Privacy Policy for Gather
Last Updated: May 12, 2026 · Effective Date: May 12, 2026
1. Introduction
Gather ("the App," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the Gather mobile application.
This Privacy Policy complies with the General Data Protection Regulation (GDPR) and other applicable data protection laws. By using Gather, you agree to the practices described in this policy.
2. Data Controller & Contact
Data Controller: Gather
Contact Email: terrymaher3@gmail.com
Jurisdiction: European Union
If you have questions about this Privacy Policy or your personal data, please contact us at the email above.
3. What Personal Data We Collect
3.1 Information You Provide Directly
- Email address — Used for account creation and authentication
- Nickname & username — Used for your public profile and display in the app
- Password — Hashed and stored securely for authentication
- Avatar/Profile photo — Optional image you upload to customize your profile
- Photos you share — Images you upload to your Uploads or share to Tables
3.2 Information Automatically Collected
- Push notification tokens — Device identifiers used to send push notifications
- Account metadata — Creation date, last login, authentication events
- Device information — OS version, app version (for analytics and debugging)
- Usage data — Which features you interact with (tables created, photos shared)
3.3 Information We Do NOT Collect
- We do not collect location data
- We do not sell or share your data with third parties for marketing
- We do not use tracking cookies or analytics tools
- We do not audit or log password reset attempts
4. Legal Basis for Processing
We process your personal data based on the following lawful grounds:
- Contract performance — Your data is necessary to provide the Gather service
- Legal obligation — We retain certain data as required by law
- Legitimate interest — We use data for account security, fraud prevention, and service improvement
- Consent — For push notifications, you must opt-in via device permissions
5. How We Use Your Data
Your data is used to:
- Create and manage your account
- Authenticate you securely
- Enable photo sharing within Tables
- Send push notifications for new messages, connection requests, and accepted connections
- Provide technical support
- Prevent abuse and fraud
- Comply with legal obligations
6. Data Storage & Security
- Storage location: Your data is stored on Supabase servers in compliance with GDPR
- Encryption: Passwords are hashed using industry-standard algorithms
- Access: Only authorized Gather staff can access your data
- Retention: We retain your data as long as your account is active; see Section 9 for deletion rights
7. Third-Party Services
Gather uses the following third-party services:
7.1 Supabase
- Purpose: Backend database and authentication
- Data shared: Email, nickname, username, profile photo, photos, push tokens
- Privacy Policy: https://supabase.com/privacy
- GDPR compliance: Supabase maintains a Data Processing Agreement (DPA) with users in the EU
7.2 Expo Push Notifications
- Purpose: Delivery of push notifications to your device
- Data shared: Push notification tokens, notification content
- Privacy Policy: https://expo.dev/privacy
7.3 Firebase Cloud Messaging (Android only)
8. Your Rights Under GDPR
You have the following rights regarding your personal data:
8.1 Right to Access
You can request a copy of all personal data we hold about you.
8.2 Right to Rectification
You can correct or update your personal data in your account settings.
8.3 Right to Erasure ("Right to Be Forgotten")
You can delete your account and all associated data directly within the app — no need to contact us. To do this:
- Open Gather and sign in
- Tap the gear icon on the Tables screen to open Settings
- Tap Delete Account
- Confirm the deletion
This permanently and immediately deletes your account, profile, photos, comments, reactions, connections, and all other personal data associated with your account. You can also request deletion by emailing terrymaher3@gmail.com if you're unable to access the app.
8.4 Right to Restrict Processing
You can restrict how we use your data for specific purposes.
8.5 Right to Data Portability
You can request a machine-readable copy of your data in a standard format.
8.6 Right to Object
You can opt out of certain data processing activities (e.g., push notifications).
8.7 Right to Lodge a Complaint
If you believe we've violated your privacy rights, you can file a complaint with your local data protection authority (e.g., GDPR supervisory authority in your EU member state).
To exercise any of these rights, contact us at terrymaher3@gmail.com.
9. Data Retention
- Active accounts: Data is retained as long as your account is active
- Deleted accounts: When you delete your account, we permanently delete your personal data within 30 days, except where required by law
- Backup retention: Backups may be retained for up to 90 days for disaster recovery purposes
- Legal holds: Data may be retained longer if required by law or pending legal proceedings
10. Children & Age Restrictions
Gather is not intended for users under 13 years of age. We do not knowingly collect data from children under 13. If we discover we've collected data from a child under 13, we will delete it immediately. Parents or guardians who believe their child has used Gather should contact terrymaher3@gmail.com.
11. Changes to This Privacy Policy
We may update this Privacy Policy periodically. We will notify you of changes by updating the "Last Updated" date. Your continued use of Gather constitutes acceptance of the updated Privacy Policy.
12. Disclaimer on Data Security
While we implement industry-standard security measures, no system is completely secure. We cannot guarantee absolute security of your data. You use Gather at your own risk. We recommend using a strong, unique password and enabling device-level security features.
13. Governing Law
This Privacy Policy is governed by the laws of the European Union, specifically GDPR and the laws of member states where users reside.