Legal
Privacy Notice
How Nokoru uses and protects personal information
Effective 12 August 2026 · last updated 8 September 2026
Contents
- Who we are
- Information we collect
- Why we use personal information and our lawful bases
- Where information comes from
- Other people in your books - and you, if you're in someone else's
- Who we share information with
- International transfers
- How long we keep information
- Security
- Your rights
- Complaints
- Google user data
- Changes to this notice
1. Who we are
Nokoru Ltd (company number 17391086, registered in England and Wales) is the controller responsible for the personal information described in this notice.
Email (fastest way to reach us): [email protected]
Post: Nokoru Ltd, 124-128 City Road, London, England, EC1V 2NX
This notice applies when you use our website or app, create an account or album, upload content, place or receive an order, are named as a gift recipient, contact us, join a waitlist or appear in content uploaded by a customer.
Our service is intended for adults aged 18 or over, and we do not knowingly permit under-18 accounts. A photo or video may nevertheless contain information about children or other people who do not have a Nokoru account. Section 5 explains how we handle that.
2. Information we collect
- Identity and contact information, including your name, email address, delivery address and confirmation that you are aged 18 or over.
- Account and sign-in information, including your account identifier, the email address we send sign-in links or codes to, and identifiers received from Apple or Google if you choose social sign-in. If you turn on Face ID, fingerprint or a passkey, that check happens entirely on your device - no face, fingerprint or other biometric data ever reaches Nokoru.
- Customer content, including photographs, videos, captions, album information, book layouts and information about people appearing in that content.
- Gift access information, including a recipient display name and mobile phone number supplied by the purchaser. We immediately transform the number into a keyed matching code tied to the specific book and retain only that code and the last two digits, not the clear number. Section 5 explains how this works.
- Order and payment information, including products ordered, delivery status, transaction identifiers, amounts, refunds and disputes. Stripe handles full payment-card details; Nokoru receives payment status, transaction references and limited card information supplied by Stripe.
- Device, usage and security information, including IP address, device and browser type, app version, timestamps, diagnostic events, cookie identifiers and security logs.
- Communications, including customer-support messages, complaints, rights requests and survey responses.
You need to give us an email address to create an account, and a delivery address to receive a book; without them we cannot provide the service.
Camera scanning and image matching
When you scan a Nokoru photobook, live camera frames are analysed on your device to find the matching book image. Nokoru does not upload or store the live camera feed as part of scanning. Our image-matching technology matches a printed image to album content; it does not identify people, perform facial recognition or infer personal characteristics.
Technical image features associated with an album may be stored locally on your device so the matching feature can work. These features relate to the book image, not to a biometric identity profile.
Sensitive information in customer content
We do not ask customers to provide special category information and we do not analyse content to infer health, ethnicity, religion, political opinions, sexual orientation or other sensitive characteristics. However, a customer photo, video or caption may expressly contain sensitive information. Customers must not deliberately include another person's sensitive information unless they have that person's explicit permission or another lawful authority and have provided appropriate information about the upload. Where special category information is present, we apply the additional safeguards and legal conditions required by data protection law.
3. Why we use personal information and our lawful bases
Providing the Nokoru service - contract
We use customer account information, content, image-matching data, order information and delivery details where necessary to create and manage accounts and albums, host and play back your videos for your book's hosting period, manufacture and deliver photobooks, take payment, issue refunds and provide support.
Information about other people in customer content - legitimate interests
A customer may upload information about family members, friends, gift recipients and other people with whom we do not have a contract. We rely on our legitimate interests and the customer's interests in privately creating, storing, printing and delivering the requested memory product. We limit this processing to what is necessary, keep albums private by default, do not use the content for advertising, profiling or AI training, and provide a way for people appearing in content to exercise their rights (section 5).
Gift recipients - legitimate interests
When a purchaser names you as a recipient, we use your details only to set up secure access to a specific book. We never use those details for marketing or to contact you before you choose to claim access. The purchaser remains the owner of the book. Section 5 explains the matching process and how your phone number is protected.
Security, fraud prevention and service administration - legitimate interests
We use limited account, transaction, device and log information to secure our systems, detect abuse or fraudulent payments, investigate incidents, maintain the service, understand faults, improve reliability and establish or defend legal claims. We balance these interests against the impact on individuals and use proportionate safeguards. Our payment provider also runs automated fraud screening; if a payment of yours is declined and you think that is wrong, contact us and we will look into it.
