Gather — Privacy Policy
Last updated: 14 July 2026
This policy explains what personal data Gather (“the app”, “we”) collects, why, and your rights. Gather is operated from Norway and complies with the EU General Data Protection Regulation (GDPR) as incorporated into Norwegian law (personopplysningsloven).
1. Who is responsible
The data controller is Victor Skaar, Oslo, Norway, contactable at vnskaar@gmail.com. Because we are established in the EEA, no Article 27 EU representative is required.
2. What we collect
- Account data: email address, and the display name and avatar you choose.
- Content you create: events (title, description, date, time, location, cover photo), groups (name, description, cover photo), RSVPs, polls, shared lists, discussion messages.
- Availability: dates you mark yourself unavailable, if you use that feature.
- Invitations: when you invite someone by email, we process that email address to deliver the invitation.
- Technical data: if crash reporting is enabled, diagnostic data (device model, OS version, error stack traces) is processed by our error-monitoring provider. We do not collect precise location, contacts, advertising identifiers, or payment data, and we do not use tracking for advertising.
3. Why we process it, and our legal basis (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Create and operate your account | Performance of a contract (Art. 6(1)(b)) |
| Show your events/groups to invited people | Performance of a contract |
| Send invitations you initiate | Legitimate interests (Art. 6(1)(f)) — enabling you to invite guests |
| In-app notifications about your activity | Legitimate interests |
| Crash/diagnostics to keep the app working | Legitimate interests |
| Marketing messages (if any) | Consent (Art. 6(1)(a)), opt-in only |
4. Sharing and processors
We do not sell your data. We use these processors under GDPR-compliant data processing agreements:
- Supabase (database, auth, storage) — hosted in the EU (Ireland).
- Sentry (crash reporting, if enabled).
- Expo, Apple, Google (app delivery and push notifications).
Some processors may transfer data outside the EEA under Standard Contractual Clauses or an adequacy decision. Content you post is visible to the people you share it with (group members, event invitees). Cover photos are stored in public storage buckets, meaning anyone with the direct file link can view them — do not upload images you consider private.
5. Retention
We keep your data while your account is active. When you delete your account (Profile → Delete account), your account, profile, and the events and groups you created are permanently deleted. Backups are purged on our provider’s rolling schedule.
6. Your rights (GDPR Art. 15–21)
You have the right to access, correct, delete, restrict, object to, and receive a portable copy of your data. In the app you can export your data (Profile → Download my data) and delete your account (Profile → Delete account). For any other request, contact vnskaar@gmail.com. You may also lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no).
7. Children
Gather is not intended for anyone under 16. You must confirm you are 16 or older to create an account. We do not knowingly collect data from children under this age; contact us if you believe a child has provided data.
8. Security
Data is encrypted in transit. Authentication tokens are stored in the device’s secure keychain. Access to your data is enforced by database row-level security. If a breach affects your data, we will notify the authority within 72 hours as required, and you where legally required.
9. Changes
We may update this policy; material changes will be communicated in-app. Continued use after an update constitutes acceptance.
10. Contact
Victor Skaar · vnskaar@gmail.com