is kept no longer than the photos it belongs to.
- Events and organiser accounts are kept until the organiser deletes them. Deleting an event deletes its photos at once, and deleting an account deletes its events and their photos.
- Purchase records are kept as long as tax and accounting law requires.
What we store on your device
Organisers get one cookie that keeps them signed in. On a guest's phone, the browser keeps the random device identifier and the name you typed, so you don't have to type it again. If you clear your browser data, both are gone, and you can no longer delete your earlier photos yourself. Cloudflare Turnstile runs a short check in the browser to tell people from bots. We use no advertising or analytics cookies, which is why there is no cookie banner.
Your choices and rights
As a guest, you can delete your own photo from the phone that took it. It is removed from the event screen and from our storage at once. If you no longer have that phone, or you cleared your browser, ask the organiser to hide or delete the photo, or write to us.
As an organiser, you can hide or delete any photo from your events, download all of an event's photos, and delete an event or your account at any time.
Anyone can ask us for a copy of their personal data, or ask us to correct it, delete it, or stop or limit how we use it. Write to [email protected]. Guests' photos are not tied to a name or an account, so tell us the event and roughly when the photo was taken, and we will help you find it. We reply within one month. If you are in the European Union or the United Kingdom, you can also complain to your data protection authority.
Children
Organiser accounts are for adults. Guests under 18 should ask a parent before taking a photo, and the organiser is responsible for having that permission. We do not check ages.
Changes to this policy
When we change this policy, we update this page and the date at the top. If a change affects how we use organisers' data, we also email them before it takes effect.