This Privacy Policy explains how Gyde (the "App"), produced by the developer of Gyde (the "developer", "we", "us"), collects, uses, and protects information when you use the App. Gyde proposes hangouts with people you already know, and gives every plan its own group chat with an AI copilot. Suggestions for where to go are found by web search at the time you ask, from the venue's or organizer's own public web page.
1. Information we collect
1.1 Information you provide
- Account information. If you sign in with Apple, Apple shares an opaque user identifier with us. If you choose to share your name and email with the App, we receive and store those values to identify your account and send service-related messages.
- Password account (if used). If you create an account with an email address and password, we store your email and a salted hash of your password. We never store your password in plain text.
- Phone number and SMS information. If you add a mobile phone number, we collect and store the number and its verification status so we can verify your account. If you explicitly choose text messages for Gyde-member introduction alerts, we also record that choice and when you made it. You can change the choice in your profile. Gyde does not use this consent to text people who are not members.
- Nonmember invitations. When you choose a person who is not yet on Gyde, we collect that selected person's name and phone number or email address, the invitation type, and any short note you include. We create an invitation link and prefill a message, but you review and send the first message from your device's Messages, Mail, or sharing app. We store invitation status and timestamps to operate the link, prevent duplicates, and limit abuse.
- Organization rosters. An organization may provide a roster containing member names and a phone number or email address. We store those entries for membership matching and make unclaimed entries available only to signed-in members of that organization as invitation choices. Gyde does not send an invitation merely because a person appears on a roster.
- Private profile and connection context. We collect your date of birth during setup and use it to calculate your age. Gender is optional context for future hangout recommendations; you can leave it unanswered or clear it in your profile. You may also choose to provide your relationship status, family stage (for example, whether you have children or caregiving responsibilities), the kinds of personal connections you want, and a short note about what would make an introduction useful. These details are stored with your account and are not displayed on your public profile.
- Optional social-graph intake. If you choose to talk or type with Gyde about your social life, we store the conversation transcript and the facts saved from it, such as names you mention, how you know someone, how close you are, what you do together, when you last met, notes, and social preferences. These details are kept with your account, are not shown to other users, and help Gyde make future conversations and plans more useful. In voice mode, the App asks for microphone access and sends live audio directly from your device to OpenAI Realtime so OpenAI can transcribe and respond to the conversation. Gyde's backend does not receive or store the raw audio.
- Social and planning content. We store crew names, member display names, messages, shared-place notes, saves, reactions, votes, and related timestamps so your group can plan together.
- Safety information. When you report content or block an account, we store the report reason, optional details, the involved account identifiers, a snapshot of the reported content, moderation decisions, and an audit record of moderator actions.
1.2 Information collected automatically
- Precise location (while in use). When you use features that require location, the App requests "While Using the App" location access. Your device's location is sent to our backend so it can suggest your home city and rank places and events near you. Coordinates may also be stored with search or planning history so a conversation or plan works as expected. This history is deleted when you delete your account.
- Device session metadata. When you sign in or refresh your session, the App sends a short device label (for example, "iOS device") and platform name to associate with your session so you can see and revoke sessions in the future.
- Authentication tokens. Access and refresh tokens are stored on your device in the iOS Keychain (via Expo SecureStore) and sent in API requests so you stay signed in.
- Optional contact matching. When you select a contact to save to your social graph, the App sends their name, normalized phone number, and normalized email address when available. Gyde stores the selected phone number and email privately with your saved person and derives their SHA-256 hashes for matching against verified Gyde accounts. The separate contact-sync feature continues to upload only device-generated phone and email hashes. We do not upload your full raw address book. Names you speak or type during intake, and the contact names shown as possible matches during that conversation, may be processed as part of the OpenAI Realtime conversation and may appear in the transcript Gyde stores. Gyde creates a saved social-graph record when you confirm a person. If you choose to invite a nonmember, the selected name and phone number or email address are also sent to Gyde when you prepare that invitation, as described in Section 1.1. Saving a contact does not itself send an invitation.
- Server logs. Like most internet services, our backend may log basic request information (timestamps, request paths, response codes, error messages, and IP address as seen by the server) for reliability and abuse prevention. We do not use these logs for advertising.
- Product analytics. In the App we use PostHog to measure screen views, searches, chat-message counts, link and place clicks, active time, and how far people get through setup, along with a visitor ID and session ID. PostHog session replay is enabled with text masking. If you sign in, this data can be associated with your account so we can keep the product reliable and understand feature use. We do not use advertising cookies and we do not track you across apps or websites owned by others. This website itself runs no analytics, no cookies, and no third-party scripts.
1.3 Information we do not collect
- We do not receive or store raw audio recordings. If you choose voice intake, live microphone audio is processed directly by OpenAI Realtime as described in Sections 1.1 and 4.
- We do not use advertising SDKs, ad networks, or cross-app tracking SDKs. The only analytics SDK in the App is PostHog, described above and in Section 4.
- We do not upload your full raw address book. We store the names and normalized phone numbers and email addresses of contacts you explicitly choose to save, contact-matching hashes, and the name and contact method of a nonmember when you choose to prepare an invitation. Saved phone numbers and emails are private to your account and are not added to public profiles. We do not collect contact photos, calendar entries, health data, or HomeKit data.
2. How we use information
- To provide the core App experience: proposing hangouts with people you know, suggesting where to go, and remembering your account.
- To conduct the optional social-graph intake, retain its transcript and saved facts, and use those facts to make future conversations and plans more useful.
- To save the contacts you select and match their phone and email hashes with verified Gyde accounts. These hashes may be derived on your device or by Gyde from a selected contact's stored phone number and email.
- To make personal introductions more relevant. Shared connection goals may improve a potential match's score and appear as a reason for the introduction. Date of birth, calculated age, gender, relationship status, and family stage are not used to automatically exclude people or score a match.
- To provide crew messages, shared saves, collaborative voting, reporting, blocking, and content moderation.
- To send one-time phone verification codes and, only when a Gyde member explicitly chooses text messages in their profile, Gyde-member introduction alerts by SMS; to honor opt-out requests; and to prevent duplicate or abusive sending.
- To prepare nonmember friend, group, or hangout invitation copy and a link for the inviting member to review and send from their own device.
- To operate, secure, and improve the service (debugging, abuse prevention, capacity planning).
- To communicate with you about your account, including responding to support requests and confirming account deletion.
- To comply with legal obligations and respond to lawful requests.
3. Legal bases (EEA, UK, and similar regimes)
If the GDPR or UK GDPR applies to you, we process your personal data on the following legal bases:
- Performance of a contract - to provide the App's core features when you ask for them (for example, returning nearby points of interest after you grant location access).
- Legitimate interests - to keep the service secure, prevent abuse, debug errors, and maintain account integrity, balanced against your rights.
- Consent - for optional permissions you explicitly grant, such as precise location, contacts, or microphone access. You can withdraw a device permission at any time in your device settings.
- Legal obligation - to comply with applicable laws.
4. Sharing and third parties
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. The list below is every external service Gyde relies on. If a company is not named here, we do not send your information to it.
- Apple. If you sign in with Apple, Apple processes your authentication and may share your name and email with us according to the choices you make in the Sign in with Apple dialog. Apple Maps renders the maps shown in the App.
- Google. If you sign in with Google, Google processes your authentication and shares your Google account identifier, and the name and email on that account, with us. We use Google for sign-in only.
- Hosting provider. Our backend and its database run on a third-party server hosting provider. Server operators may have technical access to data at rest as needed to operate the infrastructure.
- Resend. Sign-in links, support replies, and the reports you send us are delivered by email through Resend, which receives your email address and the contents of the message.
- Expo. Push notifications you opt into are delivered through Expo's push service to Apple and Google. Expo receives your device's push token and the notification text.
- SURGE. We use SURGE to deliver one-time phone verification codes and introduction alerts to existing Gyde members who explicitly choose SMS. SURGE receives the destination phone number and message content. SURGE also processes SMS commands such as STOP, START, and HELP. Nonmember invitations are sent by the inviting member through their own device, not through SURGE. We do not use SURGE to send marketing or promotional messages.
- Cerebras. When Cerebras is the configured copilot provider, we send the message you asked it, the surrounding chat context needed to answer, your city, and any place details it is reasoning over. We do not send your email address, your contacts, or your precise coordinates.
- OpenAI. We send short interest-tag text to OpenAI's embeddings endpoint so people with similar interests can be matched. When OpenAI is the configured copilot provider, we also send the same categories of copilot context described for Cerebras above. If you choose social-graph intake, the App connects directly to OpenAI Realtime using a short-lived credential. OpenAI processes your typed messages or, in voice mode, your live microphone audio, along with the conversation instructions and context needed to transcribe and respond. Possible contact names returned by the App's on-device search may also be included in that conversation so you can confirm the right person. Gyde does not send raw address-book phone numbers, email addresses, or precise coordinates to OpenAI for matching, and Gyde does not receive or store the raw intake audio.
- Tavily. To find real places and events, we send Tavily a search query built from what you asked for and the city it applies to, and we ask it to read the public page it finds. The query does not carry your identity, your contacts, or your precise coordinates.
- Geoapify. Place names and address text are sent to Geoapify to resolve them to an address and coordinates. When you have allowed location access, an approximate coordinate may be sent with the query so nearby results rank first.
- PostHog. We use PostHog to understand how people use the App, diagnose errors, and review masked session replays. For signed-in users, we may share your account ID, name, and email address with PostHog so analytics and session replays can be associated with your account. We do not use PostHog for cross-context behavioral advertising.
- Langfuse. We use Langfuse to trace and review the copilot's prompts and responses so we can debug and improve answer quality. It receives the same copilot content described under Cerebras above, associated with an account identifier.
- Law enforcement and legal process. We may disclose information if we believe in good faith that disclosure is required by law or is necessary to protect rights, safety, or property.
Place and event details shown in the App are read from the venue's, organizer's, or group's own public web page at the time of the suggestion, and each card links back to that page. We do not send your personal information to those sites. Gyde no longer ingests data from Overture Maps, Google Places, Wikidata, OpenStreetMap, Wikimedia Commons, Ticketmaster, or Eventbrite; see our attributions page.
5. Data retention
- Account records and authentication identifiers are kept while your account is active.
- Your private profile and connection context is kept with your account while it is active. You can change your required date of birth or remove optional answers, including gender, from your profile, and it is deleted when you delete your account.
- Your phone number, verification status, selected introduction-delivery method, and any SMS-consent timestamp are kept with your account while it is active. Nonmember invitation records, including the selected recipient's name and phone number or email address, are retained as needed to operate invitation links and prevent duplicate or abusive use.
- Refresh tokens expire and are rotated periodically.
- Social-graph intake transcripts, saved people (including selected phone numbers and emails), memories, and contact hashes are retained with your account so Gyde can remember what you shared. In the App, you can delete your intake conversation history or remove an individual saved person or memory. Removing a saved person deletes the phone number and email on that contact record; separate invitation records follow the retention described above. These controls are separate so clearing a conversation does not silently remove the people or memories you chose to keep. Deleting your account removes the intake sessions and transcripts, saved people and their phone numbers and emails, memories, and matching hashes owned by your account.
- Contact-import metadata and matched contact hashes are retained with your account to provide friend suggestions and are covered by account deletion and applicable privacy requests.
- Blocks remain until you unblock the account or delete your account.
- Moderation reports, content snapshots, and action logs are retained for up to 12 months to investigate abuse, handle appeals, and prevent repeated harm, unless law requires longer retention.
- Operational logs are retained for a limited period for debugging and abuse prevention, then deleted or aggregated.
- Account-linked search history and first-party analytics are retained while needed to operate and improve the service, then deleted or aggregated. Account data held by Gyde is removed when account deletion succeeds, subject to the limited safety, operational-log, and legal records described in this section.
- When in-App deletion succeeds, Gyde removes your account and the account-linked data covered above. If a deletion attempt fails, your account stays in place so you can retry.
6. Your rights
Depending on where you live, you may have rights to access, correct, delete, export, or restrict our processing of your personal data, and to object to certain processing. You may also have the right to lodge a complaint with your local data protection authority.
To exercise any of these rights, email drewb97@gmail.com. We may need to verify your identity before acting on a request. To delete your account specifically, see our Account Deletion page.
7. Children
Gyde is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal data to us, contact drewb97@gmail.com and we will take appropriate steps to remove it.
8. Security
We use industry-standard practices to protect your information, including HTTPS in transit, salted password hashing, signed access tokens, rotating refresh tokens, and encryption of stored third-party revocation credentials. No system is perfectly secure; we do not represent that the App is immune from every attack. We do not claim any specific security certification (such as SOC 2 or ISO 27001).
9. International data transfers
Gyde is operated from the United States. If you use the App from outside the United States, your information will be transferred to and processed in the United States or other jurisdictions where our service providers operate. These jurisdictions may have data protection laws different from those in your country.
10. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Effective date" above. Material changes will also be announced in the App or by email where reasonable.
11. Contact
Questions about privacy or this policy? Email drewb97@gmail.com.
Appendix A - Apple App Privacy disclosures
This appendix maps the practices above to Apple's App Privacy questionnaire categories.
Data linked to you
- Contact info: your email address, optional name, and mobile phone number when provided, used for account management, phone verification, member-selected introduction alerts, app functionality, and support.
- Other user content: required date of birth, calculated age, optional gender, relationship and family context, connection goals, and an optional introduction note, associated with your account and used for app functionality and relevant personal introductions. These details are not displayed on your public profile.
- Contacts: names, normalized phone numbers, and email addresses of contacts you explicitly choose to save, phone and email hashes used for matching, and the name and phone number or email address of a nonmember you explicitly select for an invitation. These records are associated with your account; your full raw address book is not uploaded.
- Precise location: coordinates used to return nearby places and events and to support location-aware search and planning.
- Identifiers: your Gyde account ID, opaque sign-in provider identifier, first-party visitor ID, and session IDs, used for authentication, app functionality, fraud prevention, and first-party analytics.
- User content: social-graph intake transcripts and saved facts, crew names, member names, messages, shared-place notes, saves, reactions, votes, report details, and support communications, used for app functionality, safety, and support.
- Search history: searches, chat messages, and related planning context, used for app functionality and product improvement.
- Usage data: product interactions such as screen views, link and place clicks, feature activity, and session timing, used for app functionality and analytics.
- Diagnostics and safety: request and error logs, reports, blocks, moderation outcomes, and related identifiers, used for reliability, security, abuse prevention, and support.
Audio processing
If you choose voice intake, live audio is sent directly from your device to OpenAI Realtime for transcription and response. Gyde does not receive or store the raw audio recording; Gyde stores the conversation transcript and the social-graph facts described above.
Data not collected
- Health and fitness data, sensitive financial information, browsing history outside Gyde, advertising data, or third-party tracking identifiers.
Tracking
Gyde does not "track" you across apps and websites owned by other companies, as that term is defined by Apple's App Tracking Transparency framework. Gyde does not present the App Tracking Transparency prompt because it does not track.