Sparefilm

Privacy Policy

Last updated: 2026-08-31

Sparefilm is made by Gwei Labs Pty Ltd (ABN 98 656 175 174), 470 St Kilda Road, Melbourne VIC 3004, Australia. Questions, requests, complaints: privacy@sparefilm.app. This policy is free to read here and in the app, and we'll give it to you in another format if you ask.

1 · The short version

We collect what the product visibly needs: an email to let you in, a date of birth to keep the door at sixteen, and the things you make. We don't run ads, we don't sell anything about you, and we don't use your photographs for anything except showing them to the people you chose. When you destroy something, we destroy it.

2 · What we collect

Your account: sign-in email (or the relay address Apple gives us if you hide yours); date of birth (kept on your device only, never sent to our servers); name; handle; bio; your portrait (kept on your device only, never sent to our servers, and no other member ever sees it).

Your work: the photographs you shoot; the note you seal when you load a roll; the marks (vouches) you leave on other members' frames, which carry your name.

Your room: who you follow, who follows you, who invited you and who you invited. An invite link carries your handle: anyone you hand it to can see it came from you.

Technical: service logs.

Before launch: if you gave us an email at TAKE A PLACE, we hold it to write to you until the door opens, and delete it with that send.

The website: on the pre-launch site (sparefilm.app, not the app), we count visits ourselves so we can tell whether the page is working. A visit adds one to a number we keep for that page on that day, and that is the whole of it: no cookie, nothing stored in your browser, no identifier, and nothing that could be joined to you or to a second visit. There is no banner because there is nothing to agree to. Sending the form still loads reCAPTCHA, which sets a cookie and tells Google what it saw of that press, so we can tell a person from a machine (§5, §7). That runs on your press, not on a page load.

We collect nothing that follows you: no advertising identifiers, no tracking, no analytics that profile you. Our own service logs, and, if the app crashes, a crash report that tells us what broke (device model, OS version, the crash trace; never your photographs or messages), are the whole technical take. So that a crash can be placed in the run of the app it happened in, the app also generates a session identifier on this device: a random tag that tells one run of the app from another. It is not your handle and not your account, and it is joined to neither; it carries no photographs, no note text, and no message content.

3 · How we collect it

You type it or you shoot it. Sign-in comes through Apple, Google, or a code we email you. Nothing is scraped, bought, or inferred.

4 · How we hold it

Your data lives in Google Cloud (Firebase) in the United States: your records in Iowa (us-central1), your photographs in South Carolina (us-east1), encrypted in transit and at rest. Access inside Gwei Labs is limited to operating the service and to reports you file.

5 · What we use it for

To run Sparefilm: let you in, keep the door at sixteen, develop your roll at your eight, show your sheet to your followers, deliver marks and invites, send the service's letters, keep the room safe when something is reported, and check, when you send the form on the pre-launch website, that a person sent it and not a machine. That is the list. No advertising, no sale of personal information, no model training.

6 · Who sees what

Your published rolls go to your followers. A share link is a public URL: anyone holding it can see that sheet until you withdraw it; withdrawing kills the link. Nobody sees an undeveloped roll, including you. Staff look at content only when a report or a safety-scan hold requires it (§14).

7 · Third parties

Our processors: Apple and Google for sign-in, Google Cloud for hosting, Postmark for email (the sign-in code and the letters), Google (Firebase Crashlytics) for crash diagnostics, Google (Firebase Sessions) for grouping those crash reports by app session, and Google (reCAPTCHA Enterprise) for telling people from machines at the waitlist form on that same website. The crash and session diagnostics are processed by Google in the United States. Counting visits to the website is ours: it runs on our own servers, it reaches no third party, and there is nothing in it to send. They process your data for us, under terms that protect it at least as well as this policy. reCAPTCHA Enterprise runs on the website only as well, and only when you send the form: the app links nothing of the kind, and nothing loads until you press the button. Pressing it sets a cookie and sends Google what it saw of that press and of the browser that made it, which Google scores for how likely a machine sent it. That score is joined to nothing else we hold, least of all your address, and it is not analytics: it counts no visits and builds no profile. We disclose personal information to nobody else, except where the law compels us, and then only what it compels.

8 · Overseas

Our infrastructure providers are global companies; personal information is held in the United States, and our providers' support and subprocessors may access it from other countries where they operate. We don't otherwise send your information overseas.

9 · Retention

Your account and work stay until you remove them. Destroy a roll and every frame, the note and every vouch on it are deleted at once, gone from every screen, ours included. We keep no backups and no point-in-time recovery: once deleted, we could not bring it back if we wanted to. One record outlives all of this, and you should know it does: when a frame is held or taken down after review, the decision (whose frame it was, where it was stored, and what the review found) is kept for twelve months, so that if you appeal we can tell you what was decided and when; then it too is deleted. It is the single exception to everything above, and it exists so the appeal has something to answer. Deleted data lingers only inside Google's storage machinery for the brief period its systems take to purge. The website's visit counts are numbers with nobody in them, so there is nothing there to be about you; we keep them for fourteen months and then delete them. Delete your account and: your rolls are destroyed, your share links die, marks you left on others' work are removed, and your handle is quarantined for 30 days before anyone can take it. A refused under-16 attempt stores nothing except the scrambled record §10 describes.

10 · Under sixteen

Sparefilm is for sixteen and older. We ask your date of birth once, at the door, to enforce that; the date stays on your device. If we refuse an under-sixteen attempt, we keep one thing for thirty days: a scrambled record of the refused address, never the address itself, and never the date of birth. It deletes itself. Information collected to assure age is used for that purpose and nothing else.

11 · Access and correction

Everything we hold about you is visible in the app, and the profile sheet edits it: name, handle, bio, date of birth and your portrait. Your date of birth and your portrait we never receive at all; the sheet is where you change or remove them on your phone. Want a copy of your data? Email privacy@sparefilm.app and a person will send you everything we hold, within 30 days. Export is by request, not a button. Consent withdrawal = deletion, and deletion lives in Settings, in the app.

12 · Where you live

Sparefilm is available in Australia, New Zealand, the United States, Singapore, Hong Kong, and Japan. Wherever you are: complaints start at privacy@sparefilm.app. We acknowledge within 7 days and answer within 30.

Australia: our home law. If our answer doesn't settle it, the Office of the Australian Information Commissioner takes complaints: oaic.gov.au.

New Zealand: your rights run under the NZ Privacy Act 2020; after us, the Office of the Privacy Commissioner: privacy.org.nz.

United States: nothing here limits rights your state gives you.

Singapore: our data protection officer under the PDPA is reachable at privacy@sparefilm.app; after us, the PDPC: pdpc.gov.sg.

Hong Kong: Sparefilm is operated from Australia; we honour the access and correction requests this policy describes for everyone.

Japan: your purposes-of-use and disclosure rights under the APPI are the §5/§11 rights. Your data is entrusted to cloud infrastructure in the United States (§4, §8) that stores it without accessing it.

13 · If something goes wrong

If a breach is likely to cause you serious harm, we assess it within 30 days and notify you and the OAIC under the Notifiable Data Breaches scheme.

14 · Automated decisions

When your roll develops, a safety scan checks each frame before it publishes. If the scan is very sure a frame breaks the rules, the frame is held and a person reviews it before it can publish; if it is merely suspicious, it publishes and a person reviews it after. The final call on any frame is always a person's, and a takedown always tells you what came down.

15 · Changes

We'll tell you in the app before a change takes effect, and the date at the top always says which version you're reading.