Privacy policy

Last updated: 8 August 2026

Protecting your personal data matters a great deal to us. In this privacy policy we explain which data we collect, how we use it and what rights you have.

1. Controller

Gathered UG (haftungsbeschränkt) i.G.

Represented by its managing director: Lenny Anzalichi

Berliner Straße 10

63110 Rodgau, Germany

Email: Lenny@gathered.world

Commercial register: Offenbach am Main Local Court, HRB [to be added once registered]

Data protection officer (Art. 37 GDPR)

Under § 38 BDSG (German Federal Data Protection Act) we are not required to appoint a data protection officer, because fewer than 20 people are permanently engaged in the automated processing of personal data. Our core activity also does not require extensive regular and systematic monitoring (Art. 37 (1) (b) GDPR). For data protection enquiries: Lenny@gathered.world

2. What data we collect

2.1 Account data

When you register we collect:

2.2 Location data

With your permission we collect your location in order to:

If you have consented to location use and no city is stored in your profile yet, we derive your city from your approximate position and save the city name (not exact coordinates) in your profile — among other things for aggregated event statistics. You can change the city in your profile at any time.

In addition we store a coarsened location, so that we can send you notifications about new events in your area. When you open the App your position is rounded to a grid of roughly 39 km × 20 km and only that grid cell is stored (technically: a four-character geohash) — never your exact coordinates and never a movement history. We store only the most recently known grid cell, updated at most once a day. Until August 2026 this grid was much coarser at roughly 156 km × 156 km; the refinement was necessary because no meaningful nearby recommendation can be derived from a cell that large. We do not store the value more precisely than this grid.

You can withdraw the location permission at any time in your device settings. Without location access you will not receive notifications about events in your area; all other features remain usable.

2.3 Usage data and technical diagnostic data

For product improvement and technical diagnosis we collect, in the normal App, event-only usage data without an account ID and without deliberate cross-session linking. An explicit objection in the privacy settings stops this collection. This includes in particular:

For this we use Firebase Analytics, Firebase Crashlytics, Firebase Performance Monitoring and PostHog. Message and chat content, event titles and descriptions and exact location data are not transmitted to these providers as product analytics properties; at most, anonymised feature usage (e.g. "message sent") may be recorded.

2.4 Session replay (separate opt-in)

PostHog session replay is completely disabled in the normal App until you expressly activate the consent provided for it. If consent is active, anonymised screen states and interactions are processed for error and usability analysis on a sample of currently 10 % of sessions. Text, input fields, images and platform views (e.g. maps, web views or camera views) are masked on the device itself. Native system screens and network and log content are not recorded.

For expressly selected internal TestFlight testers, a separately built test mode can enable retention with an account ID and session replay at a 100 % sample. This build uses the same event schema as the production app and is not intended for public or production tracks.

Session replay is a separate purpose and is not automatically part of the consent for anonymous product statistics. You can withdraw the consent at any time under Settings > Privacy & security . After that no new recordings are created; recordings already stored are deleted at the latest after PostHog’s current retention period of 30 days, unless they are deleted earlier.

2.5 Event data

When you create an event we store:

2.6 Technical data / device fingerprint

To prevent fraud we create an anonymised device hash (SHA-256). It is used only temporarily to detect abuse (rate limiting) and is not stored permanently.

2.7 Aggregated event statistics (Crowd Insight)

For public events we produce aggregated, anonymised statistics about the confirmed guests ("Crowd Insight"). For this we process the following guest profile details server-side:

Purpose: to give guests and hosts an anonymous impression of the expected crowd at an event (e.g. age-group distribution, share of guests from the event’s city).

Recipients: The statistics are seen only by paying "Gathered Pro" subscribers and by the host of the event in question — both see only the aggregates. Values for individual guests cannot technically be retrieved, not even by subscribers. Statistics are shown only from 2 confirmed guests, the full detail view only from 5 — so no conclusions about individuals can be drawn. Guests with a private profile are also included in the anonymous aggregates.

Retention period: The aggregated statistics are kept until 7 days after the event ends and then deleted automatically; immediately if the event is deleted.

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in anonymised event statistics). Objection (Art. 21 GDPR): You can object at any time to your profile details being included — you will then only be counted in "unknown" categories. Until there is a switch for this in the app settings, an email to the following address is enough: Lenny@gathered.world.

