Our privacy position
No face recognition,
ever
PopStudio collects no biometric data. It runs no face matching. It never will. A guest is joined to their photos by a five-character code they were handed themselves — nothing in the system looks at a face.
- No faceprints, templates or embeddings. None are created, stored or bought in.
- No scanning the crowd. A guest who does not check in is never matched to anything.
- No age estimation, no advertising trackers. Not on the guest phone, not anywhere.
- Photos expire on a timer and guests can delete their own at any moment.
The mechanism
How other platforms do it. How we do it.
This is the whole difference. It is worth two minutes, because everything else on this page follows from it.
Match by face
A guest uploads a selfie. The platform turns that face into a mathematical template — a faceprint — and compares it against every face in every photo from the event.
It genuinely works, and it works at festival scale. That is why big events use it. The cost is that a biometric identifier now exists for every guest who was scanned, and often for people who simply walked through the frame and never asked to be in anything.
selfie → faceprint → searched against every photo
Match by code
A guest scans one printed sign while queuing, types their name and email, and gets a five-character code with a QR on their phone.
At the front of the line the operator scans that code, shoots, and taps Done. The code is the join. It is issued to one person, held by that person, and shown by that person. No face is measured at any point in the chain.
K4M9T → scanned at the station → those photos, that inbox
Image placeholder
Face-scan matching struck through, beside the five-character code path
Two horizontal lanes, one canvas, 16:9. Top lane: selfie thumbnail → wireframe face-mesh → grid of photos being searched; the entire lane struck through with a single red rule and captioned "not how PopStudio works". Bottom lane, in safelight amber: printed QR sign → phone check-in form → code chip "K4M9T" → operator scanning it → one photo landing in an inbox. Flat vector, silhouettes not stock faces, arrows left to right.
New Zealand
The Biometric Processing Privacy Code
The Office of the Privacy Commissioner issued a Biometric Processing Privacy Code in 2025. It is in force now, and deployments that were already running must comply by 3 August 2026.
If a tool does automated facial recognition, the Code puts real work on whoever runs it:
- A privacy impact assessment before you switch it on.
- A proportionality test — is the benefit worth the privacy cost, and is there a less intrusive way to get the same result?
- Explicit notice to the people being processed, in plain language, where they will actually see it.
That is a sensible bar for anyone building a face database. It is also a bar a volunteer running a Friday youth night should not have to clear.
PopStudio performs no biometric processing, so the Code does not apply to it. There is no assessment to file, no proportionality argument to construct, and no biometric notice to write, because there is no biometric anything.
You still have ordinary privacy obligations — tell people what you are collecting, keep it safe, use it only for what you said. Those apply to any event photography. The Code is the extra layer, and choosing a non-biometric tool is how you step around it rather than through it.
This is information, not legal advice. We are a photography platform, not your lawyer. We have summarised a public Code in plain words and linked the source so you can read it yourself. If your organisation has a specific obligation — a school, a health provider, a government agency — take proper advice on it.
Australia. Biometric data is sensitive information under the Privacy Act, which means it needs consent before it is collected. Separately, the OAIC is developing a Children's Online Privacy Code, due to be registered by December 2026, which treats under-15s as unable to consent for themselves. The first question does not arise here, because no biometric data is collected at all. The second sits with you as the organiser: if consent is needed for a young person, you obtain it your way, before the event.
Consent
Nobody is in the system by accident
Check-in is the consent. It is a deliberate act, taken on the guest's own phone, before any photo exists.
They choose to scan
One static QR sign near the queue. Reading a sign is not consent; scanning it is a choice.
They enter their own details
Name and email, typed by the guest. We never buy, guess or import a guest list.
They get a code
Five characters plus a QR. Showing it at the station is the second, in-person confirmation.
No code, no match
A guest who never checks in is never matched to anything. There is no "find me in the crowd".
There are no per-event consent settings and no branching paths. Every guest gives a name and an email address, and their photos go to that address. We do not ask anyone's age, and nothing in the system treats one guest differently from another. Deciding who is photographed at your event, and obtaining any permission your policy or the law requires, is the organiser's call.
Children & young people
You decide who is photographed. We never ask an age.
PopStudio has no minor path, no age question and no parental-consent step. It cannot tell a fourteen-year-old from a forty-year-old, and it does not try. Every guest gives a name and an email, and their photos go to that address.
