privacy
Last updated September 26, 2026.
astra is a camera for nights out. You shoot, nobody sees anything until the capsule develops, and the photos belong to the people who were there — or, if the host makes the capsule public, to anyone using astra once it develops. This policy says what we collect, why, and what we never do with it.
what we collect
Account: your email address, which is how you sign in (with a one-time code sent to it), the name and handle you choose, and your phone's time zone, which settings shows you. Any social handles you add to your profile are kept with it. If you join a capsule as a guest, you give only a first name: there is no email, handle or password, just an account tied to this phone, until you add an email to keep your photos.
Profile photo and covers: a profile photo you pick is uploaded and shown with your name. A cover you pick for a capsule is uploaded and shown to whoever can see that capsule.
Photos: everything you shoot inside astra is uploaded to our servers so it can develop and be shown to the people allowed to see it. We keep the original file and a small thumbnail of it. We do not scan your photos for advertising, train models on them, or sell or give them to anyone.
Capsule details: the name of a capsule, who joined and who left, when it started, ended and developed, its settings, and which film each photo was shot on.
Notifications: if you allow notifications, Expo receives your phone's Apple push token and an installation ID and gives astra a push token for it. We store it with your account and the kind of device, and use it only to tell you when a capsule you are in has developed. Signing out on that phone removes it.
Purchases: if you buy astra plus, a peek, or a bigger capsule, Apple processes the payment and RevenueCat keeps track of what you bought. RevenueCat tells our server what was bought, when, the price paid, its store transaction number and which astra account bought it, so the purchase counts for that account on any phone. RevenueCat also uses these records to show us purchase totals, trends and each account's purchase history. We never receive your card number.
Reports and blocks: when you report a photo, we receive the photo, the reason you chose and your account, so we can review it. Who you block is stored with your account, so it follows you to a new phone.
Device and usage: RevenueCat receives the identifier Apple gives astra on your phone, so purchases match your device. Each time astra opens it asks Expo whether there is an update, sending a random install ID with your app and system version; Expo shows us only totals, never tied to your account. Apart from these and the push token above, astra collects no device identifiers. astra has no crash-reporting service and no advertising. If you allow it in your phone settings, Apple may share crash reports with us.
who can see your photos
Before a capsule develops, nobody can see the photos, including the host and including us in normal operation. The one exception is a peek: a single random photo shown privately to the person who bought it. A host can turn peeks off for their capsule.
After a capsule develops, every member of that capsule can see all of its photos, and if the host made it public, so can anyone using astra (see public capsules below). The host can delete any photo for everyone and remove people. Anyone can report a photo.
You can delete any photo you took once the capsule develops, from the photo itself, and it goes for everyone. Before then nobody can see your photos, you included, so they cannot be picked out one by one; instead, when you leave a capsule you can take every photo you took in it with you. You can leave any capsule you did not start; you stop seeing it, and the photos you took stay in it unless you choose to delete them.
A capsule you shoot alone starts out visible only to you, and becomes public only if you make it public yourself.
Anyone with an astra account can look you up by your handle and see your name, handle, profile photo and the social handles you added. Your profile photo is stored at a web address that loads for anyone who has it. Being someone's friend shows them none of your photos; a friend's profile shows only the capsules you were both in. Your friends list is kept on your phone.
A capsule's join link or code shows anyone who has it, signed in or not, the capsule's name, when it runs, when it develops and how many people are in it. It shows no photos, no names and nothing else, and it stops working once the capsule develops.
There are no followers, no likes, no comments, no counts and no ranking anywhere in astra, and nothing is ever posted on your behalf.
public capsules
A host can make a capsule public. A public capsule appears in the gallery inside astra once it has developed, where anyone using astra can see it — including people who were not there — along with the names of the people who shot it. New capsules you start with other people are public unless you change them, and the host can change it at any time, before or after the capsule develops.
Public changes who, never when. Nothing in a public capsule is visible to anybody, including the host, until it develops.
Your own photos stay yours. The host decides whether the capsule is public; you decide whether your own frames are in it. Any photo you took can be taken out of a public capsule from the photo itself, and it stays visible to the people who were there.
Nothing you had already shot became public. Every capsule that existed before we added this is visible only to the people who were in it, and we did not change any of them. Public applies only to capsules created afterwards.
The gallery is inside astra, for people signed in to it. It is not a public web page, it is not searchable from outside astra, and we do not show your photos anywhere else.
reporting and blocking
Any photo can be reported from the photo itself. A reported photo disappears for you immediately, and we review every report within 24 hours and remove photos that break our terms. You can also block whoever took a photo, which hides everything they have ever shot from you and leaves their photos out of your peeks; they are not told, and you can undo it in settings.
Photos in public capsules that several people report are hidden automatically while we look at them. We keep a record of the action we take on a report.
how long we keep things
Photos stay in your capsules until you delete them, the host deletes them, or you delete your account. There is no expiry.
When you delete your account from settings, your account, profile, profile photo, push token, blocks, capsule memberships and every photo you took are deleted from our servers, files included. A capsule you started that others are in passes to whoever has been in it longest, without its cover; the photos they took stay in it. A capsule only you were in is deleted, with everything in it. Photos you already saved to your phone stay on your phone. Apple and RevenueCat keep their own record of past purchases under their policies. Two exceptions: if a photo you took, or one in a capsule you host, is held for a legal reason such as a report of child sexual abuse material, the account cannot be deleted until the hold ends, and we keep what the law requires; and reports you made stay with the photo they concern, under a key that no longer points to you. If a subscription you did not cancel renews after you delete your account, RevenueCat still tells us, and we keep that notice without an account.
A guest cannot sign back in after signing out. Their photos stay in the capsules they joined, but nothing on another phone can reach them. To keep them, add an email first; to delete them, delete the account from settings before signing out.
services we rely on
Supabase stores accounts, photos and push tokens, and Resend delivers the sign-in codes by email. Expo delivers app updates (and counts app launches from those update checks) and passes reveal notifications to Apple, which delivers them to your phone. RevenueCat manages purchases and subscriptions, and Apple processes payments. Each of them processes data only to provide its service to us, which for RevenueCat includes the purchase reports described above.
your choices
You can edit your name, handle, profile photo and socials in the app, save any photo from a capsule you were in to your phone, delete your own photos, take them out of a public capsule, leave a capsule, block people, and delete your account at any time from settings.
Camera, photo library and notification permissions are asked for in the app and can be changed in your phone settings. You can turn reveal notifications off in settings; if you never allow notifications, no push token is sent.
age
astra is not for children under 13, and you must be old enough to agree to these terms where you live. We do not knowingly collect information from children under 13.
changes and contact
If this policy changes in a way that matters, we will tell you in the app before it takes effect. Questions go to support@astracamera.com.
Questions go to support@astracamera.com.