Pinlo Privacy Policy
Last updated: June 21, 2026
Pinlo (operated by Koncrate, "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the Pinlo mobile application on iOS and Android (the "Service").
By using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please do not use the Service.
1. Who we are
- Service name: Pinlo
- Contact email: aperio@koncrate.com
- Eligible users: Individuals aged 13 or older (or the minimum age required in your jurisdiction, if higher)
2. Information we collect
2.1 Information you provide
| Category | Examples | Purpose |
|---|---|---|
| Account data | Identifiers from Google or Apple sign-in (such as email and OAuth IDs), username, display name, profile photo | Create and manage your account, authenticate you |
| Date of birth | Collected once during account setup | Age verification to confirm you meet the minimum age requirement (13+); stored in your account metadata on Supabase and retained for the lifetime of your account |
| Profile data | Public or private account settings, bio, and other optional profile fields | Profile pages and social features |
| Trip content | Trip titles, date ranges, cover and representative photos, photo notes, pin colors, visibility settings | Build travel records, map display, cloud sync |
| Location data | GPS coordinates from the EXIF metadata of photos you explicitly select | Show pins and routes on your trip map; stored on our servers linked to your account |
| Direct messages | Text content of messages you send or receive through in-app DMs | Deliver messages to recipients and maintain conversation history; stored on our servers and accessible only to the sender and recipient |
| Social activity | Follow relationships, comments, likes, reports and report reasons | Explore, interaction, and safety |
| Support and reports | Details you provide when contacting us or submitting a report | Respond to requests, handle violations |
Important: Pinlo only uploads photos you explicitly select (up to 1 cover plus 9 representative photos per trip). Photos in the same date range that you do not select are not uploaded to our servers.
2.2 Device permissions and automatically collected data
With your permission, we may access:
- Photo library: Read photos and metadata (including capture time and location) within the date range you choose, so you can pick representative images. We do not request photo library access on cold start; we ask only when you use "Load photos" or similar actions.
- Location — photo GPS: GPS coordinates embedded in the EXIF metadata of photos you select are uploaded to our servers and stored to display pins and routes on your trip map.
- Location — device GPS: Your device's current location may be accessed to center the map view when you open the app. This location is not transmitted to our servers or stored anywhere; it is used only on-device for the initial map position.
- Push notifications (if you opt in): Account and interaction-related notifications. When you grant permission, we store an Expo push token linked to your account in our database (`device_push_tokens`) to route notifications to your device. You can revoke this at any time in device settings.
We may also automatically collect:
- Device type, operating system version, app version, and language settings
- Usage data (such as feature usage and error logs)
- Account-linked user identifiers after sign-in (for sync and diagnostics)
2.3 Analytics and crash reporting
We use Firebase Analytics to understand how features are used and Firebase Crashlytics to collect crash and error reports to improve stability.
- Analytics data consists of functional usage events (such as feature taps and upload errors), along with app version, platform, and your account identifier (a randomly generated UUID).
- We do not send your name, email address, trip titles, or any trip content to Firebase Analytics.
- Crash reports include the app version, device platform, build profile, and your account identifier to help us reproduce and fix issues.
2.4 Advertising (if enabled)
The Service may display ads through Google AdMob. When ads are enabled:
- iOS: We present the App Tracking Transparency (ATT) prompt before showing personalized ads. Personalized ads are only served if you explicitly grant tracking permission. The relevant identifier is the Advertising Identifier (IDFA).
- Android: Google AdMob may use the Android Advertising ID (GAID) to serve and measure ads.
- In both cases, AdMob and its partners may also collect your IP address and ad interaction data (impressions, clicks, conversions) under Google's Privacy Policy.
- Pinlo itself does not receive or store your advertising identifier; it is used solely by the AdMob SDK and Google's ad network.
To limit personalized advertising:
- iOS: Go to Settings → Privacy & Security → Tracking and disable tracking for Pinlo.
- Android: Go to Settings → Google → Ads and enable "Opt out of Ads Personalization," or reset your Advertising ID.
3. How we use your information
We use the information above to:
- Provide, operate, and improve the Service (maps, trip records, cloud sync, share cards, and related features)
- Enable social features (Explore, follows, comments, direct messages, visibility controls)
- Verify identity, confirm minimum age, prevent abuse, and enforce rate limits
- Handle reports, blocks, and account security
- Analyze usage, fix bugs, and improve performance
- Comply with legal obligations and protect our rights
- Contact you for support or important service notices
We do not sell your personal information.
4. Sharing and third parties
We may share necessary information with:
| Third party | Purpose |
|---|---|
| Supabase | Authentication, database, cloud storage (trip photos, avatars, share cards, push tokens) |
| Google (sign-in, Maps, Firebase Analytics, Firebase Crashlytics, AdMob) | Authentication, map display, analytics, crash reporting, advertising |
| Apple (Sign in with Apple) | iOS authentication |
| Cloudflare (where applicable) | File storage (R2) and delivery |
Each third party has its own privacy policy. We encourage you to review them separately.
Other users: If your account is public, or a trip is set to "public" or "followers only," other Pinlo users may see your profile, trips, and representative photos according to your visibility settings. You can set your account to private or mark individual trips as "only me."
Legal requirements: We may disclose information when required by law, court order, or a lawful request from public authorities.
5. Data retention
- We retain your data while your account is active to provide the Service.
- Account deletion: When you delete your account (in App Settings → Delete Account), we permanently delete your profile, trips, photos, direct messages, and push notification tokens. This action is irreversible. Aggregate and anonymized entries in analytics systems (Firebase) may persist for up to 90 days before expiring naturally. Backup copies are purged on a rolling basis within 30 days.
- Your date of birth is stored for the lifetime of your account and deleted together with your account data upon deletion.
- We may retain records required by law (such as report handling records) for as long as legally required.
6. Your rights and choices
Depending on your location, you may have the right to:
- Access and correct your personal information (editable in-app on your profile and trips)
- Delete your account in App Settings; we will permanently delete your profile, trips, cloud photos, direct messages, and push tokens
- Control visibility at the account level (public/private) and trip level (public, followers, or only me)
- Block users so you cannot see each other
- Revoke permissions for photos, location, or push notifications in device settings (some features may stop working)
- Limit ad tracking in iOS or Android system settings (see Section 2.4)
- Request data export or erasure by emailing us at aperio@koncrate.com
For help exercising these rights, email aperio@koncrate.com.
7. Children's privacy
The Service is not directed to children under 13. You must confirm you are at least 13 by providing your date of birth during account setup. If we learn that an underage user has created an account, we will delete it. If you are a parent or guardian and believe your child has provided personal information, please contact us.
8. Security
We use reasonable technical and organizational measures to protect your data, including encryption in transit (HTTPS/TLS) and access controls on our database and storage systems. However, no method of transmission over the Internet is completely secure. Please keep your sign-in methods secure.
9. International transfers
Your data may be processed and stored on servers outside your country or region (for example, data centers operated by Supabase, Google, or Cloudflare). By using the Service, you consent to such cross-border transfers.
10. Changes to this policy
We may update this Privacy Policy from time to time. For material changes, we will notify you in the app or on this page and update the "Last updated" date. Continued use after changes means you accept the revised policy.
11. Contact us
Questions about this Privacy Policy:
Pinlo