Privacy Policy
1. Controller
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
[Company Name GmbH] [Street and number], [Postcode] Berlin, Germany Email: hello@mawatu.app
[Optional, if appointed:] Data Protection Officer: [Name, contact details]
This Privacy Policy applies to the mawatu website (mawatu.app), the mawatu mobile app, and related services (together, the "Service").
2. Overview and legal bases
We process personal data only where necessary to operate the Service, comply with law, or where you have given consent. Common legal bases:
- Art. 6(1)(b) GDPR — performance of a contract or pre-contractual steps (account, core app features, subscriptions).
- Art. 6(1)(a) GDPR — your consent (e.g. newsletter, optional notifications, live location sharing, marketing cookies if ever enabled).
- Art. 6(1)(f) GDPR — legitimate interests (security, fraud prevention, product stability, handling enquiries) where your interests do not override ours.
- § 25 TDDDG — storage/access on your device (cookies/local storage) as described in section 4.
We do not sell your personal data. We do not use advertising trackers or the Apple IDFA.
3. Website hosting and server log files
This website is hosted by Vercel Inc., 340 S Lemon Ave #4133, Walnut, CA 91789, USA, as our processor. When you access the site, Vercel processes technical access data (e.g. IP address, date/time, URL requested, browser type, referrer) to deliver the site securely (Art. 6(1)(f) GDPR).
Transfers to the USA are safeguarded by the EU Commission's Standard Contractual Clauses (Art. 46 GDPR) and/or, where applicable, the EU-US Data Privacy Framework.
4. Cookies, local storage, and consent
Strictly necessary technologies (e.g. admin login session cookies, remembering your privacy choice in local storage) do not require consent (§ 25 (2) TDDDG; Art. 6(1)(f) GDPR).
Non-essential categories (analytics, marketing) are only activated after opt-in via our consent banner (Art. 6(1)(a) GDPR; § 25 (1) TDDDG). Non-essential categories are off by default. You can change or withdraw your choice anytime via "Cookie settings" in the footer.
At present we do not load any analytics or marketing scripts on the public website.
5. Waitlist (website)
If you join the beta waitlist, we process your email address, optional first name, chosen platform (iPhone/Android/either), the consent text shown at sign-up, and technical metadata (IP address, user agent, timestamp) to manage early access and prove consent (Art. 6(1)(a) and (b) GDPR). Data is stored in our database (Supabase, EU region). We delete waitlist entries when they are no longer needed for this purpose.
6. Newsletter (double opt-in)
Newsletter sign-up uses double opt-in: we send a confirmation link; only after you confirm are you subscribed. We log sign-up, confirmation, consent wording, and technical metadata (IP, user agent) to demonstrate consent (Art. 6(1)(a) GDPR; § 7 (2) UWG).
You may unsubscribe anytime via the link in each email or by contacting us.
Emails are sent via Resend, Inc. (processor). If data is processed outside the EU/EEA, safeguards under Art. 46 GDPR apply.
7. Partner enquiries (website)
The partner form collects name, email, company, website, Instagram handle, partner type, message, and technical metadata (IP, user agent) to handle your enquiry (Art. 6(1)(b) or (f) GDPR). Data is deleted when no longer needed, unless statutory retention applies.
8. Contact
If you email us or contact us through the addresses on this site, we process the data you provide to respond (Art. 6(1)(b) or (f) GDPR).
9. Backend infrastructure (Supabase)
We use Supabase, Inc. as processor for authentication, database, file storage, serverless functions, and realtime features. Production data is hosted in the EU (Frankfurt am Main, Germany) unless otherwise stated. A data processing agreement pursuant to Art. 28 GDPR is in place.
10. mawatu app — registration and account
You can register using email and password, Sign in with Apple, Google, or phone number (SMS OTP). We process the credentials and identifiers required for authentication and account recovery (Art. 6(1)(b) GDPR).
Your Supabase user ID is used across the Service. We do not use your data for cross-app advertising tracking.
11. Profile and community data
Depending on your use, we process profile information such as:
- Display name, age (18+), gender, meeting preferences, bio
- Travel styles, languages, interests
- Optional social handles (Instagram, TikTok)
- Home base / city and approximate coordinates you choose
- Membership tier, verification status, notification and privacy settings
This data is shown to other users according to your settings and the feature you use (Art. 6(1)(b) GDPR).
Profile visits: if another user views your profile, we may record the visit. Push notifications about profile visits are off by default and only sent if you enable them.
12. Photos and verification
You may upload profile photos stored in Supabase Storage. Photos are visible to other users as part of your profile.
Photo verification compares a live selfie to your uploaded photos on your device using on-device machine learning. The verification selfie is not uploaded to our servers. A successful check sets a verified flag on your account via our API.
We may use on-device sensitive-content checks before upload. We do not currently run automated face recognition on our servers.
13. Discover map ("travelers nearby")
If you enable location for Discover, we process your GPS coordinates to maintain a presence record. Other users see your position only on an approximate grid (roughly 1 km resolution), not your exact coordinates. You can disable Discover location sharing in the app at any time.
Legal basis: Art. 6(1)(b) GDPR for providing the feature; where required, Art. 6(1)(a) GDPR for location permission on your device.
14. Trusted Circle and live location
Live location sharing is optional and consent-based. It is only active when you explicitly share with contacts you accept in Trusted Circle. You can pause sharing globally or revoke individual grants at any time.
