Privacy Policy
This policy explains what data mySpoils collects, how it's used, and how you can control it. We keep things simple.
The person responsible for your data (“the controller”, in the words of the GDPR) is the individual who operates mySpoils, based in Spain. Identification details are on the Legal information page, or on request at hello@myspoils.app. Write to that address to ask what is held about you, to correct it, or to have it deleted.
What we collect
When you sign in with Google we receive your:
- Email address
- Display name
- Profile photo (avatar)
Beyond that, the only data we store is the content you create inside the app: your spoils (entries), lists, ratings, notes, and any profile information you fill in.
If you report a public profile without having an account, we hold the email address you gave and what you wrote. It is used to answer you and for nothing else. It is never shown to the person you reported, and no list you can be mailed on is built from it.
We keep the address for twelve months after the report is dealt with, then delete it. What was reported and what we did about it stays, without your address on it.
Age, and a date of birth
You have to be 16 to have an account here (why). Today that is a confirmation you make by signing up and nothing is stored: we hold no date of birth for anybody.
If that changes we will store the date and nothing derived from it, use it for the age requirement and for nothing else, never show it on a profile or hand it to a third party, and say so here before it starts. A date of birth is personal data and the least we can hold is none.
How data is stored
Your data lives in a PostgreSQL database managed by Supabase and the app is hosted on Vercel. Both are reputable infrastructure providers with their own security and compliance practices.
What you publish, and what a visitor sees
Nothing you log is public until you say so, and it takes two separate decisions. A new account's profile is closed, and every spoil starts private. Turning the profile on opens your address; marking a spoil public puts that one spoil on it. Neither does the other's job.
A public profile is a public web page. It needs no account to read, we list it in our sitemap, and search engines may index it. Turning the profile off takes the page down.
A profile that is on shows:
- Your display name, your username, your avatar and your bio
- Any badges you have earned, and the supporter mark if you have one
- The spoils you have made public. For each one: its title, subtitle, category, artwork, release date, the date you experienced it, your rating, whether you marked it a favourite, and your note
- Counts and summaries drawn from those spoils: how many per category, how many favourites, your year in review, and your Top 10
It never shows:
- Your private spoils, or any count or hint of how many there are
- The things you keep with a spoil: photographs, tickets, files and links. Those are never shown to a visitor, on any surface, whether or not the spoil itself is public
- Your email address, or anything you have not published
A link to one spoil works off that spoil alone. If you share a single spoil, the link keeps working even while your profile is closed, because publishing that spoil was a decision about it and it stays true. Your name stays off the page while the profile is closed.
A shared link carries how you were looking at your collection, not only where. When you share a filtered view, the narrowing travels in the address: what you searched for, the categories, the date range, the rating and note filters, and your tags. A tag is your own word for something, and it is written into the link, so whoever you send it to can read it, and can forward it. Tags appear on no public page otherwise: nobody browsing your profile discovers them, and somebody holding a link is shown which spoils carry the tags in that link and nothing about any other tag on any of your spoils.
Every link, however it is filtered, resolves against your public spoils only. A filter that matches something private shows the visitor nothing.
Pasting a link somewhere generates a preview. Chat apps, social networks and messaging services fetch a preview card when a link is posted, and for a collection link that card carries your display name, username, avatar, bio and the number of public spoils in it. That fetch is made by the service you posted it to, not by us.
Paying, and what Stripe gets
If you buy Pro or a Lifetime licence, the payment is handled by Stripe. You are sent to Stripe's own checkout page to pay, so your card number is entered there and never reaches mySpoils. We never see it, never store it, and could not produce it if you asked us to.
What Stripe receives from us is your email address, so it can send you a receipt and recognise you as the same customer next time, and an internal reference to your account so we know which account the payment was for. What we receive back and store is the identifier Stripe gives your customer record and your subscription, and whether the plan is active. That is all we need to know what you are entitled to, and it is all we keep.
Stripe handles the payment on their own terms and privacy policy as well as this one. If you cancel, your entitlements change and nothing you have logged is touched.
What we keep is on our side: which plan the account holds, whether it is active, and that it was paid for. Stripe keeps its own records of the payment itself, under its own terms, and what survives a request you make to them is theirs to answer.
