Effective 10 September 2026
Privacy Policy
Albi is a place to plan things to do with the people you know, and to keep what came of them. It is operated by Jorge Gonzalez Cardelus, an individual developer.
This Privacy Policy explains what personal data we collect, why we collect it, who it is shared with, how long we keep it, and the rights you have over it. It covers the Albi mobile app on iOS and Android and this website, and it forms part of the Terms of Service. You are asked to accept it once, during sign-up, and your acceptance is recorded on your account together with the revision in force at the time.
We do not sell your personal data. We do not share it for advertising and we show no advertising. We do not buy personal data, and we do not obtain it from data brokers.
Who we are
The controller of your personal data — the person who decides why and how it is processed — is:
Jorge Gonzalez Cardelus
chiteki.albi@gmail.com
Under the privacy laws of the United States, the same person is the “business”. Albi is not required to appoint a Data Protection Officer and has not appointed one; privacy requests are handled by the controller directly.
What we collect
Three kinds of information: what you give us, what we record while you use Albi, and what other people and platforms tell us about you.
What you give us
- Account information
- When you create an account, our authentication provider issues an account identifier, which we store. Where you sign in with Apple or with Google, we receive the identifier and the email address that provider releases to us. Where you sign in with an email address and a password, the password is set and verified by the authentication provider — we never receive it and never store it.
- Profile information
- Your username, exactly as you typed it — capitals included, because the username is case-sensitive and the spelling you chose is what identifies you; a lowercased copy of it, which is what username searches match against so that people can find you whatever casing they type; the first and last name you enter; your avatar image; your profile backdrop (your “Mural”), which may be a solid colour, a line of repeating text you write, or a picture you upload; and a lowercased, combined copy of your name and username, which is the field that makes you findable in search. Your profile privacy setting and your message privacy setting are stored alongside them.
- Your content
- The nooks you create — their names, colours, cover images and visibility; the entries you add to them, including titles, descriptions, scheduled dates and times, the timezone those were set in, and place details where an entry carries them; and, where an entry or a nook is a copy of someone else’s, a reference to the original. We do not request access to your device’s location and do not record where you are. Where an entry carries a place, that place is supplied with the entry rather than sensed from your device.
- Photos and videos
- The media you upload, and the reduced-size copies we generate from it so that images load quickly — for a photo, up to four renderings at descending resolutions; for a video, the transcoded file and a poster frame. We also store each file’s dimensions and, for a video, its duration. Photos are re-encoded to JPEG on your device before upload, which drops the metadata a camera embeds in a file, including the GPS coordinates of the place a photograph was taken. Videos are re-encoded on your device to H.264 and AAC.
- Messages, comments and reactions
- The text of the messages you send in nook conversations and in direct messages; the comments and replies you write on entries; and, where a message is about a specific photo, a reference to that photo. Also the entries you like, the entries you mark as done, the comments you like, and the photos you mark as favourites. Messages and comments are stored on our servers in a readable form. Albi does not offer end-to-end encryption. Data is encrypted in transit and at rest, but we can technically access message content, and will do so where we are legally required to or where it is necessary to investigate a report.
- Your connections
- The accounts you follow and the accounts that follow you, including follow requests that have not yet been answered; the nooks you belong to and your role in each; the conversations you belong to; and the accounts you have blocked. We do not ask for access to your phone’s contacts, and we do not upload your address book.
- Age assurance
- Before you can use Albi, your account passes an age check. We store the outcome: an age band (under 13, 13–15, 16–17, or 18 and over); where the band came from; the age range the platform returned, where it returned one; on iOS, whether the range was declared by you, declared by a guardian, or confirmed by the platform; on Android, the account status the platform reports; which platform ran the check; and the date of the check. Where neither platform can answer, we ask for your date of birth instead. That date of birth is not stored. Only the band derived from it is kept.
- Reports and support
- Reports you submit about content or about another account, including the category you choose and any note you write; requests you submit for additional storage, including any note; and the content of any message you send us for support.
- Acceptance of our terms
- The date on which you accepted the Terms of Service and this Policy, and the revision of those documents that was in force at the time.
What we record while you use Albi
The first three items below are collected only if you allow them. The app asks during sign-up, as its own step, separately from accepting our terms. Both switches start off, and nothing is collected while they are off. Usage data and session replays are two separate choices: allowing one does not enable the other, and you may allow one, both or neither. You can change either at any time in Settings, and Albi works the same whichever you choose. Accounts in the 13–15 age band are never asked, and never have any of it collected.
- Usage and log information
- How the app is used, so that we can find defects and see which features matter: the screens you open — including identifiers for the nook, entry or conversation named in the route — taps on interface elements, the app opening, backgrounding and closing, and named product events. Those events record the action, not its content: that an entry was created, how many photos it had, whether it had a date, a place or a description, and what visibility was chosen; that a search ran and how many results it returned; that a follow, a like, a fork, a deletion or an upload happened. These events carry your account identifier and your username, so that a single session can be reconstructed. They do not carry the text of your messages, your comments, or your photographs.
- Error reports
- Crashes and handled failures, with a stack trace, a short label for where in the app it happened, and the application and device details needed to reproduce it.
- Session replays
- A masked replay of app sessions, so that we can see where the interface fails. Masking is applied on your device before anything is transmitted: text you type, images, and embedded content are all obscured. A recording shows the layout of a screen and where it was touched, not what you were reading, writing or looking at. Recordings also capture the app’s own diagnostic log output.
- Device and connection information
- The device model, operating system version, application version, language and region settings, and network connection type, as reported by the analytics software in the app. Also, for each device on which you sign in, a push notification token, the platform of that device, and the date it was last seen.
- Storage accounting
- A running total of the bytes you are storing, and the date on which that total was last recalculated against our storage provider. This is what enforces the storage limit in the Terms.
- Account status
- Whether your account is suspended and the reason recorded for it; whether you have requested deletion and when; whether an age check resolved to under 13; and how many times an age check has been re-answered on your account.
- Data held on your device
- The app stores your session token in the operating system’s secure store, and your preferences, cached content and pending uploads in the app’s own storage. This storage keeps you signed in and lets the app work offline. It is not transmitted to us, and it is cleared when you sign out or remove the app.
Cookies and similar technologies
The Albi website runs product analytics. It records page views, which calls to action are clicked — including which of the two app store badges — and which sections are scrolled into view. The website has no form and collects nothing you type. Nobody is identified on the website, no visitor profile is created, and session recording is switched off there. To count a returning visitor as the same visitor, the analytics software stores an anonymous identifier on your device, using cookies and local storage.
None of that happens until you agree to it. The first time you visit, the site asks, and nothing analytics-related loads — no script, no cookie, no request — until you accept. If you decline, the site works the same and we do not ask again. You can change your mind at any time through “Cookie settings” at the foot of any page, which stops the analytics, deletes the cookies and local-storage entries it set, and returns you to the original question.
Our hosting provider keeps standard server logs, which include IP addresses. Those are kept to run and secure the site, and are not subject to the choice above.
What other people and platforms tell us
- Other people
- Other users can add you to a nook, send you a message, follow you, comment on your entries, like or mark your entries as done, and upload photos and videos to entries you can see. Where someone likes or marks an entry of yours, we store their name and username alongside that record so the list can be searched. Other users can also report you or your content, and their report and any note they write is stored against your content.
- Platform age signals
- Where your device supports it, we ask Apple’s Declared Age Range or Google’s Play Age Signals for an age range. The range, and — on Android — the account status, come from Apple or Google rather than from you. We do not receive your date of birth from either platform.
- Your sign-in provider
- Where you sign in with Apple or with Google, that provider releases an account identifier and an email address to our authentication provider, which passes the identifier to us.
What you share, and who can see it
Most of what we store is content you deliberately shared. Who can see it is decided by the settings you choose, on a single ladder:
| Tier | Who can see it |
|---|---|
| Private | Only you. Entries only — a nook always has its members. |
| Collaborators | The members of the nook. |
| Network | The members of the nook, plus everyone who follows any of them. |
| World | Anyone on Albi. |
An entry may be more private than the nook that holds it, but never more public. That limit is enforced on our servers.
New profiles are private by default. A private profile’s follow requests need your approval, and someone who does not follow you sees only your username and avatar — your real name is withheld by the server, not merely hidden by the app. Your username, your avatar and the fact that your account exists are always visible. Every request the app makes is authorised on our servers against your identity and against these rules.
Blocking. You may block any account. Blocking works in one direction and is never disclosed: the blocked person continues to see an ordinary conversation, and nothing they send is delivered to you. It is scoped to direct messages — it does not unfollow, and it does not remove either of you from a shared nook.
Notifications. We send push notifications through the notification services operated by Apple and Google, and through an intermediary delivery provider. A notification carries the name or username of the person who caused it, the name of the nook or entry involved, a count, and a small image — an avatar or a nook picture. A notification never carries the text of a message or a comment. When someone messages you, the notification says that they sent you a message, not what it said.
Who we share your information with
We do not sell your personal data. We do not share it for advertising and we show no advertising. We do not buy personal data, and we do not obtain it from data brokers.
Service providers
The following providers process personal data on our behalf and on our written instructions. They may not use it for their own purposes.
| Provider | What they do | What they handle | Where |
|---|---|---|---|
| WorkOS | Authentication and identity | Email addresses, sign-in credentials and sessions | United States |
| Convex | Application database and backend | Profiles, nooks, entries, comments, messages and the social graph | United States |
| Amazon Web Services (S3) | Object storage | Photos and videos | European Union (Frankfurt) |
| PostHog | Product analytics, error tracking and session recordings — only with your consent | The usage data described under “What we collect” | European Union |
| Expo | Push notification delivery and app updates | Push tokens and notification copy | United States |
| Vercel | Website hosting | Server logs, including IP addresses | European Union / United States |
PostHog is the only one of these you can switch off. Product analytics and session recordings are off until you turn them on, and you can change your mind at any time under Settings → “Help improve Albi” in the app, or through “Cookie settings” on this website. Recordings are masked on your device before anything leaves it, and none of these events carry the text of your messages, your comments, or your photographs. Everything else in the table is infrastructure Albi cannot run without.
If a provider changes, this list changes with it, and the date at the top of this page moves. Write to chiteki.albi@gmail.com with any question about one of them.
Independent controllers
The operators of the Apple App Store and the Google Play Store distribute the app, provide the age-range signal the age check relies on, and run the notification services that deliver push messages to your device. They decide their own purposes for the data they handle in doing so, and their own privacy policies govern it.
Affiliates, and a change of ownership
Albi has no parent, no subsidiaries and no affiliated companies, and no personal data is shared with any such entity. If Albi is transferred to another owner, or its assets are acquired, personal data may be transferred with it. You will be told before that happens, and before this Policy is replaced by the new owner’s.
Why we process your information, and our legal basis
Our lawful basis under the General Data Protection Regulation for each purpose is set out below.
Performing our contract with you
Article 6(1)(b). We rely on this for:
- creating your account, holding your profile, and signing you in;
- storing your nooks and entries, and showing them to the people your settings allow;
- storing and delivering your comments and messages, and keeping track of what you have read, what is unread, and what you have muted or pinned;
- storing your photos and videos, generating the reduced-size copies, and serving them back to you and to the people allowed to see them;
- maintaining your follows, follow requests, nook memberships and blocks;
- building the Explore feed and the Gallery from the content you and the people you follow have shared;
- applying your storage limit, and handling a request for more;
- recording your acceptance of our terms.
You must provide an email address or a linked sign-in account, a username, and an age band in order to hold an account. Everything else — a real name, an avatar, a Mural, a place on an entry, the content you add — is optional, and declining affects only the features that depend on it.
Your consent
Article 6(1)(a). We rely on consent for:
- product analytics and error reporting, in the app and on the website. Both are off until you say yes, and both can be switched off again afterwards — in the app’s settings, or through “Cookie settings” in the website footer;
- session recordings in the app, which are a separate choice from product analytics: allowing one does not enable the other. The website does not record sessions at all;
- push notifications, which are sent only to devices where you granted the operating system’s notification permission. You can withdraw it at any time in your device settings, and doing so is as easy as granting it was;
- camera, photo library, and microphone access, each requested only when you first use the feature that needs it, and each of which you can withdraw in your device settings.
The first two also store an identifier on your device, which requires your prior agreement under Article 5(3) of the ePrivacy Directive — in Spain, Article 22.2 LSSI. We obtain it before anything is stored.
If you are under 16, we do not ask, and analytics and session recordings stay off. Article 8 of the GDPR sets the age at which a person can consent for themselves anywhere between 13 and 16 depending on the member state; we apply 16 everywhere. Accounts below it are never shown the prompt, the settings toggles do not appear, and the threshold is applied on our servers.
Withdrawing consent does not affect the lawfulness of anything done before you withdrew it. Withdrawing analytics consent also deletes the identifier from your device.
Complying with a legal obligation
Article 6(1)(c). We process your age band and the evidence behind it in order to keep under-13s off the platform, and we retain a minimal record of a blocked account so that the same identity cannot immediately register again — see “Deleting your information”. This discharges obligations placed on us by the app stores through which Albi is distributed, and by children’s privacy law. We also process personal data where we must respond to a valid legal request, or retain records for a legal claim.
Protecting vital interests
Article 6(1)(d). In rare cases — a credible threat to someone’s life or physical safety — we may access, retain and disclose personal data in order to prevent harm.
Legitimate interests
Article 6(1)(f). Where we rely on legitimate interests, we have weighed our interest against your rights. The specific interests are:
- Keeping Albi safe
- Handling reports, hiding content that reaches the report threshold, reviewing moderation decisions, suspending accounts that break our terms, and rate-limiting unsolicited message requests. Our interest is in running a service that is safe to use and in protecting our users from harassment and abuse. We consider this not to be overridden by your rights, because the processing is confined to what a report or an enforcement decision requires.
- Securing the Service
- Detecting and preventing abuse of the API, fraudulent sign-ups, and unauthorised access to accounts.
We do not rely on legitimate interests to improve the service. Product analytics, error reports and session recordings run on your consent, and refusing them is enough to stop them.
Automated decision-making
We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, on a solely automated basis. Two automated mechanisms operate on the service:
- Content ordering
- The Explore feed and the Gallery are assembled automatically from the accounts you follow and the nooks you belong to, in reverse chronological order, with a random sample used for the slideshow. There is no behavioural profiling and no inferred-interest model.
- Report thresholds
- Content is marked as reported after one report, and automatically hidden after a small number of distinct reporters. A human moderator reviews it after that, and can restore it. The automatic step is reversible and does not by itself close an account; suspension is always a human decision.
Your rights
If you are in the EEA, the United Kingdom or Switzerland, you have the right to:
- access the personal data we hold about you, and receive a copy;
- rectify data that is inaccurate or incomplete;
- erase your data;
- restrict our processing of it;
- object to processing carried out on the basis of legitimate interests — the safety and security processing described above;
- port your data, in a structured, commonly used, machine-readable format;
- withdraw consent at any time, without affecting what was lawful before;
- complain to a supervisory authority.
You can exercise much of this yourself, immediately, and without asking us — see “Managing your information”.
For anything you cannot do yourself — a copy of your data, a correction you cannot make in the app, or a question about this Policy — write to chiteki.albi@gmail.com. We will answer within one month, and will tell you if we need longer. Exercising a right will never get you a worse service.
If we refuse a request we will tell you why. You can appeal by replying to our answer; we will review it and give you a written outcome within a further month. That does not limit your right to complain to a regulator.
You may complain to the supervisory authority in the country where you live, where you work, or where you think the infringement happened. In Spain this is the Agencia Española de Protección de Datos (aepd.es).
How long we keep your information
We keep personal data for as long as we need it for the purpose we collected it for. In practice:
| What | How long |
|---|---|
| Your account, profile and content | For as long as your account exists. |
| An entry or nook you delete | Hidden immediately; permanently erased 30 days later. |
| Your account after you request deletion | Hidden immediately; permanently erased 30 days later. |
| Messages you sent, after your account is erased | Kept, for as long as the people who received them keep their conversation. They are part of that conversation too, and erasing one side of it would take away their record of an exchange they took part in. A conversation nobody is left in is erased outright. |
| Your username, after your account is erased | Kept indefinitely, and never released for anyone else to register. This is the narrowest way we can keep the messages above honestly attributed: if the username could be taken by someone new, they would appear to have written them. Nothing else about the account is retained with it. |
| Push notification tokens | Until you sign out on that device, or the platform reports the token as dead. |
| Unfinished uploads in temporary storage | One day. |
| A declined message request | Kept as a tombstone for as long as both accounts exist, so that the sender cannot re-request. |
| Reports and moderation records | For as long as the account they concern exists, as the audit trail behind a decision. |
| Product analytics and session recordings | No longer than twelve months. |
| The minimal record of an under-13 block | Indefinitely — see “Deleting your information”. |
Deleting your information
You can delete your account from within the app — see how to delete your account for the steps. When you do:
- your account and all its content are hidden from everyone immediately, and you are signed out;
- you have 30 days to change your mind — signing back in during that window restores everything, exactly as it was;
- after 30 days, everything is erased permanently: your profile, your nooks, your entries, your photos and videos, your comments, your likes, your follows, your memberships, your blocks, your notifications, your device tokens, and the reports you filed as well as those filed about your content. Your photos and videos are deleted from object storage, which keeps no prior versions. Your identity is then deleted at our authentication provider, which frees your email address for a fresh sign-up.
Deleting a single entry or nook works the same way: hidden at once, erased permanently 30 days later.
Messages you sent, and the username you sent them under, are kept. A message that reached someone is part of their conversation as much as yours, so it stays with them rather than being erased out from under them — in a nook’s group chat and in a one-to-one conversation alike. It is still shown as sent by your username, so the conversation remains readable; your name and your avatar are removed from it. To make that attribution honest we also keep the username itself, and never release it for anyone else to register: a username that could be re-registered would let someone else appear to have written the messages you left behind. Everything else on the account record is erased, and the username is not returned to you either — deleting the account severs the link between it and you, so signing up again gives you a new account and not your old username back. If you want a message gone, delete the message before you delete the account; that removes it for everyone. Your own side of every conversation — your inbox, what you had muted, pinned or read — is erased, as is any conversation in which you were the last remaining person.
A record of an age block outlives deletion. Where an age check resolved to under 13, we keep an account identifier, the date of the check, the age band, and a count of how many times the check was re-answered, so that the same identity cannot sign up again with a different answer. Everything identifying is erased the moment the block is applied: the name, username, avatar and Mural entered during sign-up are cleared from the record and the images are deleted from storage in the same operation. What is left holds no profile, no content and no contact details. The sign-in identity itself, including the email address, stays with the authentication provider, for the same reason.
Content you shared with other people may survive your deletion of your own copy: a nook that someone else created does not disappear because you left it, and someone who forked your entry keeps their fork.
Managing your information
Inside the app you can, at any time:
- edit your username, name, avatar and Mural, or remove any of them;
- switch your profile between public and private, and choose who may open a conversation with you — anyone, only people you follow, or only mutual friends;
- change the visibility of any nook or entry, up or down the ladder described above;
- leave a nook, remove a member from a nook you administer, mute or pin a conversation, and decline or accept a message request;
- block and unblock accounts, and see the list of accounts you have blocked;
- delete individual entries, nooks, comments, messages and photos;
- turn analytics and session recordings off in Settings, or on the website through “Cookie settings” in the footer;
- turn notifications off in your device settings, and revoke camera, photo and microphone access there;
- delete your account.
Transferring information outside the EEA
Photos and videos are stored in the European Union, in Frankfurt. Product analytics, error reports and session recordings are processed on European Union infrastructure.
Several of the providers listed above are established in the United States, so using Albi involves transferring personal data outside the European Economic Area and the United Kingdom. Where that happens we rely on:
- the European Commission’s Standard Contractual Clauses under Article 46(2)(c), together with the supplementary measures we assessed as necessary; or
- an adequacy decision under Article 45 — including the EU–US Data Privacy Framework — where the provider is certified under one.
A copy of the safeguards relied on for any specific transfer is available on request — write to chiteki.albi@gmail.com.
Security
All traffic between the app and our backend is encrypted in transit, and all data is encrypted at rest. Photos and videos sit in a private bucket that cannot be listed publicly and has no public access of any kind; the app obtains a separate signed link for each read, valid for six hours, and each upload link is valid for five minutes.
Your session token is held in your device’s secure store. Every server request is authorised against your identity and against the visibility rules described above, so a modified app cannot reach content it should not see.
No system is perfectly secure. Where a breach affects your personal data and is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and, where the risk is high, we will notify you directly.
Children
Albi is not for children under 13. Every account passes an age check before it can be used, and an account that resolves to under 13 is blocked outright rather than put into a restricted mode.
When an account is blocked this way, the name, username, avatar and Mural entered during sign-up are erased immediately and the images are deleted from storage. What remains is the minimal record described under “Deleting your information”.
If you believe a child under 13 holds an account, write to chiteki.albi@gmail.com and we will remove it.
We store an age band for every account, including 13–15 and 16–17. The band is used for two purposes only: enforcing the minimum age, and deciding who is asked to consent to analytics — an account in the 13–15 band is never asked, and never has product analytics or session recordings collected. Nothing else about the app differs by band. If we ever use the band for anything further — a different default feed, limits on who can reach a younger user — we will say so here first.
If you are in the United States
In the twelve months before the date of this Policy, we collected these categories of personal information:
- identifiers — email address, username, name, account identifiers, push tokens;
- internet or other electronic network activity — screen views, taps, feature events, error reports, masked session recordings;
- audio, electronic or visual information — the photos and videos you upload, and the messages and comments you write;
- commercial information — your storage consumption, and any request for more;
- age — an age band only, never a date of birth.
We collect no geolocation data. The purposes for each category, and the recipients of each, are in the sections above.
Sign-in credentials are sensitive personal information under the CPRA. They are held by our authentication provider and are used only to authenticate you. We do not use sensitive personal information to infer characteristics about you, and so we offer no separate right to limit its use.
You have the right to know what is collected, used and disclosed; to have it deleted; to have it corrected; to opt out of the sale or sharing of personal information; and to limit the use of sensitive personal information. We do not sell or share personal information as the CCPA/CPRA define those terms, and we do not process it for cross-context behavioural advertising. Exercising any of these rights will never get you a worse service.
To make a request, or to appeal a refusal, write to chiteki.albi@gmail.com.
Updating this Policy
We will update this Policy whenever what we do with personal data changes. The effective date at the top always reflects the version in force.
Where a change is material, we will give notice inside the app before it takes effect, and — where the change requires it — ask you to accept the new version. Your acceptance is recorded against the revision that was in force at the time.
Contact
Write to chiteki.albi@gmail.com for any privacy question or request, including access, correction, erasure, portability, an objection, or a copy of a transfer safeguard. It reaches the controller directly:
Jorge Gonzalez Cardelus
chiteki.albi@gmail.com