Legal

Privacy Policy

Last updated: August 4, 2026

Version: 1.2


1. Data Controller Identity

Spotinerary data controller information
Field Information
ControllerSPOTINERARY TECNOLOGIA LTDA
CNPJ (Brazil tax ID)65.861.495/0001-99
AddressAV PREFEITO OSMAR CUNHA 416 SALA 1108, 88015-100, CENTRO, FLORIANÓPOLIS, SC, BRASIL
Data Protection Officer (DPO)Heitor Murara
DPO Emailhmurara@spotinerary.com.br

Spotinerary is a travel-planning app organized around Destinations and Trips. Destinations can contain covers, tags, notes, saved spots, bookmark folders, and supported social links. Trips can contain Destinations, spots scheduled by date, and transfers. This policy describes how we handle data during your use of the app.


2. Data Collected

2.1 Data We Do NOT Collect

Spotinerary does not collect:

2.2 Account, Entitlement, and Quota Data

Creating an account is optional for limited local browsing and required before starting a trial, subscribing, restoring a subscription, or using server-funded features. We process:

Account, entitlement, and quota data and purposes
DataPurpose
Pseudonymous account and authentication identifiersRecognize and authenticate the same account across sessions and compatible iPhones
Subscription and transaction information, including product and statusVerify subscription access and prevent misuse
Usage allowance and reset informationEnforce limits for server-funded features

2.3 Data Collected Automatically

Firebase Analytics (Google)

When you consent to analytics data collection, the following data is collected:

Data collected through Firebase Analytics
DataExample
Device modeliPhone 15 Pro
Operating system versioniOS 26.0
Device languageen-US
Country (IP-based, no precise geolocation)United States
App usage eventsScreens visited and feature actions completed
Session dataSession duration, usage frequency
App instance IDPseudonymous identifier generated by Firebase, not linked to your name or email

Categories of tracked events include:

Firebase Crashlytics (Google)

When you consent to analytics and diagnostics, the following data may be collected for issue resolution:

Data collected through Firebase Crashlytics
DataPurpose
Crash logsIdentify and fix errors
Stack tracesLocate the technical source of errors
Device state at time of crashUnderstand conditions that caused the error
Device model and OS versionReproduce issues under similar conditions
Non-fatal SwiftData errorsMonitor data persistence issues

Firebase account security, service configuration, and server records

Firebase Authentication and Cloud Functions may process IP-address and user-agent security metadata when you sign in or make a server request. The app and backend also use the following services:

Firebase security, configuration, and server data and purposes
Service and dataPurpose
Firebase App Check: Apple App Attest material and App Check tokensVerify that requests come from the authentic app and device, protect backend services, and prevent replay and abuse
Firebase Remote Config: Firebase installation IDReturn operational feature availability and a non-blocking app-update policy. This processing is independent of Analytics consent, and no travel content is sent
Cloud Firestore: one-way-hashed account identifier, app account token, subscription, transaction, entitlement, quota, rate-limit, request, provider, usage, and minimal App Store notification audit recordsAuthenticate and authorize service access, meter usage, safely retry requests, handle subscription lifecycle events, and prevent fraud and abuse

Temporary provider results stored in Cloud Firestore can contain generated or extracted content until automatic deletion. The general travel library is not stored in Cloud Firestore; it remains local and in iCloud. Structured backend logs exclude prompts, source URLs, provider payloads, credentials, Firebase user identifiers, Apple subjects, and provider job identifiers.

iCloud / CloudKit (Apple)

Your travel data, including Destinations, Trips, covers you choose, tags, notes, saved spots and links, dates, and transfers, is synchronized through iCloud/CloudKit when iCloud is enabled. Apple manages this storage, which makes the data available to Spotinerary on compatible iPhones signed in to the same iCloud account.