Legal and regulatory compliance - legal obligation
We use and retain information where necessary to keep tax and accounting records, respond to lawful requests, protect data-protection rights, report qualifying security incidents and comply with court, regulatory or law-enforcement requirements.
Optional analytics and similar technologies - consent
Where analytics is enabled, we use PostHog, hosted in the EU, to understand how the website and app are used, for example screens viewed, features used and errors. We do not use non-essential analytics storage or access technologies unless you have given consent where required. PostHog does not receive your photos, videos or captions, and session recording is disabled. You can withdraw consent or turn analytics off at any time in settings. Analytics identifiers are kept for no more than 12 months. In the mobile app, crash and error reporting through Sentry (EU-hosted) follows the same choice, and withdrawing consent stops it immediately. On the website, Sentry operates as part of maintaining and securing the service, described under legitimate interests above. In both cases email addresses, usernames, IP addresses and request URLs are removed before a report is sent, reports are keyed to an opaque account identifier, and performance tracing and session replay are disabled.
No significant automated decisions
We do not make decisions about people based solely on automated processing that produce legal or similarly significant effects.
4. Where information comes from
- Directly from you, when you register, upload content, place an order, use the service or contact us.
- From a purchaser, if they name you as a gift recipient or provide your delivery details.
- From another customer, if they upload content featuring you.
- From Apple or Google, if you choose their social sign-in service.
- From Stripe, banks, card networks, couriers, print fulfilment partners and other service providers involved in your transaction.
- Automatically from your browser, device and our systems through necessary logs and, where you have consented as required, analytics tools.
5. Other people in your books - and you, if you're in someone else's
If you upload information about someone else
You should only upload content that you are entitled to use. Where reasonably possible, tell the people shown or described in the content that it will be processed by Nokoru and direct them to this notice. If the content concerns a child, you must be the child's parent or guardian or otherwise be authorised to use the content.
If you appear in someone's Nokoru book
Customers can upload photos and videos that show other people, including family, friends and children. If that includes you, we hold the images, videos and captions the customer uploaded, stored privately as part of their book. We received this content from the customer, not from you, and we usually cannot contact the people shown because we do not know who they are. This notice is how we make the information available. We host, print and play back the content to provide the book the customer ordered, relying on our and the customer's legitimate interests (section 3). We keep it for the book's hosting period (section 8). We do not use it for advertising, profiling, facial recognition or AI training, and we never make it public.
You have the rights in section 10, including the right to object and to ask for deletion. Email [email protected]; if the content shows your child, you can contact us on their behalf.
Gift recipients - how book matching works
A purchaser can give us a recipient display name and mobile phone number to set up secure access to a specific book. We use the number at entry to generate a keyed matching code tied to that book. Nokoru does not retain the clear number after the code is created. The code remains pseudonymised personal information: it is used only for matching and cannot be used to send a message. We temporarily retain the last two digits so the purchaser can identify the intended recipient. We do not use the purchaser-supplied number to contact the recipient or spoil the surprise. Giving access does not transfer ownership; the purchaser remains the owner unless they later make a separate ownership transfer.
When a person chooses to claim access, they enter their own mobile number and receive a one-time text code to verify possession of that number. The claimant-provided number is handled transiently by our text-message provider and telecommunications carriers to deliver the code. If the newly generated matching code corresponds to the stored code, access is granted. If it does not match, access is not granted automatically and we ask the purchaser to approve the request. The stored matching code and last two digits are deleted when access is successfully claimed, or 60 days after dispatch if unclaimed. After that, a claim requires the purchaser's approval. Pending claim requests expire after 48 hours.
If a claimant chooses to add a phone number to their own Nokoru account, that number comes directly from them and is handled as account information. Otherwise, the claimant's number is used only for the one-time verification and matching process and is not retained as a gift contact detail.
6. Who we share information with
We share only the information needed for the relevant purpose. Our main categories of recipients are:
- Amazon Web Services EMEA SARL and its approved subprocessors, for cloud hosting, storage, authentication, databases, content delivery, logging, and email and text-message delivery. Telecommunications carriers receive a claimant-provided mobile number only when that person initiates text-message verification.
- Cloudflare, Inc., which serves and protects our website and therefore handles the technical request information any web server receives, such as IP address, browser type and request timestamps.
- Stripe Payments Europe, Limited and payment participants, for payment processing, refunds, fraud prevention and disputes.
- Print, manufacturing and fulfilment providers, together with their approved production and delivery partners, to validate and route orders, create, quality-check, reprint and deliver photobooks. Depending on the order, they may receive the recipient's name, UK delivery address and contact details, order and product configuration, print-ready image files, and shipping or tracking information.
- PostHog (EU-hosted), our analytics provider, where analytics is enabled and consent has been obtained as required. See section 3.
- Sentry (EU-hosted), our error and crash reporting provider, to diagnose faults and improve reliability. See section 3.
- Crisp (EU-hosted), which provides the in-app support chat in test builds of the app (TestFlight and Play beta). If you open that chat, we pass your name, email address and account reference so we can recognise you and reply. Public App Store and Google Play releases do not start the chat and send Crisp nothing.
- Apple and Google, when you use social sign-in or their mobile-platform services. They process information under their own privacy notices.
- Professional advisers, insurers, auditors, regulators, courts, law-enforcement bodies and other organisations where disclosure is necessary or legally required.
- A potential buyer, investor or successor and their advisers if Nokoru is involved in a financing, reorganisation, sale or acquisition, subject to appropriate confidentiality safeguards.
We do not sell personal information, we do not allow processors to use customer photos or videos for their own purposes, and we never use customer content to train AI models.
7. International transfers
Nokoru currently accepts delivery addresses only in the UK. Our primary AWS cloud region is London, and our analytics are hosted in the EU. Delivery destination does not determine every processing location: some providers and global services may process or make information accessible outside the UK. This includes Stripe and Apple entities in Ireland, Google LLC in the United States, AWS global content-delivery and support infrastructure, and print, fulfilment or delivery providers and their approved partners in the UK, EEA, United States, Australia or other locations needed to provide the service.
Where information is transferred outside the UK, we use a permitted safeguard. Depending on the recipient, this may include UK adequacy regulations, the UK Extension to the EU-US Data Privacy Framework, the UK International Data Transfer Agreement, or the UK Addendum to the EU Standard Contractual Clauses. We also assess providers and apply technical and contractual protections. Contact us if you would like a copy of the safeguard used for a particular transfer.
8. How long we keep information
How long we keep your books and videos
Video hosting is part of what you buy. Each book includes a hosting period selected at purchase. The period starts on the purchase date and lasts for the term shown in your order, up to 30 years. An eligible hosting period may be extended.
During the hosting period we keep the album content needed to play your book's videos, even if you rarely open the app. If the hosting period is extended, we keep the content for the extended period. If it is not extended, the content is deleted after the period ends, from active systems within 30 days and from routine backups within 30 days. Once the content is deleted, the printed book will no longer play its videos.
You can delete content or close your account at any time. Deleting content is permanent and means the printed book will no longer play its videos. Closing an account deletes the books and content that account owns. It also removes access that the account holds to books owned by somebody else, but it does not delete those other people's books. Giving a recipient access does not transfer ownership. A book you own remains after you close your account only if you deliberately transfer its ownership to another Nokoru user before closure.
We keep personal information only for as long as it is needed for the relevant purpose. Our standard periods are below. We may retain information for longer when required by law, where a dispute or investigation is ongoing, or where deletion is temporarily suspended to protect legal rights.
