Legal
Privacy policy
Last updated: 8 September 2026 · Effective date: 8 September 2026
This Privacy Policy describes how Summoner ("we", "our", or "us") collects, uses, and protects your personal data when you use the Summoner mobile application and the website summoner-app.com (collectively, the "Service"). We are committed to processing your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Bulgarian data protection law.
Data controller: Aleksandar Ivanov Ivanov, trading as Vaultpoint Labs / Vaultpoint Social, operator of the Summoner service.
97 Sveti Patriarh Evtimiy Blvd., Tsentar, 6000 Stara Zagora, Bulgaria
Email: support@vaultpointlabs.com · Website: summoner-app.com · Full provider details: Legal notice
1. Data we collect
1.1 Account Data
When you register, we collect:
- Email address - used for authentication and account recovery.
- Phone number - collected after OTP verification. Stored in hashed form (using a one-way hash of your normalised number) in a server-side lookup table. The plaintext number is stored only in your private account record, accessible solely by you.
- Username - the display name you choose.
- Profile avatar - an image you upload voluntarily.
1.2 Content You Create
- Circle messages and photos - stored on our cloud infrastructure.
- Private messages - stored as end-to-end encrypted ciphertext. We cannot read the content of private messages. Your encryption keys are generated on your device and never transmitted to our servers.
- Summons - including activity description, duration, and the geographic coordinates you choose to share.
- Public content (Discover) - public Summons, communities, and the messages you post in public Summon or community chats. This content is publicly readable (or readable by community members) and is NOT end-to-end encrypted: unlike private messages, we can access it and moderate it. It includes your username, avatar, the text/photos you post, tags, and (for public Summons) an approximate location.
1.3 Location Data
- Summon locations - coordinates you select for a Summon. For public Summons, the exact point is never published: it is offset to an approximate area before storage, and the precise coordinate is shared only with the host and confirmed attendees.
- Live device location - used to find Summons near you when you open the public discovery feed, to confirm you are inside a region-based community's area at the moment you join it, and, once you have said you are going to a Summon, to work out how far you still have to travel to reach it (see Google Maps Platform in section 4). We do not store a persistent "home area" for you; each of these uses your location at the time of the action. What is stored is a single road distance in metres, with no coordinates and no route. It is a reading from the moment you last opened that Summon, not a live position, and it is deleted 30 minutes after it was taken, or as soon as the Summon ends, whichever comes first.
- Community region - if you create a local community, the centre point and radius you choose are stored as part of that community's public profile.
1.4 Public Reputation
For Discover, we maintain a small, publicly visible count of how many public Summons you have hosted and attended (credited only when an event completes). These counts and the badges derived from them are shown on your public profile to help other users decide whether to join.
1.5 Technical & Usage Data
- Push notification token - a device token used to deliver push notifications. Stored privately and never exposed to other users.
- Last activity timestamps - used to sort circles and determine notification eligibility.
- Standard server logs generated by our cloud infrastructure (IP address, device type, request timestamps). These are processed by our infrastructure provider under their own terms.
1.6 Contacts (Optional)
If you grant the READ_CONTACTS permission, your device contacts' phone numbers are normalised to E.164 format and hashed client-side. Only the hashes are transmitted to our servers to identify mutual connections. Raw phone numbers from your contacts are never sent to or stored by us.
2. Legal basis for processing
We process your personal data on the following legal bases under Article 6 GDPR:
- Contract performance (Art. 6(1)(b)) - processing necessary to provide the Service you signed up for (account creation, messaging, Summons).
- Consent (Art. 6(1)(a)) - for optional features such as contact matching and push notifications. You may withdraw consent at any time in the app settings.
- Legitimate interests (Art. 6(1)(f)) - for security, fraud prevention, and service improvement, where our interests are not overridden by your rights.
- Legal obligation (Art. 6(1)(c)) - where required by applicable law.
3. How we use your data
- To create and maintain your account.
- To enable real-time messaging, Summons, and social features within the app.
- To deliver push notifications for messages, Summons, and friend requests.
- To power public discovery - showing nearby public Summons and communities based on your current location, and confirming you are within a region-based community's area when you join it.
- To moderate public content for safety (automated image scanning and prohibited-term checks) and to act on user reports.
- To allow optional contact-based friend discovery.
- To enforce our Terms of Service and prevent abuse.
- To operate and maintain the technical infrastructure of the Service.
