FotoMemoris

Privacy

Last updated: June 4, 2026

Here, in plain language, is how we care for the photos, videos and data of everyone using FotoMemoris. For any privacy question, write to contact@lykoscompany.com.

1. Who we are

FotoMemoris is a digital platform for collaborative event albums shared through QR Codes or links, operated in Brazil by LYKOS Desenvolvimento de Softwares LTDA.

Under the Brazilian General Data Protection Law (LGPD), LYKOS acts as controller for data processed to operate the platform. The host may also have their own responsibilities regarding event images, invitations, privacy settings and participant consents.

Privacy contact: contact@lykoscompany.com.

2. What this Policy covers

This Policy explains what data we collect, why we use it, who we share it with, how long we keep it and what rights you may exercise. It applies to website visitors, hosts, buyers and guests.

FotoMemoris is not an open social network. Access to photos, boomerangs, short videos and other media depends on event settings, the QR/link received and applicable permissions.

3. Data we collect

  • Account and authentication data: phone, SMS code, user identifier, language, acceptance of the Terms and Privacy Policy and, when provided, name and email.
  • Host and event data: event name, cover, dates, capacity, per-guest limits, filters, reveal mode, privacy mode, SMS requirement, retention period, QR/link, status and counters.
  • Guest data: entered name, session/user identifier, phone when SMS is used or required, event participation, uploaded media, usage counters and acceptance records.
  • Media and content: photos, boomerangs, short videos, cover images and technical metadata needed to store, show, download, technically moderate and remove content according to event rules.
  • Purchase and billing data: name or company name, tax ID, email, ZIP code, address, purchased items, amount, payment method, status, receipts/invoices when applicable, purchase history and seller/campaign reference when present.
  • Technical and security data: IP, access date/time, device, browser, operating system, error logs, authentication events, visited pages, anti-fraud identifiers and aggregated metrics.

We do not collect precise device location, contact lists, data from other apps or biometrics for identification. Uploaded media may include image, voice, visible location, health data, children or other sensitive information if the user chooses to record or upload it.

4. How we use data

  • Create, save, edit, unlock, reveal, close and list events.
  • Generate QR Codes and links, authenticate hosts and guests and control capacity.
  • Allow capture, upload, viewing, deletion, download and display of media according to privacy and reveal settings.
  • Process payments, Pix, cards, refunds, history, credits, financial reports and tax obligations.
  • Send SMS codes, transactional messages, operational notices and support.
  • Prevent fraud, spam, abuse, improper uploads, unauthorized access and technical failures.
  • Improve stability, usability and performance through logs and aggregated metrics.
  • Comply with law, court orders, authority requests or regulatory obligations.

We do not sell personal data. We also do not use private photos, videos or boomerangs for advertising, stock media, commercial promotion or AI model training without specific authorization.

5. LGPD legal bases

We process personal data under the legal bases allowed by the LGPD, depending on the purpose:

  • Performance of contract or pre-contractual steps: account, authentication, event creation, participation, upload, album, checkout and operational support.
  • Compliance with legal or regulatory obligations: tax and accounting records, fraud prevention, authority requests and evidence preservation when needed.
  • Legitimate interest: security, abuse prevention, technical diagnostics, product improvement and defense of rights, with proportionality assessment.
  • Consent: acceptance of legal documents, marketing communications when applicable and optional processing that depends on specific authorization.
  • Regular exercise of rights: disputes, chargebacks, audits, abuse investigations and administrative or court proceedings.

6. Sharing and processors

Event media may be seen by the host and, depending on the selected mode, by authorized guests or by anyone with a shared link. Hosts control this setting, but links, downloads, screenshots and screen recordings may be passed on outside FotoMemoris.

We share data only when needed to operate the service or comply with legal obligations. Current main providers are:

  • Firebase/Google Cloud: authentication, database, media storage, Cloud Functions, security and technical logs.
  • Mercado Pago: Pix and card payment processing, anti-fraud, installments, refunds and statuses. Full card data and CVV move through secure/tokenized Mercado Pago fields; FotoMemoris receives tokens, statuses, identifiers and safe metadata such as brand and last digits when needed.
  • ViaCEP: address lookup from ZIP code entered in the billing form.
  • SMS and transactional communication providers: authentication codes and operational messages.
  • Hosting, monitoring, support, audit and security tools needed to keep the platform available and protected.

