Privacy policy
Last updated: 13 July 2026
Spinocchio limits data collection to operating, securing and improving the service. This document describes the main processing activities, their purposes and your rights.
Data controller
RUSSEBLANC, the sole trader publishing Spinocchio, is the controller for the processing described in this document. Address: 23 rue des Frères Bonie, 33000 Bordeaux, France. SIRET 821 041 431 00023, APE code 6201Z (computer programming). For any question about your data, or to exercise your rights, use the Contact page.
Data we process
Without an account, game history stays locally in your browser. With an account, we process your email address, profile and the content you create. Payments are handled by Stripe; Spinocchio does not store card numbers. When an organiser enables reinforced duplicate protection, an irreversible fingerprint of your IP address and browser is stored with the response, for the retention period chosen for that poll; neither the address nor the browser is stored in clear form.
Purposes and legal bases
Data is used to provide the service, authenticate accounts, enforce plan entitlements, answer requests and prevent abuse. Optional processing, including advertising, relies on consent where required. A poll’s reinforced protection relies on the organiser’s legitimate interest in collecting one response per participant.
Recipients and retention
Access is limited to authorised people and providers needed for hosting, email and payments. Retention depends on the plan and purpose; data that is no longer needed is deleted or anonymised.
Your rights
You may request access, correction, deletion, restriction, objection or portability through the Contact page. You may also withdraw consent at any time.
Security
We use access controls, encrypted connections, limited logging and abuse-prevention measures. No online service can, however, guarantee zero risk.
Transfers outside the European Union
Some providers (payment, hosting, e-mail delivery, search) may process data outside the European Union. Such transfers rely on the safeguards set out by the GDPR, in particular the European Commission's standard contractual clauses.
Complaint to a supervisory authority
If you believe the processing of your data does not comply with the regulation, you may lodge a complaint with the supervisory authority of your country of residence. In France, this is the CNIL (www.cnil.fr).