That means consent sits where it always really sat: with the organisation running the event. You are the one collecting the information and taking the photographs; we process it as your agent, under the Terms of Service. If your safeguarding policy or the law where you operate requires a parent's permission before you photograph a young person, you obtain it your way, before the event.
What the product does guarantee is narrower and checkable. Nobody is photographed unless they chose to check in and showed their code. Nothing biometric is collected, so no face is measured and no age is estimated. Photos go to the address that guest typed, and to no gallery. Every delivery email carries a delete button that works, and everything expires on the retention clock whether or not anyone remembers.
If a parent wants photos of their child sent to their own inbox, they can simply use their own email address at check-in. That is a choice they make at the sign, not a mode you configure.
Image placeholder
Where responsibility sits
Two stacked bands, paper background. Top band labelled "the organiser": icons for a consent form, a policy document and a person deciding at the camera. Bottom band labelled "PopStudio": check-in form (name, email), code chip, one arrow to a single inbox, a delete icon and a retention clock. A clean horizontal rule between the bands, no arrows crossing it. Print-safe in one colour.
Retention
Photos do not live here forever
Every photo has an expiry from the moment it is taken, and every guest has a delete button they do not need our permission to use.
Image placeholder
Retention timeline from shutter to purge
Horizontal timeline, 16:9, four marked points on one amber rule. Day 0: shutter icon, "shot, developed, emailed in about a minute". Day 0 onward: lock icon, "stored encrypted on Cloudflare R2", with a small "guest delete" button floating above the whole span to show it is available at any time. Day 30 (labelled "your setting: 7 / 30 / 90 / 365"): a broom icon, "daily purge removes the files". After: a greyed photo page reading "Photos expired". Keep dates generic, no invented figures.
The clock
Default retention is 30 days. You can set 7, 30, 90 or 365 to suit your organisation's own policy. The free test drive keeps photos for 7 days.
The purge
A job runs daily and deletes everything past its date. After that the guest's photo page says "Photos expired" — a plain answer, not a broken grid of missing images.
The button
Every guest photo page carries a delete button. Tapping it removes the stored objects. No email to us, no waiting, no form.
The stored files are removed — both the original camera file and the developed version — and the database rows that pointed at them go too. It is not a hidden flag or a trash folder we keep. One honest caveat: a group photo belongs to everyone in it, so it survives until the last participant deletes it. One person's deletion removes it from their page and their copy; it does not delete other people's copies out from under them.
The full list
What we collect, exactly
Not a summary. This is the list.
| Collected | Why | Never collected |
|---|---|---|
| Name | So the operator can call the right guest forward and the email reads like a human wrote it. | Faceprints — no face is ever measured. |
| Email address | It is the delivery address. That is its only job. | Biometric templates or embeddings of any kind. |
| A five-character code, issued at check-in | It is how photos are joined to the right guest. Nothing else does that job. | Age, or anything about it — we never ask, and we never infer. |
| The photos | They are the product. They are what the guest came for. | Advertising or analytics trackers on the guest photo page. |
| Timestamps — check-in, capture, delivery | To run the queue, honour retention, and answer "did mine send?" | Location, contacts, or anything else on the guest's phone. |
Guest data is never sold, never rented, and never passed to an advertiser. It is used to deliver photos to the person who asked for them, and for nothing else.
Infrastructure
Where it lives
Storage
Photos are stored on Cloudflare R2, encrypted in transit and at rest.
Access
Your team sees your own events, and nobody else's. We do not browse customer photos. Staff access exists only to keep the service running and to fix something when you ask us to.
Sub-processors
Cloudflare for hosting, database and photo storage, and an email delivery provider to send the link. That is the list. There is no analytics vendor and no ad network in it.
PopStudio is operated by System Advance Limited, a New Zealand company. Full detail is in the Privacy Policy.
You checked in, and you want your photos changed or gone
You do not need us for that. The delete button on your own photo page does it. If the link never arrived, or you want to know what is held about you, the guest help page walks through both.
Ask us
Send us the hard question
Board papers, a school policy review, a privacy officer with a checklist — send it through. We would rather answer a pointed question before your event than a complaint after it. Real answers from the people who built the system.