2.8 Ratings (Gathered Score)

After an event, verified attendees can rate the event or the host from 0 to 10 ("Gathered Score"), optionally with a public text. Hosts can in turn rate their guests. In doing so we process:

Anonymity: The bare numeric value is published without your name — only a continuously updated average of all ratings is visible. Note: for events with very few ratings, the host may under some circumstances be able to draw conclusions about individual ratings (e.g. if only one person rated). If you write a text, you decide yourself whether it appears anonymously or with your name (default: anonymous); for anonymous texts the publication time is additionally coarsened to the calendar day. The anonymity applies towards other users — not towards us as the operator: server-side, your rating remains linked to your account (necessary for moderation, abuse prevention, reports under the Digital Services Act and the deletion of your data).

Guest ratings: Ratings given by hosts about guests are never public. Hosts see only an aggregated average in the context of attendance requests. You can view your own guest average in the App at any time (Art. 15 GDPR).

Retention period: Ratings are kept for as long as your account exists. If you delete your account, the ratings you have given and those given about you are deleted and the averages corrected accordingly; in addition you can delete public texts yourself at any time.

Legal basis: Art. 6 (1) (b) GDPR (the rating feature as part of the service) and Art. 6 (1) (f) GDPR (legitimate interest in a trustworthy, safe rating system and in preventing abuse).

2.9 School/university network ("Your school/university")

You can voluntarily state your school or university in order to see who from your institution uses Gathered and to be informed about new events from your institution. In doing so we process:

Visibility: As soon as you enter a school/university, you appear in a member list that is visible solely to other users who have entered the same school/university. Only your display name and profile picture are visible there — the same data as in your public profile. The bare counter ("X people are here") is aggregated and allows no conclusions about individuals. We do not publish anywhere a searchable list of a school or one retrievable by outsiders; retrieval is technically limited to logged-in members of the same institution.

Objection / hiding (opt-out): You can switch off your visibility at any time in the privacy settings. You then disappear from the member list immediately and your public events are no longer attributed to your institution; the aggregated counter remains. You can also remove your school/university entirely.

Event notifications: If you create a public event while your school visibility is active, members of the same institution may receive a push notification about it (provided they have allowed notifications). Private events, link-only events and group-internal events are never included here.

Friend invitations: If you invite friends via an invitation link, that link contains an identifier for your school/university and a referral identifier, so that your institution is suggested to the invited person. No contact data from your address book is processed in the process.

Note on verification: The school/university you state is not separately verified. Only enter details you are happy to disclose.

Retention period: Your school/university assignment is stored for as long as you keep it entered or your account exists. If you remove the entry or delete your account, it is deleted and the aggregated counter corrected accordingly.

Legal basis: Art. 6 (1) (a) GDPR (consent through the voluntary entry, withdrawable at any time via the visibility switch) and Art. 6 (1) (f) GDPR (legitimate interest in connecting users of the same institution). For minors aged 16 and over we rely on their own consent under Art. 8 GDPR; Gathered can be used from the age of 16 (see clause 10).

2.10 Campus Pulse ("who is doing what / who is going where")

Campus Pulse is part of the school/university network (section 2.9) and makes it visible to members of your institution who is currently taking part in which activity or event. There are two kinds:

In doing so we process:

No location data: No GPS or location data is collected for the pulse itself. A plan pulse consists only of a template or short text (please do not enter a precise address there — a corresponding note appears in the App); an event pulse merely refers to an event that is already public.

Visibility: Pulses and their participants (display name and profile picture in each case — the same data as in your public profile) are solely visible to logged-in members of the same institution whose campus is open. There is no pixelation (real names and faces). People you have blocked, or who have blocked you, do not see your pulses and vice versa. A pulse therefore shows your fellow pupils or students what you are currently taking part in — only create or join pulses whose visibility you are willing to accept.

Push notifications: Members of your institution can — provided they have allowed notifications — be informed about new pulses. These lock-screen notices are deliberately anonymised (no name, no place — e.g. "New pulse on your campus" or "X people from your campus are going"). A join request and its confirmation contain the respective display name and go to exactly one person. Quiet hours (10 pm–8 am) and a daily cap apply.

Moderation and reporting: Free-text titles and chat messages go through an automated content check; impermissible content is blocked (see the content moderation section). You can report a pulse (reporting procedure under Art. 16 Digital Services Act).

Retention period: A plan pulse is deleted automatically at the end of the day; the associated chat remains until 24 hours after the pulse ends and is then removed automatically together with messages and open requests. An event pulse ends with the event, or is deleted immediately if the event is cancelled, set to private or deleted. If you switch off your school visibility, change institution or delete your account, your own pulses are deleted and you are removed from all participant lists and open requests.

