Legal
Last updated: 3rd September 2026
Community Guidelines
belongi is built on one simple idea: that shared interests are the best foundation for new friendships. These guidelines exist to protect that — and everyone in it.
1) Be kind
Treat everyone with respect — in messages, in person, always.
Keep the tone friendly. Insults, harassment, hate speech, and bullying are not tolerated, full stop.
Don't pressure anyone for their time, attention, or personal details.
2) No creep behaviour. We mean it.
belongi is not a dating app. It is not a place to pursue people who aren't interested, make anyone feel watched, or test how far you can push things before someone complains.
The following are strictly prohibited and will result in immediate account review or permanent ban:
- Sending repeated unwanted messages after someone has not responded or has asked you to stop
- Making sexual comments or initiating unsolicited flirting
- Following someone, engineering "accidental" run-ins, or showing up to a location you weren't invited to
- Asking for someone's contact details after they've said no — once is enough; asking again is a violation
- Sharing another user's personal information with anyone, inside or outside the app
- Attempting to identify, locate, or dig up information about another user beyond what they've chosen to share
If someone says no, seems uncomfortable, goes quiet, or stops engaging — stop. Immediately. There is no grey area here.
Violations of this section are treated as serious. We do not issue warnings for behaviour that makes another person feel unsafe.
3) Respect boundaries — before, during, and after the hangout
A "no" is a complete answer. It doesn't need an explanation, and it doesn't invite negotiation.
Do not touch people without their consent.
Do not push people toward plans, locations, or activities they didn't agree to when they signed up.
What happens at a hangout stays between the people who were there. Don't share what people said, did, or disclosed without their permission.
4) Keep it safe and legal
The following are prohibited on belongi — no exceptions, no context that makes them okay:
- Threats or acts of violence
- Any illegal activity, including but not limited to fraud, drug dealing, or solicitation
- Scams or spam of any kind
- Self-promotion, business pitching, or recruiting other users
If it's illegal, it's also a belongi violation. The two aren't separate.
One clarification on self-promotion: event organisers are invited by belongi specifically to publish their events, and doing so through that feature is not a violation. The rule applies to everyone else, and to event organisers everywhere other than their own event listings — including chat, profiles, and hangouts.
5) Privacy matters
Do not share screenshots, messages, or personal details from conversations or hangouts without explicit permission from everyone involved.
Do not ask for someone's home address or workplace. If an address is needed for the hangout itself, share it only with accepted participants and only when the time is right.
You are not entitled to know anything about another user beyond what they've chosen to make visible on their profile.
6) Show up honestly
If you can't make it, cancel early — don't ghost.
Your profile should be accurate. Don't misrepresent who you are, what you're into, or why you're on the app.
Organisers: be upfront about cost, timing, and what the hangout actually involves. Bait-and-switch hangouts are a violation of these guidelines.
Terms of Use
1) Who we are
belongi is currently a hobby project to help people in Berlin meet through shared activities. It is not currently operated with commercial intent. Operator details are available in our Imprint.
This may change. If belongi grows, introduces paid features, or becomes commercially operated, we will update these Terms as described in section 10 below.
2) What belongi is (and isn't)
belongi helps people in Berlin discover and coordinate small-group, real-life hangouts. It also lists events published by event organisers, which members can attend and build a hangout around.
Whoever sets something up is responsible for it:
- A hangout — the member who created it.
- An event — the event organiser who published it, including where that organiser is belongi.
For hangouts, and for events published by organisers other than belongi, belongi is only the platform they are listed on. It does not organise, attend, supervise, or guarantee them, is not a party to any arrangement between the people involved, and is not responsible for what happens. Participation is entirely at your own discretion.
3) Eligibility
You must be at least 18 years old and have the legal capacity to enter into agreements in your jurisdiction to use belongi. By creating an account, you confirm that you meet both requirements.
4) Accounts & profiles
You agree to:
- Provide accurate, truthful information when creating your account
- Keep your login credentials secure and not share access with others
- Not impersonate another person or misrepresent your identity in any way
Accounts found to be fraudulent or impersonating others will be permanently removed without warning.
