Goba

Privacy Policy

Effective Date: September 1, 2026

Welcome to Goba (the "App"), a service for chatting about ephemeral topics with people nearby. We believe your privacy should be simple and transparent. This Privacy Policy explains how we collect, use, and protect your data.

1. Who we are (Data Controller)

The controller of your personal data is:

For any questions about your data or to exercise your rights, please contact us at the email above.

2. Data we collect

We collect only what is needed to operate the App:

Website and link analytics: When you open a page of goba.app — the landing page, this policy, or any other document — or when you follow a link to a topic (goba.app/t/…) or a group (goba.app/g/…), we record the visit: which page was opened, its language, the referring website's domain, any utm_source / utm_campaign tags present in the address, the country derived from your IP address, the broad device type (iOS, Android or other), and whether you tapped an app store button. For this analytics we do not store your IP address and we set no cookies. To tell one visitor from repeated visits by the same person we store an irreversible daily fingerprint derived from your IP address, browser identification and a secret key; it changes every day, so it cannot be used to follow you over time.

App install and sign-up measurement: To measure whether our advertising brings people who actually use Goba, the App sends a short list of named events to Google Analytics for Firebase: the first launch after installation, a completed sign-up, the creation of a topic, and four screens of the sign-up funnel (guest feed, sign-in screen, profile setup, location screen), plus the SDK's own session events. We do not collect your advertising identifier, we do not attach these events to your Goba profile, and no screen where you read or write content is reported. What you do inside the App is measured only by our own statistics, which stay on our servers.

Note: We do not sell your data, and we do not track you across other apps or websites.

3. Why we process data and our legal basis (GDPR)

Purpose Data Used Legal Basis
Providing the service (sign-in, chats, profile creation) Account, profile, UGC, technical data Performance of a contract (Art. 6(1)(b))
Showing nearby topics Location Consent (Art. 6(1)(a))
Push notifications Push token, notification settings Consent (Art. 6(1)(a))
Understanding where our traffic comes from (website and link analytics) Page, language, referrer domain, utm tags, country, device type, daily fingerprint Legitimate interest (Art. 6(1)(f))
Measuring our advertising (app install and sign-up measurement) Install, sign-up, topic creation and sign-up funnel events, device and app data collected by the Firebase SDK Legitimate interest (Art. 6(1)(f))
Safety, moderation, and abuse prevention UGC, reports, blocks, logs Legitimate interest (Art. 6(1)(f))
Legal compliance As required by applicable law Legal obligation (Art. 6(1)(c))

You can withdraw your consent for location access and notifications at any time via your device's system settings.

4. Who we share data with (Processors)

We do not sell your personal data. We use trusted third-party providers ("processors") strictly to operate the App:

Automated image screening: Images you upload are automatically checked for illegal or abusive content by software running on our own servers in Germany. This screening is not performed by, or shared with, any third party.

AI-assisted translation: When you enable automatic translation, text in a language other than your interface language — topic titles and descriptions, and chat messages — is translated by an AI model running on our own servers in Germany. The text is not sent to any third-party translation service. This includes messages in closed groups and, unless you switch it off in Settings, in private chats. Translations are cached on our servers so the same text is never translated twice.

AI-assisted moderation review: When content is reported to us, that content (its text and, where applicable, its image) may be sent to Google (Gemini API) for an automated assessment that helps our moderators. The assessment is advisory only: the decision on a report is always taken by a human moderator.

Public Content: Please remember that some of your content (topics, public messages, nickname, and avatar) is, by its nature, visible to other users of the App, including visitors who are browsing without an account.

5. International data transfers

Your data is primarily processed on secure servers located in Germany. Where data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as EU Standard Contractual Clauses.

6. Data retention

7. Your rights (GDPR)

Depending on your location, you have the right to:

For any privacy requests not covered by the App's settings, email info@goba.app. We will respond within the time required by law. You also have the right to lodge a complaint with your local data protection supervisory authority.

8. Age restriction

The App is intended for users who are 16 years of age and older. We do not knowingly collect data from children under 16. If we discover that a child under 16 has created an account, we will promptly delete it.

9. Security

We implement reasonable and robust technical and organizational measures to protect your data, including HTTPS traffic encryption and strict access controls. However, please be aware that no method of internet transmission or electronic storage is 100% secure.

10. Changes to this Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via the App or by email. The effective date at the top reflects the latest revision.