Map and place services (Apple MapKit)

When you search for or view places, request a country lookup, or estimate a route, Apple may receive search terms or places viewed, map viewport and request/device metadata, saved or planning coordinates, and route origin, destination, transport mode, and departure time. Spotinerary does not request permission to access your live device location. We do not separately retain raw MapKit requests; places and route information you choose to save become part of your local/iCloud travel data. Apple handles these requests under Apple Maps & Privacy.

AI and social-content processing

When you request AI discovery, planning, or import processing, the following data may be sent to Google:

Data sent for artificial intelligence processing
Data SentPurpose
Destination names and location contextDiscover Destinations and spots and provide relevant place information
Selected Destination and Trip context, including dates, notes, saved spots, and transfer contextPlan dated itineraries and transfers or provide contextual suggestions
Requested public-source content from a supported importExtract and organize the travel content you requested

AI requests are sent through Spotinerary's Firebase Cloud Functions and processed by Gemini on Google Cloud Vertex AI. When you import supported social-media links, the source URL and the source's public media are also processed by Supadata to retrieve metadata and extract the travel content you requested. Google and Supadata may retain data according to their processing terms.

Unsplash API

When the app searches for a Destination cover image, the Destination name or cover-search terms are sent to the Unsplash API.

2.4 Purchase Data

All in-app purchases (monthly and annual subscriptions) are processed exclusively by Apple through StoreKit. Spotinerary:


3. Purpose of Processing

Purposes and GDPR legal bases for data processing
DataPurposeLegal Basis (GDPR)
Usage events (Analytics)Improve user experience, understand usage patterns, prioritize featuresConsent (Art. 6(1)(a))
Session dataAnalyze engagement and identify areas for improvementConsent (Art. 6(1)(a))
Crash logs and stack tracesIdentify, diagnose, and fix technical failuresConsent (Art. 6(1)(a))
Device state at crashReproduce and resolve technical issuesConsent (Art. 6(1)(a))
Sync data (iCloud)Make your data available to Spotinerary on compatible iPhonesPerformance of contract (Art. 6(1)(b))
Map and place requests (MapKit)Provide maps, place search and details, country lookup, and route estimates requested by youPerformance of contract (Art. 6(1)(b))
Data sent for AI and social-content processingGenerate or extract travel content as requested by the userConsent (Art. 6(1)(a))
Search terms (Unsplash)Fetch relevant Destination cover imagesPerformance of contract (Art. 6(1)(b))
Analytics app instance IDGroup pseudonymous events from one app installationConsent (Art. 6(1)(a))
Remote Config installation IDProvide operational feature availability and app-update configurationPerformance of contract (Art. 6(1)(b))
App Check attestation material and tokensProtect the service from unauthorized clients, replay, fraud, and abuseLegitimate interests (Art. 6(1)(f))
Pseudonymous account and authentication dataProvide subscription and server-funded feature accessPerformance of contract (Art. 6(1)(b))
Subscription transaction and usage recordsPrevent fraud and service abuseLegitimate interests (Art. 6(1)(f))

4. Legal Basis for Processing

GDPR (EU Regulation 2016/679, Art. 6)

LGPD (Brazil Law 13.709/2018, Art. 7)


