Privacy Policy
Last updated: 23 September 2026 · Effective immediately for all European and global users.
GPS sharing is strictly opt-in. Pause anytime with Ghost Mode or Ghost Mode+, or set an auto-expiring timer.
AI persona flairs use broad categories only. Never raw GPS, private DMs, or financial data.
We never sell or monetize your data. Telemetry is privacy-first and requires explicit prior consent.
This Privacy Policy explains how DPA TECH SOLUTIONS S.R.L. (“WhereU”, “we”, “us”, “our”) collects, uses, processes, stores, and protects personal data when you use the WhereU mobile application, progressive web app (PWA), website at whereu.fun, and associated native platforms for Android and iOS (collectively, the “Service”).
We act as the Data Controller under Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation – GDPR), Romanian Law no. 190/2018 on the implementation of the GDPR, Directive 2002/58/EC (ePrivacy Directive), the European Union Artificial Intelligence Act (EU AI Act), and applicable global data protection frameworks (including CCPA/CPRA).
1. Data Controller & Data Protection Officer (DPO)
Controller Legal Identity:
DPA TECH SOLUTIONS S.R.L.
Company Registration Number (Reg. Com.): J2026024656007
Sole Registration Code / Tax ID (CUI): 54485223
Incorporated and registered in Romania, European Union.
Contact Channels:
- Data Protection Officer (DPO): privacy@whereu.fun or dpo@whereu.fun
- General Legal Notices: legal@whereu.fun
- Customer Support: support@whereu.fun
2. Categories of Data We Collect
We process personal data only when necessary to provide the real-time social mapping and event discovery services you request:
A. Account & Identity Information
- Credentials: Email address, encrypted authentication tokens, and user IDs managed via Supabase Auth.
- Profile details: Chosen username, display name, avatar photo, personal biography, social profile links, and preferred interface language (English, Romanian, German, Bulgarian, Spanish, Portuguese).
- Registration metadata: Invite code verification, whitelist eligibility records, and account creation timestamp.
B. Real-Time & Background Geolocation Data
WhereU is a location-powered social network designed to help friends meet up in real life (“IRL”):
- Live GPS tracking: Latitude, longitude, horizontal accuracy, altitude, speed, and heading sampled while the app is active or when you explicitly enable background tracking.
- Battery-adaptive tracking: Our background position tracker detects stationary intervals and pauses unnecessary database writes until movement resumes.
- Ghost Mode & Ghost Mode+: You retain complete control to pause location broadcasting instantly (“Ghost Mode”) or blur your position to a broad neighborhood zone (“Ghost Mode+”). You may also set automated countdown timers to revert to Ghost Mode automatically.
- Dwell stop detection: When your device remains in a specific vicinity for 15 minutes or longer, our system records a dwell stop to assemble your personal daily activity timeline and visited spots. Live public markers are restricted to 15 minutes of recency.
- Spatial resolution & geocoding: We reverse-geocode coordinates using multi-tier spatial engines covering Romanian cartiere and administrative zones (such as Mamaia Nord / Năvodari and Bucharest sectors), German cities, European capitals, and global discovery databases.
- Converge Radar HUD & Proximity Alarms: Proximity calculations, edge directional pointers, and audio alarm synthesizers run locally to signal when authorized friends or planned meetups are nearby. Synthesized alarm audio is generated on-device via Web Audio API and is never transmitted to servers.
C. Social Interactions, Meetups & Check-ins
- Social graph: Friend connections, squads, friend requests, user blocks, and safety reports.
- Direct & Group Communications: In-app chat messages, emoji reactions, read receipts, pings, vibe checks, and pulse handshakes (shake-to-connect proximity discovery).
- Venues, Mayorships & Leaderboards: Venue check-ins, top regular rankings, and community mayorship badges. Users may opt out of appearing on public venue regular boards in their privacy settings.
- Events & Flash Perks: Event RSVPs, ticket passes, curated venue Flash Perk claim sheets, and merchant redemption records.
D. Artificial Intelligence & Persona Flairs
- AI Persona Badges & Summaries: To add playful context to your profile (e.g., “Night Owl” or “Art Explorer”), we process aggregated category visit frequencies through Google Gemini models (served via the Lovable AI Gateway).
- Privacy Safeguards: No private direct messages, sensitive chat logs, financial details, or precise GPS coordinates are ever provided to LLM services. All processing uses anonymized category statistics.
