Privacy policy
Last updated: August 2026
1. Data collected
Allways collects the following data while you use the app:
• Email address or phone number — for authentication and account management.
• GPS location — to show events near you. Your position is never stored on our servers. If you post an event, however, its address and coordinates are saved and visible to other users.
• Profile picture — optional, stored securely.
• Username and optional profile info — social media handles (Instagram, TikTok, Spotify, X), preferred language and currency.
• Events created — title, description, location, and photos of the events you post.
• Interest marks and alerts — events you mark as "interested" and the category or neighborhood alerts you set up.
• ID document — a photo of an ID document, requested once before your first event post, to fight fake events (see retention period in section 4).
• Feedback and reports — the content of messages sent via the feedback or report form.
• AI search — the text of your natural-language searches, sent to our AI provider.
• Technical diagnostic data — IP address, app and OS version, error logs, in case of a malfunction.
2. Use of data
Your data is used to:
• Show events near your location.
• Manage your account and profile.
• Send local notifications if you enable them.
• Let other users follow you and see your events.
• Automatically translate, categorize, and surface events relevant to your search — these are AI-assisted processes (see section 3).
• Prevent fraud and fake events, in particular through identity verification.
Depending on the case, these processes rely on the performance of the contract between you and Allways (account creation, event posting), on your consent (notifications, AI search, advertising — see section 3), or on our legitimate interest (security, fraud prevention, technical diagnostics). Your data is never sold to third parties.
3. Third-party services
Allways uses the following third-party services:
• Supabase — database hosting and authentication (servers located in Japan, a country recognized by the European Commission as offering an adequate level of data protection).
• Naver Maps — map display (South Korea).
• Naver & Kakao — sign-in via Naver or Kakao account (South Korea).
• Apple Sign In — sign-in via Apple ID.
• Solapi — sending SMS verification codes (South Korea).
• Expo — delivery of push notifications (United States).
• Google AdMob — displaying non-personalized ads; consent is collected before any ad loads for users located in the EU/UK.
• OpenAI — processing your natural-language queries for the "AI Search" feature, as well as automatic translation and categorization of events (United States).
Some of these providers are located outside the European Union, notably in Japan, South Korea, and the United States. The transfer to Japan is covered by a European Commission adequacy decision; other transfers are covered by the contractual safeguards offered by these providers.
4. Data retention
Your account data (profile, events you create, follows) is kept while your account is active.
Some data has its own retention period, independent of your account's lifetime:
• ID document — deleted as soon as your verification request has been reviewed.
• Technical diagnostic logs (IP address, errors) — kept for 30 days.
• Events imported from Ticketmaster — kept for a maximum of 1 month, in accordance with that source's terms.
• In case of a ban for proven fraud — your phone number and/or email are kept for up to 3 years to prevent recreating an account under another identity, on the basis of our legitimate interest in the service's security.
When you delete your account, your authentication account and your personal data are deleted immediately and irreversibly, except for the data listed above, which follows its own retention period.
5. Your rights
You have the following rights over your personal data:
• Access — you can view your data from your profile, or ask us for a copy by email.
• Rectification — you can edit your profile at any time.
• Deletion — you can delete your account from the app (Settings → Delete account).
• Objection and restriction — you can object to processing based on our legitimate interest, or ask for it to be restricted, by contacting us.
• Portability — you can ask us for a copy of your data in a structured format.
To exercise these rights, contact us at: tevaserra0@gmail.com
If you believe your rights are not being respected, you can lodge a complaint with your national data protection authority (in France, the CNIL, www.cnil.fr).
6. Security
Your data is protected by security policies (Row Level Security) that prevent any unauthorized access. Connections are encrypted via HTTPS.
7. Data controller and contact
The controller of your personal data under GDPR is Teva Serra, developer of the Allways app, reachable at: tevaserra0@gmail.com.
For any question about this policy: tevaserra0@gmail.com