5) Community rules
By using belongi, you agree to follow the Community Guidelines above. These guidelines are part of these Terms — violating them is a violation of this agreement.
We may update the Guidelines from time to time to reflect new situations or risks. When we do, we will notify you as described in Section 10.
6) Safety, payments, and your responsibility
Your safety
You are responsible for your own personal safety and the decisions you make on and off the app.
Safety tips — please take these seriously:
- Tell a trusted person where you're going and when you expect to return.
- Arrange your own transport and do not share personal addresses unless genuinely necessary.
- Trust your instincts. If something feels wrong, leave.
- All hangouts on belongi are required to take place in public spaces — you will never be asked to meet somewhere private through this app.
You can cancel or leave a hangout at any time, for any reason. If you feel unsafe because of another user's behaviour, report them via Contact.
Payments
Any costs associated with a hangout — tickets, class fees, entrance, food, drinks, or anything else — are strictly between you and the organiser or venue. belongi is not involved in any financial transaction, does not process payments, and accepts no liability for payment disputes or losses.
6a) Event organisers
Organiser access lets an account publish events to all members. It is granted by invitation from belongi only, cannot be applied for or purchased, and may be withdrawn at any time. The organisation an organiser publishes under is set when the invitation is sent and cannot be changed afterwards.
An event organiser is responsible for the events they publish: the accuracy of the listing — timing, location, pricing, accessibility — and the running and safety of the event. Section 6 applies in full: belongi is not a party to any transaction between an organiser and a member, and does not process payments. Hangouts that members create around an event are not the organiser's responsibility, and the organiser has no say in who joins one.
belongi may publish events itself, under its own name and identified as such. Where it does, belongi is that event's organiser and carries the same responsibility as any other.
Cost of organiser access
Publishing events is currently free of charge.
It will remain free permanently for any event that is both free to attend and not commercially motivated — meaning it is not used to promote or sell a product or service, to generate leads or custom, to recruit, or otherwise to further a business interest. belongi assesses this, acting reasonably. The commitment does not expire and does not depend on belongi's commercial status.
We may introduce charges for events that do not meet both conditions. That would be a material change under section 10: affected organisers would be notified in advance, and never charged for anything published beforehand.
7) Content and messaging
Chat on belongi is for planning hangouts. That's its purpose.
belongi may restrict or remove content that includes — but is not limited to — photos, spam, harassment, solicitation, self-promotion, or anything that violates these Terms or the Community Guidelines. There is no entitlement to send any particular type of message on belongi.
This section governs chat messages, profiles, and hangout titles and descriptions. Events published through the event organiser feature in section 6a are promotional by their nature and are not restricted by this section, though they remain subject to these Terms and the Community Guidelines in every other respect.
8) Enforcement
We may warn, restrict, suspend, or permanently ban any account that violates these Terms or the Community Guidelines. Enforcement decisions are made at belongi's sole discretion.
Serious violations may result in immediate, permanent bans without prior warning. Serious violations include stalking, harassment, intimidation, unsolicited sexual behaviour, threats, sharing private user information, fraud, or illegal activity.
We are not obligated to share the details of our investigation or the evidence considered when making an enforcement decision.
8a) Complaints about enforcement decisions
In line with applicable EU law, if your account has been restricted, suspended, or permanently banned, you have the right to submit one written complaint via Contact within 14 days of the decision.
Your complaint will be acknowledged and reviewed. We will send a written final response within 30 days.
Please note:
- Submitting a complaint does not automatically reverse or pause the enforcement action.
- belongi is not obligated to disclose the specifics of its investigation or the identity of anyone who reported you.
- Our response following the complaint review is final. We will not enter into further correspondence on the matter after our final response has been sent.
If you remain dissatisfied, you may seek out-of-court dispute resolution through an applicable certified dispute resolution body under EU law, or pursue any legal remedies available to you under applicable law.
9) Data, privacy, and retention
Your use of belongi is governed by our Privacy Policy, which covers what we collect, why, retention, and your rights.
