Last updated: October 1, 2026
This Privacy Policy explains how the WhereAt mobile application ("App", "WhereAt") and its web page for group rooms (whereatapp.vercel.app/r/…) collect, use and protect your personal data. WhereAt is developed and operated by an individual independent developer based in Slovenia, European Union ("I", "me", "my").
By using the App, you acknowledge that you have read and understood this Privacy Policy.
For all privacy-related inquiries, contact: whereatapp@proton.me
1. Who Is Responsible for Your Data
WhereAt is operated by an individual developer, not a registered company. As the data controller under the General Data Protection Regulation (GDPR) and applicable Slovenian data protection law, I am responsible for your personal data collected through the App.
Contact: whereatapp@proton.me · Location: Slovenia, European Union
2. What Data I Collect
2.1 Data you give me
| Data | Purpose |
|---|---|
| Email address | Creating your account, signing in, password reset emails |
| Username | Your profile inside the App (it is not shown to other users) |
| Password | Securing an email account (stored only as a secure hash by Supabase, never in plain text) |
| Name and email from Sign in with Apple or Google | Creating and signing in to your account. With Apple you can hide your email; Apple then gives me a private relay address |
| Profile stamp (an emoji you pick) | Your profile |
| Student mode | The student lunch features. Whether you are a student is saved with your account; your faculty stays on your device |
| The name you enter in a group room | Showing the other people in that room who is in it |
| Your saved places, your own wheels (name, emoji, colour, places) and your 👍/👎 on places | Features you use in the App |
2.2 Data created while you use the App
| Data | Purpose |
|---|---|
| Spin history (which place the wheel picked, when, and whether you went for it, including "the wheel decides" spins) | Your history, passport and the "Did you go?" reminder |
| Visits: places you mark as visited, with the date, and for "I'm here" check-ins a note that the visit was confirmed on the spot (within about 150 m) | Your passport stamps and milestones |
| Group rooms: who is in a room, vetoes, picks and the result | Running the room for everyone in it. Rooms close 2 hours after they are opened |
| In-app notifications (your inbox) | Showing you news inside the App |
| Usage events: screens you open, features you use, the text you type into the search field on Home, the distance to a place when you check in, app version, device type and OS version, a random device ID, and your account ID when you are signed in | Understanding which features work, fixing problems (PostHog, see section 4) |
| Crash reports: what went wrong in the code, device model, OS and app version, your account ID when signed in | Fixing crashes (Sentry, see section 4) |
2.3 Location
- The App asks for your precise location only while you use it (never in the background), and only with your permission.
- Your location is used on your phone to show how far places are, and it is sent with your searches to my database so places can be sorted by distance. These coordinates are used for that request only and are not stored.
- When you tap "I'm here", your location and its GPS accuracy are sent once so the server can check that you are within about 150 m of the place. I store only the result (a confirmed visit and its time), not your coordinates. PostHog receives the distance to the place, not your coordinates.
- If you don't allow location, the App shows places around Ljubljana centre. You can change this at any time in iPhone Settings → WhereAt → Location.
2.4 Photos and notifications
- Photos: the App only adds an image to your photo library when you choose "Save Image" on a share card. It never reads your photos.
- Notifications: the lunch reminder and the weekly wheel reminder are local notifications scheduled on your phone. They are off until you turn them on in Profile. No push token or notification data is sent to me.
2.5 Data I do NOT collect
- Payment or billing information (the App is free)
- Contacts, camera or microphone
- Background location
- Your data is never sold, and there are no advertising or cross-app tracking SDKs (no Google Analytics, Facebook SDK or Meta Pixel)
3. Legal Basis for Processing (GDPR)
| Processing | Legal basis |
|---|---|
| Account, saved places, spin history, visits, your wheels, group rooms | Performance of a contract — Art. 6(1)(b) |
| Location, notifications, saving images to Photos | Your consent (the iOS permission dialogs) — Art. 6(1)(a) |
| Usage analytics and crash reports | Legitimate interest in keeping the App working and improving it — Art. 6(1)(f) |
| Responding to your requests, preventing abuse | Legitimate interest — Art. 6(1)(f) |
| Legal compliance | Legal obligation — Art. 6(1)(c) |
4. Third-Party Services
| Service | Role | Data | Location |
|---|---|---|---|
| Supabase | Database and sign-in | Everything in 2.1 and 2.2 except usage events and crash reports | EU (Frankfurt, Germany) |
| PostHog | Product analytics | Usage events (2.2), your account ID when signed in | EU |
| Sentry | Crash reporting | Crash reports (2.2) | EU data region |
| Apple | Sign in with Apple | Sign-in data. When you delete an account that uses Sign in with Apple, the App asks Apple to revoke WhereAt's access | Apple's own policy |
| Sign in with Google | Sign-in data | Google's own policy | |
| Expo (EAS) | Building the App and delivering updates | Basic device and app version data | USA |
| Vercel | Hosting the website and the group room web page | Standard server logs (e.g. IP address, browser) | Global edge network |
Venue information (names, addresses, opening hours, ratings) comes from Google Places and other public sources. The App does not send your data to Google, except when you sign in with Google or tap "Take me there", which opens Google Maps under Google's own terms.
5. Group Rooms and Guests
- Everyone in a room sees the names entered by the people in it, their vetoes and picks, and the result.
- If you join a room without an account (in the App or on the web page), a random anonymous technical account is created so the room can recognise you. It holds only the name you entered and your room actions.
- Rooms close 2 hours after they are opened.
6. Data Retention
| Data | Kept |
|---|---|
| Account data, saved places, spin history, visits, wheels, ratings | Until you delete your account |
| Names and memberships in group rooms, and anonymous guest accounts | Deleted at the latest 30 days after the room |
| Usage events (PostHog) | Up to 12 months |
| Crash reports (Sentry) | Up to 90 days |
| After you delete your account | Deleted immediately from the database; backups roll over within 30 days |
| Record of a deleted account (the random account ID, the date, and how many spins and saves it had; no email or name) | Kept as a deletion log |
Deleting your account: Profile → Delete Account. This permanently deletes your account and everything linked to it (saved places, spin history, visits and passport stamps, your wheels, ratings, notifications and your room memberships). For Sign in with Apple accounts, the App also asks Apple to revoke WhereAt's access to your Apple ID.
7. Your Rights Under GDPR
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21), including analytics. Write to whereatapp@proton.me and I will respond within 30 days. You can also lodge a complaint with the Slovenian Information Commissioner (Informacijski pooblaščenec, www.ip-rs.si).
8. Data Security
Data is sent over encrypted connections (HTTPS/TLS). Access to the database is limited by row-level security, so an account can read only its own data and the rooms it is in. Passwords are hashed by Supabase. No system is completely secure, but I take reasonable measures to protect your data.
9. Children's Privacy
WhereAt is intended for users aged 18 and older. I do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact me and I will delete it.
10. International Data Transfers
The database (Supabase) and analytics (PostHog) are in the EU. Where a provider processes data outside the EU (for example Expo or Vercel), the transfer is covered by the European Commission's Standard Contractual Clauses or the EU–US Data Privacy Framework.
11. Changes to This Policy
I may update this policy. The "Last updated" date shows the latest version, and I may also let you know about important changes in the App.
12. Contact
Email: whereatapp@proton.me