Privacy Policy
Last updated: 1 September 2026
Gofy is a hyperlocal discovery app. To do its job it needs to know where you are, and it lets you publish things other people can see. This page explains exactly what that means, in the order it actually happens.
The short version. We collect your email, your profile, what you post, and your location while you are using a feature that needs it. We use your precise location to check you are really at a place you are verifying or reporting, and to show you to friends on the map if you turn that on. We do not sell your data. We show ads on the free tier, and we use analytics and crash reporting to keep the app working. You can delete your account, and everything personal in it, from inside the app.
1. Who we are
Gofy ("we", "us") is operated from Barcelona, Spain, and is the data controller for the personal data described here. You can reach us at [email protected] for anything in this policy, including privacy requests.
2. What we collect, and when
Account
- Your email address, and a password if you did not use Apple or Google sign-in.
- If you sign in with Apple or Google, the identifier and email address that provider returns to us. We never receive your password from them.
- Whether the account is an Explorer or a Business account, and the date you accepted these documents.
Profile
- Display name, @handle, and avatar image, if you set them.
- Optionally, a full name, date of birth and phone number if you fill in the profile-details step. The phone number is stored as you typed it and is not verified by SMS.
- For Business accounts: the venue name, address, category, contact email and phone, opening hours, logo and any social links you add. This is published on your venue page and is meant to be public.
Location
This is the part worth reading closely. Gofy uses location only while the app is open. There is no background location tracking, and the app does not ask for "Always" access.
- Verifying a gem. While a verify session is open, the app sends your coordinates, the reported accuracy, and whether your operating system says the position is mocked. This is how we establish you were actually at the place, which is what makes a verification worth anything. We keep the session record, including the worst accuracy and whether a mocked position was seen.
- Map reports. When you post or vote on a safety report, we send your device position alongside it, so we can check you are close enough to the thing you are describing. Your position is used for that check; the report itself is stored at the coordinates of the report.
- Friends on the map. Off by default. If you turn location sharing on, the app sends your position roughly every 30 seconds while the map is open. It is shown only to people you have accepted as friends who are also sharing, and only while it is less than three minutes old. Turn the toggle off and it stops, and your position is no longer shown to anyone.
- Sharing a location in chat. Only when you tap to send one. It is stored with that message.
- Your city. We resolve a position into a city name for leaderboards and local content, and store the city, not the coordinates.
- Nearby digest. Optional. If you enable it, we store a position rounded to a grid of roughly one kilometre, so we can tell you when something appears near you.
- On your device only. The app remembers your last map position locally so the map opens where you left it. That does not leave your phone.
What you post
- Gems you create: title, description, place, coordinates, category, times, links and any photo you add.
- Safety reports you create, including the free text and any contact details you choose to put in a lost-pet report. Anything you type into a report is visible to other users near it — please do not put anything there you would not hand to a stranger.
- Verifications, votes, saves, unlocks, event registrations, and reports you file about other people's content.
- Images you upload: avatars, gem pin images, business logos and community images. We re-encode uploaded images, which removes embedded GPS and other EXIF metadata.
Messages
Direct messages, group chats and communities are stored so they can be delivered and so you can read them again on a new device. They are not end-to-end encrypted. We do not read them routinely, but we can access them where we have to: to investigate a report of abuse, to keep the service running, or where the law requires it.
Purchases
Subscriptions and one-off purchases are processed by Apple or Google, not by us. We never see your card details. We receive from RevenueCat a record of what was bought, when it renews or expires, and the store it came from, so we can unlock what you paid for.
Device and notifications
If you allow notifications we store a push token for that device, along with its platform, language, app version and time zone, so a notification arrives in the right language at a sensible hour. Signing out removes the token for that device.
Analytics and diagnostics
We collect product analytics (which screens are used, which actions succeed or fail) and crash and performance diagnostics. Analytics events are linked to your account identifier, and your email and name are attached to your analytics profile. Event properties are categories and counts, not your coordinates and not the content of what you write. There is no session recording or screen replay in the app.
Advertising
On the free tier we show ads supplied by Google AdMob. Depending on the consent you give when asked, ads may use your device advertising identifier and approximate location to select what to show. See section 5.
3. Why we use it, and our legal basis
- To provide the service — your account, your content, messages, maps, payouts. Legal basis: performance of a contract.
- To keep it honest and safe — proximity checks, spoofing and fraud detection, rate limits, moderation of reported content, enforcement of our Terms. Legal basis: legitimate interests in preventing fraud and abuse, and protecting other users.
