Privacy Policy

Last updated: May 22, 2026

This Privacy Policy describes how BuddyGem (the mobile and web application published as Hiddenly) collects, uses, shares, and protects personal information when you use our services.

This policy is published at https://hiddenly.up.railway.app/privacy. Have a qualified lawyer review it for your jurisdiction(s), especially if you operate in the EU/EEA, UK, or California.


1. Who we are

Data controller: Egor Ilyankov
Address: 62-613, Osiek Mały, Poland
Contact (privacy): buddy.bus.app@icloud.com
Product: BuddyGem / Hiddenly — a community map for discovering, saving, and sharing interesting places, routes, and travel-related content.

Websites and domains associated with the service include, among others: buddygem.app, www.buddygem.app, and our API/share hosts (e.g. hiddenly.up.railway.app).


2. Scope

This policy applies to:

It does not cover third-party apps or websites you open from BuddyGem (e.g. Google Maps, Instagram, TikTok, YouTube) — those services have their own privacy policies.


3. Information we collect

3.1 Account and identity

When you sign in, we process:

Data Source Purpose
Email address Email one-time password (OTP) via Supabase Auth Account creation, login, security
Email, name (if provided) Sign in with Google or Apple Account creation and login
User ID (UUID) Supabase Auth Tie your data to your account across the app and backend
Session tokens Supabase Auth Keep you signed in securely

We do not require a password for email login; authentication uses a verification code sent to your email.

3.2 Profile

If you use profile features, we store in our database (Supabase PostgreSQL):

OAuth providers may supply a profile photo URL; we may use it as a fallback for your avatar.

3.3 Location and map usage

With your permission (iOS/Android location permission, requested during onboarding):

We also store location-related data you generate:

If you deny location access, you can still use the map without centering on your current position.

3.4 Community and social content

When you interact with community features, we process:

Other users may see your nickname, avatar, and public contributions (e.g. place author name, comments) according to product rules and moderation status.

3.5 Share import (e.g. Instagram)

If you share a link into the app (Share extension / share intent):

Our servers may fetch public preview metadata (e.g. Open Graph) from the shared URL and send relevant text or image references to AI providers (see Section 5) to suggest or create a place. Do not share links or content you do not have the right to use.

3.6 Reports and safety

If you report a place from the map, we store:

Reports may trigger an email to our team (via Resend or SMTP, when configured) and/or push notifications to authorized staff. Reports are not designed to identify you to other users.

3.7 Push notifications

If you allow notifications, we store:

We use push for product events such as completed share imports and, for staff accounts, new place reports. You can disable notifications in device settings.

3.8 Photos and files

3.9 Technical, security, and usage data

Our NestJS API and Supabase may process:

On your device, we may store small preferences in local storage (e.g. onboarding completion flags, push registration cache, UI preferences such as preferred maps app) — not synced as account data unless tied to a logged-in feature.

3.10 Payment data (when subscriptions are enabled)

If you subscribe or pay through Stripe, we may store a Stripe customer ID in your account metadata. Payment card details are handled by Stripe, not stored on our servers. See Stripe’s privacy policy for payment processing.

3.11 Analytics and email marketing (when enabled)

When configured in production:

If these integrations are not enabled in your environment, we do not process data through them.


4. How we use your information

We use personal data to:

  1. Provide the service — authentication, maps, places, favorites, routes, search history, share import, AI-assisted descriptions, and sharing links
  2. Operate community features — display content, attributions, and moderation workflows (staff roles)
  3. Improve reliability and security — rate limits, fraud/abuse prevention, debugging, and infrastructure monitoring
  4. Communicate with you — login codes (via Supabase/Auth email), push notifications, and responses to reports where applicable
  5. Comply with law and enforce our terms
  6. Process account deletion — as described in Section 8

We do not sell your personal information. We do not use your data for third-party advertising profiles in the codebase described here; if that changes, we will update this policy.


5. Legal bases (EEA/UK users)

Where the GDPR or UK GDPR applies, we rely on:

Basis Examples
Contract Providing the app you signed up for; storing your places, favorites, and profile
Legitimate interests Security, rate limiting, fraud prevention, improving the service, anonymizing places after account deletion
Consent Device location, notifications, and optional marketing/analytics where consent is required — you may withdraw consent in device or in-app settings
Legal obligation Responding to lawful requests from authorities

You may have the right to object to processing based on legitimate interests; contact us to exercise that right.