We may also share data due to court order, legal obligation, abuse investigation, protection of LYKOS rights, corporate reorganization, merger, asset sale or operational transfer, preserving data subject rights.

7. Payments and financial data

Checkout uses Mercado Pago. For card payments, secure/tokenized fields prevent FotoMemoris from storing the full card number or CVV. We may store only safe data needed for experience and support, such as brand, last digits, installments, gateway identifiers and status.

For Pix, we may store the QR Code, copy-and-paste code, payment URL, expiration, status and references needed so the buyer can track, resume, cancel or change payment method while the charge is pending.

Billing and tax data may be kept for the legally required period even if other account or event data is removed.

8. Event content, image rights and minors

Event photos and videos may contain image, voice and data from other people, including minors. The host is responsible for informing guests, legal guardians and participants about FotoMemoris, obtaining necessary authorizations and choosing privacy settings suitable for the event.

Guests must upload only content they have the right to upload and that does not violate privacy, honor, image rights, copyrights, trademarks, trade secrets or applicable law.

FotoMemoris may remove or restrict content reported or detected as illegal, abusive, sexually explicit, discriminatory, violent, fraudulent or incompatible with these documents.

9. Retention and deletion

  • Event media: available during the contracted or configured period. The current default is 30 days after the event, unless extended retention or a specific rule is shown in the product.
  • Events and metadata: may be kept as needed for account, history, support, audit, security, legal obligations and defense of rights.
  • Host account: remains active until deletion request, termination or prolonged inactivity under operational policy.
  • Guest participation: may remain linked to the event for access control, audit, deletion of own media and abuse prevention.
  • Tax, accounting and payment records: kept for the applicable legal period.
  • Technical and security logs: kept as needed for security, diagnostics and audit.
  • Backups: data deleted from primary systems may remain in backups for a limited period until normal rotation.

At the end of the retention period or after event deletion, media may be permanently removed. Before deletion, the host should download anything they want to preserve.

10. Security and incidents

We adopt technical and organizational measures compatible with the size and risk of the service, including Firebase authentication, Firestore/Storage access rules, HTTPS/TLS, permission controls, audit records, segregation of critical functions and providers with recognized security practices.

No system is immune to incidents. If we identify a relevant incident involving personal data, we will assess the risk and notify data subjects and competent authorities as required by the LGPD and ANPD guidance.

11. Cookies, local storage and analytics

We use cookies, localStorage and similar technologies mainly for session, language, authentication, preferences, security, flow progress and event functionality. We may use aggregated metrics to understand performance and product usage.

If we start using non-essential marketing or behavioral advertising cookies, we will update this Policy and, when required, request specific consent.

12. International transfers

Because we use global providers, data may be stored or processed outside Brazil. When this happens, we will use appropriate protection mechanisms, vendor contracts and safeguards compatible with the LGPD.

13. Data subject rights

Under the LGPD, you may request confirmation of processing, access, correction, anonymization, blocking, deletion, portability, information about sharing, review of automated decisions when applicable, information about consent and withdrawal of consent.

Some requests may be limited by legal obligation, security, fraud prevention, trade secrets, third-party rights or the need to preserve records for defense of rights.

To exercise rights, write to contact@lykoscompany.com with enough information for us to verify your identity and locate the data.

14. Requests about photos and videos

If you are a guest and want to delete media you uploaded, use available event controls when present or contact support. If you appear in media uploaded by someone else, we may guide contact with the host and assess removal when there is rights violation, abuse or legal obligation.

Removal inside FotoMemoris does not delete copies third parties have already downloaded, shared, screenshotted or stored outside the platform.

15. Children and teenagers

FotoMemoris may be used in family, school or children events, but it is not intended for autonomous registration by children. Minors must use the platform with authorization and supervision from legal guardians.

Hosts of events involving minors must obtain necessary consents from parents or guardians and choose privacy settings compatible with the sensitivity of the event.

16. Changes to this Policy

We may update this Policy to reflect changes in the product, providers, law or security practices. The update date will be shown at the top of the page.

When material changes materially affect data processing, we may highlight the notice in the product, by email, SMS or another appropriate channel.

17. Contact

Email: contact@lykoscompany.com.

When contacting us, avoid sending unnecessary sensitive data and include the phone, email, event or payment involved so we can analyze the request faster.