Magic Booth

Magic Booth: Event Photos

Privacy Policy

Last updated: September 8, 2026

Magic Booth is operated by Staxel (we, us). This policy covers the Magic Booth iOS application and the services behind it. Two kinds of people appear in it: operators, who hold accounts and run booths, and guests, who are photographed at a booth an operator runs.

1. What we collect

  • Operator accounts. Email address, name, and a password (stored only as a hash). Workspace membership, booth configuration, and the reference images and prompts you upload.
  • Guest photographs. The photograph a booth takes, and the stylized image generated from it.
  • Guest email addresses. Collected only when a guest asks to receive their photo, and used for exactly that: releasing that photograph to that guest. Guest addresses are never used for marketing and never added to any mailing list.
  • Device and usage records. Which devices are enrolled in a workspace (name, model, app version, and an installation identifier the app generates itself so a reinstalled device is recognised as the same one — it is not Apple’s advertising identifier), and a record of each generation — when, which look, what it cost in credits. These are the operator’s usage and billing history.
  • Purchases. Subscriptions are bought through Apple. We receive the signed transaction — which plan, for which period, in which store environment. We never see payment card details; Apple’s own privacy policy covers the payment itself.

2. How photographs are processed

To produce the stylized image, the booth photograph is sent to a third-party AI image-generation provider acting as our processor. The providers we use are bound to process the image only to produce the result. Photographs and results are stored in cloud object storage until deletion.

3. How long we keep things

  • Guest photographs are deleted 30 days after they are taken — the original capture, the generated image, the guest’s email address, and the token that fetched the photo, all together. What survives is a count: how many photos were taken and how many were claimed, with nothing that says who anyone was.
  • Generation records (what was made, when, what it cost) are kept as billing history. They do not contain the photographs.
  • Operator account and workspace data is kept for as long as the account exists.

4. What we share, and what we do not

  • We share data only with the processors needed to run the Service: cloud hosting and object storage, the AI image providers above, an email delivery provider (for invitations, password resets, and photo delivery), and Apple for purchases.
  • We do not sell personal data, we do not use photographs to train models, and we do not use guest data for advertising or profiling of any kind.
  • We disclose data if the law requires it, and will tell the affected operator unless legally barred.

5. Your rights

  • Operators can see and correct their account data in the app, and can delete their account and workspace data themselves, from Settings in the app. What remains afterwards is a record that an account was deleted, a record of what each App Store purchase paid out, and a count of the free trial already used on that device, none of which names anyone.
  • Guests can simply not claim a photo — it is deleted with everything else within 30 days — or ask for earlier deletion through the operator who ran the booth, or directly through us.
  • Depending on where you live, you may have additional statutory rights (access, portability, objection, complaint to a supervisory authority). Requests go to the address below and we honor them as the law requires.

6. Children

Operator accounts are for adults. Guests at an event may be minors; photographing a minor at a booth requires the consent of a parent or guardian, and obtaining it is the operator’s responsibility. A guardian may request deletion of a minor’s photograph at any time — though every photograph is deleted within 30 days regardless.

7. Security

Data moves over TLS, passwords are stored only as hashes, photographs are retrievable only with per-photo tokens, and access to customer data inside Staxel is limited to staff who need it, with the actions they take recorded in an audit trail.

8. Changes

When this policy changes, the date at the top changes with it, and material changes are announced in the app or by email to operators before they take effect.

9. Contact

Privacy questions and requests: support@staxel.ai.