Trust

Security & Privacy

How we protect your photos, face data, and payments, described honestly, with no claims we can’t back up.

Last updated: June 22, 2026

01Encryption

  • In transit: all traffic to and from DSPRS is encrypted with TLS (HTTPS).
  • At rest: data stored on our Google Cloud infrastructure is encrypted at rest.
  • Saved payment tokens: additionally encrypted by us with AES-256-GCM before storage.
We do not provide end-to-end encryption. Event galleries are shared through private, hard-to-guess links and event codes, not listed publicly, but anyone you share a link or code with can view those photos.

02Infrastructure

DSPRS runs on Google Cloud, using managed, regularly-patched services. We separate environments, restrict internal access to personal data on a need-to-know basis, and monitor for abuse and operational issues.

03Payment security

Payments are processed by Paymob. Your card is tokenized by Paymob; we never see or store your full card number, expiry, or security code. The reusable token we keep for renewals is encrypted at rest. See our Subscription Terms for details.

04Your privacy controls

  • Choose which events can match your selfie.
  • Delete your face signature, photos, or account at any time.
  • Control how and with whom you share gallery links.

05Compliance & standards

We design DSPRS to align with applicable data-protection law, including GDPR principles for users in the EU/EEA and UK and the data-protection law of the Arab Republic of Egypt. See our GDPR page and Privacy Policy.

We do not currently hold formal third-party certifications such as SOC 2 or ISO 27001. We’ll say so clearly here if and when that changes. We won’t imply certifications we don’t have.

06Reporting a vulnerability

Found a security issue? Please email privacy@dsprs.com with details so we can investigate. We appreciate responsible disclosure and will work with you in good faith.