Back to Spunj
Effective September 18, 2026

Privacy Policy

This Privacy Policy explains how Restyn, Inc. d/b/a Spunj ("Restyn," "Spunj," "we," "us," or "our"), a Maryland corporation with offices at 300 Red Brook Blvd, Suite 220, Owings Mills, MD 21117, USA, handles information when you use the Spunj mobile application and related services (the "Service"). It is written to comply with Apple's App Store requirements and applicable U.S. privacy laws, including the Maryland Online Data Privacy Act ("MODPA").

Restyn is the controller of the limited personal data described in this policy. For anything privacy-related, contact privacy@spunj.app.

1. Privacy by Design — The Short Version

Spunj was built so that your information stays with you:

  • Your data lives on your device. Your card, connections, notes, follow-ups, and events are stored locally in the app. An event travels only by an invitation code you choose to show someone.
  • Sharing is phone-to-phone. Nearby discovery and card exchanges happen directly between devices over Bluetooth. Your card does not pass through our servers when you connect with someone.
  • No location tracking. Spunj never follows you around. Nearby discovery uses short-range Bluetooth only, with no location involved. The one feature that uses location — Favorite Places — reads it a single time, only in the moment you tap to tag a place, and never in the background. See Section 5.
  • Your places never reach us. The places you tag, their coordinates, your visit history, and your private notes about them stay on your device. They travel only by QR code, directly to a person you choose to show it to.
  • Optional iCloud sync is yours alone. If you enable it, your data is stored in your private iCloud database under your Apple ID. We cannot read it.
  • No ads. No data sales. No tracking. We do not show ads, sell or share personal data for targeted advertising, or track you across other apps and websites.
  • We collect only what the Service needs to work — and we itemize all of it below.

2. Information You Provide

  • Profile card. Name, and optionally a photo, job title, company, bio, email, phone, website, links, and social handles. You choose every field, and your card is shared only as described in Section 6.
  • Photo. If you add a photo, it is re-encoded and stripped of metadata (including GPS data) before it is ever shared. Sharing your photo during nearby discovery is optional and off by default for the bubble preview.
  • Notes, follow-ups, meetups, and events. Private notes and reminders you attach to connections stay on your device (and your private iCloud if you enable sync). They are never shared with the person they are about.
  • Favorite places. Places you tag, including the name and category you choose, the coordinates of the spot, your visit history, and any private note you add. See Section 5 for how location is used and what does and does not leave your device.
  • Recommendations. If you recommend a connection to someone, the recommendation you write — the person's card, the type, and your reason — is transferred device-to-device to the person you show it to.
  • Event room status line. Inside an event room you may add an optional status line of up to 40 characters ("Speaking at 3pm"). It is not a message and there is no messaging in Spunj: nobody can send you text, and your status line is simply shown to someone in the same room who taps your tile. It travels device-to-device and never reaches our servers.
  • Arcade games. Spunj includes small games, some of which you can play with another Spunj user nearby. While you wait in a two-player lobby, your broadcast carries which game you are waiting on (see Section 6), and you can see anyone nearby waiting in any two-player game rather than only the one you opened. A match is a direct Bluetooth link between the two phones, and the moves, scores, and results stay on those two devices. We never receive your scores, your moves, or who you played.
  • Reports. If you report someone, we receive the contents of your report, the reason you select, the reported user's identifier, and the card data they broadcast to you, so our safety team can review it.
  • Feedback and bug reports. If you submit feedback or a bug report, we receive what you write and the contact email you provide so we can respond.

3. Information Collected Automatically

We run a minimal backend that exists only to keep the Service secure and make specific features work. It processes:

  • Sign in with Apple. When you sign in, Apple gives us a token confirming your Apple ID identity, and the name/email you authorize Apple to share. We use this to verify you are a real person and to enforce community removals.
  • Account identifier. A random identifier (your "Spunj ID") that represents you to other users without exposing your Apple ID.
  • Device integrity (App Attest). Cryptographic attestations from Apple that confirm requests come from a genuine, unmodified copy of the app. These do not identify you personally beyond your account.
  • Subscription status. Whether your Apple ID has an active Spunj Pro subscription, verified with Apple. We never see your payment details — Apple processes all payments.
  • Denylist checks. The app periodically downloads the list of removed accounts so blocked users cannot appear in anyone's bubbles.
  • Service logs. Short-lived technical logs (request identifiers, timestamps, error codes) used for security and debugging. Logs are not used to profile you.

We do not collect advertising identifiers, analytics profiles, or browsing history. We do not collect your location — the location used by Favorite Places (Section 6) is read on your device, for that one action, and is never transmitted to us.

4. Contacts Access (Optional)

If you grant contacts permission, Spunj reads your address book on your device only to recognize when a new connection matches someone you already know and to help you save connections to Contacts. Your address book is never uploaded, stored, or transmitted to our servers or to other users. You can revoke access anytime in iOS Settings.

