English | Italiano

VattenAI

Privacy Policy — Last updated: October 10, 2026

1. Controller and contact

Controller: Federico Ribaldi, individual, sole developer of VattenAI. Certified email (PEC): federico.ribaldi@pec.it.

Privacy contact: federico.ribaldi97@gmail.com.

Data Protection Officer: not appointed, because it is not mandatory for a controller that does not process data on a large scale or special categories of data (Art. 37 GDPR).

2. Summary

3. What we process, why, legal basis, retention

Bases (Art. 6(1)): (b) service you requested; (a) consent; (c) legal obligation; (f) legitimate interest. You may object to (f) processing (§9).

3.1 Using the app (everyone, guests included)

3.2 Security and abuse prevention

3.3 Guest account

Anonymous Firebase ID; basis (b); deleted after 30 days of inactivity. Guests cannot publish content; they can report a content without an account (§3.14). Guest push tokens: §3.9.

3.4 Google or Apple account

3.5 Events you publish

3.6 Uploaded images and automated check

Before storage, images go to Google Cloud Vision SafeSearch; flagged or unchecked uploads are rejected. Images uploaded by administrators skip this check. Google states no training and in-memory processing. The app re-compresses photos, normally stripping EXIF/GPS; our server does not strip metadata. Basis (b)/(f); retention as §3.5.

3.7 Auto-fill from a poster (if available in your app version)

3.8 AI travel estimates

3.9 Push notifications and the city used for them

3.10 Rain alerts and event reminders (Premium)

Premium is free and invitation-only (admin adds your email).

3.11 Location

Optional, OS-requested; on Android the app declares only precise and approximate foreground location, not background.

3.12 Usage statistics (Firebase Analytics)

3.13 Handling your requests

Request content and email; basis (c); retained up to 24 months after the request is closed, to prove we answered.

3.14 Content reports

reason, optional text (≤500 chars), date; your uid if you have an account; if you report without an account, the hash of a random installation key (not linked to an account) and, if you want the outcome, your email. The publisher doesn't see who reported; admins see reason/text, not uid. Basis (c) DSA Art. 16, (f). A closed report is deleted 12 months after closure; an open one is kept until reviewed; uid/text erased on account deletion.

3.15 Web share pages and information pages

Share pages (/e/…, /v, on Vercel) load Vercel Web Analytics and Speed Insights (not for private events; no first-party cookies). This policy and the Terms are on GitHub Pages (GitHub, USA), which receives visitors' IP. Basis (f) unless counsel requires consent.

3.16 Direct connections from your phone

Receive your IP and device data: Google Fonts at first launch before any consent; OpenStreetMap tiles via a global CDN, with the map area viewed; Wikimedia welcome image (USA); event images from source sites; Google Maps on tap only. Independent controllers.

3.17 Events from public sources (Art. 14 notice)

Automatically collected from event sites, ticketing, open-data portals, Wikidata; no organiser contact fields, but descriptions may contain names/contacts. Basis: (f). Title, description (≤800 chars), place and city may go to Jev (TypeSafe) via OpenRouter for categorisation and duplicate detection. Categorisation excludes user and private events; deduplication can include user events, private ones too, and modify them (§3.5). Deleted after end date. To object, email the §1 contact (no account needed).

3.18 Restaurants (suspended)

Disabled. When active, the server used Google Places to verify places and fetch photos. Past restaurants, personal tags and hidden items remain linked to your uid and are not erased on account deletion.

3.19 Data kept only on your phone

Preferences, favourites, saved trips, reminders, consent choice, caches. Note: your home city (if you granted notifications) and reminders are also sent to our server (§3.9, §3.10). Android backup disabled; iOS preferences may be in iCloud backups.

4. Automated decision-making

No decisions based solely on automated processing with legal or similarly significant effects (Art. 22). Automated tools: image filter (may reject an upload); categorisation and deduplication of events; AI drafts/estimates you review. Every user-published event is approved by a human.

5. Recipients

No selling, no advertising sharing.

5.1 Processors (Art. 28): | Provider | Service | Location | Contract status | |---|---|---|---| | Vercel Inc. | backend hosting, logs, Web Analytics/Speed Insights | USA (iad1) | No DPA on the Hobby plan in use; terms allow AI training on content | | Supabase Inc. | database, storage | EU (Ireland, eu-west-1) | DPA in terms | | Upstash Inc. | limits, IP blocks, cache, Premium/admin emails (DB shared test/prod) | | DPA in terms | | Google (Firebase) | Auth, FCM, App Check | Auth US-only; others global | Firebase terms | | Google (Cloud Vision) | image check, poster OCR | global | Cloud DPA | | OpenRouter Inc. | AI routing | USA | DPA for commercial use |

5.2 AI model providers: Mistral AI (France) and Google (Vertex AI), paid models with no retention or training requested (§3.7, §3.8); xAI (if enabled); TypeSafe.

5.3 Independent controllers: Google (Analytics, Play Integrity, Fonts, Maps), Apple, OSM Foundation, komoot, HeiGIT, Open-Meteo, Wikimedia, GitHub, image source sites, authorities when required.

5.4 Authorised persons: controller and admins (moderation queue incl. submitter name/email, reports).

6. Whether providing data is required

Browsing requires no identifying data, but IP/requests are needed. A Google/Apple account is needed only to publish/report, self-service export/deletion and Premium. Location, notifications and analytics are optional.

7. Children

Under-14 access to AI requires parental consent in Italy (Art. 4(4) Law 132/2025, in force 10/10/2025); digital consent age 14 (Art. 2-quinquies It. Privacy Code). VattenAI is intended for people aged 14 or over. At launch we ask you to declare you are at least 14 and you cannot continue without it. This declaration is not verified: if we learn an under-14 has an account without the consent of the person with parental responsibility, we delete it.

8. Transfers outside the EU

Vercel (USA, all requests): DPF claimed; SCCs only in the DPA, not available on the plan in use. Google/Firebase: Auth US-only; DPF + SCCs. Upstash: DPF + SCCs. Supabase: data in Ireland; SCCs for Singapore entity and sub-processors. OpenRouter: USA, SCCs. Google (Vertex AI), xAI: USA. Mistral AI: France (EU), via OpenRouter (USA). HeiGIT states non-EU transfers; OSMF in the UK (adequacy); Wikimedia and GitHub in the USA. DPF valid but under appeal (C-703/25 P). You may request the safeguards.

9. Your rights

How to delete your account and data, step by step

Access (15), rectification (16), erasure (17), restriction (18), portability (20), objection (21), withdraw consent anytime (7(3)).

10. Complaints

Italian Garante per la protezione dei dati personali (www.garanteprivacy.it, Piazza Venezia 11, 00187 Rome) or the authority of your EU country (Art. 77); courts (Art. 79).

11. Security

Encrypted connections, server-only database access with row-level security, token revocation checks, rate limits and spending caps. Breaches notified per Arts. 33-34.

12. Changes

Material changes notified in the app before they take effect.