Privacy Policy

Last updated: January 15, 2026

Only 35 ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our digital asset management platform for photographers.

TL;DR (Too Long; Didn't Read)

Your photographs are yours, we don't claim any copyright or usage rights. We treat your photographs as they were our photographs and we use the tool to make your life easier. We comply with GDPR and we don't sell any of your information. If you have any doubts, just ask! :D

1. Data Controller

The data controller responsible for your personal data is:

Carlo Nicora Partita IVA: 01356480325 Email:

As the data controller, we determine the purposes and means of processing your personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Italian Data Protection Code (Legislative Decree 196/2003, as amended by Legislative Decree 101/2018).

2. Information We Collect

We collect and process the following categories of personal data:

2.1 Account Information

  • Email address
  • Name
  • Password (stored as a secure hash, never in plain text)
  • Account preferences and settings

2.2 Photographs and Content

  • Digital photographs you upload to the platform
  • EXIF metadata embedded in your photographs (camera model, date taken, GPS coordinates if present, exposure settings)
  • Titles, descriptions, and tags you assign to photographs
  • Albums, projects, and organizational structures you create

2.3 AI-Generated Analysis

When you use our AI-powered features, we generate and store:

  • Automatic tags and descriptions
  • Semantic embeddings for visual search
  • Scene and object recognition data
  • Aesthetic quality assessments

Important: Your photographs are processed by third-party AI models via OpenRouter to generate this analysis. AI providers may temporarily retain your data for up to 55 days for abuse monitoring and service improvement, but do not use your photographs to train their models. Only the resulting tags, descriptions, and embeddings are permanently stored by Only 35.

2.4 Payment Information

  • Billing name and address
  • Payment card details are processed directly by Stripe and never stored on our servers
  • Transaction history and subscription status

2.5 Usage Data

  • IP address and approximate location
  • Browser type and device information
  • Pages visited and features used
  • Error logs and performance data

3. How We Use Your Information

We use your personal data for the following purposes:

3.1 Service Provision

  • Creating and managing your account
  • Storing and organizing your photographs
  • Enabling client delivery and sharing features
  • Processing payments and managing subscriptions

3.2 AI-Powered Features

  • Automatic tagging and description generation
  • Visual similarity search

3.3 Service Improvement

  • Analyzing usage patterns to improve features
  • Debugging and fixing technical issues
  • Developing new features based on user needs

3.4 Communication

  • Sending essential service notifications
  • Responding to support requests
  • Informing you of significant changes to our service or policies

3.5 Legal Compliance

  • Complying with legal obligations
  • Responding to lawful requests from authorities
  • Protecting against illegal activity and enforcing our terms

4. Legal Basis for Processing

Under GDPR Article 6, we process your personal data based on the following legal grounds:

4.1 Contract Performance (Article 6(1)(b))

Processing necessary to provide our services to you, including account management, photo storage, and subscription handling.

4.2 Explicit Consent (Article 6(1)(a) and Article 9(2)(a))

For certain optional features, we rely on your explicit consent. This consent is freely given, specific, informed, and can be withdrawn at any time.

4.3 Legitimate Interests (Article 6(1)(f))

For service improvement, security monitoring, and fraud prevention, where our interests do not override your fundamental rights and freedoms.

4.4 Legal Obligation (Article 6(1)(c))

Where we are required to process data to comply with applicable laws, such as tax regulations or responding to lawful requests from authorities.

5. Third-Party Service Providers

We work with carefully selected third-party service providers who process data on our behalf. All providers are bound by data processing agreements ensuring GDPR compliance.

5.1 Stripe (Payment Processing)

  • Purpose: Processing subscription payments
  • Data shared: Email, billing address, payment card details
  • Location: EU and US (Privacy Shield successor mechanisms in place)
  • Privacy policy: stripe.com/privacy

5.2 Hetzner (Cloud Storage)

  • Purpose: Storing your photographs and associated data
  • Data shared: Photographs, metadata, encrypted account data
  • Location: European Union (Germany/Finland)
  • Privacy policy: hetzner.com/legal/privacy-policy

5.3 AI Processing (OpenRouter & Google Vertex AI)

We use one or both of the following services for AI-powered image analysis:

OpenRouter (AI Routing to Google Gemini)

  • Purpose: Routing AI requests for image analysis (tagging, descriptions, visual search)
  • Data shared: Photographs and text prompts for analysis
  • Data retention: Up to 55 days by Google (Gemini) for abuse monitoring and service improvement
  • Training: Your data is not used to train AI models
  • Location: Requests are routed via OpenRouter to Google Gemini (US/EU infrastructure)
  • Privacy policies: openrouter.ai/privacy, cloud.google.com/terms/cloud-privacy-notice

Google Vertex AI (Direct EU Processing)

  • Purpose: AI-powered image analysis (tagging, descriptions, visual search)
  • Data shared: Photographs and text prompts for analysis
  • Data retention: Up to 55 days for abuse monitoring and service improvement
  • Training: Your data is not used to train AI models
  • Location: European Union (configured for EU-only processing)
  • Privacy policy: cloud.google.com/terms/cloud-privacy-notice

Note: Regardless of which service processes your request, Google may temporarily retain your data for up to 55 days for safety monitoring and service improvement. They do not use your photographs to train their AI models. OpenRouter itself does not retain prompts or completions.

