Information ConstaLink collects
ConstaLink may collect the following information when you use the app:
- Account information such as email address, display name, username, profile photo, and sign-in provider. Email and provider details are kept in private account systems and are not included in your public ConstaLink profile.
- Event information such as event names, event codes, participant lists, permissions, owner-selected expiration dates (if configured), and admin status.
- Web-sharing information such as a one-way share-token hash, web access settings, optional passcode hash, and short-lived guest session records.
- Content you choose to upload, including photos, videos, filenames, file metadata, and event cover images.
- Media validation details, including file type, file size, and video duration where available.
- Nearby-sharing details you choose to expose during a Send or Receive session, including display name, username, app user ID, temporary discovery service information, sharing status, and item counts.
- Connect history created after completed direct sharing, including connected date and recent shared activity.
- Optional external profile information you add, such as a public username or HTTPS profile URL, plus the per-Connect permissions you choose.
- Device and app information used for security, diagnostics, crash reports, analytics, push delivery, and abuse prevention. This can include app version, device platform, diagnostic events, a push token, and network information such as IP address in service logs.
- Support information you choose to send when requesting help.
How ConstaLink uses information
ConstaLink uses information to provide and protect the app, including to:
- Create and authenticate accounts.
- Create, join, manage, and delete events.
- Store and display uploaded event photos and videos.
- Discover active ConstaLink receivers through local-network discovery or an authenticated online fallback and deliver approved direct sharing.
- Apply owner, admin, upload, download, sharing, and deletion permissions.
- Keep optional profile links private until you grant a specific Connect access to selected links.
- Reject unsupported media and enforce upload limits, including photos up to 60 MB and videos up to 500 MB and 10 minutes.
- Send push and in-app notifications and show event activity.
- Diagnose crashes, improve reliability, and prevent abuse.
New media is placed temporarily in a private processing area before it appears in ConstaLink. Trusted automated services inspect the actual file type, declared type, size, image decodability, and supported video metadata, duration, and dimensions. Supported images may be normalized and metadata removed, and ConstaLink may create thumbnails or a privacy-limited event preview. Files that cannot be safely processed are rejected and their temporary copies are deleted or scheduled for cleanup.
Nearby discovery
Nearby discovery runs only when you intentionally open Send or Receive and stops when that session ends or the app leaves the foreground. A receiver temporarily advertises a ConstaLink service on the local network with their display name, username, and app user ID so a sender can identify them. ConstaLink does not use this feature to collect precise location, estimate distance, build location history, or continuously scan in the background.
Nearby discovery is used for pairing. Local sharing starts after the receiver accepts. Items shared with an existing Connect or exact username are securely prepared for the intended recipient before the request is sent, so the sender does not need to remain online after ConstaLink says they are ready. Access is limited to the sender, intended receiver, and authorized backend through Firebase Storage and Firestore controls. Email addresses are not exposed through discovery or username search.
Firebase services
ConstaLink uses Firebase services from Google, including Firebase Authentication, Cloud Firestore, Firebase Storage, Firebase Analytics, Firebase Crashlytics, and Firebase App Check. These services help provide sign-in, database storage, file storage, reliability monitoring, analytics, abuse detection, and app integrity signals. Apple and Google may also process sign-in information when you choose their sign-in methods.
Security and encryption
ConstaLink uses HTTPS/TLS to encrypt supported network traffic in transit. Firebase and Google Cloud encrypt stored Firestore and Storage data at rest using their infrastructure controls. Access is also restricted through authentication, database rules, Storage rules, and server authorization.
ConstaLink is not currently end-to-end encrypted. Authorized ConstaLink backend services and cloud processors can technically access and process uploaded media and metadata to store, display, validate, deliver, create thumbnails or covers, support guest sharing, and operate the service. Face ID, Touch ID, or device unlock protects access to the app on your device; it is not a replacement for server authentication and does not encrypt cloud media end to end.
On-device downloads and cache
When Keep event media offline is enabled, ConstaLink may automatically download event photos, videos, and thumbnails into the app's private cache on your device. This preference is enabled by default on supported mobile devices and can be turned off in Settings. You can clear downloaded media from Settings. ConstaLink also clears this cache when you sign out or delete your account through the app.
