Back to projects

Inemsellar App Privacy Policy

Last updated: 18 August 2026

1. Introduction

Welcome to Inemsellar App. We value and respect your privacy, and we are committed to protecting the personal data you share with us. This Privacy Policy explains what data we collect, what we use it for, who we share it with, and what rights you have over it.

By downloading, installing or using the app, you accept the practices described in this policy.

2. Data controller

  • Controller: AppToLast
  • App: Inemsellar App (Android and iOS)
  • Contact and privacy enquiries: admin@apptolast.com

3. General information and unofficial status

Inemsellar App is an independent utility and is NOT an official app of any public body, including SEPE (Spain's State Public Employment Service) or AEAT (the Spanish tax agency). The app makes public resources, guides and community-contributed content easier to reach.

4. Data we collect

4.1 Anonymous session identifier

From first launch, the app automatically creates an anonymous Firebase session. It consists of a technical identifier (uid) that contains no personal data and that makes voting, saving preferences and enforcing security rules possible. It requires no registration or action on your part.

4.2 Account data (registration and sign-in)

Registration is optional: you can browse guides, calculators, phone directories, card-sealing links and content without creating an account. An account is required to post content, vote, report, or publish your CV.

Depending on the method you choose, we process:

  • Email registration: your email address, a password and, optionally, a display name. Authentication is handled by Firebase Authentication: the password travels encrypted and is stored on Google's systems as a cryptographic hash. We never have access to your password.
  • Sign in with Google: your email address, your name and, if your provider supplies it, your profile picture.
  • Sign in with Apple: your email address (or Apple's private relay address, if you choose to hide it) and your name, which Apple sends only on first sign-in.
  • Password recovery: your email address, to send you the reset link.

4.3 Content you publish

The app has a community component. Anything you publish becomes visible to other people using the app:

  • Tips, courses and job offers: title, description, body, dates, website and — if you choose to include them — a contact email address and phone number, plus the location of the job or course.
  • CVs (talent board): name, professional title, target role, professional summary, location, LinkedIn profile, contact email address and phone number, and your CV PDF file.
  • Votes: which content you voted on and in which direction.
  • Reports: the reported content, the reason you select and any detail you write. Only the moderation team sees these.
  • Display name on the public leaderboard: if you take part in the community, your display name and score appear in the app's ranking.

Important note about CVs. A CV's details and PDF are visible only to people signed in to the app, and the PDF is served through an authenticated download: there is no public link that would allow it to be downloaded from outside the app. Even so, any user of the app can see it, so publish only the information you want to make visible and avoid including unnecessary data in the PDF (national ID number, social security number, health data, photographs of other people, and so on). You can edit or delete your CV at any time from within the app.

4.4 Data collected automatically

  • Identifiers: the device advertising identifier (Android/iOS), the Google Analytics app instance identifier, our own installation identifier and the push notification token, together with the platform and app version.
  • Usage data: screens viewed and actions taken in the app (opening content, voting, publishing, opening an external link, buying or restoring ad removal).
  • Diagnostic data: crash reports, stack traces and app state at the time of a crash, through Firebase Crashlytics.
  • IP address: processed by Firebase (security and abuse prevention) and Google AdMob (advertising, measurement and fraud prevention).
  • Purchases: the fact that you have bought or restored ad removal, linked to your user identifier. We do not process card or payment details.

4.5 Data that stays on your device

This data never leaves your phone and disappears when you uninstall the app or clear its data: your selected province, your favourites, the date and time of the card-sealing reminder, the ad-removal status and your app preferences.

5. Permissions the app uses

  • Internet: loading content, signing in and serving ads.
  • Notifications: sending you alerts about new content and the local card-sealing reminder. You can turn them off from your profile or in your system settings.
  • Advertising identifier: serving ads and measuring their performance.
  • Device boot: rescheduling the local sealing reminder after your phone restarts.
  • Billing: handling the ad-removal purchase.

The app does not request access to your camera, photo gallery, contacts, calendar or device location. Attaching your CV uses the system document picker, which grants access only to the file you select.

6. What we use the data for

  • Providing the app's features and keeping you signed in.
  • Managing your account: registration, sign-in, password recovery and deletion.
  • Publishing and displaying community content, including CVs, and enabling contact between users through the details each person chooses to publish.
  • Moderating the community: handling reports, removing inappropriate content and preventing abuse.
  • Sending you notifications about new content and reminders, where you have allowed this.
  • Serving advertising and, with your consent, personalising it and measuring its performance.
  • Analysing aggregate app usage in order to improve it.
  • Detecting and fixing errors and crashes.
  • Handling the ad-removal purchase.
  • Complying with our legal obligations.

7. Legal basis for processing (GDPR)

  • Performance of a contract (Art. 6(1)(b) GDPR): creating and managing your account, publishing your content and your CV, and handling the ad-removal purchase.
  • Consent (Art. 6(1)(a)): personalised advertising, analytics and push notifications. You may withdraw consent at any time from Profile → Privacy preferences and in your notification settings, without affecting the lawfulness of processing carried out beforehand.
  • Legitimate interests (Art. 6(1)(f)): app security, fraud and abuse prevention, content moderation, non-personalised advertising and technical stability.
  • Legal obligation (Art. 6(1)(c)): where we are required to retain or disclose information by law.

8. Third-party services

We do not sell or rent your personal data. We share it only with the providers needed to operate the app, which process it on our behalf or, where they act as independent controllers, under their own policies:

ProviderServiceData involved
Google (Firebase Authentication)Accounts and sign-inEmail address, name, user identifier, IP address
Google (Cloud Firestore and Cloud Storage)Storage of community content and CV PDFsPublished content, contact details you include, CV file
Google (Firebase Cloud Messaging)Push notificationsDevice token, platform, app version
Google (Google Analytics for Firebase)Usage analyticsInstance identifier, usage events, user identifier
Google (Firebase Crashlytics)Crash reportingStack traces, device model and state, user identifier
Google (AdMob and User Messaging Platform)Advertising and consent managementAdvertising identifier, IP address, interactions, diagnostic data
RevenueCat, Inc.In-app purchase managementUser identifier, purchase history, device identifiers
Google Play / Apple App StorePayment processingHandled entirely by the store; we receive no payment data

We may also disclose data where necessary to comply with the law or respond to requests from competent authorities, to protect rights, the safety of our users or the integrity of the service, and in the context of a corporate transaction such as a merger or acquisition, giving prior notice if this entails a change to this policy.

See the Google Privacy Policy and the RevenueCat Privacy Policy.

9. Advertising and consent

The free version shows Google AdMob advertising. In the European Economic Area and the United Kingdom, we show you a consent form managed with Google User Messaging Platform before any ad loads. Your choice determines whether advertising is personalised and whether analytics is enabled, through Google Consent Mode v2.

You can review or change your choice at any time from Profile → Privacy preferences. Buying ad removal disables advertising, but not analytics or crash reporting, which are governed by your consent.

10. Data retention

  • Account and profile data: for as long as the account is active. Deleting it removes your Firebase Authentication identity.
  • Published content and CVs: until you delete them from the app or moderation removes them.
  • Diagnostic and usage data: according to the retention periods configured in Firebase Crashlytics and Google Analytics, which you can consult in Google's documentation.
  • Deletion requests received by email: handled within a maximum of 30 days.

11. Security

We apply technical and organisational measures to protect your data:

  • All communications travel encrypted over TLS.
  • Firestore and Cloud Storage security rules restrict each piece of data to whoever is entitled to see or change it: only the author can edit or delete their own content, and vote and report counters are written by the server alone.
  • A CV's PDF is served through an authenticated download; no freely accessible download links are generated or published.
  • Team access to data is restricted and limited to moderation and support tasks.

No system is completely infallible, so we cannot guarantee absolute security. Data held on your device depends on that device's security; we recommend using a screen lock, PIN or biometrics.

12. Your rights

You may exercise your rights of access, rectification, erasure, restriction of processing, data portability and objection, and withdraw your consent at any time. To do so, write to admin@apptolast.com stating the right you wish to exercise and the email address linked to your account.

If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or with your local supervisory authority.

13. Deleting your account and your data

You can delete your account from within the app, at Profile → Delete account. This removes your Firebase Authentication identity and permanently signs you out; afterwards you can keep using the app as a guest.

Before deleting your account, use the app to delete any content you have published — including your CV and its PDF file. Once the account is gone you will no longer be able to manage it yourself, and you will need to request its deletion by writing to admin@apptolast.com. We will handle such requests within a maximum of 30 days.

Data stored only on your device is removed by uninstalling the app or clearing its data in your system settings.

14. Children

The app is aimed at people looking for work or managing their employment situation and is not intended for children under 14, the minimum age in Spain for consenting to data processing in information society services. We do not knowingly collect data from children below that age; if we find that we have, we will delete it as soon as possible. If you are a parent or guardian and believe a child in your care has given us their data, please write to admin@apptolast.com.

15. International transfers

The providers listed in section 8 are companies based in the United States that may process data outside the European Economic Area. These transfers rely on the safeguards provided for by the GDPR, in particular the EU–US Data Privacy Framework and, where applicable, the European Commission's Standard Contractual Clauses.

16. Changes to this policy

We may update this Privacy Policy to reflect changes to the app or for legal or operational reasons. We will publish the updated version at this same address and change the "Last updated" date. If a change is substantial, we will tell you inside the app.

17. Contact

For any question, request or complaint relating to this policy or to how we process your data: