Skip to content

Privacy Policy

What personal data Apperah collects, why, how it's used, and the rights you have.

Effective:
2026-06-29
Last updated:
2026-09-01
Version:
v1.7

1. About this Privacy Policy

This Privacy Policy explains how Apperah processes your personal data. It applies to Apperah’s mobile app, the website at apperah.com, and related services.

This Policy is separate from our Terms of Service. Acceptance of the Terms is not a condition for the rights described here.

Effective date and changes: this Policy takes effect on the date stated above. For material changes, we provide notice in the app and by email in advance of the change taking effect, and we maintain an archive of previous versions.

2. Who we are and how to contact us

Data Controller Apperah Aksjeselskap (Norwegian AS — registered in Norway)
Registered office Flintoes gate 4, 0361 Oslo, Norway
Privacy contact privacy@apperah.com
Rights requests by email to privacy@apperah.com

Complaints and supervisory authorities: you have the right to lodge a complaint with a data protection authority. In the EU/EEA, our lead supervisory authority is Datatilsynet (Norway) under the GDPR one-stop-shop mechanism; you may also complain to the authority in your own country. Elsewhere, you may complain to your local authority.

Where local law requires us to appoint a data protection officer or a local representative before we operate in a country, we do so and publish their contact details in that country’s supplement.

3. What data we process, why, and on what lawful basis

We handle three broad kinds of information:

  • Information you give us — when you create an account and profile, create or join activities, message people, share photos and posts, choose to share your location, or connect a calendar.
  • Information from your use of Apperah — how you use the app, and device and log data (for security and crash reports), including approximate location for things like showing nearby places.
  • Information from other sources — public information we use to build our places-and-events directory (see §4), and the sign-in provider you choose if you use social sign-in.

Here is what we use each broad category for, and our legal basis:

Category of data Why we use it Legal basis
Account and profile — name, email, hashed password, date of birth (age checks), optional phone Create and operate your account; keep it secure Contract; legitimate interest (security)
Your activity — activities you create or join, your connections, messages, orders you place with a venue through the app, and what you share Provide the core service Contract
Location — only when you choose to share it, plus approximate area Features you turn on (coordination, nearby places); service localisation Consent — you opt in each time you share live location; legitimate interest (approximate area)
Content you connect — a calendar you link Provide the feature you request Consent — per connection, withdrawn by disconnecting
Usage and device data — device and security log data; crash reports and basic performance timings (always on — service integrity, no name or email); and, only if you opt in, usage analytics tied to your account ID Keep Apperah secure, stable, and working (logs, crash and performance data); understand how the app is used so we can improve it (analytics) Legitimate interest (security, service logs, crash and performance data); consent (analytics — off by default, withdraw anytime)
Public and directory data — public information about places and events Build and improve an accurate places directory and search Legitimate interest (see §4 and §14)

Apperah does not collect location data in the background. Location is processed only when you actively share it or use a feature that requires approximate location.

4. Where we get your data

We obtain data:

  • From you — when you sign up, create plans, share content, or connect your calendar
  • From your device — IP address, device identifier (for crash reports), push notification token, app version
  • From other sources (limited):
    • A calendar provider (Google Calendar) if you connect one
    • Public sources, for our places-and-events directory (see §4.1)
    • A sign-in provider — Meta (Facebook), Google, or Apple — if you use social sign-in

We do not buy data from data brokers.

When a search in the app finds no results, we log the search text and the town or area it was made in — without any link to you or your account — so we know where our directory needs improving. These logs are deleted automatically after 60 days.

4.1 Information we obtain from other sources (Article 14)

Some information we hold was not provided by you directly — for example, public information about a venue, or a publicly listed business contact, gathered to build our places-and-events directory. Under GDPR Article 14, we provide the following information:

  • Categories of data: business/venue details and, where individuals are identifiable (for example, a sole trader’s publicly listed name or contact details), limited personal data.
  • Sources: open data — OpenStreetMap (ODbL), Overture Maps (CDLA), and Wikidata (CC0) — and public-facing venue websites. See our Data Sources & Attribution page.
  • Purpose and legal basis: to build and maintain an accurate directory and improve search — our legitimate interests (Art. 6(1)(f)), balanced against your rights.
  • Your rights: you can access, correct, or object to this processing — and if it’s your business, you can claim the place to manage it.

5. Who we share your data with

We share data with service providers that help us run Apperah, described here by category of service. We require each one to operate under a data-processing agreement and to use your data only on our instructions.

Category of provider What they do Where they process
AI providers Extract public event information, draft venue descriptions, and import venue menus; run an automated safety review of public event listings users submit (text and images) and of photos on Open Invites; power semantic search (search uses public venue text only); and provide AI features you actively use — generating a trip itinerary or checklist in a group, reading a schedule photo you choose to scan, translating user-written content when you ask, and replying in the in-app feedback conversation EEA and US, with safeguards
Email and push delivery Send transactional emails and deliver push notifications (push is relayed through your device platform) US
Cloud hosting Hosting, databases, media storage and delivery, and caching EEA
Error diagnostics Crash and error monitoring to keep the app stable (always on — personal data scrubbed) EEA / US
App performance telemetry App-startup and screen timings so we can find slowdowns (always on — no name or email) US
Product analytics (only if you opt in) Usage analytics tied to your account ID — never your name or email; no session recording EU
Maps and geocoding Map rendering and turning addresses into coordinates EEA / US
Social sign-in (only if you choose it) Lets you sign in with your existing Google, Apple, or Facebook account US

We keep our Service Providers page up to date as our providers change.

Venues you order from. Where a claimed venue offers in-app ordering, placing an order shares the order details (items, amounts, requested pickup time) and your account identity with that venue so it can fulfil the order.

We do not sell your personal data. We do not share it for cross-context behavioural advertising (see Your Privacy Choices for US-state specifics).

We may also disclose data:

  • To law enforcement on valid legal process (we challenge overbroad requests; see our Law Enforcement Request Policy)
  • To enforce our Terms or protect users (for example, to detect and report child sexual abuse material to NCMEC and Kripos)
  • In a corporate transaction (merger, acquisition, restructuring) — with continued protection

6. Where your data goes (cross-border transfers)

Apperah is headquartered in Norway (EEA). When your data goes outside the EEA — primarily to our US-based processors — we use:

  • EU-US Data Privacy Framework (DPF) where the processor is DPF-certified
  • EU Standard Contractual Clauses (Module 2) as a fallback
  • UK Addendum for UK-source data
  • Swiss SCCs for Swiss-source data
  • ANPD SCCs for Brazilian-source data

Where data goes outside the EEA, we also apply appropriate additional safeguards to protect it.

7. How long we keep your data

We keep personal data only as long as we need it for the purposes in this Policy, then delete or anonymise it. How long that is depends on the type of data and why we hold it:

  • Account, profile, plans, and social activity — while your account is active; deleted or anonymised after you close it (with a short grace period in case you change your mind).
  • Messages — your conversation history is kept while your account is active; messages you delete are removed within 30 days. When you delete your account, the messages you sent are deleted.
  • Location — kept only while you’re actively sharing.
  • Security and anti-fraud logs — kept for a limited period for security and abuse-prevention.

When you delete your account, we delete or anonymise your personal data within 30 days, except records the law requires us to keep — which we retain (anonymised where possible) only for the statutory minimum.

8. Your rights

Under the GDPR and equivalent laws, you have the following rights:

Right What it means How to use it
Access A copy of the personal data we hold about you In-app: Settings > Your data > Export my data
Rectification Correct inaccurate or incomplete data In-app: Settings > Edit profile
Erasure (“right to be forgotten”) Delete your account and data In-app: Settings > Your data > Delete my account
Restriction Limit how we use your data while a dispute is resolved In-app: Settings > Your data > Freeze account — or contact us
Portability Take your data to another service in a structured format In-app: Settings > Your data > Export my data
Object Object to processing based on legitimate interest (e.g., personalised recommendations, discoverability) In-app: Settings > Data & personalization and Settings > Discoverability — or contact us
Withdraw consent Withdraw any consent you’ve given (e.g., analytics) In-app: Settings > Data & personalization (with a consent-history audit trail)
Complain to a regulator Lodge a complaint with your data protection authority See §2 (supervisory authorities)

We respond to rights requests within 1 month (GDPR Art. 12(3)) — extendable by 2 months for complex requests with notice.

We verify your identity before processing requests. For account-tied requests, in-app authentication is sufficient.

9. How we work to protect your data

Our security measures include:

  • Encryption in transit (TLS) for your data, and encryption at rest for stored media and backups — and additionally for your messages, any calendar connection, and two-factor authentication secrets, each with dedicated keys
  • Access controls: role-based and least-privilege, with regular access reviews
  • Security logging and monitoring of authentication and sensitive-data access
  • Independent security assessments of our providers (e.g., SOC 2 / ISO 27001)
  • A vulnerability disclosure programme — see our Vulnerability Disclosure Policy

No method of transmission over the internet or electronic storage is completely secure. While we use reasonable technical and organisational measures to protect your data, we cannot guarantee absolute security.

We notify regulators within 72 hours of any personal data breach with risk to your rights (per GDPR Art. 33). We notify you directly if there’s a high risk to your rights (Art. 34).

