Privacy Policy — Place of the Day

Last updated: 2026-07-25

This Privacy Policy (the "Policy") describes how an individual developer (the "developer", "we") processes the data of users of the Place of the Day app (the "App").

The developer is a natural person (Individual Apple Developer) and acts as an independent data controller within the meaning of the GDPR with respect to the processing described in this Policy.

This Policy applies solely to the Place of the Day App and does not govern data processing by other applications, websites or services, including services of Apple Inc. and other third parties.

By using the Place of the Day App, you confirm that you have read this Policy and understand the data-processing practices described in it. If you do not agree with this Policy, please stop using the App.

The App is provided "as is". This Policy describes data processing and is not a warranty of continuous, error-free or uninterrupted operation of the App, nor of the accuracy or completeness of any content or information displayed in the App. This does not affect any statutory rights that cannot be excluded under applicable law.

Your use of the App is governed by the Place of the Day Terms of Use and, unless a separate license agreement is provided, by Apple's standard Licensed Application End User License Agreement (EULA). Those documents contain warranty disclaimers and limitations of liability that apply in addition to the terms of this Policy; this Policy governs data processing.

Information We Collect

Data-collection minimization. The Place of the Day App is designed on a data-minimization principle. By default, the data you create or enter in the App is stored locally on your device (in the App's internal storage) and is not transmitted to the developer.

Data processed locally. The content you create in the App (records, settings, user input) is processed and stored on the device. The developer has no technical access to this data and receives no copies of it, except in the cases expressly described in the applicable sections of this Policy.

Data that may leave the device. Data is transmitted outside the device only to the extent and in the cases expressly described in the relevant sections of this Policy, in particular: when using analytics services (if enabled), and when using the App's server-side features (see "Server-Side Data & Your Account") — and in other cases expressly described in this Policy.

No sale of data. The developer does not sell personal data and does not share it with third parties for behavioral-advertising purposes.

Third-Party Services

Third-party analytics services. If the corresponding feature is enabled, the Place of the Day App uses the third-party analytics and crash-diagnostics services listed below. These services collect a limited set of data for the purposes of usage analytics and App stability. With respect to such processing, the providers act as processors on behalf of the developer, who acts as the controller.

The developer transmits data only to providers that, under their data-processing terms (DPA), are obligated to ensure a level of data protection equivalent to this Policy and to Apple's requirements. The developer relies on these providers' standard data-processing terms and does not control their internal practices beyond those terms.

The services listed below may begin collecting data at the App's first launch. Where applicable law (in particular, GDPR/ePrivacy) requires consent for such processing, you may object to it or request deletion of analytics data by contacting the developer (see the section on your rights), and you may also limit collection using iOS controls.

Firebase — Analytics, Crashlytics & Performance Monitoring (Google)

The App uses Firebase Analytics and Firebase Crashlytics, and — where the corresponding SDK is included — Firebase Performance Monitoring, provided by Google. These services may collect: device and installation identifiers (in particular, the Firebase Installation ID / installation UUID, IDFV), a pseudonymous user identifier assigned by the developer (User ID, which does not contain your name or contact details), the device model and OS version, the App version, and usage events. In addition: Firebase Analytics processes the IP address and derives an approximate country/region from it; Firebase Crashlytics, in the event of a crash, collects stack traces, diagnostic device information and the installation UUID (per Firebase documentation, with a retention period of about 90 days); Firebase Performance Monitoring collects network-request traces, App-launch metrics and device attributes. These SDKs begin collecting data by default at the App's first launch. Google processes this data as a processor; data may be transferred to the United States and other countries. Firebase/Google privacy policy: https://firebase.google.com/support/privacy and https://policies.google.com/privacy.

Mixpanel

The App uses Mixpanel for product analytics. Mixpanel may collect: a user/device identifier (distinct_id), the IP address and an approximate geolocation derived from it (city/region/country), technical device attributes, and usage events and their properties. Mixpanel acts as a data processor; data may be transferred to and stored in the United States (Mixpanel is certified under the EU-U.S. Data Privacy Framework and uses Standard Contractual Clauses for cross-border transfers). By default, Mixpanel automatically deletes event data after 2 years from the event date (for projects created before 1 September 2025 the initial retention period is 5 years, but it is reduced to 2 years upon a change of pricing plan or a switch to Mixpanel's free plan). Mixpanel privacy policy: https://mixpanel.com/legal/privacy-policy/.

Responsibility. IP addresses and device identifiers may constitute personal data under the GDPR and identifiers under CCPA/CPRA. The developer discloses the use of these services and relies on these providers' standard data-processing terms (in particular, the Google Data Processing and Security Terms; Mixpanel's DPA and Standard Contractual Clauses); the developer is not responsible for the providers' independent actions beyond those terms.

Server-Side Data & Your Account

Place of the Day offers an optional account so your content can be synced across your devices via our own server. If you create an account, we store on our server:

Location

When you submit a photo, the app checks on your device that you are physically near the place, to keep contributions authentic. Your coordinates are processed in memory only — they are never stored on your device and never sent to our server.

All communication between the app and our server is encrypted in transit (TLS/HTTPS). Server data may be processed in jurisdictions other than your own; where required, we rely on appropriate safeguards for such transfers.

Service availability

The sync service is provided "as is" and as a convenience: it may be interrupted, changed or discontinued. The server is not a guaranteed backup of your content — keep your own copies of anything important. To the maximum extent permitted by applicable law, the developer is not liable for loss of data caused by service interruptions, transmission failures or discontinuation of the service. Where reasonably possible, the developer will give advance notice of a permanent shutdown of the service.

