Komos

Privacy Policy

Last updated 7 September 2026. Applies to the Komos iOS app and to komos-app.com. Information under Articles 13 and 14 GDPR.

Komos is an app for making real-world plans with friends, friends of friends, and the people they bring. There is no feed, no advertising, and no tracking. Everything below describes what the app actually stores and who it actually shows it to.

The short version

1. Who is responsible

The controller within the meaning of Art. 4(7) GDPR is:

Nicolas Chalons
Hohenzollernstraße 29
80801 München, Deutschland
Email: [CONTACT EMAIL]

Full provider details are in the Impressum.

Data protection officer. Komos is run by one person. We are not required to appoint a data protection officer under Art. 37 GDPR or § 38 BDSG, and have not appointed one voluntarily. Address any privacy question to the email above.

2. What we process, why, on what basis, and for how long

All of it comes from you, in the app. Nothing is bought, and nothing is enriched from third-party sources. "Art. 6(1)(b)" means we need it to provide the service you signed up for; "Art. 6(1)(f)" means legitimate interests, which we name in each case; "Art. 6(1)(a)" means your consent, which you can withdraw at any time with effect for the future.

DataPurposeLegal basisRetention
Email addressYour login; password resetsArt. 6(1)(b)Until you delete your account
Display name, @usernameSo other people know who you are. Both are editable; the username is also the address a shared profile link resolves through, so changing it stops any link already shared from working — nothing redirects the old oneArt. 6(1)(b)Until you delete your account
Profile photo (required)A host deciding whether to accept you sees your name, photo, who you have in common, and your shared interests — that is the whole basis of the decisionArt. 6(1)(b)Until you delete your account or replace the photo
Date of birth (required)Enforcing the 18+ minimum, and letting a host limit a plan to an age range. Other people see your age in years; nobody but you ever sees the dateArt. 6(1)(b); age minimum also Art. 6(1)(c)/(f)Until you delete your account
Gender (required)Letting a host limit a plan to particular genders, e.g. a women-only walkArt. 6(1)(b)Until you delete your account
Bio, interests, home city, current cityContext on your profileArt. 6(1)(b)Until you delete them or your account
Favourite placesShown as chips on your profile. We store the name, address and coordinates of the place, never of youArt. 6(1)(b)Until you remove them or delete your account
Trips (a city and a date range)So your friends know when you're in town. Visible to accepted friends onlyArt. 6(1)(b)Until you remove them or delete your account
"I'm free tonight"One expiring marker, visible to accepted friends onlyArt. 6(1)(b)Expires automatically at 4am; no history is kept
Plans you create or joinRunning the plan: title, description, time, location text, capacity, cover image, guest listArt. 6(1)(b)Cancelled when you delete your account; otherwise kept as your history
Chat messages and imagesGroup chat attached to a planArt. 6(1)(b)Kept as part of the conversation — see section 6
A safety contactTelling somebody outside the app where you're goingArt. 6(1)(a) — you type it deliberately; also Art. 6(1)(f), the vital interest of your own safetyUntil you delete your account
Blocks and reportsKeeping people apart; acting on abuseArt. 6(1)(f) — keeping the service safe and usable, and our and other users' interest in acting on abuseBlocks until you undo them; reports see section 6
Read markers, hidden plans, dismissed noticesSo unread badges and dismissed cards agree across your devices. Nobody else can read any of it, and none of it is a read receiptArt. 6(1)(b)Until you delete your account
Server logs at our hosting providers (IP address, timestamp, request)Delivering the service and defending against attacksArt. 6(1)(f) — operating and securing the service[LOG RETENTION — confirm with Supabase, typically a few days]

The safety contact — somebody who never signed up

If you tell someone where you're going, Komos stores the contact detail you typed for a person who has no account and never agreed to this. Two things follow. Only enter a contact for someone who has agreed to it — you are asking us to store their data. And what leaves the app is the plan alone, never the guest list, which is restricted to attendees inside the app and is not routed around by any export. If you are that person and want your contact detail removed, write to [CONTACT EMAIL] and we will delete it; this is our Art. 14 notice to you.

3. Who can see what

This is the part worth reading. Visibility is enforced by row-level security rules in the database, so a screen that is not supposed to show you something cannot be persuaded to.

Visible toWhat
Any signed-in Komos accountYour name, @username, photo, bio, interests, cities, favourite places, and your age in years.
Your accepted friends onlyYour trips, and your "free tonight" marker.
People a plan was opened toThe plan. A host chooses between friends, one of their circles, friends of friends, specific invited people, or public — and can additionally limit it by age range or gender.
People actually on a planIts guest list and its chat. Nobody else can query either, including people who can see the plan.
Only youYour date of birth, your email address, your blocks, your hidden plans, your read markers, and the reports you file.
NobodyFollower counts, like counts, or any other social metric. The app has none and stores none.

