SPIN Privacy Policy

Effective date: 7 September 2026
Operator: Seo Kihyun (independent developer)
Contact: [email protected]
Home: https://spin.atit.app · Terms of Service: /terms/
The Korean text is the authoritative version; this English text is a translation with the same article structure.

Article 1 (Purpose and Scope)

  1. This policy applies to SPIN, a powerchair football tactics-board and training app made by Seo Kihyun ("the operator"), covering the web app at spin.atit.app and the desktop app ("the app").
  2. SPIN stores your data on your own device. The operator runs no server that collects user data. The single exception is a share link you create yourself: even then, all that reaches the server is a drill or training session already encrypted in your browser, whose contents the operator cannot see (Article 10).
  3. Nothing is collected or transmitted beyond what this policy states.

Article 2 (At a Glance)

Article 3 (Data Processed and How It Is Collected)

  1. Collected by the operator: none. There is no sign-up, no contact form, no contact-details collection, and no device identifier is sent to the operator. (With sync on, a device identifier — writerId — is recorded in the file properties inside your own Drive; see Article 8.)
  2. Content you enter and keep on your own device
    • Drills: tactics-board placements, paths, and free-text notes (up to 600 characters).
    • Training sessions: note text and participants (references to players in your roster).
    • Roster: player names (up to 40 characters) and an optional PF class (PF1/PF2). A PF class corresponds to a physical-impairment classification under powerchair football competition rules and is therefore sensitive data. The operator does not collect it; you record it on your own device.
  3. Technical data the app stores on your device
    • localStorage spin.prefs — all app settings: theme, playback speed, accessibility, language, whether you have seen the tutorial, sync on/off.
    • localStorage spin.board — the last tactics-board snapshot, used for the home screen.
    • IndexedDB spin — stores drills, drillSummaries, sessions, meta (drills, drill summaries, sessions, roster).
    • sync/* records inside the IndexedDB meta store — sync bookkeeping: last sync time and remote file ID per document, deletion tombstones, the connected Google account email, and a device identifier (writerId). These are not included in backup files.
  4. How it is collected: entirely by you typing it into the app, or by the app writing it to your device. None of it is sent to the operator.
  5. Your Google account email is recorded in the on-device bookkeeping described in 3-4 only if you turn sync on.

Article 4 (Purposes of Processing)

  1. Your content: creating and playing back drills, recording training sessions, managing a roster — used only on your device to provide app features.
  2. Settings and board snapshot: restoring your screen state the next time you open the app.
  3. Sync bookkeeping and Google account email: keeping the same data consistent across your devices and showing which account is connected on the settings screen.
  4. No other use. No profiling, no automated decision-making, no targeted advertising.

Article 5 (Retention Period)

  1. On-device data: kept until you delete it — in the app, by clearing site data in your browser, or by uninstalling the desktop app.
  2. Data uploaded to Google Drive: kept in your own Drive until you delete it in the app or press [Disconnect].
  3. Web access token: held in memory only and gone when you close the tab. Desktop refresh token: kept in a file on your device until you disconnect.
  4. The operator holds no personal data: a share link's ciphertext is held in a form whose contents the operator cannot read, and it is deleted 180 days after it was last opened (Article 10). Web server access logs are covered by Article 14.

Article 6 (Provision to Third Parties)

The operator does not provide, sell, or share personal data with third parties, including ad networks and data brokers. Because the operator holds no readable user data, there is nothing to provide — a share link's ciphertext cannot be opened by the operator either (Article 10). Google Drive sync, when you enable it yourself, is not a provision to a third party: it places your files in your own account's storage (Articles 7 and 8).

Article 7 (Outsourcing of Processing)

  1. No processing is outsourced under normal use.
  2. Only when you turn Google Drive sync on:
    • Processor: Google LLC
    • Task: storing your content files in the hidden app-specific folder (appDataFolder) of your own Google Drive.
    • Location: servers operated by Google outside Korea (Article 8).
    • Nature: this is your own account's storage, not the operator's. The operator cannot access those files.
  3. There is no other outsourcing. The app self-hosts its fonts and uses no CDN. The only externally loaded code is Google’s sign-in script (accounts.google.com/gsi/client), injected at that moment only for users who have turned sync on; with sync off, no external script is loaded at all.

Article 8 (Cross-Border Transfer)

A cross-border transfer occurs only if you turn sync on.

Article 9 (Google User Data — Google API Services User Data Policy)

  1. Scope requested: only https://www.googleapis.com/auth/drive.appdata. This scope reaches SPIN's own hidden folder and cannot access your regular Drive files, photos, or documents.
  2. Limited purpose: used solely to sync between your devices (uploading, downloading, and deleting files).
  3. No ads, no sale: data received from Google is never used for advertising, sold, or transferred to any other party.
  4. Not read by humans: no person, including the operator, reads this data. The files live only in your account, so it is technically impossible for the operator to open them.
  5. No server storage: SPIN does not store data received from Google on any server of its own and does not pass it to other apps.
  6. Limited Use commitment:
    SPIN's use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
  7. Revoking access: use [Disconnect] in the app's settings, or revoke it at any time at https://myaccount.google.com/permissions.

