1. Who controls your personal data
Sticktime is operated by Panagiotis Florous, a sole trader registered in Greece under his personal AFM and operating from Aristeidou 7, 16345 Ilioupoli, Greece (we, us or our). He is the controller of the personal data described in this Policy unless stated otherwise.
Privacy contact: support@sticktime.online
This Policy applies to the Sticktime mobile application, related support and the web pages on which this Policy is published.
2. Data we process
Account and authentication data
Depending on how you sign in, we process your Firebase user identifier, email address, display name, profile photo, authentication provider and information needed to secure and administer your account. Google sign-in is also processed by Google under its own privacy terms. Password authentication is handled by Firebase Authentication; we do not receive your plaintext password.
Guest sessions receive an anonymous Firebase identifier. Guests can view limited content but cannot use all contribution features.
The app also records your account identifier, the Terms and Community Guidelines version identifiers, your confirmation that you are at least 18, and the time of acceptance. A copy of the accepted version is cached locally. The app records the version identifiers and time of acceptance.
Content and community activity
We process content you submit and its associated metadata, including:
- spot names, descriptions, categories, coordinates, drone suitability, images and external video links;
- feed posts, event details, comments and replies;
- votes, favourites and content ownership;
- reports, report explanations and moderation records;
- timestamps and identifiers needed to organise and secure those records.
Public contributions can be seen by other users, including anonymous guest sessions. Report records are restricted to authorised moderators and administrators and trusted backend processing.
Location data
With device permission, Sticktime accesses approximate or precise device location to centre the map, focus on you, create a spot at a selected location and support location-related features. Device permission can be changed in Android settings.
Choosing a spot's coordinates publishes that location, whether it was selected on the map or derived from device GPS. Map display makes requests to Mapbox. Typed place-search queries are sent to Mapbox's geocoding service; those queries are not confined to your device. Provider processing is described below.
Quick scouting pins are stored locally on your device and remain there until you remove them, initiate account deletion on that device, clear the app's data or uninstall the app. If you convert a pin or otherwise publish a spot, the chosen coordinates become part of that public spot.
When you start a flying session, we store your account identifier, selected spot, spot name, start time and expiry time. Other users are shown an aggregate count of active sessions at the spot. This feature does not display your identity, individual session times or live GPS position to them. Sessions end when stopped and otherwise expire after approximately eight hours; backend cleanup and updates to the public count run separately.
Images and device access
If you choose images for a spot or post, the app accesses the selected files and uploads them to Firebase Storage. Sticktime does not currently upload videos; users may provide supported public YouTube, Instagram or TikTok links.
Uploaded images are made available with the content you publish. Do not assume that every image's embedded metadata, such as camera or location information, has been removed. Image validation does not establish that all such metadata is stripped.
Embedded video providers receive requests when their player is loaded, before you press Play. The current app loads these players automatically when the relevant content is displayed and has no separate in-app provider-consent control. Provider requests can involve network information, identifiers, interaction and diagnostic data.
Technical, security and support data
We and our service providers may process IP address, device and operating-system information, app version, network information, security tokens, request logs, errors and similar technical data needed to operate, protect and troubleshoot the Service. App Check and Play Integrity help distinguish legitimate app instances from abuse.
If you report an app problem, we process your account identifier, email address, description, app version, platform and submission time.
Preferences stored on your device
Some settings are stored locally, such as scouting pins, whether a flying warning was dismissed, upload preferences and interface preferences. The app also caches spot information and images. Clearing app data or uninstalling may remove local copies; account deletion does not remotely erase copies on other devices.
3. Why we process data and our legal bases
We rely on the following legal bases where they apply:
- performance of our contract to create and administer accounts, publish requested content, provide favourites, votes, comments, events, notifications, flying sessions and account deletion;
- your consent, where required and validly obtained, for the relevant processing. Device choices govern access to location and selected images; a device permission alone does not establish consent to all provider uses;
- our legitimate interests in securing the Service, preventing fraud and abuse, maintaining Community listings, moderating content, responding to support requests and improving reliability, balanced against user rights;
- legal obligations when we must preserve, disclose or act on information under applicable law;
- vital interests or public-interest grounds only in exceptional situations involving a credible and serious threat, where permitted by law.
