Version 2026-08-04
Privacy notice
What is collected, who can see it, and how to get rid of it.
What is collected
Your email address, used to sign in and to contact you about your account.
Your name, username, and anything you choose to add to your profile — bio, location, website, avatar and cover photo. All of it is visible to other members except your email.
Your photographs, captions, gear details, comments, statuses and albums. All visible to other members, except albums you mark private.
The date you accepted these terms, and which version.
If you sign in with Google, Google confirms your email address to us and passes along your name and profile picture. We never receive your Google password, and we ask Google for nothing beyond that basic profile.
Reports you file: what you reported, the category you chose, and anything you typed. Reports are kept after they are resolved, because a pattern across several reports is often the only way a repeat problem is visible.
What is not collected
No advertising trackers, no third-party analytics, no data sold to anyone.
No GPS coordinates are read from your photographs — though see the EXIF note in the terms, because the coordinates may still sit inside the file you uploaded.
Who can see what
StopDown is members-only. Photographs, profiles, comments and albums are visible to signed-in accounts and are not served to anyone without one. This is enforced by the database, not by hiding a screen.
Private albums are visible only to you, on the same footing.
Image files themselves are served from a storage URL that does not check for a session, the way images on any website are. The addresses are long random strings and are not listed anywhere, but treat a photograph you have uploaded as something that could be viewed by anyone holding its direct link.
Your email address is never shown to other people. Neither is the fact that you reported something, or that you blocked someone.
Where it lives
Data is stored with Supabase (PostgreSQL and object storage). Passwords are hashed by the authentication provider and are never visible to this application or its operator.
If a CAPTCHA is enabled on signup, that provider sees your IP address as part of verifying you are not a bot.
Files in a paid vault are stored in a private bucket. Unlike photographs posted to the feed, they are not reachable by URL — every read is authorised against your session and expires shortly after it is issued.
Purchases are handled by Apple or Google. They tell us that a subscription is active and which plan it is for; they do not give us your payment details, and we never see a card number.
Deleting your data
Deleting a photograph removes both the database row and the stored file. The same is true of a file in your vault.
Deleting your account is available in Edit profile and takes effect immediately. It removes your sign-in record, your profile, photographs, albums, statuses, comments, likes, follows, notifications and reports you filed, and empties both your photo storage and your vault. There is no waiting period and no way to undo it. Download anything you want to keep first — a paid plan does not slow this down or hold anything back.
Two things survive a deletion, deliberately. Comments other people left on your photographs go with the photographs. Moderation records — that an action was taken, when, and why — are kept without your profile attached, because a service that forgets its own enforcement history cannot enforce anything.
Backups holding copies age out on their normal schedule.
Getting in touch
Questions about your data, requests for a copy of it, abuse reports and legal notices all go to cosmanophotography@gmail.com.