ViewItOnce
Last updated: July 13, 2026
When you first open the app, your device generates a random ID and a pair of cryptographic keys. We store the random ID, the public halves of those keys, and a push notification token so we can tell your paired partner when a photo arrives. None of this identifies you personally.
Photos are encrypted on your device before they are uploaded. Our servers store only the encrypted bytes, and we do not hold the keys to read them. A photo is deleted from our servers the moment it has been viewed the allowed number of times, or after 24 hours if it is never opened — whichever comes first.
The only third party involved is our hosting provider, Cloudflare, which stores the encrypted content described above.
Plaintext photos never touch disk. A received photo is decrypted only in memory, shown once, and discarded. Your identity keys live in the device Keychain and never leave the device. Location data and other photo metadata are stripped before a photo is sent.
The app can't prevent screenshots. If your recipient takes one while viewing your photo, we send you a notification, and that's the extent of it.
Deleting the app destroys the keys on your device, which makes anything still on our servers permanently unreadable; the encrypted remnants are cleaned up automatically within 24 hours. Unpairing inside the app immediately expires any undelivered photos.
Questions? Email pawels.apps@gmail.com.
← BackViewItOnce © 2026 Pawel Szydlowski