Pattio · legal
Privacy policy
Last updated: 22 September 2026 (version 1.1)
In three sentences
Pattio works entirely on your device and without an account: if you never create one, there is nothing of yours anywhere on our side. If you do create one, what you sync travels encrypted with a key that only your devices hold and that we neither have nor can recover. The one exception, and we say it plainly because it matters, is what you deliberately share: that has to be readable by the server so the people you invite can open it, and therefore we could read it too. And it is exactly that and nothing more: if you share a single item, the server can only read that item and the name of the board it comes from; the rest of the board — the other notes, the zones, the scribbles — stays encrypted. If you share the whole board, then it really is everything.
The app carries no advertising, no trackers and no sale of data to anyone, and that will not change. What there is, since August 2026, is pseudonymous product analytics: a handful of action names — “the app was opened”, “a poll card was added” — with no text of yours, no identifier of yours and no figures, on servers in the European Union, and with a switch to turn it off in Pattio’s Settings ▸ Your data ▸ Privacy (§3.7). We say “pseudonymous” and not “anonymous” because a random identifier for this installation goes with it — it is not your name, not your email and not your account, and it is erased when you turn the switch off. Separately, the page that opens when someone follows a shared link has its own page-view analytics, which only runs if the visitor says yes (§3.6), and this very site has its own (§3.11).
1. Who the data controller is
There is no data protection officer: this activity is not among those for which article 37 GDPR requires one.
- Controller: Joan Cama Ribot
- Trading name: Somia Digital
- Tax ID (NIF): 41531670H
- Address: Carrer de Sant Joan, 17200 Palafrugell (Girona), Spain
- Contact email: hola@somiadigital.com
2. The principle: local first
Pattio is a local-first app. The boards, the notes, the photos, the drawings and everything else you put in are stored in your device’s database. Without an account, not a single byte leaves the phone for any server of ours: there is no copy in the cloud, and no identifier or file of ours anywhere.
Creating an account is optional and serves one purpose only: syncing between your devices and, if you want, sharing boards.
3.1. The account
If you sign in with Apple, you can hide your email: Apple gives us a relay address and we never see the real one. If you sign in with Google, Google handles the verification. The app asks Apple for your full name but does not store it anywhere: it only uses the identity token.
The key fingerprint is a shortened cryptographic digest (truncated SHA-512). It does not allow the key to be reconstructed or anything to be decrypted: it can only be used for comparison.
Your acceptance of the Terms is stored on your device when you finish (or skip) the welcome tour, and it records only two things: the document version and the timestamp. No identifier, no language, no personal data. If you have an account it travels inside the encrypted vault like everything else — so we cannot read it — and if you do not, it never leaves the device. Anyone who already had Pattio installed before this existed has none, and we do not invent one for them: an acceptance nobody ever saw is not proof.
- Email address — identify you and let you in (email code, Apple or Google) — legal basis: performance of the contract, art. 6.1.b GDPR — as long as the account exists.
- User identifier (UUID) — tie your content to your account — art. 6.1.b — as long as the account exists.
- Key fingerprint (key_check) — warn you if a device is carrying a key that is not yours — art. 6.1.b — as long as the account exists.
- Which version of the Terms you accepted, and when — being able to say which version of the contract you accepted and on what day — art. 6.1.b (proof that the contract exists) — as long as the account exists.
3.2. The content of PRIVATE boards
This content travels and is stored end-to-end encrypted with XSalsa20-Poly1305 (NaCl secretbox). The key is generated on your device, lives in the iOS Keychain and never reaches us. What we see is an unreadable block of bytes.
How the key gets to your second device, and what that costs. So that signing in to the same account on your iPad or Mac does not force you to transcribe anything, the key is also stored as a synchronisable Keychain item (the iCloud Keychain): that way it travels on its own between the devices of your own Apple Account, end-to-end encrypted by Apple, and it never passes through our server. We still do not see it.
