Legal
Privacy Policy
1. Data Controller Identity
| Field | Information |
|---|---|
| Controller | SPOTINERARY TECNOLOGIA LTDA |
| CNPJ (Brazil tax ID) | 65.861.495/0001-99 |
| Address | AV PREFEITO OSMAR CUNHA 416 SALA 1108, 88015-100, CENTRO, FLORIANÓPOLIS, SC, BRASIL |
| Data Protection Officer (DPO) | Heitor Murara |
| DPO Email | hmurara@spotinerary.com.br |
Spotinerary is a travel-planning app organized around Destinations and Trips. Destinations can contain covers, tags, notes, saved spots, bookmark folders, and supported social links. Trips can contain Destinations, spots scheduled by date, and transfers. This policy describes how we handle data during your use of the app.
2. Data Collected
2.1 Data We Do NOT Collect
Spotinerary does not collect:
- Names, emails, or phone numbers through the app account flow. Sign in with Apple is requested without name or email scopes
- We do not access your real-time location (no location permission is requested)
- We do not access your camera (no camera permission is requested)
- Photos used as Destination covers are selected by you through the system picker (PhotosPicker). The app receives only the images you choose and does not receive access to your full photo library
- Payment-card details, billing addresses, or financial-account information
2.2 Account, Entitlement, and Quota Data
Creating an account is optional for limited local browsing and required before starting a trial, subscribing, restoring a subscription, or using server-funded features. We process:
| Data | Purpose |
|---|---|
| Pseudonymous account and authentication identifiers | Recognize and authenticate the same account across sessions and compatible iPhones |
| Subscription and transaction information, including product and status | Verify subscription access and prevent misuse |
| Usage allowance and reset information | Enforce limits for server-funded features |
2.3 Data Collected Automatically
Firebase Analytics (Google)
When you consent to analytics data collection, the following data is collected:
| Data | Example |
|---|---|
| Device model | iPhone 15 Pro |
| Operating system version | iOS 26.0 |
| Device language | en-US |
| Country (IP-based, no precise geolocation) | United States |
| App usage events | Screens visited and feature actions completed |
| Session data | Session duration, usage frequency |
| App instance ID | Pseudonymous identifier generated by Firebase, not linked to your name or email |
Categories of tracked events include:
- Screen visits and interactions with maps, place search, and directions
- Creation, deletion, sharing, and organization actions for Destinations, Trips, tags, and saved spots
- Supported-import source category, route, outcome, and saved-item counts, without logging source URLs or extracted content
- AI action type, filter and saved-item counts, metered usage units, and usage-threshold notices
- Paywall display, product selection, conversion, and restoration actions, including product identifiers
- Onboarding, language, theme, and issue-report categories
Firebase Crashlytics (Google)
When you consent to analytics and diagnostics, the following data may be collected for issue resolution:
| Data | Purpose |
|---|---|
| Crash logs | Identify and fix errors |
| Stack traces | Locate the technical source of errors |
| Device state at time of crash | Understand conditions that caused the error |
| Device model and OS version | Reproduce issues under similar conditions |
| Non-fatal SwiftData errors | Monitor data persistence issues |
Firebase account security, service configuration, and server records
Firebase Authentication and Cloud Functions may process IP-address and user-agent security metadata when you sign in or make a server request. The app and backend also use the following services:
| Service and data | Purpose |
|---|---|
| Firebase App Check: Apple App Attest material and App Check tokens | Verify that requests come from the authentic app and device, protect backend services, and prevent replay and abuse |
| Firebase Remote Config: Firebase installation ID | Return operational feature availability and a non-blocking app-update policy. This processing is independent of Analytics consent, and no travel content is sent |
| Cloud Firestore: one-way-hashed account identifier, app account token, subscription, transaction, entitlement, quota, rate-limit, request, provider, usage, and minimal App Store notification audit records | Authenticate and authorize service access, meter usage, safely retry requests, handle subscription lifecycle events, and prevent fraud and abuse |
Temporary provider results stored in Cloud Firestore can contain generated or extracted content until automatic deletion. The general travel library is not stored in Cloud Firestore; it remains local and in iCloud. Structured backend logs exclude prompts, source URLs, provider payloads, credentials, Firebase user identifiers, Apple subjects, and provider job identifiers.
iCloud / CloudKit (Apple)
Your travel data, including Destinations, Trips, covers you choose, tags, notes, saved spots and links, dates, and transfers, is synchronized through iCloud/CloudKit when iCloud is enabled. Apple manages this storage, which makes the data available to Spotinerary on compatible iPhones signed in to the same iCloud account.
Map and place services (Apple MapKit)
When you search for or view places, request a country lookup, or estimate a route, Apple may receive search terms or places viewed, map viewport and request/device metadata, saved or planning coordinates, and route origin, destination, transport mode, and departure time. Spotinerary does not request permission to access your live device location. We do not separately retain raw MapKit requests; places and route information you choose to save become part of your local/iCloud travel data. Apple handles these requests under Apple Maps & Privacy.
AI and social-content processing
When you request AI discovery, planning, or import processing, the following data may be sent to Google:
| Data Sent | Purpose |
|---|---|
| Destination names and location context | Discover Destinations and spots and provide relevant place information |
| Selected Destination and Trip context, including dates, notes, saved spots, and transfer context | Plan dated itineraries and transfers or provide contextual suggestions |
| Requested public-source content from a supported import | Extract and organize the travel content you requested |
AI requests are sent through Spotinerary's Firebase Cloud Functions and processed by Gemini on Google Cloud Vertex AI. When you import supported social-media links, the source URL and the source's public media are also processed by Supadata to retrieve metadata and extract the travel content you requested. Google and Supadata may retain data according to their processing terms.
Unsplash API
When the app searches for a Destination cover image, the Destination name or cover-search terms are sent to the Unsplash API.
2.4 Purchase Data
All in-app purchases (monthly and annual subscriptions) are processed exclusively by Apple through StoreKit. Spotinerary:
- Receives the subscription and transaction information needed to determine access
- Verifies purchase authenticity server-side using information provided by Apple
- Never has access to payment-card details, billing addresses, or financial-account information
3. Purpose of Processing
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Usage events (Analytics) | Improve user experience, understand usage patterns, prioritize features | Consent (Art. 6(1)(a)) |
| Session data | Analyze engagement and identify areas for improvement | Consent (Art. 6(1)(a)) |
| Crash logs and stack traces | Identify, diagnose, and fix technical failures | Consent (Art. 6(1)(a)) |
| Device state at crash | Reproduce and resolve technical issues | Consent (Art. 6(1)(a)) |
| Sync data (iCloud) | Make your data available to Spotinerary on compatible iPhones | Performance of contract (Art. 6(1)(b)) |
| Map and place requests (MapKit) | Provide maps, place search and details, country lookup, and route estimates requested by you | Performance of contract (Art. 6(1)(b)) |
| Data sent for AI and social-content processing | Generate or extract travel content as requested by the user | Consent (Art. 6(1)(a)) |
| Search terms (Unsplash) | Fetch relevant Destination cover images | Performance of contract (Art. 6(1)(b)) |
| Analytics app instance ID | Group pseudonymous events from one app installation | Consent (Art. 6(1)(a)) |
| Remote Config installation ID | Provide operational feature availability and app-update configuration | Performance of contract (Art. 6(1)(b)) |
| App Check attestation material and tokens | Protect the service from unauthorized clients, replay, fraud, and abuse | Legitimate interests (Art. 6(1)(f)) |
| Pseudonymous account and authentication data | Provide subscription and server-funded feature access | Performance of contract (Art. 6(1)(b)) |
| Subscription transaction and usage records | Prevent fraud and service abuse | Legitimate interests (Art. 6(1)(f)) |
4. Legal Basis for Processing
GDPR (EU Regulation 2016/679, Art. 6)
- Consent (Art. 6(1)(a)): For analytics data collection (Firebase Analytics) and crash reporting (Crashlytics). This consent is requested on first app use and can be withdrawn at any time through Settings > About > Help Improve Spotinerary. Separately, when you explicitly request a supported AI or social-content feature, that affirmative request provides consent for the specific processing; it is not controlled by this setting.
- Performance of contract (Art. 6(1)(b)): For iCloud sync, MapKit requests, Unsplash image search, Remote Config, account authentication, subscription verification, and delivery of requested server-funded features.
- Legitimate interests (Art. 6(1)(f)): For App Check security and the minimum transaction, request, and quota records needed to prevent replay, duplicate subscription claims, repeated quota resets, fraud, and service abuse.
LGPD (Brazil Law 13.709/2018, Art. 7)
- Consent (Art. 7, I): For Analytics and Crashlytics. This consent is freely given, specific, informed, and unambiguous, requested on first app use, and may be withdrawn through Settings > About > Help Improve Spotinerary. Separately, when you explicitly request a supported AI or social-content feature, that affirmative request provides consent for the specific processing; it is not controlled by this setting.
- Performance of contract (Art. 7, V): For iCloud sync, MapKit requests, Unsplash image search, Remote Config, account authentication, subscription verification, and delivery of requested server-funded features.
- Legitimate interests (Art. 7, IX): For App Check security and the minimum transaction, request, and quota records needed to prevent replay, fraud, and service abuse, subject to applicable necessity and balancing requirements.
5. Third-Party Data Sharing
| Third Party | Data Shared | Purpose | Privacy Policy |
|---|---|---|---|
| Google LLC (Firebase Analytics) | Consent-gated usage events, device data, app instance ID | Usage analysis | Google Privacy Policy |
| Google LLC (Firebase Authentication and Cloud Functions) | Pseudonymous account identifiers, IP address, user agent, entitlement and service requests | Account authentication, request execution, and service authorization | Google Privacy Policy |
| Google LLC (Firebase App Check) | Apple App Attest material and App Check tokens | Authentic app/device verification, replay protection, and abuse prevention | Firebase Privacy and Security |
| Google LLC (Firebase Remote Config) | Firebase installation ID; no travel content | Feature availability and app-update configuration | Firebase Privacy and Security |
| Google LLC (Cloud Firestore) | Pseudonymous account, transaction, entitlement, quota, request, provider-usage, temporary-result, and App Store notification audit records | Authorization, metering, safe retries, fraud prevention, and subscription lifecycle handling | Google Privacy Policy |
| Google LLC (Firebase Crashlytics) | Consent-gated crash logs, stack traces, device state, and installation identifiers | Crash resolution | Google Privacy Policy |
| Google LLC (Cloud Functions and Vertex AI / Gemini) | Requested prompt content, including Destination, Trip, spot, date, note, transfer, and supported-import context | AI discovery, planning, and import processing | Google Cloud Privacy |
| Dumpling Software (Supadata) | Supported social-media URLs and public source media | Metadata retrieval and requested travel-content extraction | Supadata Privacy Policy |
| Apple Inc. (Sign in with Apple) | Apple identity token and pseudonymous account subject; no requested name or email scope | Account confirmation | Apple Privacy Policy |
| Apple Inc. (iCloud/CloudKit) | Destination and Trip data, covers, notes, saved spots and links, dates, coordinates, and transfers | Sync on compatible iPhones | Apple Privacy Policy |
| Apple Inc. (StoreKit/App Store) | Purchase and subscription transaction data | Payment, subscription, and restoration processing | Apple Privacy Policy |
| Apple Inc. (MapKit) | Place searches and views, map/request metadata, planning coordinates, and route details | Maps, place information, country lookup, and route estimates | Apple Maps & Privacy |
| Apple Inc. (App Attest) | App-integrity attestation material generated for Firebase App Check | Verify authentic app/device requests and protect backend services | Apple Privacy Policy |
| Unsplash Inc. | Destination name or other cover-search terms | Destination cover-image search | Unsplash Privacy Policy |
We do not sell, rent, or share your data with third parties for marketing or advertising purposes.
6. International Data Transfers
Data processed by Firebase Authentication, App Check, Cloud Functions, Cloud Firestore, Remote Config, Analytics, Crashlytics, and Vertex AI may be handled on Google infrastructure outside the European Economic Area and Brazil, including in the United States. Firebase Authentication operates from United States data centers; the other listed Firebase services may use global Google infrastructure.
Transfers Between Brazil and the European Union
Data transfers between Brazil and EU member states are supported by the mutual adequacy decision between Brazil and the EU (Resolution CD/ANPD No. 32/2026, January 2026), which recognizes the adequate level of data protection between both jurisdictions.
Transfers to the United States
For transfers to the United States, Google operates under its Data Processing Terms, which include Standard Contractual Clauses approved by the European Commission and protection mechanisms recognized by the ANPD.
iCloud Data
iCloud sync is managed by Apple, which processes data in its global data centers in accordance with Apple's Privacy Policy and in compliance with both GDPR and LGPD.
7. Data Retention
| Data | Retention Period | Notes |
|---|---|---|
| Firebase Analytics | 14 months (Google Analytics default) | Configurable. Aggregated data may be retained longer. |
| Firebase Crashlytics | 90 days | Crash logs are automatically removed after this period. |
| AI and social-provider inputs | Per the providers' terms | Google and Supadata may retain inputs under their applicable processing terms. |
| Firebase Authentication account and security metadata | Active account until account deletion; logged IP addresses generally for a few weeks | After account deletion, Google removes associated Authentication data from live and backup systems under its published process, which may take up to 180 days. |
| Firebase App Check | Attestation material is not retained by App Check; ordinary tokens are valid for no more than 7 days; replay-protection tokens may be stored for up to 30 days | Attestation material sent to Apple is subject to Apple's terms. |
| Firebase Remote Config installation ID | Until a deletion request for the installation ID | After such a request, Firebase removes associated live and backup data within 180 days. Spotinerary account deletion does not currently delete this installation ID. |
| Temporary provider request records and results in Cloud Firestore | Normally no longer than 25 hours | They expire after 1 hour; Firestore TTL deletion normally completes within the following 24 hours. Account deletion removes active temporary requests. |
| App Store notification audit metadata | About 180 days | Minimal pseudonymous metadata retained for idempotency, lifecycle handling, and fraud prevention, then removed by TTL. |
| Raw MapKit requests | Not separately retained by Spotinerary | Apple processes them under Apple Maps & Privacy. Places and routes you save follow local/iCloud retention. |
| iCloud data | While iCloud account is active | Managed by Apple. Users can delete via iCloud settings. |
| Local device data | While the app is installed | Removed when the app is uninstalled. |
| Active backend entitlement state | Until account deletion | The Firebase Authentication account is deleted and the active backend entitlement is deactivated through Settings. The separate pseudonymous ledger below remains for its stated retention period. |
| Pseudonymous subscription, transaction, and usage records | Up to 24 months after account deletion | Retained only for fraud and service-abuse prevention, then deleted. |
8. Your Rights
Rights Under the GDPR (Arts. 15-22)
You have the right to:
- Access (Art. 15) your personal data
- Rectification (Art. 16) of inaccurate data
- Erasure (Art. 17) of your data ("right to be forgotten")
- Restriction (Art. 18) of processing
- Data portability (Art. 20)
- Object (Art. 21) to processing
- Not be subject (Art. 22) to automated decision-making
Response timeframe: We respond without undue delay and in any event within one month, as provided by Article 12(3) GDPR. Where permitted due to the complexity or number of requests, this period may be extended by two further months, and we will notify you within the first month.