- To pay creators — calculating and settling earnings, and keeping the records that go with a payment. Legal basis: contract, and legal obligation for accounting records.
- To improve the app — analytics and crash diagnostics. Legal basis: legitimate interests, or consent where local law requires it.
- To show ads — legal basis: consent, which you give or refuse in the prompt shown when ads are first loaded, and can change later in your device settings.
- To send notifications — legal basis: your consent, given through the operating system permission, and revocable there or per-type in the app.
4. Who we share it with
We do not sell your personal data, and we do not share it with advertisers as a product. We use the following processors and services, each for the purpose listed:
- Supabase — database, authentication and file storage. Hosted in the EU.
- Railway — application hosting.
- Mapbox and Stadia Maps — map tiles and route directions. They receive the map area you are looking at, and for directions the start and end points.
- PostHog — product analytics, including your account identifier, email and name.
- Google Firebase (Crashlytics and Performance Monitoring) — crash reports and performance traces, tied to your account identifier.
- Google AdMob — advertising, subject to your consent choice.
- RevenueCat — subscription and purchase state, keyed to your account identifier.
- Apple Push Notification service and Google Firebase Cloud Messaging — delivering notifications to your device.
- DeepL — translating content into the language you read the app in. Text you post publicly, such as a gem description, is sent for translation. Private messages are not.
- Umami — self-hosted, cookieless analytics on the gofyapp.com website.
We may also disclose data where we are legally required to, or where it is necessary to investigate fraud, abuse, or a threat to someone's safety.
5. Ads, tracking and your choices
Ads appear on the free tier only. Before ads load we ask for your consent, and on iOS the system also asks whether Gofy may track you across other companies' apps and websites. If you decline, you still see ads, but they are non-personalised. You can change your mind at any time:
- iOS: Settings, then Privacy & Security, then Tracking.
- Android: Settings, then Google, then Ads, where you can also reset or delete your advertising ID.
A paid subscription removes ads. Ads shown inside the app are labelled as sponsored.
6. Where your data is
Our database and file storage are hosted in the European Union. Some of the services listed above are operated from outside the EU, in which case transfers are covered by the European Commission's standard contractual clauses or an equivalent safeguard.
7. How long we keep it
- Your account and profile — until you delete your account.
- Precise location from verify sessions and reports — kept while it is doing its job: proving a verification and defending it against a later dispute. Presence sessions expire and are not kept as a location history, and we never build a movement trail from them.
- Friends-on-map position — the latest position only. It is overwritten each time and treated as stale after three minutes. There is no history.
- Safety reports — they expire on their own, within hours for most categories, and disappear from the map when they do.
- Messages — until you or the other participants delete them, or you delete your account.
- Payment and earnings records — kept for as long as Spanish accounting and tax law requires, even after an account is deleted. These are financial records, not profile data.
- Analytics and crash data — retained on a rolling basis by those services and not kept indefinitely by us.
8. Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or export it in a portable form. You can also withdraw a consent you previously gave. Write to [email protected] and we will answer within one month. If you think we have got it wrong, you can complain to the Spanish data protection authority (AEPD) or the authority where you live.
9. Deleting your account
You can delete your account from inside the app: open your profile, then Settings, then Danger zone. It is a real deletion, not a freeze. Your account, profile, messages, location records, verifications, notification tokens and uploaded images are removed.
Two things survive, and it is fair that you know which:
- Financial records of payments already made to or from you, because the law requires us to keep them.
- Content you contributed that other people depend on may remain without you attached to it — a gem others have saved, for example, stays on the map but is no longer credited to your profile. If you want a specific gem taken down as well, remove it before deleting your account, or ask us.
10. Children
Gofy is not for children under 13, and we do not knowingly collect their data. Where local law sets a higher age for consenting to services like this, that age applies. If you believe a child has created an account, tell us and we will remove it.
11. Security
Your login session is stored in your device's secure keychain or keystore. Traffic between the app and our servers is encrypted in transit. Access to data in our database is restricted per user by row-level security, so an account can only read what it is entitled to. No system is perfect, and we will tell affected users and the regulator if a breach requires it.
12. Cookies and local storage
The gofyapp.com website uses no tracking cookies. Its analytics are self-hosted and cookieless. Local browser storage is used only for essentials such as your language choice. The mobile app does not use cookies; it stores your session and a few preferences on the device.
13. Changes
If we change this policy in a way that matters, we will update the date at the top and tell you in the app. Continuing to use Gofy after a change means you accept the updated policy.