5. Third-Party Data Sharing

Third parties, data shared, purposes, and privacy policies
Third PartyData SharedPurposePrivacy Policy
Google LLC (Firebase Analytics)Consent-gated usage events, device data, app instance IDUsage analysisGoogle Privacy Policy
Google LLC (Firebase Authentication and Cloud Functions)Pseudonymous account identifiers, IP address, user agent, entitlement and service requestsAccount authentication, request execution, and service authorizationGoogle Privacy Policy
Google LLC (Firebase App Check)Apple App Attest material and App Check tokensAuthentic app/device verification, replay protection, and abuse preventionFirebase Privacy and Security
Google LLC (Firebase Remote Config)Firebase installation ID; no travel contentFeature availability and app-update configurationFirebase Privacy and Security
Google LLC (Cloud Firestore)Pseudonymous account, transaction, entitlement, quota, request, provider-usage, temporary-result, and App Store notification audit recordsAuthorization, metering, safe retries, fraud prevention, and subscription lifecycle handlingGoogle Privacy Policy
Google LLC (Firebase Crashlytics)Consent-gated crash logs, stack traces, device state, and installation identifiersCrash resolutionGoogle Privacy Policy
Google LLC (Cloud Functions and Vertex AI / Gemini)Requested prompt content, including Destination, Trip, spot, date, note, transfer, and supported-import contextAI discovery, planning, and import processingGoogle Cloud Privacy
Dumpling Software (Supadata)Supported social-media URLs and public source mediaMetadata retrieval and requested travel-content extractionSupadata Privacy Policy
Apple Inc. (Sign in with Apple)Apple identity token and pseudonymous account subject; no requested name or email scopeAccount confirmationApple Privacy Policy
Apple Inc. (iCloud/CloudKit)Destination and Trip data, covers, notes, saved spots and links, dates, coordinates, and transfersSync on compatible iPhonesApple Privacy Policy
Apple Inc. (StoreKit/App Store)Purchase and subscription transaction dataPayment, subscription, and restoration processingApple Privacy Policy
Apple Inc. (MapKit)Place searches and views, map/request metadata, planning coordinates, and route detailsMaps, place information, country lookup, and route estimatesApple Maps & Privacy
Apple Inc. (App Attest)App-integrity attestation material generated for Firebase App CheckVerify authentic app/device requests and protect backend servicesApple Privacy Policy
Unsplash Inc.Destination name or other cover-search termsDestination cover-image searchUnsplash Privacy Policy

We do not sell, rent, or share your data with third parties for marketing or advertising purposes.


6. International Data Transfers

Data processed by Firebase Authentication, App Check, Cloud Functions, Cloud Firestore, Remote Config, Analytics, Crashlytics, and Vertex AI may be handled on Google infrastructure outside the European Economic Area and Brazil, including in the United States. Firebase Authentication operates from United States data centers; the other listed Firebase services may use global Google infrastructure.

Transfers Between Brazil and the European Union

Data transfers between Brazil and EU member states are supported by the mutual adequacy decision between Brazil and the EU (Resolution CD/ANPD No. 32/2026, January 2026), which recognizes the adequate level of data protection between both jurisdictions.

Transfers to the United States

For transfers to the United States, Google operates under its Data Processing Terms, which include Standard Contractual Clauses approved by the European Commission and protection mechanisms recognized by the ANPD.

iCloud Data

iCloud sync is managed by Apple, which processes data in its global data centers in accordance with Apple's Privacy Policy and in compliance with both GDPR and LGPD.


7. Data Retention

Data retention periods and notes
DataRetention PeriodNotes
Firebase Analytics14 months (Google Analytics default)Configurable. Aggregated data may be retained longer.
Firebase Crashlytics90 daysCrash logs are automatically removed after this period.
AI and social-provider inputsPer the providers' termsGoogle and Supadata may retain inputs under their applicable processing terms.
Firebase Authentication account and security metadataActive account until account deletion; logged IP addresses generally for a few weeksAfter account deletion, Google removes associated Authentication data from live and backup systems under its published process, which may take up to 180 days.
Firebase App CheckAttestation material is not retained by App Check; ordinary tokens are valid for no more than 7 days; replay-protection tokens may be stored for up to 30 daysAttestation material sent to Apple is subject to Apple's terms.
Firebase Remote Config installation IDUntil a deletion request for the installation IDAfter such a request, Firebase removes associated live and backup data within 180 days. Spotinerary account deletion does not currently delete this installation ID.
Temporary provider request records and results in Cloud FirestoreNormally no longer than 25 hoursThey expire after 1 hour; Firestore TTL deletion normally completes within the following 24 hours. Account deletion removes active temporary requests.
App Store notification audit metadataAbout 180 daysMinimal pseudonymous metadata retained for idempotency, lifecycle handling, and fraud prevention, then removed by TTL.
Raw MapKit requestsNot separately retained by SpotineraryApple processes them under Apple Maps & Privacy. Places and routes you save follow local/iCloud retention.
iCloud dataWhile iCloud account is activeManaged by Apple. Users can delete via iCloud settings.
Local device dataWhile the app is installedRemoved when the app is uninstalled.
Active backend entitlement stateUntil account deletionThe Firebase Authentication account is deleted and the active backend entitlement is deactivated through Settings. The separate pseudonymous ledger below remains for its stated retention period.
Pseudonymous subscription, transaction, and usage recordsUp to 24 months after account deletionRetained only for fraud and service-abuse prevention, then deleted.