We do not sell your personal data. We do not use your data for advertising profiling.
3.1 Automated processing in moderation
Some safety measures run without a person looking first, and Article 13(2)(f) GDPR requires us to tell you which:
- Image scanning. Images destined for public places - avatars, circle and community icons and covers, public Summon cover photos, and photos and video thumbnails in community chat - are checked by Google Cloud Vision SafeSearch before publication. A flagged image is refused. The image is not published; nothing else about your account changes.
- Prohibited-term checks. Text entered when creating public Summons and communities is matched against a blocklist and can be refused at the point of creation.
- Report thresholds. A public Summon reported by three or more separate people is hidden from Discover pending review, and an account reported by five or more separate people is flagged for us to look at. Hiding is reversible and flagging is only a queue for human attention.
No penalty against your account is ever applied automatically. Warnings, restrictions on Discover, suspensions and bans are decided by a person, every time, and deliberately so: an automatic ban driven by report counts could be triggered by a handful of accounts acting together, which would make the safety system into a weapon. Automated steps can hide a piece of content or refuse an upload; only a human decision reaches your account.
Because of this, we do not carry out decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. If content of yours is refused or hidden and you believe it was wrong, write to support@vaultpointlabs.com and a person will review it.
4. Data sharing & third parties
We use the following third-party processors, each bound by data processing agreements:
- Cloud infrastructure provider - authentication, database, file storage, push notifications, and hosting. Data may be stored on servers within the EU or the United States under Standard Contractual Clauses approved by the European Commission.
- Google Maps Platform - maps, place search, travel-distance lookups and address lookup. Specifically: the coordinates for any map we draw (for public Summons that is the approximate offset area, unless you are the host or a confirmed attendee); what you type into a place-search box; when you have said you are going to a Summon, your current device location and the meeting point, sent to the Directions service to measure the road distance between them; and, when a public Summon is created, its exact coordinate, sent to the Places and Geocoding services so our server can size the blur area and name the surrounding neighbourhood. That last exchange happens on our server, and the exact coordinate is still never published to other users.
- Google Cloud Vision (SafeSearch) - avatars, circle and community icons and covers, public Summon cover photos, and photos and video thumbnails posted in community chat are sent to Google's image-moderation service before they are published. An image we cannot check is not published. Images are checked transiently for this purpose and are not used to build a profile of you.
- OpenStreetMap / Nominatim - not currently in use. The browser version of Summoner is closed while it is rebuilt, and it is the only part of the Service that used OpenStreetMap map tiles and the Nominatim address-search service. If and when it reopens, the coordinates or search terms involved would be processed under OpenStreetMap's privacy terms, and we will say so here without the caveat.
- Resend - used to deliver transactional and abuse-report emails to us; the contents of a report (and the reporter's email) are processed to handle the report.
- Firebase Crashlytics (Google) - crash reporting for the mobile app only, described in section 10. Crash reports are processed by Google on our behalf. Firebase Analytics was removed in version 1.0.5 and is no longer present.
- Fonts and styles - none. The fonts our pages use are served from our own servers, so opening a page does not disclose your IP address to a font CDN. We load no third-party stylesheet or script libraries on the website at all.
We do not share your data with any other third parties except where required by law or a court order, in which case we will notify you to the extent permitted by law.
5. Data retention
- Account data - retained for as long as your account is active.
- Messages - retained until you or the other participant deletes the conversation.
- Summons - auto-expired and deleted within 5 minutes of expiry by our Cloud Function.
- Public Summons - marked ended at expiry and their cover photos deleted; a host may cancel or delete a public Summon at any time, which also removes its attendees, chat, and exact location.
- Communities - retained while active; deleting a community removes its members, chat, and icon. Public reputation counts persist with your account.
- Abuse reports - reports you submit are retained to investigate and act on them and to keep records of safety enforcement.
- Account deletion - when you delete your account, your authentication entry, profile, circle memberships, and social connections are removed via an automated cascade. You can do this yourself in the app, or ask us to; how to delete your account sets out both routes and exactly what is and is not removed. Encrypted private message history may be retained in read-only form for the other participant with a clear "account deleted" indicator.
- Backups - residual data may remain in infrastructure backups for up to 30 days after deletion.
6. Your rights under GDPR
As a data subject in the EU, you have the following rights:
- Right of access (Art. 15) - request a copy of the personal data we hold about you.
