Privacy

The short version: your data stays in the EU, nobody can find you unless you choose to be found, photos of you come down the moment you ask, and you can erase your data — not just hide it.

What we collect

Your name, email, and password (for your account); the profile you choose to write (values, interests, stories — never demographic categories); the gatherings you take part in; and the photos, quotes, and reflections you add to a gathering's memory book.

Discovery is your choice

You are not discoverable to anyone until you turn discovery on. If you do, only people you have cooked with, and people one shared gathering away, can see your profile card — never further, and never through public search. You can turn it off again anytime in Settings.

Photos of you

Whoever uploads a photo must confirm they have permission or a reasonable basis to share it. If you appear in a photo — whether or not you use this product — you can have it removed immediately, no questions asked: any participant can act for you, or use the photo's removal link. The uploader is told after it is gone. We never run facial recognition or any biometric processing.

Leaving and erasure

Leaving hides your profile and stops new invitations while past gatherings stay intact. Erasure goes further: your account and profile are deleted or anonymized, your contributions are deleted, and your name in past gathering records becomes an anonymous placeholder — the gathering itself remains for the people who were there.

Where your data lives

All data is stored with managed providers in the EU region. Analytics is limited to a fixed set of product events recorded server-side; there is no advertising tracking, no session recording, and no engagement profiling.

Audit records

Security and audit logs (who did what, when) are kept for a defined period with restricted access, then removed.

This notice describes the product as built and is under legal review; it will be finalized with counsel before the product opens to real users.