This Privacy Policy explains how Spotary ("we", "us") collects, uses, and protects your personal data when you use the Spotary mobile application ("App"). We comply with the General Data Protection Regulation (GDPR) for users in the EU/EEA.

Data Controller

SIA Horizon C
Registration number: 40203709918
Registered address: Matīsa iela 61A-18, Riga, LV-1009, Latvia
Contact: privacy@spotary.app

1. Data We Collect

Account data

  • Email address
  • Username
  • First name and last name
  • Date of birth (used to verify age eligibility)
  • Password (stored using industry-standard hashing)
  • Optional residence (free text field)
  • Bio (up to 150 characters)
  • Profile photo (if uploaded)

Content & usage data

  • Posts, captions, and media files you upload (photos and videos)
  • Optional location coordinates you manually attach to posts
  • Comments, likes, saves, and other interactions you perform
  • Follow relationships and block lists
  • Messaging content between you and other users (visible only to conversation participants)
  • Support requests and feedback you submit

Technical data

  • Device type, operating system, and app version
  • IP address and timestamps (for security and abuse prevention)
  • Device token (for push notifications)
  • Crash reports and error logs (anonymised where possible)
  • Anonymous usage analytics (feature interaction frequency; no personally identifiable data)

We do not collect

  • Background or continuous real-time location
  • Your phone contacts or address book
  • Payment data (no payments are currently processed)

2. Location Data

  • The App may read your current approximate location solely to suggest a starting point for the map marker when creating a post. You may move the marker freely before saving.
  • Adding a location to a post is always optional.
  • Followers may see your post location only if you explicitly enable it for that specific post.
  • The Explore feature sends your approximate current location to our server solely to filter nearby content for display. This data is used only to process that individual request and is not stored, logged, or shared with other users.
  • Location drafts created while offline are stored only on your device and are never transmitted to our servers.
  • We do not store historical movement patterns, routes, or background location data.

3. How We Use Your Data

We use your data to:

  • Create and manage your account;
  • Display your posts, comments, and profile to users according to your privacy settings;
  • Enable social features such as messaging, following, and notifications;
  • Send push notifications about activity on your account;
  • Detect and prevent abuse, spam, and security threats;
  • Diagnose and fix technical issues;
  • Measure aggregate app performance and feature usage;
  • Comply with legal obligations.

We do not sell your personal data, share it with advertisers, or use it for automated decision-making that produces legal or similarly significant effects.

4. Legal Bases (GDPR)

  • Performance of a contract — providing the App and its core features.
  • Your consent — for optional features such as location sharing.
  • Legitimate interests — security, abuse prevention, and anonymous performance analytics.
  • Legal obligation — where required by applicable law.

You may withdraw consent for optional features at any time in your profile settings.

5. Third-Party Services

We use the following third-party providers to operate the App. Each processes limited data as necessary to deliver their service.

Infrastructure & hosting

  • Microsoft Azure (Frankfurt, Germany) — hosts our backend API servers.
  • Neon Postgres (AWS eu-central-1, Frankfurt, Germany) — primary database.

Media storage & processing

  • AWS S3 — stores user-uploaded images and videos.
  • AWS CloudFront (CDN) — delivers media to end users.
  • AWS MediaConvert — transcodes and processes uploaded videos.
  • AWS Lambda & EventBridge — handle video processing callbacks and status updates between AWS services and our API.

Maps

  • Mapbox SDK — renders interactive maps within the App. Mapbox may receive limited technical data such as map tile requests.

Push notifications

  • Firebase Cloud Messaging (FCM) — delivers push notifications to your device. Only your device token is shared; no message content is stored by FCM.

Analytics & error tracking

  • Firebase Analytics — collects anonymous, aggregated usage statistics (e.g. feature interaction frequency). No personally identifiable information is included.
  • Firebase Crashlytics — collects frontend crash reports to help us fix bugs. Reports include device type, OS version, and a stack trace; they do not include the content of your posts or messages.
  • Sentry.io (EU servers) — collects backend error reports. Reports include your user ID, basic device information, and a stack trace. Sentry is configured to minimise personal data collection.

All AWS and Firebase services used by us are operated within or routed through EU data centres where applicable. We take reasonable contractual and technical measures to protect your data when using these providers.

6. Data Retention

  • Account data: retained while your account is active.
  • Messages: automatically deleted after 60 days from the date sent.
  • Notifications: automatically deleted after 30 days.
  • Account deletion: when you request deletion, your account is immediately deactivated and hidden. You may cancel the deletion by logging back in within 7 days. After 7 days, your account and all associated data are permanently deleted or irreversibly anonymised.

We may retain limited data beyond these periods where required for legal obligations, dispute resolution, or fraud prevention.

7. Your Rights (GDPR)

You have the right to:

  • Access the personal data we hold about you;
  • Request correction of inaccurate or incomplete data;
  • Request deletion ("right to be forgotten");
  • Request restriction of processing;
  • Data portability;
  • Object to processing based on legitimate interests;
  • Withdraw consent at any time;
  • Lodge a complaint with your local data protection authority.

To exercise any of these rights: privacy@spotary.app

8. Children

Spotary is not intended for users under 16 years old. We do not knowingly collect data from children under this age. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the App after changes means you accept the updated Policy.

10. Contact

privacy@spotary.app