Privacy Policy
How Spotka collects, uses, and protects your personal data.
Effective date: August 3, 2026 · Last updated: August 3, 2026
1. Who we are (data controller)
Spotka is operated by Sponic Gardens sp. z o.o., a company registered in Poland. Registered office: al. „Solidarności" 68/121, 00-240 Warsaw, KRS 0001248017, NIP 5253094235, REGON 545044515. We are the data controller for the personal data described in this policy.
Questions about this policy, or to exercise your rights: [email protected].
2. Data we collect
Information you provide directly
- Account data: name, email address, profile photo, and the answers you give during onboarding, including your onboarding interview, which you can complete by voice or by text with our AI agent, Fern.
- Profile data: the interests, availability, and preferences you set or edit, and any info you choose to add later.
- Content you create: messages to other members or to Fern, gathering invitations and ideas you post, photos you attach, and any feedback or bug reports you send us.
Data collected through your use of the app
- Gathering and activity data: the gatherings you create, join, or attend; guest lists; and your responses to invitations.
- AI interaction data: voice audio and transcripts, text, and feedback you give Fern during onboarding or a gathering, used to personalize your experience and improve our AI systems.
- Location: only if you turn on location sharing in your settings, used to suggest nearby gatherings and members. You can turn it off at any time.
- Device and log data: IP address, device type, operating system, app version, and timestamps when you use the app.
- Push notification tokens: so we can notify you about messages and gatherings; you can disable notifications in your device or in-app settings.
Data from third parties
- If you sign in via Google or Apple, we receive your name, email, and profile photo from that provider.
- Our payment processor provides transaction confirmation and limited billing details when a gathering involves a ticket, deposit, or paid offer.
- If another member chooses to find friends using their phone's contacts, and your email address is in their contact list, we receive a one-way scrambled (hashed) version of your email, never the address itself, to check whether it matches an existing Spotka account. See "Finding friends via your contacts" below.
Finding friends via your contacts
Spotka members can optionally use their phone's contacts to find friends who are already members, or invite the ones who aren't. This is always something the member chooses to do. We never read anyone's contacts automatically.
- What we receive: a scrambled (SHA-256 hashed) version of each contact's email address: never the raw email, never a name, and never a phone number.
- What we do with it: we check whether the scrambled email matches an existing member, then immediately forget the request. We do not store the scrambled codes or keep any record of who was checked against whom.
- What you control: a "let people who have your email find you" setting in your profile lets you opt out of being matchable this way, independent of whether you use the feature yourself.
3. How we use your data
| Purpose | Data used | Legal basis |
|---|---|---|
| Providing and operating the app | Account, profile, gathering data | Contract |
| Onboarding and AI personalization (Fern) | AI interaction, profile, preferences | Consent / Legitimate interest |
| Suggesting nearby gatherings and members | Location (only if enabled) | Consent |
| Processing gathering payments | Billing data (via payment processor) | Contract |
| Sending service and gathering notifications | Email, push token | Contract |
| Helping members find friends who are already members | Scrambled contact email addresses, discarded immediately after each check | Legitimate interest |
| Safety and abuse prevention | Account, message metadata, device data | Legitimate interest |
| Improving our AI models and the app | AI interaction, usage data (anonymized where possible) | Legitimate interest |
| Legal compliance | As required | Legal obligation |
We do not sell your personal data. We do not use your data to train third-party AI models without your explicit consent.
4. AI and automated decision-making
Fern, our AI agent, conducts onboarding interviews, participates in gatherings, and helps personalize what you see in the app, including which gatherings and ideas get suggested to you. These decisions are designed to benefit you and are informed by your preferences and feedback.
Where an automated decision could have a significant effect on you, you have the right to request human review: contact [email protected].
We do not build persistent psychological profiles intended for manipulation. Fern is designed to optimize for your wellbeing, not engagement metrics.
5. How we share your data
We share personal data only in the following circumstances:
- Service providers (sub-processors): trusted providers who help us operate the app, bound to use data only on our instructions: Supabase (database hosting), Resend (email delivery), Cloudflare (hosting, DNS), PostHog (EU-hosted product analytics), Meta (advertising measurement, only with your consent), and Przelewy24 (payment processing, for gatherings that carry a ticket or deposit).
- Other members: your name and profile are visible to other members as part of the app's community experience.
- Business transfers: if Sponic Gardens is acquired or merged, your data may be transferred as part of that transaction; we will notify you before your data becomes subject to a different privacy policy.
- Legal requirements: when required by law, court order, or to protect the safety of members or the public.
- With your consent: for any other purpose, with your prior consent.
6. Data retention
- Account and profile data: retained while your account is active, then deleted within 90 days of account closure unless a longer period is required by law.
- AI interaction logs (Fern transcripts, interview recordings): retained for 12 months then deleted, unless retained longer by legal requirement.
- Billing records: retained for 7 years per accounting regulations.
- Contact-matching data: the scrambled email codes used to find friends via contacts are never stored: each check is discarded immediately after it completes.
7. Your rights
Depending on your location, you may have the right to: access the data we hold about you, correct it, request deletion (subject to our retention obligations), receive it in a portable format, object to processing based on legitimate interests, restrict processing, withdraw consent at any time, and request human review of significant automated decisions.
To exercise any of these rights, email [email protected]. We will respond within 30 days. You may also lodge a complaint with the Polish supervisory authority, the President of the Personal Data Protection Office (UODO), uodo.gov.pl.
8. Cookies and tracking
The Spotka web app uses cookies for essential session management and authentication. These cannot be disabled without breaking sign-in. Our marketing pages use privacy-respecting analytics that do not fingerprint individuals.
Advertising measurement and Meta
If, and only if, you accept advertising cookies on our marketing pages, we measure Meta ad performance via the Meta Pixel (page views, sign-ups) and the Meta Conversions API (a hashed, irreversible version of your email sent server-side on sign-up). Declining does not stop you signing up. Withdrawing consent is as easy as giving it: clear this site's cookies and choose Decline, or email us. Meta acts as an independent controller for data it receives.
9. Data security
We use encryption in transit (TLS) and at rest, access controls, and regular security reviews. No system is perfectly secure. If you believe your account has been compromised, contact us immediately. In the event of a breach that poses a risk to your rights, we will notify affected users and relevant authorities as required by law.
10. International transfers
Sponic Gardens sp. z o.o. is established in Poland (EU). Some service providers process data outside the EEA, in particular in the United States. Where this happens we rely on appropriate safeguards: the EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework.
11. Children's privacy
Spotka is not directed to children under 18. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a child, contact us and we will delete it promptly.
12. Changes to this policy
We may update this policy from time to time. For material changes, we will notify you by email or a prominent in-app notice at least 14 days before the changes take effect.
13. Contact and complaints
Sponic Gardens sp. z o.o.
al. „Solidarności" 68/121, 00-240 Warsaw, Poland
[email protected] · spotka.co
If you are not satisfied with our response, you have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), uodo.gov.pl.