Givore Logo
Back to Home

Privacy Policy for Givore

Effective Date: October 5, 2025
Last Updated: July 13, 2026

1. Introduction

Welcome to Givore. This Privacy Policy explains how Karol Dąbrowski, trading as "Givore" ("we," "us," or "our"), collects, uses, discloses, and protects your information when you use the Givore mobile application (the "App"). By using the App, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use the App.

2. Developer Information

  • App Name: Givore
  • Data Controller: Karol Dąbrowski, self-employed (autónomo), NIE ESZ0649598Z, Valencia, Spain
  • Contact Email: [email protected]

3. Information We Collect

We collect several types of information to provide and improve our services:

3.1 Personal Information

  • Name: To identify you within the App
  • Email Address: For account registration and communication
  • Phone Number: For account verification and communication
  • Location Data: To provide location-based features and services
  • Photos: When you choose to upload or share images within the App

3.2 Device Information

  • Device type and model
  • Operating system version
  • Unique device identifiers
  • Mobile network information
  • IP address

3.3 Analytics and Usage Information

  • Anonymized crash and error data: Device type, operating system version, and crash diagnostics (no personal identifiers are included)
  • Anonymized website analytics: Page views, traffic sources, and session data
  • User interaction data (non-anonymized): Views of posts, ideas, comments, and profiles; clicks, saves, and other interactions within the App — stored on our servers and linked to your account

4. How We Use Your Information

We use the collected information for the following purposes, each with its legal basis under Article 6 GDPR:

  • App Functionality: To provide core features and services of the App (legal basis: performance of a contract, Art. 6(1)(b))
  • Account Management: To create and manage your user account (legal basis: performance of a contract, Art. 6(1)(b))
  • Communication: To send you service updates and notifications and respond to your inquiries (legal basis: performance of a contract, Art. 6(1)(b)); the newsletter is sent only with your consent (Art. 6(1)(a))
  • Analytics: To understand how users interact with the App and improve user experience (legal basis: our legitimate interest in improving the service, Art. 6(1)(f)); optional analytics cookies on the website load only with your consent (Art. 6(1)(a))
  • Promoted content: To show posts in the feed that are clearly marked as ads. This is our own promoted content; we do not use third-party advertising networks or advertising trackers (legal basis: our legitimate interest, Art. 6(1)(f))
  • Security: To protect against fraud, abuse, and unauthorized access (legal basis: our legitimate interest in keeping the service safe, Art. 6(1)(f))
  • Legal Compliance: To comply with applicable laws and regulations (legal basis: legal obligation, Art. 6(1)(c))

5. Authentication

The App provides the following authentication methods:

  • Email Authentication: Account creation and login using email and password
  • Google OAuth: Sign in using your Google account credentials
  • Sign in with Apple: Sign in on iOS using your Apple ID

5.1 Google OAuth Data

When you choose to sign in with Google, we request access to the following information from your Google account:

  • Email Address: Used to create and identify your Givore account
  • Display Name: Used to personalize your profile within the App
  • Profile Picture: Used to display your avatar in the App (optional)

We only request the minimum data necessary to provide our services. We do not request access to your Google contacts, calendar, drive, or any other Google services.

5.2 Google API Services User Data Policy Compliance

Givore's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, we commit to the following:

  • We only use Google user data for the purposes described in this Privacy Policy
  • We do not transfer Google user data to third parties except as necessary to provide or improve our services, comply with applicable laws, or as part of a merger or acquisition
  • We do not use Google user data for serving advertisements
  • We do not allow humans to read Google user data unless we have your affirmative agreement, it is necessary for security purposes, to comply with applicable law, or our use is limited to internal operations

5.3 Apple Sign-In Data

When you choose to sign in with Apple on iOS, we receive the following data from Apple, governed by the Apple Developer Agreement and Apple's Sign in with Apple privacy commitments:

  • Apple user identifier: A unique, per-app pseudonymous identifier used to create and identify your Givore account
  • Email address: Either your real Apple ID email or a private relay address that Apple generates and forwards to us. We treat the relay address identically to a real email and never attempt to resolve it
  • Name: Provided by Apple only on the first sign-in; not requested again afterwards

We only request the minimum scopes required to create your account. Apple Sign-In data is retained for as long as your Givore account exists and is deleted within 30 days of account deletion or upon revocation of Sign in with Apple via your Apple ID settings.

You can manage or revoke Givore's access at any time via Settings → Apple ID → Password & Security → Apps Using Apple ID on your iOS device.

6. Data Sharing and Third Parties

We work with two categories of third-party service providers: App-data processors, which process data you generate when using the Givore app, and Marketing-channel processors, which process data only from interactions with Givore's social-media accounts and website analytics. The full canonical registry, with jurisdiction, data scope, and Data Processing Agreement status, is published at givore.com/sub-processors.

