Privacy Policy

Version 2026-10-08. This is the version number recorded against your consent in the app.

Gather is a place to meet people by doing things together. That only works if you can see what we collect and why, so this says it plainly rather than at length.

Before publishing: replace [[REGISTERED ADDRESS]], and have this reviewed by a lawyer qualified in Bulgaria and Spain. It describes what the software actually does, which is the hard part — but it is not legal advice.

1. Who we are

Gather is run by Yuliyan Manolov, an individual established in Bulgaria, of [[REGISTERED ADDRESS]]. He is the data controller for the Gather app and the website at wegather.fun. "We" and "Gather" mean him.

You can reach us about anything in this policy at support@wegather.fun.

2. What we collect

Almost all of it is what you type into the app. We do not buy data about you, we do not track you across other apps or websites, and we do not run advertising.

WhatDetail
AccountYour email address and a password, which is stored only as a cryptographic hash and is never visible to us.
ProfileDisplay name, photos, bio, the city and country you live in, the country you are from, age, languages, interests, and your gender together with whether you have chosen to show it.
LocationIf you allow it, your device's approximate location, used to sort activities by distance and to centre the map. We request "balanced" accuracy rather than precise, and only while the app is open. You can refuse and still use Gather.
ActivitiesWhat you host or join: title, description, category, date and time, venue name, address, price and number of spots.
InteractionsJoin requests and their messages, group chat messages, ratings you give and receive with their tags and comments, who you have blocked, reports you make, and which profiles you have viewed.
VerificationWhether you passed, when, a reference number for the check, and a record of your consent. Not the selfie itself — see section 3.
PaymentsYour subscription tier and renewal date, plus identifiers from Stripe or Apple. We never see or store your card number.
TechnicalA push notification token for your device, if you enable notifications, and basic app and error logs.

3. Your selfie and biometric data

A selfie used to confirm a live person is holding the phone is biometric data. Under the GDPR that is a special category of personal data, and in some US states it is governed by its own statute. We treat it accordingly, and we ask before any camera opens.

What actually happens — this is the notice you agree to in the app, word for word:

This is a liveness check, not an identity check. We do not ask for a passport, driving licence or any government document, and we do not learn your legal name from it. A verified badge on Gather means a real person completed the check — nothing more. We say "Verified", not "identity verified", because the stronger claim would not be true.

Consent is specific and revocable. We record which version of this notice you agreed to and when. If we change what is collected, who processes it, or how long it is kept, we publish a new version and ask again — your consent to the old text does not carry over. Withdrawing consent in Settings stops any future check; it does not retroactively undo a check already completed, and it may mean you can no longer join activities that require a verified badge.

Our verification provider is Persona Identities, Inc., a company incorporated in the United States. Their own handling of the image is described in their privacy policy at withpersona.com/legal/privacy-policy.

4. Why we use it, and our lawful basis

PurposeLawful basis (GDPR Art. 6)
Creating your account, showing your profile, running activities and group chatsPerformance of a contract
Taking payment for Gather PlusPerformance of a contract
Keeping tax and accounting records of paymentsLegal obligation
Sorting activities by distance, centring the mapConsent (your device location permission)
Sending push notificationsConsent (your notification permission)
The selfie liveness checkExplicit consent (Art. 9(2)(a), as biometric data)
Investigating reports, enforcing our rules, preventing fraud and fake accounts, keeping people safeLegitimate interests — ours and those of other users in a platform where people meet strangers in person
Fixing bugs and improving the appLegitimate interests

Where we rely on consent you can withdraw it at any time, and where we rely on legitimate interests you can object — section 9 explains how.

5. Who else sees it

We do not sell your personal data, and we have never sold it. We share it with the companies that run parts of the service for us, each bound to use it only on our instructions:

WhoWhat for
SupabaseDatabase, login, file storage and live chat delivery. This is where your account lives.
Persona Identities, Inc.The selfie liveness check (section 3).
StripeCard payments taken on the web. Stripe handles the card details directly; we receive only a customer reference and the subscription status.
Apple and RevenueCatSubscriptions bought inside the iOS app. Apple takes the payment; RevenueCat tells our servers whether your subscription is active.
ExpoDelivering push notifications to your device.
Google MapsDrawing the map and looking up venue addresses you search for.
CloudflareServing our domain and protecting it from attack.

We may also disclose data where the law requires it, or where it is necessary to protect someone's safety — for example, responding to a police request about a credible threat.

6. What other users can see

Gather is a social app, so some things are deliberately public to other signed-in users: your display name, photos, bio, city, country of origin, age, languages, interests, your verified badge, and your ratings — though ratings only appear once you have received at least three, so a single bad night does not define you.

Some things are yours to control or are deliberately withheld:

7. Where your data goes

Your account, your messages and your photos are stored on servers in Frankfurt, Germany, inside the European Union. Some of our providers — Persona, Stripe, RevenueCat, Expo, Google and Cloudflare — are based in the United States, so using Gather involves transferring personal data outside the EEA and the UK. Those transfers rely on the European Commission's Standard Contractual Clauses, or on an adequacy decision such as the EU–US Data Privacy Framework where the provider is certified under it.

8. How long we keep it

9. Your rights

Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or send it to another service. You can withdraw consent at any time without affecting what we did before you withdrew it.

Two of these are built into the app and take effect immediately, with no need to email anyone:

For anything else, write to support@wegather.fun and we will respond within one month. If you think we have handled your data badly, you can complain to your national data protection authority — in Spain the AEPD, and in Bulgaria the Commission for Personal Data Protection (cpdp.bg), which is our lead authority because that is where we are established — but we would rather you told us first.

10. If you are in the United States

Several US states regulate biometric information specifically, and Illinois' Biometric Information Privacy Act requires us to publish how long we keep it and when we destroy it. This is that schedule:

Biometric retention and destruction schedule. Gather does not collect, capture, store or possess any biometric identifier or biometric information. The selfie used for the liveness check is transmitted to and processed by Persona Identities, Inc.; Gather receives only a pass or fail result, a timestamp and a reference number, none of which is a biometric identifier. Where Persona holds biometric information on our behalf, it is destroyed in line with Persona's retention policy and in any event no later than three years after your last interaction with Gather, or when the purpose of the check has been satisfied, whichever comes first. Your consent record is destroyed when your account is deleted.

We do not sell personal information and we do not share it for cross-context behavioural advertising, as those terms are defined under California law. If you are a California resident you may still request access to or deletion of your personal information using the Settings options above, and we will not discriminate against you for exercising those rights.

11. Age

Gather is for adults. You must be 18 or over to create an account. We do not knowingly collect data from anyone under 18, and if we learn that we have, we delete the account.

12. Security

Access to your data is enforced at the database itself, not only in the app, so a flaw in one screen cannot expose another person's account. Passwords are hashed, traffic is encrypted in transit, and payment card details never reach our servers. No system is perfectly secure, and we will tell you and the relevant authority without undue delay if a breach puts you at risk.

13. Changes

If we change this policy we update the version at the top. For ordinary changes we will tell you in the app. For anything that changes what we collect about your selfie, who processes it, or how long it is kept, we will ask for your consent again — the new version does not apply to you until you agree to it.

14. Contact

Yuliyan Manolov, [[REGISTERED ADDRESS]], Bulgaria
support@wegather.fun