Rights Under the LGPD (Art. 18)
You have the right to:
- Confirmation of the existence of data processing
- Access to data collected about you
- Correction of incomplete, inaccurate, or outdated data
- Anonymization, blocking, or deletion of unnecessary or non-compliant data
- Data portability to another service provider
- Deletion of data processed based on consent
- Information about third parties with whom your data has been shared
- Information about the possibility of not providing consent and its consequences
- Withdrawal of consent at any time
Response timeframe: For confirmation and access requests, the LGPD provides an immediate simplified response or a complete response within 15 days under Article 19. Other requests are handled within the periods required by applicable law and ANPD guidance.
9. How to Exercise Your Rights
In the App
- Privacy Settings: Go to Settings > About > Help Improve Spotinerary to enable or disable analytics data collection and crash reporting.
- Account Deletion: Go to Settings > Account > Delete Account. A fresh Sign in with Apple confirmation revokes the authorization and deletes the Firebase account. This does not cancel an App Store subscription; the app provides a separate Manage Subscription link. Local travel data remains on the iPhone while the app is installed, and iCloud-synced copies are managed separately through Apple's iCloud storage controls.
By Email
Send your request to: support@spotinerary.com.br
Please include in your request:
- Description of the right you wish to exercise
- Sufficient information to locate your data (for example, your operating system and device model)
Supervisory Authority
If you believe your rights have not been addressed, you may file a complaint with:
- Brazil: ANPD (National Data Protection Authority) - www.gov.br/anpd
- European Union: The supervisory authority of your country of residence
10. Security Measures
We implement the following technical measures to protect your data:
| Measure | Description |
|---|---|
| Encrypted communications | Network communications are protected using industry-standard encryption. |
| Protected storage | Data stored locally and in iCloud benefits from platform security controls. |
| Access controls | Access to account and service data is restricted to authorized app components and backend services. |
| Transaction verification | Purchases are verified server-side using authenticity information provided by Apple. |
| Minimal identity processing | Sign in with Apple requests no profile scopes. Only pseudonymous identifiers needed to provide and protect the service are retained. |
11. Children's Data
Spotinerary is not directed at children under 13 years of age (per COPPA) or under 18 years of age (per LGPD, Art. 14).
We do not knowingly collect data from children or minors. If we become aware that data has been collected from a minor without appropriate parental consent, we will take immediate steps to delete such data.
In compliance with Brazil's Law 15.211/2025 (Digital Framework for Children and Adolescents), we reaffirm our commitment to protecting minors' data and to transparency in data processing.
If you are a parent or guardian and believe your child has provided data to the app, please contact us at support@spotinerary.com.br.
12. Policy Updates
This policy may be updated periodically to reflect changes in the app, applicable legislation, or our data processing practices.
How you will be notified:
- Significant changes will be communicated in the app's update notes on the App Store.
- The "last updated" date at the top of this policy will be changed.
- When applicable, a notice will be displayed in the app requesting renewed consent.
We recommend that you review this policy periodically.
13. Contact
For questions, requests, or complaints about this policy or about the processing of your data:
| Channel | Information |
|---|---|
| General email | support@spotinerary.com.br |
| Data Protection Officer (DPO) | Heitor Murara |
| DPO email | hmurara@spotinerary.com.br |
| Website | https://spotinerary.com/privacy |
This privacy policy was drafted in compliance with the General Data Protection Regulation (EU Regulation 2016/679), Brazil's General Data Protection Law (Law 13.709/2018), and Brazil's Law 15.211/2025.