Article 10 (Share Links)

  1. What it does: sends a single drill — or a single training session, together with the drills it uses — to someone else as one link. It runs only for the drill or session you press [Share link] on; if you never press it, nothing is uploaded.
  2. What is uploaded: your browser encrypts the drill or session first and uploads only the encrypted result to the operator's server. The key that opens it lives only after the # in the link, and by web standards that part of an address is never sent to a server. Player names and team names are stripped before sharing (numbers, roles, and goalkeeper status remain). When a training session is shared its participant list is stripped as well; the session’s venue and notes are uploaded with it.
  3. What the server keeps: the ciphertext, its size, the link id, the times it was created and last opened, and a hash of the deletion key (the key itself stays only on the device that created the link). To rate-limit abuse the requesting IP address is held in memory only for a short while; it is never written to disk and disappears when the server restarts.
  4. The operator cannot see the contents either. The server has no key, so the operator cannot open the title, layout, or notes of an uploaded drill or session. There are no accounts, so who created a link is not known either.
  5. Retention: a link is deleted automatically 180 days after it was last opened, and stops working from then on.
  6. Deletion requests: the device that created the link also stores that link's deletion key (Article 3, item 3-5). Write to [email protected] with the link id (the part after /s/ in the address) and it will be deleted after verification.
  7. Anyone holding the link can open it. The key is inside the link, so whoever it is forwarded to can also see that drill or session. Do not post it publicly, and ask for deletion once you no longer need it.

Article 11 (Your Rights and How to Exercise Them)

  1. Access, correction, deletion: your data is on your device, so you can view, edit, and delete it directly in the app.
  2. Stopping processing: turning sync off in settings immediately stops any transfer to Google.
  3. Withdrawing consent and deleting: [Disconnect] in settings (a) attempts to revoke consent on Google's side, (b) actually deletes every file in the app-specific folder, including files it cannot recognise, and (c) on desktop, also deletes the stored refresh token file. Data on this device stays as it is.
  4. You can also revoke the app's access from your Google account at https://myaccount.google.com/permissions.
  5. The operator holds no personal data, so there is nothing for the operator to disclose or delete on your behalf. Questions about this policy or the app: [email protected].
  6. Entering other people's data: if you record another person's name or PF class in a roster, it is your responsibility to inform them and obtain their consent.

Article 12 (Destruction Procedure and Method)

  1. Deleting a drill, session, or player in the app removes the IndexedDB record on your device. With sync on, a deletion tombstone also removes the file on your other devices and in Drive.
  2. [Disconnect] actually deletes every file in the app-specific folder.
  3. Clearing site data in your browser, or deleting the desktop app's data folder, removes everything left on the device.
  4. The operator keeps no copies that would need to be destroyed.

Article 13 (Security Measures)

  1. Minimal collection: no personal data is transmitted to the operator. Share links are the only thing sent to the operator’s server, and what is sent is ciphertext already sealed on your device — the server holds no key (Article 10).
  2. Minimal permission: the app requests one Google scope, limited to its own folder (drive.appdata).
  3. Encryption in transit: all communication with Google uses HTTPS.
  4. Web token: the access token is held in memory only and is never written to localStorage or IndexedDB; closing the tab discards it.
  5. Desktop token (known limitation): the desktop app stores the refresh token in a file named google-refresh-token in its app data folder. File permissions are restricted to 0600, but the file is not encrypted. Another program running as the same user account can read it. Keep your device account locked and encrypted, and use [Disconnect] after using a shared machine.
  6. Desktop network restriction: the app may connect only to itself, its internal channel, and three Google domains (www.googleapis.com, accounts.google.com, oauth2.googleapis.com).
  7. Third-party code kept to a minimum: no analytics, no ad code, no CDN fonts; fonts are self-hosted. The only externally loaded code is Google’s sign-in script, and only when sync is on (Article 7-3).
  8. No auto-update: the desktop app has no updater. Security fixes require you to download and install a new package yourself.

Article 14 (Automatic Collection Devices and Access Logs)

  1. SPIN sets no cookies. No analytics, ad trackers, or error-reporting tools are included. Google’s own sign-in and consent screens, shown when you turn sync on, may use Google’s cookies under Google’s policies.
  2. localStorage and IndexedDB are on-device storage for app functionality; their contents do not leave the device.
  3. There is no service worker. "Add to home screen" relies on a manifest file only, and no code intercepts network requests.
  4. The web page contains only a search-engine ownership-verification meta tag and static structured data (JSON-LD); there are no external script tags.
  5. Web server access logs: the site is served as static files by an Apache web server on AWS Lightsail. The web server may record standard access logs (IP address, timestamp, requested path, user agent). Such logs are used only to operate the service and respond to faults and abuse; they are not used for analytics, profiling, or advertising, and are not given to third parties.

Article 15 (Children's Data)

  1. The app does not ask for your age and is not directed at children.
  2. Since the operator collects no personal data, no personal data is collected from children either.
  3. Children under 14 should use the app under the guidance of a legal guardian. If you enter a child player's name or PF class in a roster, obtaining the guardian's consent is your responsibility.

Article 16 (Data Protection Officer)

Article 17 (Remedies for Infringement)

For disputes or reports concerning personal data, you may contact the following Korean bodies.

Article 18 (Changes to This Policy)

  1. This policy takes effect on 7 September 2026 (first effective 6 September 2026; Article 10 on share links added).
  2. Changes will be announced on this page together with their effective date. Changes that are significant or disadvantageous to users will be posted here at least 7 days before they take effect.
  3. To request a previous version, write to [email protected].

Back to top · Terms of Service · spin.atit.app