We do not use any user data to train, fine-tune, or improve machine learning or AI models — ours or anyone else's.
Optional AI-assisted features (such as pre-filling a hangout description from a pasted event link) use Anthropic's Claude API (currently the Haiku model) to generate text at your request. Only the public content of the page you provide is sent for this purpose — never your profile or other hangout data — and Anthropic does not use this data to train its models.
Your email is used only for account operation — sign-in, verification, password reset, notifications about your hangouts and events (such as application updates and reminders), invitations to become an event organiser, and when you contact us. We do not send newsletters or marketing emails. Email notifications are optional and can be enabled or disabled at any time in your account settings.
10) Changes to belongi or these Terms
We may modify, suspend, or discontinue belongi at any time, or update these Terms and Community Guidelines.
If changes are material — meaning they meaningfully affect your rights or how we process your data — we will notify you by email or via an in-app notice before the changes take effect, and we will require your acknowledgement before you can continue using belongi.
For minor, non-material changes (such as wording clarifications that do not affect your rights), updates will be posted on our Updates and noted with a revised date on this page. Continued use of belongi after such changes take effect constitutes acceptance.
Privacy
belongi takes your privacy seriously. This policy explains what personal data we collect, why we collect it, how long we keep it, and what rights you have. We've written it in plain language on purpose — if something isn't clear, contact us.
1) Who is responsible for your data?
The data controller for personal data collected through belongi is: Bárbara Araújo da Silva Borges (Contact)
belongi is currently operated as a hobby project by an individual. If this changes, this section will be updated and you will be notified in line with Section 10 of the Terms of Use.
2) Where is your data stored?
Application data (accounts, profiles, hangouts, and messages) is stored on servers located within the European Union. belongi uses Hetzner Online GmbH (Industriestraße 25, 91710 Gunzenhausen, Germany) as its hosting provider. Hetzner operates exclusively EU-based data centres and acts as a data processor on belongi's behalf under a Data Processing Agreement.
Transactional and notification emails (such as verification links, password resets, and hangout notifications) are sent through Sweego, our email delivery provider. Sweego processes your email address and message content only to deliver these emails on our instructions, under a Data Processing Agreement.
3) What data we collect and why
3.1) Always stored while you have an account
Storing this is necessary to run belongi and keep it safe. It is not optional, and it applies to every account.
3a) Account data+
What: Your email address, date of birth (to confirm you are at least 18), and a password stored only in hashed form — we never store your password as plain text. If you sign in with Google, we also store the stable identifier Google assigns to your Google account, and we use the email address and, where your Google account shares one, the date of birth that Google provides. An account created via Google sign-in has no password unless you later set one. We never receive or store your Google password.
Why: To create and manage your account — sign-in (by password or via Google), age eligibility, verification, password reset, and support.
belongi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Legal basis: Performance of a contract (Article 6(1)(b) GDPR).
Kept for: As long as your account is active. If you delete your account yourself, a one-way hash of your email is retained for 30 days to prevent immediate re-registration, then removed; your live email address is removed from your account record immediately, and the account record itself is permanently deleted 30 days later. If you don't sign in for 1 month, we'll send a one-time email to your registered address letting you know your account will be deleted after 2 months of inactivity unless you sign in again — in that case, once 2 months of inactivity is reached, your account and all associated data are permanently deleted immediately, with no 30-day grace period (a one-way hash of your email is still retained for 30 days to prevent immediate re-registration).
3b) Profile data+
What: Username, optional nickname, chosen preset avatar (illustration — not a photo of you), avatar background colour, gender, personality type, bio, interest tags you select, and the languages you speak.
Why: To match you with relevant hangouts and other users, to show a consistent identity in the app, and to ensure you and a hangout's participants share at least one common language.
Who can see it: Your profile is only visible to people you share a hangout with — specifically, other members who matched into that same hangout based on shared interests with its organiser — or people you are friends with (see section 3i). It is never visible to unrelated users browsing the app. Your nickname is visible only to your friends, never to anyone else.
