Effective date: 22 June 2026 Last updated: 22 June 2026 Version: 1.0
We wrote this policy to be clear about exactly what gleich does with your data — in plain language, with no surprises. It explains what we collect, why, the legal basis under the GDPR, who we share it with, how long we keep it, and your rights. If anything is unclear, email us at [email protected].
gleich is an iOS app for meeting up with friends at real-world events. You create an event (a place and a time), invite friends with a link or QR code, and while the event is live everyone in it can see each other moving toward the meeting point on a map.
What that means for your data, in plain terms:
The "controller" of your personal data — the entity that decides why and how it's processed under the GDPR — is the developer of gleich:
de.kesselapps.gleichapp.We only collect what the app needs to do its job. Here is everything, by category.
When you sign in, you choose a display name (it may be pre-filled from the name Apple provides on your first sign-in). It is stored on your account so your friends can recognise you in an event. It is not required to be your real name.
gleich uses Sign in with Apple. When you sign in, Apple gives the app a signed "identity token", which our backend verifies (against Apple's public keys) and from which it reads your Apple user identifier — a stable, opaque value Apple assigns specifically for gleich (it is not your Apple ID, email, or a value shared with other apps). We store that identifier as the key to your account, together with a random, opaque session token that keeps you signed in. We request only your name from Apple; we do not receive or store your Apple email address. The Apple identifier is not used for advertising or cross-app tracking.
While you have the live map of an event open, the app reads your precise GPS location and shares it, in real time, with the other people in that event. The app requests "When In Use" and "Always" location permission so the map keeps working even when your phone is locked on the way to the meeting point. The location accuracy is set to roughly 100 metres and a new position is only sent after you've moved about 60 metres — gleich does not use the most precise possible GPS fix. Precise location is declared as "collected" in gleich's iOS Privacy Manifest (alongside your name and user identifier), all marked as linked to your account, not used for tracking, and used only for app functionality.
When you create or join an event we store: - the event details: title, type, the destination's coordinates and (if you typed one) its address, and the meeting time; - an invite token (the secret behind your invite link / QR code); - who is in the event (the membership list linking your account to that event); - contributions ("who's bringing what"): an item, an optional note, and who added it.
Together, the membership records reveal which events you attend and with whom — information we treat as personal data. ### e. Camera (only to scan a QR invite) If you choose to join an event by scanning a friend's QR code, gleich uses your camera. The camera feed is used on-device to read the code; gleich does not store or upload photos. ### f. Technical connection data Like any internet service, our server receives the basic technical data needed to deliver a response, including your device's IP address, which our web server (nginx) can record in standard access logs. ### What we do not collect Based on the code as it stands today, gleich does not collect: your email address, phone number, real name, password, contacts, photo library, health data, payment data, or advertising identifiers; and it contains no analytics, crash- reporting, attribution, or advertising SDKs. (the only third-party SDK is Mapbox)
Under the GDPR we must have a lawful basis for each purpose. Here is each one.
| What we do | Why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and keep your account (Apple user identifier, display name, session token) | So you can sign in with Apple, use the app, and stay signed in | Contract — Art. 6(1)(b): necessary to provide the service you asked for |
| Create, store, and show events, memberships, and contributions | To run the core "plan and join an event" feature | Contract — Art. 6(1)(b) |
| Share your precise live location with the other members of an event | The reason the app exists — so friends can find each other on the way to a meet-up | Contract — Art. 6(1)(b): sharing your location is necessary to provide the live meet-up feature you choose to open. You stay in control: grant or revoke location in iOS Settings, use the in-app sharing toggle, and stop at any time by closing the map or leaving the event. |
| Use your camera to scan an invite QR code | To let you join an event quickly | Consent — Art. 6(1)(a), via the iOS camera permission prompt |
| Turn an address you type into map coordinates (via Mapbox) | To set an event's destination | Contract — Art. 6(1)(b) |
| Keep basic server logs (incl. IP) | To operate, secure, and debug the service | Legitimate interests — Art. 6(1)(f): running a secure, reliable service |
| Enforce a simple API key gate on requests | To reduce abuse/automated misuse of the API | Legitimate interests — Art. 6(1)(f) |
Is providing this data required? Signing in (your Apple identifier) and choosing a display name are necessary to have an account and use gleich. Sharing your location is necessary only for the live map — if you don't, you can still create, join, and plan events. We do not require any other data, and there is no statutory obligation to provide it.
We do not use your data for advertising, profiling, or automated decision-making with legal effects.
Because precise location is the most sensitive thing gleich handles, here is exactly how it works, end to end.
location background mode so the map keeps updating while you walk to the
meeting point with your phone locked. - Who can see it: only the other signed-in members of that same event —
nobody else. The server only ever sends a member's position to other members of
the same event, and never echoes your own position back to strangers.Because location is shared only among the app's own users for the core feature you asked for — not collected to track you across other companies' apps or websites — this is not "tracking" in Apple's App Tracking Transparency sense, and gleich shows no ATT prompt. ---
This is the point of the app: members of an event see each other's display names, live positions (while the live map is open), and contributions. Don't join an event with people you don't want to share your location with.
We keep this list short and only include companies the code actually relies on.
| Provider | What it does for gleich | What it receives | Where | Their policy |
|---|---|---|---|---|
| Apple | Distributes the app (App Store), runs iOS, provides Sign in with Apple authentication, and provides location/camera permission controls | The Sign in with Apple exchange (Apple authenticates you and issues the identity token we verify); whatever Apple processes as the platform; App Store account data is between you and Apple | USA / global | https://www.apple.com/legal/privacy/ |
| Mapbox | Renders the map and converts a typed address into coordinates (geocoding) | Map view requests; the address text you type when setting a destination; map tile/usage data tied to our access token. Mapbox's own mobile SDK may also collect standard telemetry — see the gap noted in Section 14. | USA (and CDN) | https://www.mapbox.com/legal/privacy |
| Hetzner Online GmbH | Hosts the gleich backend and database | All data processed by the backend (account, events, memberships, contributions; transient live-location relay; connection/IP data) | Germany (EU) | https://www.hetzner.com/legal/privacy-policy |
| Cloudflare, Inc. | Sits in front of the API as a proxy/CDN (TLS, DDoS/abuse protection) | Connection metadata, IP | USA / global edge | https://www.cloudflare.com/privacypolicy/ |
Each processor acts on our instructions under a data-processing agreement (or the provider's equivalent terms). ### c. We do not sell or "share" your data for advertising gleich has no advertising or attribution SDKs and performs no ad-related sharing.
We may disclose data if required by law (e.g. a valid legal request from a competent authority), but only to the extent required.
Some providers are based outside the EU/EEA:
Where data goes to a non-EU country, the transfer is protected by appropriate safeguards: the EU Standard Contractual Clauses (SCCs) and/or the provider's certification under the EU–US Data Privacy Framework, as applicable to each US provider.
Deleting your account. In the app, go to Settings → Delete account. This calls our server and performs a permanent hard delete in a single transaction: your account is removed, along with the events you host (and those events' membership and contribution records), and your memberships and contributions in other people's events. There is no soft-delete or hidden copy. Because live locations are never stored, there is nothing further to purge.
Note: when a non-host deletes their account, the events they merely attended remain (only their own membership and contributions are removed). Account deletion also clears your locally stored session and device identifier on the phone.
We reflect only measures the code actually shows:
Under the GDPR you have the right to:
To exercise any right that you can't complete in the app, contact us at [email protected]. We'll respond within the time limits the law requires (generally one month).
gleich is not intended for young children. You must be at least 16 (the age of digital consent in Germany under the GDPR / BDSG) to use gleich. We do not knowingly collect data from anyone below this age; if you believe a child has used gleich, contact us and we will delete the account.
We may update this policy as gleich evolves. When we make material changes we'll update the "Last updated" date and version above and, where appropriate, notify you in the app. The current version is always available at https://gleich.app/privacy.
Questions or privacy requests: