Privacy Policy
This policy describes how what-are-you-do-ing (“we”, “us”, “the Service”) collects and uses information when you use our group diary platform at whatareyoudo.ing and related applications.
1. Who we are
- Application
- Whatcha (
ing.whatareyoudo.app) — Google Play, Apple App Store, Microsoft Store - Website
- whatareyoudo.ing
- Provider / developer
- LoveKapibarasan
- Address
- TechBase Regensburg, Franz-Mayer-Straße 1, 93053 Regensburg-Galgenberg, Germany
- Contact
- hey@whatareyoudo.ing
The Service is operated as an independent project under the domain whatareyoudo.ing. For privacy-related requests, contact: hey@whatareyoudo.ing.
The Whatcha app (ing.whatareyoudo.app) and this website are provided by LoveKapibarasan, TechBase Regensburg, Franz-Mayer-Straße 1, 93053 Regensburg-Galgenberg, Germany.
2. Information we collect
2.1 Account information
When you register, we collect:
- Email address and password (authentication via Supabase Auth)
- Username (3–30 characters; immutable after registration)
- Display name and optional avatar image
2.2 Diary and group content
When you use the Service, we store:
- Group names, membership, and invite links (single-use, expiring links)
- Diary names and access-control settings (ACL)
- Diary entries: text, mood, location, entry dates
- Version history (“commits”): messages, content snapshots, parent commit references, merge metadata
- File attachments (images and other files) linked to commits
2.3 Billing information
Paid subscriptions are processed by Stripe. We store Stripe customer and subscription identifiers on your profile. We do not store full payment card numbers; Stripe handles card data according to its own privacy policy.
2.4 Technical data
We may automatically collect:
- IP address, browser or app type, and request timestamps (server logs)
- Authentication tokens (JWT) used to secure API requests
- Anonymous usage statistics via Google Analytics (screens opened, features used) — only with your consent, never your diary content
3. How we use information
We use your information to:
- Provide, maintain, and improve the group diary Service
- Authenticate you and enforce access control on diaries and entries
- Enable search within diaries (PostgreSQL full-text search on entry text)
- Process subscriptions and manage Free vs Pro plan limits
- Send transactional emails (e.g. sign-up confirmation, password reset) via our auth provider
- Prevent abuse, fraud, and unauthorized access
4. Legal bases (EEA/UK users)
Where applicable, we rely on:
- Contract — to provide the Service you signed up for
- Legitimate interests — security, abuse prevention, and product improvement
- Consent — where required (e.g. optional marketing, if offered in the future)
- Legal obligation — when we must retain or disclose data by law
5. How we share information
We do not sell your personal data. We share data only with:
- Other members of your groups — according to diary ACL settings (read/create/update/delete permissions)
-
Service providers who help us operate the Service:
- Supabase (authentication, PostgreSQL database)
- Object storage (e.g. Supabase Storage / AWS S3 bucket
whatareyoudoing-uploads) for attachments - Stripe (payments and subscriptions)
- Google (Google Analytics, usage statistics) — only after you consent. Analytics is off by default in the app and cookies are set to denied on the website until you accept.
- Authorities — if required by valid legal process
6. Data retention
- Free plan: version history is retained for 30 days, then older commits may be removed per plan limits.
- Pro plan: unlimited version history while subscribed.
- Account and content remain until you delete them or close your account, subject to backups and legal holds.
7. Storage and security
Data is stored in PostgreSQL (via Supabase) and file attachments in encrypted object storage. API access requires a valid Supabase JWT. Permissions are checked on every request. No method of transmission over the Internet is 100% secure; we use industry-standard practices but cannot guarantee absolute security.
8. Your rights
Depending on your location, you may have the right to:
- Access, correct, or delete your personal data
- Export your data (portability)
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority
To exercise these rights, email hey@whatareyoudo.ing. We will respond within a reasonable time.
9. Children
The Service is not directed at children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect data from children. Contact us if you believe a child has provided data.
10. International transfers
Our providers may process data in countries other than yours. Where required, we rely on appropriate safeguards (e.g. standard contractual clauses) offered by those providers.
11. Changes to this policy
We may update this Privacy Policy. The “Last updated” date at the top will change. Material changes may be communicated in the app or by email where appropriate. Continued use after changes constitutes acceptance of the updated policy.
12. Contact
Questions about this policy: hey@whatareyoudo.ing