Privacy Policy
What we collect
When you sign up, we collect your email address and a display name. You may optionally provide a profile photo, cover image, bio, and location. When you use the app we store the events you create or RSVP to, the messages you send, the people you follow, and the notifications you receive. Device push tokens are stored so we can deliver reminders and alerts you've opted into. We also record basic product analytics (which screens and features are used) tied to your account — never your IP address, device fingerprint, or browsing outside the app.
How we use your data
We use your data to provide the service: showing you relevant events, delivering messages, sending reminders, and powering the recommendation algorithm. We do not sell your data to third parties, and there are no advertising trackers in the app.
Who processes it for us
- Supabase (EU-hosted) — database, storage, and authentication
- Stripe — payment processing for paid events (we never see your card number)
- Expo — push notification delivery
- Sentry — crash reporting (personal fields are scrubbed before sending)
- DeepL / Google Translate — only when you use the Translate feature
- Resend — transactional email (invites, receipts, verification)
Location data
Location is only collected when you grant the permission and only used to rank nearby events. You can revoke the permission at any time in your device settings; the app keeps working without it.
How long we keep things
- Event chats are automatically deleted when an event is archived (shortly after it ends). Event boards and photos remain as the event's record.
- Product analytics are deleted after 13 months.
- Financial records (invoices, receipts) are kept for as long as tax law requires.
- Everything else lives until you delete it — or delete your account.
Deleting your account
Deleting your account (Settings → Delete account) erases your identity: your profile, follows, RSVPs, saves, and memberships are removed. Content other people depend on — events you organized, messages in shared conversations — is kept but permanently anonymized to "Deleted user". Financial records are retained where the law requires it, with your name removed from public view. Residual copies may persist in encrypted backups for up to 30 days before being purged.
Your rights (GDPR)
If you are in the EU/EEA you have the right to access, correct, export, and delete your data. Export is available in-app under Settings → Data export; deletion under Settings → Delete account. Our lawful basis for processing is your consent (given at sign-up) and our legitimate interest in operating the app. You also have the right to lodge a complaint with your local supervisory authority. For any other request, email hello@chamaeleon.app.
Your rights (California / CCPA)
We do not sell your personal information. If you are a California resident, you have the right to know what we collect, to request deletion, and to opt out of any sale of personal data. To exercise these rights, email hello@chamaeleon.app — we won't discriminate against you for it.
Security
We take reasonable measures to protect your data, including encrypted connections (TLS) and access controls. No method of transmission or storage is completely secure, though. During the beta, data may occasionally be reset or migrated for technical reasons, and please don't store sensitive personal information in the app.
Children
Chamaeleon is intended for users aged 16 and older. We do not knowingly collect data from anyone under 16. If you believe a child under 16 has given us data, email hello@chamaeleon.app and we'll remove it.
Changes to this policy
We may update this policy as the app evolves. We'll flag significant changes with an in-app notice or by updating the date above; continued use after a change means you accept the revised policy.
Contact
Questions about this policy? Email hello@chamaeleon.app.
Also available in Català, Español, Français, and Italiano. The English version is the official, legally binding text.