Legal
Privacy policy
Last updated: 22 June 2026 · Effective date: 22 June 2026
This Privacy Policy describes how Summoner ("we", "our", or "us") collects, uses, and protects your personal data when you use the Summoner mobile application and the website summoner-app.com (collectively, the "Service"). We are committed to processing your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Bulgarian data protection law.
1. Data we collect
1.1 Account Data
When you register, we collect:
- Email address - used for authentication and account recovery.
- Phone number - collected after OTP verification. Stored in hashed form (using a one-way hash of your normalised number) in a server-side lookup table. The plaintext number is stored only in your private account record, accessible solely by you.
- Username - the display name you choose.
- Profile avatar - an image you upload voluntarily.
1.2 Content You Create
- Circle messages and photos - stored on our cloud infrastructure.
- Private messages - stored as end-to-end encrypted ciphertext. We cannot read the content of private messages. Your encryption keys are generated on your device and never transmitted to our servers.
- Summons - including activity description, duration, and the geographic coordinates you choose to share.
- Public content (Discover) - public Summons, communities, and the messages you post in public Summon or community chats. This content is publicly readable (or readable by community members) and is NOT end-to-end encrypted: unlike private messages, we can access it and moderate it. It includes your username, avatar, the text/photos you post, tags, and (for public Summons) an approximate location.
1.3 Location Data
- Summon locations - coordinates you select for a Summon. For public Summons, the exact point is never published: it is offset to an approximate area before storage, and the precise coordinate is shared only with the host and confirmed attendees.
- Live device location - when you open the public discovery feed it is used to find Summons near you, and when you join a region-based community it is used at that moment to confirm you are within the community's area. We do not store a persistent "home area" for you; this check uses your current location at the time of the action.
- Community region - if you create a local community, the centre point and radius you choose are stored as part of that community's public profile.
1.4 Public Reputation
For Discover, we maintain a small, publicly visible count of how many public Summons you have hosted and attended (credited only when an event actually completes). These counts and the badges derived from them are shown on your public profile to help other users decide whether to join.
1.5 Technical & Usage Data
- Push notification token - a device token used to deliver push notifications. Stored privately and never exposed to other users.
- Last activity timestamps - used to sort circles and determine notification eligibility.
- Standard server logs generated by our cloud infrastructure (IP address, device type, request timestamps). These are processed by our infrastructure provider under their own terms.
1.6 Contacts (Optional)
If you grant the READ_CONTACTS permission, your device contacts' phone numbers are normalised to E.164 format and hashed client-side. Only the hashes are transmitted to our servers to identify mutual connections. Raw phone numbers from your contacts are never sent to or stored by us.
2. Legal basis for processing
We process your personal data on the following legal bases under Article 6 GDPR:
- Contract performance (Art. 6(1)(b)) - processing necessary to provide the Service you signed up for (account creation, messaging, Summons).
- Consent (Art. 6(1)(a)) - for optional features such as contact matching and push notifications. You may withdraw consent at any time in the app settings.
- Legitimate interests (Art. 6(1)(f)) - for security, fraud prevention, and service improvement, where our interests are not overridden by your rights.
- Legal obligation (Art. 6(1)(c)) - where required by applicable law.
3. How we use your data
- To create and maintain your account.
- To enable real-time messaging, Summons, and social features within the app.
- To deliver push notifications for messages, Summons, and friend requests.
- To power public discovery - showing nearby public Summons and communities based on your current location, and confirming you are within a region-based community's area when you join it.
- To moderate public content for safety (automated image scanning and prohibited-term checks) and to act on user reports.
- To allow optional contact-based friend discovery.
- To enforce our Terms of Service and prevent abuse.
- To operate and maintain the technical infrastructure of the Service.
We do not sell your personal data. We do not use your data for advertising profiling.
4. Data sharing & third parties
We use the following third-party processors, each bound by data processing agreements:
- Cloud infrastructure provider - authentication, database, file storage, push notifications, and hosting. Data may be stored on servers within the EU or the United States under Standard Contractual Clauses approved by the European Commission.
- Google Maps Platform - used to display location maps on the public Summon share page and map thumbnails/pickers in the app and web app. Only the coordinates relevant to the map shown (for public Summons, the approximate offset area unless you are the host or a confirmed attendee) are passed to Google Maps.
- Google Cloud Vision (SafeSearch) - public Summon cover photos, community icons, and avatars are sent to Google's image-moderation service to detect unsafe content before they are published. Images are checked transiently for this purpose and are not used to build a profile of you.
- OpenStreetMap / Nominatim - the web app uses OpenStreetMap map tiles and the Nominatim service for address search; the coordinates or search terms involved are processed under OpenStreetMap's privacy terms.
- Resend - used to deliver transactional and abuse-report emails to us; the contents of a report (and the reporter's email) are processed to handle the report.
We do not share your data with any other third parties except where required by law or a court order, in which case we will notify you to the extent permitted by law.
5. Data retention
- Account data - retained for as long as your account is active.
- Messages - retained until you or the other participant deletes the conversation.
- Summons - auto-expired and deleted within 5 minutes of expiry by our Cloud Function.
- Public Summons - marked ended at expiry and their cover photos deleted; a host may cancel or delete a public Summon at any time, which also removes its attendees, chat, and exact location.
- Communities - retained while active; deleting a community removes its members, chat, and icon. Public reputation counts persist with your account.
- Abuse reports - reports you submit are retained to investigate and act on them and to keep records of safety enforcement.
- Account deletion - when you delete your account, your authentication entry, profile, circle memberships, and social connections are removed via an automated cascade. Encrypted private message history may be retained in read-only form for the other participant with a clear "account deleted" indicator.
- Backups - residual data may remain in infrastructure backups for up to 30 days after deletion.
6. Your rights under GDPR
As a data subject in the EU, you have the following rights:
- Right of access (Art. 15) - request a copy of the personal data we hold about you.
- Right to rectification (Art. 16) - request correction of inaccurate data.
- Right to erasure (Art. 17) - request deletion of your personal data ("right to be forgotten"). You may delete your account directly from the app, which triggers an automated erasure cascade.
- Right to restriction (Art. 18) - request that we restrict processing of your data in certain circumstances.
- Right to data portability (Art. 20) - request your data in a structured, machine-readable format.
- Right to object (Art. 21) - object to processing based on legitimate interests.
- Right to withdraw consent - withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at support@vaultpointlabs.com. We will respond within 30 days. You also have the right to lodge a complaint with the Commission for Personal Data Protection of Bulgaria (CPDP) at www.cpdp.bg.
7. Security
We implement industry-standard technical and organisational measures to protect your data:
- Private messages are end-to-end encrypted. Keys are generated and stored on your device, protected by biometric authentication. Our servers receive only encrypted data and have no means to decrypt it.
- All data in transit is encrypted via TLS.
- Access controls restrict each user's data strictly to their authenticated identity.
- Push notification tokens and phone numbers are stored in private records inaccessible to other users.
No system is 100% secure. In the event of a personal data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by Art. 33-34 GDPR.
8. Children's privacy
The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, contact us immediately at support@vaultpointlabs.com and we will delete it promptly.
The public, real-world-meetup features (Discover) are restricted to users 18 and over; you must confirm you are 18+ before using them.
9. International transfers
Your data may be processed by Google LLC on servers located outside the European Economic Area (EEA), including in the United States. Such transfers are safeguarded by Standard Contractual Clauses (SCCs) approved by the European Commission, as part of Google's Data Processing Addendum. You may request a copy of the applicable transfer mechanisms by contacting us.
10. Cookies & tracking
The Summoner mobile application does not use cookies. The website summoner-app.com does not use analytics or advertising cookies. The only external resources loaded by the website are Google Fonts (for typography) and Google Maps (only on active Summon share pages), which may set cookies governed by Google's own Privacy Policy.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where required, notify you via email or in-app notification. Continued use of the Service after changes constitutes acceptance of the updated Policy.
12. Contact & data controller
For any privacy-related questions, requests, or complaints: