Privacy Policy

Last updated: 12 July 2026

This policy explains how Ephemeros handles personal information across the Ephemeros website (ephemeros.app), the Ephemeros mobile app, and our APIs. It is written to comply with the South African Protection of Personal Information Act 4 of 2013 ("POPIA") and, for users elsewhere, with the EU/UK General Data Protection Regulation ("GDPR") and similar international laws.

1. Who is responsible

The responsible party (POPIA) and data controller (GDPR) is Ephemeros, operated by Willem van Zyl t/a "CLC Agency", based in South Africa, who also acts as Information Officer. For anything in this policy — questions, requests, complaints — email hello@ephemeros.app.

2. What we collect

We collect this information directly from you and from your device when you use the service. We do not collect special-category personal information, and we do not sell your contact details.

3. Why we use it and our legal grounds

You give two explicit consents at registration: to this policy, and to the content-rights licence described in the Terms of Use. Where processing rests on consent, you may withdraw it (section 8), without affecting processing already carried out.

4. Photos, location, and what is public

5. AI review and automated processing

Uploaded photos may be analysed by an AI vision service (currently OpenAI) to generate a description and tags that assist moderation and enrich the research dataset. Only the photo is sent — never your name, email, or account details — and our agreement with the provider does not permit it to use the images to train its models. Moderation decisions that affect you (declining content, suspending accounts) are made or reviewed by humans; we do not make solely automated decisions with legal or similarly significant effects.

6. Who we share it with

We use a small set of service providers (operators under POPIA, processors under GDPR) bound by contract to protect your information:

We also share:

7. International transfers

We are based in South Africa and some providers above process data in the EU and the United States, so your information may be transferred across borders. We only transfer personal information as POPIA section 72 and GDPR chapter V allow: to recipients subject to laws or binding agreements providing an adequate level of protection (for EU/UK data, the EU–US Data Privacy Framework or Standard Contractual Clauses), or otherwise with your consent or as necessary to provide the service you requested.

8. Your rights

Subject to applicable law, you have the right to:

To exercise any right, email hello@ephemeros.app. We may need to verify your identity, and we respond within the time limits of the applicable law (one month under GDPR; as soon as reasonably possible under POPIA). If you are unhappy with our response, you may complain to the South African Information Regulator (inforegulator.org.za, complaints.IR@inforegulator.org.za) or, for EEA/UK users, to your local data-protection authority.

9. Account deletion and retention

Deleting your account (self-service in the app, or by email) anonymises you: your name and username become "Anonymous", your email address is removed, and your avatar, devices, push tokens, friendships, and notifications are deleted. A one-way hash of your email address is kept solely to prevent abuse of re-registration; it cannot be reversed into your address. Photos and spots you contributed are retained and displayed as "Anonymous" — the long-term record is the purpose of the platform, and you accept this at registration and again in the deletion confirmation. Copies of photos already released under the open CC BY 4.0 licence remain licensed to those who obtained them and cannot be recalled.

Retention periods:

10. Cookies and analytics (website)

The website uses essential cookies for signing in and security (session and CSRF cookies) — these are required for the site to work. It also uses Google Analytics to understand aggregate usage: pages visited, approximate location derived from your IP address, and device/browser information. Google sets its own cookies and processes this data on our behalf; we do not link analytics data to your account. You can block analytics cookies in your browser or with Google's opt-out browser add-on. Where forms are protected by Cloudflare Turnstile or Google reCAPTCHA, those services process technical signals from your browser to distinguish humans from bots.

11. The mobile app: permissions and on-device data

Meta app events (ad install attribution). The Android app includes the Meta (Facebook) SDK so that we can measure how many app installs our advertising on Meta's platforms brings in. On each app launch the SDK sends an app-activation event to Meta together with your device's advertising ID and basic device information — this happens for every user, on every launch, whether or not you arrived through an ad. It is used solely for install attribution and aggregate ad measurement; we do not send your name, email, account details, photos, or location to Meta, and we do not use it to build advertising profiles of you inside Ephemeros. Meta processes this data as described in its own privacy policy. You can limit this on your device: in Android settings under Privacy → Ads you can delete or reset your advertising ID, which removes or unlinks the identifier the SDK reports.

12. Security

We protect your information with, among other measures: encrypted connections (HTTPS) everywhere, hashed passwords, hashed API keys, signed expiring URLs for original-resolution images and password resets, EXIF stripping and image re-encoding on upload, rate limiting, role-restricted admin access with activity logging, and encrypted off-site backups. No system is perfectly secure; if a breach creates a risk to you, we will notify you and the Information Regulator (and other authorities where required) as the law demands.

13. Children

The service is not directed at children under 13, and we do not knowingly process their personal information. Users under 18 require the consent of a parent or guardian (a "competent person" under POPIA). If you believe a child is using the service without such consent, contact us and we will remove the account.

14. Changes to this policy

We may update this policy as the service or the law changes. For material changes we will notify you (email or in-app notice) before they take effect; the "Last updated" date above reflects the current version. Where a change requires fresh consent under applicable law, we will ask for it.

15. Contact

Ephemeros — operated by Willem van Zyl t/a "CLC Agency", South Africa (Information Officer).
Email: hello@ephemeros.app
Takedown requests: ephemeros.app/takedown