- Right to rectification (Art. 16) - request correction of inaccurate data.
- Right to erasure (Art. 17) - request deletion of your personal data ("right to be forgotten"). You may delete your account directly from the app, which triggers an automated erasure cascade; see how to delete your account, including what to do if you can no longer open the app.
- Right to restriction (Art. 18) - request that we restrict processing of your data in certain circumstances.
- Right to data portability (Art. 20) - request your data in a structured, machine-readable format.
- Right to object (Art. 21) - object to processing based on legitimate interests.
- Right to withdraw consent - withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at support@vaultpointlabs.com. We will respond within 30 days. You also have the right to lodge a complaint with the Commission for Personal Data Protection of Bulgaria (CPDP) at www.cpdp.bg.
7. Security
We implement industry-standard technical and organisational measures to protect your data:
- Private messages are end-to-end encrypted. Keys are generated and stored on your device, protected by biometric authentication. Our servers receive only encrypted data and have no means to decrypt it.
- All data in transit is encrypted via TLS.
- Access controls restrict each user's data strictly to their authenticated identity.
- Push notification tokens and phone numbers are stored in private records inaccessible to other users.
No system is 100% secure. In the event of a personal data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by Art. 33-34 GDPR.
8. Children's privacy
The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, contact us immediately at support@vaultpointlabs.com and we will delete it promptly.
The public, real-world-meetup features (Discover) are restricted to users 18 and over; you must confirm you are 18+ before using them.
9. International transfers
Some of our processors are established outside the European Economic Area (EEA) or operate infrastructure there, including in the United States:
- Google LLC - cloud infrastructure, Maps Platform and Cloud Vision. Our database is configured to the European multi-region, but Google's platform services may process data in the United States.
- Resend - transactional and abuse-report email delivery, processed in the United States.
These transfers are safeguarded by Standard Contractual Clauses (SCCs) approved by the European Commission, as part of each provider's data processing agreement. You may request a copy of the applicable transfer mechanisms by contacting us.
10. Cookies & tracking
The website sets no cookies and runs no analytics. There is no analytics package, tag manager, advertising pixel, session recorder or A/B testing tool on summoner-app.com. We do not track you across sites. There is nothing on the website to consent to, which is why you are not asked.
The app runs no analytics either. Earlier versions included Google's Firebase Analytics, which switched itself on by being present and recorded automatic events - first opens, session starts, screen views - against a pseudonymous app-instance identifier. We never asked it for anything and never used it, so we removed it. From version 1.0.5 onward it is not in the app at all, and neither is the advertising-identifier permission it brought with it.
One Google SDK remains, and it only reports on the app itself rather than on you:
- Firebase Crashlytics - when the app crashes, it sends us the crash: the stack trace, the device model, the operating system version and the state of the app at that moment, against its own installation identifier. It is what tells us something is broken for real people rather than only on our own phone. It is switched off entirely in development builds.
It is not used to build a profile of you, it is not shared with advertisers, and it cannot read your messages. It is listed as a processor in section 4.
In full, this is everything the website stores in your browser:
- Nothing. The pages you can currently reach - the home page, this policy, the terms, the legal notice, the child safety standards, the contact page and a shared Summon page - set no cookies, and write nothing to local storage, session storage or IndexedDB.
The website also loads no third-party resources on its own initiative. Typography is served from our own domain rather than from a font CDN, so opening a page does not tell Google, or anyone else, that you did.
The Summoner app stores its settings on your own device (your theme, which chats you have hidden, your notification preferences and your encryption keys). That data stays on the phone and is not a cookie; the encryption keys in particular are never uploaded.
There is exactly one exception, and it only happens if you ask for it. On a shared Summon page (/summon) we can show an embedded Google map of the meeting point. That embed is not loaded until you press "Show map", because loading it would send your IP address and the address of the page you are on to Google. Until you press it, nothing about your visit reaches Google. If you do press it, that request is governed by Google's own Privacy Policy and Google may set cookies on your device. The "Open in Maps" link on the same page is an ordinary link and behaves like any other link you choose to follow.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where required, notify you via email or in-app notification. Continued use of the Service after changes constitutes acceptance of the updated Policy.
12. Contact & data controller
The controller of your personal data under Article 4(7) GDPR, and the provider of the Service, is:
Send privacy questions, requests and complaints to that address or that inbox. Our Legal notice carries the same identity together with our register entry, VAT status and hosting details.