1. Who is responsible
The controller is [Legal entity name — O1], [Legal form — O1], [Registered address — O1]. Contact: support@valinka.app.
Data protection officer: [DPO, if any — O1].
2. Data we collect
| Category | What | Source | Linked to you | Apple label | Play Data safety |
|---|---|---|---|---|---|
| Account | name, email address, profile photo, Google or Apple account id | Google / Apple sign-in through Clerk | yes | Contact Info: Name, Email | Personal info: name, email |
| Identifier | user id (Clerk id; also the RevenueCat app user id) | generated | yes | Identifiers: User ID | Personal info: user IDs |
| Trips and places | trips (name, destination, dates, note, cover photo), saved places, your notes, the links you import | you | yes | User Content: Other User Content | App activity: other user-generated content |
| Uploads | photos, screenshots or videos you upload for analysis | you | yes, until analysed | User Content: Photos or Videos | Photos and videos |
| Sharing | the display name you type for a shared trip; trip membership; share and invite links | you | yes | User Content: Other | App activity: other user-generated content |
| Referral | your invite code; that an invite was redeemed | generated | yes | (App Functionality) | (app functionality) |
| Purchases | credit-pack purchase history, credit balance and history | Apple / Google through RevenueCat | yes | Purchases: Purchase History | Financial info: purchase history |
| Crash data | crash reports with the user id, email, tokens and pasted links removed | app, backend | no | Diagnostics: Crash Data (not linked) | App info and performance: crash logs (optional) |
| Usage statistics | 12 named events (e.g. “import started”, “trip created”) with a random anonymous id; no content, no link, no name, no id; IP address discarded | app | no | Usage Data: Product Interaction (not linked) | App activity: app interactions (optional) |
| Location | your position, only when you allow it: used on the device for “near you” and walking times, and sent as a search hint when you search for a place | device | no | not collected (processed, not stored) | not collected |
| Abuse prevention | a keyed hash of your Google or Apple identity (kept after deletion, see retention); request counters per user and per hashed IP address | generated | hash: no | (not a listed type) | (not a listed type) |
| Technical | IP address and device/app version in standard server logs of our providers | automatic | no | — | — |
Not collected: contacts, calendar, camera, microphone, advertising id, precise location history, health, browsing history, payment card data. No device push token is collected at this time.
3. Why we use it, and legal basis
| Purpose | Data | Legal basis (GDPR art. 6) |
|---|---|---|
| Create and run your account | Account, Identifier | contract (art. 6.1.b) |
| Find places in what you import; build and sync trips | Trips and places, Uploads | contract |
| Share a trip, plan together | Sharing | contract |
| Sell credits, keep the balance right, refund failed imports | Purchases | contract; legal obligation for accounting records held by the stores |
| Invite-a-friend credits | Referral | contract |
| Prevent abuse of free credits and of the service | identity hash, counters, hashed IP | legitimate interest (art. 6.1.f) |
| Reuse the result for the same public post or the same file, so the next import is faster and cheaper | shared extraction cache (no user id) | legitimate interest |
| Fix crashes | Crash data | legitimate interest, with opt-out — or consent [O8] |
| Understand which steps work | Usage statistics | legitimate interest, with opt-out — or consent [O8] |
| Answer your requests | your emails to support | legitimate interest / contract |
Lawyer check pending: [O8].