6. How we share information

We share data only as needed to run BuddyGem:

Recipient Role Typical data shared
Supabase Auth, database, file storage Account, profile, user content, tokens
Hosting (e.g. Railway) API and share pages Requests, logs, IP
Google Sign-In; Maps/Places APIs for place search and photos Account tokens; place queries; quotas
Apple Sign in with Apple (iOS) Account tokens; name/email per Apple rules
Google Gemini / OpenAI AI place descriptions, share import, enrichment Text, URLs, place context you submit
OpenStreetMap / Nominatim / OSRM Geocoding and routing Coordinates, place names (public OSM policy applies)
Wikipedia / Wikidata Place enrichment Titles, coordinates, queries
Mapbox Satellite imagery for places Coordinates, zoom parameters
Expo Push notification delivery Push tokens
Stripe Payments (if enabled) Customer ID; payment handled by Stripe
PostHog Analytics (if enabled) Usage events, distinct ID
Resend Email (reports, auth-related email via Supabase) Email address, report content
Social platforms When you share or link content URLs you provide; public metadata fetches

We require service providers to process data only on our instructions and for the purposes above, subject to their own terms and privacy policies.

We may disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition (with notice where legally required).


7. International transfers

Our infrastructure and processors may be located in the European Union, United States, or other countries. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses offered by Supabase, Google, Stripe, and others) for transfers outside your country.


8. Retention and account deletion

While your account is active, we retain data needed to provide the service.

When you delete your account (in-app: Profile → Settings → Data & privacy → Manage my data → Delete my data):

  1. We remove your avatar and user-specific storage sweeps where applicable.
  2. Places you authored are not deleted from the community map; ownership transfers to a system author, your author notes in place descriptions are cleared, and your display identity is replaced with a system label (see product rules in our account-deletion design).
  3. We delete your Supabase Auth user, which cascades to profile, comments, ratings, favorites, collections, private notes, and similar user-linked rows.
  4. When configured, we run erasure steps at Stripe, PostHog, and Resend for identifiers we store.
  5. We write a minimal audit log of the deletion pipeline for operational and legal purposes.

Other retention:

Some aggregated or non-personal statistics may be retained after deletion.


9. Your rights and choices

Depending on your location, you may have the right to:

To exercise rights, contact buddy.bus.app@icloud.com. We may need to verify your identity. We respond within the timeframes required by applicable law.

California (CCPA/CPRA): You may have rights to know, delete, and correct personal information, and to opt out of “sale” or “sharing” for cross-context behavioral advertising. We do not sell personal information as defined by the CCPA based on the practices described in this policy.


10. Security

We use industry-standard measures including:

No method of transmission or storage is 100% secure; please use a strong, unique email and protect your device.


11. Children

BuddyGem is not directed at children under 13 (or the minimum age in your country). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.


12. Third-party links and public content

Places and profiles may contain links to external sites (Instagram, websites, maps). Opening those links is subject to the third party’s policy.

Shared place URLs (/open, /p/...) may expose place title, description, and images to anyone with the link — do not share sensitive personal information in public place fields.


13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the new date at the top and, for material changes, provide notice in the app or by email where appropriate. Continued use after the effective date constitutes acceptance where permitted by law.


14. Contact

Privacy inquiries: buddy.bus.app@icloud.com
Support / reports (operational): [buddy.bus.app@icloud.com] — replace with your official support address before publication.


Appendix A — Summary of main data categories

Category Examples Stored where
Identity Email, user UUID, OAuth IDs Supabase Auth
Profile Nickname, bio, avatar, locale Supabase DB + Storage
Location GPS (with permission), search/route/place coordinates Device; Supabase DB
User content Places, photos, comments, ratings, favorites, notes Supabase DB + Storage
Import jobs Shared URLs, job status Supabase DB (server-side)
Push Expo token Supabase DB
Technical IP/user rate limits, audit logs Supabase DB; server logs
Payments Stripe customer ID (optional) Auth metadata / Stripe

Appendix B — In-app data controls

This appendix reflects the implementation documented in lib/account-deletion/ and related Supabase schemas as of the last updated date above.