Privacy Policy
Effective Date: September 16, 2026 Version: 2026.09
This Privacy Policy explains what information Gather Media collects, how we use it, and your choices. Gather Media is operated by Open Civic Systems ("OCS"), a California 501(c)(3) nonprofit organization.
1. Our Approach to Privacy
Gather Media is built with privacy as a core value. We do not use advertising, third-party analytics, algorithmic recommendations, or cross-collection user tracking. We collect only what is necessary to operate the platform and serve the communities that use it.
2. What We Collect
2.1 From Anonymous Contributors (Share Link Uploads)
When you upload media through a share link without an account:
| Information | How It Is Stored | Retention |
|---|---|---|
| Uploaded photos | Cloud storage as WebP copies; original file deleted after processing | Life of the collection |
| Uploaded videos, documents and other files | Cloud storage as uploaded; original file and its embedded metadata (including any location, dates and author) retained | Life of the collection |
| GPS coordinates | Extracted from file metadata (photos, videos, and when present, documents), stored in database | Life of the collection (only if collection policy permits) |
| Capture date and time | Extracted from file metadata (photos, videos, and when present, documents), stored in database. For documents, this is usually the file's creation date | Life of the collection (only if collection policy permits) |
| Compass direction | Extracted from file metadata, stored in database | Life of the collection (only if collection policy permits) |
| Device make and model | Extracted from file metadata, used for direction correction | Life of the collection (only if collection policy permits) |
| Original filename | Stored in database. Used as the display title until a title is assigned; also shown in the file's details and may appear publicly | Life of the asset |
| IP address | Hashed using SHA-256 | Removed from active systems within 60 days |
| Upload timestamp | Stored in database | Life of the asset |
What we do NOT collect from anonymous contributors:
- Name, email, or any contact information
- Browser fingerprints or device identifiers
- Cookies (the upload page works without login)
- Advertising or tracking data of any kind
2.2 From Authenticated Users
When you create an account and use Gather Media:
| Information | Who Can See It | Purpose |
|---|---|---|
| Email address | Collection administrators, OCS | Account management, notifications |
| Display name | Other collection members, public (in public collections) | Attribution (you control this) |
| Google profile information | OCS only | Authentication (if using Google sign-in) |
| Upload history | Collection administrators | Collection management |
| Activity (comments, edits) | Collection team | Accountability |
| Policy acceptance record | OCS only | Compliance (version and timestamp) |
2.3 From All Visitors
| Information | Retention | Purpose |
|---|---|---|
| IP address (access logs) | Masked, removed from active systems within 60 days | Platform operations |
| IP address (error logs) | Full, removed within 10 days by automated log rotation | Debugging |
| Session cookie | Session duration | Login state |
| CSRF token | Session duration | Security |
3. How We Handle Your Files
3.1 Hidden Metadata in Your Files
Photos, videos and documents often contain hidden information called metadata (for photos, usually "EXIF data"). Your camera, phone or software adds it automatically, often without you realizing it. It can include your exact GPS location, the time a file was created, your device's serial number, camera model, editing software, and for documents, the author's name.
How we handle this depends on the type of file.
3.2 Photos
When you upload a photo, we create web-friendly copies (a full-size version, plus smaller versions for faster viewing) in WebP format. The original file you uploaded is then deleted and is not retained.
Creating these copies removes all embedded metadata. None of the stored or served photo files contain it.
If the collection you are contributing to has opted to collect certain information, such as location, capture time or compass direction, that specific information is extracted and stored separately in our database before the original is deleted. When compass direction is kept, the device make and model may also be kept so the direction can be corrected for your device. You are told what information the collection requests before you upload.
All other photo metadata, including camera serial numbers, software versions, device identifiers and editing history, is permanently deleted and cannot be recovered.
3.3 Videos
Videos are stored as you uploaded them. The original file is kept, including all of its embedded metadata, such as the location where it was recorded. We may also create smaller preview copies and a poster image. Very large videos may be downsized; in that case the original is not kept, but the downsized copy may still contain the original's metadata.
If you agree to share location or date when uploading, and the video contains them, they are also saved in our database to place the video on maps and timelines.
