Privacy policy

ViewItOnce

Last updated: July 13, 2026

In short: There are no accounts. We never ask for your name, email, or phone number. Photos are encrypted on your device before upload, our servers only ever hold bytes we can't read, and each photo is deleted the moment it has been viewed.

What we store on our servers

When you first open the app, your device generates a random ID and a pair of cryptographic keys. We store the random ID, the public halves of those keys, and a push notification token so we can tell your paired partner when a photo arrives. None of this identifies you personally.

Photos are encrypted on your device before they are uploaded. Our servers store only the encrypted bytes, and we do not hold the keys to read them. A photo is deleted from our servers the moment it has been viewed the allowed number of times, or after 24 hours if it is never opened — whichever comes first.

What we don't do

The only third party involved is our hosting provider, Cloudflare, which stores the encrypted content described above.

On your device

Plaintext photos never touch disk. A received photo is decrypted only in memory, shown once, and discarded. Your identity keys live in the device Keychain and never leave the device. Location data and other photo metadata are stripped before a photo is sent.

Screenshots

The app can't prevent screenshots. If your recipient takes one while viewing your photo, we send you a notification, and that's the extent of it.

Deleting your data

Deleting the app destroys the keys on your device, which makes anything still on our servers permanently unreadable; the encrypted remnants are cleaned up automatically within 24 hours. Unpairing inside the app immediately expires any undelivered photos.

Contact

Questions? Email pawels.apps@gmail.com.

← Back

ViewItOnce © 2026 Pawel Szydlowski