lsrs@lab:~$cat privacy.txt

Privacy policy

Last updated: 9 October 2026

LSRS is a lab of personal projects. This policy explains what data our apps receive when you sign in with your Google or Apple account and what we do with it. Some apps also have their own, more detailed policy, for example Vínculo (in Spanish).

Scope

The LSRS apps and websites published on lsrs.dev and its subdomains (such as vinculo.lsrs.dev) and their mobile apps.

What we receive

When you sign in, Google or Apple share your name, your email, your profile picture if you have one and an identifier for your account. With Apple you can hide your email: we then receive an Apple relay address. We never receive your password and we do not access your contacts, emails, files or any other data in your account.

How we use it

Only to create your account, recognise you when you come back and show your name inside the app. The legal basis is providing the service you ask for (article 6(1)(b) GDPR). We do not use it for advertising or profiling.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Where it is stored and who helps us

Accounts are stored with Supabase, on servers in the European Union (Frankfurt). The websites are served by Cloudflare. Both act as data processors under the GDPR.

Who we share it with

No one else. We do not sell or hand over data to third parties.

How long we keep it

For as long as you keep your account. If you ask us to delete it, we do so within 30 days, unless a law requires us to keep some data.

Your rights

You can ask for access, rectification, erasure, objection, restriction or portability of your data by writing to hola@lsrs.dev. You can also complain to the Spanish Data Protection Agency (AEPD).

Changes

If we change this policy we will say so on this page with a new date.