Last updated: September 9, 2026
Honeyfell is how a photographer delivers private photo galleries to their clients. This policy explains what happens with your data when you open a gallery link a photographer has shared with you, or use the app.
To make gallery favorites, view counts, and save counts work, the app stores a small amount of anonymous information: a random device identifier generated the first time you open a gallery, which images you favorite, how many times a gallery has been opened, and whether photos were saved. None of this is connected to your identity — it only lets the photographer see engagement, not who was engaging.
If something in the app breaks, an anonymous crash report may be recorded so it can be fixed. Crash reports contain no identity, and gallery links are stripped out before anything is stored.
To screen out spam and abuse, our servers briefly use your IP address for rate limiting. These records are automatically deleted within a day and are never used for anything else.
When you order prints from a gallery, you provide your name, email address, and shipping address so the order can be produced and delivered. Payment is handled by Stripe — your card details go directly to Stripe and we never see or store them. Your order details and shipping address are shared with your photographer and with the professional print lab that produces and ships the order, and are used for nothing else.
Your photographer is the seller. Honeyfell operates the software the store runs on. The terms of the sale itself — shipping times, returns, refunds — are your photographer's, and they are shown to you before you pay.
If your photographer sends you an agreement to sign, the signing page records what is needed to make the signature stand up later: your name and email address as your photographer entered them, the name you type or the signature you draw, the times the agreement was sent, first opened and signed, the IP address and browser you signed from, and a cryptographic fingerprint of the exact wording you agreed to.
That record exists so that neither you nor your photographer can be told years later that the agreement said something else. A copy of the signed PDF, including that record, is emailed to both of you at the moment of signing — keep it. The agreement itself is between you and your photographer; Honeyfell is not a party to it.
When you send an inquiry through a photographer's website or booking form, the name, contact details, and message you type are delivered to that photographer so they can reply to you. We store them on the photographer's behalf and do not use them for anything else.
When you save a photo, the app requests permission to add photos to your Photos library. It only saves the image you asked to save — it never reads, uploads, or transmits anything else from your Photos library.
Photographers and their team members sign in with Google or Apple to manage their own galleries. Either way we receive only what the sign-in provider shares: a name, an email address, and an account identifier, used solely to operate their studio's galleries. If a photographer signs in with Apple and chooses Hide My Email, Apple gives us a private relay address that forwards to their real inbox — we never see, and cannot look up, the real address.
A photographer can delete their account themselves, inside the app, without contacting anyone — the Delete account option is at the bottom of Settings → Account → Billing after signing in. Deletion removes the sign-in and the person's team-membership records, and for Apple sign-ins we also ask Apple to disconnect Sign in with Apple from the app. Galleries belong to the studio and its clients, not to an individual sign-in, so they are not deleted when a team member's account is.
Honeyfell is a small operation built on other companies' infrastructure. These are all of them, what each one is for, and what reaches it. Each is used solely to operate this service, on our instructions, and none of them is permitted to use your information for their own purposes.
Google Firebase (Firestore, Authentication)
The database, and photographer sign-in
Gallery records, favorites, view counts, orders, bookings, inquiries and signed agreements; photographers' sign-in identities
Cloudflare (R2, Workers, KV, Turnstile)
Photo storage, published photographer websites, spam screening
Photographs; requests to tenant websites; standard server logs
Stripe
Payments
Your name, email, billing and shipping address, and your card details — which go to Stripe directly and never through us
Resend
Email delivery
Your email address and the contents of the emails we send you — order confirmations, signed agreements, gallery notifications — and whether each one was delivered, bounced or was marked as spam, which your photographer can see
Vercel
Hosting for the app and its servers
Every request, as standard server logs
The print lab
Making and shipping your prints
Your name, shipping address, and the photographs in your order
SignWell (only if your photographer chose it)
Third-party e-signature service
Your name, email address and the agreement text — but only for photographers who have connected their own SignWell account. Honeyfell's own signing does not use it.
Plausible or Fathom (only if your photographer switched it on, and only on their own website)
Cookieless visitor statistics for a photographer's public website — never for a gallery
That a page on that website was viewed. No cookies, no cross-site tracking, and no profile of you.
Anthropic (photographer accounts only)
The AI assistant in the admin's help panel
The photographer's typed questions and their studio's own setup facts (plan, store configuration, storage use). Never clients' names, photographs, galleries, bookings, or orders. Sent over Anthropic's paid API, which does not use submitted data to train models.
We use no advertising network and no data broker, and Honeyfell runs no analytics on you. The one exception is listed above and explained under “Visitor statistics on a photographer's own website”: a photographer may switch on cookieless visitor statistics for their own public site, never for a gallery. If anything else ever changes, this list changes first.
Some browsers can send a “Do Not Track” signal. There is no agreed standard for what a website should do when it receives one, so Honeyfell does not respond to Do Not Track signals — but only because there is nothing for us to stop doing. We do not track you across other websites, and we do not permit anyone else to.
We also do not authorize any third party to collect personally identifiable information about your online activities over time or across different websites when you use Honeyfell.
Reviewing or changing what we hold. If you gave us information yourself — an order, an inquiry, an agreement, an email address for a gallery — email us at the address below and we will show you what we have and correct or delete it. Most of it belongs to your photographer's account rather than ours, so we may need to point you at them; we will say so plainly rather than leaving you waiting.
California. We do not sell or share personal information, and we have never done so. Honeyfell is well below every threshold that makes the California Consumer Privacy Act apply to a business, so its formal request machinery is not something we are required to operate — but the practical rights it protects (know, correct, delete) are ones we will honor for anybody who asks, in California or anywhere else, without making you prove where you live.
Some photographers use Honeyfell to publish their own public website — the page you might find by searching for them, as distinct from the private gallery link they send you.
On that website, and only there, a photographer can switch on cookieless visitor statistics through one of two services, Plausible or Fathom. Both are privacy-focused by design: they set no cookies, they do not follow you between websites, and they build no profile of you. What they record is that a page was viewed. Turning this on is the photographer's choice, not ours, and most have not.
This never happens inside a gallery. The private link a photographer sends you carries no analytics of any kind, from anyone. Nor does anything you sign, pay for, or fill in through Honeyfell.
Honeyfell is a United States company, operated from the United States, and our database — the record of galleries, bookings, orders and accounts — is held in the United States.
Some of the companies in the table above run global networks, so a page or a photograph may be served to you from a machine nearer to you. That is how delivery works everywhere on the internet; the record itself stays with us, in the United States.
If you are outside the United States, using Honeyfell means your information is sent to the United States and handled under United States law, which may protect it differently than the law where you live.
Honeyfell is a very small company with no branch, office, or representative in the United Kingdom or the European Economic Area. We are not claiming to operate the formal request machinery of the UK or EU General Data Protection Regulation, and we would rather say that plainly than imply a process we do not run.
What we will actually do, for anyone who asks, is what we promise everyone above: tell you what we hold, correct it, delete it, or send you a copy. Email [email protected] and we will answer. We do not sell or share personal information, we run no advertising, and we make no automated decisions about you. Honeyfell runs no analytics on you either; the single exception is the cookieless visitor statistics a photographer can switch on for their own website, described above.
Two things are worth knowing about how this service is arranged. Most of what concerns you belongs to your photographer's account rather than ours — they choose what to collect and how long to keep it, and we hold it on their instructions — so some requests are theirs to answer, and we will say so and point you to them rather than leaving you waiting. And your information is kept in the United States, as the section above explains.
Because we do not know who you are, we cannot look up your data by identity. Clearing your browser or app's site data removes your random device identifier. To have anonymous records tied to a specific gallery removed, email us and reference the gallery.
This service is not directed at children under 13, and we do not knowingly collect information from children directly.
Photographs of children do appear in galleries, because photographing families is what many of our photographers do. Those photographs are uploaded by the photographer, not by the child, and the photographer is responsible for having the consent of a parent or guardian before uploading them — that is a term of their agreement with us. If a photograph of your child is in a gallery and you want it removed, ask the photographer first; if you cannot reach them, email us and we will act.
If we change how the app handles data, we'll update this page and the date above. If the change is material, we will say what changed rather than only moving the date.
Questions about this policy: