Last updated: May 22, 2026
This Privacy Policy describes how BuddyGem (the mobile and web application published as Hiddenly) collects, uses, shares, and protects personal information when you use our services.
This policy is published at
https://hiddenly.up.railway.app/privacy. Have a qualified lawyer review it for your jurisdiction(s), especially if you operate in the EU/EEA, UK, or California.
Data controller: Egor Ilyankov
Address: 62-613, Osiek Mały, Poland
Contact (privacy): buddy.bus.app@icloud.com
Product: BuddyGem / Hiddenly — a community map for discovering, saving, and sharing interesting places, routes, and travel-related content.
Websites and domains associated with the service include, among others: buddygem.app, www.buddygem.app, and our API/share hosts (e.g. hiddenly.up.railway.app).
This policy applies to:
It does not cover third-party apps or websites you open from BuddyGem (e.g. Google Maps, Instagram, TikTok, YouTube) — those services have their own privacy policies.
When you sign in, we process:
| Data | Source | Purpose |
|---|---|---|
| Email address | Email one-time password (OTP) via Supabase Auth | Account creation, login, security |
| Email, name (if provided) | Sign in with Google or Apple | Account creation and login |
| User ID (UUID) | Supabase Auth | Tie your data to your account across the app and backend |
| Session tokens | Supabase Auth | Keep you signed in securely |
We do not require a password for email login; authentication uses a verification code sent to your email.
If you use profile features, we store in our database (Supabase PostgreSQL):
avatars under your user ID)app_locale: e.g. ru, en, de, fr, and other supported codes)OAuth providers may supply a profile photo URL; we may use it as a fallback for your avatar.
With your permission (iOS/Android location permission, requested during onboarding):
We also store location-related data you generate:
user_search_history): place titles, subtitles, latitude/longitude, and optional links to community places, Google Place IDs, or OpenStreetMap IDsuser_route_plan_history): origin and destination labels, coordinates, deviation radius (km), and whether origin was your current locationuser_saved_routes): route geometry/metadata and optional notesuser_visited_places): which community places you marked visited, optional rating and visit dateIf you deny location access, you can still use the map without centering on your current position.
When you interact with community features, we process:
user_place_notes)Other users may see your nickname, avatar, and public contributions (e.g. place author name, comments) according to product rules and moderation status.
If you share a link into the app (Share extension / share intent):
share_import_jobs)Our servers may fetch public preview metadata (e.g. Open Graph) from the shared URL and send relevant text or image references to AI providers (see Section 5) to suggest or create a place. Do not share links or content you do not have the right to use.
If you report a place from the map, we store:
Reports may trigger an email to our team (via Resend or SMTP, when configured) and/or push notifications to authorized staff. Reports are not designed to identify you to other users.
If you allow notifications, we store:
user_expo_push_tokens), registered via our backendWe use push for product events such as completed share imports and, for staff accounts, new place reports. You can disable notifications in device settings.
avatars)place-photos) and URLs referenced on place recordsOur NestJS API and Supabase may process:
X-Forwarded-For or connection), route group, and counters (api_rate_limit_counters)On your device, we may store small preferences in local storage (e.g. onboarding completion flags, push registration cache, UI preferences such as preferred maps app) — not synced as account data unless tied to a logged-in feature.
If you subscribe or pay through Stripe, we may store a Stripe customer ID in your account metadata. Payment card details are handled by Stripe, not stored on our servers. See Stripe’s privacy policy for payment processing.
When configured in production:
If these integrations are not enabled in your environment, we do not process data through them.
We use personal data to:
We do not sell your personal information. We do not use your data for third-party advertising profiles in the codebase described here; if that changes, we will update this policy.
Where the GDPR or UK GDPR applies, we rely on:
| Basis | Examples |
|---|---|
| Contract | Providing the app you signed up for; storing your places, favorites, and profile |
| Legitimate interests | Security, rate limiting, fraud prevention, improving the service, anonymizing places after account deletion |
| Consent | Device location, notifications, and optional marketing/analytics where consent is required — you may withdraw consent in device or in-app settings |
| Legal obligation | Responding to lawful requests from authorities |
You may have the right to object to processing based on legitimate interests; contact us to exercise that right.
We share data only as needed to run BuddyGem:
| Recipient | Role | Typical data shared |
|---|---|---|
| Supabase | Auth, database, file storage | Account, profile, user content, tokens |
| Hosting (e.g. Railway) | API and share pages | Requests, logs, IP |
| Sign-In; Maps/Places APIs for place search and photos | Account tokens; place queries; quotas | |
| Apple | Sign in with Apple (iOS) | Account tokens; name/email per Apple rules |
| Google Gemini / OpenAI | AI place descriptions, share import, enrichment | Text, URLs, place context you submit |
| OpenStreetMap / Nominatim / OSRM | Geocoding and routing | Coordinates, place names (public OSM policy applies) |
| Wikipedia / Wikidata | Place enrichment | Titles, coordinates, queries |
| Mapbox | Satellite imagery for places | Coordinates, zoom parameters |
| Expo | Push notification delivery | Push tokens |
| Stripe | Payments (if enabled) | Customer ID; payment handled by Stripe |
| PostHog | Analytics (if enabled) | Usage events, distinct ID |
| Resend | Email (reports, auth-related email via Supabase) | Email address, report content |
| Social platforms | When you share or link content | URLs you provide; public metadata fetches |
We require service providers to process data only on our instructions and for the purposes above, subject to their own terms and privacy policies.
We may disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition (with notice where legally required).
Our infrastructure and processors may be located in the European Union, United States, or other countries. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses offered by Supabase, Google, Stripe, and others) for transfers outside your country.
While your account is active, we retain data needed to provide the service.
When you delete your account (in-app: Profile → Settings → Data & privacy → Manage my data → Delete my data):
Other retention:
Some aggregated or non-personal statistics may be retained after deletion.
Depending on your location, you may have the right to:
To exercise rights, contact buddy.bus.app@icloud.com. We may need to verify your identity. We respond within the timeframes required by applicable law.
California (CCPA/CPRA): You may have rights to know, delete, and correct personal information, and to opt out of “sale” or “sharing” for cross-context behavioral advertising. We do not sell personal information as defined by the CCPA based on the practices described in this policy.
We use industry-standard measures including:
No method of transmission or storage is 100% secure; please use a strong, unique email and protect your device.
BuddyGem is not directed at children under 13 (or the minimum age in your country). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
Places and profiles may contain links to external sites (Instagram, websites, maps). Opening those links is subject to the third party’s policy.
Shared place URLs (/open, /p/...) may expose place title, description, and images to anyone with the link — do not share sensitive personal information in public place fields.
We may update this Privacy Policy from time to time. We will post the new date at the top and, for material changes, provide notice in the app or by email where appropriate. Continued use after the effective date constitutes acceptance where permitted by law.
Privacy inquiries: buddy.bus.app@icloud.com
Support / reports (operational): [buddy.bus.app@icloud.com] — replace with your official support address before publication.
| Category | Examples | Stored where |
|---|---|---|
| Identity | Email, user UUID, OAuth IDs | Supabase Auth |
| Profile | Nickname, bio, avatar, locale | Supabase DB + Storage |
| Location | GPS (with permission), search/route/place coordinates | Device; Supabase DB |
| User content | Places, photos, comments, ratings, favorites, notes | Supabase DB + Storage |
| Import jobs | Shared URLs, job status | Supabase DB (server-side) |
| Push | Expo token | Supabase DB |
| Technical | IP/user rate limits, audit logs | Supabase DB; server logs |
| Payments | Stripe customer ID (optional) | Auth metadata / Stripe |
This appendix reflects the implementation documented in lib/account-deletion/ and related Supabase schemas as of the last updated date above.