5. Location and Favorite Places (Optional)

Favorite Places lets you tag a spot you have actually been — a restaurant, a trailhead, an overlook — and share it with someone you have met. Because the feature's entire point is that a place is authentic, the app confirms you were really there. Here is exactly how that works.

  • One reading, only when you ask. Spunj requests your location only in the moment you tap to tag a place or to log a return visit. It asks iOS for a single fix and stops immediately once it has one. There is no continuous tracking, no trail of where you have been, and no location access while the app is in the background or closed.
  • "While Using the App" only. Spunj requests only foreground location permission. It never requests "Always" access, and it does not use background location, significant-change monitoring, geofencing, or region monitoring.
  • The check happens on your device. Your coordinates are compared with the place's coordinates on your phone to confirm you are close enough. That comparison is never sent anywhere.
  • Your places stay with you. Tagged places, coordinates, categories, visit dates, and notes are stored locally in the app (and in your private iCloud if you enable sync). Our servers never receive or store them.
  • Your private note cannot leave. The note you write on a place is not part of the data a shared place carries. There is no field for it in the shared format at all, so it cannot be transmitted by accident.
  • Sharing is device-to-device. When you share a place, it travels as a QR code shown on your screen and scanned by the other person's phone. Nothing passes through our servers, and you decide who sees your screen.
  • Receiving a place shares nothing about you. A place you receive is a place, not a location report. It tells the other person nothing about where you are, and scanning one does not require or reveal your location.
  • Business name lookup uses Apple Maps. To offer the name of the business nearest to you when you tag a place, the app asks Apple's map service what is at those coordinates. That one lookup leaves your device and is handled by Apple under Apple's privacy policy; it is not sent to us. If you name a place yourself, no lookup is performed.
  • Turning it off. You can decline location permission or revoke it anytime in iOS Settings. Every other part of Spunj keeps working; you simply will not be able to tag or verify places.

5A. Motion (Optional)

Spunj Sounds, a small audio toy in the app, reads how you tilt your phone so that sound appears to move around your head as you turn. This reading is used on your device, in the moment, to position audio and nothing else. It is never recorded, stored, or transmitted, and it tells us nothing about where you are. You can decline motion permission and the rest of Spunj is unaffected.

6. How Your Information Is Shared

  • When you are Spunjable. Spunjable is the single switch that controls everything Spunj puts on the air. When it is on, your device broadcasts a small card preview over Bluetooth to Spunj users physically near you. That broadcast carries: a short form of your name (your first name and last initial, or a short name you set yourself), your chosen theme, whether you have a profile photo, and — only in the relevant moment — whether you are carrying that event's Wallet pass, a scrambled 3-character tag identifying the event room you are in, and which game you are waiting on in an Arcade lobby. It does not carry your full card, your photo itself, your contact details, or your location.
  • When Spunjable is off. Turning it off stops the broadcast immediately and completely. It is one master control, not a per-feature setting: while it is off you are invisible in nearby bubbles, event rooms, and Arcade lobbies alike, and nothing goes out over the air from your device.
  • When you connect. After both people confirm a tap, your full card — the fields you chose to include, and your photo — is transferred directly to the other person's device. They keep that copy; we cannot delete it for you.
  • Event rooms. Your card preview is visible to people in the same room. Your status line and subtitle are sent to someone in the room only when they tap your tile. While you are in a room, nearby phones running Spunj also ask each other, briefly and repeatedly, which room they are in — the answer is only the scrambled event tag described in Section 3, and it is what keeps everyone standing in one room seeing the same set of people. Everything in a room travels directly between phones over Bluetooth; room contents do not pass through our servers.
  • Arcade games. In a two-player lobby, people nearby waiting in any two-player game see the same short name your broadcast already carries, along with which game you are waiting in. During a match, game moves travel over a direct link between the two phones, with nobody in between.
  • Favorite places and recommendations. When you share a place or a recommendation, it is encoded in a QR code on your screen and read directly by the other person's device. It does not pass through our servers. A shared place carries the place's name, category, and coordinates — never your private note, and never your current location.
  • Event invitations. An event room is shared by invitation: the host shows an invite QR code and guests scan it. That code carries the event's name, hashtag, dates, an identifier for the event, and the host's name — nothing else. It does not carry the host's card, contact details, attendee list, private notes, or status line, and it is read directly by the guest's device without passing through our servers. Scanning an invitation and walking into the room is free for everyone; only hosting an event of your own requires Spunj Pro.
  • Apple Wallet passes. If you create a Wallet pass, your card data is sent to our signing server, used transiently in memory to produce the signed pass, and returned to your device. We do not retain your card data after signing.
  • Service providers. We use a small number of infrastructure providers (such as Cloudflare, which hosts our backend, and Apple) that process data solely on our behalf under contractual confidentiality obligations.
  • Safety and legal. We may disclose information (such as report contents) if we believe in good faith that it is necessary to comply with law or legal process, enforce our Terms, or protect the rights, property, or safety of our users or others.
  • Corporate transactions. If Restyn is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this policy.

We do not sell personal data, and we do not share personal data for targeted advertising.

7. iCloud Sync

If you enable iCloud sync (a Spunj Pro feature), your card, connections, notes, and places are stored in your private iCloud database, protected by your Apple ID and Apple's encryption. This data is accessible only to you; Restyn cannot read, access, or recover it. Apple's iCloud terms and privacy policy govern that storage. You can turn sync off at any time in the app.

8. How We Use Information

We use the information described above only to:

  • Provide the Service — discovery, card exchange, events, places, Wallet passes, and sync;
  • Verify identity and device integrity to prevent spam, fraud, impersonation, and abuse;
  • Confirm Spunj Pro entitlements;
  • Review safety reports, enforce our Terms and Community Standards, and maintain the denylist;
  • Respond to your support requests and feedback; and
  • Comply with legal obligations.

Consistent with MODPA's data-minimization requirements, we collect and process only the personal data reasonably necessary for these purposes, and we do not process personal data for purposes that are neither reasonably necessary for, nor compatible with, the purposes above. We do not use your personal data to train AI models, build advertising profiles, or make automated decisions with legal or similarly significant effects.

9. Data Retention

  • On-device data (your card, connections, notes, events, places, and visit history): kept until you delete it or delete the app. Deleting a place deletes its coordinates, visit history, and note with it.
  • Account records (Spunj ID, Apple identity token reference, App Attest key registration): kept while your account is active and deleted within 30 days after you ask us to delete your account.
  • Subscription status: kept while your subscription is active, then only as needed for legal and accounting purposes.
  • Reports and enforcement records: kept for up to 2 years, or longer where needed to enforce a permanent removal or comply with law.
  • Feedback and bug reports: kept for up to 2 years.
  • Service logs: kept for no more than 90 days.
  • Denylist entries: kept as long as the removal remains in effect.

10. Security

We protect information using industry-standard measures, including encryption in transit (TLS) for all server communication, Apple's App Attest device integrity checks, encrypted Bluetooth exchange payloads, and Keychain storage for sensitive tokens on your device. No method of transmission or storage is completely secure, but the small amount of data we hold is minimized by design.

11. Your Rights (Maryland and Beyond)

Under MODPA and similar state privacy laws, you have the right to:

  • Know and access the personal data we hold about you, and obtain a portable copy;
  • Correct inaccurate personal data;
  • Delete personal data we hold about you (deleting the app removes on-device data, including your places and visit history; email us to delete server-side account records);
  • Opt out of the sale of personal data, targeted advertising, and significant-decision profiling — none of which Spunj engages in; and
  • Not be discriminated against for exercising these rights.

To exercise any right, email privacy@spunj.app from the address associated with your account or your feedback submissions, or write to us at the address in Section 15. We will verify your request using the limited data we hold, respond within 45 days (extendable by 45 days where reasonably necessary, with notice), and honor requests free of charge up to twice annually.

Appeals. If we decline your request, you may appeal by replying to our decision or emailing privacy@spunj.app with the subject "Privacy Appeal." We will respond within 60 days. If your appeal is denied, you may contact the Maryland Attorney General's Consumer Protection Division at marylandattorneygeneral.gov or 410-528-8662.

Other states. Residents of California, Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws have similar rights, which we honor through the same process. For California residents: we do not "sell" or "share" personal information as defined by the CCPA/CPRA, and we do not use or disclose sensitive personal information for purposes requiring a right to limit.

12. Children's Privacy

The Service is for adults 18 and over. We do not knowingly collect personal data from anyone under 18, and the Service is not directed to children under 13. If we learn that a person under 18 has created an account, we will remove the account and delete associated server-side records. If you believe a minor is using the Service, contact safety@spunj.app.

13. International Users

The Service is operated from the United States, and information we process is handled on servers in the United States (with edge infrastructure that may process requests closer to you). If you use the Service from outside the U.S., you understand that your information will be processed in the U.S., where privacy laws may differ from those in your jurisdiction.

14. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide notice through the app or by other reasonable means and update the effective date above. Where required by law, we will ask for your consent. Your continued use of the Service after changes take effect constitutes acknowledgment of the revised policy.

15. Contact Us

Restyn, Inc. d/b/a Spunj · 300 Red Brook Blvd, Suite 220 · Owings Mills, MD 21117, USA

Restyn, Inc. d/b/a Spunj · 300 Red Brook Blvd, Suite 220 · Owings Mills, MD 21117, USA