What that costs, and we say it here rather than in a footnote: it ties the security of your content to that of your Apple Account — whoever gets into a person’s iCloud Keychain has the key that decrypts their boards. It is exactly the same deal the Keychain already makes with all of that person’s passwords, including the one for their bank. The recovery code still exists and is still the fallback: for anyone with iCloud Keychain switched off, for a change of Apple Account, and for anyone who wants a key that does not depend on Apple.
If you lose the key and the recovery code, nobody can recover what was there — not us either. That is the price of real encryption, and it is worth knowing beforehand, not afterwards.
Data processed: encrypted content of boards, zones, items and strokes, and encrypted files (photos, videos, scans, drawings, documents) — purpose: syncing your content between your devices — legal basis: art. 6.1.b GDPR — retention: until you delete it or delete the account.
What we do see, even though the content is encrypted (and there is no way to hide it if we want syncing to work):
- which table each row belongs to (an item, a board, a zone…);
- the row’s identifier (a UUID generated on your device, meaningless in itself);
- the timestamps of creation, modification and deletion;
- the path and the size in bytes of each file, because that is how we count the space you take up and it is what we bill you for.
- In other words: we can know that you have 412 items and that you touched one on a Tuesday at eleven, but not what it says.
3.3. The content of what you SHARE
There is no end-to-end encryption here, and that has to be said plainly. What opens in the browser of someone who does not have your key has to arrive there readable, and therefore it is stored readable on the server. While it is shared, its content and its photos could be read by whoever administers our infrastructure. When you stop sharing it, it goes back to travelling encrypted.
And “it” is exactly what you shared and nothing more. There are two scopes, and both are spelled out in plain words before you commit: if you share a single item, what leaves in the clear is that item, its photos, and the name (with the emoji and the colour) of the board it comes from — the page the recipient sees has to be able to say where it is from — and the rest of the board stays encrypted; if you share the whole board, then everything does leave in the clear: every note, the zones, the scribbles, the notebooks and the photos.
The practical rule: if you would not upload something to a server, do not share it by link.
The people you invite get an anonymous session: we ask them for no email, no account and no data beyond the name they type themselves.
Exactly who sees a guest’s name. The name exists so that, in a poll, people know who voted for what — which means the other people who can read that same thing see it, and nobody else. And one clarification that runs the other way and is also true: votes by the owner and by members with an account come out with no name, because they are not on the guest list. The page shows the name when it knows it, and always shows the count; it never invents a “Someone”.
- The content and files you share, held IN THE CLEAR — so the people you invite can open them in a browser — art. 6.1.b — until you stop sharing it or delete it.
- Email of the people invited — give them access when they sign in with that email — art. 6.1.b — until you withdraw the invitation.
- Name typed by whoever opens a guest link — so everyone else knows who wrote what and who voted — art. 6.1.b — until sharing stops.
- Poll votes on a shared board — count the votes — art. 6.1.b — the same.
- Link tokens — open the board without an account — art. 6.1.b — until you revoke it.
- If what is shared is the whole board, the guest’s name is seen by those who have the board (owner, members and the other guests of that link).
- If what is shared is a single item, the name is visible only through that item, and only for the guests who actually voted on it: opening the link to one poll does not hand over the board’s guest list.
- A guest’s link token is never visible to any other guest. The server serves only their name and the vote identifier, never anything else from their row.
3.4. Purchases
Subscriptions are charged by Apple through your App Store account: we never see your card, your billing name or your address. What tells us “this person has Plus” is RevenueCat, a subscription intermediary we pass your user identifier to (and nothing else: not your email, not your name). Their SDK independently collects technical device data in order to do its job (for example Apple’s vendor identifier, the device model and the country); that is their doing, and it is described in their own policy.
- User identifier and history of purchases and renewals — know which plan you have and how much space you get — art. 6.1.b — as long as the account exists.
