Privacy Policy
Wildberry is an app for sharing family photos and videos privately in albums with relatives you approve. This policy explains which personal data Wildberry processes, why, who receives it and which rights you have.
1. Who is responsible
The controller responsible for data processing in Wildberry is:
CodeBakery, Nicolas Mehlei (sole proprietor)
Wedel, Germany
Email: hello@codebakery.net
The full postal address and further provider information are in the imprint: https://codebakery.net/imprint/.
2. Which data we process
- Sign-in data: when you sign in with Google, we receive your Google account identifier, your name and your email address. The identifier links your sign-in to your Wildberry account; name and email are shown to the owners and members of albums you belong to.
- Photos and videos: the photos and videos you upload, the album each one belongs to, its capture date (read from the file or set by you), who uploaded it and when.
- Captions and comments that you write.
- Albums and memberships: the albums you create (including the album name, which is often a child's name), invitations, access requests, your role (owner or member), your upload and download permissions and your notification settings per album.
- Push notification data: a device token issued by Firebase Cloud Messaging so that we can send notifications to your Android device.
- Technical data: when your device connects to our servers, technical data arises such as your IP address, the time of the request, the requested address and technical information sent with the request (for example app and operating system version). This data may be recorded in server logs for security and troubleshooting.
Location: Wildberry does not read or use location data. The app does not request access to location or to the location metadata of your media. Viewing copies and thumbnails are created without any metadata, including GPS. Original photos are stored as uploaded; if your device embedded location data in a file, it remains in that original, which only album owners and members with download permission can download.
Wildberry shows no advertising, does not sell your data, contains no analytics or tracking SDKs and does not profile you.
3. Purposes and legal bases
- Providing the service (signing you in, storing and showing photos, videos, captions and comments to the members of an album, managing invitations and permissions): Art. 6(1)(b) GDPR, performance of the contract with you.
- Security, abuse prevention and operating the service (rate limits, server logs, troubleshooting): Art. 6(1)(f) GDPR, based on our legitimate interest in a secure and reliable service.
- Push notifications about new photos, videos and comments are part of the service (Art. 6(1)(b) GDPR). Notifications name the person who acted but never contain album names, comment text or media. You can turn them off for each album in the app (album → Members → Notifications) or for the whole app in your Android settings.
4. Who receives data
Album members: photos, videos, captions and comments are visible only to members of the album they belong to, after an album owner has approved them. Albums are independent: membership in one album does not grant access to another.
Service providers: we use the following services to run Wildberry:
- Microsoft (Azure): hosting of the Wildberry server application and storage of photos and videos, in the Azure region West Europe (Netherlands).
- Hetzner Online GmbH (Germany): hosting of the server that runs the Wildberry database (account, album, membership and comment data).
- Google (Firebase Cloud Messaging): used to deliver push notifications to Android devices.
- Cloudflare: network proxy in front of our server, providing encrypted (TLS) connections and protection against attacks. All requests to our server pass through Cloudflare.
- Our own media-processing server: creates viewing copies and thumbnails from uploaded photos and videos. It is operated by us and is not a third-party service.
Google sign-in: you sign in to Wildberry with your Google account. Google handles the sign-in under its own privacy policy; Wildberry receives only the sign-in data described above.
Google, Microsoft and Cloudflare are companies with operations outside the EU/EEA. Personal data is not transferred outside the EU/EEA except as covered by these providers' standard contractual terms (EU Standard Contractual Clauses) or an adequacy decision of the European Commission.
We do not otherwise pass on your data unless we are legally obliged to do so.
5. How long data is kept
- Your account is kept until you delete it.
- Deleted photos and videos disappear immediately and can be restored by an album owner for 7 days. After that they are permanently removed.
- A deleted album can be restored by an owner for 31 days. After that its photos, videos, comments, memberships and invitations are permanently removed. Media that was also added to another album remains there.
- Deleting your account removes your sign-in data, name, email address, sessions, devices, memberships and all of your comments. Photos and videos you uploaded stay in the albums, shown as uploaded by "Former member", unless an album owner removes them. Albums in which you were the only member are deleted with your account.
- Push device tokens are deleted when you sign out, delete your account or the token becomes invalid.
- Server logs are kept only as long as needed for security and troubleshooting.
- Backups: database backups are kept for a limited period. Deleted data may remain in these backups until they expire.
6. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have incorrect data rectified (Art. 16);
- have your data erased (Art. 17);
- restrict processing (Art. 18);
- data portability (Art. 20): owners and members with download permission can save an album's original photos and videos to their device in the app (album → Members → Save all originals);
- object to processing based on legitimate interests (Art. 21);
- withdraw any consent you have given, with effect for the future (Art. 7(3));
- lodge a complaint with a supervisory authority (Art. 77). The authority responsible for us is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD); you may also contact the authority where you live.
To delete your account, use Settings → Delete account in the app. For everything else, or if you cannot use the app, email hello@codebakery.net, ideally from the email address of your Google account. See also Support.
7. Children
Wildberry is not directed at children and children should not use it themselves. The albums usually contain photos and videos of children; these are added by their parents or guardians, who decide whom they invite. Album owners are responsible for the people they approve and for what is shared in their albums.
8. Changes to this policy
We will update this policy when the app or the law changes. Changes are published on this page with an updated "Last updated" date.
Last updated: 2026-10-02