your personal artificial social intelligence

Legal

Privacy Policy

Last updated: 16 July 2026

1. Who's the data controller

John Dreic, trading as Dreic Labs, based in London, United Kingdom, is the controller of your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Reach us at hello@palaner.com.

2. What we collect

Account data. Email address, hashed password (or your Google account identifier if you sign in with Google), and the date you joined.

Profile data you give us.Things you tell palaner during onboarding or chat — for example your home area, hobbies, favourite music or comedians, what you don't like, and similar. You choose what to share. You can edit or delete this from your profile settings at any time.

Activity data. Events you save, plans you build, feedback signals you give (thumbs-up / thumbs-down / hide), chat messages exchanged with palaner, voice transcripts if you use voice mode.

Location for nearby searches. If you allow location access and ask palaner for something nearby, the app can send your current coordinates with that request. We use them only to answer that request, do not add them to your chat history, and do not retain a movement history.

People you tell palaner about.If you mention friends, partners, or others in chat (e.g. "my friend Marko likes techno"), or upload a screenshot of someone else's dating profile to help plan a date, palaner extracts those details and stores them in your account so it can remember next time. We do not contact those people, and we don't persist any images you upload — they're passed to the AI provider and deleted in the same request.

Contacts you sync ("People You May Know").If you choose to let the iOS app check your phone contacts, we never see or store a raw phone number or email address from your address book. Your device hashes each contact's phone number and email (one-way SHA-256, computed on your phone) and sends us only those hashes. We compare them against hashes of our own registered users' contact details to suggest people you may already know — nothing about your OTHER contacts (the ones who don't match) is ever transmitted or retained. This is opt-in: it only runs after you grant the Contacts permission, and you can turn it off any time in iOS Settings. See "How long we keep things" below for how long the matching index is kept.

Technical data. IP address, browser user-agent, broad device type, and basic page-load timings, collected through our hosting and content-delivery providers. We also use privacy-friendly, cookieless analytics (PostHog, EU) to count page views and key actions in aggregate. With your consent we additionally record anonymised session replays (via PostHog and FullStory) and link activity to your account. We never use advertising or cross-site tracking SDKs.

3. Why we use it (and the lawful basis)

  • To provide the service — running your account, personalising your event feed, holding chat history, syncing your saved plans across devices. Lawful basis: performance of contract.
  • To make the service better — debugging errors, improving the ranking algorithm, monitoring cost. Lawful basis: legitimate interest.
  • To keep it safe — preventing abuse, enforcing rate limits, investigating suspected fraud. Lawful basis: legitimate interest.
  • To tell you about service news — important account or product changes. Lawful basis: legitimate interest. Marketing emails (if we ever send them): explicit opt-in.
  • To comply with law — responding to lawful requests from regulators or law enforcement.

4. Who we share it with

We share personal data with the following sub-processors, strictly to operate the service. Each is bound by a data processing agreement and processes data on our instructions only. We do not sell your data.

  • Supabase (auth and database) — your account record, profile, plans, chat history. Region: EU.
  • Fly.io (backend hosting) — runs the API that talks to Supabase. Region: London (LHR).
  • Vercel (frontend hosting) — serves the Palaner web app to your browser.
  • Cloudflare (DNS and edge proxy) — sees request metadata (IP, URL, user-agent) on the way in.
  • Google Cloud (Vertex AI — Gemini)— our primary AI provider. Receives your chat messages, the profile context palaner uses to personalise replies, and (if you upload one) any screenshot or document you ask palaner to analyse. Processing region: EU (europe-west4). Google's Vertex AI terms state customer data is not used to train their foundation models.
  • Google Maps Platform (Places) — when you ask for nearby restaurants, bars, shops, or similar places, receives the search category and either your city or your current coordinates if you allowed location access. Palaner shows the returned place details with Google Maps attribution and a source link, but does not save those live details in your chat history. See the Google Privacy Policy.
  • Anthropic(Claude AI) — a fallback AI provider we can switch to if our primary provider is unavailable; when active it receives the same chat messages and profile context. Anthropic's API terms say they do not train models on API inputs.
  • OpenAI(Whisper speech-to-text, TTS voice) — receives audio you record for voice mode and any text palaner reads aloud. OpenAI's API terms say they do not train models on API inputs by default.
  • ScrapingBee — used to fetch public event pages on our behalf. Does not receive your account or profile data.
  • ScrapingAnt — like ScrapingBee, used to fetch public event pages on our behalf. Does not receive your account or profile data.
  • PostHog (product analytics + optional session replay, EU Cloud) — aggregate page-view and event counts run cookielessly for everyone; session replay and linking activity to your account run only if you accept analytics in the consent banner.
  • FullStory (session replay) — if you accept analytics in the consent banner, records anonymised replays of your session linked to your account so we can diagnose UX problems. Runs only with consent; never for users who decline.
  • Sentry (error and performance monitoring, EU) — receives crash reports and latency traces (which can include your user id, URL, and technical context) so we can fix bugs.
  • MusicBrainz (and Last.fm) — we look up the genres of artists you like to translate your music taste into real-world event categories. We send artist names, never your identity.
  • Event sources (Resident Advisor, Eventbrite, Luma, Skiddle, Ticketmaster, Bandsintown, etc.) — when you click an event link, you are sent to that site, which has its own privacy policy.

Several of these providers process data outside the UK and EEA (typically in the United States). Where they do, the transfers are covered by Standard Contractual Clauses or the UK International Data Transfer Addendum.

5. How long we keep it

  • Account, profile, plans, chat history — for as long as your account is open. Deleted within 30 days of you closing your account.
  • Voice recordings — never persisted. Audio is sent to OpenAI, the transcript stored, audio discarded in the same request.
  • Uploaded images — never persisted, same pattern as above.
  • Server logs — kept for up to 30 days for debugging and abuse-prevention, then deleted or aggregated.
  • Backups — Supabase keeps point-in-time backups for up to 7 days, which is the maximum window in which deleted data may still exist before it is purged from cold backup storage.

6. Your rights

Under UK GDPR you have the right to:

  • Ask for a copy of the personal data we hold on you. You can also see what palaner knows about you in-app at any time.
  • Ask us to correct anything that's wrong.
  • Ask us to delete your account and the data tied to it. You can also delete your account directly from your account settings.
  • Restrict or object to certain processing.
  • Receive your data in a portable format and ask us to send it to another controller.
  • Withdraw consent at any time, where we relied on consent.
  • Complain to the Information Commissioner's Office (ICO) at ico.org.uk. We'd ask you to tell us first so we can try to put things right.

To exercise any of these rights, email hello@palaner.com. We'll respond within one month.

7. Cookies and similar technologies

Palaner uses a small number of strictly necessary cookies to keep you signed in (set by Supabase auth) and to remember UI preferences. Our default analytics (PostHog, EU) run in a cookieless mode that counts visits in aggregate without setting any tracking cookie or building a profile of you. We ask for your consent before turning on session replay or linking analytics to your account; you can accept or decline in the banner shown on your first visit, and change your mind at any time by clearing the choice in your browser. We do not use advertising cookies or third-party tracking pixels.

8. Children

Palaner is not for under-18s. We don't knowingly collect data from anyone under 18. If you believe a child has signed up, please email us and we will remove the account.

8b. How long we keep things (retention)

We keep personal data only while it does its job, then delete it:

  • Account & profile (name, handle, taste profile, saved plans): for as long as your account exists. Deleting your account removes them immediately.
  • Chat history with palaner: kept while your account exists so palaner remembers context; deleted with your account. You can also clear it in-product.
  • Location: your home area/postcode is kept as part of your profile (deleted with the account). Live location shared with friends is held only while sharing is on and is not retained as a movement history. A current coordinate used for a nearby place search is processed for that request and is not written into your chat history.
  • Server logs & error reports: rotate automatically within ~30 days and reference you only by a pseudonymous ID.
  • Analytics(PostHog, FullStory): events are keyed to a pseudonymous ID, not your name or email. After account deletion the link between that ID and you is destroyed; ask hello@palaner.com and we'll purge the analytics records themselves within 30 days.
  • Contact-hash matching index: we keep a hash of your OWN email (and phone number, if we ever collect one) so other users' contact scans can find you — never a raw value, never your contacts' details. Deleted with your account. The people-you-may-know results shown to YOU from scanning your own contacts are computed fresh each time and are never stored.

Location sharing has its own consent: sharing your location with friends is off by default and only happens when you switch it on (Article 6(1)(a) consent). You can turn it off any time in settings and the shared location stops being available immediately. Signing in with Apple? Deleting your account also destroys the sign-in link on our side.

Contacts matching has its own consent, too: checking your phone contacts against our users only happens after you grant the iOS Contacts permission (Article 6(1)(a) consent) — we never ask for or receive your contacts any other way. Revoking the permission in iOS Settings stops all future matching immediately.

9. Security

We use HTTPS in transit, encrypted-at-rest storage via Supabase, and least-privilege access controls for the small team that maintains Palaner. No system is perfectly secure. If we become aware of a breach affecting your data we will notify you and the ICO as required by law.

10. Changes to this policy

We may update this policy. If a change is material we'll tell you by email or in-product before it takes effect. We'll always update the "last updated" date at the top.

11. Contact

Anything about your data, hello@palaner.com gets you to the right place.