3.5. Device permissions
Pattio does not ask for access to contacts, health data, Bluetooth or the local network, and it never uses location in the background.
Reminders are LOCAL, and that means something concrete. When you ask a countdown, an upcoming event or a habit to remind you, Pattio tells your phone’s own operating system to wake you at a given time. There is no server involved, no notification token, no registration of your device and no remote sending: we never receive any of your reminders and we cannot know whether one reached you or whether you opened it. What appears on the lock screen is the item’s title and nothing else — never what the card holds inside.
The Spotlight index carries titles and nothing else. So that you can find a board or a card from your home screen search, Pattio leaves in the Spotlight index the board’s name, the item’s title, its emoji and the link that opens it. Nothing else: not the body of a note, not the lines of a list, not a transcription, not a thumbnail. That index belongs to your phone’s operating system: it lives on the same device, nobody syncs it and we never receive anything from it. If you uninstall the app, it goes.
The app lock is handled by iOS, and we receive nothing about you. If you turn the lock on (iOS Settings ▸ Privacy ▸ Lock), Pattio asks the SYSTEM to recognise you with Face ID, Touch ID or your device passcode. Pattio never receives any biometric data — not your face, not your fingerprint, not your passcode: what reaches it is a yes or a no, and nothing is stored and nothing leaves the phone. The only things stored are whether the lock is on and how long it waits before asking again, and both are settings on this device that never leave it.
And the lock can switch itself off, in one case and one only. If you remove your phone’s passcode while Pattio’s lock is on, that device no longer holds any key that could open it: Pattio then opens anyway, tells you so with a notice, and saves the setting as off. This is deliberate, and we say so here because it is a decision and not a bug — a local lock is a curtain against whoever is holding the phone, not a safe against you. The strict reading would shut you out of your own notes for good, with no way even to reach the switch that turns it off. For the same reason, if the setting cannot be read, the app opens.
- Camera — when you take a photo to put on the board — the photo goes on the board, like any other.
- Photo library — when you pick a photo or a video — the same.
- Location (while in use only) — only when you tap “Current location” — the coordinates are turned into an address by Apple. If you save the card to a synced board, they go there encrypted (or in the clear if the board is shared). The weather never asks for this permission: if you have already granted it, it reads the last stored point and rounds it (§3.10).
- Microphone and speech recognition — when you tap “Record” to put a voice note on the board or to dictate a list — the sound stays on your device: the transcription is done by your own phone and is sent neither to us nor to Apple.
- Calendar and Reminders — when you put a scheduling card on a board — they are read on the device and do not leave it. We upload nothing anywhere.
- Notifications — the first time you switch on a reminder for an item, never at launch — nothing: your own device schedules and delivers the reminder.
3.6. The guest web portal and its analytics
This section is about the web page ONLY — the one that opens when someone sends you a Pattio link (app.pattio.app). What this section describes — Google Analytics, cookies and a banner — does NOT exist inside the app and never will. The app has its own product analytics, which is a different thing, with a different provider and its own switch: §3.7.
What the portal always stores, and why we do not ask for permission. When you open a link, the browser stores an anonymous session, and that session is what lets you into the board. Without it there is no page. This is strictly necessary storage for delivering the service you asked for, and Article 5.3 of the ePrivacy Directive therefore exempts it from consent. We do not ask permission for the one thing without which the link would not open.
What the portal does NOT do without your permission. If the portal has analytics configured, before measuring anything it shows you a notice with two equally easy options: accept and reject. Until you answer — and also if you say no — not a single byte is downloaded from Google and no measurement cookie is stored. The page looks and works exactly the same whether you say yes or no: there is no wall.
Data processed: page view (which of the three page types, approximate country inferred from the IP, browser and device type) — purpose: knowing how many people open shared links — legal basis: art. 6.1.a, your consent, and nothing else — retention: whatever the Google Analytics property is configured to keep.
