Effective 9 August 2026
Privacy Policy
Who we are
The social network for doers. Albi is an app to discover new plans and new friends, share your own, and save the memories.
The data controller for Albi is Jorge Gonzalez Cardelus. Under the privacy laws of the United States, the same person is the “business”. Albi is not required to appoint a Data Protection Officer and has not appointed one; privacy requests are handled by the controller directly.
This policy applies to the Albi mobile application and to this website. For any privacy question or request, write to chiteki.albi@gmail.com.
What we collect
Albi collects only what is required to operate the service and to improve it. We do not purchase personal data, we do not obtain it from data brokers, and we do not operate or serve advertising.
Data you provide
- Account and sign-in
- Your email address and an account identifier. Where you sign in with Apple or Google, we receive the identifier and email address that provider releases to us. Passwords are set and verified by our authentication provider; Albi does not receive or store them.
- Profile
- Your handle, the first and last name you enter, your avatar image, your profile backdrop (“Mural”), and your profile and message privacy settings. We also store a lowercased copy of your name and handle, which is what allows other people to find you through search.
- Content you create
- Nooks, including their names, colours and visibility; the entries you add to them, including titles, descriptions, dates and place names; and your comments, direct messages, likes, and the entries you have marked as done. Place names are text you type. The application does not request access to your device location and does not record where you are.
- Photos and videos
- The media you upload, together with the reduced-size copies we generate so that images load quickly, and a running total of the bytes you are storing, which is used to enforce a per-account storage quota. Images are re-encoded on upload, which removes the metadata a camera embeds in a file — including the GPS coordinates of the location at which a photograph was taken.
Data generated by your use of the service
- Your connections
- The accounts you follow and those that follow you, pending follow requests, the nooks and conversations you belong to, and any accounts you have blocked.
- Activity within the app
- Which conversations you have read and when, your unread counts, photographs you have marked as favourites, conversations you have muted or pinned, the backdrop you have chosen for a conversation, your in-app notification history, and any request you submit for additional storage.
- Devices and notifications
- A push notification token for each device on which you sign in, the platform of that device (iOS or Android), and the date on which it was last seen.
- Safety, moderation and account status
- Reports you submit and reports submitted about your content, together with the outcome of any moderator action; whether your account is suspended and the reason recorded for it; and the number of times an age check has been re-answered on your account.
- Age assurance
- An age band (under 13, 13–15, 16–17, or 18 and over); the source of the check (Apple’s Declared Age Range, Google’s Play Age Signals, or your own answer where neither platform can respond); the age range the platform returned; on iOS, whether the range was declared by you, declared by a guardian, or confirmed by Apple; on Android, the account status Google reports; the platform; and the date of the check. Your date of birth is not stored, even where you enter one — only the band derived from it. The age range and account status originate from Apple and Google rather than from you.
Data collected automatically
- Product analytics and error reports
- Screen views, taps, feature events (for example, that a nook was created), crash and error reports, and general device and application version information. These events are associated with your account identifier and your handle, so that a single session can be reconstructed. They do not carry the text of your messages or your photographs.
- Session recordings
- The application records a masked replay of your sessions so that we can identify where it fails. Masking is applied on your device before any recording is transmitted: text you type, images, and embedded content are obscured. A recording therefore shows the layout of a screen and where it was touched, and not the content you were reading, writing or viewing.
Providing an email address, a handle and an age band is necessary to create an account, and we cannot provide the service without them. Everything else — a profile picture, a Mural, a place name, the content you add — is optional, and declining to provide it affects only the features that depend on it.
This website sets no cookies and runs no analytics, trackers or logins. As with any website, our hosting provider records standard server logs, which include IP addresses.
Why we use it, and our legal basis
Under the General Data Protection Regulation we must identify a lawful basis for each purpose for which we process personal data. Ours are set out below.
- To provide the service — performance of a contract
- Creating and maintaining your account, displaying your nooks and their contents, delivering comments and messages, storing your photographs, and applying the visibility settings you have chosen. Article 6(1)(b).
- To keep Albi safe — legitimate interests, and legal obligation
- Preventing and investigating abuse, handling reports, suspending accounts that breach our terms, and enforcing the minimum age. Our legitimate interest is in maintaining a service that is safe to use and in protecting our users from harm; we consider this interest not to be overridden by your rights, because the processing is limited to what an abuse report or an age check requires. Article 6(1)(f). Operating an age check also discharges obligations imposed on us by the application stores through which Albi is distributed. Article 6(1)(c).
- To improve the service — legitimate interests
- Understanding which features are used, and identifying where and why the application fails, through product analytics, error reports and masked session recordings. Our legitimate interest is in diagnosing defects and in directing development effort at the parts of the service people actually use; the processing is limited by the masking described above and by the fact that message content and photographs are never transmitted. Article 6(1)(f). You have the right to object to this processing at any time — see “Your rights”.
- To send push notifications — consent
- Notifications are sent only to devices on which you have granted the operating system permission to receive them, and you may withdraw that permission at any time in your device settings. Article 6(1)(a).
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or that similarly significantly affects you. The Explore feed orders content algorithmically, but that ordering is not a decision of the kind Article 22 governs.
Who can see your content
Most of what Albi stores is content you have deliberately shared with other people. Who can see it is determined by the settings you choose:
- Friends — visible only to the friends you added to a nook.
- Network — visible to your friends’ followers.
- World — visible to anyone on Albi.
An entry within a nook may be more private than the nook that contains it, but never more public; this limit is enforced on our servers and cannot be overridden. New profiles are private by default, which means that follow requests require your approval and that people who do not follow you see only your handle, and not your name.
You may block any account. Blocking operates in one direction and is not disclosed: a blocked person continues to see an ordinary conversation, but nothing they send is delivered to you.
Who we share it with
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
The following providers process personal data on our behalf and on our instructions, under written terms that require them to do so:
- WorkOS
- Authentication and identity — email addresses, sign-in credentials and sessions.
- Convex
- Application database and backend — profiles, nooks, entries, comments, messages and the social graph.
- Amazon Web Services (S3)
- Storage for photographs and videos, in the eu-central-1 (Frankfurt) region. Objects are private and cannot be listed publicly; the application reads each one through a signed link that expires after six hours.
- PostHog
- Product analytics, error tracking and session recordings, on European Union infrastructure.
- Expo
- Delivery of push notifications and of over-the-air application updates.
The following companies determine their own purposes for the data they handle and act as independent controllers rather than on our instructions. Their own privacy policies govern that processing:
- Apple and Google
- Distribution of the application; the age-range signal relied upon by the age check; and the notification services through which push messages reach your device. A push notification carries the name or handle of the person who triggered it, the name of the relevant nook or entry, and a small image. It never carries the text of a message.
We will also disclose personal data where we are legally required to do so, or where disclosure is necessary to investigate abuse or to protect the safety of any person.
International transfers
Photographs and videos are stored in the European Union, and product analytics and session recordings are processed on European Union infrastructure. Several of the providers named above are established in the United States, and using Albi therefore involves transferring personal data outside the European Economic Area and the United Kingdom.
Where such a transfer occurs we rely on the European Commission’s Standard Contractual Clauses, or on an adequacy decision — such as the EU–US Data Privacy Framework — where the provider is certified under one.
How long we keep it
Your account and its contents are retained for as long as your account exists. When you delete your account — see how to delete your account for the steps:
- it is hidden from everyone immediately, and you are signed out;
- you have 30 days in which to change your mind, and signing back in during that period restores everything;
- after 30 days your profile, entries, nooks, photographs, videos, comments and messages are erased permanently, including the comments and messages you sent to other people, and the reports you filed and those filed about your content. Your identity is then deleted at our authentication provider.
Deleting an individual entry or nook works the same way: it is removed from view immediately and erased permanently 30 days later.
One record outlives the deletion of an account. Where an age check has resolved to under 13, we retain an account identifier, the date of the check and the age band, so that the same identity cannot simply register again. The name, handle, avatar and Mural on such an account are erased at the moment the block is applied, and the retained record contains no profile, content or contact details. The sign-in identity itself, including the email address, remains with our authentication provider, because releasing it would allow the account to be recreated immediately.
Reports and moderation records relating to accounts that still exist are retained for as long as they are needed as an audit trail of decisions taken. Product analytics events and session recordings are retained for no longer than twelve months.
How we protect it
All traffic between the application and our backend is encrypted in transit, and all data is encrypted at rest. Photographs and videos are held in a private bucket that cannot be listed publicly; the application obtains a separate signed link, valid for six hours, for each read or write.
Every request the application makes is authorised on our servers against your identity and against the visibility rules described above. The application is never trusted to enforce those rules on its own, so a modified client cannot reach content it should not see.
No system is perfectly secure. Where a breach affects your personal data and is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and, where the risk is high, we will notify you directly.
Your rights
If you are in the EEA, the UK or Switzerland
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to how we process it, including a general right to object to processing carried out on the basis of legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting the lawfulness of processing already carried out;
- lodge a complaint with your local supervisory authority — in Spain, the Agencia Española de Protección de Datos (aepd.es).
If you are in California or another US state with a privacy law
In the twelve months preceding the date of this policy we have collected the following categories of personal information: identifiers (your email address, handle, name and account identifiers); internet or other electronic network activity (screen views, taps, feature events, error reports and session recordings); audio, electronic or visual information (the photographs and videos you upload); and commercial information limited to your storage consumption. We collect no geolocation data. The purposes for which each category is used, and the recipients of each, are described in the sections above.
Sign-in credentials are treated as sensitive personal information under the CPRA. They are held by our authentication provider and are used solely to authenticate you. We do not use sensitive personal information to infer characteristics about you, and we therefore do not offer a separate right to limit its use.
You have the right to know what personal information is collected, used and disclosed; to request its deletion; to request its correction; to opt out of the sale or sharing of personal information; and to limit the use of sensitive personal information. We do not sell or share personal information as those terms are defined by the CCPA/CPRA. Exercising any of these rights will never result in a reduced level of service.
How to exercise your rights
You may edit or delete your profile, your content and your entire account from within the application at any time. For anything else — a copy of your data, a correction you cannot make yourself, or a question about this policy — write to chiteki.albi@gmail.com. We will respond within one month, and will tell you if we need longer.
If we decline your request, we will tell you why. You may appeal that decision by replying to our response, and we will review the appeal and give you a written outcome within a further month. Nothing in this appeal process limits your right to complain to a supervisory authority or to your state’s Attorney General.
Children
Albi is not intended for children under 13. Every account passes an age check before it can be used, and an account that resolves to under 13 is blocked outright rather than placed in a restricted mode.
When an account is blocked in this way, the name, handle, avatar and Mural entered during sign-up are erased immediately, and the images are deleted from our storage. What remains is the minimal record described under “How long we keep it”.
If you believe that a child under 13 holds an account, write to chiteki.albi@gmail.com and we will remove it.
Changes to this policy
We will update this page whenever what we do with personal data changes. The effective date at the top of this page always reflects the current version, and we will give notice within the application before a material change takes effect.