Privacy Policy
Last updated: August 10, 2026.
1. Who this is about, and who's responsible
SpatialProbe, operated by Spatial Probe Ltd (company number 17346177, registered office Unit 82A James Carter Road, Mildenhall, Bury St. Edmunds, England, IP28 7DE), is the "data controller" for the personal data described below: the one who decides what gets collected and why, and who you'd contact about it (see Section 11).
This applies to anyone with a SpatialProbe account, and, to a lesser extent, anyone who just visits the public website (see Section 5's cookie section).
2. What's actually collected
Everything below is either something you directly provide, or generated by using the Service -- nothing is bought or scraped from elsewhere.
| Category | What | Why |
|---|---|---|
| Account | Email address, password (stored as a salted hash, never in plain text -- see Section 7) | Sign-in, password reset, account-related email |
| Profile (optional) | Username, display name, full name, bio, avatar | Shown publicly, credits your content (see Terms §3) |
| Preferences | Saved starting map location, unit system | Personalizing the apps to how you use them |
| Content you upload | Photos/videos, their location, captions, titles, EXIF metadata your camera/phone attached, journeys, comments | The core of what the Service does; public content is licensed per Terms §3 |
| Photo/video metadata handling | The copy actually shown/downloadable is re-encoded on upload -- this strips whatever your camera or phone originally embedded (precise device-level GPS, device serial, software version) and replaces it with just your username, a profile link, and the CC BY 4.0 notice (see Terms §3). On the Explorer plan, the original file you uploaded can optionally be kept and downloaded as-is (including whatever the camera itself recorded), or downloaded with your own title/caption/credit/location re-embedded on request. | Data minimization by default; extra capability only where you've actively chosen it |
| Billing | Subscription tier/status, a Paddle customer/subscription ID | Knowing what you're subscribed to -- your actual card/payment details are held by Paddle, never by us (Section 4) |
| Support | Whatever you write in a support/contact request | Replying to you |
| Technical | IP address and standard request logs (server access logs), a session cookie | Keeping you signed in, security, diagnosing abuse/outages -- not used to build an advertising profile |
3. Legal basis for processing (GDPR)
- Contract -- account/profile/content/billing data: we can't provide the Service you signed up for without it.
- Consent -- optional profile fields (bio, avatar, full name), which you can leave blank or remove any time.
- Legitimate interest -- technical/security logs, moderation screening, and fraud/abuse prevention, balanced against your own privacy interest in each case.
4. Who this data is shared with
Only what's needed to actually run the Service -- never sold, never shared for anyone else's marketing:
- Paddle (payment processor) -- handles checkout, billing, and your card details entirely on their own systems; we only ever see a customer/subscription ID back from them, never your card number.
- Google Workspace / Gmail -- relays transactional email only (signup confirmation links, password reset links, contact-form replies), never marketing email.
- Cloudflare (Turnstile) -- sees your IP address and some browser signals for the moment it takes to verify you're not a bot on sign-up/sign-in/password-reset forms.
Each of these vendors processes data under their own data-processing agreement with us, and none of them is permitted to use your data for their own purposes. Where a vendor processes data outside the UK/EEA, that transfer is covered by Standard Contractual Clauses (or an equivalent adequacy mechanism) as required under UK/EU GDPR.
5. Cookies
One cookie: spatialprobe_auth_session, which stores your session so you stay
signed in across the app and its sibling sites. Strictly necessary for the Service to
work -- there's no cookie banner because there's nothing optional to consent to: no
analytics cookies, no advertising cookies, no third-party tracking cookies of any kind.
6. How long data is kept
For as long as your account exists, plus whatever's needed afterward for legitimate purposes (fraud prevention, legal obligations, resolving disputes -- e.g. billing records Paddle/tax law requires keeping). Deleting your account (Account settings -> Delete account) removes your private data immediately and cancels any active subscription straight away -- see Terms §7 for exactly what stays and why. Short version: public content you licensed under Creative Commons isn't "your data" in the same sense once it's been shared under an irrevocable license, the same way it wouldn't be on any other CC BY platform -- but public content you kept "All rights reserved" was never licensed to anyone else in the first place, so that erasure IS complete, along with everything private. Billing identifiers are kept for the accounting/dispute reasons above, but are never visible to anyone except you or, for support purposes, us.
7. Security
Passwords are never stored in plain text -- only a salted hash (via our self-hosted authentication service), which even we can't reverse. All traffic to the Service is encrypted (HTTPS). Access to the underlying servers/database is restricted to the operator; nobody else has standing access to raw user data.
8. Your rights
Under GDPR (or equivalent local law), you can:
- Access what we hold on you -- most of it is already visible in Account settings; ask support for anything that isn't.
- Correct inaccurate data -- directly in Account settings for most fields.
- Erase your data -- self-service via Account settings -> Delete account (see Section 6 above for what that covers).
- Export your data in a portable format -- ask support; not yet a self-service button.
- Object to processing based on legitimate interest -- contact support.
- Complain to your local data protection supervisory authority, if you think we've gotten something wrong and haven't fixed it.
9. Children
The Service requires you to be 18 or older to create an account (see Terms §2), and we don't knowingly collect data from anyone under that age. If you believe a minor has created an account, contact support and it'll be removed.
10. Changes to this policy
We may update this policy as the Service changes. Meaningful changes will be reflected here with an updated date at the top of the page.
11. Contact
Contact us with any question about this policy, a data request, or a concern about how your data's been handled.