What is NEVER sent, and this is the part that matters: the link token (the key to the board), any board or item identifier, any guest name, any content. The path that is sent is not the one in the address bar but one of three fixed strings (/convidat, /e or /), written into the code for that single purpose. There are no custom events either: one page view and nothing more.
Who processes it. Google Ireland Limited / Google LLC as processor, with the IP anonymised (Google Analytics 4 does this by default), with Google signals and ad personalisation switched off, and with Consent Mode v2 configured with every permission denied by default. Transfers to the United States rely on the standard contractual clauses and on the EU–US Data Privacy Framework (§4).
You can change your mind at any time. At the foot of every page of the portal there is “Cookies”, which reopens the question. Your choice is remembered for twelve months in your own browser and carries the version of the purposes it covers: if those ever changed, you would be asked again rather than have an older “yes” reused.
And right now this is switched off. As long as no analytics property is configured for the portal, there is neither a notice nor any measurement: the page only stores the anonymous session described in the first paragraph.
3.7. The app’s product analytics
What it is. Since August 2026 the app sends a handful of pseudonymous usage measurements that serve exactly one purpose: knowing which features actually get used, so we can decide where the work is worth doing. It is not advertising, it is not tracking, and it has nothing to do with the web portal’s measurement (§3.6), which is a different system, in a different place, answering a different question.
You can switch it off in one tap, and you lose nothing. The switch is in Pattio’s Settings ▸ Your data ▸ Privacy. It ships on, and that same screen shows you — read from the code rather than written by hand — the complete, literal list of the names the app knows how to send. Turning it off takes no feature away.
What is NEVER sent, and this is the important part: no text and no content of yours (no titles, no notes, no photos, no files, no drawings), no identifiers for boards, items or shared links, no names or email addresses, no figures (not how many boards you have, not how much space you use, not a single coordinate) and nothing about who shares with whom. The code holds a filter with a closed list of what may leave the device, there is no path around it, and automated tests check this on every change.
And nothing about your device goes out either. Measurement services send the screen size, the device model and type, the operating system and its version, the language and the time zone by default. Pattio strips all of that before it leaves the device, with the same closed-list filter.
Pseudonymous, and the word matters. No user identifier is sent, your email is not sent and no profile of a person is built. IP-based geolocation is disabled and session replay is disabled too: the app never records the screen. That said, the random installation identifier stays the same while the switch is on, so measurements from one device can be grouped together. That is not anonymity within the meaning of the GDPR — it is pseudonymisation — and it is why the legal basis is legitimate interest (art. 6.1.f) with a right to object.
Where it goes. To PostHog (EU Cloud, Frankfurt, Germany, European Union), at eu.i.posthog.com, as a processor (§4). And if the app carries no key for the service, it sends nothing: a build compiled without it stays “on hold” and nothing is initialised, even if the switch looks on.
- The name of an action taken in the app, and nothing more: opening the app, finishing the welcome, opening the guide and creating a board carry nothing else. Four of them carry one label from a closed list: switching view (pinboard or grid), adding a card (note, poll, photo…), changing the theme (light, dark or the system’s) and starting or completing a purchase (Plus or Pro) — purpose: knowing which features get used, so we can decide what to work on — legal basis: art. 6.1.f, legitimate interest, with a right to object that is literally the Privacy switch — retention: the event retention configured on the PostHog project.
- The app version that sent the measurement — knowing which build a signal came from — art. 6.1.f — the same retention.
- A random identifier for this installation, minted by the measurement service, which is not your name, not your email and not your account — so that two measurements from the same device are not counted as two people — art. 6.1.f — the same retention, and it is erased from the device when you turn the switch off.
3.8. What we do NOT process
So that it is on the record and can be checked by opening the code:
- No analytics that track you. There is no Firebase, no Amplitude, no Mixpanel, no Segment, and nothing that follows you from one app to another or across the web. The only measurements anywhere in the project are the app’s product analytics (§3.7), which are pseudonymous, carry a switch and rest on legitimate interest, the guest portal’s page views (§3.6) and this website’s (§3.11) — the last two only with your permission.
- No automatic crash reporting. There is no Sentry and no Crashlytics.
- No push notifications and no device tokens. Pattio’s reminders are scheduled and delivered by your own phone (§3.5): there is no delivery service involved and we register no device anywhere.
- No advertising and no ad network.
- No tracking. The app does not ask for tracking permission (ATT) because it does not need it: it does not use the IDFA or any advertising identifier, and it does not share any data of yours with third parties for advertising purposes or with any data broker.
- No profiling and no automated decision-making with legal effects (art. 22 GDPR).
- No sale and no transfer of data to anyone.
3.9. Artificial intelligence: all of it on your device
In this version there is no active cloud AI path at all. Pattio does not offer to read a photo, a scan or a link and suggest what to make of it (“smart capture”), and there is no assistant inside the app. Both features are written and tested, but they are shown nowhere — no button, no row, no command — and so there is nothing that could send any text to any AI server. That is also why this version asks you for no AI permission: there is nothing to permit. The day they come back, this section will explain the whole thing again, before anything happens.
What Pattio does do, it does entirely INSIDE your phone, and it is three things: reading the text in your photos and scans so you can find them again by the words that appear in them (that is Vision, Apple’s text recogniser, on the device and in the background); meaning-based search, with Apple’s embeddings model on the device; and dictation of a note or a checklist, with Apple’s speech recogniser forced to work offline. In none of the three does anything leave the phone.
The text in photos, in detail. What is read is stored inside the card, in your encrypted vault, and is therefore your data, just like a photo caption: it is never shown as text on any screen — not on the card, not in the PDF, not on the web page of a shared board — and the only thing the app does with it is let you search it. If you share the board, it travels with the card along the same path that already carries the full photo.
With one caveat worth spelling out: the summary of a shared board — the list of topics your guest sees at the top of the page — is built from the words that come up most often across the cards, and the words of a photo that has been read count like any others. It can only happen if you have shared the whole board.
You can turn it off in Pattio’s Settings ▸ Privacy ▸ “Read the text in photos”. No more will be read after that; text already read stays inside its cards, and to remove it you delete the photo.
3.10. The weather
Pattio shows the weather in two places: the home screen widget and the “Weather” item you can pin to a board. Both work the same way and this paragraph covers both.
The forecast comes from Apple WeatherKit, the operating system’s service. There is no other provider: when WeatherKit does not answer, nobody else is called and the card says so in words.
What leaves the device: two rounded coordinates and nothing else. Before anything is looked up, the position is rounded to one decimal place of a degree — about 11 km — enough to get the weather right and far too little to say where you are. No identifier goes with it, nor your account, nor any board data. The request is made by iOS on the app’s behalf and is governed by Apple’s WeatherKit data policy.
Where the position comes from, and what we do NOT do to get it. The weather “wherever you are” reads the last point the system already had stored: it does not switch on the GPS, it asks for no permission, and it never uses location in the background. With no location permission granted there is no request: the card explains it and you can pick a fixed place, which is the only thing stored on the row.
What is stored. Nothing of the weather is stored, except a copy of the last reading (the degrees, the condition and the time) inside the card, so that the PDF you export and the guest web page can show something. None of this is sent to any server of ours, and the rest of the forecast lives in memory only and expires within an hour.
3.11. This website: the support form and the analytics
This section is about pattio.app ONLY, the page that presents Pattio. There are no user accounts here and the content of your boards never passes through it.
If you write to us from the support form, you leave us your email address, your message and the language you are browsing in; the name is optional and you can leave it blank. We use them to answer you, and for nothing else. The legal basis is your consent (art. 6.1.a GDPR), which you can withdraw at any time by writing to hola@somiadigital.com. The form is handled by Netlify, the processor listed in §4 that hosts the site: the message stays in its dashboard and reaches us by email. We keep it for as long as it takes to deal with your query and, at most, twelve months after it is closed.
