Last updated: 5 August 2026
Pycter is a photo sharing and synchronization application designed with privacy as a core principle.
Pycter allows users to store and share photos across devices and with other people. Photos and their metadata are encrypted on your device before they are transmitted, and remain encrypted on our servers.
Albums can additionally be protected with end-to-end encryption (E2EE), where the key is generated on your device and never reaches our servers, so that Pycter cannot decrypt the album at all. Encryption is chosen per album and is not enabled by default, because losing the key means losing the album. Section 5 sets out exactly what Pycter can and cannot see in each case.
This Privacy Policy explains how personal data is collected, used, stored, and protected when you use:
This policy is written in accordance with the General Data Protection Regulation (GDPR) and applicable Belgian and European Union data protection laws.
Data controller: Louis Regout, Belgium.
Contact: privacy@pycter.com
Pycter is intended for the general public and is not designed for children. You must be at least 16 years old to use Pycter.
Pycter does not knowingly collect personal data from children under the age of 16. If you believe that a minor has provided personal data, please contact us so it can be removed.
Depending on how you use Pycter, we may process:
Creating an account is not required for the free tier: Pycter can be used on mobile without providing an email address.
The following data is encrypted on your device before upload, and is stored on Pycter servers in encrypted form only:
Encryption on its own does not mean Pycter is unable to read it — that depends on who holds the key. Section 5 explains both cases.
For the proper functioning and security of the service, Pycter may process:
This data is not used for advertising or behavioral profiling.
Every album is encrypted before it leaves your device, so that our hosting and storage providers never hold anything readable. What differs from one album to the next is who holds the key.
Standard albums are the default. They are encrypted with a key that Pycter is able to derive. Your content is therefore protected against our providers and against anyone intercepting it in transit, but Pycter is technically able to access it.
When you enable end-to-end encryption on an album, its key is generated randomly on your device and is never transmitted to or stored on Pycter servers. It reaches the people you invite through the anchor of the invitation link, which browsers do not send to servers.
Pycter cannot decrypt an end-to-end encrypted album. Neither can we recover it if the key is lost — which is why encryption is a choice you make per album rather than the default.
| Data | Standard album | End-to-end encrypted album |
|---|---|---|
| Photos and videos | Readable by Pycter | Not readable |
| Location and other EXIF metadata | Readable by Pycter | Not readable |
| Album title and nicknames | Readable by Pycter | Not readable |
| Member list | Visible | Visible |
| Number of media and their file sizes | Visible | Visible |
| Capture time of each photo | Visible | Visible |
| Media identity (whether two albums hold the same file) | Visible | Visible |
The last four rows stay visible to Pycter in both cases, because the service cannot work without them:
When you share content within an album:
Content already synchronized to other users' devices cannot be retroactively revoked. Leaving an album prevents future synchronization but does not remove data already received by others.
Other members of an album can see:
The names you give your own devices are visible to you alone.
| Data | Retained |
|---|---|
| Account data | Until you delete your account |
| Media in transit between devices | 2 days after upload |
| Thumbnails | 180 days |
| Media held in cloud backup (paid plans) | Until deleted by the album's members |
| Invitation links | 14 days |
| Albums with no remaining member | Deleted daily, together with their content |
| Last-seen time shown to other members | 3 days maximum |
| Technical logs | Retained briefly for security and abuse prevention |
Encrypted content remains available while at least one album member retains access. Once a member's device has downloaded a photo, that copy lives on their device and is no longer governed by these server-side periods.
Users may delete their Pycter account at any time, from the application or at pycter.com/delete-account. Upon deletion:
Content previously shared with other users may remain on their devices, as Pycter cannot remove data already synchronized.
Pycter relies on a limited number of trusted service providers acting strictly as data processors:
| Provider | Purpose | Location |
|---|---|---|
| Google Cloud | Application servers and database | EU — Belgium |
| Cloudflare R2 | Encrypted media storage and transfer | EU |
| Amazon Web Services | Long-term encrypted media storage | EU — Sweden |
| Firebase Cloud Messaging | Push notifications | Google — EU / United States |
| Firebase App Check | Abuse and tampering detection, using Play Integrity on Android and App Attest on iOS | Google — EU / United States |
| Firebase Crashlytics | Crash diagnostics, Android only | Google — EU / United States |
| Brevo | Delivery of sign-in codes by email | EU — France |
| Google, Apple | Optional sign-in providers, when you choose to sign in with them | EU / United States |
Authentication itself runs on Pycter's own infrastructure; account credentials are not entrusted to a third-party identity provider unless you choose to sign in with Google or Apple.
These services may process technical identifiers strictly necessary for security and functionality. They are not permitted to use data for advertising or profiling.
Pycter does not display advertising, sell personal data, track users across apps or websites, or perform behavioral profiling. No advertising identifiers are used, and there is no product analytics or usage tracking.
The one thing collected automatically is crash diagnostics on Android: when the application crashes, a report containing the stack trace, the device model and an application installation identifier is sent so the fault can be fixed. It carries none of your photos, album content or encryption keys.
Pycter servers, database and media storage are located within the European Union.
Push notifications, abuse detection and crash diagnostics rely on Google services that may process technical identifiers outside the EU. Those transfers are covered by appropriate safeguards, including Standard Contractual Clauses. Your photos and album content are never part of them.
If the service expands internationally, personal data may be processed outside the EU using the same safeguards, including strong encryption.
Under Article 6 of the GDPR, Pycter processes personal data on the following bases:
Under the GDPR, you have the right to access, correct, delete, restrict, or port your personal data, and to withdraw consent at any time. Contact us at privacy@pycter.com to exercise these rights.
You also have the right to lodge a complaint with your local data protection authority. In Belgium: Autorité de protection des données (APD).
If you are a California resident, you have additional rights under the CCPA/CPRA, including the right to access and delete your personal data. Pycter does not sell personal data and does not share personal data for advertising purposes.
This Privacy Policy may be updated to reflect changes in the service or legal requirements. When significant changes are made, the updated version will be published on this page with a revised "last updated" date.
For any privacy-related questions or requests: privacy@pycter.com