10. Automated decision-making

We do not make decisions about you that have legal or similarly significant effect based solely on automated processing (GDPR Art. 22).

We personalise your home feed using signals such as the interests you choose, your friends and the businesses you follow, and the kinds of places you have recently engaged with (a rolling ~90-day window). This ranking only affects the order of what you see — it does not affect your account access, pricing, or service quality — and you can turn it off at any time (Settings > Data & personalization > AI Recommendations), which switches your feed to a location-and-recency order. Beyond this, we do not build behavioural profiles of you and do not use your behaviour for advertising. Our optional usage analytics (see §12) are used only in aggregate to understand how features are used, and you can withdraw from them at any time.

Our AI features (such as event extraction and venue descriptions) produce outputs that can be reviewed and corrected. AI is not the final decision-maker for anything that affects you.

11. AI features and transparency (EU AI Act Art. 50)

We use AI to provide certain features:

  • AI-generated labelling — AI-generated content such as event and venue descriptions carries a clear “AI-generated” label in the app (EU AI Act Art. 50).
  • AI features you choose to use — some features send data to an AI provider only when you use them: generating a trip itinerary or packing checklist in a group, scanning a photo of a schedule to add its entries to your calendar, translating user-written content when you tap translate, and the feedback conversation in Messages, where an AI assistant may reply before our team follows up.
  • We use third-party AI providers under contract (described by category in §5 above)
  • We require AI providers, under contract, not to use your personal data to train their general models
  • You can turn off AI-personalised recommendations in Settings > Data & personalization > AI Recommendations
  • Public event listings submitted by users, and photos added to Open Invites, go through an automated AI safety review before they are shown (see §5) — this safety check is part of running the service and cannot be switched off

More: AI Ethics Policy.

12. Cookies and tracking technologies

We use cookies and similar trackers on apperah.com (web) and equivalent mechanisms in the mobile app. Details and your consent choices: Cookie Policy.

The categories are:

  • Strictly necessary (always on): auth session, CSRF token, mobile keystore
  • Service integrity (always on): crash reports and basic performance timings, so we can find crashes and slowdowns — no name or email, never used for advertising
  • Functional (opt-in): language preference, theme
  • Analytics (opt-in): usage analytics through an EU-hosted provider, tied to your account ID (never your name or email)
  • Advertising: we don’t deploy advertising trackers

In jurisdictions requiring banner-based consent (EU/EEA, UK, others), the mobile app shows a consent banner on first use, and you can change your choices anytime in Settings > Data & personalization. Our website (apperah.com) currently sets no optional trackers at all, so it shows no cookie banner.

When you follow a link out of Apperah — for example to a ticket seller — the destination site may set its own cookies under its own policies, including, for partner links, a cookie that attributes your visit to Apperah (we may earn a commission on a purchase; this never changes what you pay). See our Cookie Policy for details.

13. Children’s privacy

Apperah is not directed at young children. Our minimum sign-up age is 16 everywhere today. We are introducing per-country minimum ages aligned to each country’s digital-consent age under the GDPR (which ranges from 13 to 16 in the EU/EEA — for example 16 in Germany, 15 in France, 14 in Spain, 13 in Norway and Sweden), with a few countries requiring you to be 18 or to have a parent’s or guardian’s consent (for example India, South Africa, and Brazil). Until that country-by-country tailoring is in place, the 16 minimum applies to everyone. The exact minimum for your country, once tailored, is set out in the country supplement.

If you believe a child under our applicable age is using Apperah, please contact us. We act on actual-knowledge reports under our Youth Safety framework.

14. Special categories of data

Some data we process can reveal “special category” information by inference (GDPR Art. 9). Examples:

  • Location patterns may reveal religious, health, political, or sexual-orientation visits
  • Calendar events may reveal medical appointments, worship, or political activity

We apply heightened safeguards to such data: minimised collection, short retention, and restricted access.

We do not infer or assign special-category labels to you.

15. Higher-risk features

For features that involve more sensitive data, we carry out data-protection assessments and apply extra safeguards such as data minimisation, tighter access controls, and short retention. You can ask us about the assessment for a specific feature.

Public communities. If you join a public community, your membership and your participation (for example, that you are going to an event) may be visible to other members and discoverable. Who sees that you’re going: by default, your attendance on public events is visible to your friends and mutual connections; in your settings you can narrow this to friends only, or hide it entirely. The setting is reciprocal — what you choose to show is also what is shown to you about others. For some community processing (member directories, community analytics), Apperah and the community’s organiser may be joint controllers under GDPR Article 26; the split of responsibilities is described in the Community Group Organizer Terms.

Memories. When you post a Memory, we process the photos and videos and any caption, the people you tag, and — if you add one — the location you type or the map pin you drop. You choose who can see each Memory: your friends, close friends, selected people, only you, or any Apperah user (public) — public Memories can be seen by anyone signed in to Apperah, including via shared links. People you tag can also see the Memory, whatever visibility you chose, and if you tag a group, its members can see it too — for as long as they are members: someone who leaves the group loses that access, someone who joins later gains it. When you are tagged in someone else’s Memory, it appears on your own profile only if you approve the tag, and you can remove the tag at any time. If the author allows it, tagged people can add their own photos or videos to the Memory (their contributions stay linked to their account and are unlinked if they delete it). A Memory can also be hosted in a group you’re part of, where it follows that group’s visibility. We remove hidden technical data (such as GPS tags) from photos when they are uploaded. We process this on the basis of your consent (and our legitimate interest for people incidentally pictured), and your Memories are deleted or anonymised when you delete them or close your account.

Followers. Alongside mutual friendships, you can follow other people and others can follow you (a one-directional connection). Following doesn’t need approval, and there are no private accounts — anyone signed in can follow you. We keep your follower and following lists and counts, and these are visible to every signed-in Apperah user; there is currently no setting to hide them. If you turn on notifications, someone may be told when they gain a new follower. You can unfollow at any time, and you can block someone to remove and prevent their follow. When you close your account, your profile is anonymised and deactivated, so your follow connections no longer appear to you or to others.

Public events you register. If you register a public event in the directory (see our Events & Hosting Policy), the event page shows you as its creator — your name, username, and profile photo — together with overall attendance counts. Public event pages are part of the open directory and can be viewed on the web without an Apperah account. Registering a public event is your choice; deleting the event removes the page.

16. Marketing communications

We do not currently send marketing email. Communications from us are transactional (account, security, plan-related notifications) or service-utility (for example, reminders for plans you have created).

If we introduce marketing communications, we will:

  • Get your separate opt-in consent
  • Include an easy unsubscribe in every message (one-click)
  • Honour CAN-SPAM (US), ePrivacy (EU), CASL (Canada), and equivalent regimes

17. Data breach response

If we detect a personal data breach:

  1. We investigate immediately and contain the breach
  2. We notify our lead supervisory authority (Datatilsynet, Norway) within 72 hours when there’s a risk to your rights (GDPR Art. 33)
  3. We notify you directly without undue delay if there’s a high risk to your rights (Art. 34)
  4. We publish a summary of significant incidents in our transparency reporting

18. Complaints and dispute resolution

If you have a concern about how we have handled your data:

  1. Contact us at privacy@apperah.com.
  2. You also have the right to complain to your local data protection authority at any time. In the EU/EEA, our lead authority is Datatilsynet (Norway) under the GDPR one-stop-shop mechanism, and your home authority can also receive your complaint. Authorities for other regions are listed in the relevant country supplement.

You also have the right to a judicial remedy in your home jurisdiction.

19. Updates to this Policy

We update this Policy when:

  • We add or change features that affect your data
  • We add new service providers
  • Regulators issue guidance that requires it
  • The law changes

For material changes, we will:

  • Notify you in-app before the change takes effect
  • Email you at the address we have on file
  • State the new version’s effective date prominently
  • Maintain an archive of past versions

For minor edits (typographical corrections, clarifications), we update the effective date without individual notice.

20. Glossary

  • Apperah / “we” / “us”: Apperah Aksjeselskap (Norwegian AS)
  • You / “user”: a person who has an Apperah account
  • Personal data: information that identifies you or could identify you (GDPR Art. 4(1) definition; equivalent in other laws)
  • Processing: any action on personal data — collecting, storing, sharing, using, deleting
  • Controller: the entity that decides why and how personal data is processed (we are the controller for your Apperah account)
  • Processor: a third party that processes data on the controller’s behalf (e.g., a provider that delivers our emails or hosts our data on our behalf)
  • Special category data: GDPR Art. 9 — health, religion, political opinion, sexual orientation, etc.
  • Consent: GDPR Art. 4(11) — freely-given, specific, informed, unambiguous, with affirmative action

Jurisdiction-specific addenda

This Policy is supplemented by jurisdiction-specific addenda where local law requires:

  • California (US-CA) — CCPA / CPRA
  • Quebec (CA-QC) — Loi 25
  • Brazil (BR) — LGPD
  • Korea (KR) — PIPA
  • Japan (JP) — APPI
  • Australia (AU) — Privacy Act 1988
  • Israel (IL) — PPL Amendment 13
  • South Africa (ZA) — POPIA
  • UK (GB) — UK GDPR
  • EU bloc — DPA matrix

Where an addendum says “this addendum prevails” for your jurisdiction, the addendum’s specific rules take precedence over this main Policy.