Third-party services
We use the following external services to run the app. Each is listed with what it receives.
Signing in, paying, and email
- Google OAuth: sign-in only; we do not access your Google Drive, Gmail, or any other Google data.
- Stripe: payments. See the section above for what is sent and what comes back.
- Resend: to send transactional emails (e.g. sign-in links, waitlist confirmations) and, if you have asked for them, occasional product-news emails. We share only your email address, and your name if you have set one, for this purpose.
Looking things up when you log a spoil
When you log something, mySpoils searches public catalogues so you do not have to type in the director, the cover or the address yourself. What those services receive is the words you typed and nothing about you: the request comes from our server, not your browser, and it carries no name, no email address and no account identifier. They cannot tell one person's searches from another's, or from ours.
- TMDB (The Movie Database): the film, series or person you are searching for, and the scores and artwork it holds for them.
- Open Library: the book or author you are searching for, and its cover.
- Google Books: the same, as a second catalogue when the first has nothing; and the country your browser reports, which is what decides whether a preview of a book is available where you are.
- MusicBrainz and the Cover Art Archive: the artist, album or track you are searching for, and its sleeve.
- Google Places: the place you are searching for, as you type it, and a photograph of the one you pick. This is the one lookup that happens while you are still typing.
- Wikidata: an identifier or a code we already hold - an airport code on an imported flight, an airline code, a catalogue id - to find the city it serves, the carrier it belongs to, or a fact worth knowing about what you logged.
- Wikipedia and Wikimedia Commons: the name of a place or a subject, to find a photograph of it and the credit its licence requires.
- Logo.dev: the brand you are searching for, to find its logo.
- YouTube: an identifier for a trailer or a music video, to check that it can be played before we offer it to you. Nothing about you goes with it.
What your browser loads from somebody else
Three things inside the app are loaded from another company's server, and each only after you ask for it:
- A YouTube player, when you press play on a trailer or a music video. We load it from youtube-nocookie.com, Google's privacy-enhanced host, which holds cookie data back until the video actually plays. And pressing play is what creates the player in the first place.
- A Google Books preview, when you open a book's preview.
- A Google Map, when you expand the map on a place.
The two Google frames are requests to Google. If you are signed in to Google, they carry your Google cookies with them, and Google can set more. That is true of any page anywhere carrying a Google map or a book preview; we cannot show them and prevent it.
Vimeo videos are drawn as a still picture with a link out. No Vimeo player is ever loaded.
Pictures are fetched by your browser directly. A poster, a cover, a sleeve, a portrait, a brand's logo, a video thumbnail: your browser goes to whoever holds it, with nothing of ours in between. Each of them sees your IP address and your browser's user agent, and each can set a cookie on its own domain. They are TMDB, Open Library, Google Books, Wikimedia, Logo.dev, the Cover Art Archive, Primavera Sound, and the thumbnail hosts of YouTube and Vimeo.
Two kinds of picture do not work that way, because our server fetches them for you: photographs you have uploaded, and photographs of places from Google. For those, the other service sees us rather than you.
Understanding how the app is used
- Google Analytics: to understand how the app is used in aggregate, and only if you accepted it in the cookie banner. No personal data is sold or shared with advertisers.
Product-news emails
We only send these if you have asked for them. The switch is off by default, at sign-up and in Settings, and signing up never subscribes you. Turn them off any time under Settings → Emails, or with the unsubscribe link at the bottom of any one of them. Either way we stop; emails about your account, like sign-in links, still come through.
What we don't do
We do not sell, rent, or trade your personal data to anyone. Full stop.
Deleting your data
You can delete your own account from Settings, at any time, without asking anybody. It asks for a deliberate confirmation, because after 30 days it cannot be undone.
Deleting takes your public profile down at once and signs you out. The data stays for 30 days, so an accident can be undone and so you can still ask for a copy. Export your collection first if you want to keep it. After 30 days it is deleted, apart from records we have to keep: payment and tax records, and the fact that an account was closed and why.
If you cannot sign in, write to hello@myspoils.app and we will do it for you.
Contact
Questions or concerns? Reach out at hello@myspoils.app.