KATEapp legal

Privacy Policy

How we handle information across the Kate mobile app and kateapp.io.

Effective and last updated: 23 July 2026

The short version

Built for real-world connection

We use account, profile, event, attendance, location, and safety information to operate Kate.

Choices stay available

You can manage profile visibility, advertising consent, exports, corrections, and deletion requests.

Identity evidence stays with Didit

Kate stores verification status and provider references, not passport images, selfies, or biometric evidence.

1. Scope and controller

This Privacy Policy applies to the Kate mobile application, KATEapp services, and the website at kateapp.io (together, the “Service”).

KATEapp (“Kate”, “we”, “us”, or “our”) is the data controller for personal information processed to provide the Service. Some providers process information for us, while others may act as independent controllers for their own services. You can contact us at connect@kateapp.io.

2. Information we collect

Information you provide

  • Account information: email address, authentication details, account identifiers, and information you provide when contacting support.
  • Profile information: name, username, city, biography, profile image, interests, preferences, and visibility choices.
  • Events and community content: hosted or saved events, descriptions, images, venue and schedule details, attendance, join requests, ratings, survey answers, reports, and moderation-only private notes.
  • Identity verification information: your affirmative consent to verification, verification status, Didit session reference, and Didit user reference. Identity documents, selfies, liveness recordings, and biometric evidence are submitted directly to and retained by Didit. Kate does not store that evidence in its application database.
  • Purchases: product, transaction, and entitlement information supplied by Apple for in-app purchases. Kate does not receive your full payment-card details.

Information collected when you use Kate

  • Location: precise location when you grant device permission, event and venue coordinates, check-in location, city or area, and approximate location inferred from network information.
  • Activity and usage: app launches, feature interactions, suggestion impressions, event views, saves, dismissals, attendance activity, survey eligibility, and advertising interactions.
  • Device and notification information: device and app identifiers, operating system, language, IP address, push-notification token, consent signals, and advertising identifiers where applicable and permitted.
  • Diagnostics: crash reports, error events, request timing, and limited technical logs used to keep the Service reliable and secure.

Please do not place sensitive personal information in event descriptions, profile text, reports, or other free-text fields unless it is necessary for the feature and you are comfortable sharing it with the relevant audience.

3. How and why we use information

PurposeExamplesTypical legal basis
Provide the ServiceAccounts, profiles, events, joining, check-ins, ratings, surveys, notifications, purchases, and supportPerformance of our contract with you
Location-based featuresNearby events, maps, venues, directions, and attendance confirmationYour device permission and consent; contract where appropriate
Trust and safetyIdentity verification, fraud prevention, moderation, reports, abuse prevention, and incident investigationConsent where required; legitimate interests; legal obligations
Improve KateDiagnostics, aggregate analytics, feature performance, and recommendation qualityLegitimate interests or consent, depending on law
AdvertisingOptional rewarded ads, ad delivery, measurement, fraud prevention, and consent managementConsent where required; legitimate interests for limited non-personalized processing where permitted
ComplianceResponding to lawful requests, enforcing terms, and protecting users and the ServiceLegal obligations and legitimate interests

Where we rely on legitimate interests, we consider the impact on your rights and use the information only where those interests are not overridden by your privacy rights.

4. Advertising and consent

Kate may offer an optional Google AdMob rewarded ad as one way to cover the cost of identity verification. If you choose this option, Google and approved advertising partners may process information such as IP address, device and app identifiers, advertising or vendor identifiers, consent signals, ad requests, ad interactions, diagnostics, and approximate location. Personalized advertising is used only where allowed and where the required consent or device permission has been obtained.

We use Google’s User Messaging Platform to request and record advertising privacy choices in regions where a consent or opt-out message is required. You can revisit those choices from Profile → Settings → Privacy → Advertising privacy choices when the option is available. Device-level controls, including Apple’s tracking setting, also apply.

Kate does not provide identity documents, selfie or biometric evidence, private survey notes, or precise check-in coordinates to Google for advertising personalization.

We do not sell personal information for money. Disclosures for personalized advertising may be considered “sharing”, “targeted advertising”, or a “sale” under some US state laws. Where those laws apply, you may opt out through the in-app advertising privacy choices or by contacting us.

Learn more about how Google uses information from partner apps and sites and review Google’s Privacy Policy.

