Privacy Policy
Last updated: [date]
AtPlace — last updated: 8 September 2026
This policy explains what AtPlace collects, why, who sees it, and what you can do about it. It is written to match how the app actually works. Where something depends on a choice you make (for example, whether your account is private), we say so.
AtPlace is run by Stefan Stojanovic, Beograd, Serbia ("we"). You can reach us at atplaceapp@gmail.com.
1. What we collect
Account. Your email address, a nickname, and a password. We store the password only as a hash — we cannot read it. We also record whether your email has been confirmed, when you registered and when you last signed in.
Profile. Whatever you choose to add: a profile picture, a short bio, a location line, a website.
Places, photos and trips. Every place you add — its name, map coordinates, category, description, best time to visit, notes — and the photographs you upload to it (yours or somebody else's place). Trips: their name, story and the places they connect. Photographs may carry technical data (EXIF) from your camera; we do not use it, but the file is stored as uploaded unless the upload service strips it.
Activity. Places you like or save, people you follow or who follow you, follow requests, people you block or mute, photographs you report, and the places you have visited (kept as a count per country for your profile figures).
Messages. Direct messages you send and receive, with the time they were sent and read. Messages are stored in plain form on our servers and are not end-to-end encrypted; we can access them if a report or a legal request requires it.
Sessions and devices. For each signed-in session we keep an IP address, a description of the browser or device, and timestamps, so you can see and sign out of your devices and so we can detect stolen sessions.
Technical logs. Server logs with request timestamps, paths, response codes, an IP address, and a request identifier. Logs are used for security, abuse prevention and fixing faults. Secrets and passwords are never written to logs.
We do not collect precise device location. A place's coordinates are what you set on the map, not where your phone is.
2. What is public
AtPlace is a place to share where you have been. Please read this part carefully.
- New places and trips are public by default. You can make any place or trip private when you create it or afterwards. Private places are visible only to you.
- Public places are visible to everyone, including people without an account, and may be shown on the Explore map, in search, in feeds, and on your public profile at
/u/<nickname>. Public profiles and public places can be indexed by search engines. - Your live map (
/u/<nickname>/map) is a public page you can share by link. It shows your public places and trips and your figures (places, countries, years). It updates on its own as you add public places. It works for anyone with the link, without an account. - Photographs you add to somebody else's public place are public and remain attached to that place.
- A private account hides your profile content, places and live map from everyone except followers you approve. Your nickname and profile picture remain visible so people can find and follow you.
- Curated places (the catalogue we maintain) are public and are not tied to any user.
Blocking somebody removes any follow between you, stops messages, and hides your profile and places from them.
3. Why we use your data (legal bases)
| Purpose | Data | Basis |
|---|---|---|
| Running your account, showing your places, delivering messages and notifications | Account, profile, content, activity, messages | Performance of the contract with you |
| Keeping the service safe: sign-in security, rate limiting, abuse and spam prevention, screening uploaded images, handling reports | Sessions, logs, IP address, photographs, reports | Our legitimate interest in a safe service; in some cases a legal obligation |
| Sending you transactional email: email confirmation, password reset, a notice if somebody tries to register with your address | Email address | Contract and legitimate interest (security) |
| Fixing faults | Technical logs, error reports | Legitimate interest |
| Anything optional we may add later (for example marketing email) | — | Only with your consent, which you can withdraw at any time |
We do not sell your data, we do not show advertising, and we do not use third-party analytics or tracking cookies.
4. Automated image screening
Every uploaded photograph is screened automatically by an image-moderation service (see section 5) before it becomes visible, to keep illegal and explicit content off the map. A photograph that fails screening is refused and deleted; you are told it was refused, not why in detail. If you believe a photograph was refused in error, contact us and a person will look at it.
5. Who processes data on our behalf
We use a small number of service providers. They may only process data on our instructions.
| Provider | What for | Where |
|---|---|---|
| Cloudinary | Storing and delivering photographs (yours and profile pictures). Your browser may upload files directly to Cloudinary. | EU / USA |
| Sightengine | Automated screening of uploaded images | EU / USA |
| MongoDB Atlas | Database hosting | EU (Frankfurt) |
| Redis Cloud | Session limits and real-time messaging between servers | EU (Frankfurt) |
| Google (Gmail SMTP) | Sending transactional email | EU (Frankfurt) |
| Sentry | Error reporting. Configured not to send personal data; error reports may still contain a request identifier. | USA |
| Render | Running the servers | EU (Frankfurt) |
Some of these providers are outside the European Economic Area and Serbia. Where data leaves those areas, we rely on the provider's standard contractual clauses or an equivalent safeguard.
Services your browser contacts directly. When you use the map, your browser requests map imagery from third parties, which therefore see your IP address and the area of the map you are viewing:
- OpenStreetMap (map tiles) — openstreetmap.org/privacy
- Esri (satellite imagery)
- CARTO (tiles on the live map, when enabled)
- Google Fonts (typefaces) and unpkg / Cloudflare (map library)
- Wikimedia Commons (photographs of curated places)
When you name a place, we send the name you typed to OpenStreetMap's Nominatim service to find its coordinates. Nothing about you is sent with it.
6. Cookies and local storage
We use only the cookies the service needs to work:
| Name | Purpose | Lifetime |
|---|---|---|
sg_at |
Keeps you signed in (access token) | 15 minutes, renewed automatically |
sg_rt |
Renews your sign-in (refresh token) | 30 days, or until you sign out |
sg_csrf |
Protects forms against cross-site request forgery | Session |
Your browser also keeps a copy of your own profile in local storage so the app opens faster, and remembers where you left the map. None of this is used for tracking or advertising, and no consent banner is required for it.
7. How long we keep data
- Your account and content: for as long as you have an account.
- Account deletion: when you ask us to delete your account you are signed out everywhere at once, and the account and its content — places, trips, photographs (removed from Cloudinary), likes, saves, follows, messages you sent — are erased after a grace period of 24 hours, during which you can sign in to cancel. Photographs you added to other people's places are removed as well; the place itself stays, and its cover passes to another photograph if yours was the cover.
- Messages you delete are removed from your view immediately and from our servers once both sides have deleted them or the conversation is gone.
- Sessions: 30 days from last use, or immediately when you sign out.
- Server logs: [30] days.
- Backups: [X] days; deleted data disappears from backups on that cycle.
- Reports: kept 12 months after resolution so we can recognise repeat abuse.
8. Your rights
Under the Serbian Law on Personal Data Protection and, for people in the EEA/UK, the GDPR, you can:
- see the data we hold about you and get a copy;
- correct it — most of it you can edit yourself in Settings;
- delete it — you can delete individual places, photographs, trips and messages yourself, and delete your whole account from Settings;
- restrict or object to processing based on our legitimate interests;
- take your data with you in a machine-readable form, on request;
- withdraw consent for anything you consented to;
- complain to a supervisory authority: in Serbia, the Commissioner for Information of Public Importance and Personal Data Protection (Poverenik za informacije od javnog značaja i zaštitu podataka o ličnosti, poverenik.rs); in the EEA, your national data-protection authority.
Write to atplaceapp@gmail.com. We answer within 30 days and may ask you to confirm it is your account.
9. Security
Connections are encrypted (HTTPS). Passwords are stored only as salted hashes. Sign-in cookies cannot be read by scripts, and sign-in tokens are rotated so a stolen one is detected and revoked. Requests are rate-limited and uploads are screened. No system is perfectly secure; if we learn of a breach affecting your data we will notify you and the authority as the law requires.
10. Children
AtPlace is not intended for anyone under 16. We do not knowingly keep accounts of younger children; if you believe a child has registered, tell us and we will remove the account.
11. Changes
When this policy changes in a way that matters, we will tell you in the app or by email before the change applies. Earlier versions are available on request.
12. Contact
Stefan Stojanovic Beograd, Serbia atplaceapp@gmail.com