Two consequences are deliberate: a declined join request is indistinguishable from one still pending, and a block is invisible to the person blocked. Both exist so that saying no is never a confrontation.

4. Recipients and processors

Other Komos users receive what section 3 says they receive. Beyond that, four parties, and only these four:

We disclose data to public authorities only where we are legally required to, and we treat a valid legal order as the only such requirement.

5. Transfers outside the EEA

Supabase, Inc., Cloudflare, Inc. and Apple Inc. are US companies, so access from the United States is possible even where the servers themselves are in Europe. The safeguards are:

A copy of the safeguards is available from [CONTACT EMAIL]. US authorities may in principle be able to access data held by US providers, and US law does not offer protection identical to the GDPR. We use these providers because there is no equivalent alternative for this service; you can avoid the transfer entirely by not creating an account.

6. Deletion and retention

You can delete your account from Settings in the app. It is immediate and needs no email to us.

Deletion anonymises the account rather than wiping every trace, and it is worth being exact:

If you want the content of your messages removed as well, email us and we will do it by hand.

7. Your rights

You have the right to access your data (Art. 15), to have it corrected (Art. 16), deleted (Art. 17), to have processing restricted (Art. 18), to receive it in a portable format (Art. 20), and to withdraw consent at any time with effect for the future (Art. 7(3)). Most of it is exercisable in the app directly: everything on your profile is editable, and deletion is a button. For the rest, write to [CONTACT EMAIL]; we answer within one month (Art. 12(3)).

Right to object (Art. 21 GDPR)

Where we rely on legitimate interests — Art. 6(1)(f), which in this policy covers security logging, and the handling of blocks and reports — you have the right to object at any time, on grounds relating to your particular situation, to that processing. Send the objection to [CONTACT EMAIL]. We will then stop processing that data unless we can demonstrate compelling legitimate grounds which override your interests, rights and freedoms, or the processing serves to establish, exercise or defend legal claims. We do not process any personal data for direct marketing.

Complaints. You can complain to a data protection supervisory authority, in particular in the Member State of your residence or place of work, or where you believe an infringement occurred. The authority competent for us is Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 27, 91522 Ansbach.

8. Do you have to provide this data?

There is no statutory obligation to give us anything. Providing an email address, a name, a username, a photo, a date of birth and a gender is required by contract in the sense of Art. 13(2)(e) GDPR: without them an account cannot be created and the service cannot be provided. Everything else — bio, interests, cities, favourite places, trips, "free tonight", a safety contact — is voluntary, and leaving it out costs you nothing but the corresponding feature.

9. No automated decision-making, no profiling

We do not use automated decision-making, including profiling, within the meaning of Art. 22(1) and (4) GDPR. Nothing in Komos scores, ranks or matches people. The only ranking anywhere in the app is the friend-suggestion list, which orders people by how many friends you already have in common — a count of a graph you built yourself, not a profile of anyone, with no legal or similarly significant effect.

10. Storage on your device (§ 25 TDDDG)

The app stores a small amount of information on your phone: your session token, unread and dismissed markers, and a cache of place lookups and images. All of it is strictly necessary to provide the service you have expressly requested, so it falls under the exception in § 25(2) no. 2 TDDDG and needs no consent. There is no advertising identifier, no tracking pixel, and no third-party cookie. This website is static, sets no cookies and runs no analytics, which is why it has no consent banner.

11. What we never do

12. Location

Komos requests no location permission and uses no location API. It never knows where your phone is. What it holds are places you typed or picked: a home city, a current city, a trip's city, a plan's location text, and your favourite places. A map in the app is built by looking those words up, not by locating you.

13. Security

All traffic is HTTPS. Profile photos, plan covers and chat images are held in private storage and served through short-lived signed links, never public URLs. Passwords are handled by Supabase Auth and are never visible to us. Access between users is restricted at the database level rather than in the app, so a client cannot ask for data it is not entitled to.

14. Under-18s

Komos is for adults. You must be 18 or over to create an account, and the app enforces that at signup. We do not knowingly process data of anyone under 18; if you believe we do, write to us and we will delete the account.

15. Changes

If this policy changes in a way that affects what we collect or who can see it, we will update the date at the top and tell you in the app before the change takes effect.

Contact

[CONTACT EMAIL]