Where processing depends on consent, you may withdraw it without affecting earlier lawful processing. Some features will not work without the relevant permission or data.
4. How data is used
We use the data to:
- authenticate users and provide app features;
- display maps, spots, events, posts, comments, ratings and activity;
- upload and deliver user-selected images;
- show aggregate active-flying information;
- send and display relevant in-app notifications;
- remember preferences and locally saved scouting pins;
- investigate reports, enforce rules and respond to legal notices;
- detect abuse, protect accounts and maintain service reliability;
- answer support requests and process deletion requests;
- comply with law and establish, exercise or defend legal claims.
Sticktime does not include a dedicated Sticktime advertising SDK. Embedded providers can have their own advertising, analytics and diagnostic processing; the absence of an app-owned ad SDK does not mean that all provider content is ad-free or free of tracking.
5. Who receives data
Other Sticktime users
Other users, including guest sessions, can receive public creator names, account identifiers attached to contributions, spots and their coordinates, uploaded images, external links, posts, comments, events and aggregate ratings and flying-session counts. Your account profile photo can be loaded from your authentication provider for display in your account settings.
Infrastructure and external services
We use providers that process data to operate the Service, including:
- Google Firebase / Google Cloud for authentication, database hosting, file storage, Cloud Functions, App Check, configuration and infrastructure;
- Google Sign-In for optional account authentication;
- Google Play Integrity for app and device integrity signals;
- Mapbox for map display, place searches and related SDK processing;
- YouTube, Instagram and TikTok when supported external content is embedded or requested;
- Google Maps or another installed navigation service when you choose to request directions.
These services do not necessarily act in the same role for every purpose. Some processing occurs on our behalf and some occurs under a provider's own terms and privacy notices. See each provider's privacy information for its processing of data in connection with its services.
Authorities and corporate events
We may disclose information where reasonably necessary to comply with law, respond to valid legal process, protect rights or safety, investigate abuse or handle a merger, financing, reorganisation or transfer of the Service. We will apply applicable safeguards and notice requirements.
6. International transfers
Some providers may process data outside Greece or the European Economic Area. Where required, transfers will rely on an adequacy decision, approved standard contractual clauses or another lawful safeguard. Contact us for information about applicable safeguards.
7. Retention and deletion
We aim to retain identifiable data only for as long as needed for the purposes above:
- accounts: until deleted, plus any short period required to complete deletion or meet a lawful retention need;
- public spots and media: while published, subject to the removal process below;
- spot removal requests: a seven-day restoration window measured from the server-recorded removal request; final cleanup runs afterwards in scheduled, retryable batches;
- flying sessions: until stopped or expired, normally no longer than eight hours, subject to ordinary backend deletion/expiry operations;
- quick scouting pins: locally until removed or account deletion is initiated on that device, app data is cleared or the app is uninstalled; ordinary device preferences remain after account deletion;
- feed posts and their images: until the owner deletes them, the account is deleted or moderation requires earlier removal;
- comments: discussion text may remain after account deletion with the author's UID and display name removed; deleting a parent post or permanently deleting a parent spot removes the associated discussion;
- votes, favourites and notifications: the deleting account's records are removed; notifications identifying it as the actor are also removed from other users' inboxes;
- reports submitted by the deleting account: removed, including its app problem report; reports submitted by others retain their content but remove the deleted account's structured target-author reference;
- restricted moderation, administrative audit and deletion-security records: retained for up to 12 months for abuse investigation, rule enforcement, administrator accountability and preventing deleted content from reappearing;
- Storage recovery copies: the provider configuration inspected on 5 September 2026 had seven-day soft-delete retention, separate from the app's seven-day spot restoration window; these copies are not accessible through the app;
- Cloud Logging: that inspection recorded 30-day retention for `_Default` and 400-day retention for the locked `_Required` audit-log bucket;
- Firestore backups: that inspection found point-in-time recovery disabled and no scheduled backups;
- support correspondence, other provider logs and device caches: separate operational or provider retention applies; account deletion does not directly purge them;
- records connected to legal disputes or obligations: until they are no longer reasonably required;
- operational recovery checkpoints: retained as needed to resume bounded work; account or content identifiers may remain in backend-only checkpoints.
The provider configuration above was inspected on 5 September 2026 and is rechecked when configuration changes.
When a spot owner requests removal, the public spot is hidden and direct in-app reads of its original images are denied. Backend cleanup revokes existing download tokens and moves retained images into a backend-only quarantine without download tokens. Failed operations are retried. Administrators can restore the spot before the seven-day deadline, using fresh media URLs; a restoration cannot commit at or after that deadline. After seven days, unsafe or private spots are deleted from the live service by scheduled cleanup. Other spots may retain coordinates, type, drone suitability, creation date and aggregate votes as a generic Community listing. The original contributor's name, description, attribution, media and comments are removed. Comments and ratings contributed by other users, together with aggregate vote information, may remain attached to the Community listing.
During account deletion, active spots are converted to generic Community listings. Coordinates, type, drone suitability, creation date, aggregate votes and activity contributed by other users may remain. The former owner's attribution, original name, original description and media are removed. Their comments retain discussion text with author details removed. Structured copies of original spot names in events, flying sessions and notifications are replaced with generic labels. Other people's independently written posts, comments and reports are not automatically rewritten. Pending spot-removal requests are finalised without waiting for the seven-day deadline: unsafe or private locations are permanently deleted, while other eligible locations are converted to Community listings without waiting for the remainder of the recovery period.
Account deletion removes authentication access, the profile, legal acceptance, active flying session, uploaded media (including quarantine), owned feed posts, votes, favourites, notifications, account write/upload quota records and the account's role mirror from the live service. It may take multiple attempts: accepted cleanup is designed to resume through scheduled retries after interruptions. Acceptance of the request or signing out does not by itself mean all cleanup is finished. Deletion of an app account does not delete the Google account or videos hosted on external platforms.
Restricted retained records can still identify people. Examples include a moderator's UID, a role-change administrator's UID, the subject UID in a role audit, an original owner's UID in a restoration audit, deletion tombstone UIDs, and operator email addresses in maintenance audit logs. Removing author details from a comment or retaining a location is not a guarantee that its content is anonymous: free text, coordinates or contextual information can identify someone. Previously downloaded copies and separately managed logs, backups and caches are not erased by the live account-cleanup operation.
8. Your rights
Depending on applicable law, you may have the right to:
- access your personal data;
- correct inaccurate data;
- request deletion;
- restrict or object to processing;
- receive portable data you provided in a structured format;
- withdraw consent;
- complain to a supervisory authority;
- receive information about safeguards for international transfers;
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects, where applicable.
To exercise a right, contact support@sticktime.online. We may need to verify your identity. We normally respond within the period required by law.
Users in Greece may complain to the Hellenic Data Protection Authority at <https://www.dpa.gr/>. You may also contact the authority in your place of residence or work where applicable.
9. Account deletion
Registered users can initiate deletion through the app's Settings page. Recent authentication is required to protect the account; the app asks you to reauthenticate if needed. Users without access to the app can follow the email request instructions on the external deletion page.
External deletion page: <https://sticktime.online/delete-account>
If a retained Community location can still identify you or creates a safety, privacy or property concern, contact support@sticktime.online and identify the spot.
10. Security
We use measures intended to protect data, including authenticated access, Firebase security rules, encrypted network transport, role-restricted moderation functions, App Check/Play Integrity and bounded upload rules. No service can guarantee absolute security. Tell us promptly at support@sticktime.online if you believe an account or the Service has been compromised.
11. Children
Sticktime is for adults aged 18 or over. People under 18 may not create an account. If you believe a child has provided personal data contrary to this rule, contact support@sticktime.online.
The app uses an 18+ self-declaration after authentication. It does not verify identity or age.
12. Automated decisions
Sticktime does not currently make solely automated decisions that produce legal or similarly significant effects. Automated security signals may restrict a request or app instance, but users can contact support if they believe this was an error.
13. Changes to this Policy
We may update this Policy when the Service or law changes. We will publish the new version and effective date and provide additional notice or seek renewed consent where required.
14. Contact
Controller: Panagiotis Florous, sole trader registered in Greece under his personal AFM Address: Aristeidou 7, 16345 Ilioupoli, Greece Privacy, rights and support requests: support@sticktime.online