Privacy Policy for Placetory

Effective Date: June 1, 2025
Last Updated: July 12, 2026

1. Introduction

Welcome to Placetory ("we," "our," or "us"). Placetory is a location-based social media application that allows users to discover places, create and share check-ins with photos and videos, connect with other users, plan trips with AI assistance, and interact through chats, collections, and shared flows. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application Placetory (the "App"). Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access the App.

1.1 Data Controller

The data controller responsible for your personal information under the EU General Data Protection Regulation (GDPR) is:

Nikapps
Registered address: Heidestraße 34, 10557 Berlin, Germany
Privacy contact email: [email protected]

For any privacy-related request, including exercising the data subject rights described in Section 6, please contact us at [email protected]. We aim to respond to all valid requests within 30 days.

2. Information We Collect

The categories of personal data we collect are described below. For each category, the lawful basis under GDPR Article 6 that we rely on is noted; a full mapping is given in Section 3.

2.1 Location Information

Our App collects location data to enable location-based features. This includes:

Privacy protection: When you share your location via check-ins, precise coordinates are only visible to you. Other users see coarsened coordinates (rounded to a privacy radius) unless you explicitly opt in to share your precise location for a specific check-in.

2.2 Account and Profile Data

When you create an account, we collect and store:

Lawful basis: contractual necessity (Article 6(1)(b)) for account creation and authentication; legitimate interest (Article 6(1)(f)) for profile display to other users.

2.3 User-Generated Content

When you use the App's social features, you create and share content. This includes:

Lawful basis: contractual necessity (Article 6(1)(b)) for providing the social features you requested.

EXIF and metadata stripping: When you upload photos, we automatically strip all EXIF metadata (including GPS coordinates, camera model, timestamps, and ICC color profiles) by decoding and re-encoding the image. Only the pixel data is preserved. This means location data embedded in your photos by your camera is removed before the image is stored or displayed to other users.

2.4 Social Graph Data

We store information about your social connections, including:

Lawful basis: contractual necessity (Article 6(1)(b)) for providing social features; legitimate interest (Article 6(1)(f)) for safety and moderation.

2.5 AI Processing Data

The App uses Google Gemini AI to provide features such as trip planning, tour generation, chat assistance, and content suggestions. When you use these features, the following data is sent to Google's Gemini API:

Lawful basis: contractual necessity (Article 6(1)(b)) for providing the AI features you requested.

2.6 Content Moderation Data

When you upload photos, they are processed through our content moderation pipeline before becoming publicly visible:

Lawful basis: legitimate interest (Article 6(1)(f)) for protecting users and complying with legal obligations; legal obligation (Article 6(1)(c)) for CSAM detection and reporting.

2.7 Device Information

We may collect information about your device, including:

Lawful basis for device identifiers and crash/usage reports: legitimate interest (Article 6(1)(f)), keeping the App reliable and secure.

2.8 Google Services Integration

Our App integrates with Google Maps and other Google services. When you use these features, Google's privacy policies also apply to the data collected by Google services. Lawful basis: contractual necessity / legitimate interest (Article 6(1)(b)/(f)).

3. Lawful Basis for Processing

Under the GDPR, we must have a valid lawful basis under Article 6 for every processing activity involving your personal data. The table below summarises the lawful basis we rely on for each category of processing. More detail about each activity is given in Section 2 and Section 5.

Processing activity GDPR Article 6 basis Notes
Foreground (in-use) location data Contractual necessity (Article 6(1)(b)) Required to deliver the core location-based service you have asked for.
Background location data Explicit consent (Article 6(1)(a)) Only collected with your opt-in. You can withdraw consent at any time (see Section 6.7).
Account and profile data Contractual necessity (Article 6(1)(b)) Required to create and maintain your account and display your profile.
User-generated content (photos, videos, check-ins, messages) Contractual necessity (Article 6(1)(b)) Required to provide the social features you requested.
Social graph data (follows, blocks) Contractual necessity / legitimate interest (Article 6(1)(b)/(f)) For social features and user safety.
AI processing (trip planning, chat, suggestions) Contractual necessity (Article 6(1)(b)) Required to provide the AI-powered features you requested. Data is sent to Google Gemini API.
Content moderation (NSFW, violence, CSAM detection) Legitimate interest / legal obligation (Article 6(1)(f)/(c)) Protecting users and complying with legal obligations. Images sent to Google Cloud Vision API.
Push notifications Explicit consent (Article 6(1)(a)) Only sent after you opt in via your device settings or the App.
Device identifiers and crash / usage reports Legitimate interest (Article 6(1)(f)) Used to keep the App reliable and secure. You can object (see Section 6.6).
Google Maps API integration Contractual necessity / legitimate interest (Article 6(1)(b)/(f)) Required to provide mapping and location features.
Legal compliance and responding to valid legal requests Legal obligation (Article 6(1)(c)) Where we are required to retain or disclose data by law.

4. How We Use Your Information

We use the collected information for the following purposes:

5. Information Sharing and Disclosure

We do not sell, trade, or otherwise transfer your personal information to third parties, except in the following circumstances:

6. Your Rights Under GDPR

If you are in the European Economic Area (EEA) or the UK, you have the following rights under the GDPR in relation to your personal data. To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.

6.1 Right of Access (Article 15)

You have the right to request a copy of the personal data we hold about you and information about how we use it. To exercise this right, email [email protected].

6.2 Right to Rectification (Article 16)

You have the right to ask us to correct any personal data we hold about you that you believe is inaccurate or incomplete. To exercise this right, email [email protected].

6.3 Right to Erasure / "Right to be Forgotten" (Article 17)

You have the right to ask us to delete the personal data we hold about you in certain circumstances (for example, where the data is no longer necessary for the purpose for which it was collected). This includes your profile data, check-ins, photos, videos, chat messages, and social connections. To exercise this right, email [email protected].

Note: we may retain certain data where required by law (e.g., records of CSAM reports) or where necessary for the establishment, exercise, or defence of legal claims.

6.4 Right to Restriction of Processing (Article 18)

You have the right to ask us to suspend the processing of your personal data in certain circumstances (for example, while we verify the accuracy of data you have disputed). To exercise this right, email [email protected].

6.5 Right to Data Portability (Article 20)

You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to transmit that data to another controller. This applies to personal data we process by automated means on the basis of your consent or a contract with you. To exercise this right, email [email protected].

6.6 Right to Object (Article 21)

You have the right to object to processing of your personal data that we carry out on the basis of legitimate interest (Article 6(1)(f)), including the device-identifier, crash/usage, and content moderation processing described in Section 2. To exercise this right, email [email protected].

6.7 Right to Withdraw Consent

Where we rely on your consent to process your personal data (for example, for background location or push notifications), you can withdraw that consent at any time:

Withdrawal of consent does not affect the lawfulness of any processing we carried out before you withdrew your consent. The App will continue to work after withdrawal, but with reduced functionality (for example, background location-based features will no longer be available).

6.8 Right to Lodge a Complaint with a Supervisory Authority

If you are in the EEA or the UK and you believe that we have not handled your personal data lawfully, you have the right to lodge a complaint with your local data protection authority (supervisory authority). You do not need to contact us first.

A directory of national data protection authorities in the EEA is available from the European Data Protection Board at https://edpb.europa.eu/about-edpb/about-edpb/members_en. If you are in the UK, the relevant authority is the Information Commissioner's Office (https://ico.org.uk). In Germany, the relevant authority is the Berlin Commissioner for Data Protection and Freedom of Information (https://www.datenschutz-berlin.de).

6.9 Location Permissions (Device Controls)

In addition to the rights above, you can control location permissions through your device settings. You may:

6.10 Push Notifications (Device Controls)

You can enable or disable push notifications through your device settings or within the App settings.

6.11 Account Deletion

You can request deletion of your account at any time by emailing [email protected]. Upon account deletion:

7. Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Specific retention periods for each category of data are:

Data category Retention period
Precise / approximate (foreground) location data Up to 90 days after your last active session, unless you request earlier deletion
Background location data Up to 30 days after collection, or until you revoke background permission / withdraw consent, whichever is sooner
User-generated content (photos, videos, check-ins, comments) Until you delete the content or your account, or until 24 months after your last active session, whichever comes first
Chat messages Until you delete the conversation or your account
Social graph data (follows, blocks) Until you unfollow/unblock the user or delete your account
Account and profile data Until you request erasure, or after 24 months of account inactivity, whichever comes first
Content moderation records (blocked content, CSAM reports) As required by applicable law for legal compliance and reporting obligations
Device identifiers For the lifetime of the App installation, and deleted within 30 days of uninstall
Analytics and crash reports 13 months on a rolling basis
Records of consent and rights requests For the period required by applicable law (to demonstrate compliance)

On expiry of the retention period above, the data is either deleted or anonymised so that it can no longer be associated with you.

8. Children's Privacy

Our App is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information. Users between 13 and 16 years old must have parent or legal guardian permission to use the Service, in accordance with GDPR Article 8 and German data protection law.

9. International Data Transfers

Your information may be transferred to and maintained on computers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ from those in your jurisdiction. In particular:

You can contact us at [email protected] if you would like a copy of the relevant safeguard documentation.

10. Third-Party Services

Our App integrates with the following third-party services, each with their own privacy policies:

We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies.

11. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy within the App and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.

13. Compliance with Laws

This Privacy Policy is designed to comply with applicable privacy laws, including but not limited to the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and other relevant data protection regulations.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Email: [email protected]
Website: https://www.placetory.ai

For users in the European Union, you also have the right to lodge a complaint with your local data protection authority. See Section 6.8 for details.