Privacy Policy

This Privacy Policy explains what personal data Kommunitea (“Kommunitea”, “we”, “us”) collects when you use the Kommunitea mobile app and website (together, the “Service”), why we collect it, who else can see it, and what rights you have over it. It is written to meet the EU General Data Protection Regulation (GDPR).

We have tried to describe what the Service actually does rather than what a privacy policy usually says. If you find something here that does not match your experience of the app, please tell us at privacy@kommunitea.app.

1. Who is responsible for your data

The data controller for the Service is:

You can reach us about anything in this policy at privacy@kommunitea.app.

2. What Kommunitea is

Kommunitea is a platform for discovering and organising events and for running communities of all kinds — interest groups, neighbourhood groups, company teams, and university clubs and societies among them. Through the Service you can create or join communities, create and RSVP to events, manage who is attending, chat with other participants, share photos and “memories”, answer polls, and apply to opportunities that communities list.

3. Information we collect

We collect the following, and only what the feature you are using actually needs:

4. Why we use it, and our legal basis

5. What other people can see

Kommunitea is a social product, so much of what you do is visible to other people by design. What follows depends on the settings of the community, event or chat in question:

Other users may also be able to see you through features such as suggested invitees, which draws on events and communities you have in common with someone. Blocking a user prevents this in both directions.

6. Payments

Kommunitea does not process payments. There is no payment provider integrated into the Service. We do not collect, store, or process card details, bank details, or payment credentials, and no money passes through us.

Where an organiser has indicated that their event has a cost, that money is collected by the organiser directly and outside the Service — for example by bank transfer or in cash at the event. That arrangement is between you and the organiser, and any personal data you give them for it is handled by them, not by us.

We do record whether an organiser says you have paid. The app gives organisers a way to keep track of who has settled up. When an organiser marks your ticket as paid, we store:

This is a note made by a person, not a confirmation from a bank or payment provider. It records what the organiser told us, and we cannot verify that any money actually changed hands. We keep who marked it and when so that a disagreement about payment has something to refer back to.

This information is visible to the event’s organisers and co-hosts, and to you on your own ticket. It is included in the attendee list an organiser can export. We keep it for as long as the ticket exists, and it is deleted with the event or your account. If your ticket is marked unpaid again, the record of who marked it and when is deleted.

Splitting a cost between people is the same in this respect: no money moves through us. The Service lets the people at an event record what something cost, who put money in, and how it should be divided. From those entries it works out, by arithmetic, what each person’s share comes to and who is owed what. That is a running note kept by the people involved. It is not an account, we hold no funds, and nothing about it moves money between anybody.

When you tell the Service you have paid someone back, we record that you said so, the amount, and the date. The other person is asked to confirm it. Their answer, including a refusal, is kept alongside the claim, because a claim that quietly disappears looks to the person who made it as though it was never made. None of this is verified by us and none of it is evidence that money changed hands. If you disagree about a shared cost or about whether someone paid, that is between the two of you: we are not a party to it, and we cannot adjudicate it.

The Service can also offer to reduce a group’s debts to fewer payments, so that three people owing each other in a circle can settle with one transfer instead of three. It is arithmetic on the amounts already entered, it is off unless someone turns it on, and it changes who pays whom without changing what anyone owes in total.

Aside from this, event functionality in the app is limited to registration, RSVP, ticket issuance for entry, and attendance management.

7. Location

Location is optional. The Service asks for it only when you open a map or use the “use my location” control, and you can decline or revoke permission at any time in your device settings; the rest of the app continues to work without it.

8. Verifying an affiliation

If you want to show that you belong to a university, company or other organisation, you can enter an email address at that organisation. We send a one-time code to it and check the code you enter back.

9. Documents you upload when applying to an opportunity

Communities can list opportunities, and you can apply in the app, optionally attaching a CV or similar document.

10. Who else processes your data

We do not sell your personal data and we do not share it for advertising. We use the following providers to run the Service:

Organisations are different from everyone in that list. If you choose to affiliate with a university, company, or other organisation, that organisation receives your data as a controller in its own right — it is not our processor, and it does not act on our instructions. What it receives, and what it agrees to do with it, is described in section 5. Our basis for disclosing it to them is our legitimate interest, and yours, in an affiliation that means something (Art. 6(1)(f)), and the disclosure only happens because you asked to be affiliated. Ending the affiliation stops it.

We disclose personal data outside these arrangements only where we are legally required to, or where it is necessary to protect the rights or safety of users or the public.

11. Where your data is stored, and international transfers

Our servers, our database and its backups, and the storage holding uploaded images and documents are all located in the European Union, in Amazon Web Services’ Frankfurt (Germany) region. Crash reports are held by Sentry in its European data region.

Some processing necessarily takes place outside the EU/EEA and is outside our control: when you choose to sign in with Apple or Google, or when we hand a push notification to Apple’s or Google’s notification service for delivery to your device, those companies process data under their own privacy policies and their own transfer arrangements. The same applies to Google Maps when you view a map, and to Google Wallet if you choose to add a ticket to it — see section 10 for exactly what that sends.

The place-search and weather services described in section 10 are run by European providers, and we send them only a search term or an event’s coordinates — never anything identifying you. Each operates under its own privacy policy.

The Service is operated and administered from Germany. We do not use support or engineering staff outside the EU/EEA.

12. Security

The measures we have in place include:

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do commit to notifying you and the competent supervisory authority where a personal data breach requires it under Articles 33 and 34 GDPR.

13. How long we keep your data

We keep personal data for as long as your account is active, and then apply the rules below.

14. Recommendations, automated decisions and AI

The Service suggests communities and events that may interest you, ranked using your stated interests, any organisation affiliation, your approximate location if you have shared it, and communities and events you already belong to. This is ordinary ranking of what to show you first. It does not produce legal effects, it does not decide anything about you, and it does not restrict what you can access.

Where the Service works out who owes what after a shared cost, or offers to reduce a group’s debts to fewer payments, that is arithmetic on figures people entered themselves. It decides nothing about you, it is visible to everyone it concerns, and anyone involved can correct the entries it is working from.

We do not make decisions about you by automated means within the meaning of Article 22 GDPR. We do not use AI or machine-learning services to analyse your messages, photos, CVs or other content, and we do not screen applications automatically. Reports and moderation decisions are reviewed by people.

15. Cookies, analytics and tracking

We do not use advertising SDKs. We do not track you across other apps or websites, we do not build advertising profiles, and we do not sell or share anything for advertising.

We do use one product-analytics tool inside the app, PostHog, to understand how the app is used and where people get stuck. It is hosted in the European Union and acts as our processor.

What it records is a short, fixed list of things you do, and nothing else:

Each of these is recorded as a count, tied to your account’s internal ID number. The contents are never sent. We do not send the text of your messages, your search terms, captions, photos, names, email addresses or your location. For a chat message we record only that one was sent and whether it had a photo attached; for a memory, only that one was added and whether it was public or private; for sharing a memory into a chat, only that it happened — never which memory, which chat, or who could see it. There is no session recording, no screen recording, and no automatic capture of taps: only the events listed above are collected.

You can turn this off. Open Settings → Privacy in the app and switch off “Usage analytics”. It takes effect immediately, and your choice is remembered on that device. Turning it off does not affect anything else in the app.

Our legal basis is our legitimate interest (Article 6(1)(f) GDPR) in understanding how the Service is used so that we can improve it, balanced against the limited, non-content nature of what is collected and your ability to switch it off at any time.

The app stores a sign-in token and a small amount of preference data on your device so that you stay signed in. This is essential to the Service working.

The kommunitea.app website sets no cookies. It is a set of static pages, with no accounts, no analytics and no embedded trackers, which is why you are not asked for cookie consent when you visit it.

If we ever introduce a non-essential cookie or similar technology, we will ask for your consent before it is used, and update this section first.

16. Children

The Service is not directed at children. You must be at least 18 years old to create an account, and the app is rated accordingly in the App Store and on Google Play.

We do not ask for your date of birth, so we do not verify your age — the minimum age is a condition of using the Service rather than a check the app performs. We do not knowingly collect personal data from anyone under 18. If we learn that an account belongs to someone under 18 we will disable it and delete the associated personal data. If you are a parent or guardian, or you believe a child has created an account, contact us at privacy@kommunitea.app and we will act on it.

17. People who are not users

In one situation we hold personal data about someone who has no account with us and has never agreed to anything: a guest brought to an event by someone else. Where an organiser asks registering attendees to name the guests they are bringing, we store those names. If that is you, this section is for you.

The person who adds your name is required by our Terms of Service to have your permission first, and is asked to confirm this when they type it. A guest under 18 may only be added by their parent or guardian, who is responsible for them at the event. If your name was added without your agreement, contact us and we will remove it.

18. Your rights

Under the GDPR you have the right to:

To exercise any of these, email privacy@kommunitea.app. We will respond within one month, and will tell you if we need longer as the GDPR permits. We may need to confirm your identity first.

You also have the right to lodge a complaint with a data protection supervisory authority — in your country of residence, your place of work, or where you believe an infringement occurred. The authority competent for us is:

19. Changes to this policy

We may update this policy as the Service develops. When we do, we will post the updated version on this page and change the “Last updated” date at the top. If a change materially affects how we handle your data, we will tell you within the Service before it takes effect.

20. Contact

For any question about this policy, or to exercise your rights, contact us at privacy@kommunitea.app.