Privacy Policy
What we collect, who can see it, and how to get rid of it.
Team Capture is a tool a business gives its own staff for capturing photos and video at events. This policy covers the iOS app and the web dashboard.
Last updated 21 August 2026
Who is responsible for your information
Team Capture is operated by Bluhook. Your employer, or the organization that invited you, decides who joins their workspace and what happens to the media captured in it. We hold that media on their behalf.
What we collect
Your account
Your email address, which is how you sign in, and an account identifier we generate. The iOS app signs you in with a one-time code sent to that address. The dashboard accepts either a one-time code or a password, and where you set a password we store only a hash of it, never the password itself.
The photos and videos you choose to upload
Nothing is uploaded on its own. The app takes only the items you select, or the ones you record with it. It does not read your photo library in the background.
Information carried inside those files
When a photo or video is uploaded we keep the details the file already contains, because they are what make the media findable later:
- the date and time it was taken
- the location it was taken, when the file records one
- its dimensions, and for video its length
- its file name, size and format
Location is precise, and it reaches us two ways. If your phone saved coordinates into a photo you picked from your library, those coordinates are stored with it. Separately, when you take a photo inside Team Capture and you have granted Team Capture location permission, the app takes its own reading at that moment and attaches it, even if the photo itself carries none. Either way the coordinates are visible to anyone who can see that photo, and they are sent to OpenStreetMap to be turned into a place name. To stop the first, turn off location for the Camera app in iOS Settings or remove location when you share. To stop the second, deny or revoke location permission for Team Capture itself in iOS Settings — turning it off for the Camera app does not cover this path.
What you type into the access-request form
If you ask for access from this website, we receive the name, email address, company and description of the events you run that you enter on that form. It is mailed to our inbox through Resend, named in the list of processors below, and we use it only to reply to you about access. Submitting it also puts your IP address in a short-lived, in-memory rate limit for ten minutes, so that the form cannot be flooded. That IP is not written to a database and is not sent with the message.
Your place in a workspace
Which organization you belong to, your role in it, and when you joined or left.
What we do not collect
We do not run advertising. We do not track you across other apps or websites, we do not sell information to anyone, and we do not record your screen or your session.
Product analytics and crash reporting
The iOS app does send two kinds of operational information, and both are named in the list of processors below. PostHog receives product analytics: which screens are opened, whether a capture or an upload succeeded or failed, and a few product actions — that an album was created, and that media was assigned to an album, with how many items were in that assignment. All of it is tied to your account identifier. Session replay is switched off. Sentry receives crashes and errors so we can fix them; automatic collection of personal information is switched off and the URLs of network requests are stripped from its trail, because a signed URL is a credential. Both are sent your account identifier, so a crash or a failed upload can be tied to the session that produced it. Neither receives your photos or videos.
Who can see what you upload
These rules are enforced by the system itself, not by convention:
- A photo you put in an album is visible to everyone in your workspace. Albums exist to share.
- A photo not in an album is visible only to you, and to the workspace owner and admins.
- Editing and approving is limited to your own media, and to managers and above.
- Nobody outside your workspace can see any of it, and one workspace can never see another's.
Losing access is immediate. If your membership is removed you stop being able to open that workspace's media straight away. One bound worth knowing: a media link your app had already opened keeps working until it expires, which is five minutes for a photo and up to four hours for a video.
Why we hold it
To sign you in, to store and show the media your organization asked you to capture, to apply the access rules above, and to keep the service working and secure. We do not use your media or your account to advertise anything, and we do not sell information to anyone.
Who else processes it
This list is deliberately short. These companies process data so the product can function and for no purpose of their own. All but one are under contract with us; the exception is OpenStreetMap, whose Nominatim service is a free public one used under its usage policy rather than an agreement:
- Supabase — stores the database and the media files, in the United States.
- Resend — delivers your sign-in code and password resets by email. It also carries two other kinds of message: an access-request form submission from this website, containing the name, email address, company and event description entered on that form; and a membership invitation, containing the invited email address, the name of the organisation inviting them, and an install link. That invitation therefore reveals the organisation to the address it is sent to.
- Apple — distributes the app through TestFlight and the App Store.
- PostHog — product analytics from the iOS app, as described above.
- Sentry — crash and error reporting from the iOS app.
- Expo — serves over-the-air code updates. The app checks for one at every launch; that request carries device and build information, never your media or your account.
- OpenStreetMap — turns coordinates into a place name. Wherever we hold a location for an item, from the file or from the app’s own reading, those coordinates are sent to its Nominatim service under its usage policy. The photo itself is never sent.
We will disclose information if the law requires it, and would tell you unless we were prohibited from doing so.
How long we keep it
You can delete media you uploaded yourself, from the app. Two things about that are worth stating plainly. First, deleting marks the item deleted and takes it out of the product, but the stored file is not yet erased automatically; to have the bytes removed as well, write to us and we will do it. Second, there is today no control anywhere — not in the app, not in the dashboard — that lets an administrator delete somebody else’s media, so anything other than your own uploads is removed by writing to us. Account records are removed when the account is deleted, and ordinary operational logs are kept briefly and then discarded.
When a workspace is closed its records are removed. The stored files themselves are erased on request rather than automatically — write to us and we will do it.
Deleting your account
You can delete your account yourself. Open the dashboard, go to Account, and choose Delete my account. This removes your account and your membership. If you have already left the workspace and can no longer sign in to reach that page, write to us at privacy@teamcapture.app and we will delete it for you.
Media you captured for an organization belongs to that organization and stays in its workspace after you leave, in the same way work produced for an employer stays with the employer. If you want specific items removed as well, write to us at privacy@teamcapture.app and we will help — there is no administrator control for deleting another person’s media today, so this is the route.
When a workspace is closed, its records are removed. The stored files are erased on request rather than automatically — write to us and we will do it.
Your rights
Depending on where you live you may have the right to see a copy of your information, correct it, delete it, or object to how it is used. Write to privacy@teamcapture.app and we will respond. Because your organization controls its workspace, we may need to pass a request on to them.
Security
Everything travels over an encrypted connection and is stored encrypted. Access is enforced in the database itself rather than only in the app, so the rules above hold no matter how the data is reached. Your sign-in is kept on your device in the iOS keychain.
Children
Team Capture is a workplace tool and is not intended for children. It is rated 17+ and we do not knowingly collect information from anyone under that age.
Changes to this policy
If we change what we collect or who can see it, we will update this page and change the date at the top. Material changes are told to workspace administrators directly.
Contact
Questions about this policy, or about information we hold, go to privacy@teamcapture.app.