Legal

Privacy Policy

Last updated: August 3, 2026 · Version: 2026-08-03

1. Who Processes the Data

The Data Controller is Individual Entrepreneur MAKSIM GUSEV (Tax ID 304665609), registered at: Georgia, Tbilisi, Krtsanisi district, Ponichala settlement 3, building 5, entrance 2, floor 4. Inquiries regarding any data-related matters are accepted via email at: [email protected]. Data processing is conducted in accordance with the legislation of Georgia.

The legal basis for processing is the performance of the contract you enter into by accepting the Terms of Service, and your consent, recorded during registration along with the date and document version. Consent can be withdrawn by deleting your account.

2. What Data is Collected

The service does not collect data about your health, does not build advertising profiles, and does not enrich your profile with data from external sources.

3. Photos

Before saving, the server strips all metadata from the image, including GPS shooting coordinates; only the image orientation is retained. Files are stored in a private storage bucket and are served via signed URLs with a 5-minute lifespan — unauthorized persons cannot access anything via a direct file link.

4. Who Can See Your Entries

5. Cookies and Browser Storage

The service uses one technical cookie — between_bubbles_refresh. It is httpOnly (inaccessible to page scripts), transmitted exclusively over HTTPS, restricted to the /api/auth path, and lives for 30 days; it contains the session extension token. Login is impossible without it, therefore no cookie consent banner is required.

In the browser's local storage, the service keeps only internal login and logout flags to synchronize open tabs. There are no analytical, advertising, or tracking scripts used in the service.

6. Where Data is Stored and Who Else Sees It

Data is hosted in a data center located in Frankfurt (Germany). Subcontractors:

Cross-Border Data Transfer. Because our servers are located in Frankfurt, Germany, your data is transferred to and stored within the European Union. Germany provides an adequate level of personal data protection in accordance with the GDPR and Georgian data protection laws. By agreeing to this Policy, you explicitly consent to such cross-border transfer, storage, and processing of your data.

Data is not transferred or sold to third parties. The only exception is a lawful request from an authorized state body, provided it is presented in the manner prescribed by law.

7. How Long Data is Stored

8. Your Rights

9. Security

The connection to the service is secured via HTTPS. Passwords are stored exclusively as an argon2id hash, and email links as a token hash with a limited lifespan (one hour for password recovery, 24 hours for email confirmation). Changing the password and deleting the account will revoke all active sessions. The frequency of login attempts and file uploads is rate-limited. Photos reside in closed storage and are accessible only via short-lived signed links.

10. Children

The service is not intended for individuals under 18 years of age and does not intentionally collect their data. If such an account is discovered, it will be immediately deleted.

11. Policy Changes

New versions are published on this page with an updated date and version number. We will notify you of any significant changes via the email address provided during registration.