Privacy Policy

Last updated: 29 July 2026

This Privacy Policy explains how DPA Tech Solutions SRL ("we", "us", "our") collects, uses and protects your personal data when you use the WhereU mobile and web application, the website at whereu.fun and the native apps for Android and iOS (together, the "Service"). We act as the data controller for your personal data under the EU General Data Protection Regulation (GDPR) and Romanian Law no. 190/2018.

This page is maintained by DPA Tech Solutions SRL. It describes what the Service does today and is not an independent audit or certification.

1. Who we are

DPA Tech Solutions SRL, a company registered in Romania. For any privacy request contact us at privacy@whereu.fun.

2. Data we collect

  • Account data — email address, chosen username, display name, avatar, language, invite/whitelist status.
  • Profile data — bio, interests, optional links, saved places and places you approve or edit.
  • Location data — live GPS coordinates and speed when you enable sharing or "Live" mode, a location history used to detect stops (dwells of 15 minutes or more) and to draw your day map, and the daily activity score computed from it. Sharing can be paused with Ghost Mode / Ghost Mode+ or set to expire automatically.
  • Social graph & interactions — friends, squads, RSVPs, group and direct messages, message reactions, read receipts and typing indicators, pings, vibe checks, Stranger Dinner preferences and matches, Pulse (shake) events, blocks and reports you submit.
  • Payment data — handled by Stripe for WhereU PRO, event tickets and host plans. We store subscription status, tier and the last four card digits Stripe returns; we never receive or store full card details.
  • Device & notification data — device type, OS, browser, IP address (temporarily, for security and rate limiting), crash and error logs, and, if you opt in, push notification tokens (APNs / FCM / Web Push).
  • Agent access — records of AI agents you have authorized via the MCP endpoint (whereu.fun/mcp), the scopes granted and their activity.

3. Why we use your data (legal bases)

  • Performance of a contract — to provide your account, the social features, WhereU PRO, ticket purchases and host tooling.
  • Consent — for sharing your live location, push notifications, Pulse, analytics and marketing emails. You can withdraw consent at any time from the in-app Settings.
  • Legitimate interests — to keep the Service safe and reliable, prevent abuse and fraud, throttle abusive requests, moderate reports, and improve features. We balance these interests against your rights.
  • Legal obligation — accounting, tax, responding to lawful requests and consumer-protection rules.

4. How location data is protected

Live location is sampled from your device by a background tracker whose cadence is configurable in Settings (presets: Battery Saver, Balanced, High Accuracy). The defaults skip writes that are close in time and space to the previous one and back off further when you are stationary, so we store the minimum needed for map features to work. Live positions older than 15 minutes are hidden from the map by default. Access to your location on the server is restricted by row-level security policies: only you and the friends you have explicitly allowed can read it.

5. Sharing your data

We share data only with processors needed to run the Service:

  • Supabase — database, authentication and file storage.
  • Stripe — payments, subscriptions and billing portal.
  • Mapbox and OpenStreetMap-based routing (OSRM) — map tiles, geocoding and pedestrian routes to friends.
  • Cloudflare — TLS, DDoS protection and static asset delivery for whereu.fun and its subdomains.
  • Apple Push Notification service and Firebase Cloud Messaging — push notification delivery when you opt in.
  • Transactional email — ticket confirmations, invites and account emails from notify.whereu.fun.

We never sell your personal data. Some of these providers may transfer data outside the EEA; in those cases we rely on Standard Contractual Clauses approved by the European Commission and any additional safeguards required by the provider.

6. Sharing with other users

The Service is inherently social. Your username, avatar, bio, saved places you make public, upcoming events you host, live status (online/offline) and, when you opt in, your live location are visible to friends or to the people you explicitly share with. Group chats and DMs are visible to participants. Public place, event and profile links can be indexed by search engines and shown in social previews. You control most of this from the in-app Settings, Notifications, Ghost Mode and Privacy screens.

7. Agent (MCP) integrations

You can grant AI assistants access to a limited set of actions on your account viawhereu.fun/mcp. Each agent connects through a consent screen listing the scopes it requests, and can be revoked from Settings. Agents act with your credentials and are subject to the same RLS policies as you.

8. How long we keep your data

  • Account data — until you delete your account.
  • Live location pings — automatically hidden after 15 minutes; raw history is kept for the past 30 days on the free tier and up to 12 months for WhereU PRO users, then deleted.
  • Group and direct messages — until you or the sender delete them, or the thread is deleted.
  • Blocks and reports — kept while your account is active for safety enforcement.
  • Invoices and payment records — 10 years (Romanian fiscal law).
  • Security and rate-limit logs — up to 90 days.

9. Your rights

Under GDPR you have the right to access, rectify, erase, restrict or port your data, to object to processing and to withdraw consent at any time. You can:

You may also lodge a complaint with the Romanian Data Protection Authority (ANSPDCP, dataprotection.ro) or your local EU supervisory authority.

10. Security

We use HTTPS/TLS in transit and encryption at rest, row-level security on our database, least-privilege access controls, rate limiting on sensitive endpoints (including password resets), signed webhooks, JWT validation on API calls and periodic security scans. No system is 100% secure, but we work hard to keep yours safe. Report suspected vulnerabilities to security@whereu.fun.

11. Children

WhereU is not intended for users under 16. If you believe a minor has registered, contact us and we will remove the account.

12. Changes

We will notify you of material changes to this Policy in the app or by email at least 15 days before they take effect (unless a change is required by law to apply sooner). Continued use of the Service after changes take effect means you accept the updated Policy.