6.A App-data processors (processing your Givore app data)

6.1 Google Analytics

We use Google Analytics to analyze App and website usage and performance. Google Analytics may collect information such as how often users visit the App, what features they use, and device information. Google's ability to use and share information collected by Google Analytics is restricted by the Google Analytics Terms of Service and Google Privacy Policy. Google Analytics is loaded only after you accept the cookie consent banner.

6.2 PostHog

We use PostHog for product analytics to understand how users interact with our features. Data is processed in the European Union (eu.i.posthog.com). Person profiles are created for identified users only. On the mobile App, PostHog session replay may record your interactions with the screen, including text you type into fields, to help us diagnose usability problems. PostHog's use of data is governed by its privacy policy.

6.3 Firebase Crashlytics & Firebase Cloud Messaging (FCM)

We use Firebase Crashlytics to collect anonymized crash reports from the mobile App, including device type, operating system version, and crash diagnostics. No personal identifiers are sent to Crashlytics. We also use Firebase Cloud Messaging to deliver push notifications; FCM stores a device push token until the device unregisters or you delete the App.

6.4 Sentry

We use Sentry for error monitoring and performance tracking. Sentry is configured for EU data residency (Frankfurt region) and collects error and performance telemetry from the App. On the website, error reports sent to Sentry may include personal identifiers associated with your session (for example, your account identifier or your IP address) to help us diagnose the problem.

6.5 Hostinger

We use Hostinger as our hosting provider for the API and database that power the Givore App. All personal data you submit (profile information, posts, messages, images) is processed and stored at rest on Hostinger infrastructure in the European Union.

6.6 Cloudflare & Cloudflare R2

We use Cloudflare for CDN, DNS, TLS termination, and WAF protection across givore.com, api.givore.com, app.givore.com, cdn.givore.com, and ws.givore.com. User-uploaded media (avatars, post images) is stored in Cloudflare R2 object storage in the EU jurisdiction.

6.7 Google OAuth & Apple Sign-In

When you sign in with Google or Apple, those providers transmit identifying information (email/relay address, name, profile picture in Google's case, pseudonymous user ID in Apple's case) to Givore as described in §5. Google and Apple are independent controllers for their own platforms; the data exchange is governed by Google's and Apple's privacy policies as well as this Policy.

6.8 OpenAI (AI-assisted features)

Some Givore features can use AI, provided by OpenAI. These features are optional and are currently switched off. When a feature is enabled and you use it, the content you submit for that feature is sent to OpenAI to produce the result. OpenAI processes this data in the United States under the Standard Contractual Clauses. When we enable these features, we will require OpenAI, by contract, not to train its models on this content and to minimise how long it is kept. A fuller description of each AI feature is in section 6.E below.

6.9 User Interaction Data

We collect non-anonymized interaction data linked to your user account, including views of posts, ideas, comments, and profiles, as well as clicks, saves, and other interactions within the App. This data is stored on our own servers and is not shared with third parties. It is used to improve the App experience and content relevance. This data is retained until you request its deletion through our data removal process.

6.10 Subscription billing (Givore Premium)

When Givore Premium becomes available, purchases are made through the Apple App Store and Google Play, which act as the sellers of record: they take your payment directly and are independent controllers of your payment data under their own privacy policies. Givore never receives or stores your card or payment details. To manage entitlements (to know whether your account has an active subscription), we use RevenueCat, Inc. (United States) as a processor acting on our behalf. It processes subscription events, transaction identifiers, and entitlement status linked to your account. This transfer to the United States is covered by the Standard Contractual Clauses. We process this data to provide the subscription you purchase (Art. 6(1)(b) GDPR, performance of a contract).

6.B Marketing-channel processors (NOT processing your Givore app data)

The following providers process data only from public marketing channels (the givore.com website, Givore's social-media accounts) and do not receive personal data from your Givore app account.

6.11 Metricool

We use Metricool (a Spanish vendor, governed by Spanish RGPD) for website-traffic analytics on givore.com and for analytics and publishing on Givore's Instagram, TikTok, Facebook, and YouTube accounts. Metricool does not have access to your Givore app account or user-generated content from the App.

6.12 ManyChat

We use ManyChat to manage inbound messages received on Givore's Instagram, Facebook, and WhatsApp social-media accounts. ManyChat processes only the messages and follower data of people who voluntarily message Givore on those platforms; it has no connection to your Givore app account and does not receive any data from the App.

6.C AI Crawler & LLM Access to Public Content

Public content on givore.com (marketing pages, guides, blog posts, city pages) and public, non-private content surfaces of app.givore.com (public posts, public profiles) is intentionally accessible to AI search and training crawlers (ChatGPT, Perplexity, Claude, Gemini and similar services). This serves Givore's discoverability in AI-powered search experiences.

Private content is excluded from this access: chats, drafts, hidden profiles, draft posts, private messages, reservations, notifications, support tickets, search alerts, and any content served behind authentication. User personally identifiable information (email addresses, phone numbers, location data) is never made available to AI crawlers or shared with AI training partners. Our crawler authorisation scope and exclusions are published at givore.com/llms.txt.