Legal basis: Art. 6 (1) (a) GDPR (consent through voluntarily creating or joining a pulse) and Art. 6 (1) (f) GDPR (legitimate interest in the spontaneous connection of members of the same institution); content moderation is based on Art. 6 (1) (f) GDPR (platform safety). For minors aged 16 and over we rely on their own consent under Art. 8 GDPR; Gathered can be used from the age of 16 (see clause 10).

2.11 Direct messages (1:1 chat)

You can write to individual people directly. Such a chat is only possible if you have both confirmed the same event or you follow each other — there is no way to message someone straight from search or the feed. The first message to a person who has not yet accepted is a request: until the recipient accepts it, you cannot send another message.

In doing so we process:

Visibility: A chat is readable only by the two people involved. We do not access chat content without cause; access happens only if a message is reported or we are legally obliged to.

No end-to-end encryption: Your messages are encrypted in transit (TLS) and stored encrypted on our servers, but they are not end-to-end encrypted. Technically that means: content could be viewed by us, for example to process a report. If you want to exchange messages that nobody but the recipient should be able to see, please use an end-to-end encrypted messenger for that.

Automated content checking — scope: Text messages go through an automated word filter that blocks insults, threats and certain scam patterns. Photos and voice recordings are not automatically checked for their content, and even for text the word filter does not detect content that manages without the relevant terms. We point this out expressly so that you can take it into account when deciding whom you write to and what you send.

Reporting and blocking: You can report every single message — including a photo or a voice recording; the file in question is attached to the report for review (reporting procedure under Art. 16 Digital Services Act). You can block a person at any time; any further exchange is then ruled out in both directions.

Push notifications: We deliberately inform you about a new request without the sender’s name and without the message text (e.g. "Someone from one of your events has written to you"), so that unwanted content does not reach you unasked on your lock screen. Only after you accept do notifications contain the name and the message text. You can mute each chat individually.

Age: There is no age restriction within the 1:1 chat; Gathered as a whole can be used from the age of 16 (see clause 10).

Retention period: Accepted chats remain permanently so that a contact that has formed is not lost — you can delete individual messages at any time. A request that is not accepted is deleted automatically 14 days after the underlying event ends. If you delete your account, your messages are anonymised and the photos and voice recordings you sent are deleted; the other person’s conversation history otherwise remains, because it also contains their own data.

Legal basis: Art. 6 (1) (b) GDPR (performance of the user agreement — communication between participants is part of the service offered) and Art. 6 (1) (f) GDPR (legitimate interest in platform safety, for the word filter and the reporting and blocking functions).

3. Legal bases (Art. 6 GDPR)

Your personal data is processed on the following legal bases:

Processing Legal basis
Account creation, profile, event creation, tickets, chat Art. 6 (1) (b) GDPR (performance of a contract)
Push notifications Art. 6 (1) (a) GDPR (consent)
Usage statistics (PostHog, Firebase Analytics) Art. 6 (1) (f) GDPR (legitimate interest in product improvement; documented balancing of interests)
Session replay (PostHog, separate purpose) Art. 6 (1) (a) GDPR (separate consent)
ML-based event recommendations Art. 6 (1) (f) GDPR (legitimate interest: improving the user experience)
Aggregated event statistics (Crowd Insight, see section 2.7) Art. 6 (1) (f) GDPR (legitimate interest: anonymised statistics for subscribers and hosts)
School/university network and Campus Pulse (sections 2.8 and 2.9) Art. 6 (1) (a) GDPR (consent) and Art. 6 (1) (f) GDPR (legitimate interest in connecting members of the same institution)
Content moderation (automated) Art. 6 (1) (f) GDPR (legitimate interest: platform safety)
Fraud prevention (device fingerprint) Art. 6 (1) (f) GDPR (legitimate interest: protection against abuse)
Payment processing (Stripe) Art. 6 (1) (b) GDPR (performance of a contract)

4. Services and third-party providers

4.1 Firebase (Google)

We use Firebase (operator: Google Ireland Limited for EU customers, sub-processor: Google LLC, USA) for the following services:

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract) for Auth/Firestore/Storage/Functions/FCM/App Check; Art. 6 (1) (f) GDPR (legitimate interest in stability and product improvement, subject to the documented balancing of interests) for the event-only diagnostic channel. Account linking remains a separate purpose.

Privacy policy: firebase.google.com/support/privacy

4.2 Stripe

For paid events we use Stripe as our payment service provider. Stripe processes payment data as its own controller.

