1Introduction
Welcome to Sunslider ("we," "our," or "us"). We are committed to protecting your privacy and ensuring that your personal data is handled securely and in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This Privacy Policy explains how we collect, use, and protect your personal data when you use the Sunslider mobile application and related services.
Our Privacy Philosophy: Sunslider is built on the principle that social media should serve users, not exploit them. We collect only the data necessary to provide our service, we don't track your behavior for advertising, and we don't sell your data to third parties.
2Data Controller
Sunslider SAS is the data controller responsible for your personal data. If you have any questions about this Privacy Policy or your rights, you can contact us at:
3What Data We Collect
3.1 Account Information
When you create a Sunslider account, we collect:
- Email Address: For account authentication and essential communications
- Username: Your unique identifier on the platform
- Display Name: Optional name shown to other users
- Password: Stored as an encrypted hash, never in plain text
- Birth Date: To verify you meet our 16+ age requirement
- Bio: Optional description (up to 150 characters)
- Profile Picture: Optional image, automatically processed with our open-source privacy tools to remove sensitive metadata
3.2 Interest and Social Data
- Selected Interests: Categories you choose during signup to help with content discovery
- Invitation Relationships: If you joined via an invitation code, we store this relationship to suggest connections
- Social Connections: Users you follow and who follow you
- Content Interactions: Slides you like, comments you make, and basic interaction patterns
3.3 Content You Share
- Photos and Videos: Content you upload as slides or stories
- Captions: Text descriptions you add to your content
- Privacy Settings: Your chosen visibility levels for each piece of content
Privacy Protection:
All photos are automatically processed to remove EXIF metadata including GPS location, device information, and timestamps before storage. This EXIF removal is performed using our open-source privacy tools, which are publicly available for audit and transparency.
How Privacy Settings Work:
- "Everyone": Visible to all Sunslider users; may be cached globally if you share via web viewer
- "Followers Only": Only visible to users who follow you; always served from EU servers with authentication
- "Mutuals Only": Only visible to users you mutually follow; always served from EU servers with authentication
3.4 Technical Information
- Device Tokens: For push notifications (only if you enable them)
- App Performance Data: Anonymous information about load times, errors, and feature usage to improve app stability
- Error Reports: When the app crashes or encounters errors, we collect anonymous technical diagnostics (no personal information included)
We do NOT collect or store:
- IP addresses: Not logged or retained
- Precise device identifiers: Beyond what's necessary for push notifications
- Usage timestamps or session recordings: We don't track when you use the app
- Tracking across other apps or websites: We don't follow you around the internet
3.5 What We DON'T Collect
We don't collect:
- Location Data: We never collect or store your location
- Browsing History: We don't track your activity outside Sunslider
- Behavioral Profiles: We don't build advertising or psychological profiles
- Contact Lists: We don't access your phone's contacts
- Personal Files: We only access photos you explicitly choose to share
4How We Use Your Data
4.1 Essential App Functions
- Account Management: Authentication, profile display, account recovery
- Content Sharing: Displaying your content to users based on your privacy settings
- Social Features: Enabling follows, likes, and content discovery
- Interest-Based Discovery: Showing you content and suggesting users based on your declared interests
- Push Notifications: Sending notifications about app activity (only if enabled)
4.2 Privacy Protection
- EXIF Stripping: Automatically removing sensitive metadata from all uploaded images using our open-source tools
- Privacy Controls: Enforcing your chosen visibility settings (Everyone, Followers, Mutuals)
- Data Security: Protecting your information with encryption and access controls
4.3 Service Improvement
- Bug Fixes: Using anonymous crash reports to identify and fix technical issues
- Performance Optimization: Improving app speed and reliability
- Feature Development: Understanding which features are most valuable to users
4.4 Essential Communications
- Service Updates: Important information about app changes or security updates
- Account Security: Notifications about login attempts or security concerns
- Policy Changes: Updates to our terms or privacy practices
5Legal Basis for Processing
We process your personal data based on one or more of the following legal grounds:
- Contractual Necessity: To provide the Sunslider app service you've requested
- Consent: When you enable push notifications or provide optional information
- Legitimate Interests: To improve app security, prevent fraud, and enhance our services while respecting your privacy
- Legal Obligations: To comply with laws and regulations
6Data Storage and Security
6.1 Data Storage and Infrastructure
Data Storage (Permanent):
All your personal data is stored exclusively on EU-based servers:
- User data and database: Supabase (EU-Central region)
- Photos and videos: Hetzner Cloud Storage (Germany)
- Application servers: Hetzner Cloud (Germany/Finland)
Content Delivery (Temporary Caching):
We use Cloudflare's Content Delivery Network (CDN) to deliver content faster worldwide. How your content is delivered depends on how it's accessed:
- In-App Viewing: When you or others view content within the Sunslider app, it is served through our authenticated API with full privacy enforcement. This content is always fetched from EU servers and is not cached globally.
- Web Viewer Sharing (Opt-In): When you choose to share content via our web viewer (generating a public share link), those images may be temporarily cached by Cloudflare's global network for faster loading. This caching only occurs when you explicitly create and share a web viewer link, is temporary (cached for up to 30 days), and is covered by Cloudflare's GDPR-compliant Data Processing Addendum.
Your original data always remains stored exclusively on EU servers.
7Security Measures
We protect your data with multiple layers of security:
Technical Protections:
- End-to-end encryption for data in transit: HTTPS/TLS
- Encrypted password storage: bcrypt hashing, never stored in plain text
- Multi-layer access controls and authentication: JWT tokens
- Automated attack detection and blocking: Web application firewall, rate limiting
- Regular security audits and updates: Continuous monitoring and improvements
Infrastructure Security:
- EU-based servers with physical security controls: Hetzner Germany/Finland datacenters
- Isolated database with row-level security policies: Supabase RLS enabled
- Automated backup systems: Daily backups with retention policies
- 24/7 monitoring for suspicious activity: Automated intrusion detection
Your Role in Security:
- Use a strong, unique password for your Sunslider account
- Enable two-factor authentication when available (coming soon)
- Report any suspicious activity to [email protected]
8Third-Party Service Providers
We work with the following GDPR-compliant service providers to operate Sunslider:
Infrastructure Providers:
- Hetzner Online GmbH (Germany): Server hosting and storage
- Supabase Inc.: EU-based database hosting
- Cloudflare Inc.: Content delivery network and security services
All service providers:
- Are bound by GDPR-compliant Data Processing Agreements
- Process data only on our instructions
- Implement appropriate technical and organizational security measures
- Store or process data in accordance with EU privacy laws
We do not share your data with advertising networks, data brokers, or analytics companies. We do not use third-party tracking or behavioral profiling services.
19Contact Information
For any questions, concerns, or requests regarding this Privacy Policy or how we handle your data:
6 rue Jean-Marie Chavant
Lyon, France
[email protected]
Data Protection Officer: [email protected]
We are committed to addressing your privacy concerns promptly and transparently.
Summary: Sunslider is built to respect your privacy. We collect only essential data, store everything in the EU, never sell your information, and give you complete control over your content and privacy settings. Your data is protected by the strongest privacy laws in the world, and you can delete your account and all data at any time.
By using Sunslider, you acknowledge that you have read and understood these terms.