Privacy policy
This policy describes the data Spray Social collects, why it collects it, where it is hosted and which rights you can exercise. We have tried to write it so that it can be read, not merely complied with.
We do not sell your data. We do not transfer it outside Europe. We do not geolocate you. We do not keep your IP address. We do not build an advertising profile.
Last updated: August 2026
Data controller
The data controller is the publisher of Spray Social, identified in the legal notice.
For any question about your data or to exercise your rights: contact@spraysocial.com
You may also lodge a complaint with the French data protection authority (CNIL), or with the data protection authority of your country of residence.
Data we collect
Account data
Email address, username, first and last name, display name, password (stored as a hash, never in clear text), date of birth, display language, date of last login, and where applicable profile picture, banner and biography.
Published content
Posts, comments, polls, events, predictions, images and audio files you choose to publish, along with your interactions: likes, shares, follows, participation in community verification.
Human verification
At registration, an automated mechanism verifies that the account is indeed being created by a human being, and not by a bot or a computer program. This verification runs on our own infrastructure, with no transmission to a third-party service, and produces no biometric or behavioural data that is retained.
Reports and moderation
When you report content or an account, we keep the reason, the timestamp, the identifier of the reported account and that of the reporting account. Moderation decisions and their grounds are kept in the same way.
Usage statistics
We count the number of logins, registrations and posts per day and per device type (web, iOS, Android). These counters are aggregated: they are not linked to any user and identify no one.
What we do not collect
We do not keep our users' IP addresses. An IP address is only recorded for administrative actions carried out on the service, for security purposes, and for addresses explicitly blocked or allowed.
We collect neither your geographic location, nor your contacts, nor your address book, nor your advertising identifiers, nor your browsing history outside Spray Social.
Our hosting provider keeps its own technical access logs for its servers, under the conditions and for the periods laid down by the regulations applicable to hosting providers. We do not access them in the ordinary course of running the service.
Why we process this data
Performance of the contract: creating and managing your account, publishing and displaying your content, delivering emails related to your account, operating messaging and the features you access.
Legitimate interest: ensuring the security of the service, preventing fraud and automated accounts, protecting minors, moderating content, preventing repeat offences after a sanction, measuring use of the service in aggregate form, improving it.
Legal obligation: cooperation with judicial authorities and compliance with the retention obligations incumbent on us.
We send you no commercial or promotional communication. The only emails you receive are those necessary for your account to function. None of our purposes includes targeted advertising, commercial profiling or the resale of data.
Who processes your data
Spray Social uses three processors, all established in the European Union. Each accesses only the data strictly necessary for its task.
OVHcloud, a French company. Hosts the entire infrastructure and the databases, in Gravelines (France) and Milan (Italy).
Brevo, a French company, servers in the European Union. Delivers the emails related to your account: email address verification, password reset, security and moderation notifications. Brevo processes your email address, for that sole purpose.
Mistral AI, a French company, processing within the European Economic Area. Analyses posts for moderation purposes, carries out source verifications on request, and computes the indicators of the Plurality Observatory.
No other third party receives your data. No advertising network, no data broker, no external analytics tool is integrated into the service.
Geolocation
Spray Social does not collect your geographic location, does not track it and does not infer it from your activity, neither at registration nor while you use the service.
In the Events space, it is the events that appear on the map, based on the location their author entered voluntarily. That location concerns the event, not the person publishing it.
Browsing the map reveals to us neither your position nor your movements. Your browser sends us no coordinates.
Encrypted messaging
Private messages are end-to-end encrypted. Encryption and decryption take place entirely on your device.
We cannot read the content of your messages. We do not hold your private keys in any usable form. We therefore cannot disclose them to anyone, including at the request of an authority, because they are technically inaccessible to us.
Private messages are not subject to any automated analysis, by artificial intelligence or otherwise.
Messages are deleted automatically after 24 hours. Once deleted, they cannot be recovered by you or by us.
If you lose your private key, for example by clearing your browser data, past encrypted messages become permanently unrecoverable. We cannot restore them.
Automated processing and artificial intelligence
Every post is analysed automatically when it goes online, in order to detect content contrary to our rules. This analysis concerns the published content, not your person: no individual profile is built from these analyses.
Content may be hidden or removed following this analysis. Any automated decision can be contested and reviewed by a natural person, on simple request.
These systems are not infallible. Legitimate content may be wrongly flagged, and problematic content may go unnoticed.
The Plurality Observatory measures the diversity of debate from aggregated data. It classifies no opinion, attributes no orientation to a user and produces no individual profiling.
Minors
Registration is reserved for people aged 16 or over. This threshold is more demanding than the one set by French law.
Accounts of users aged 16 and 17 are subject to protections that are active by default and cannot be disabled: private messaging is inaccessible to them, and the entire gamification system is switched off.
These protections rely on the date of birth declared at registration. To date, we do not implement third-party certified age verification. We prefer to say so plainly rather than suggest a guarantee we do not have.
A dedicated reporting reason makes it possible to raise the alarm about a minor being put at risk. These reports are handled as a priority.
Retention periods
Account data: for the entire duration of your use of the service.
After account deletion: 30 days, unless a legal obligation requires longer retention.
Encrypted messages: 24 hours, automatic deletion.
Reports and moderation decisions: 12 months from the decision, to allow appeals to be handled and repeat offences to be detected.
Logs of administrative actions: 12 months maximum.
Aggregated usage statistics: kept without time limit, as they concern no one in particular.
Registrations refused on age grounds: kept in aggregated, non-nominative form.
Your rights
The General Data Protection Regulation grants you the following rights, which you may exercise at any time by writing to us.
Access: obtain a copy of the data we hold about you.
Rectification: correct inaccurate information, directly from your settings or by writing to us.
Erasure: delete your account and your data, from your profile settings or on request.
Portability: receive your data in a structured, machine-readable format.
Objection and restriction: object to certain processing based on our legitimate interest, or request its restriction.
We respond within one month. This period may be extended by two months for complex requests, in which case we inform you.
Security and data breach
We implement technical and organisational measures intended to protect your data. They are described in Section 15.4 of the terms of service.
No computer system is 100% secure. A residual risk exists and will always exist, including in the face of vulnerabilities unknown at this date.
In the event of a personal data breach, we notify the CNIL within 72 hours of becoming aware of it, in accordance with Article 33 of the General Data Protection Regulation.
Where the breach is likely to result in a high risk to your rights and freedoms, we inform you directly and as soon as possible, setting out the nature of the breach, its likely consequences and the measures taken.
Transfers and cookies
Your data does not leave the European Economic Area. No transfer to the United States or to a third country is carried out.
Your data is neither sold, nor rented, nor transferred to a third party, for any purpose.
Spray Social sets a single cookie, to remember your display language, and uses the browser's local storage for your session. Details are given in the legal notice.
Changes
This policy may change. Any substantial modification is signalled in the application. The date of the last update appears at the top of this page.