Deleting your account

You can delete your account at any time directly inside the app (no email or support request needed). Deleting your account permanently removes your account record, credentials and synced content from our server within 30 days; residual copies in encrypted backups are purged on the regular backup rotation schedule. Deletion is irreversible: the developer does not offer restoration of deleted accounts or their content. Content stored locally on your device remains until you delete it or remove the app.

How We Use Information

Purposes of data processing. The developer processes data for the following purposes:

No sale and no behavioral advertising. The developer does not use your data for behavioral advertising and does not sell personal data.

Change of purposes. The developer does not use data for purposes incompatible with those stated above without obtaining consent, where required by applicable law.

Data Retention

Local data. Data stored locally on your device is retained until you delete it in the App or delete the Place of the Day App itself. Deleting the App deletes the local data stored in the App's container on the device.

Backups and data loss. The App is not a backup service. The developer has no access to data stored locally on your device and cannot recover or restore it if it is lost or deleted — including through deletion of the App, loss, damage or reset of the device, or a software error; content synced to your account is an exception and can be restored by signing in again for as long as the sync service operates. You are responsible for backing up your device (for example, via iCloud Backup or a computer backup) if you wish to preserve your data.

Analytics data. Data collected by third-party analytics services is retained in accordance with the retention periods set by the respective providers. The developer does not control these providers' internal retention periods; you can review the periods in the respective providers' privacy policies (see the section on third-party services).

Server data. Data stored on the developer's server is retained while your account remains active and is deleted after the account is deleted or the service is discontinued (see "Server-Side Data & Your Account", including "Service availability").

Your Rights and Choices

Your rights. Depending on your jurisdiction, you have rights regarding your personal data.

Exercising rights through the device. Some of the Place of the Day App's data is stored locally, and some on the developer's server. You can change or delete local data in the App or by deleting the App itself; data stored on the server is deleted through the account-deletion function in the App (see "Server-Side Data & Your Account").

Rights under the GDPR (European Economic Area, United Kingdom). You have the right to: access to data; rectification; erasure ("the right to be forgotten"); restriction of processing; data portability; objection to processing; withdrawal of previously given consent; and the right to lodge a complaint with a data-protection supervisory authority. In accordance with Article 12(3) of the GDPR, the developer provides information on the action taken on your request without undue delay and in any event within one month of receiving the request; this period may be extended by a further two months where necessary, taking into account the complexity and number of the requests.

Rights under CCPA/CPRA (California). To the extent CCPA/CPRA applies to the developer, you have the right to: know what personal information is collected and how it is used; request deletion; correct inaccurate information; opt out of the "sale" or "sharing" of personal information; and limit the use of sensitive personal information. For verified requests (to delete, correct, and provide information), the developer responds within 45 calendar days of receiving the request; this period may be extended once by a further 45 days with notice. The developer does not sell personal information and does not share it for behavioral-advertising purposes. The developer does not discriminate against users for exercising their rights.

How to exercise your rights through the developer. For requests that cannot be fulfilled by deleting the App (for example, requests regarding analytics data) or by deleting your account, contact the developer using the details in the "Contact" section below. The developer may request information to verify your identity before fulfilling a request.

Security

Security measures. The developer applies reasonable technical and organizational measures to protect data, commensurate with the nature of the data processed, including a preference for local, on-device storage and reliance on the iOS platform's protection mechanisms.

No guarantee of absolute security. No method of transmitting or storing data is absolutely secure. Despite the measures applied, the developer cannot guarantee the absolute security of data. To the maximum extent permitted by applicable law, the developer is not liable for unauthorized access to, loss of, or disclosure of data, including incidents on the side of third parties or the platform infrastructure. Nothing in this Policy excludes or limits liability that cannot be excluded under applicable law, including liability for intentional misconduct or gross negligence and rights of data subjects under the GDPR that cannot be waived.

Incident notification. In the cases provided for by applicable law (in particular, Articles 33-34 of the GDPR), the developer notifies the supervisory authority and/or the affected users of security incidents affecting personal data.

User responsibility. The security of your data also depends on the security of your device and your Apple account. We recommend using an up-to-date version of iOS, a passcode, and two-factor authentication.

Children's Privacy

Age restriction. The Place of the Day App is not intended for and is not directed to children under 13 years of age (and, in the European Economic Area, under the applicable age of digital consent, which ranges from 13 to 16 depending on the country).

No knowing collection. The developer does not knowingly collect the personal data of children under the specified age. The App contains no features designed to attract children as a primary audience.

Actions for parents. If you are a parent or legal guardian and believe that a child has provided personal data, contact the developer using the details in the "Contact" section below. Upon receiving verified information that data was collected from a child under the applicable age without appropriate consent, the developer will delete such data.

Platform age mechanisms. Where applicable law requires age restrictions or age verification, the App relies on the App Store's (Apple's) age-rating mechanisms and age signals; the developer does not request or store users' dates of birth.

Changes to This Policy

The developer may amend this Policy at any time, for example due to changes in the Place of the Day App's functionality, platform requirements, or applicable law.

Notice. The current version of the Policy is indicated by the last-updated date at the top of the page. Changes are communicated by updating this date and/or posting the updated Policy. We recommend that you periodically review the current version of the Policy; the last-updated date lets you determine whether it has changed since you last reviewed it.

Continued use. By continuing to use the App after the updated Policy is posted, you accept the updated Policy to the maximum extent permitted by applicable law. If the changes require your consent under applicable law, such consent will be requested separately.

Contact

For questions related to this Privacy Policy, and to exercise your rights regarding personal data, you can contact the developer:

Requests related to the exercise of rights regarding personal data are handled within the periods established by applicable law (one month under the GDPR; 45 days under CCPA/CPRA, where applicable). For other inquiries, the developer strives to respond within a reasonable time. When you contact us through third-party channels (for example, Telegram), the processing of your correspondence is governed by the terms of the respective service.