| Information | Standard retention period |
| Account, authentication and age-confirmation information | While the account is open. Following account closure, removed from active systems within 30 days, except for limited information retained for legal, security or accounting purposes. Routine backup copies roll off within 30 days. |
| Photos, videos, captions, albums and image-matching data | For the hosting period selected at purchase, up to 30 years, including any extension, or until you delete the content, whichever is sooner. After expiry or deletion, removed from active systems within 30 days and routine backups within 30 days. |
| Gift access setup details (display name, keyed number-matching code and last two digits) | The matching code and last two digits are deleted when access is successfully claimed, or 60 days after dispatch if unclaimed. An unclaimed display name is deleted at the same time. After a successful claim, only the recipient account identifier and access permission remain for as long as access continues or the book exists. Pending claim requests expire after 48 hours. |
| Files supplied for printing and fulfilment | Nokoru's own print-ready copy is normally deleted within 60 days after dispatch unless it is needed for a reprint, complaint or dispute. Print, manufacturing and fulfilment providers may retain production copies for manufacture, quality control, reprints, support and applicable legal obligations, then delete or render them inaccessible under their documented retention processes. |
| Orders, payments, invoices, refunds and accounting records | Six years from the end of the company financial year to which the record relates, or longer if the law or an active investigation requires it. |
| Customer support and ordinary correspondence | Two years after the matter is closed. Records connected with a complaint, dispute or legal claim may be kept for up to six years. |
| Security, access and diagnostic logs | Normally 12 months. Relevant records may be kept longer while an incident, fraud concern or legal matter is investigated. |
| Analytics identifiers | Up to 12 months, or a shorter period set through our analytics controls. |
| Data-protection requests and complaints | Three years after closure, or up to six years where needed for a legal claim or regulatory matter. |
9. Security
We use technical and organisational measures designed to protect personal information, including access controls, appropriate encryption in transit and at rest, private storage, time-limited content access, monitoring and supplier due diligence. No system is completely secure, so we also maintain incident-response and recovery processes.
10. Your rights
Depending on the circumstances and the lawful basis, you may have the right to:
- ask for access to your personal information and a copy of it;
- ask us to correct inaccurate or incomplete information;
- ask us to erase information or restrict how it is used;
- object to processing based on legitimate interests;
- receive information you provided in a portable format where the right applies; and
- withdraw consent at any time where we rely on consent.
These rights are not absolute and exemptions may apply. We normally respond within one month. We may ask for proportionate information to verify your identity and locate the relevant records. Deleting content or closing an account is permanent for content that the account owns; a printed book will no longer play its videos once that content is deleted. To exercise a right, email [email protected] or write to the address above.
11. Complaints
If you have a concern, please contact us first so we can investigate. We will acknowledge your complaint within 30 days. Without undue delay, we will take appropriate steps to investigate, keep you informed and tell you the outcome.
Email: [email protected]
Post: Nokoru Ltd, 124-128 City Road, London, England, EC1V 2NX
If you remain unhappy, you can complain to the Information Commissioner's Office:
Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Telephone: 0303 123 1113
Website: ico.org.uk/make-a-complaint
12. Google user data
Nokoru offers Google sign-in, and the book builder offers an "Import from Google Photos" feature that lets you add photos and videos from your Google Photos library. This section sets out, in one place, what we receive from Google APIs, why, how long we keep it and who we share it with.
What we receive
- Google sign-in, if you choose it: your email address, basic profile information and your Google account identifier (the
userinfo.email,userinfo.profileandopenidscopes). We use this only to create and run your Nokoru account, as described in sections 2 and 3. - Import from Google Photos, if you choose it: only the specific photos and videos you select in Google's own picker, via the
https://www.googleapis.com/auth/photospicker.mediaitems.readonlyscope. We never browse, list or search your Google Photos library - we receive only the items you hand-picked.
How we use it
An item you import from Google Photos is copied once into your Nokoru album, where it is treated exactly like any other photo or video you upload: laid out, printed and stored under the same rules (section 8). The Google access token used to make that copy is used for that one import and then discarded. We do not request offline access, we receive no refresh token, and we do not store any Google credential - access to your Google Photos library ends as soon as the import finishes.
We do not sell Google user data, we do not use it for advertising or profiling, and we do not use it to train machine-learning models. We do not share it with third parties beyond what section 6 already describes for personal information generally - in particular, our print and fulfilment providers, to produce the book you ordered.
Limited Use
Nokoru's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access
You can revoke Nokoru's access to your Google account at any time at myaccount.google.com/permissions. Revoking access stops any future sign-in or import; it does not remove photos or videos already copied into a book. Those are removed the same way as any other album content - by deleting the item, the album or your account (section 8).
13. Changes to this notice
We may update this notice when our service, suppliers or legal obligations change. We will publish the current version and, where a change materially affects how we use personal information, provide an appropriate additional notice.
Last updated: 8 September 2026