Security
Our approach
At Fotelya, security isn't an option: it's the foundation of the product. Your guests share easily, and you stay in control.
Measures in place
- Encryption of your media in transit and at rest.
- Private access : non-public galleries, accessible only via your QR or link, protected by a PIN code, with non-guessable identifiers.
- Hosting in the European Union for photos, videos and the database; any processing outside the EU by a subcontractor is covered by appropriate safeguards.
- Automatic deletion of media after the event: your data doesn't linger indefinitely.
- Minimization : no account required for guests, the GPS position is removed from photos (JPEG, PNG, WebP), leaving the file identical in quality; videos and certain formats (raw HEIC/AVIF/GIF) keep the metadata recorded by the device.
- Admin access protected by a Cloudflare Access identification followed by a password.
Responsible disclosure of vulnerabilities
If you discover a security flaw, we thank you for reporting it to us responsibly, privately, at security@fotelya.com, before any public disclosure.
We commit to: acknowledging receipt within a reasonable timeframe, reviewing each report in good faith, fixing confirmed vulnerabilities as quickly as possible, and not pursuing legal action against researchers acting in good faith (without accessing user data, without disrupting service, without extortion).
Please do not access data that does not belong to you, do not degrade the service, and allow us a reasonable timeframe to fix issues before publication.
Machine-readable information
Our file security.txt (RFC 9116) centralizes our security contact points.
Contact
Security: security@fotelya.com · General: contact@fotelya.com.