8. Your Rights

Rights Under the GDPR (Arts. 15-22)

You have the right to:

  1. Access (Art. 15) your personal data
  2. Rectification (Art. 16) of inaccurate data
  3. Erasure (Art. 17) of your data ("right to be forgotten")
  4. Restriction (Art. 18) of processing
  5. Data portability (Art. 20)
  6. Object (Art. 21) to processing
  7. Not be subject (Art. 22) to automated decision-making

Response timeframe: We respond without undue delay and in any event within one month, as provided by Article 12(3) GDPR. Where permitted due to the complexity or number of requests, this period may be extended by two further months, and we will notify you within the first month.

Rights Under the LGPD (Art. 18)

You have the right to:

  1. Confirmation of the existence of data processing
  2. Access to data collected about you
  3. Correction of incomplete, inaccurate, or outdated data
  4. Anonymization, blocking, or deletion of unnecessary or non-compliant data
  5. Data portability to another service provider
  6. Deletion of data processed based on consent
  7. Information about third parties with whom your data has been shared
  8. Information about the possibility of not providing consent and its consequences
  9. Withdrawal of consent at any time

Response timeframe: For confirmation and access requests, the LGPD provides an immediate simplified response or a complete response within 15 days under Article 19. Other requests are handled within the periods required by applicable law and ANPD guidance.


9. How to Exercise Your Rights

In the App

By Email

Send your request to: support@spotinerary.com.br

Please include in your request:

Supervisory Authority

If you believe your rights have not been addressed, you may file a complaint with:


10. Security Measures

We implement the following technical measures to protect your data:

Technical security measures
MeasureDescription
Encrypted communicationsNetwork communications are protected using industry-standard encryption.
Protected storageData stored locally and in iCloud benefits from platform security controls.
Access controlsAccess to account and service data is restricted to authorized app components and backend services.
Transaction verificationPurchases are verified server-side using authenticity information provided by Apple.
Minimal identity processingSign in with Apple requests no profile scopes. Only pseudonymous identifiers needed to provide and protect the service are retained.

11. Children's Data

Spotinerary is not directed at children under 13 years of age (per COPPA) or under 18 years of age (per LGPD, Art. 14).

We do not knowingly collect data from children or minors. If we become aware that data has been collected from a minor without appropriate parental consent, we will take immediate steps to delete such data.

In compliance with Brazil's Law 15.211/2025 (Digital Framework for Children and Adolescents), we reaffirm our commitment to protecting minors' data and to transparency in data processing.

If you are a parent or guardian and believe your child has provided data to the app, please contact us at support@spotinerary.com.br.


12. Policy Updates

This policy may be updated periodically to reflect changes in the app, applicable legislation, or our data processing practices.

How you will be notified:

We recommend that you review this policy periodically.


13. Contact

For questions, requests, or complaints about this policy or about the processing of your data:

Privacy and data protection contacts
ChannelInformation
General emailsupport@spotinerary.com.br
Data Protection Officer (DPO)Heitor Murara
DPO emailhmurara@spotinerary.com.br
Websitehttps://spotinerary.com/privacy

This privacy policy was drafted in compliance with the General Data Protection Regulation (EU Regulation 2016/679), Brazil's General Data Protection Law (Law 13.709/2018), and Brazil's Law 15.211/2025.