This site also uses Google Analytics 4, and only if you accept it in the cookie notice. If you do not answer, or if you decline, not a single byte is downloaded from Google. The detail of what is stored in your browser and how to change your choice is in the Cookie policy (/cookies).
4. Who else touches it (processors)
We have no servers of our own: we rent other people’s. All of them have a data processing agreement in place (art. 28 GDPR).
International transfers. RevenueCat, Apple and Google are in the United States. These transfers are made under the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework. Netlify is in the United States too, and the basis for that transfer is the European Commission’s Standard Contractual Clauses incorporated in its data processing agreement. You can ask us for a copy of the safeguards at hola@somiadigital.com.
- Supabase Inc. — database, authentication and (depending on the configuration) file storage for the app — eu-central-1 (Frankfurt, Germany), in the European Union.
- Cloudflare, Inc. (R2) — file storage, when enabled: today it is NOT — Cloudflare’s global network.
- RevenueCat, Inc. — subscription status — USA.
- Apple Inc. — payment, Sign in with Apple, maps, song search and the weather (WeatherKit, §3.10) — USA / global.
- Google LLC — Sign in with Google, only if you choose that sign-in method; and the web pages’ page-view analytics, only if you consent (§3.6 and §3.11). Gemini plays no part in this version: there is no cloud AI path at all (§3.9) — USA / global.
- PostHog, Inc. — the app’s product analytics, pseudonymous and only while you leave it on (§3.7) — EU Cloud, Frankfurt, Germany, European Union (eu.i.posthog.com).
- Netlify, Inc. (San Francisco, United States) — hosting for this website and for the guest portal, and this site’s support form (§3.11).
Third parties that see your IP (and why)
There are three moments when your device talks directly to someone who is not us. We send them nothing of yours; you go there yourself.
- Link previews. When you paste an address — or when you share a page into Pattio from another app — Pattio goes and fetches its title and image directly from your device. That website sees your IP, just as if you had visited it with your browser. (We do it this way on purpose: routing it through a server of ours would mean we saw every link you save.) For a handful of well-known platforms — YouTube, Reddit, Spotify, Instagram, Facebook, TikTok, Pinterest — we request the card from their own embed service instead of reading the page, and the cover image is stored on your device, because their addresses expire within a few days.
- Song search. What you type goes to Apple’s iTunes search.
- Maps and addresses. Maps and the translation of coordinates into an address are done by Apple.
5. How long we keep it
- As long as the account exists, whatever you have synced to it.
- If the subscription expires or you cancel it, nothing is deleted that same day: you go back to the free plan, everything can still be read and downloaded, and the only thing that is blocked is uploading more while you are over quota. There is a 30-day grace period, with in-app warnings that state the exact date; after that, only the excess is withdrawn (from the oldest to the newest) and what is withdrawn lives another 30 days in the bin, where it can still be recovered by renewing. On day 60 there is no going back. The full timetable, with the numbers, is in §9 of the Terms and conditions (/termes).
- Deletion tombstones. When you delete an item, we keep its row with a “deleted” marker and with no content, so that your other devices know it has to disappear there too. That is sync machinery, not your content, and it goes away with the account.
- Emptying the bin deletes the files from the server, not just from this device. When you remove an item from the bin “for good”, the photos and files that belonged only to it have their space reclaimed on this device straight away and their cloud copy is deleted from storage as soon as this device has synced. Your device decides this, not us, and the reason is the encryption itself: we cannot know which files you still use. Files that also belong to another item you are keeping are not deleted.
- Deleting the account really does delete everything: the rows, the files, the key fingerprint and your user. You can do it yourself from the app, and what you have on the device stays on the device.
- Backups. The database provider makes routine backups; a deleted piece of data may survive in them until the backup expires (30 days at most). Once expired, it is nowhere any more.
