Your data
Privacy policy
pvlsr ties photographs to places and places to people. That is a sensitive combination, and this page describes exactly what the system does — not what a template policy would claim it does.
A technical description awaiting legal review — against the GDPR and the local data protection law that applies — before the service opens to the public.
The short version
Places, never a trail
Your position is compared against venue footprints on your own device. What is kept is the event — arrived, left — not the path between them.
Nothing is sold
No data brokers, no advertisers, no audience segments. The suppliers behind the service each receive only what their one task needs.
You choose the audience
Every photograph carries a visibility set at the moment of capture, and one database function decides every read against it.
You can take it and go
Export your whole record and delete your account from inside the app, without writing to anybody.
Who this covers
In short The pvlsr app, this website, and the moderation work behind both.
pvlsr is the publisher of the app and of this site, and decides what is collected and why. This page applies to everybody who uses the service — from the first screen, before an account exists — and to the people whose photographs or places appear on it. Where a venue appears here as a business rather than as a person, this page still governs the people who go there.
Written to be read against the GDPR, and against whatever data protection law applies where you are — whichever of the two gives you the stronger right.
What we collect
In short An identifier, an age check, what you capture and write, and the technical minimum to deliver it.
Nothing here is collected speculatively. Each of these exists because a specific screen cannot work without it.
- Phone number
- Your account identifier and the only way to sign in. Verified once by a code sent over SMS.
- First name, date of birth
- Asked once at sign-up. The date of birth confirms you are 18 or over; it is not shown on your profile.
- Photographs
- What you capture in the app, with the place the capture was verified at and the visibility you chose for it.
- What you write
- Posts, replies, messages, and reports you send to moderation.
- Who you are connected to
- Your friends, the Circles you belong to, and the tables you have joined.
- Technical signals
- Device model and operating system version, notification token, app version, crash and error logs. Enough to deliver a push and to find out why a screen broke.
Location, and why it is not tracked
In short The app tests where you are; the service only learns that you arrived somewhere and left.
pvlsr never broadcasts your position and keeps no live friend map. The app compares your position against venue footprints to decide whether the camera may arm; that is a local test whose result is an event — entered this footprint, left it — and the event is what is kept, not a trail. The GPS trace attached to a capture exists to reach a verification verdict and is discarded afterwards: what remains is the place, not the path that led there.
Location permission can be withdrawn at any time in your phone's settings. The app keeps working; the camera simply stops arming, because there is no longer anything to verify against.
Who sees your photographs
In short One function decides every read, and a photograph of people is never public.
Every photograph carries a visibility you choose at capture time. A single database function decides, for each reader-and-photograph pair, whether it may be served — there is no second read path that could forget. A public photograph must additionally have passed the automatic safety screen, and until that screen has answered it stays private. A photograph categorised as being of people is never public, whatever visibility was chosen.
- Public — anyone in the region can see it, once the safety screen has cleared it.
- Circle — the people who actually go to that place.
- Table — the people sitting with you, and nobody else.
Notifications, and two families of consent
In short Consequences are on by default; disclosures are off until you turn them on.
Notifications that follow from your own actions — a message, a reply, an invitation — are on by default and can be switched off one at a time. Those that reveal a detected place, meaning co-presence alerts, are off by default and are only ever switched on deliberately. The difference is intentional: the first family announces a consequence, the second is a disclosure.
What we share
In short Suppliers who run the service, and lawful requests that are actually valid. Nothing else.
Nothing goes to data brokers, and nothing goes to advertisers. We use suppliers to run the service, each bound to use what it receives only to perform its task:
- Hosting and database
- Runs the API and stores the record. Sees what the service stores, because it is where the service stores it.
- Image storage and delivery
- Holds and resizes photographs, and serves them to the readers allowed to see them.
- SMS delivery
- Receives your phone number and a one-time code, so you can sign in. Nothing else.
- Push delivery
- Receives a device token and the notification's text, in order to hand it to your phone.
- Mapping
- Serves the basemap the map is drawn on, and therefore sees which part of the map is being looked at.
We answer requests from authorities when they are valid and properly served, and not otherwise.
How it is protected
In short Encrypted in transit, access decided per read, and moderation limited by region.
Traffic between your phone and the service is encrypted in transit. Sign-in is a one-time code rather than a password you might reuse elsewhere. Read access to any photograph is decided by the same single function every time it is served, so a mistake in one screen cannot become a leak in another. Moderators can only act inside the region they were scoped to, and every decision they take is recorded against their name.
No system is beyond breach. If one happens and it puts you at risk, you will be told what happened and what to do about it — not after an internal decision about how it looks.
This website
In short One cookie, and only if you sign in here. No analytics, no advertising, no third-party trackers.
Reading this site sets nothing. Signing in to the web view sets exactly one cookie, and it exists to keep you signed in.
- pvlse_session
- Set only after a successful sign-in. Not readable by page scripts, sent only to this site, and it expires after 30 days. Signing out deletes it.
- Analytics
- None. There is no measurement script on this site, from us or from anybody else.
- Map tiles
- The map on this site is drawn with tiles fetched from our mapping supplier, which therefore sees your browser's request for them.
Your rights
In short Two of them are buttons in the app. The rest are one email away.
You do not have to ask us for the two that matter most — they are in the app, under Profile, then Privacy.
- Export — take your whole record with you, from inside the app.
- Delete — close your account from inside the app. Your content goes; what must be kept for the integrity of the moderation ledgers is anonymised.
- Access — ask what is held about you, and get a copy.
- Correction — have something inaccurate fixed.
- Restriction and objection — ask us to stop a particular use while a dispute is open.
- Complaint — take it to the data protection authority where you live, at any point.
Written requests are answered within 30 days. We may need to confirm the request comes from the account holder before acting on it, because the alternative is handing somebody's record to whoever asks for it.
How long
In short As long as the thing it belongs to exists, and no longer — with one deliberate exception.
Nothing is kept because it might be useful one day.
- Your account and its content
- For as long as the account exists. Deleting the account removes it.
- A capture's GPS trace
- For as long as the verdict takes. Discarded once the capture is verified or refused.
- Technical logs
- A few weeks, then they roll off.
- Moderation decisions and appeals
- Kept longer, and this is the exception. They are the record that a penalty was issued, notified and contested — a record that vanishes with the account is no record at all.
Under-18s
In short The service is 18 and over, and an account found to be a minor's is closed.
pvlsr is not for anyone under 18. Age is asked at sign-up, and an account identified as a minor's is closed and its content removed. If you believe a minor holds an account, write to the safety address on the contact page and it will be handled first.
When this page changes
In short The date at the top moves, and anything material is announced in the app before it takes effect.
This page will change as the product does — that is what it means for it to describe the real system rather than a template. Small corrections move the date at the top. A change that alters what is collected, who it is shared with, or how long it is kept is announced in the app before it takes effect, so that leaving is a real option rather than a discovery made afterwards.
Reaching us
In short One address for data questions, answered by a person within 30 days.
For any question about this page or about your data, write to the personal data address on the contact page. If the answer does not satisfy you, you can take the matter to the data protection authority where you live.
Still have a question?
A person reads what comes in. Questions about your data are answered within 30 days; everything else is usually a good deal faster.
Write to us