Privacy policy: stripe.com/de/privacy

4.3 PostHog

We use PostHog for product analytics, feature flags and — only after a separate opt-in — session replay. The project is configured in the EU region eu.i.posthog.com .

Privacy policy: posthog.com/privacy

4.4 Umami Analytics

For our website we use Umami Analytics — a cookieless, privacy-friendly web analysis tool. No personal data is collected.

Legal basis: legitimate interest (Art. 6 (1) (f) GDPR)

4.5 OpenAI

We use OpenAI for automated content moderation (checking text for inappropriate content). Content is transmitted only for moderation and is not used for training.

Privacy policy: openai.com/privacy

4.6 Google Cloud Vision

We use the Google Cloud Vision API for automated moderation of uploaded photos (detecting inappropriate image content). Uploaded images are transmitted to Google for analysis. Google processes the images solely to provide the service and not for its own purposes.

Legal basis: legitimate interest in the safety of our platform (Art. 6 (1) (f) GDPR)

4.7 RevenueCat (USA)

For processing in-app purchases (paid reach "Boost" and the "Gathered Pro" subscription) we use RevenueCat Inc. (600 California St, San Francisco, CA 94108, USA).

RevenueCat processes:

Third-country transfer: USA. RevenueCat is not certified under the EU-U.S. Data Privacy Framework (TADPF). The transfer takes place on the basis of EU standard contractual clauses (module 2, Commission Decision 2021/914).

Retention period: until your account is deleted, or a maximum of 7 years after the last transaction (tax retention obligation, § 147 AO German Fiscal Code).

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract)

Privacy policy: revenuecat.com/privacy

4.8 Brevo (EU)

For transactional emails relating to paid reach ("Boost") we use Brevo SAS (106 Boulevard Haussmann, 75008 Paris, France).

Brevo sends on our behalf:

Data processed: email address, name (if given in the withdrawal form), order number/purchase ID.

Third-country transfer: none — Brevo processes exclusively within the EU.

Retention period: email delivery logs are kept for 30 days and then deleted automatically.

Legal basis: Art. 6 (1) (c) GDPR (legal obligation — § 312f / § 356a BGB)

Privacy policy: brevo.com/privacy-policy

4.9 Sentry (USA)

For error monitoring (crash reports, non-fatal server errors) we use Functional Software Inc. dba Sentry (45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA).

Sentry processes:

The data processed serves solely the stability of the App and is not used for other purposes (advertising, profiling).

Third-country transfer: USA. The transfer takes place on the basis of EU standard contractual clauses (module 2, Commission Decision 2021/914).

Retention period: 30 days, deleted automatically (Sentry default).

Legal basis: Art. 6 (1) (f) GDPR (legitimate interest — providing an error-free service).

Privacy policy: sentry.io/privacy

4.10 Snap Camera Kit (USA) — AR filters in the event camera

When you use the camera while creating an event, you can apply AR filters ("lenses"). For this we use Camera Kit from Snap Inc. (3000 31st Street, Santa Monica, CA 90405, USA).

The filters run on your device. Your camera image is processed exclusively locally and is not transmitted to Snap. The photo or video you record ends up solely in your event in our EU storage.

The following is transmitted to Snap:

The SDK’s privacy manifest additionally discloses that it can technically access precise location data as well as environment, hand and head movement detection — the latter because lenses react to faces and movements. This processing takes place on the device and, according to Snap, is not linked to your person; use for tracking purposes is expressly excluded. Gathered itself does not carry out any app tracking.

Snap’s own terms of use: The first time you open the filters, Camera Kit itself shows you a notice about Snap’s terms of use, which you must confirm. Without that confirmation no filters are loaded.

Voluntary use: The filters are an add-on. You can take photos and videos without filters at any time; the camera then works entirely without Snap.

Third-country transfer: USA. Transfer on the basis of EU standard contractual clauses (module 2, Commission Decision 2021/914).

Legal basis: Art. 6 (1) (b) GDPR (performance of a contract — providing the filter feature you called up).

Privacy policy: snap.com/privacy · Camera Kit terms: snap.com/terms/camera-kit

4.11 Snapchat linking (optional) — Bitmoji as your profile picture

You can voluntarily link your Snapchat account in order to use your Bitmoji as your Gathered profile picture. Sign-in runs through Snap’s official login procedure (OAuth 2.0); Gathered never learns your Snapchat password.

The only thing retrieved is the image address of your Bitmoji avatar. The image is then stored in our EU storage like a normal profile photo. Snap’s access token is discarded immediately after the single retrieval and is not stored — Gathered then no longer has any access to your Snapchat account.

