Privacy policy
Last updated: 8 August 2026.
This is a translation, provided for convenience. The French version is the authoritative one: if the two ever disagree, the French text prevails.
Spoor is a private field notebook. The principle that governs this whole document fits in one sentence: what you write down is nobody's business but yours, and the service is built to collect as little of it as possible and share none of it.
There are no cookies, no advertising, no data brokers. That is why you have seen no consent banner: there is nothing to consent to. The only audience measurement is anonymous and hosted on our own server: it counts page views so we know what to improve in the interface, and it does not follow you around (§ 2a).
1. Who is the data controller
Victor Prouff, publisher of the service in a personal capacity. Contact for any question or to exercise your rights: spoor@victorprouff.fr. Full details are in the legal notice.
2. What data is processed
| Data | Why | Legal basis |
|---|---|---|
| Email address, password (never stored in plain text: argon2 hash), display name | To identify you and protect access to your notebook | Performance of the service requested |
| The date your address was confirmed, the date you accepted the terms, the date of your last password change | To prove the address really is yours — without which anyone could open an account in someone else's name —, to know which version of the terms you accepted, and to close open sessions when you change your password | Performance of the service requested |
| Transactional emails sent (address confirmation, password reset): recipient, subject and date in the server logs — never the link itself | To diagnose an email that does not arrive | Legitimate interest: keeping the service working |
| Your observations: GPS coordinates and their accuracy, date and time, free notes, types, tags, species and confidence levels | This is the content of the notebook itself | Performance of the service requested |
| Your photos, and the EXIF data they contain (date, position) | To illustrate a visit, and to pre-fill the date and place when the photo carries them | Performance of the service requested |
| Your requests to open the map over an area: coordinates rounded to a hundredth of a degree (about a kilometre), your message, and the date | To know which areas to prepare first, and to be able to reply to you. The rounding is deliberate: it points at a mountain range, not at a hide | Performance of the service requested |
| Your reports and suggestions sent from the app: the message, its kind (problem or idea), the app version and the browser used | To fix what does not work and understand what is missing. Version and browser are shown on screen before sending: nothing goes out behind your back, and without them a fault cannot be reproduced | Performance of the service requested |
| The weather conditions attached to your observations | To put an old outing back in context | Performance of the service requested |
| Technical server logs (timestamp, address requested, response code, IP address) | To diagnose failures and spot abuse | Legitimate interest (security and proper operation) |
No profiling, no automated decision-making. None of the above is cross-referenced to guess who you are or what you like.
2a. Audience measurement
Why it exists: to know what deserves improving in the interface. A feature nobody finds, a screen where people stop, a page nobody opens any more — you do not guess these things without counting a little. That is the only use made of it: these figures are not resold, not shared, and not used to target you, and they say nothing about you in particular. This notebook does not live off your data, it lives off being useful to you.
So the service counts page views, with Umami, installed on our own server: no data goes to a third party, and there is nothing to switch off in a dashboard that would not belong to us.
What is recorded: the page visited, the page you came from, the device type, the browser, the language and the country. What is not: no cookies, and not your IP address — it is used to work out the country, then thrown away. To tell two visitors apart without naming them, the tool computes a fingerprint from the IP address and the browser, with a salt that changes every day: within a single day your page views count as one visit, and from one day to the next nothing links them any more.
Legally this is legitimate interest: an anonymous, cookie-free measurement does not require your prior consent, and that is precisely why this tool was chosen over another. If merely being counted bothers you, your browser's Do Not Track option is honoured, and any blocker is enough to stop the measurement: the app works exactly the same.
3. What is stored on your device
To work without a network, the app keeps locally, in your browser: a copy of your observations, the queue of entries waiting to be sent, the map areas you have downloaded, your sign-in token (valid for 30 days) and your display preferences. These are technical data needed by the service, not trackers — they are read by nothing other than the app itself.
They are erased when you deliberately sign out, and when another account signs in on the same device. Signing out warns you if entries are still unsent.
4. Who else sees your data
Nobody, among the other users
Every record carries its owner and every query filters on it. There is no sharing, publishing or cross-viewing feature at all. The service's admin interface gives access to accounts, their permissions and some volumetrics (number of observations, size of photos) — never to the content of an observation nor to its position.
Third-party services, and only what they strictly need
An important point: these services are called by our server, not by your browser. So they receive neither your IP address, nor your identity, nor any means of tying a request to a person.
| Service | What it receives | Country |
|---|---|---|
| Open-Meteo — weather | Coordinates and a date, not tied to any account | Germany (EU) |
| iNaturalist — species reference data and photos | A species name being searched, or an area for “around a point” | United States |
| Wikipedia — species descriptions | A species name | United States |
| Photon (komoot) — place search | The text you typed and the map view, not tied to any account | Germany (EU) |
Base maps, relief and aerial imagery are served from our own server. So no mapping provider receives the list of places you look at — which is not a small thing for a notebook whose positions are precisely where the value lies.
The host
The server is rented from Hostinger International Ltd, and sits in a European Union
data centre. Like any host, it has technical control of the machine. The service's
emails — address confirmation, password reset — go out from the
spoor@victorprouff.fr mailbox, hosted with the same provider, which
therefore carries those messages. No other data is entrusted to a third party: no
outsourced image storage, no third-party email sending service, and the audience
measurement runs on our own machines (§ 2a) — no third-party analytics tool.
5. For how long
- Your observations and your photos: for as long as your account exists. They do not expire — a field notebook is worth exactly what its age makes it worth.
- When your account is deleted: everything is deleted, in cascade and with no residual copy — observations, sites, photos, tags, preferences.
- A registration never confirmed: the account is deleted automatically after seven days. So if someone signs up with your address, it does not stay taken — and you are told by email at the time of the attempt.
- Confirmation and reset links: only a hash of the link is kept, never the link itself. It is erased one day after expiry.
- Your map coverage requests: kept as long as the area is not open, then for as long as it takes to tell you that it is.
- Technical logs: kept for the length of ordinary diagnosis, on the order of a few weeks.
- Backups: database and photo backups run on a rolling window. So deleted data may survive there for a few days before rotation erases it for good.
6. Your rights
The General Data Protection Regulation gives you a right of access, rectification, erasure, portability, restriction and objection. In practice:
- Rectification: the app's “Account” page lets you change your name, your email address and your password. Your observations can be edited at any time.
- Access and portability: self-service export does not exist yet. In the meantime, write to me and you will receive all of your data in an open, readable format, within 30 days and without condition.
- Erasure: on request, your account and everything in it are deleted. Ask for the export first — there is no going back.
One address for all of this: spoor@victorprouff.fr. If an answer does not satisfy you, you can refer the matter to the French data protection authority, the CNIL.
7. Security, and its limits
Everything travels over HTTPS. Passwords are stored as argon2 hashes, never in plain text, and cannot be read back — which is also why a forgotten password is reset rather than recovered. Photos are only served after the sign-in token has been checked. The database and the photos are backed up.
What you should know all the same: this service is run by one person, on a modest server, with no independent security audit and no availability commitment. If your locations are sensitive — the nest site of a protected species, a place vulnerable to disturbance or to poaching — weigh that before entrusting them to any service at all, this one included.
8. Changes
This document will change along with the service. Any significant change — a new recipient, a new purpose, a new piece of data collected — will be announced to you by email before it takes effect, and not merely by a date quietly updated at the top of this page.