Last updated: August 3, 2026
Honeyfell is how a photographer delivers private photo galleries to their clients. This policy explains what happens with your data when you open a gallery link a photographer has shared with you, or use the app.
To make gallery favorites, view counts, and save counts work, the app stores a small amount of anonymous information: a random device identifier generated the first time you open a gallery, which images you favorite, how many times a gallery has been opened, and whether photos were saved. None of this is connected to your identity — it only lets the photographer see engagement, not who was engaging.
If something in the app breaks, an anonymous crash report may be recorded so it can be fixed. Crash reports contain no identity, and gallery links are stripped out before anything is stored.
To screen out spam and abuse, our servers briefly use your IP address for rate limiting. These records are automatically deleted within a day and are never used for anything else.
When you order prints from a gallery, you provide your name, email address, and shipping address so the order can be produced and delivered. Payment is handled by Stripe — your card details go directly to Stripe and we never see or store them. Your order details and shipping address are shared with your photographer and with the professional print lab that produces and ships the order, and are used for nothing else.
When you send an inquiry through a photographer's website or booking form, the name, contact details, and message you type are delivered to that photographer so they can reply to you. We store them on the photographer's behalf and do not use them for anything else.
When you save a photo, the app requests permission to add photos to your Photos library. It only saves the image you asked to save — it never reads, uploads, or transmits anything else from your Photos library.
Photographers and their team members sign in with Google or Apple to manage their own galleries. Either way we receive only what the sign-in provider shares: a name, an email address, and an account identifier, used solely to operate their studio's galleries. If a photographer signs in with Apple and chooses Hide My Email, Apple gives us a private relay address that forwards to their real inbox — we never see, and cannot look up, the real address.
A photographer can delete their account themselves, inside the app, without contacting anyone — the Delete account option is on the account screen after signing in. Deletion removes the sign-in and the person's team-membership records, and for Apple sign-ins we also ask Apple to disconnect Sign in with Apple from the app. Galleries belong to the studio and its clients, not to an individual sign-in, so they are not deleted when a team member's account is.
Anonymous favorites, view counts, and order records are stored on Google Firestore (Firebase). Photos are stored on Cloudflare R2. Payments are processed by Stripe. Emails (like order confirmations and inquiry notifications) are delivered through Resend. The service is hosted on Vercel and Cloudflare, which keep standard server logs. Each of these providers is used solely to operate this service.
Because we do not know who you are, we cannot look up your data by identity. Clearing your browser or app's site data removes your random device identifier. To have anonymous records tied to a specific gallery removed, email us and reference the gallery.
This service is not directed at children under 13, and we do not knowingly collect information from children.
If we change how the app handles data, we'll update this page and the date above.
Questions about this policy: