Privacy Policy
Glyph Museum
Effective date: September 29, 2025 · Last updated: August 7, 2026
1. Introduction
This Privacy Policy describes how Glyph Museum App ("we," "our," or "us") collects, uses, and protects your personal information when you use our mobile application (the "App"). We are committed to protecting your privacy and ensuring transparency about our data practices.
2. Data Controller Information
Developer: pauwma (Pau Muñoz)
Contact Email: [email protected]
Jurisdiction: Spain, European Union
3. What Information We Collect
3.1 Account Information (When You Sign In)
When you create an account using OAuth providers, we collect:
- Display name (from your OAuth profile)
- Email address (from your OAuth profile)
- Avatar/profile picture URL (from your OAuth profile or user-provided)
- Unique user identifier (generated by the OAuth provider or user-chosen)
- OAuth provider type (currently Google, GitHub or Discord)
3.2 Profile Information
- User handle (@username, automatically generated or user-chosen)
- Bio/description (optional, user-provided)
- Social media links (optional, user-provided)
- Profile creation and update timestamps
3.3 App Usage Data
- Glyph patterns you create or upload
- Posts you publish (title, description, tags, glyph data)
- Likes you give to other posts
3.4 Local Device Data
- Frame assignments (which posts you assign to glyph frames)
- Frame configurations (stored locally on your device)
- App settings (stored locally on your device)
- Authentication tokens (for maintaining your session)
4. How We Use Your Information
We use your information to:
- Provide App functionality: Enable you to create, share, and manage glyph patterns
- Manage your account: Authenticate your identity and maintain your profile
- Enable social features: Display your profile to other users and manage interactions
- Ensure App security: Prevent misuse and protect against unauthorized access
- Improve the App: Understand how features are used (without personal identification)
- Communicate with you: Respond to your inquiries and provide support
5. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), our legal bases for processing your data are:
- Contract performance (Art. 6(1)(b) GDPR): Creating and maintaining your account, authenticating you via OAuth, hosting and serving your glyphs and posts (including making published posts publicly available as described in Section 7.5), displaying your profile to other users.
- Legitimate interests (Art. 6(1)(f) GDPR): Aggregated and anonymised analytics to understand product usage and improve the App, security monitoring to detect abuse and prevent unauthorised access, and content moderation to keep the community safe. You may object to processing based on legitimate interests at any time.
- Consent (Art. 6(1)(a) GDPR): Optional features such as social media links on your profile and any future marketing or newsletter communications. You may withdraw consent at any time without affecting the lawfulness of prior processing.
- Compliance with legal obligations (Art. 6(1)(c) GDPR): Responding to lawful requests from competent authorities, retaining records as required by law and complying with child safety obligations.
For users under 18, processing of personal data is conditional on the user being at least 14 years old (Article 7 LOPDGDD) and, where applicable under local law, on parental or guardian consent.
6. Data Storage and Security
6.1 Data Storage
- Self-hosted infrastructure: Your account data, profile and user-generated content are stored on a self-hosted Supabase instance running on infrastructure we operate directly. No personal data is sent to Supabase Inc. or any third-party cloud provider for this storage.
- Data location: Servers are located in the European Union; personal data does not leave the EEA in the course of providing the App.
- Local storage: Some data (frame settings, preferences, authentication tokens) is stored locally on your device.
6.2 Security Measures
- Encryption in transit: All data transmission uses HTTPS / TLS.
- Authentication: OAuth 2.0 with PKCE flow.
- Access controls: Strict role-based access controls limit who can access stored data; administrative access is restricted to the developer.
- Operational security: Up-to-date software, hardened server configuration and regular backups.
- Incident response: In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the AEPD within 72 hours and, where required, the affected users (Articles 33-34 GDPR).
7. Data Sharing and Third Parties
7.1 We Do NOT Share Your Data With:
- Advertising networks
- Marketing companies
- Data brokers
- Any third parties for commercial purposes unrelated to operating the App
7.2 Third Parties We Do Interact With:
- OAuth Providers (currently Google, GitHub and Discord): only to authenticate your identity. Each provider has its own privacy policy that you should review.
- Google Play / Android distribution: the App is distributed via Google Play, which collects its own data subject to Google's privacy policy.
- Legal Authorities: only when required by law or in response to a valid legal request.
The Supabase backend used for data storage is self-hosted on our own infrastructure; it does not act as an external processor and no data is shared with Supabase Inc. or any third-party cloud provider for storage purposes.
7.3 Website Analytics (glyphmuseum.com only)
On the public website (glyphmuseum.com) we use Plausible Analytics, self-hosted on our own infrastructure at analytics.pauwma.com. Plausible operates without cookies, does not collect or store personally identifiable information, does not cross-reference data across sites and does not share data with third parties. It provides aggregated statistics only (page views, referrers, device type, country). Legal basis: legitimate interest (Article 6(1)(f) GDPR) in understanding how the website is used. You may object at any time by emailing [email protected] or by using browser privacy features.
The mobile App itself does not include any analytics or telemetry.
7.4 Cookies and Similar Technologies
The website does not set tracking cookies. The App stores authentication tokens and preferences locally on your device for strictly functional purposes only. No advertising or cross-site tracking technologies are used.
7.5 Public Content and Interoperability
Posts you publish, together with the public profile information attached to them (display name, handle, avatar and featured badge), are publicly accessible. They can be viewed in the App, on our public web app, in link previews when a post is shared, and may be displayed in third-party applications that interoperate with our open design format, always with attribution to you. Design files you export may embed your handle and a link to the original post as attribution metadata.
If you delete a post or your account, we remove the content from our services, but copies of design files that were already exported or downloaded by other users may continue to exist outside our control.
8. Your Rights Under GDPR
As an EU resident, you have the right to:
- Access (Art. 15): Request a copy of your personal data
- Rectification (Art. 16): Correct inaccurate or incomplete data
- Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten")
- Portability (Art. 20): Receive your data in a structured, commonly used and machine-readable format
- Restriction (Art. 18): Limit how we process your data
- Object (Art. 21): Object to processing based on legitimate interests
- Withdraw consent (Art. 7(3)): For data processed based on consent, without affecting the lawfulness of prior processing
- Not to be subject to automated decision-making (Art. 22): We do not use solely automated decisions that produce legal or similarly significant effects on you; automated moderation flags are reviewed by a human before any material account action.
To exercise these rights, contact us at: [email protected]. We will respond within one month (extendable by two further months for complex requests).
8.1 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement. In Spain, the competent supervisory authority is the Agencia Española de Protección de Datos (AEPD):
- Website: www.aepd.es
- Address: C/ Jorge Juan, 6, 28001 Madrid, Spain
We encourage you to contact us first so we can try to resolve any concerns directly.
9. Data Retention
- Account & profile data: retained for as long as your account is active.
- User-generated content (glyphs, posts, likes): retained until you delete it or close your account. Content liked or referenced by other users may be retained in anonymised aggregate form (e.g., like counts) after deletion.
- Authentication logs and security events: retained for up to 12 months for security and fraud-prevention purposes.
- Aggregated analytics (Plausible): stored indefinitely in non-identifiable, aggregated form; no individual user records.
- Moderation and abuse records (including reports, takedowns and account suspensions): retained for up to 24 months to comply with DSA Article 17 record-keeping and to prevent repeat abuse.
- Records required by law (e.g., responses to authorities): retained for the period required by the applicable legal obligation.
- Deleted accounts: all personal data is permanently deleted within 30 days, except where retention is necessary to comply with legal obligations or to resolve disputes.
10. Children's Privacy
The App is designed for users aged 14 and older, in line with Article 7 of Spain's Organic Law 3/2018 (LOPDGDD) and Article 8 GDPR. We do not knowingly collect personal information from children under 14. If we discover that we have collected personal information from a child under 14, we will delete it without undue delay. Parents or legal guardians who believe their child has provided information to us should contact us at: [email protected].
Depending on local law, additional parental or guardian consent may be required for users between 14 and 18. We rely on the user's declaration of age and reserve the right to suspend any account where we have reasonable doubt about compliance with the minimum age requirement.
11. International Data Transfers
Your account data and user-generated content are stored exclusively on our self-hosted infrastructure located in the European Union. As a general rule, no personal data leaves the EEA in the course of providing the App.
Authentication via third-party OAuth providers (Google, GitHub, Discord) may involve limited processing of authentication metadata outside the EEA by those providers. Where this is the case, we rely on the safeguards offered by those providers, including (where applicable) Standard Contractual Clauses approved by the European Commission and supplementary measures, in accordance with Chapter V GDPR.
You may request additional information about the safeguards in place by contacting us at [email protected].
12. Offline Functionality
Some App features work offline using data stored locally on your device:
- Glyph pattern creation and editing
- Frame configurations and displays
- App settings and preferences
This local data is not transmitted to our servers unless you explicitly save or publish content.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes:
- We will update the "Last Updated" date
- Significant changes will be communicated through the App
- Continued use of the App after changes constitutes acceptance
14. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us:
Email: [email protected]
Subject Line: Privacy Policy Inquiry
For GDPR-related requests, please include "GDPR Request" in the subject line and specify which right you wish to exercise.
Data Protection Officer: Not applicable (small-scale processing)
Supervisory Authority: Agencia Española de Protección de Datos (AEPD) — Spain