All articles
Guides Updated October 5, 2026 8 min read

Photo sharing apps and GDPR: what to check, and what providers say in 2026

Selfie, face template, hosting, retention: the five questions to ask an event photo app and what six providers publicly state.

Guests taking photos with their phones during an event

An event photo app with face recognition processes biometric data: under the GDPR it requires explicit consent, limited retention and clear information. Among the providers surveyed, CéSAR Photo states it deletes the selfie after the search, runs its own model (no third-party service) and hosts its database in the EU; most others do not detail these points on their pricing page.

“GDPR compliant” has become a sales argument, but it means little without details. Five questions help sort: what happens to the selfie, what is kept (a template?), who runs the face recognition, where is data hosted, and for how long. The table below lists what each provider publicly states; “not stated” means the information wasn't on the page consulted on October 5, 2026, not that the practice is bad. This article is not legal advice.

The comparison at a glance

SolutionPersonal dataSelfie / face sortingStorage timePrices found
CéSAR PhotoSelfie deleted after the search, model run by CéSAR Photo itself, database in the EUYes, by selfie30 days (free), 12 months (paid)Free, then €49 per event
EvoklyConsent explicitly requested; hosting not statedYes15 days (free), 6 months (paid)Free (100 photos), then €69
Keep PicsGDPR claimed; AWS Rekognition according to its siteYes, according to its site1 year (5 years optional)€49, €79 or €129 depending on guest count
GathmoConflicting information: servers in Phoenix (pricing page) or Frankfurt (its blog); to verifyNot mentioned30 days (free) to 1 year€0 (60 uploads), €29, €69 or €89
Waldo PhotosNot statedYesGold: 50 GB for a yearGold $49.99 (one-time); Plus $7.99/month
Google PhotosManaged by GoogleNo, not for guestsAs long as the album existsFree within the Google quota

CéSAR Photo: most detailed about its practices

Explicit consent before analysis; selfie deleted a few seconds after the search; only a 512-number template is kept, comparable only with faces from the same event; InsightFace model run by CéSAR Photo; full erasure at gallery expiry or deletion. Database in the EU (Neon), photos on Cloudflare R2, application on Vercel: the privacy policy lists the subprocessors.

Evokly: explicit consent stated

Its page states consent is explicitly requested before the selfie is compared; hosting and selfie retention are not stated on the page consulted.

Keep Pics: GDPR claimed, third-party provider

States GDPR compliance and says it uses AWS Rekognition, an Amazon service: images therefore pass through a third-party provider. Information from its own site.

Gathmo: hosting: conflicting information

No face recognition mentioned, so no biometric data at stake. On hosting, its pricing page mentions servers in Phoenix (Arizona) with media on Cloudflare, while its blog speaks of Frankfurt: ask which applies before using it for photos of people in Europe.

Waldo Photos: practices not detailed on the pricing page

Face recognition by selfie, but the pricing page consulted details neither hosting nor selfie retention: read its privacy policy before using it for European guests.

Google Photos: Google account and personal settings

No selfie search for guests; data depends on the organizer's Google account and sharing settings. Simple, but without an event-dedicated framework.

The five questions to ask the provider

  • Is consent explicitly requested before any face analysis?
  • What happens to the selfie: deleted immediately, or kept? For how long?
  • What is kept to find the photos (a mathematical template) and can it be deleted?
  • Who runs the recognition: the service's own model or a third-party provider? Where are the servers?
  • What happens when the gallery ends: complete erasure of photos and templates?

Frequently asked questions

Is a wedding photo app with face recognition GDPR compliant?

It can be if explicit consent is collected before analysis, the selfie is deleted, templates are limited to the event and erased at its end, and subprocessors are governed by contract. Check these five points in the provider's privacy policy.

Where does CéSAR Photo host data?

The database is hosted in the European Union (Neon), photos on Cloudflare R2, the application on Vercel; the recognition model runs on a Hugging Face server that is only computing capacity. The privacy policy details each subprocessor.

Sources: official sites of evokly.io, keeppics.com, gathmo.com, waldophotos.com and support.google.com/photos, accessed October 5, 2026; CéSAR Photo's privacy policy. This article is not legal advice. CéSAR Photo is our own product: this list applies the same criteria to every solution and states their limits.

CéSAR

Compare for yourself

Create a free CéSAR Photo gallery, import a few photos and test selfie search before you choose.

See pricing

Read also