5. When we share information

We share information only as needed for the purposes described in this Policy:

  • Supabase: authentication, database, storage, server functions, and account data. Supabase Privacy Policy
  • Didit: identity-document, selfie, liveness, and biometric verification. Didit Verification Privacy Notice
  • Google: AdMob advertising and consent management, Firebase analytics and diagnostics, and website analytics. Google and individual ad technology partners may process data under their own notices.
  • Mapbox: maps, geocoding, venue search, and directions. Mapbox Privacy Policy
  • OpenAI: generation and safety moderation of event copy and cover images. Requests are designed to exclude direct contact details; they may include a pseudonymous safety identifier and event context such as category, time, venue name, and venue address. API requests are configured not to be stored for model improvement where supported.
  • Apple: App Store distribution, in-app purchases, push notification delivery, and device platform services.
  • Operational providers: hosting, communications, weather, venue, safety, and technical service providers that help us run Kate.
  • Legal and safety recipients: authorities, professional advisers, or affected parties where disclosure is required by law or reasonably necessary to protect users, prevent harm or fraud, or defend legal rights.
  • Business transfers: a buyer, investor, or successor in connection with a merger, financing, reorganization, or sale, subject to appropriate safeguards.

We may also share aggregated or de-identified information that is not reasonably capable of identifying you.

6. Public and social features

Kate is a social event service. Depending on your settings and the event’s visibility, other users may see your profile name, avatar, city, biography, hosted events, verified status, rating summary, attendance indicators, and content you publish. Invite-only or approval-based events limit some information to eligible participants. Exact venue details may be withheld until a join request is accepted.

Private moderation notes are not displayed publicly. Rating summaries are designed to appear only after the minimum participation threshold is met.

7. Retention

We keep personal information only for as long as reasonably necessary to provide the Service, maintain security, resolve disputes, comply with law, and enforce our agreements. Retention depends on the type of information and why it is processed:

  • Account, profile, event, and attendance records are generally retained while your account is active and during the period needed to complete a valid deletion request.
  • Safety, fraud, transaction, and moderation records may be retained longer where necessary to protect users or comply with legal obligations.
  • Raw pseudonymous signals used to evaluate automated event suggestions are retained for up to 30 days by default; aggregate metrics may be kept longer.
  • Backups and technical logs are removed or overwritten on ordinary backup and operational cycles.
  • Didit retains identity-verification evidence under its own verification privacy notice and applicable legal requirements.

8. International transfers

We plan to make Kate available internationally. We and our providers may process information in countries other than the country where you live. Where required, we use recognized transfer mechanisms and contractual safeguards, such as Standard Contractual Clauses, and apply additional protections appropriate to the information and destination.

9. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, withdraw consent, opt out of targeted advertising or sharing, and appeal a denied privacy request. You may also complain to your local data protection authority.

  • Update profile and visibility choices in Kate.
  • Manage location, notifications, photos, camera, microphone, and tracking permissions in iOS Settings.
  • Revisit advertising consent or opt-out choices in Kate’s Privacy settings when required for your region.
  • Request an account data export or account deletion from Kate’s Privacy settings.
  • Email connect@kateapp.io for other requests.

We may need to verify your identity before completing a request. Rights are subject to lawful exceptions. Withdrawing consent does not affect processing already carried out lawfully before withdrawal.

10. Age requirements

Kate is intended for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a person under 18 has provided personal information to Kate, contact us so we can investigate and take appropriate action.

11. Security

We use administrative, technical, and organizational measures designed to protect personal information, including access controls, encrypted network transport, server-side secrets, privacy-focused database rules, signed provider callbacks, and minimization of identity-verification evidence. No system can guarantee absolute security.

12. Website and cookies

kateapp.io may use cookies and similar technologies for essential operation, preferences, audience measurement, and website analytics. The website uses Google Analytics and Google Tag Manager, which may process device, browser, IP address, and page-interaction information. Where required, we ask for consent before using non-essential technologies.

See our Cookie Policy for more information and browser controls.

13. Changes to this Policy

We may update this Policy as Kate, our providers, or applicable laws change. We will update the date above and, when a change is material, provide an appropriate notice in the Service or by email before the change takes effect where required.

14. Contact us

For questions, complaints, or privacy requests, contact the KATEapp privacy team:

connect@kateapp.io

Please include the country or region where you live and enough detail for us to understand your request. Do not email copies of identity documents unless we specifically ask for them through a secure method.