3.4 Documents and Other Files
PDFs, documents and other files are stored exactly as you uploaded them, including their embedded properties such as author name, software, creation date and any location tags.
If you agree to share date or location when uploading, a creation date or location already recorded in the file's own properties may be saved in our database. For documents, this date is usually when the file was created or exported. Author and software information is never saved to our database, but remains inside the stored file.
3.5 Your Choices When Uploading
The location and date choices on the upload page apply to every file in that upload.
Because videos and documents are stored with their embedded metadata, remove any location, author or other information you don't want to share before uploading. Keep your own copy of any photo you upload, because the original photo file is not retained.
3.6 Original Filenames
The name of the file you uploaded (for example, IMG_1234.heic) is stored for every file type. It is used as the display title until you or the collection team add a title, and it may appear publicly on collection pages and in a file's details.
4. File Storage and URL Privacy
- Files are stored in Backblaze B2 cloud storage with unique, unpredictable URLs (long random identifiers)
- For disaster recovery, we periodically copy stored files to a private backup on Amazon Web Services (AWS) S3. This backup is not publicly accessible and is not used to serve files
- URLs cannot be guessed, enumerated, or crawled
- Collection visibility controls (public, unlisted, draft) determine who can browse the gallery; file URLs are a separate layer
- File access can be revoked by the collection team through the platform's content management tools, which hide the file or delete it from primary storage (see §8 regarding backups)
5. What We Do Not Do
- No advertising. We do not serve ads or use ad tracking.
- No third-party analytics. We do not use Google Analytics or similar services.
- No data sales. We do not sell or share personal data with third parties for their own purposes.
- No algorithmic recommendations. Content is organized by the collection team, not by algorithms.
- No cross-collection tracking. Your activity in one collection is not visible to administrators of another collection. Your collection memberships are fully siloed.
6. Who We Share Data With
| Recipient | What We Share | Why |
|---|---|---|
| Backblaze (B2) | Media files | Cloud storage provider |
| Amazon Web Services (S3) | Copies of media files | Private disaster-recovery backup |
| Amazon Web Services (SES) | Email addresses | Sending transactional emails (account verification, notifications) |
| Collection administrators | Member information, upload history | Collection management (within their own collection only) |
| Authorized OCS reviewers | Collection content, member records, activity logs | Support, moderation, security investigations, and platform operations (see Terms of Service §8) |
| Law enforcement | Only if legally compelled | We cannot identify anonymous contributors even if asked — no personal data is collected from them |
7. Account Deletion and Data Retention
If you delete your account:
- Your personal information (name, email, profile) is removed
- Your user ID is retained in anonymized form for referential integrity of collection records
- Media you uploaded remains part of the collection under the license granted at upload (see Terms of Service)
- Your comments are attributed to "deleted user"
For anonymous contributors: no personal data is collected, so there is nothing to delete. Hashed IP addresses are removed from active systems within 60 days.
8. Data Retention and Backups
Data described as "removed from active systems" is deleted from the production database within the stated timeframe. However, database backups may retain data for a limited additional period consistent with our backup retention schedule.
Files deleted from our primary storage are no longer served, but copies may remain in our private disaster-recovery backup until that backup is replaced. If a file must be removed for legal or privacy reasons, such as a DMCA takedown, we can also remove it from the backup on request (see §12).
Restoring from any backup is not part of normal operations and happens only in disaster recovery scenarios.
9. Children
Gather Media requires all users and contributors to be at least 16 years old. We do not knowingly collect information from anyone under 16. If we become aware that a user is under 16, we will take steps to remove their account and contributions.
10. Your Choices
- Metadata sharing: When uploading to a collection, you are informed of what metadata the collection requests. You choose what to share.
- Display name: You control your display name and can change it at any time.
- Account deletion: You can request deletion of your account and personal information.
- Collection membership: You can leave a collection at any time.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Authenticated users will be prompted to review and accept updated policies on their next login. The effective date at the top of this page indicates when the policy was last revised.
12. Contact
For questions about this Privacy Policy, contact us at privacy@opencivicsystems.org.