wemeo (“wemeo”, “we”, “us”) helps you discover communities, places and events in cities across Romania, save the ones you like, and get a reminder before they start. This policy explains what we collect, how we use it, and your choices. By using wemeo you agree to this policy.
Information we collect
- Sign-in details. You sign in with Apple, Google or an email code. With Apple we receive the name and email address you choose to share (including Apple's private relay address if you use “Hide My Email”); with Google we receive your name, email address and profile picture; with email sign-in we receive your email address. (Some early accounts were created with a sign-up method we've since retired; we no longer use it, and we delete that data on request or when you delete your account.)
- Profile. An optional display name, city and language; a profile picture if you upload one or sign in with Google (otherwise we generate a simple avatar from your initials); an optional contact email or phone number you add for outings; and light, optional fun — your “city animal” quiz result and things you'd like to try (sidequests).
- Activity. The communities, places and festivals you add to your list, the events you save reminders for, and a short history of the messages we've sent you.
- Outings. If you join an outing (our small, capped group meetups) we record your participation and generate a personal ticket code. Joining requires a profile photo and a reachable email; your first name and photo appear on that outing's card to other participants. Tapping “I'm interested” on the outings page stores that preference so we can tell you when sign-ups open.
- Technical. A session token stored in your browser to keep you signed in; a device push token if you enable notifications in our iOS app; basic, privacy-friendly usage analytics; and, briefly, your IP address to throttle abusive sign-in attempts.
How we use your information
- To sign you in and keep your session active.
- To send you sign-in codes, the event reminders you set, and outing details (location and your ticket) — by email and, in the iOS app, by push notification.
- To show your first name and a small avatar next to the communities and places you follow and the events you say you're going to (the “people going / following” you see on pages). This is on by default; you can turn it off anytime with the “show my picture” setting — you'll still be counted, just never shown.
- To operate, secure, and improve the service (including throttling sign-in attempts to prevent abuse).
Legal basis (EU/EEA)
Where the GDPR applies, we rely on: contract — to create your account and run the service you asked for; consent — to send the reminders and notifications you ask for (switch them off anytime); legitimate interests / your settings — to show your first name and avatar next to what you follow or attend, which you can switch off at any time; and legitimate interests — to keep wemeo secure and working. You can withdraw consent at any time without affecting prior processing.
Sign in with Apple or Google
If you sign in with Apple or Google, authentication is handled by them and governed by Apple's Privacy Policy or Google's Privacy Policy. We never see your password — we only receive a signed proof of who you are, which we verify directly against Apple's or Google's public keys.
AI processing
We use AI models to keep the public event catalogue fresh: they help read publicly available web pages of event organizers, venues and ticketing sites (event titles, dates, venues, descriptions). Your account data — email, name, follows, activity — is never sent to AI providers. The AI providers we use for this public-content processing are Anthropic and locally hosted models under our control.
How we share information
We do not sell your personal data. We share it only with the providers (sub-processors) that run wemeo:
- Supabase — database and image storage.
- Vercel — hosting and anonymous analytics.
- Apple / Google — to authenticate you when you choose Sign in with Apple or Google.
- Resend — to deliver sign-in codes, event reminders and outing emails.
- Anthropic — AI processing of public event and organizer web content only; never your personal data.
- OpenStreetMap (Nominatim) — to turn a community or place address into map coordinates.
- PostHog (EU) and Plausible — product and traffic analytics, when enabled (see “Analytics” below).
Some of these providers are located outside the EU/EEA. Where personal data is transferred internationally, it is protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses.
Community and place pages may link to third-party groups, Instagram pages and websites run by the organisers; those are governed by their own terms and privacy policies.
Data retention
We keep your account information while your account is active. More specifically:
- Sign-in sessions expire automatically (currently after 90 days) and are then deleted.
- Message history — we keep a rolling record of the most recent reminders and messages we sent you (roughly the last 50), so you and we can see what was delivered.
- Abuse-prevention logs — we briefly keep an IP-derived record of sign-in attempts to throttle brute-force attacks; these are pruned automatically (within hours).
- When you delete your account, we remove your profile, sessions, your entries in any outings, and your identifying details from any communities you submitted; we complete deletion within 30 days.
You can switch off reminders, or request deletion of your account and data, at any time.
Deleting your data
Delete your account directly in the app — Profile → Delete my account — or send a request through the in-app Support form or by email at hello@wemeo.com. We delete your personal data within 30 days.
Your rights
You can access, correct or delete your data, and switch off reminders at any time (in the app, or by replying to a message). If you are in the EU/EEA, you have rights under the GDPR, including the right to lodge a complaint with your local data protection authority.
Analytics
To understand how wemeo is used and improve it, we record basic product-usage events (for example: a page opened, a community added to a list, a reminder set). These feed:
- Our own first-party log — event names and minimal properties, linked to your account only while you're signed in. No IP address is stored.
- PostHog (EU region) — product analytics (funnels, retention), active only when configured. It is set up to send only these explicit events (no autocapture, no session recording) and to honour your browser's Do Not Track setting.
- Plausible — privacy-friendly, cookieless page-view counts, active only when configured.
We also store first-touch campaign parameters (utm_source/medium/campaign) in your browser's local storage so we can see which channel brought you in. Turn on Do Not Track, or delete your account, to opt out of identified analytics.
Cookies & local storage
We use your browser's local storage for a session token (to keep you signed in) and the analytics values described above. We do not use advertising cookies.
Children
wemeo is not intended for anyone under 16. We do not knowingly collect data from children.
Changes
We may update this policy. We'll change the “last updated” date above and, for material changes, let you know in the app.
Contact
Questions or requests: hello@wemeo.com, or use the in-app Support form.