← Back

Privacy & GDPR

This page is maintained by the OurWorld team to explain how we handle your personal data. Last updated: June 2026.

Who we are

OurWorld is a live social platform where people drop into events and meet others around the world. The OurWorld team is the data controller for the personal data described below.

What we collect

  • Account data: email address and password (stored hashed by our auth provider).
  • Profile data: display name, optional avatar, optional bio and other profile fields you choose to add.
  • Content you create: events you host, photos you upload, messages you send in conversations and event chats.
  • Social graph: friend requests, friendships and blocks.
  • Location data: approximate location attached to events you create or interact with, used to show events on the map.
  • Technical data: session tokens stored in your browser to keep you signed in, plus standard request logs.

Why we use it (legal basis)

  • Contract (Art. 6(1)(b) GDPR): to provide the account, events, messaging and map features you sign up for.
  • Legitimate interest (Art. 6(1)(f) GDPR): to keep the service secure, prevent abuse, and handle reports.
  • Consent (Art. 6(1)(a) GDPR): for optional things like sharing your location or adding extra profile details — you can withdraw at any time by removing them.

Who can see what

Your display name, avatar and public profile fields are visible to other signed-in users. Events you host are visible to users who can see them on the map. Direct messages are visible only to the people in that conversation. Email and password are never shown to other users.

Sharing & subprocessors

We don't sell your data. We share it only with the trusted infrastructure providers below, who process it on our behalf under their own GDPR commitments:

  • Lovable Cloud (Supabase-backed): database, auth, file storage, server functions. Region: EU.
  • Google Maps Platform (Google Ireland Ltd.): map tiles and geocoding. Receives the coordinates needed to render the map you're viewing.
  • Google OAuth (Google Ireland Ltd.): only if you choose "Continue with Google" — Google authenticates you and shares your email and name with us.
  • Cloudflare: edge hosting and DDoS protection. Sees standard request metadata (IP, user agent).

We don't use third-party analytics, advertising, or trackers.

Cookies & local storage

We only use what's strictly necessary to run the app: a session token in your browser's localStorage to keep you signed in, and standard security cookies. No analytics or advertising cookies. Because we don't set non-essential cookies, no cookie banner is required under the EU ePrivacy Directive.

International transfers

Our primary infrastructure is in the EU. Google services (Maps, OAuth) may process data in the United States under the EU-U.S. Data Privacy Framework and Standard Contractual Clauses.

How long we keep it

  • Account & profile: while your account is active. Deleted within 30 days of you clicking "Delete my account".
  • Events: kept until you delete them, or 12 months after they end, whichever comes first.
  • Messages: kept until you or the other party deletes the conversation, or you delete your account.
  • Inactive accounts: if you don't sign in for 24 months, we'll email you and delete the account 30 days later.
  • Security & abuse logs: 90 days.
  • Reports & moderation records: 12 months after the case is closed.

Data Processing Agreement (DPA)

OurWorld is a consumer service. If you represent a business that needs a signed DPA (Art. 28 GDPR) to use OurWorld on behalf of your own users, contact ourworldapp.service@gmail.com and we'll provide one.

Your GDPR rights

You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data (you can edit most of it in your profile).
  • Delete your account and associated personal data.
  • Export your data in a portable format.
  • Object to or restrict certain processing.
  • Withdraw consent at any time.
  • Lodge a complaint with your national data protection authority.

To exercise any of these rights, contact us at ourworldapp.service@gmail.com.

Security

Data is transmitted over HTTPS and stored on managed infrastructure with row-level security so that users can only access data they're allowed to see. Passwords are never stored in plain text.

Children

OurWorld is not intended for users under 16. If you believe a child has created an account, please contact us and we'll remove it.

Changes to this policy

We'll update this page when our practices change and adjust the "last updated" date at the top.