Privacy policy
What we know about you
Crit measures nothing, advertises nothing, and sells nothing to anybody. This page is the specific version of that sentence.
Last updated August 30, 2026
1. Who is responsible
The controller of your personal data is Thodoris Markou, sole trader (ατομική επιχείρηση), established in Greece. Write to hello@crit.photo about anything on this page.
There is no data protection officer. Crit is small enough that the address above reaches the person who can actually answer.
2. What we hold
All of it, in the order you produce it.
| What | Which fields |
|---|---|
| Your account | Name, email address, an irreversible hash of your password, and the dates it was made and changed. Never the password itself. |
| Signing in | One row per active sign-in, holding the time, your IP address and your browser's user agent. It is what keeps you signed in without asking for your password again, and what would tell one machine from another if an account were broken into. Signing out deletes the row; any left behind expire after 30 days and are swept nightly. |
| A crit master's profile | Your written bio, portfolio link, the three prices, specialities, your picture, and a Stripe account identifier. All of it public on your listing except the identifier. |
| Sets and photographs | The title and description you write, and a working copy of each photograph plus a thumbnail. Not your original file. |
| Votes | The name a voter typed, their mark on each frame, any note they wrote, and a random token in their browser used to recognise the same ballot. If they were signed in, their account instead of the token. |
| Invitations | The email addresses you invite to a set, and a token for each link, until you withdraw the invitation or delete the set. |
| Paid critiques | Your brief, the master's written read, the price and our commission, every date in the job, the moment you agreed to the work starting, and, where one happened, the reason a fee was questioned and what was decided. |
| Payments | Stripe identifiers only: a checkout session, a payment intent, a refund. No card number, expiry or security code ever reaches Crit. |
| Reviews | The score and words you write about a master after a delivered critique, published under your name, and their one reply. |
| Server logs | One line per request with the time, the path, and your IP address. Passwords, tokens, email addresses and everything anybody wrote (briefs, critiques, reviews, notes, voter names) are filtered out before the line is written. |
3. Why, and on what legal basis
- To give you the thing you asked for, which covers your account, your sets, your photographs, the votes on them and every part of a paid critique. Legal basis: performance of a contract with you (GDPR article 6(1)(b)).
- To keep the service standing up and honest: rate limits, the sign-in records, the server logs, and stopping abuse. Legal basis: our legitimate interests in a service that works and is not attacked (article 6(1)(f)).
- To send the email the product runs on: password resets, invitations, "your read has landed", the warning before photographs are deleted. Legal basis: contract. These are not marketing and there is no marketing to unsubscribe from, because we do not send any.
- To keep the records the tax authority requires of money that changed hands. Legal basis: legal obligation (article 6(1)(c)).
We do not rely on consent for any of it, which is why there is no consent to withdraw. The cookie banner exists to tell you what the three cookies are, not to ask for permission we do not need.
4. Photographs, and the people in them
A photograph of an identifiable person is that person's personal data as well as your work. When you upload a set, you are the one who decided to show those images to the people you sent the link to, and you are responsible for having whatever permission that needs. Crit holds and displays them on your instruction.
If you are in a photograph on Crit and you should not be, write to hello@crit.photo. You will not have a link, so say what you can and we will find it.
Photographs are never public. They are visible to you, to whoever holds the link or the invitation, and to a master you send the set to. There is one exception and it is deliberate: the preview image a shared voting link unfurls into in a chat app or a social post is the first frame of the set, and once that preview has been fetched it stays fetchable by whoever holds it. Do not share a link to work you are not willing to have one frame of seen.
5. How long we keep it
Photographs are on a clock, and it is printed on the set itself:
- a set nobody has voted on for about 1 month closes itself
- 3 days after it closes, you get one warning email
- 5 days after it closes, the working copies are deleted from our storage for good
Thumbnails, the counts, the notes people wrote and any delivered critique are kept, so that a results page still reads after the photographs have gone. Delete the set yourself at any time and all of it goes at once.
Sign-in records are swept after 30 days. Everything else lives as long as your account does.
Deleting your account deletes your sets, your photographs, your votes, your critiques and the reviews you wrote, immediately. Anything owed to you is refunded first. Two things survive and both are named here rather than buried: records of money that changed hands, which Greek tax law requires us to keep, and a critique somebody else paid for, which is theirs rather than yours.
6. Who else sees it
Four companies, each doing one job, none of them allowed to do anything with your data except that job.
| Who | For what | Where |
|---|---|---|
| Fly.io | Runs the application and the database | Servers in Frankfurt, Germany. Company in the United States |
| Cloudflare | Stores the photographs (R2) | Company in the United States |
| Resend | Sends the email | Company in the United States |
| Stripe | Takes the payment, pays the masters, holds the card details we never see | Stripe Payments Europe, Ireland, and Stripe in the United States |
Where that means data reaching the United States, it is covered by the European Commission's standard contractual clauses or by the provider's certification under the EU to US Data Privacy Framework, in each provider's own data processing agreement.
Beyond those four: nobody. We do not sell data, we do not share it with advertisers, there is no analytics on this site and there is no third party script on any page.
8. Your rights
Under the GDPR you can ask us for a copy of what we hold about you, to correct it, to delete it, to restrict what we do with it, to object to processing based on our legitimate interests, and to receive it in a portable form.
Some of it you can do yourself and immediately. Your account page changes your picture and deletes your account outright, and a crit master's profile page edits everything on their listing. Your name and your email address are not editable in the product yet, so for those, and for a copy of what we hold, or anything else on this page, write to hello@crit.photo. You will have an answer inside a month, which is the deadline the law sets and considerably longer than it will take.
If you think we have handled your data badly you can complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias 1 to 3, 115 23 Athens, dpa.gr, or to the authority in the EU country where you live. We would rather you told us first.
9. Age
Crit is not for children. You need to be 15 or over to have an account, which is the age Greek law sets, and older where the country you live in sets a higher one. We do not knowingly hold data about anybody younger, and we delete it if we find out we do.
10. Keeping it safe
Everything is served over HTTPS. Passwords are stored as bcrypt hashes and cannot be read back, by us or by anybody who steals the database. Photographs are served through short-lived signed links rather than public addresses. Sign-in sessions expire after 30 days. Card details never touch our servers.
If a breach happens that puts you at risk, you will hear it from us, and the supervisory authority will hear it within 72 hours.
11. What we never do
- Sell or rent your data, to anybody, for anything
- Use your photographs to train a model, ours or anybody else's
- Advertise, profile you, or run analytics
- Make a decision about you automatically that has any legal effect
- Send marketing email
12. Changes
The date at the top is when this last changed. Anything that changes what we collect or who sees it is emailed to you before it takes effect.