- User Control: In accordance with Article 22 GDPR and the EU AI Act, this feature is completely voluntary. You can regenerate, edit, clear, or toggle off AI persona flairs at any time in your profile settings.
E. Model Context Protocol (MCP) & Agent Tool Integrations
- When you authorize external AI assistants (such as Claude, Cursor, or Antigravity) to access your WhereU profile via the Model Context Protocol (
whereu.fun/mcp), we log the granted permission scopes, issued bearer tokens, and authenticated request timestamps. You can revoke tool permissions instantaneously.
F. Subscriptions, Invoicing & Payment Data
Payment processing depends on the platform through which you access the Service:
- Google Play In-App Billing (Android): When you purchase or subscribe to WhereU PRO through the Android application distributed on Google Play, your payment is processed directly by Google LLC / Google Ireland Ltd. We receive cryptographic confirmation of active subscription status, purchase tokens, and expiration timestamps. We never receive, process, or store credit card or financial account numbers.
- Apple In-App Purchases (iOS): When you purchase or subscribe to WhereU PRO on iOS devices via the App Store, transactions are processed directly by Apple Inc. / Apple Distribution International Ltd. We receive transaction receipts and renewal status from Apple. We never receive or store your payment card or billing information.
- Web Checkout & Event Ticketing (Stripe): Purchases made on the web platform (
whereu.fun), Host Hub subscriptions, and independent event ticket passes are securely processed through Stripe Payments Europe, Ltd. We store subscription status, expiration timestamps, and masked card details (last four digits and brand) returned by Stripe for fiscal invoicing. Full card details never touch our servers.
G. Technical Telemetry, Device Info & Push Notifications
- Device data: Device model, operating system version, browser family, screen resolution, and temporary IP address (retained for rate limiting, DDoS defense, and fraud prevention).
- Push notification tokens: Apple Push Notification service (APNs), Firebase Cloud Messaging (FCM), and Web Push tokens, stored only when you grant OS or browser notification permission.
- Behavioral analytics: Screen views, search terms, filter choices, and feature interactions are recorded in
public.behavior_eventswith a rotating per-tab session ID only after you accept analytics cookies or telemetry. We do not engage in cross-site tracking or advertising profile construction.
3. Legal Bases for Processing (GDPR Article 6)
| Purpose of Processing | Categories of Data | GDPR Legal Basis |
|---|---|---|
| Account creation, profile management, and social meetup discovery | Account, profile, friend connections, squad memberships | Article 6(1)(b) – Performance of a contract |
| Live GPS broadcasting and proximity alarms to approved friends | Precise & background GPS coordinates, speed, heading | Article 6(1)(a) – Explicit consent (withdrawable anytime) |
| Push notifications for friend pings, proximity alerts, and chats | APNs / FCM / WebPush device tokens | Article 6(1)(a) – Consent (via OS/browser prompt) |
| Product telemetry, error monitoring, and behavioral analytics | In-app interaction events, error reports, session IDs | Article 6(1)(a) – Consent (via Cookie & Telemetry settings) |
| AI persona flairs and category summaries | Aggregated venue category visit counts | Article 6(1)(a) – Consent (customizable in profile) |
| Platform security, anti-stalking safeguards, and DDoS mitigation | IP addresses, audit logs, rate limit counters, safety reports | Article 6(1)(f) – Legitimate interests |
| Subscription billing, ticket invoicing, and fiscal accounting | Payment receipts, transaction amounts, VAT identification | Article 6(1)(c) – Legal & statutory obligation |
4. Third-Party Sub-Processors & International Data Transfers
We do not sell, rent, or trade your personal data. We engage vetted sub-processors strictly to deliver infrastructure, security, and application functionality:
- Supabase Inc. (USA / EU): Cloud database hosting, user authentication, edge functions, and encrypted object storage. Data is hosted in the EU (Frankfurt) with standard contractual safeguards.
- Google LLC / Google Ireland Ltd. (USA / EU): Google Play In-App Billing for Android subscriptions, Firebase Cloud Messaging (FCM) for push notifications, and Google Gemini API for optional profile persona summaries.
- Apple Inc. / Apple Distribution International Ltd. (USA / EU): Apple In-App Purchase (IAP) for iOS subscriptions, Apple Push Notification service (APNs), and Apple Sign-In authentication.
- Stripe Payments Europe, Ltd. (Ireland / Global): Payment processing, organizer payouts, subscription portal, and ticketing invoicing for web-based purchases on
whereu.fun(PCI-DSS Level 1 compliant). - Cloudflare, Inc. (USA / Global): TLS termination, CDN asset delivery, DDoS defense, and privacy-preserving web analytics.
- Mapbox / MapTiler / OpenStreetMap Foundation: Map tiles, vector cartography, and OSRM routing.
- Resend Inc. (USA / EU): Transactional emails (verification codes, pass receipts) sent from
notify.whereu.fun.
Where personal data is transferred outside the European Economic Area (EEA), we enforce the European Commission’s Standard Contractual Clauses (SCCs) pursuant to GDPR Article 46 to guarantee an equivalent level of protection.
5. Data Retention & Erasure Schedules
- Live location coordinates: Active positions expire from public map querying after 15 minutes of inactivity. Historical movement trajectories are stored for 30 days (extended up to 12 months for WhereU PRO subscribers for personal rewind), after which they are permanently expunged.
- Direct and group messages: Retained until manually deleted by conversation participants or upon account deletion.
- Behavioral analytics: Event logs in
public.behavior_eventsare maintained on a 90-day rolling retention cycle. You can delete all your analytics data at any time via in-app settings. - Account profile & uploads: Maintained while your account remains active. Upon initiating deletion, your account is immediately deactivated and scheduled for full permanent erasure within 30 days.
- Accounting & fiscal records: Invoices, ticket transaction records, and tax receipts are archived for 10 years in compliance with Romanian and European fiscal statutory requirements (Law no. 82/1991).
6. Your Statutory Rights Under the GDPR
As a data subject in the European Union, you possess comprehensive rights regarding your personal data:
- Right of Access (Article 15 GDPR): You have the right to obtain confirmation and receive a copy of your personal data. You can request a JSON export directly from your profile settings.
- Right to Rectification (Article 16 GDPR): You can update inaccurate profile details, avatars, or usernames at any time.
- Right to Erasure / “Right to be Forgotten” (Article 17 GDPR): You can permanently delete your account and all associated data self-serve at whereu.fun/data-deletion without having to send an email.
- Right to Restriction of Processing (Article 18 GDPR): You can request suspension of processing under statutory dispute conditions.
- Right to Data Portability (Article 20 GDPR): You can export your profile, check-in history, and friends list in a structured, machine-readable format.
- Right to Object (Article 21 GDPR): You may object at any time to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent (Article 7(3) GDPR): You can withdraw consent for location sharing (via Ghost Mode), push notifications (via device settings), or analytics (via our Cookie Preference Center).
- Rights regarding Automated Decisions (Article 22 GDPR): We do not conduct automated profiling that produces legal effects. AI flairs remain completely under your review and control.
To exercise your rights, email our DPO at privacy@whereu.fun. We respond to all verified inquiries within 30 calendar days at no charge.
7. Supervisory Authority Complaints
You have the right to lodge a complaint with our lead data protection supervisory authority:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
Address: B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, postal code 010336, Bucharest, Romania
Website: dataprotection.ro
Email: anspdcp@dataprotection.ro
You also retain the right to submit a complaint to the national data protection authority in the EU Member State of your habitual residence or workplace.
8. Age Restriction & Protection of Minors
In compliance with GDPR Article 8 and Romanian Law no. 190/2018, WhereU is strictly restricted to individuals who are 16 years of age or older. We do not knowingly collect personal data from minors under 16. If we become aware that an account was created by an individual under 16, we will immediately terminate the account and purge all associated records.
9. Security Measures
We implement comprehensive technical and organizational measures to ensure a level of security appropriate to the risk:
- Full encryption in transit using TLS 1.3 / HTTPS across all client, API, and WebSocket connections.
- Database encryption at rest utilizing AES-256 standards.
- PostgreSQL Row-Level Security (RLS) policies guaranteeing that location and message records can only be queried by authorized friends and participants.
- Strict principle of least privilege for backend services, rotating cryptographic JWT tokens, and automated anomaly detection.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect platform enhancements or regulatory changes. If we introduce material updates, we will notify you via in-app announcement, email, or a prominent notice on whereu.fun at least 15 days prior to implementation.