Privacy Policy
Last updated 30 August 2026. This describes how the SPAIA App, operated by Playstate UG (haftungsbeschränkt), handles your data.
Who we are
The SPAIA App is operated by Playstate UG (haftungsbeschränkt), Thomas Cox. For anything in this policy, or to exercise any of the rights below, contact us at hello@playstateprojects.com. See our Impressum for full company details.
What we collect
- Account data — email address, and a password (stored as a salted hash) if you sign up with email/password rather than a magic link.
- Profile data — display name, bio, and profile photo, if you choose to add them.
- Observation data — the insect sightings you tap during a session, session timing, weather, and any notes on habitat conditions or other wildlife.
- Location data — GPS coordinates when you create or use a spot/space, or search for an address, and to look up weather for your session.
- Photos — cover images for spots and spaces you create, and the optional scene photo you take when starting an observation session.
- Payment data — if you buy a space or spot pack, Stripe processes your payment; we receive confirmation of payment, not your card details.
- Technical data — standard server logs (IP address, request timing) generated by our hosting infrastructure.
How we use it
- To run your account and remember your sightings, cards, and streaks.
- To show spots, spaces, and leaderboards to you and other observers.
- To read the scene in a photo you submit (habitat, plants) using an AI image-analysis service, so we can pre-fill details for you.
- To look up real weather conditions for your session's time and location, from Bright Sky (a public weather API built on Deutscher Wetterdienst (DWD) open data) for German locations, or Visual Crossing for other locations.
- To process payments for space/spot packs.
- To aggregate anonymised sighting counts for biodiversity research and public leaderboards.
Who we share it with
We don't sell your data. We use the following processors to run the app:
- Cloudflare — hosting, database, and storage for photos and avatars.
- Stripe — payment processing for space/spot packs.
- Resend — sending account emails (magic links, confirmations).
- DeepSeek — AI analysis of photos you submit, to detect habitat features. This provider is located outside the EU; photos sent to it are used only to generate the description shown back to you.
- Bright Sky — a public weather API (built on Deutscher Wetterdienst open data) we query with your session's approximate location and time to record real weather conditions, for locations in Germany.
- Visual Crossing — a weather API we query the same way, for locations outside Germany.
- Stadia Maps — map tiles shown when placing a pin.
- OpenStreetMap (Nominatim) and BigDataCloud — turning addresses and GPS coordinates into place names.
Cookies
We use one essential cookie to keep you signed in. We don't use advertising or analytics cookies.
How long we keep it
We keep your account and observation data for as long as your account is active. If you delete your account, we delete your profile and personal data, though aggregated, anonymised sighting counts may be retained for research purposes.
Your rights
Under GDPR, you can ask us to access, correct, delete, or export your data, or object to how we use it. Email hello@playstateprojects.com and we'll respond as quickly as we can. You can also lodge a complaint with your local data protection authority.
Children
The SPAIA App isn't directed at children under 16. If you believe a child has created an account without parental consent, contact us and we'll remove it.
Changes
We may update this policy as the app changes. We'll update the date at the top when we do.