6.D Other Disclosure Circumstances

We may also disclose your information:

  • To comply with legal obligations
  • To protect our rights, privacy, safety, or property
  • In connection with a merger, sale, or acquisition of all or part of our business
  • With your explicit consent

6.E AI Features & Automated Processing

We use one AI provider: OpenAI (based in the US). Some features send content to OpenAI to work. The features below are optional and may be turned off; some are not switched on yet. When a feature is on and you use it, this is what happens.

The AI features and what data is sent

Idea suggestions from your posts. When you ask for ideas, we send your post's title, description and photos to OpenAI. It uses them to suggest reuse or upcycling ideas and to create an illustration.

Draft replies in support chat. To help our team answer you faster, the last few messages of a support conversation may be sent to OpenAI to draft a suggested reply. A person on our team always reviews and sends the final message — the AI never sends anything to you on its own.

Automatic content checks (moderation). Content you post may be checked automatically to help approve it faster or to flag posts that break the rules.

We do not use your content to train AI

Content sent to OpenAI to run a feature is not used to train its models. It is used only to run the specific feature you used, and nothing more.

Sending data outside the EU

When these features are enabled, OpenAI processes this data in the United States. We rely on the Standard Contractual Clauses approved for international transfers, and we will require OpenAI, by contract, not to train its models on your data and to minimise how long it is kept.

Automatic decisions and your right to a human review

Some accounts may be automatically suspended or banned by an automatic anti-spam and anti-scam system, without a person checking first.

If this happens to you, you can contact us at [email protected] to ask a real person to look at the decision again. A person on our team will review it again; you can explain your side and challenge the decision. Where we notify you of the reason, we will do so by email.

We only use automatic banning where the law allows it. You always have the right to ask for a human review, to give your point of view, and to contest the outcome.

Questions about AI features

Questions about AI features or a decision about your account? Contact us at [email protected].

7. Cookies and Tracking Technologies

Our website uses cookies and local storage to enhance your experience:

  • Essential cookies and local storage: Required for the site to work — for example, remembering your language and your cookie choice. These are always on and do not require consent.
  • Analytics cookies: Off by default. They load only if you choose to allow them in our cookie banner, and they enable Google Analytics, PostHog, and Metricool to collect anonymized website usage data.
  • Newsletter token: If you subscribe to our newsletter, a subscription token is stored locally in your browser.

Our banner lets you accept all, reject all (just as easily), or choose per category. You can change or withdraw your choice at any time using the "Cookie preferences" control shown at the bottom of the page. If you reject analytics cookies, those services are not loaded.

8. Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

9. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. When your information is no longer needed, we will securely delete or anonymize it.

9.1 Retention Periods

  • Account Information: Retained for the duration of your account's existence and up to 30 days after account deletion
  • Google OAuth Data: Retained only while your account is active; deleted within 30 days of account deletion or upon revocation of Google access
  • Posts and Content: Retained until you delete them or delete your account
  • Location Data: Retained for 12 months for service improvement, then anonymized or deleted
  • Analytics Data: Retained in aggregated, anonymized form for up to 26 months
  • Communication Records: Retained for 90 days after the last message in a conversation
  • User Interaction Data (Impressions): Retained until you request deletion through our data removal process
  • Crash and Error Logs: Retained per Crashlytics and Sentry default policies (typically 90 days)
  • Newsletter Subscription: Retained until you unsubscribe

9.2 Google Account Data

If you signed in with Google, you can revoke Givore's access to your Google account data at any time through your Google Account permissions. Upon revocation, we will delete your Google-provided data within 30 days, though your Givore account may remain active with limited functionality.

10. Your Rights

Depending on your location, you may have the following rights regarding your personal information:

  • Access: Request access to your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your personal data
  • Objection: Object to processing of your personal data
  • Data Portability: Request transfer of your data to another service
  • Withdraw Consent: Withdraw consent where processing is based on consent
  • Lodge a Complaint: Lodge a complaint with a supervisory authority, in particular the Spanish Data Protection Agency (AEPD, www.aepd.es) or the authority of your place of residence

To exercise these rights, please contact us at [email protected].

11. Children's Privacy

The App is not intended for children under the age of 14 (the minimum age of digital consent in Spain) or under the applicable age of digital consent in your country of residence, if higher. We do not knowingly collect personal information from children below that age. If you are a parent or guardian and believe your child has provided us with personal information, please contact us, and we will delete such information from our systems.

12. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. Where we transfer personal data outside the European Economic Area (for example, to providers in the United States as described in section 6), we rely on safeguards approved under EU law: primarily the European Commission's Standard Contractual Clauses, or an adequacy decision where one exists.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy within the App and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.

14. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:

  • Email: [email protected]
  • Data Controller: Karol Dąbrowski (autónomo), Valencia, Spain

15. Consent

By using the Givore App, you consent to this Privacy Policy and agree to its terms.