Voluntary; you can change your profile picture at any time. Legal basis: Art. 6 (1) (a) GDPR (consent), withdrawable by changing your profile picture.

5. Transfers to third countries (Art. 44-49 GDPR)

Some service providers may also process data outside the European Union. Where necessary, the transfer takes place on the basis of EU standard contractual clauses (SCCs) pursuant to Art. 46 (2) (c) GDPR and further appropriate safeguards. The specific processing depends on the service used in each case.

Service providers concerned:

6. Data storage and retention periods

Our project-related Firebase databases and storage are configured in EU regions (including europe-west1 and europe-west10) where available. Individual services such as Firebase Authentication, or technical sub-processors, may deviate from this. We store data only for as long as it is necessary to provide the App or as long as statutory retention periods apply.

Data category Retention period
Account data (name, email, profile picture) Until the account is deleted
Event data (past events) 12 months after the event ends
Ratings (Gathered Score) Until the account is deleted; public texts can be deleted by you at any time
Stories 24 hours (deleted automatically)
Chat messages Until the event or the group is deleted
Follower/following relationships Until the account is deleted
Payment data 10 years (statutory retention obligation, § 257 HGB German Commercial Code)
Moderation data (NetzDG) 10 weeks
Device fingerprint Only during the rate-limit window (max. 5 minutes), no permanent storage
Crowd Insight statistics (aggregated, section 2.7) Until 7 days after the event ends; immediately if the event is deleted
ML interaction data Until the user objects
Product analytics data (PostHog) Up to 30 days under the current project setting; withdrawal stops any further collection
Session replay recordings (PostHog) Up to 30 days under the current project setting; withdrawal stops any further recording
Campus Pulse (section 2.10) Plan pulse: until the end of the day; pulse chat: until 24 hours after the pulse ends; event pulse: until the event ends, or immediately if the event is cancelled, set to private or deleted

Automatic deletion runs daily at 3:00 (Europe/Berlin) through our server-side data cleanup system.

6a. Analytics model (three separate purposes)

Level 1 — anonymous product analysis and technical diagnosis

By default, PostHog and Firebase receive event-only events for analysing onboarding, navigation, feature use, errors and performance. The events contain no account ID and are not deliberately linked across app launches unless you separately enable personalised analysis. Content from messages and chats is not transmitted; only anonymised feature events may be recorded. You can refuse this collection in the privacy settings.

Level 2 — personalised analysis

Analytics data is linked to a pseudonymous internal account ID (no email address and no real name) only after separate consent following login. The personalised consent is independent of session replay.

Level 3 — session replay

Session replay is a separate, more intrusive purpose. Only with the replay switch active does PostHog process masked screen states and interactions for error and usability analysis, currently for 10 % of sessions. Text, input, images and platform views are masked on the device before transmission; native system screens and network and log content are not captured. You can withdraw the replay consent at any time under Settings > Privacy & security.

Legal basis: For the event-only channel, Art. 6 (1) (f) GDPR (legitimate interest in product improvement and stability; documented balancing of interests). Account-linked retention and session replay remain voluntary, separate purposes under Art. 6 (1) (a) GDPR. The internal test mode is intended exclusively for selected TestFlight testers.

7. Automated decision-making (Art. 22 GDPR)

We use machine learning to personalise event recommendations. There is not no automated individual decision-making within the meaning of Art. 22 GDPR. All recommendations are non-binding suggestions with no legal effect.

8. Your rights

You have the following rights regarding your data:

Right to withdraw consent (Art. 7 (3) GDPR)

Where the processing of your data is based on your consent (e.g. push notifications, personalised analytics or session replay), you can withdraw that consent at any time. For the event-only analytics channel you can object at any time or disable it in the privacy settings. Withdrawal does not affect the lawfulness of processing carried out up to that point. You can exercise your consent or objection as follows:

Right to object (Art. 21 GDPR)

You can object to the processing of your data at any time:

If you object to personalised recommendations, your ML data is deleted without delay.

Export or delete data

In the App under Profil > Einstellungen > Privacy you can:

9. Data security

We use technical and organisational measures:

10. Minors

The App is aimed at people aged 16 and over. We do not knowingly collect data from children under 16.

11. Changes

We may update this privacy policy. We will inform you in the App of any material changes.

12. Contact and right to lodge a complaint

If you have questions about data protection, contact us:

Email: Lenny@gathered.world

You have the right to lodge a complaint with a data protection supervisory authority, e.g. the Hessian Commissioner for Data Protection and Freedom of Information (HBDI).