Information ConstaLink collects

ConstaLink may collect the following information when you use the app:

How ConstaLink uses information

ConstaLink uses information to provide and protect the app, including to:

New media is placed temporarily in a private processing area before it appears in ConstaLink. Trusted automated services inspect the actual file type, declared type, size, image decodability, and supported video metadata, duration, and dimensions. Supported images may be normalized and metadata removed, and ConstaLink may create thumbnails or a privacy-limited event preview. Files that cannot be safely processed are rejected and their temporary copies are deleted or scheduled for cleanup.

Nearby discovery

Nearby discovery runs only when you intentionally open Send or Receive and stops when that session ends or the app leaves the foreground. A receiver temporarily advertises a ConstaLink service on the local network with their display name, username, and app user ID so a sender can identify them. ConstaLink does not use this feature to collect precise location, estimate distance, build location history, or continuously scan in the background.

Nearby discovery is used for pairing. Local sharing starts after the receiver accepts. Items shared with an existing Connect or exact username are securely prepared for the intended recipient before the request is sent, so the sender does not need to remain online after ConstaLink says they are ready. Access is limited to the sender, intended receiver, and authorized backend through Firebase Storage and Firestore controls. Email addresses are not exposed through discovery or username search.

Firebase services

ConstaLink uses Firebase services from Google, including Firebase Authentication, Cloud Firestore, Firebase Storage, Firebase Analytics, Firebase Crashlytics, and Firebase App Check. These services help provide sign-in, database storage, file storage, reliability monitoring, analytics, abuse detection, and app integrity signals. Apple and Google may also process sign-in information when you choose their sign-in methods.

Security and encryption

ConstaLink uses HTTPS/TLS to encrypt supported network traffic in transit. Firebase and Google Cloud encrypt stored Firestore and Storage data at rest using their infrastructure controls. Access is also restricted through authentication, database rules, Storage rules, and server authorization.

ConstaLink is not currently end-to-end encrypted. Authorized ConstaLink backend services and cloud processors can technically access and process uploaded media and metadata to store, display, validate, deliver, create thumbnails or covers, support guest sharing, and operate the service. Face ID, Touch ID, or device unlock protects access to the app on your device; it is not a replacement for server authentication and does not encrypt cloud media end to end.

On-device downloads and cache

When Keep event media offline is enabled, ConstaLink may automatically download event photos, videos, and thumbnails into the app's private cache on your device. This preference is enabled by default on supported mobile devices and can be turned off in Settings. You can clear downloaded media from Settings. ConstaLink also clears this cache when you sign out or delete your account through the app.

Cached files are protected by the operating system's app sandbox and your device security. ConstaLink does not add separate application-level encryption to those cache files. Copies you explicitly save to Photos, Files, another app, or a device backup are controlled by that destination and may remain after the ConstaLink cache is cleared.

Sharing

Event content is shared with people who have access to the same event. A display name, username, and profile photo can be shown to signed-in users you interact with and through exact username lookup. Authentication email addresses and sign-in-provider details are not shared with Connects or event guests. ConstaLink does not sell personal information. ConstaLink may process data with service providers needed to operate the app, comply with law, or protect users and the service.

Optional profile links

Adding an Instagram, Snapchat, X, YouTube, TikTok, LinkedIn, website, or custom HTTPS link does not make it public. A ConstaLink Connect does not automatically receive access. You choose which individual links each Connect can see, and you can change or revoke that access at any time. Unrelated users and event guests cannot read these links.

ConstaLink stores only the public username, label, or HTTPS URL needed to open the profile. ConstaLink does not ask for or store passwords for external social accounts.

Guest web galleries

An event owner may enable a secure web gallery and share its link with guests. A valid link can display the event name, description, and permitted photos or videos without requiring a ConstaLink account. Owners can require an additional event code, restrict access to signed-in participants, disable downloads or sharing, revoke the link, or replace it.

ConstaLink stores the minimum server-side information needed to validate the link and a short-lived browser session. Guest pages do not expose participant email addresses, profiles, unrelated events, Firebase paths, or permanent media download addresses. Shared event pages are marked so search engines should not index them.

Authenticated gallery responses are sent with instructions not to store them in browser caches. If an owner explicitly enables a social preview cover, intermediary services may cache that public preview briefly; a revoked preview can therefore remain in a third-party cache for up to approximately five minutes. A person who already downloaded or copied content may retain that separate copy.

Retention and deletion

You can request account deletion in the ConstaLink app from Settings, Privacy & Security, Delete account. When deletion is completed, ConstaLink removes your account profile and deletes or anonymizes related event data according to the app's deletion behavior.

Photos and videos you uploaded to events owned by other people may remain as shared event content, but your uploader identity is anonymized.

Direct media already shared with another person may remain available to that person. Your display name, username, profile photo, and access are removed from retained transfer records. Optional profile links and per-Connect link permissions associated with your account are removed.

Account deletion removes the Firebase Authentication account, private and public profile records, username reservation, profile image, optional links, link grants, connections, push registrations, active temporary sessions, pending transfers, and events owned by that account. Delivered content that another person is entitled to keep is anonymized as described above. A deletion can take time to propagate through active sessions, caches, logs, and backups.

Your choices

Children

ConstaLink is not intended for children under 13. If you believe a child has provided personal information through ConstaLink, contact support.

Contact

For privacy questions, visit the Support page or email support@constalink.ca.