Last updated: 6 September 2026 · Version 1.3 · The German version is authoritative.
1020.dev e.U., Lichtenauergasse 4/8, 1020 Vienna, Austria, email: hallo@1020.dev. We are not required to appoint a data protection officer. Legal notice.
Spin is a social music app: you share one song per day, follow friends and see their posts. We only process the data needed for this. We do not sell data, run no advertising tracking and show no ads. To improve the app we evaluate usage events and crash reports — details in section 5b.
We collect no location data and no advertising IDs. Your address book leaves your device only as checksums and is not stored (section 5a).
We use service providers that process data on our behalf. A data processing agreement under Art. 28 GDPR is in place with every provider that stores personal data for us.
| Service | Purpose | Where | Third-country transfer |
|---|---|---|---|
| Supabase (Supabase Inc.) | Backend, login, database, file storage, server logs | Frankfurt, EU | US-based provider; data stays in Frankfurt. Support access covered by EU standard contractual clauses. |
| Apple (APNs, App Store) | App delivery, delivery of push notifications and Live Activities | USA | EU-US Data Privacy Framework (Apple is certified). Apple receives the push token and the notification text. |
| Resend (Resend Inc.) | Sending our emails: registration confirmation, password reset, moderation notices | USA | EU standard contractual clauses. Resend receives your email address and the message text. |
| PostHog (PostHog Inc.) | Product analytics (section 5b) | EU cloud (Frankfurt) | US-based provider; data stays in the EU. EU standard contractual clauses. |
| Sentry (Functional Software Inc.) | Crash reports (section 5b) | EU region (Germany) | US-based provider; data stays in the EU. EU-US Data Privacy Framework. |
| Spotify | Spin retrieves track metadata and cover art server-side via the Spotify Web API; the access key stays on our server | Sweden / worldwide | No personal data is transmitted — only search terms and track IDs without user reference. When you tap a song you open the Spotify app; from then on their privacy policy applies. |
| Vercel (Vercel Inc.) | Hosting of spin.1020.dev, the share previews and the web forms | worldwide (edge) | EU-US Data Privacy Framework. Vercel sees IP address and browser data of page views. |
| Cloudflare (Turnstile) | Bot protection on the web forms (feedback, notices) | worldwide | EU-US Data Privacy Framework. Cloudflare receives your IP address and browser data for the bot check. |
We pass data to other recipients only where legally obliged (e.g. authorities or courts, Art. 18 DSA) or where you expressly request it.
If you choose "Search contacts" during onboarding, we ask for access to your contacts. We read only the email addresses; they are turned into checksums on your device using SHA-256, and we send only these checksums to our matching function, which compares them against the checksums of registered users. We store neither your contacts nor the checksums — the matching happens in memory and is discarded immediately. People in your address book who do not use Spin are neither stored nor contacted. We no longer read your contacts' phone numbers.
We have deleted all phone numbers. Until 6 September 2026 a phone number had to be given at registration; it served contact matching only and was never visible to other users. On 6 September 2026 we removed that feature and deleted the entire stock — the plain text as well as the checksums derived from it and the table they lived in. We no longer ask for numbers, neither at registration nor in the profile, and we no longer store any. You need do nothing; withdrawing what you gave back then is moot.
Why we deleted them: the numbers were never verified by SMS, and a checksum over a phone number barely protects it — a country's number space is small enough to be computed through. For a feature that serves the same purpose via email addresses, that was no longer proportionate processing (Art. 5(1)(c) and (e) GDPR).
Legal basis for contact matching: access to your address book (voluntary) — your consent (Art. 6(1)(a) GDPR), granted via the permission dialog and revocable at any time in iOS Settings. Processing of the previously stored phone numbers up to their deletion remains lawful; as long as the field was mandatory at registration it rested on performance of the user agreement (Art. 6(1)(b) GDPR).
To see which features are used and where the app fails, we use two services. Both process data in the EU.
PostHog (product analytics), EU cloud. Spin reports individual events — for example "onboarding completed", "song posted", "song shared" or "streaming link opened". Only the details belonging to the respective event are sent along (for example the ISRC of the posted song, the source of a share, or whether the post fell within the posting window), a timestamp and an identifier. That identifier starts out as a random string generated on your device; once you are signed in, we link it to your user ID. The analytics data is therefore pseudonymous, not anonymous. When you sign out, a new random identifier begins. We embed no SDK but send the events directly via HTTPS. Your IP address necessarily reaches the server in the process, but PostHog discards it immediately, does not store it and derives no location from it (project setting “discard client IP data”, the default on the EU cloud). We keep event data for 12 months.
Sentry (crash reports), EU region. If the app crashes, we transmit a technical error report: the crash stack trace, device model, iOS version and app version. No user reference is set, and the transmission of default personal data is disabled — in particular no IP address is transmitted. No performance tracing takes place. We keep crash reports for 90 days.
Both serve solely the stability and improvement of Spin. We do not run advertising tracking, use no advertising identifiers, and do not pass this data to third parties for advertising purposes. The app is declared accordingly in the App Store.
Legal basis: our legitimate interest in a stable and comprehensible app (Art. 6(1)(f) GDPR). You can switch analytics off yourself at any time: Profile → Settings → Privacy → “Usage analytics”. With the switch off, no event leaves your device and the link to your user ID is dropped on the device. An email to hallo@1020.dev also works.
Spin stores content you share and is therefore a hosting service under Regulation (EU) 2022/2065 (DSA). For this we process:
We do not disclose a notifier's name or email address to the person concerned. Legal bases: legal obligation (Art. 6(1)(c) GDPR in conjunction with Art. 16 and 17 DSA) and legitimate interest in a safe app (Art. 6(1)(f) GDPR). Retention: section 6.
If you share a post or your profile via "Share", Spin creates a link (spin.1020.dev/s/… or /u/…). Anyone with this link sees a preview without logging in: for a post the title, artist, cover, caption, date, your username, display name and profile picture, plus the number of likes and comments; for the profile card your username, display name and profile picture. Share links do not expire; they disappear when you withdraw or delete the post or delete your account. The profile card at /u/your-username is available to anyone who knows your username — regardless of whether your profile is private. Your profile picture is stored at an unguessable address but is available to anyone who knows that address. Legal basis: performance of the user agreement (Art. 6(1)(b) GDPR) — you trigger the sharing yourself.
We feature selected posts as "Song of the day" on Spin's official Instagram channel. Published are the song's title and artist, your username and, where present, your caption — no profile picture, no further data. Instagram is operated by Meta Platforms Ireland Ltd.; data may reach the USA in the process (Meta is certified under the EU-US Data Privacy Framework). From publication, Meta's privacy policy applies to the post there, and other Instagram users can see and share it. Legal basis: our legitimate interest in promoting Spin and our users' music (Art. 6(1)(f) GDPR), in conjunction with section 5 of the terms of use. You can object at any time — in advance or afterwards — by emailing hallo@1020.dev; we then remove the post from our channel. We have no control over copies that other Instagram users have already shared.
We store your data as long as your account exists. You can delete your account at any time in the app (Profile → Settings → Delete account). This removes login, profile, profile picture, posts, comments, likes, reactions, saved songs, follows, blocks, push and Live Activity tokens, your feedback and your consent logs. Specifically:
Statutory retention obligations remain unaffected.
You have the right of access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), and the right to withdraw consent at any time with effect for the future (Art. 7(3) GDPR).
For all requests: hallo@1020.dev. We reply within one month.
Right to complain: you can complain to a data protection supervisory authority, in Austria the Austrian Data Protection Authority (Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, dsb@dsb.gv.at, www.dsb.gv.at — or to the authority of your place of residence.
Spin is not directed at children under 16. By registering you confirm you are at least 16; we do not perform age verification. We do not knowingly collect data from children under 16. If we learn of it, we delete the account. Parents and guardians can reach us at hallo@1020.dev.
All connections are TLS-encrypted. Passwords are stored only as hashes. Access to other users' data is restricted in the database itself (row-level security), not only in the app. Access keys to third-party services are kept exclusively on the server.
We update this policy as needed, for example for new features or changes in the law. The current version is available in the app (Settings → Privacy) and at spin.1020.dev/privacy. We inform you in the app about material changes.