Privacy Policy

1. Who we are

Gofy ("we", "us") is operated from Barcelona, Spain, and is the data controller for the personal data described here. You can reach us at [email protected] for anything in this policy, including privacy requests.

2. What we collect, and when

Account

Profile

Location

This is the part worth reading closely. Gofy uses location only while the app is open. There is no background location tracking, and the app does not ask for "Always" access.

What you post

Messages

Direct messages, group chats and communities are stored so they can be delivered and so you can read them again on a new device. They are not end-to-end encrypted. We do not read them routinely, but we can access them where we have to: to investigate a report of abuse, to keep the service running, or where the law requires it.

Purchases

Subscriptions and one-off purchases are processed by Apple or Google, not by us. We never see your card details. We receive from RevenueCat a record of what was bought, when it renews or expires, and the store it came from, so we can unlock what you paid for.

Device and notifications

If you allow notifications we store a push token for that device, along with its platform, language, app version and time zone, so a notification arrives in the right language at a sensible hour. Signing out removes the token for that device.

Analytics and diagnostics

We collect product analytics (which screens are used, which actions succeed or fail) and crash and performance diagnostics. Analytics events are linked to your account identifier, and your email and name are attached to your analytics profile. Event properties are categories and counts, not your coordinates and not the content of what you write. There is no session recording or screen replay in the app.

Advertising

On the free tier we show ads supplied by Google AdMob. Depending on the consent you give when asked, ads may use your device advertising identifier and approximate location to select what to show. See section 5.

3. Why we use it, and our legal basis

4. Who we share it with

We do not sell your personal data, and we do not share it with advertisers as a product. We use the following processors and services, each for the purpose listed:

We may also disclose data where we are legally required to, or where it is necessary to investigate fraud, abuse, or a threat to someone's safety.

5. Ads, tracking and your choices

Ads appear on the free tier only. Before ads load we ask for your consent, and on iOS the system also asks whether Gofy may track you across other companies' apps and websites. If you decline, you still see ads, but they are non-personalised. You can change your mind at any time:

A paid subscription removes ads. Ads shown inside the app are labelled as sponsored.

6. Where your data is

Our database and file storage are hosted in the European Union. Some of the services listed above are operated from outside the EU, in which case transfers are covered by the European Commission's standard contractual clauses or an equivalent safeguard.

7. How long we keep it

8. Your rights

Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to how we use it, or export it in a portable form. You can also withdraw a consent you previously gave. Write to [email protected] and we will answer within one month. If you think we have got it wrong, you can complain to the Spanish data protection authority (AEPD) or the authority where you live.

9. Deleting your account

You can delete your account from inside the app: open your profile, then Settings, then Danger zone. It is a real deletion, not a freeze. Your account, profile, messages, location records, verifications, notification tokens and uploaded images are removed.

Two things survive, and it is fair that you know which:

10. Children

Gofy is not for children under 13, and we do not knowingly collect their data. Where local law sets a higher age for consenting to services like this, that age applies. If you believe a child has created an account, tell us and we will remove it.

11. Security

Your login session is stored in your device's secure keychain or keystore. Traffic between the app and our servers is encrypted in transit. Access to data in our database is restricted per user by row-level security, so an account can only read what it is entitled to. No system is perfect, and we will tell affected users and the regulator if a breach requires it.

12. Cookies and local storage

The gofyapp.com website uses no tracking cookies. Its analytics are self-hosted and cookieless. Local browser storage is used only for essentials such as your language choice. The mobile app does not use cookies; it stores your session and a few preferences on the device.

13. Changes

If we change this policy in a way that matters, we will update the date at the top and tell you in the app. Continuing to use Gofy after a change means you accept the updated policy.

14. Contact

[email protected]