Privacy Policy
1. Who we are
Who's In ("the App", "we", "us") is operated by Triad Solutions, Gothenburg, Sweden ("the Controller"). We are the data controller for personal data processed through the App, as defined by the EU General Data Protection Regulation (GDPR).
- Contact: kontakt@triadsolutions.se
- Postal address: Triad Solutions, Gothenburg, Sweden (full postal address available on request via the contact above).
2. Scope
This policy describes how we collect, use, and share personal data when you download, install, or use Who's In on iOS or Android. It applies whether you use the App as a session organizer or as an invited participant.
3. Data we collect
3.1 Account data (required)
- Email address — for login, account recovery, and transactional email.
- Display name — shown to other members of any session you join.
- Authentication identifiers — provided by Apple Sign In if you choose that method. Apple's email-relay address (if used) is stored so invites sent to it can be matched.
- Account password (hashed) — never stored in plain text.
- Acceptance of the End User License Agreement — required at signup; we store the timestamp.
3.2 Profile data (optional, user-controlled)
- Profile photo
- Phone number
- Swish handle (Sweden) / Venmo handle (US) — used to render settlement deep links, not to move money
- Emergency contact
3.3 Special-category data (optional, explicit opt-in)
Dietary notes and accessibility notes are GDPR Article 9 "special category" data. We only collect this if you explicitly opt in; the consent timestamp is recorded. Visible only to members of the same session.
3.4 Session data
For every session you create or join:
- Session name, type (trip / party / gathering), destination, dates, activity, per-person budget, ledger currency
- Membership and role (organizer, co-organizer, participant)
- Plan changes you propose or approve
- Pins (locations) and itinerary items
- Group chat messages and reactions
- Photo attachments to the chat and memory feed (with optional captions)
- Receipt photos uploaded for expense tracking, and OCR text extracted from them (total, currency, line items)
- Expenses, splits, and settlement records
- Availability windows you submit for date negotiation
3.5 Payment data
- One-time consumable purchases (the session fee and any tier upgrade) are processed by Apple App Store or Google Play, via RevenueCat as our payment intermediary. We receive a transaction record (event id, product id, amount, currency, timestamp), not your payment instrument.
- We do not see, store, or process credit-card numbers or bank details.
- Settlements between participants happen outside the App via Swish or Venmo deep links. We do not move money on your behalf.
3.6 Device and diagnostic data
- Push notification token — to deliver invites, plan changes, and trial reminders via Expo Push.
- Crash reports and error events — via Sentry. Stack traces and breadcrumbs are scrubbed of identifiers before transmission; the user ID is the only identifier we associate with errors.
- Product analytics — via PostHog (EU Cloud), to measure conversion and feature usage. Events are pseudonymous (linked to your user ID, not your name or email).
- Locale and device model — for compatibility diagnostics.
3.7 Moderation data
- Reports you file against a message or photo, including the reason text
- Users you block
4. Purposes and legal bases
We process your data on the following GDPR Article 6 bases:
| Purpose | Data | Legal basis |
|---|---|---|
| Operate the core service (sessions, plans, ledger, chat) | Account, session, payment | Contract (Art. 6(1)(b)) |
| Send transactional email and push (invites, trial expiry, settlement reminders) | Account, push token | Contract |
| Process session-fee purchases | Payment | Contract |
| Provide AI features (itinerary, date picker, budget, chat) | Session content you submit | Contract |
| Display dietary/accessibility notes to your session | Special-category data | Explicit consent (Art. 9(2)(a)) |
| Detect and fix bugs, prevent abuse | Diagnostic, analytics | Legitimate interest (Art. 6(1)(f)) |
| Comply with legal obligations | Any of the above | Legal obligation (Art. 6(1)(c)) |
| Send marketing email (if introduced) | Account | Consent — not currently used |
5. Recipients and processors
We share your data only with the processors listed below. Each is bound by a Data Processing Agreement and processes data only on our instructions.
| Processor | Role | Region |
|---|---|---|
| Supabase | Hosting (Postgres database, authentication, storage, realtime, edge functions) | EU (Frankfurt) |
| Apple / Google | App distribution and in-app purchase processing | Per-store |
| RevenueCat | IAP receipt validation and webhook delivery | US |
| Anthropic (Claude API) | AI inference for itinerary, chat, OCR | US |
| Resend | Transactional email (invites, password resets) | US |
| Sentry | Crash and error reporting | EU |
| PostHog | Product analytics | EU |
| Expo (Push) | Push notification routing | US |
Where a processor is in the United States, transfers are governed by the EU–US Data Privacy Framework where applicable, or by Standard Contractual Clauses (SCCs) signed with the processor.
We do not sell your personal data.
6. Retention
| Data | Retention |
|---|---|
| Account data | Until you delete your account |
| Active or completed session data | Indefinitely (so memories stay available) |
| Trial sessions that go unpaid | Read-only after 5 days; hard-deleted after 90 days |
| Receipt photos | With the parent session |
| Memory photos | With the parent session |
| Diagnostic logs | 30 days |
| RevenueCat transaction records | As long as required by tax and accounting law |
| Reports and moderation actions | Up to 2 years for safety review |
When a session is deleted, all member-uploaded content (receipts, memory photos, messages) is deleted with it.
7. Your rights (GDPR)
- Access your data — export every record we hold about you as JSON + media zip from Settings → Data & Privacy → Export my data.
- Rectify inaccurate data — edit your profile from the app at any time.
- Erase your data — Settings → Data & Privacy → Delete account. Account deletion erases personal data; contributions to shared sessions (e.g. expense lines other members rely on) are anonymized as "Former member" so ledgers remain consistent.
- Restrict or object to processing — email us at the contact above.
- Portability — the export is provided in a structured, machine-readable format.
- Withdraw consent at any time for dietary/accessibility notes.
You also have the right to lodge a complaint with the Swedish data protection authority (Integritetsskyddsmyndigheten, imy.se) or your local supervisory authority in the EEA.
8. Security
- Data in transit is encrypted with TLS.
- Data at rest is encrypted in our managed Postgres and Storage buckets.
- Receipt and memory photos sit in private buckets reachable only via short-lived signed URLs.
- Row-level security policies isolate every session: a non-member cannot read, write, or even enumerate another session's data.
- AI inference uses server-side keys; your prompts and AI responses are not used by the AI provider to train models, per their commercial terms.
- We log no personally identifying information in server logs.
No system is perfectly secure. If you become aware of a vulnerability, contact kontakt@triadsolutions.se.
9. Children
Who's In is not directed at children under 13. In the EU, users must be at least 16 (or your member state's lower threshold under GDPR Art. 8). If you believe a child has provided us data without consent, contact us and we will delete it.
10. Changes
We may update this policy. Material changes will be announced in-app at least 30 days before they take effect, with the option to delete your account before the change applies. The "Last updated" date above always reflects the most recent version.
11. Contact
- Privacy questions: kontakt@triadsolutions.se
- Security disclosures: kontakt@triadsolutions.se
- General support: kontakt@triadsolutions.se