Skip to Content
Photos and Privacy

Photos and Privacy

Photo flows touch identity, consent, and moderation, so this page is intentionally detailed.

Personal Photo Centre (/me/photos)

Your personal photo workspace has three tabs:

  • Liked: photos and videos you have liked, grouped by event/album.
  • Tagged: photos where you are tagged, including approval/rejection.
  • Profile: photos shown on your profile.

Tagged Photo Workflows

In Tagged, you can:

  • Approve pending tags,
  • Reject pending tags,
  • Remove tags from already-approved photos,
  • Use bulk actions when processing high volume.

Profile Photo and Visibility Controls

Profile-facing photo controls now live in /settings/profile.

Those controls include:

  • Profile visibility scope,
  • Profile photo visibility scope,
  • Tagged-photo gallery visibility on your profile,
  • Avatar behaviour and source preferences.
  • Advanced per-community tagged-photo contribution choices when you have tagged photos from multiple communities.

The tagged-photo profile setting controls only the gallery shown on your profile page. It does not stop people from tagging you, and it does not hide your name from photo detail surfaces.

Connections, shared hubs, and shared events (people booked for or attending the same event as you) affect who can view what.

Hub and Event Photo Surfaces

Hub photo surfaces support album and timeline views.

Visibility is enforced at multiple layers:

  • Album defaults,
  • Per-photo moderation/override controls,
  • Viewer relationship and membership gates.

Some access failures intentionally return Not found to protect private resource existence.

Guest-surface rules also matter:

  • Public hubs can show PUBLIC albums to both logged-out visitors and logged-in non-members.
  • Logged-in non-members should still be treated as non-members, not as fully joined viewers: they can browse public albums, but member-only albums stay hidden.
  • Direct links to non-public albums do not open a richer preview; they show an unavailable/restricted state instead.
  • Public event pages open shared album cards directly into the chosen album.
  • Private hub overview pages do not advertise album listings to logged-out visitors, even when a specific public album URL still works.
  • Private hubs do not expose general photo listings to non-members from the hub photos index or timeline.

Filtered Album Views

Widening a single photo or video beyond its album default also makes a filtered view of that album available to the people the override admits:

  • The album keeps one address. Viewers who pass the album default see everything as before; viewers admitted only by per-item overrides see a filtered selection containing exactly those items.
  • Filtered views are labelled Public selection (logged-out) or Shared selection (logged-in) with truthful item counts. The album’s stored visibility is never presented as if the whole album were shared.
  • A filtered view never includes original or ZIP downloads, photo locations, linked chat details, uploads, or any management controls.
  • Draft and archived event albums never appear this way, and the event’s own visibility still applies (for example, invite-only events stay limited to people who can see the event).
  • Restricting or removing the last widened item makes the album disappear again for those viewers.
  • Making the first item public is the deliberate publishing action: it exposes the album’s title, description, creator, event link, and a cover drawn from an accessible item.

Album Videos

The dedicated Album Videos guide covers uploading, processing states, playback, downloads, and troubleshooting in full. The privacy essentials:

Albums on Pro and Pro+ hubs can hold short videos alongside photos:

  • Pro allows videos up to 2 minutes long and 1 GB per file, with 200 stored video minutes per hub.
  • Pro+ allows videos up to 5 minutes long and 3 GB per file, with 1,000 stored video minutes per hub.
  • Video files upload directly from your browser to the streaming provider; processing runs in the background and the tile shows its state until the video is ready.
  • Videos follow the same album visibility, moderation, and report rules as photos. Playback only starts when a viewer opens a video and passes the same permission checks; nothing autoplays. On public albums that includes logged-out visitors, via short-lived per-play tokens.
  • Liking, person tagging, and reporting work for videos exactly like photos.

On Pro+ hubs with chat album capture enabled, videos posted in an album-linked chat channel are saved to that album too.

Album Original Downloads

Album create/edit includes an Original downloads setting for the original files and album ZIP downloads.

Choices:

  • Off: viewers can browse the album, but original-file and ZIP download controls stay hidden.
  • Signed-in viewers: signed-in people who can view the album can download originals.
  • Hub members: only hub members who can view the album can download originals.

This setting does not control normal album browsing, liked-photo actions, reports, or optimized preview images. It controls full-quality original files and generated ZIP downloads only.

Video downloads follow the same policy. Single videos download as full-quality MP4 files, and bulk or album downloads list ready videos as separate direct downloads next to the zip files; videos are never packed inside the zips. Videos that are still processing are left out of bulk downloads until they are ready.

Older original-file or ZIP links still re-check the current album policy before serving anything. If access is no longer allowed, Hubbaly returns an unavailable result rather than exposing the file.

Photo Location Metadata

Album originals preserve the metadata that came from the uploaded file. That means an original download may still contain EXIF date, time, camera, and GPS metadata when the uploader’s device included it.

The Show photo locations on the map album setting controls Hubbaly’s own location display: GPS fields and map cards stay hidden unless an organiser enables the setting on a non-public album. Public albums cannot enable Hubbaly’s precise photo-location maps, but original downloads still serve the original file with its metadata intact when the album’s Original downloads policy allows that viewer to download it.

Reporting and Moderation

If a photo is unsafe or incorrect:

  1. Use report actions from the photo surface.
  2. Include reason and context.
  3. Hub admins handle local moderation.
  4. Escalate to platform level for severe or repeated abuse.

Practical Privacy Defaults

  • Start conservative, then widen visibility intentionally.
  • Review tagged photos before profile promotion.
  • Keep moderation notes clear for future audits.
  • Escalate incidents with URL + UTC time + role context.
Last updated on