Cached files are protected by the operating system's app sandbox and your device security. ConstaLink does not add separate application-level encryption to those cache files. Copies you explicitly save to Photos, Files, another app, or a device backup are controlled by that destination and may remain after the ConstaLink cache is cleared.
Sharing
Event content is shared with people who have access to the same event. A display name, username, and profile photo can be shown to signed-in users you interact with and through exact username lookup. Authentication email addresses and sign-in-provider details are not shared with Connects or event guests. ConstaLink does not sell personal information. ConstaLink may process data with service providers needed to operate the app, comply with law, or protect users and the service.
Optional profile links
Adding an Instagram, Snapchat, X, YouTube, TikTok, LinkedIn, website, or custom HTTPS link does not make it public. A ConstaLink Connect does not automatically receive access. You choose which individual links each Connect can see, and you can change or revoke that access at any time. Unrelated users and event guests cannot read these links.
ConstaLink stores only the public username, label, or HTTPS URL needed to open the profile. ConstaLink does not ask for or store passwords for external social accounts.
Guest web galleries
An event owner may enable a secure web gallery and share its link with guests. A valid link can display the event name, description, and permitted photos or videos without requiring a ConstaLink account. Owners can require an additional event code, restrict access to signed-in participants, disable downloads or sharing, revoke the link, or replace it.
ConstaLink stores the minimum server-side information needed to validate the link and a short-lived browser session. Guest pages do not expose participant email addresses, profiles, unrelated events, Firebase paths, or permanent media download addresses. Shared event pages are marked so search engines should not index them.
Authenticated gallery responses are sent with instructions not to store them in browser caches. If an owner explicitly enables a social preview cover, intermediary services may cache that public preview briefly; a revoked preview can therefore remain in a third-party cache for up to approximately five minutes. A person who already downloaded or copied content may retain that separate copy.
Retention and deletion
You can request account deletion in the ConstaLink app from Settings, Privacy & Security, Delete account. When deletion is completed, ConstaLink removes your account profile and deletes or anonymizes related event data according to the app's deletion behavior.
Photos and videos you uploaded to events owned by other people may remain as shared event content, but your uploader identity is anonymized.
Direct media already shared with another person may remain available to that person. Your display name, username, profile photo, and access are removed from retained transfer records. Optional profile links and per-Connect link permissions associated with your account are removed.
- Account profiles, events, event media, Connect records, optional links, and notifications are generally retained while the related account or content remains active, or until an authorized user deletes them. Events do not expire by default. If an owner explicitly chooses an expiration date, it limits access behavior but is not by itself a guaranteed deletion date.
- Expired nearby-presence records, invitations, and web guest sessions are scheduled for cleanup approximately hourly.
- Expired, incomplete transfer staging and its uploaded payload are scheduled for deletion after a seven-day recovery window. Completed direct sharing remains available to the recipient until the sender deletes the shared original, the related account-deletion behavior applies, or the service removes it under its policies. Hiding an item only removes it from that recipient's view and is not the same as deleting the stored original.
- Pending guest-upload records and their temporary files are removed after their expiry. Completed guest uploads become event content and follow the event's retention.
- Rate-limit and abuse-prevention records are scheduled for cleanup after approximately 24 hours. Invalid or stale push tokens are removed when detected; inactive tokens may otherwise remain until the next delivery attempt, logout, or account deletion.
- Operational, security, analytics, crash, and infrastructure logs may be retained under the settings and retention periods of ConstaLink and its service providers. Backups, if enabled, may retain deleted data for a limited recovery period before aging out.
Account deletion removes the Firebase Authentication account, private and public profile records, username reservation, profile image, optional links, link grants, connections, push registrations, active temporary sessions, pending transfers, and events owned by that account. Delivered content that another person is entitled to keep is anonymized as described above. A deletion can take time to propagate through active sessions, caches, logs, and backups.
Your choices
- You can update your profile information in the app.
- You can leave events or delete events you own, subject to event permissions.
- Event owners can disable or regenerate a web-sharing link at any time.
- You can add, edit, remove, grant, or revoke optional profile links in the app.
- You can delete your account from inside the app.
- You can contact support if you cannot access your account.
Children
ConstaLink is not intended for children under 13. If you believe a child has provided personal information through ConstaLink, contact support.
Contact
For privacy questions, visit the Support page or email support@constalink.ca.