Rollbook · Privacy
Privacy Policy
Last updated 29 July 2026
Rollbook is a film tracker for undeveloped rolls, run by an individual, not a company. This policy explains what personal data it processes, why, and what you can do about it. It is written to satisfy Articles 13 and 14 of the EU General Data Protection Regulation (GDPR).
Who is responsible
The data controller is Jeremy, operating Rollbook under the name Bystanek, U Smetanky 192/7, 190 00 Praha 9, Czech Republic. Contact: rollbook@bystanek.com. There is no Data Protection Officer; the controller handles requests personally.
What data is processed
Your email address. Rollbook has no passwords. You sign in with a magic link, so an email address is required to create and access an account. It is stored by the authentication provider and is not used for marketing.
The roll records you create. Film stock, ISO, format, camera, lens, dates, push/pull, status, location, lab notes, personal notes, an optional creator alias, and any other field you fill in. This content is yours; Rollbook treats it as personal data because it can describe where you were and when.
Technical data from hosting. The host and the backend provider record standard server logs — IP address, timestamp, requested URL, user agent — for security and abuse prevention. Rollbook does not read these routinely and does not build profiles from them.
Scan counts on shared rolls. If you publish a roll, the server increments a counter each time its public page is opened and records the time of the most recent open. The counter is a number; it does not identify visitors.
What is not processed. No analytics, no advertising, no tracking pixels, no third-party scripts, no external fonts or CDNs. No behavioural profiling. No sale or sharing of your data with anyone for their own purposes. Rollbook is not intended for children: the digital-consent age in the Czech Republic is 15, and Rollbook does not knowingly collect data from anyone below it. If you believe a child has created an account, email the address below and it will be removed.
Camera and QR scanning
The scanner asks for camera permission and decodes QR codes entirely inside your browser. No image, video frame, or camera stream is uploaded, stored, or seen by anyone. Denying camera access disables scanning and nothing else. Recently scanned roll IDs are kept in your browser's local storage so the scanner can show them again; they never leave the device.
Why, and on what legal basis
Performance of a contract (Art. 6(1)(b)) covers running your account and storing the rolls you ask Rollbook to store — that is the service itself.
Legitimate interests (Art. 6(1)(f)) cover server logs, the scan counter, and keeping the service secure and working. The interest is operating a reliable service; the data involved is minimal and is not used to profile you.
Publishing a roll also runs on Art. 6(1)(b) — it is a feature you asked for, not something Rollbook does to you. A roll is private until you deliberately share it, you choose field by field what a public page shows, and you can unpublish at any time. Unpublishing takes the page down going forward; it cannot recall copies that were already viewed, cached, or indexed.
If you publish a roll containing information about other people, you are responsible for that publication as a data controller in your own right. The household exemption in Art. 2(2)(c) does not cover publishing to the open web.
Who else processes it
Two, and only two. Supabase hosts the database and authentication and sends the magic-link emails. Vercel hosts and serves the site. Both are bound by data-processing agreements and neither is permitted to use your rolls for its own purposes. Typefaces are served by Rollbook itself, so no font provider or CDN sees your IP address.
Your rolls are stored in Supabase's eu-west-1 region (Ireland), so the database itself sits inside the EEA. These providers are US companies, however, and support or infrastructure access can involve processing outside the EEA. Those transfers rely on the EU Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.
How it is protected
Every roll is stored under your user ID and guarded by Postgres Row Level Security, so one account cannot read, edit, or delete another's rolls. Public roll pages are served through a restricted server function that returns only the fields you whitelisted — the underlying table is never exposed to anonymous visitors. All traffic is served over HTTPS. No security is absolute, and Rollbook is not the place for data you cannot afford to lose or have exposed.
How long it is kept
Your rolls are kept until you delete them or ask for the account to be deleted — Rollbook applies no expiry of its own, because a film archive is meant to last. Account deletion requests are completed within 30 days and remove the rolls attached to the account.
Two things outlive that deletion by a short, bounded period. Encrypted database backups roll on Supabase's schedule for this project's plan and overwrite themselves in turn, so deleted content disappears from backups once the cycle completes. Server logs held by Supabase and Vercel expire on those providers' own retention schedules. Neither is used to reconstruct a deleted account.
If something goes wrong
If a breach occurs that is likely to result in a high risk to your rights and freedoms, you will be told directly and without undue delay, as Art. 34 requires — what happened, what data was involved, and what to do about it. Rollbook holds little sensitive data by design, which is the best protection against this mattering much.
Your rights
Under the GDPR you can request access to your data, correction, erasure, restriction of processing, and portability; object to processing based on legitimate interests; and withdraw consent for anything based on consent. In practice the app already lets you edit or delete any roll and export your whole library to CSV or JSON at any time, which covers access and portability without waiting on anyone.
To delete the whole account, use Account → Request account deletion in the app. For anything else, email rollbook@bystanek.com. Requests are answered within one month. If you believe your data is being mishandled you can lodge a complaint with the supervisory authority in your EU country of residence, or with the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz), where the controller is established.
Changes
This policy may change as Rollbook changes. The date at the top always reflects the current version. Material changes affecting your rights will be announced in the app before they take effect. A new purpose will never be applied to data already collected without a fresh legal basis for it — editing this page is not a way to acquire one.