We store your current location for active sharing (not a historical breadcrumb trail). Location data is automatically deleted after 7 days of inactivity. Invite links use single-use tokens; redeeming a link constitutes consent to the grant relationship.
Legal basis: Art. 6(1)(a) GDPR (explicit consent). Background location on iOS is used only for this feature when you grant "Always" permission.
15. Messaging, activities, and trips
We process messages you send in direct chats, city chats, and activity chats, including optional reactions. Activity and trip data (titles, descriptions, dates, locations, participation) are processed to operate those features (Art. 6(1)(b) GDPR).
Messages may be moderated (manual review and automated rules, e.g. hiding content reported by multiple users). Reports and blocks are processed to keep the community safe (Art. 6(1)(f) GDPR).
16. Push notifications
If you enable notifications, we store a push device token, device vendor identifier, app version, and locale to deliver alerts. Delivery uses Firebase Cloud Messaging (Google Ireland Ltd.) and Apple Push Notification service.
Notification categories include chat messages, activity updates, safety/Trusted Circle events, and optional social alerts. You can control categories in app settings.
Legal basis: Art. 6(1)(b) or (f) GDPR; for optional categories, Art. 6(1)(a) GDPR where applicable.
17. Subscriptions (mawatu Pro)
Paid features are sold via the Apple App Store / Google Play. RevenueCat, Inc. helps manage subscriptions and sends lifecycle events to our backend so we can unlock Pro features. We process subscription status linked to your user ID (Art. 6(1)(b) GDPR).
Payment card data is processed by Apple/Google, not by us.
18. AI travel guides (Pro)
Premium AI features generate trip itineraries and local food recommendations using OpenAI (OpenAI, L.L.C. / OpenAI Ireland Ltd., as applicable) on our servers. We send trip destination, dates, and your stated interests/travel styles — not your name, email, or photos — to generate content. Results are cached in our database to reduce repeat API calls.
AI output may be inaccurate or outdated. It is inspiration only, not professional travel advice. Legal basis: Art. 6(1)(b) GDPR (Pro feature you requested).
19. Crash and diagnostic data
We use Firebase Crashlytics (Google) to collect crash reports and non-fatal errors so we can fix bugs. Reports may include your Supabase user ID, device model, OS version, and stack traces. We have disabled Firebase Analytics and ads in our app configuration. We do not request App Tracking Transparency (IDFA).
Legal basis: Art. 6(1)(f) GDPR (ensuring stability and security).
20. Calendar (device only)
If you add an activity to your calendar, the app writes an event locally on your device via Apple Calendar. We do not receive or store your calendar contents on our servers.
21. Account deletion
You can delete your account in the app (Settings). Deletion removes your profile, photos, trips, device tokens, location data, blocks, and most associated records.
Chat messages you sent may remain visible to other participants labelled as "Deleted user", to preserve conversation context and support abuse investigations. This is explained before you confirm deletion.
Legal basis for retention of anonymised messages: Art. 6(1)(f) GDPR (abuse prevention and integrity of conversations for other users).
22. Automated decision-making
We do not make decisions with legal or similarly significant effects based solely on automated processing. Automated moderation may hide content pending review; you can contact us if you believe this was in error.
23. Recipients and processors
| Recipient | Purpose |
|---|---|
| Vercel Inc. | Website hosting |
| Supabase, Inc. | Database, auth, storage, functions |
| Resend, Inc. | Transactional / newsletter email |
| Google Ireland Ltd. | Firebase Cloud Messaging, Crashlytics |
| Apple Inc. | Sign in with Apple, App Store, APNs |
| Google LLC / Google Ireland Ltd. | Google sign-in, Play Store (when available) |
| RevenueCat, Inc. | Subscription management |
| OpenAI | AI guide generation (server-side) |
We disclose data to other users only as part of the features you use (profile, chat, activities, etc.).
24. Transfers outside the EU/EEA
Where processors are located outside the EU/EEA (in particular the USA), transfers rely on Standard Contractual Clauses (Art. 46 GDPR), adequacy decisions, and/or the EU-US Data Privacy Framework where certified. Details are available from the respective providers.
25. Storage periods
We retain data only as long as necessary for the purposes above or as required by law (e.g. tax/commercial retention). Waitlist, newsletter, and partner data are deleted when no longer needed. Live location rows expire after inactivity as described. You can delete your account at any time.
26. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), and to object (Art. 21) GDPR. You may withdraw consent at any time with future effect (Art. 7(3) GDPR).
To exercise your rights, email hello@mawatu.app. We respond within one month unless complexity requires an extension.
27. Supervisory authority
You may lodge a complaint with a data protection authority. For us, the lead authority is typically:
Berlin Commissioner for Data Protection and Freedom of Information Alt-Moabit 59–61, 10555 Berlin, Germany https://www.datenschutz-berlin.de
If you live in another EU/EEA country, you may also contact your local authority.
28. Security
We use TLS encryption, access controls, and industry-standard practices. No method of transmission is 100% secure; please use a strong password and keep your device safe.
29. Children
The Service is for users aged 18 and over only. We do not knowingly collect data from minors. Contact us if you believe a minor has registered.
30. Changes
This Privacy Policy is dated June 2026. We will update it when our processing or legal obligations change. Material changes will be communicated where appropriate (e.g. in-app notice or email).
The current version is always available at mawatu.app/privacy.
