Pebbly

Privacy Policy

Last updated: October 2026GDPR Compliant
the human version: we don't sell your data. ever.

Introduction

At Pebbly, we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and protect your information when you use our Service.

Pebbly is compliant with the General Data Protection Regulation (GDPR) and other applicable privacy laws. This policy applies to all users, including those in the European Union and Poland.

1. What Data We Collect

Account Information

  • Email: Used for account creation, login, and important notifications
  • Username: Your chosen display name on the platform
  • Password: Securely hashed and encrypted (we never store passwords in plain text)
  • Profile: Optional bio, profile picture, and privacy settings

Location Data

  • GPS: Captured when you create a rock (origin location) or check in a rock (find location)
  • Accuracy: We record GPS accuracy to ensure data quality
  • Manual: If you manually select a location on the map, we mark it as unverified

Location data is essential for tracking rock journeys and is only collected when you actively create or check in a rock.

Photos

  • Rock photos: Images you upload when creating a rock
  • Check-in photos: Optional images you upload when finding a rock

Photos are stored securely and displayed publicly (unless you set your profile to private).

Device Information (Anti-Fraud)

  • Fingerprint: A unique identifier for your device to prevent spam and fraudulent check-ins
  • IP: Logged for security and anti-abuse purposes
  • Browser: Used for analytics and ensuring compatibility

Device fingerprinting helps us prevent fake check-ins, location spoofing, and spam accounts.

Usage Data

  • Rocks: How many rocks you've made
  • Check-ins: How many rocks you've found
  • Interactions: Likes, comments, and other platform activity

2. Why We Collect This Data

We collect and use your data for the following purposes:

Service Functionality

  • Create and manage your account
  • Track rock journeys on interactive maps
  • Display check-ins with photos and locations
  • Enable community features (likes, comments)

Security and Anti-Fraud

  • Prevent fake check-ins and location spoofing
  • Detect and ban spam accounts
  • Enforce rate limits to prevent abuse
  • Protect the integrity of rock journeys

Communication

  • Send account verification emails
  • Notify you when someone finds your rock (if enabled)
  • Send password reset emails
  • Important service updates

Legal Basis (GDPR)

  • Contractual: Processing data to provide the Service you requested
  • Legitimate: Preventing fraud and ensuring platform security
  • Consent: For optional features like notifications and analytics

3. How We Use Your Data

  • Display your rocks and check-ins on the platform (public or private based on your settings)
  • Show your username to other users (unless you set your profile to private)
  • Calculate journey distances and statistics
  • Generate maps showing rock travel paths
  • Improve the Service through analytics (anonymized where possible)
We do NOT:
  • Sell your personal data to third parties
  • Share your email address publicly
  • Use your data for advertising without consent
  • Track your location when you're not actively using the app

4. Who We Share Data With

Service Providers

  • Supabase: Database hosting and authentication (GDPR compliant)
  • Vercel: Hosts the website. Like any web host, it receives your IP address and browser details with each page request.
  • Stripe: Payment processing for premium subscriptions (if applicable)
  • Resend: Sends our emails: sign-up confirmation, password resets and notifications such as "your rock was found". Receives your email address and the content of the message.
  • Google: The "Sign in with Google" button is loaded from Google on the sign-in page. If you use it, Google verifies your account and shares your name, email address and profile picture with us.
  • OpenAI: Checks uploaded photos for inappropriate content. Receives the image only, with no account details such as your username or email address.
  • Sentry: Error reports, sent only if you accept analytics. They describe what went wrong and in which browser; we don't attach your username or email address.
  • ipify: Looks up your public IP address when you check in a rock, like something or send a report, so we can prevent fraud. ipify sees your IP address.
  • OpenStreetMap: Map images. Your browser loads them from OpenStreetMap's tile servers, which see your IP address and the area of the map you're viewing.
  • Nominatim (OpenStreetMap Foundation): Turns the coordinates of a new rock or a check-in into a place name. Receives those coordinates and your IP address.
  • OSRM: Calculates the route drawn between a rock's stops on its journey map. Receives the coordinates of those stops.
  • Photon (Komoot): Suggests places as you type your home city in your profile settings. Receives what you type and your IP address.

Some of these providers are based outside the European Economic Area, mainly in the United States. Transfers to them are covered by the safeguards described in section 10.

Public Display

If your profile is set to public, the following information is visible to all users:

  • Username
  • Profile picture
  • Rocks you've created
  • Check-ins you've logged (with locations and photos)

If your profile is set to private, only you can see your data.

Legal Requirements

We may disclose your data if required by law, court order, or to protect our legal rights.

5. Your Rights (GDPR)

Under GDPR, you have the following rights regarding your personal data:

Right to Access

You can request a copy of all personal data we hold about you. Go to Settings → Export Data or email us at privacy@pebbly.art.

Right to Delete

You can delete your account and all associated data at any time. Go to Settings → Delete Account.

Note: Deletion is permanent and cannot be undone. Backup copies may remain in our systems for up to 30 days.

Right to Rectification

You can update incorrect information through your account settings at any time.

Right to Data Portability

You can export your data in a machine-readable format (JSON). Go to Settings → Export Data.

Right to Withdraw Consent

You can opt out of optional features like email notifications. Go to Settings → Notifications.

Right to Object

You can object to processing of your data for direct marketing or analytics purposes.

6. Data Retention

We retain your data as follows:

  • Account: Stored as long as your account is active
  • Rocks: Stored permanently unless you delete them
  • Fingerprints: Stored for anti-fraud purposes (up to 2 years)
  • IP: Logged for security (up to 6 months)

When you delete your account, we immediately remove all personal data from public view. Backup copies may remain in our systems for up to 30 days before being permanently deleted.

7. Cookies and Tracking

Pebbly uses cookies and similar technologies for:

  • Essential: Session management and authentication (required)
  • Analytics: Understanding how users interact with the Service (optional)

You can manage cookie preferences in your browser settings. Note that disabling essential cookies may impact the functionality of the Service. Read the full Cookie Policy →

8. Children's Privacy

Pebbly is not intended for children under the age of 13. We do not knowingly collect personal data from children under 13. If we become aware that a child under 13 has provided us with personal data, we will take steps to delete such information.

If you believe a child under 13 has registered an account, please contact us at privacy@pebbly.art.

9. Data Security

We take data security seriously and implement the following measures:

  • Encryption: All data transmitted over HTTPS
  • Hashing: Passwords are hashed using industry-standard algorithms
  • Access: Only authorized personnel can access user data
  • Backups: To prevent data loss
  • Audits: Regular reviews of our security practices

While we strive to protect your data, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.

10. International Data Transfers

Your data may be stored and processed in servers located outside your country of residence. We ensure that any international data transfers comply with GDPR requirements through:

  • Standard Contractual Clauses (SCCs)
  • Using GDPR-compliant service providers
  • Implementing appropriate safeguards

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through a notice on the Service. Your continued use of Pebbly after changes are posted constitutes your acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your GDPR rights, please contact us:

13. GDPR Compliance Statement

Pebbly is fully compliant with the General Data Protection Regulation (GDPR) and respects the privacy rights of all users, including those in the European Union and European Economic Area.

We process personal data only when necessary for providing the Service and implement appropriate technical and organizational measures to ensure data security.

By using Pebbly, you acknowledge that you have read and understood this Privacy Policy.