Photo sharing apps and GDPR: what to check, and what providers say in 2026
Selfie, face template, hosting, retention: the five questions to ask an event photo app and what six providers publicly state.

An event photo app with face recognition processes biometric data: under the GDPR it requires explicit consent, limited retention and clear information. Among the providers surveyed, CéSAR Photo states it deletes the selfie after the search, runs its own model (no third-party service) and hosts its database in the EU; most others do not detail these points on their pricing page.
“GDPR compliant” has become a sales argument, but it means little without details. Five questions help sort: what happens to the selfie, what is kept (a template?), who runs the face recognition, where is data hosted, and for how long. The table below lists what each provider publicly states; “not stated” means the information wasn't on the page consulted on October 5, 2026, not that the practice is bad. This article is not legal advice.
The comparison at a glance
| Solution | Personal data | Selfie / face sorting | Storage time | Prices found |
|---|---|---|---|---|
| CéSAR Photo | Selfie deleted after the search, model run by CéSAR Photo itself, database in the EU | Yes, by selfie | 30 days (free), 12 months (paid) | Free, then €49 per event |
| Evokly | Consent explicitly requested; hosting not stated | Yes | 15 days (free), 6 months (paid) | Free (100 photos), then €69 |
| Keep Pics | GDPR claimed; AWS Rekognition according to its site | Yes, according to its site | 1 year (5 years optional) | €49, €79 or €129 depending on guest count |
| Gathmo | Conflicting information: servers in Phoenix (pricing page) or Frankfurt (its blog); to verify | Not mentioned | 30 days (free) to 1 year | €0 (60 uploads), €29, €69 or €89 |
| Waldo Photos | Not stated | Yes | Gold: 50 GB for a year | Gold $49.99 (one-time); Plus $7.99/month |
| Google Photos | Managed by Google | No, not for guests | As long as the album exists | Free within the Google quota |
CéSAR Photo: most detailed about its practices
Explicit consent before analysis; selfie deleted a few seconds after the search; only a 512-number template is kept, comparable only with faces from the same event; InsightFace model run by CéSAR Photo; full erasure at gallery expiry or deletion. Database in the EU (Neon), photos on Cloudflare R2, application on Vercel: the privacy policy lists the subprocessors.
Evokly: explicit consent stated
Its page states consent is explicitly requested before the selfie is compared; hosting and selfie retention are not stated on the page consulted.
Keep Pics: GDPR claimed, third-party provider
States GDPR compliance and says it uses AWS Rekognition, an Amazon service: images therefore pass through a third-party provider. Information from its own site.
Gathmo: hosting: conflicting information
No face recognition mentioned, so no biometric data at stake. On hosting, its pricing page mentions servers in Phoenix (Arizona) with media on Cloudflare, while its blog speaks of Frankfurt: ask which applies before using it for photos of people in Europe.
Waldo Photos: practices not detailed on the pricing page
Face recognition by selfie, but the pricing page consulted details neither hosting nor selfie retention: read its privacy policy before using it for European guests.
Google Photos: Google account and personal settings
No selfie search for guests; data depends on the organizer's Google account and sharing settings. Simple, but without an event-dedicated framework.
The five questions to ask the provider
- Is consent explicitly requested before any face analysis?
- What happens to the selfie: deleted immediately, or kept? For how long?
- What is kept to find the photos (a mathematical template) and can it be deleted?
- Who runs the recognition: the service's own model or a third-party provider? Where are the servers?
- What happens when the gallery ends: complete erasure of photos and templates?
Frequently asked questions
Is a wedding photo app with face recognition GDPR compliant?
It can be if explicit consent is collected before analysis, the selfie is deleted, templates are limited to the event and erased at its end, and subprocessors are governed by contract. Check these five points in the provider's privacy policy.
Where does CéSAR Photo host data?
The database is hosted in the European Union (Neon), photos on Cloudflare R2, the application on Vercel; the recognition model runs on a Hugging Face server that is only computing capacity. The privacy policy details each subprocessor.
Sources: official sites of evokly.io, keeppics.com, gathmo.com, waldophotos.com and support.google.com/photos, accessed October 5, 2026; CéSAR Photo's privacy policy. This article is not legal advice. CéSAR Photo is our own product: this list applies the same criteria to every solution and states their limits.
Compare for yourself
Create a free CéSAR Photo gallery, import a few photos and test selfie search before you choose.
Discover
Read also

Best wedding photo-sharing apps in 2026: 8 solutions compared
CéSAR Photo, Evokly, Keep Pics, Fotify, GuestCam, Gathmo, WedShoots and Google Photos: prices, face recognition, app required, storage time. Which option for which wedding?
Read the article
Best face recognition photo apps for events in 2026
CéSAR Photo, Evokly, Keep Pics, GuestCam, Waldo, FotoOwl and PiciMe: how each guest finds their photos with a selfie, at what price and with what safeguards.
Read the article
Best solutions for sharing corporate event photos in 2026
Seminar, party, trade show, convention: how to give each attendee their photos without a 2 GB file or an expiring link? Six solutions compared.
Read the article