Legal

Privacy policy

Last updated: 8 September 2026  ·  Effective date: 8 September 2026

This Privacy Policy describes how Summoner ("we", "our", or "us") collects, uses, and protects your personal data when you use the Summoner mobile application and the website summoner-app.com (collectively, the "Service"). We are committed to processing your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Bulgarian data protection law.

Data controller: Aleksandar Ivanov Ivanov, trading as Vaultpoint Labs / Vaultpoint Social, operator of the Summoner service.

97 Sveti Patriarh Evtimiy Blvd., Tsentar, 6000 Stara Zagora, Bulgaria

Email: support@vaultpointlabs.com  ·  Website: summoner-app.com  ·  Full provider details: Legal notice

1. Data we collect

1.1 Account Data

When you register, we collect:

1.2 Content You Create

1.3 Location Data

1.4 Public Reputation

For Discover, we maintain a small, publicly visible count of how many public Summons you have hosted and attended (credited only when an event completes). These counts and the badges derived from them are shown on your public profile to help other users decide whether to join.

1.5 Technical & Usage Data

1.6 Contacts (Optional)

If you grant the READ_CONTACTS permission, your device contacts' phone numbers are normalised to E.164 format and hashed client-side. Only the hashes are transmitted to our servers to identify mutual connections. Raw phone numbers from your contacts are never sent to or stored by us.

2. Legal basis for processing

We process your personal data on the following legal bases under Article 6 GDPR:

3. How we use your data

We do not sell your personal data. We do not use your data for advertising profiling.

3.1 Automated processing in moderation

Some safety measures run without a person looking first, and Article 13(2)(f) GDPR requires us to tell you which:

No penalty against your account is ever applied automatically. Warnings, restrictions on Discover, suspensions and bans are decided by a person, every time, and deliberately so: an automatic ban driven by report counts could be triggered by a handful of accounts acting together, which would make the safety system into a weapon. Automated steps can hide a piece of content or refuse an upload; only a human decision reaches your account.

Because of this, we do not carry out decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. If content of yours is refused or hidden and you believe it was wrong, write to support@vaultpointlabs.com and a person will review it.

4. Data sharing & third parties

We use the following third-party processors, each bound by data processing agreements:

We do not share your data with any other third parties except where required by law or a court order, in which case we will notify you to the extent permitted by law.

5. Data retention

6. Your rights under GDPR

As a data subject in the EU, you have the following rights:

To exercise any of these rights, contact us at support@vaultpointlabs.com. We will respond within 30 days. You also have the right to lodge a complaint with the Commission for Personal Data Protection of Bulgaria (CPDP) at www.cpdp.bg.

7. Security

We implement industry-standard technical and organisational measures to protect your data:

No system is 100% secure. In the event of a personal data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and affected users without undue delay, as required by Art. 33-34 GDPR.

8. Children's privacy

The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children under 16. If you believe we have inadvertently collected such data, contact us immediately at support@vaultpointlabs.com and we will delete it promptly.

The public, real-world-meetup features (Discover) are restricted to users 18 and over; you must confirm you are 18+ before using them.

9. International transfers

Some of our processors are established outside the European Economic Area (EEA) or operate infrastructure there, including in the United States:

These transfers are safeguarded by Standard Contractual Clauses (SCCs) approved by the European Commission, as part of each provider's data processing agreement. You may request a copy of the applicable transfer mechanisms by contacting us.

10. Cookies & tracking

The website sets no cookies and runs no analytics. There is no analytics package, tag manager, advertising pixel, session recorder or A/B testing tool on summoner-app.com. We do not track you across sites. There is nothing on the website to consent to, which is why you are not asked.

The app runs no analytics either. Earlier versions included Google's Firebase Analytics, which switched itself on by being present and recorded automatic events - first opens, session starts, screen views - against a pseudonymous app-instance identifier. We never asked it for anything and never used it, so we removed it. From version 1.0.5 onward it is not in the app at all, and neither is the advertising-identifier permission it brought with it.

One Google SDK remains, and it only reports on the app itself rather than on you:

It is not used to build a profile of you, it is not shared with advertisers, and it cannot read your messages. It is listed as a processor in section 4.

In full, this is everything the website stores in your browser:

The website also loads no third-party resources on its own initiative. Typography is served from our own domain rather than from a font CDN, so opening a page does not tell Google, or anyone else, that you did.

The Summoner app stores its settings on your own device (your theme, which chats you have hidden, your notification preferences and your encryption keys). That data stays on the phone and is not a cookie; the encryption keys in particular are never uploaded.

There is exactly one exception, and it only happens if you ask for it. On a shared Summon page (/summon) we can show an embedded Google map of the meeting point. That embed is not loaded until you press "Show map", because loading it would send your IP address and the address of the page you are on to Google. Until you press it, nothing about your visit reaches Google. If you do press it, that request is governed by Google's own Privacy Policy and Google may set cookies on your device. The "Open in Maps" link on the same page is an ordinary link and behaves like any other link you choose to follow.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where required, notify you via email or in-app notification. Continued use of the Service after changes constitutes acceptance of the updated Policy.

12. Contact & data controller

The controller of your personal data under Article 4(7) GDPR, and the provider of the Service, is:

Aleksandar Ivanov Ivanov
Trading as: Vaultpoint Labs, and Vaultpoint Social - the division of Vaultpoint Labs under which Summoner is published.

97 Sveti Patriarh Evtimiy Blvd.
Tsentar
6000 Stara Zagora
Bulgaria

Email: support@vaultpointlabs.com
Contact form: summoner-app.com/contact
Website: summoner-app.com

Send privacy questions, requests and complaints to that address or that inbox. Our Legal notice carries the same identity together with our register entry, VAT status and hosting details.