It's quite fascinating but I think as per usual, the simplest answer is the right one:

She simply used publicly available scraping software to download publicly available images. They did do many non privacy-oriented things in building the site, like leaving metadata in the images. Flickr and SmugMug leave it in because photographers demand it, but we strip it out on Cake.