Last updated: June 10, 2026
This Privacy Policy explains how the WhereAt mobile application ("App," "WhereAt") collects, uses, and protects your personal data. WhereAt is developed and operated by an individual independent developer based in Slovenia, European Union ("I," "me," "my," "the developer").
By using the App, you acknowledge that you have read and understood this Privacy Policy.
For all privacy-related inquiries, contact: whereatapp@proton.me
1. Who Is Responsible for Your Data
WhereAt is operated by an individual developer, not a registered company. As the data controller under the General Data Protection Regulation (GDPR) and applicable Slovenian data protection law, I am responsible for your personal data collected through the App.
Contact: whereatapp@proton.me Location: Slovenia, European Union
2. What Data I Collect
2.1 Data You Provide Directly
| Data | Purpose |
|---|---|
| Email address | Account creation, authentication, and communications |
| Username | Displaying your profile within the App |
| Password | Securing your account (stored as a secure hash — never in plain text) |
2.2 Data Collected Automatically
| Data | Purpose |
|---|---|
| Device location (GPS, while app is open) | Finding places near you |
| Saved / favourite places | Your in-app favourites list |
| Spin history | Tracking your spins and results |
| App usage events (screen views, button taps) | Improving the App |
| Device type and OS version | Debugging and compatibility |
| Anonymous session identifiers | Analytics |
2.3 Data I Do NOT Collect
- Payment or billing information (the App is free)
- Contacts, photos, camera, or microphone
- Precise background location (location is only accessed while you are actively using the App)
- Data from children — the App is intended for users 18 years of age and older
- Your data is never sold to advertisers or third parties
3. Legal Basis for Processing (GDPR)
| Processing Activity | Legal Basis |
|---|---|
| Account creation and management | Performance of contract — Art. 6(1)(b) GDPR |
| Location-based place search | Your explicit consent — Art. 6(1)(a) GDPR |
| Analytics and usage improvement | Legitimate interest — Art. 6(1)(f) GDPR |
| Responding to your requests | Legitimate interest — Art. 6(1)(f) GDPR |
| Legal compliance | Legal obligation — Art. 6(1)(c) GDPR |
4. Third-Party Services
To operate the App, I rely on the following third-party services. Each service processes data under its own privacy policy and terms. I do not control these services and am not responsible for their data practices beyond the disclosures below.
Supabase
- Role: Database backend and authentication provider
- Data processed: Account credentials, favourites, spin history
- Server location: EU region (Frankfurt, Germany)
- Privacy Policy: https://supabase.com/privacy
- Supabase is GDPR-compliant and stores data within the EU.
Google Places API
- Role: Sourcing venue data (names, addresses, opening hours, ratings, photos)
- Data processed: Your search queries and approximate location may be sent to Google's servers to return nearby place results
- Privacy Policy: https://policies.google.com/privacy
- Google may process data in accordance with its own privacy practices. I do not control what Google does with data sent to its APIs.
Expo (Expo Go / EAS)
- Role: App build platform and over-the-air update delivery
- Data processed: Basic device/build metadata for update delivery
- Privacy Policy: https://expo.dev/privacy
- Expo may collect minimal telemetry data related to the App's build and runtime environment.
PostHog
- Role: Product analytics (understanding which features are used)
- Data processed: Pseudonymous usage events (screen views, tap events, user ID if logged in)
- Server location: EU region
- Privacy Policy: https://posthog.com/privacy
- No personally identifiable information beyond your user ID (if logged in) is sent to PostHog.
I do not use: Google Analytics, Facebook SDK, Meta Pixel, or any advertising or tracking networks.
5. Location Data
The App requests access to your device's location only while the App is actively in use (foreground only — never background).
- Location is used solely to find nearby places and is processed in real time
- Your precise GPS coordinates are not stored on any server — they are used transiently to query nearby place results
- Granting or denying location permission is your choice. If you deny it, place results will not be personalised to your location. You can change this at any time in iPhone Settings → WhereAt → Location
- Location data sent to Google's Places API is subject to Google's privacy policy
6. Data Retention
| Data | Retention |
|---|---|
| Account data (email, username) | Until you delete your account |
| Favourites and spin history | Until you delete your account |
| Analytics events | Up to 12 months |
| Data after account deletion | Permanently deleted within 30 days |
When you delete your account through the Profile screen, all of your personal data stored by me (and, to the extent technically possible, by Supabase on my behalf) will be permanently deleted within 30 days.
7. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights. To exercise any of them, email whereatapp@proton.me. I will respond within 30 days.
- Right of Access (Art. 15): Request a copy of all personal data I hold about you.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete data.
- Right to Erasure (Art. 17): Request full deletion of your account and associated data ("right to be forgotten").
- Right to Restriction (Art. 18): Ask me to limit how I process your data in certain circumstances.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interest.
- Right to Withdraw Consent: Withdraw location or analytics consent at any time through your device settings — withdrawal does not affect prior lawful processing.
- Right to Lodge a Complaint: If you believe your data rights have been violated, you can file a complaint with the Slovenian Information Commissioner (IP RS):
- Website: https://www.ip-rs.si
- Phone: +386 1 230 97 30
8. Data Security
I take reasonable technical and organisational measures to protect your data, including:
- All data in transit is encrypted via HTTPS / TLS
- Passwords are hashed using industry-standard algorithms and never stored in plain text
- Database access is authenticated and access-controlled through Supabase's security infrastructure
- Access to backend systems is limited to the developer
However, no method of transmission over the internet or electronic storage is 100% secure. I cannot guarantee absolute security. You use the App at your own risk.
9. Children's Privacy
WhereAt is intended exclusively for users 18 years of age and older. I do not knowingly collect personal data from anyone under 18. If you believe a minor has created an account, please contact me at whereatapp@proton.me and I will delete the account promptly.
10. International Data Transfers
My infrastructure (Supabase) stores data within the EU. Where third-party services (e.g., Google) may transfer data outside the EU, they are responsible for ensuring appropriate safeguards under GDPR Chapter V, such as Standard Contractual Clauses.
11. Changes to This Policy
I may update this Privacy Policy from time to time to reflect changes in the App, third-party services, or applicable law. The "Last updated" date at the top of this document will always reflect the most recent revision.
For significant changes, I will make reasonable efforts to notify you via an in-app notice. Continued use of the App after a revised Policy is posted constitutes your acceptance of the updated Policy.
12. Contact
For any privacy questions, data requests, or concerns:
Email: whereatapp@proton.me Response time: I aim to respond within 30 days.
If you are not satisfied with my response, you may contact the Slovenian Information Commissioner (IP RS) as described in Section 7 above.