- The message you send us through this site’s support form, for as long as it takes to deal with your query and, at most, twelve months after it is closed (§3.11).
6. Portability: the button that is always there
In Pattio’s Settings ▸ Your data ▸ Download all your data there is a button that gives you a ZIP with everything: all the boards in JSON and all the original files byte for byte.
This covers your right to portability (art. 20 GDPR) and the obligation under article 119 ter of the TRLGDCU (Spain’s consumer code), and your device does it all on its own: the ZIP passes through no server of ours.
- It is free, on the free plan too and also if the subscription has expired.
- It is self-service: no need to write to us, no waiting, no asking permission.
- It is machine-readable: JSON and original files, with no need for Pattio.
7. Your rights
You have the right to access your data, to rectify it, to erase it, to restrict its processing, to object to it and to portability. If something is based on your consent, you can withdraw it whenever you like (withdrawing it does not make unlawful what had already been done).
To exercise them, write to hola@somiadigital.com. We answer within one month at most. We may ask you to confirm who you are, and that is all.
A good part of these rights you can exercise yourself and instantly, without writing to anyone: the export ZIP (access and portability), deleting items (erasure), stopping sharing a board (objection), deleting the account (total erasure), the app’s Privacy switch (objecting to the product analytics, §3.7) and the cookie settings button (withdrawing or re-granting consent for the web analytics, §3.6 and §3.11).
An honest limitation: because private content is encrypted and we do not have the key, we cannot give you a readable copy of what is on the server, nor rectify anything on it from the outside. Only your device can do that, because only it holds the key — which is why it is the device that produces the export.
If you think we are not doing it right, you can complain to the Agencia Española de Protección de Datos (the Spanish data protection authority: www.aepd.es, C/ Jorge Juan 6, 28001 Madrid). If you are in another country, you can also complain to your own supervisory authority. We would be grateful if you told us first, but you do not have to.
8. Security
No system is infallible. If there is ever a security breach that puts you at risk, we will tell you and the AEPD within the deadlines of article 33 GDPR.
- End-to-end encryption of private content (NaCl secretbox, XSalsa20-Poly1305), with the key in the device’s Keychain and never on the server. If iCloud Keychain is on, the key travels between your devices over Apple’s transport, end-to-end encrypted by Apple (§3.2).
- TLS on all traffic.
- Row Level Security in the database: each row checks, in the database itself, who is allowed to read it, rather than relying only on the client behaving well. Queries that have to cross the boundary of a guest link go through server functions that return only the necessary columns — the name of whoever voted, for instance, never their link token.
- The file credentials are not inside the app: access URLs are signed by a server function that first checks whether you are entitled to that board, and the URLs it hands out expire after a few minutes.
- Guest links can be revoked whenever you like.
- No advertising or crash-reporting SDK inside the app: what is not there cannot leak. The only thing the app sends to a third party is the product analytics of §3.7, which passes through a closed-list filter that lets out no text, no identifiers and no figures.
9. Minors
Pattio is not aimed at children under 14 and we do not deliberately ask them for data. That is the age from which Spanish law lets you consent to the processing of your own data (art. 7 LOPDGDD), and it is the same age the Terms and conditions require (§3): both documents state the same number on purpose.
If we realise we have processed the data of a child under 14 without the consent of whoever holds parental responsibility, we will delete it. If you are a mother, father or guardian and you think this has happened, write to us at hola@somiadigital.com.
10. Changes to this policy
If we change something that matters, we will change the date at the top and, if the change is substantial, we will tell you inside the app before it takes effect. Older versions can be requested by email.
This policy is provided for information, not accepted: the GDPR does not allow you to “accept privacy” as a block. The specific choices are each made in their own place and can be changed whenever you want: consent for the web pages’ analytics (§3.6 and §3.11) and the objection to the app’s product analytics, which is the Privacy switch (§3.7). What you do accept are the Terms and conditions (/termes), and the app stores their version and date (§3.1).