Privacy Policy
Last updated 15 September 2026.
The short version
Hobby Double stores the hobby records you put into it — your projects, models, paints, recipes and photos — so it can show them back to you on every device you sign in on. That is the whole purpose.
- Nothing is sold, rented, or used for advertising. There are no ad trackers and no analytics.
- Nothing you record is public unless you switch a project on for your public profile.
- If you connect Google Photos, Hobby Double only ever sees the photos you pick yourself in Google's own picker — never the rest of your library.
- You can download everything, or delete your account outright, from Account → Your data in the app.
Who is responsible for your data
Hobby Double ("we", "us") is the data controller for the personal data described here. It is a small service run by an individual rather than a company, and every new account is approved by hand before it can be used.
For anything about privacy — a question, a request, or a complaint — email privacy@hobbydouble.com. We will reply within 30 days. If you need a postal address, ask and we will provide one.
What we collect, and why
Your account
| Data | Why |
|---|---|
| Email address | Identifies your account, and is how we send sign-in and password-reset links |
| First and last name | Given when you register, and shown to the admin who approves new accounts. They also set your display name to begin with |
| Display name | Shown in the app, and on your public profile if you have one |
| Password (hashed, never stored in readable form) | Signing in, if you use a password rather than Google |
| Public profile handle, if you pick one | The address of your public page |
Sign-in records
Each session stores a session token, its expiry, and the IP address and browser user agent it was created from. These let you stay signed in for 30 days, and let us spot and shut down abuse. We keep rate-limiting counters for the same reason.
What you record in the app
Your projects, units, paints, materials, recipes and recipe steps, with whatever you put in their fields — names, manufacturers, factions, quantities, painting stage, prices, purchase dates, links and free-text notes. Also a timeline of when things changed stage, and the photos you add.
Photos you upload are resized in your browser before they are sent, stored in our object storage, and a smaller thumbnail is generated and kept alongside.
Sharing and publishing
If you invite someone to a project, we store their email address to send the invitation, and their membership once accepted. If you publish a project to your public profile, the things you chose to publish become readable by anyone, including search engines — or, if you publish it to your followers only, by the signed-in accounts following your profile. Hearts on public photos record which signed-in account hearted which photo.
Following a profile records which account follows which, and both sides can see it: your followers are listed to you, and the profiles you follow are listed to them. When a profile you follow adds photos to a published project, or a unit on one reaches a new stage, we store a notification for you until you dismiss it. Badges are assigned by us, not by you, and appear next to your name on your public pages.
AI connectors
If you connect an AI client through our connector, we store which client you authorised, the permissions you granted it, and its access tokens. What you then say to that AI client is handled by whoever provides it, under their privacy policy, not ours.
What we do not collect
No analytics, no advertising or tracking cookies, no third-party scripts that watch what you do, no location data, and no special category data. The only cookie we set is the one that keeps you signed in, which is strictly necessary for the service and is why there is no cookie banner.
Google Photos
Hobby Double's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Connecting Google Photos is entirely optional, and the app works fully without it.
When you do connect it, we ask for one permission:
photospicker.mediaitems.readonly.
This is how it works, and what its limits are:
- Picking happens inside Google's own picker, in a Google window. We never see your library, your albums, or anything you did not select.
- We receive only the photos you picked, and only for as long as that picking session lasts. We delete the session when the import finishes.
- Each picked photo is copied into Hobby Double's own storage (resized to 1600px on its longest edge) and attached to the model, project or step you chose. From then on it is an ordinary Hobby Double photo: it stays until you delete it or close your account, even if you later disconnect Google.
- The permission is read-only. We cannot add to, change, or delete anything in your Google Photos, and we never try to.
- Google Photos data is used only to show you your own photos in the app, and on your public profile if you publish that project. It is never used for advertising, never sold, never shared with anyone else, and never used to train AI or machine-learning models — ours or anyone's.
- No human reads your Google Photos data. The only exceptions would be with your explicit permission (for example, if you ask us to look into a bug), where it is necessary for security, or where the law requires it.
You can withdraw this access at any time at myaccount.google.com/permissions. Doing so stops any further importing immediately. Photos already imported stay in Hobby Double until you delete them — delete them individually in the app, or delete your account to remove them all.
If you sign in with Google, we also receive your name, email address and profile picture from Google to create and identify your account. That is separate from the Photos permission and does not give us access to your photos.
Our legal bases (UK GDPR)
| Purpose | Basis |
|---|---|
| Running your account and storing your hobby records | Performance of a contract — our terms with you |
| Sending account emails: verification, password resets, invitations | Performance of a contract |
| Keeping the service secure, and preventing abuse | Legitimate interests |
| Reading photos you pick from Google Photos | Consent — the permission you grant Google, withdrawable at any time |
| Publishing a project on your public profile | Consent — you switch each project on yourself, and can switch it off |
Who else handles your data
We use a small number of providers to run the service. They process data on our instructions only, and do not use it for their own purposes.
| Provider | What they do | What they see |
|---|---|---|
| Cloudflare | Hosting, database, photo storage, image resizing | Everything stored in the service |
| Resend | Sends our account emails | Your email address and the contents of those emails |
| Sign-in, and the Photos picker if you connect it | What you already share with Google by using it |
We do not sell personal data, and we do not share it with anyone else — except where the law requires it, or where it is necessary to establish or defend legal claims.
Where your data is
Our providers are US-headquartered and operate global networks, so your data may be processed outside the UK. Where it is, those transfers rely on the UK's approved safeguards — the International Data Transfer Addendum or equivalent standard contractual clauses in each provider's terms.
How long we keep it
- Your account and content: for as long as the account exists.
- Things you delete in the app: photo files are removed from storage straight away. The underlying records are marked deleted and stop appearing anywhere, but the rows themselves are removed when you close your account — this is what lets a deletion made offline on one device reach your others.
- Sessions: expire after 30 days, or immediately when you sign out.
- Invitations: until accepted or expired.
- Notifications: until you dismiss them, and in any case no more than 60 days.
- Backups: our database provider keeps short-term point-in-time backups, so deleted data can persist in those for a limited window before ageing out.
Your rights
Under UK GDPR you can ask us to:
- Give you a copy of your data, or a portable export of it
- Correct anything wrong
- Delete your data
- Restrict or object to how we use it
- Withdraw consent you have given, at any time
Two of these you can exercise yourself, immediately, without asking us. In the app, go to Account → Your data:
- Download my data gives you a JSON file of your projects, units, paints, materials and recipes, with a link to each photo, plus your badges and who you follow and are followed by.
- Delete my account removes your account, everything you own, and your photos, and takes your public profile down. It also asks Google to forget the Photos permission. It cannot be undone. Models other people added to your shared projects are not destroyed — they return to that person's own collection.
For anything else, email privacy@hobbydouble.com. If you think we have handled your data badly, you can complain to the Information Commissioner's Office at ico.org.uk, though we would rather you told us first so we can put it right.
Security
Everything travels over HTTPS. Passwords are stored as salted hashes, never in readable form. The tokens for any Google account you link are encrypted at rest. Your session cookie cannot be read by JavaScript. Photos on a private project need a valid session to fetch; only what you publish is readable without signing in.
No service can promise perfect security. If a breach ever affects your personal data and puts you at risk, we will tell you and the ICO within the time the law allows.
Children
Hobby Double is not intended for children under 16. We do not knowingly collect data from them. If you believe a child has an account, email us and we will remove it.
Changes
If we change this policy we will update the date at the top, and tell you by email before anything significant takes effect.