Privacy and Data Protection Policy
Last updated: 28 August 2026 · ThrowBack
This policy is long, so it is split into expandable clauses. Jump from the list, or tap “Expand all”.
Terms of use →1. Purpose of this policy
This policy explains how ThrowBack handles personal data, usage data and visual content uploaded through the platform, including the types of data, the purposes of processing, the privacy principles we follow, access limits, sharing with service providers, and how retention, deletion and recovery work.
This privacy policy forms part of the terms of use. By using ThrowBack you acknowledge that you have read it.
2. About the platform
ThrowBack is a private visual archive for individuals and businesses. It lets you save, organise, manage and share photos and videos selectively with specific people, in an environment built around privacy and access control.
The current product includes uploading photos and videos, setting privacy, follow requests that can be accepted or declined, viewing only permitted content, and managing accounts, plans, storage and reports.
Privacy is not a secondary feature of ThrowBack. It is part of the product itself and of the trust we aim to build.
3. Governing privacy principles
Visual content uploaded to the platform is private by nature. We aim to collect only the data needed to run the service, use it only for disclosed purposes, keep control with the user, restrict internal access, and not use uploaded materials for marketing, training or advertising without a separate authorised basis.
4. Data we handle
We may handle account and identity data (name, email, phone where needed, authentication including Sign in with Apple or Google, profile photo, settings); uploaded content (photos, videos, metadata, albums, family-tree details, chat); access and interaction data (sessions, device, app version, IP, crash logs, usage indicators); follow and access data; subscription and billing data (payments are processed by the App Store, Google Play or an external provider — we do not keep full card numbers); support correspondence; and, for business accounts, team and workspace data. Future AI features are not confirmed as currently in operation.
5. Nature of visual content
Uploaded content can be among the most sensitive categories of data, including personal or family photos, private videos, images of other people, professional materials, or archives of emotional value. It is handled with strict limits on use and access.
6. Purposes of processing
We process data to run the service, store and organise content, apply privacy and access controls, manage subscriptions, provide support, protect accounts and prevent abuse, and improve the product using aggregated or technical analytics without unlawful use of private content. If restore or enhance features are enabled later, processing will require an explicit request or clear contractual permission.
7. What we do not use data for
- Using user content in ads or marketing campaigns.
- Publishing photos or videos or displaying them publicly.
- Sharing content with third parties for purposes unrelated to the service.
- Training AI models on user content without an explicit, specific basis.
- Selling your memories or personal data to advertisers.
8. Basis for processing
Processing rests on performing the service, legitimate operational interests (security, stability, abuse prevention, improvement), user consent where a more explicit consent is needed, and contractual obligations with business clients.
9. Internal access to data
Internal access is on a need-to-know basis for authorised support, technical, security, compliance and operations roles. Access to photos and videos happens only for justified operational, security or support cases under strict internal controls.
10. Sharing data with third parties
We may use cloud hosting and storage providers, notification, analytics or support providers, payment providers including Apple and Google, Sign in with Apple or Google when you use them, future AI providers if enabled, and competent authorities if disclosure is required by law. Third parties act as processors within a defined scope.
11. Privacy and AI features
AI is not applied by default merely because photos or videos are uploaded. Restore or enhance functions, if added, will be tied to a conscious action by you, with clear disclosure, and content will not be used to train models without a separate authorised basis.
12. Sensitive data
Family photos, images of children, event photos and confidential professional materials are treated with extra care. You remain responsible for ensuring the upload is lawful and that you have permission regarding people who appear in the content.
13. Privacy in business use
When a business uses ThrowBack for professional or client visual content, we treat that data with extra care. ThrowBack does not alone bear every obligation the business client has toward its own customers unless that is stated expressly in a contract.
14. Data retention
We keep data as long as needed to run the service and meet operational, security or legal requirements. Deleted content may stay in the trash for 7 days if that feature is enabled. Some backups or technical logs may remain for a limited period after deletion.
15. Deleting data and content
You can delete content in the app, and request account deletion from settings or by emailing us. We may need to verify identity. Removing a follower restricts access; it does not delete the original content.
16. Recovery and backups
We may keep operational backups to protect continuity. We do not promise that every file will always be recoverable. ThrowBack should not be treated as the only backup for content of exceptional importance.
17. Your rights
Subject to the service and applicable law, you may have the right to know, access, correct, delete, object or withdraw consent, and to ask about our privacy practices. Requests are subject to identity verification and legal or security limits.
18. Children, other people and shared content
You must have the right to upload content that includes children, family members or third parties, and use the service with a parent or guardian’s consent whenever the law requires it. ThrowBack cannot verify every permission in advance and retains the right to act on reports.
19. Security and data protection
We use reasonable technical and organisational measures, which may include access controls, encryption in transit, account protection such as a passcode or Face ID, and sensitive-activity logs. No system is 100% secure. Keep your sign-in details secret.
20. Security incidents
If we discover an incident that may materially affect users’ privacy or the integrity of the service, we follow an appropriate response plan, including notification of relevant parties when required.
21. Analytics and operational data
Operational and analytical data may be used to improve the service, using as little data as possible and aggregating or de-identifying it where we can, without exploiting private content.
22. Corporate transfers or restructuring
In a merger, acquisition or restructuring, data or accounts may form part of the transfer within lawful limits, while remaining bound by confidentiality and privacy principles.
23. Limits of privacy liability
We commit to appropriate professional care. That does not mean unlimited liability for every user action, for content a user had no right to upload, or for your own sharing decisions.
24. Contact us
For privacy enquiries or to exercise your rights: visionaryinnovations.app@gmail.com
Operator: Visionary Innovations.
Throwback