Privacy

What is stored, who sees it, and how to get rid of it.

The short version

You can read this entire gallery without giving us anything. There is no cookie banner because there is nothing to consent to: no advertising, no tracking across sites, no profile of you. The only cookie is the one that keeps you signed in, and it is only set once you sign in. The map a photographer can use to mark where they stood loads on their own upload page and nowhere else — no page you can reach as a visitor ever contacts it.

What we store, and why

  • Your email address — if you subscribe to the list, apply to contribute, or buy a membership. It is the only identifier we hold. There is no password to store because there are no passwords: signing in is a one-time link sent to that address.
  • Your application — the name, website and note you type on the apply form, kept so we can answer it.
  • Your subscription — if you become a member, we store a Stripe customer reference and whether the subscription is live. We never see or store your card.
  • Server logs — our host records requests, including IP addresses, for a short period. We do not read them for anything but faults.

What we deliberately do not store

  • Where a photograph was taken, unless the photographer marked it themselves. The GPS block in an image file is never read and never stored — the camera and exposure are taken from the file, the coordinates are skipped. The image the gallery serves is a fresh copy that carries no metadata at all, so downloading it tells you nothing about where anybody stood. A photographer may choose to mark a spot on a map. When they do, we store two things: the point they marked, which only members see, and a deliberately blunt version of it — the centre of a square roughly a kilometre across — which is what the globe draws. Both exist because a photographer decided they should. A title, a description or a place name may be suggested by a model that has been shown the photograph — the copy that carries no metadata, not the original — and nothing it suggests is stored until the photographer has read it and saved it themselves.
  • Who looked at what. We count how many times each photograph is viewed by members, per day, so that photographers could one day be paid by what people actually look at. That count is a number against a photograph. It is not linked to you, and there is no table anywhere that could reconstruct your viewing history.

Cookies

One: gallery_session, set only when you sign in. It holds a random value that means nothing outside our database, is marked HttpOnly so no script can read it, and lasts thirty days. Signing out deletes it immediately and everywhere — sessions are stored on our side, so removing one really does end it.

Our analytics sets no cookies at all and collects nothing that identifies a person.

Who else receives it

Only the services needed to run the site. Each is bound by a data processing agreement, and none receives more than is listed here.

Vercel Inc.
Hosting and delivery
IP address and request metadata, in server logs
Neon Inc.
Database
Everything stored: addresses, photographs, subscriptions
Stripe Payments Europe Ltd.
Payments
Email address, payment details, billing country
Resend (Plain Text Inc.)
Email delivery
Email address and the contents of messages sent to it
MapTiler AG
Map tiles, on the photographer upload page only
IP address, when a signed-in photographer opens the map
Vercel AI Gateway (Anthropic, Google)
Suggested titles, descriptions, places and subjects, on the photographer upload page only
A photograph, its camera settings, and the location the photographer has typed — never the original file, and never a coordinate
Plausible Analytics
Visitor statistics
None that identifies anybody — no cookies, no cross-site tracking

Some of these are US companies. Transfers rely on the EU–US Data Privacy Framework or standard contractual clauses.

How long

Subscriptions last until you unsubscribe — every message has a link, and using it deletes your row rather than flagging it. Applications are kept while they are being considered and for a year after, so we do not ask twice. Membership records are kept for as long as tax law requires us to keep the invoice, which in Germany is ten years. Sign-in links expire after 60 minutes and can be used once.

Your rights

Under the GDPR you can ask what we hold about you, have it corrected, have it deleted, take it elsewhere, or object to it being processed at all. Write to hello@thebeautyof.earth and you will get an answer within a month, usually much sooner. Given how little is held, most requests can be answered in a sentence.

You may also complain to a supervisory authority — for us that is the data protection authority of our federal state.

Last updated 15 August 2026. Questions about any of this go to hello@thebeautyof.earth.