← Back to Sponio

Privacy Policy

Effective 2026-04-24 · Version 0.1-alpha

Summary: Privacy policy for the Sponio alpha — a hobby project sandbox, not a product.

Privacy Policy

Hey, thanks for being here

Sponio is a hobby project built by Sharwin Bobde and Colin Boer — two people working in tech who build this on the side, beside our day jobs. We're not trying to make money from it — we're just building something we actually want to use. Genuinely grateful you're along for the ride.

This is a sandbox

All data you enter lives in a sandbox environment. It can be wiped at any time — without warning, without recovery, and without ceremony. Don't store anything here you'd be upset to lose.

Expect a rough ride

You're in an early alpha. Things will break. Features will disappear. The database might reset. We'll try to communicate when we can, but we make no promises about uptime, stability, or continuity of your data.

Your consent

Before we collect any personal data, we explain what we're collecting and why. You then choose to opt in, after which your device will show a system permission prompt for data that requires it (such as location or contacts). We only collect that data if you grant permission.

You can withdraw consent at any time by changing permissions in your device settings or by emailing hello@sponio.com.

What we collect

To run the alpha we collect:

  • Email address — for account creation and login
  • Display name — to identify you to other users in the app
  • Phone number — for verification via one-time password and to help other users find you
  • Platform — the device type or OS you're using

We may also collect crash logs and usage traces to figure out what's broken.

Depending on the features you use, we also collect:

  • Contacts — accessed locally on your device to help you find friends. We never upload or store your contacts.
  • Geolocation — stored on our servers to power location-aware features.
  • In-app activity — things like joining plans, opening the app, and similar interactions.
  • Content you create — plans, messages, and anything else you post in the app.

Data minimization

We only collect data that is strictly necessary to run Sponio. If a feature doesn't need a piece of data, we don't collect it.

Data retention

We aim to delete all personal data after 24 months of inactivity. Remember: this is a sandbox — it may be wiped sooner.

Tracking

We do not track you across other apps or websites. We have no access to your activity outside of Sponio.

What we do with it

We use it to run and improve Sponio. That's it. We don't sell it, share it with advertisers, or do anything creepy with it.

To operate the service, we share limited data with third-party sub-processors — see the list below. We may also share data with law enforcement when required by a valid legal order. We don't share your data with anyone else.

Third-party sub-processors

We use the following sub-processors to operate the service. We aim to keep all data within the Netherlands. Where that isn't possible, data remains within the European Union.

  • Firebase (Google) — Authentication — Email address, hashed credentials
  • Google Cloud Platform — Encrypted database storage — All account and activity data, encrypted at rest
  • Google Cloud Platform — Runtime infrastructure — Unencrypted data in memory during active request processing
  • Twilio — SMS delivery for one-time passwords — Phone number, OTP message
  • Expo Application Services — Push notification delivery — Hashed device ID, push token

Your rights

Under the GDPR, you have the right to access, correct, delete, or export the data we hold about you. To exercise any of these rights, email hello@sponio.com. We'll respond within 30 days.

To delete your account and all associated data, email hello@sponio.com with the subject "Delete my account". We'll complete the deletion within 30 days and confirm when it's done. Note that some data may be retained for a short period where required by law.

Security

We use standard encryption in transit (TLS) and at rest. Access to data is limited to the people who need it to keep things running. In the event of a data breach, we will notify the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) as required by law.

Law enforcement

We only share data with law enforcement when required by a valid legal order, and only to the minimum extent required.

Children

Sponio is not for anyone under 16. We don't knowingly collect data from under-16s. If you think a child has signed up, email hello@sponio.com and we'll remove it.

Legal framework

Sponio is based in the Netherlands. During the alpha, we only accept users located in the European Union. All data collection and processing is governed by the General Data Protection Regulation (GDPR).

Changes

This is v0.1. It'll evolve as the project does. We'll update the version and date at the top when it changes.

Contact

For privacy inquiries or to exercise your data rights, contact us at hello@sponio.com — we read every message.

Questions? Email privacy@sponio.com