SpinGlobus

Privacy Policy

Effective from 25 September 2026

In short

  • SpinGlobus is a private photo chronicle. Your photos, albums and diary are yours and stay private unless you share them.
  • We collect what we need to run the service: your account details, the photos and texts you add (including the date and place a photo was taken), and technical data about how the app is used.
  • We do not sell your data, we show no advertising based on it, and we do not use your photos or texts to train AI models.
  • Usage and crash data can be switched off in the app (Settings → Advanced).
  • Deleting your account deletes everything in it within 30 days.
  • Our servers are currently in the United States; we protect that transfer the way EU law requires.
  • Questions: info@spinglobus.com.

1. Who we are

SpinGlobus is run by Codly s.r.o., Bělehradská 858/23, 120 00 Prague 2, Czech Republic, company ID 19514727, registered at the Municipal Court in Prague, section C, file 387734 (“SpinGlobus”, “we”, “us”). We are the controller of your personal data under the GDPR. We have not appointed a data protection officer; for anything about your data write to info@spinglobus.com or use Settings → Write to us in the app.

2. What this policy covers

The SpinGlobus app for iPhone, iPad and Android, the web app at core.spinglobus.com, albums opened through a link at spinglobus.com, the e-mails we send you, and our website spinglobus.com.

3. What we collect, and why

What Where it comes from Why we need it Legal basis
Account — your e-mail address, the name you choose, your password (stored only as a salted hash), your language, the dates you joined and were last active. If you sign in with Google or Apple, we receive your e-mail address, whether it is verified, and optionally your name; Apple may give us a relay address instead of your real one. You; Google or Apple To run your account, sign you in, and send service e-mails: confirming your address, resetting a password, a welcome, a reminder before your free days end. Contract
Your content — your photos, album details (name, dates, place, notes; on the web also budget, hotel and agency), diary pages (text, date, place name, mood), captions. From each photo we read the date it was taken and, when the photo carries them, its GPS coordinates, and keep them as separate fields. You To show your chronicle, place photos in time and on the map, light the countries you have visited on the atlas (we work that out ourselves from the coordinates, country-level only), make the movie, and deliver what you share to the people you choose. Contract
Sharing — the e-mail addresses of people you share an album with, your list of close people, the share links you create (a random key), and how many times and when a link was last opened — never by whom. You To deliver the album to the people you choose and let you manage and revoke your links. For the recipient’s address: to deliver what you asked us to deliver. Contract; legitimate interest (delivery)
Subscription — whether you have Chronicle, from which store, and until when; for a purchase on the web, your customer and subscription identifiers at our payment provider and billing dates. Card numbers never reach us: Apple, Google or our payment provider handle the payment. You; the app stores; our payment services To unlock Chronicle, keep it in sync across your devices, and keep the records the law requires. Contract; legal obligation (accounting)
Device and usage data — the app version, your operating system and its version, device type (phone or tablet), language, a random installation identifier, and what you do in the app in counted form: which screens you open, that a page was saved, how many photos an upload had, an error code. Never the content of a photo or a page, and never the name of a place. The app To see what works and fix what does not. Legitimate interest (improving the product) — with an off switch in Settings → Advanced
Crash reports — when the app fails: the technical error, your device model, operating system, app version and the technical steps that led there, with sign-in tokens removed. Crash reports are not linked to your name or e-mail. The app To find and fix crashes. Legitimate interest — the same off switch
Push notifications — a device token issued by Google’s push service, your platform, time zone and language. Only if you allow notifications. The app To tell you when someone shares an album with you, on an album’s anniversary, and before your free days end. Contract; legitimate interest — switch off in your phone’s settings
Technical logs — IP address, the request, its time and your browser or app identification, on our servers and at our network provider. Your device To keep the service secure, detect abuse and keep it available. Legitimate interest (security)
Support — what you write to us. Write to us in the app adds the app version and your operating system to the mail; never your account or content. You To help you. Legitimate interest; contract
Interest lists on our website — if you leave your e-mail to hear about a future feature. You To tell you when it exists. Consent — withdraw any time by e-mail

We make no automated decisions about you and build no profiles. Your account data is needed to have an account; everything else is your choice: a photo without a location still works, notifications and usage data are optional.

4. Photos, location and dictation

5. Who we share data with

We never sell personal data. We share it only with the people you choose and with the service providers that help us run SpinGlobus, each bound by a data-processing agreement to protect your data at least as this policy does.