We do not sell your personal data to third parties. We do not share your photographs with any third parties except as necessary to provide the service.

6. Data Storage & Security

We implement comprehensive technical and organizational measures to protect your data:

6.1 Encryption

  • All data transmitted between your device and our servers uses TLS 1.3 encryption

6.2 Access Controls

  • Role-based access controls for internal staff
  • Regular access audits and principle of least privilege

6.3 Infrastructure Security

  • Hosted on enterprise-grade European data centers
  • Regular security assessments and penetration testing
  • Automated threat detection and monitoring
  • Redundant backups with geographic distribution

7. Data Retention

7.1 Active Accounts

We retain your personal data for as long as your account remains active and as necessary to provide our services to you.

7.2 Account Deletion

When you request account deletion:

  • Immediate: Account access is disabled
  • Within 30 days: All personal data, photographs, and associated content are permanently deleted from Only 35
  • Exception: We may retain limited data required for legal compliance (e.g., transaction records for tax purposes) for the legally mandated period

AI Provider Retention: Please note that photographs previously processed by our AI services (Google Gemini via OpenRouter or Google Vertex AI) may be retained by Google for up to 55 days after processing for abuse monitoring purposes, even after you delete your account with us. This retention is governed by Google's data policies and is outside our direct control. After this period, Google automatically purges this data.

7.3 Backups

Automated backups may retain data for up to 30 additional days after deletion, after which backup copies are also permanently purged.

8. Your Rights Under GDPR

Under the General Data Protection Regulation, you have the following rights regarding your personal data:

8.1 Right of Access (Article 15)

You have the right to obtain confirmation of whether we process your personal data and, if so, to access that data along with information about how it is processed.

8.2 Right to Rectification (Article 16)

You have the right to have inaccurate personal data corrected and incomplete data completed.

8.3 Right to Erasure (Article 17)

You have the right to have your personal data deleted ("right to be forgotten") under certain circumstances, including when the data is no longer necessary for its original purpose.

8.4 Right to Restriction (Article 18)

You have the right to request restriction of processing in certain circumstances, such as when you contest the accuracy of your data.

8.5 Right to Data Portability (Article 20)

You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit that data to another controller.

8.6 Right to Object (Article 21)

You have the right to object to processing based on legitimate interests or for direct marketing purposes.

8.7 Right to Withdraw Consent (Article 7(3))

Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

8.8 Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. For Italy, this is the Garante per la protezione dei dati personali (www.garanteprivacy.it).

Exercising Your Rights

To exercise any of these rights, please contact us at . We will respond to your request within 30 days. We may request verification of your identity before processing your request.

9. Cookies

We use cookies and similar technologies for the following purposes:

9.1 Essential Cookies

Required for the platform to function. These include authentication tokens and session management cookies. You cannot opt out of essential cookies while using the service.

9.2 Preference Cookies

Store your settings and preferences (such as language and display options) to provide a consistent experience.

9.3 What We Don't Use

  • We do not use third-party advertising cookies
  • We do not use cross-site tracking technologies
  • We do not sell cookie data to third parties

10. Children's Privacy

Only 35 is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information immediately.

Note: The age of consent for data protection purposes in Italy is 14, but our service requires users to be 18 or older due to the professional nature of the platform and potential for adult artistic content.

11. International Data Transfers

Your data is primarily stored and processed within the European Union. Where data is transferred outside the EU, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses approved by the European Commission
  • Data Processing Agreements with all sub-processors
  • Assessment of third-country legal frameworks

11.1 AI Processing

For AI-powered features:

  • Google Vertex AI: When using Vertex AI, your data is processed entirely within the European Union and does not leave the EU.
  • OpenRouter/Google Gemini: When using OpenRouter, requests may be routed to Google infrastructure in the US or EU. For US transfers, protection is provided under the EU-US Data Privacy Framework, under which Google LLC is a certified participant.

11.2 Payment Processing

Payment data transferred to Stripe's US infrastructure is protected under Standard Contractual Clauses and Stripe's certification under the EU-US Data Privacy Framework.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. When we make material changes:

  • We will update the "Last updated" date at the top of this policy
  • We will notify you by email for significant changes affecting your rights
  • We will provide notice within the application for other updates

Your continued use of the service after changes take effect constitutes acceptance of the updated policy.

13. Contact Us

If you have questions about this Privacy Policy, want to exercise your rights, or have concerns about how we handle your data, please contact us:

Only 35 - Data Protection Email:

We aim to respond to all inquiries within 30 days.