4. Who processes it for us
| Processor | Purpose | Data it receives | Region |
|---|---|---|---|
| Clerk | sign-in and account | name, email, profile photo, Google/Apple account id, session and device data | USA [verify — O14] |
| Supabase | database, file storage, server functions | everything in “Account” to “Referral”, credit history, uploads until analysed | EU, Frankfurt [confirm — O14] |
| Google Cloud Run | our analysis server | the link or file being analysed, in transit; stores nothing | EU, Frankfurt (europe-west3) |
| Google Gemini API | finds the places in a post or an upload | the post’s caption, transcript, images or video (or the YouTube address), or your uploaded file; never your name, email or user id | not pinned to a region (Google) |
| Google Places API and Google Maps | place search, place details, place photos, Maps links, the map on Android | search text, place ids, an approximate position as a search hint; no user id | Google (global) |
| Apify | reads the public Instagram, TikTok, YouTube or Facebook post behind a link you import | the post’s address only; no user data | not verified [O14] |
| Unsplash | a photo for a place that has none | the place’s name; no user data | USA |
| RevenueCat | purchase validation and history | user id, store receipts and transactions, country, app and device version | USA |
| Apple App Store / Google Play | payment for credit packs | they act as independent controllers; we receive no card data | — |
| Sentry | crash reports (app and analysis server) | scrubbed crash data, no user id (optional) | EU, Germany |
| PostHog | usage statistics | 12 anonymous events, IP discarded (optional) | EU |
| Cloudflare | hosts this website; forwards mail sent to support@valinka.app once Email Routing is on | IP address and browser data in request logs; the emails you send us | global network |
| Mailbox provider behind support@ | reading and answering your emails | your emails | [Mailbox provider — O5] |
6. Transfers outside the EU
Some processors are located outside the EU/EEA (see the Region column above). Where they are, the transfer relies on the EU-US Data Privacy Framework certification of the processor, or else on Standard Contractual Clauses.
[Safeguard per processor — O14]
7. How long we keep it
| Data | Kept | Then |
|---|---|---|
| Account, trips, places, notes, imports, cover photos, credit history, invite code, memberships | until you delete them or your account | deleted at once on account deletion |
| Uploaded photos and videos | only until analysed (seconds to minutes); a daily job removes any leftover file older than 24 hours | deleted |
| Fingerprint (SHA-256 hash) of an uploaded file + the places found in it, with no user id | 90 days after it was last used | deleted |
| Places found in a public post (shared extraction cache: the post’s public title, author, thumbnail and places; no user id) | kept, also after your account is deleted, because it describes the public post and not you; “nothing found” answers 24 hours, failures 15 minutes | period for positive entries: [O16] |
| Keyed hash of your Google or Apple identity | kept after account deletion, so the free welcome credits are given once per identity; it cannot be turned back into your identity | period: [O16] |
| Places you added to someone else’s shared trip | stay in that trip (owned by its owner) | until the owner deletes them |
| Purchase records | held by Apple or Google and by RevenueCat under their own retention rules (our own credit history is deleted with the account) | [O7] |
| Crash reports, usage statistics | the provider’s project retention | value: [O16] |
| Request counters (rate limits) | hours to days | deleted; yours are deleted with the account |
| Emails to support | [Retention — O16] | — |
| Database backups | the hosting provider’s backup window | value: [Backup window — O16] |
8. Crash reports and usage statistics
Crash reports (Sentry) and usage statistics (PostHog, hosted in the EU) help us fix bugs and see which steps work. Both are anonymous: no name, no email, no user id, no link you imported, no trip or place name, no location. PostHog uses a random id and discards your IP address. There is no session recording and no advertising id.
They are on by default. Turn both off at any time in Settings → Notifications & privacy → “Help improve Valinka”; sending stops at once.
9. No ads, no sale, no tracking
Valinka shows no ads, does not sell or rent your data, does not share it with data brokers, and does not track you across other companies’ apps or websites.
10. Location
Location is optional. With your permission, your position is used on your device to show what is near you and walking times, and is sent as an approximate search hint when you search for a place. We do not store your position or a history of it.
11. Children
Valinka is not directed to children under 18. If you are a parent and believe a child has an account, write to support@valinka.app and we will delete it.
12. Your rights
You have the right to access, rectify, erase, restrict and port your data, to object to its processing and to withdraw your consent. No decision with legal effect is taken about you by automated means.
In the app: Settings → Notifications & privacy → “Download my data” gives you a copy of your profile, trips, imports, places and credit history; “Delete account” erases your account. Without the app, or for any other request, write to support@valinka.app from the email address of your account. We answer within one month.
You can complain to the supervisory authority: [Supervisory authority — O3], or the authority of your country.
13. Security
Data is encrypted in transit. Access is limited per user by the database’s row-level rules, and secrets are never stored in the app.
14. This website
This website uses no cookies, no analytics and no third-party content. Our host (Cloudflare) processes your IP address to deliver the pages. Pages opened from a share or invite link show no trip data and send the link to no one.
15. Changes
We may update this policy. The date at the top changes, and material changes are announced in the app.
16. Contact
support@valinka.app
[Postal address — O1]