Who What for Where
Apple and Google The app stores (payment for Chronicle, refunds), Sign in with Apple / Google, delivering push notifications, speech recognition on your device USA (EU–U.S. Data Privacy Framework)
Hosting and network providers The servers where your account and content are stored; protecting and delivering our web traffic USA (see section 6)
Payment and subscription services Payments made on the web; keeping your subscription in sync across your devices EU / USA (see section 6)
E-mail delivery Sending our e-mails USA (see section 6)
Usage statistics and crash reports Counting how the app is used and finding crashes — both can be switched off EU
Maps and web fonts Loading the map tiles in the app and the fonts of our web pages; these services see your IP address EU (maps) / USA (fonts)
People you share with They see what you share, for as long as you share it Wherever they are
Authorities Only where the law obliges us —

If you want to know exactly which companies these are, write to us and we will tell you.

6. Where your data is stored

Your account, photos and diary are currently stored on servers in the United States run by our hosting provider, and some of the services above are US companies. For every transfer outside the European Economic Area we rely on the EU–U.S. Data Privacy Framework where the provider is certified, and otherwise on the European Commission’s Standard Contractual Clauses (Article 46 GDPR). Write to us if you want details of the safeguards.

7. How long we keep data

Data Kept for
Your account and content As long as your account exists. When you delete it, the account is disabled at once, your shared links stop working, and everything is permanently erased within 30 days.
Accounts never confirmed and never used Deleted after 7 days.
Sign-in sessions 90 days per device, renewed while you use the app; expired ones are removed 30 days later.
Share links and the addresses you shared with Until the link expires (you choose the lifetime, up to one year, or none) or you revoke it; at the latest, with your account.
Purchase records Your subscription state while it matters; invoices for web purchases as long as tax and accounting law requires (up to 10 years).
Usage statistics Up to 12 months.
Crash reports 90 days.
Technical logs Up to 90 days, longer only for a security investigation.
Support correspondence As long as needed to help you, at most 2 years.
Interest-list e-mails Until you ask us to remove them.

8. Your choices

9. Your rights

You can ask us for access to your data, to correct or erase it, to restrict or object to its processing (in particular to usage statistics, which we process on the basis of legitimate interest), to receive it in a portable format, and to withdraw any consent you gave. Write to info@spinglobus.com; we answer within one month. We may ask you to confirm you are the account’s owner, for example by writing from its e-mail address.

If you believe we handle your data wrongly, you can complain to the Czech data protection authority: Úřad pro ochranu osobních údajů, Pplk. Sochora 27, 170 00 Praha 7, www.uoou.gov.cz — or to the authority in your own country.

10. Security

All traffic is encrypted (HTTPS). Passwords are stored only as salted hashes; sessions use rotating tokens that we store hashed. Every request for a photo is checked: it is served to you when you are signed in, or to a person holding the key of a share you made. We remove camera metadata from photo files, keep no card data, rate-limit sign-in attempts and run a web application firewall. No system is perfectly secure: keep your password to yourself and tell us if something looks wrong.

11. Cookies and local storage

The web app uses only cookies needed to run it:

Cookie Purpose Lifetime
sg_auth Your signed-in session 180 days, renewed while you use it
sg_in A yes/no “signed in” hint for our website As sg_auth
sg_shk Opens an album shared with you 1 day
.AspNetCore.Culture Your language 1 year
sg_cc, .AspNetCore.Consent Remember your cookie choice 1 year
Sign-in state and antiforgery cookies Security during sign-in and forms The sign-in or the session

No advertising and no analytics cookies. The mobile app uses no cookies; it keeps your session in the device’s secure storage together with a random installation identifier, which stays on the device when you sign out so that the next sign-in works. Our website spinglobus.com uses cookie-free page statistics.

12. Children

SpinGlobus is for people aged 15 and over (the age at which Czech law lets a person agree to an online service: Act No. 110/2019 Coll., § 7). We do not knowingly keep an account of a younger child; if we learn of one, we delete it. Photos of children you add are your responsibility — get the consent of those who care for them before sharing.

13. Changes to this policy

When we change this policy we publish the new version here with a new date. If the change matters to you, we tell you in the app or by e-mail before it takes effect.

14. Contact

Codly s.r.o., Bělehradská 858/23, 120 00 Prague 2, Czech Republic · info@spinglobus.com · or Settings → Write to us in the app. This is also our point of contact for authorities and for reports about content (see the Terms of Use).