Legal basis: Performance of a contract (Article 6(1)(b) GDPR).
Kept for: As long as your account is active. Deleted when you delete your account.
3c) Technical and security data+
What: IP address and browser type are logged only when a request errors or is rate-limited — not on every request. Request timestamps are recorded for all requests, without IP or browser type attached.
Why: To operate the service, prevent abuse, enforce rate limits, and protect against attacks.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR) — keeping the service secure and available.
Kept for: Server and security logs are automatically deleted after 7 days, unless longer retention is needed to investigate abuse or comply with law.
3d) Analytics and usage statistics+
This covers two separate things: anonymous website traffic analytics, and internal usage statistics we generate from account data we already hold.
Website traffic (Umami)
What: Page views, visit counts, approximate country (derived from IP address but not stored), browser type, and device type.
Why: To understand how the app is used in aggregate and improve the product.
How: We use Umami, a privacy-respecting analytics tool that we self-host on our own servers. It does not use cookies, does not fingerprint your device, and does not share any data with third parties. Your IP address is used only to derive an approximate country and is never stored.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR) — understanding product usage to improve the service, with no personal data retained.
Kept for: Aggregated analytics data is retained indefinitely. No personally identifiable information is stored.
Internal usage statistics (account data)
What: Aggregate counts derived from account data described in 3a — for example, how many accounts exist, how many were created in a given period, and how many signed in recently (used to report daily/weekly/monthly active users). This does not create or store any new data about you; it counts existing fields (account creation date, last sign-in time, account status).
Why: To understand overall product usage and growth. These are aggregate totals only — this reporting is never used to look up or profile any individual user's activity, and is visible only to belongi's administrator.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR) — understanding and improving the service.
Kept for: This reporting is generated live from existing account data and does not extend its retention — see 3a for how long that underlying data is kept.
Anonymous event counters
What: Tallies of specific actions happening in the app — for example, a hangout being created, someone viewing a hangout they can't join, tapping "Apply", leaving a hangout, a hangout link being shared or opened, or a notification email being sent. Each tally is just an event name and a timestamp — it does not record who did it, which hangout it relates to, or any other detail.
Why: To see, in aggregate, which parts of the app people actually use, so we can fix what's confusing and improve the product — for example, understanding how many people see a hangout they can't apply to helps us design a better first-time experience.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR) — understanding and improving the service, with no personal data involved.
Kept for: Indefinitely, since it's just anonymous counts with no way to trace an entry back to you or to a specific hangout.
Inactivity feedback
What: If you click a reason link in an inactivity-warning email (see section 3a), we record which reason you picked and any optional free-text detail you choose to add. This is stored with no link back to your account, email, or identity — by design, it can't be traced back to you. To stop the same link being used to submit multiple times, we briefly keep a one-way hash (not reversible back to your account) recognising that the link was already used; this hash is deleted after 30 days.
Why: To understand, in aggregate, why people stop using belongi, so we can improve the product.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR) — understanding and improving the service, with no personal data involved.
Kept for: Indefinitely, for the same reason as anonymous event counters above.
3e) Reports and safety data+
What: Information you send us when you report a concern (for example by email), or information we process when investigating reports about you.
Why: To investigate potential violations of our Community Guidelines and Terms of Use, and to keep the community safe.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR) — specifically, protecting users and enforcing platform rules.
Kept for: As long as needed to complete the investigation and any related enforcement action. Records involving serious violations (e.g. bans) may be retained longer.
3f) Banned account identifiers+
What: A one-way hash of your email address if your account is banned.
Why: To enforce the ban and prevent that email address from being used to create a new account — including after the ban is lifted, so that a banned account can't be reinstated and then used to register a fresh account, bypassing the ban. This protects the safety of the community.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR) — protecting other users from repeat harm.
Kept for: Permanently, even if the ban is later lifted, unless removal is required by applicable law.
3.2) Stored only in specific situations
These only exist if the thing they describe actually happens: you create a hangout, add a friend, contact us, or sign up through a campaign or referral link.
3g) Hangout data+
What: Hangout details you create or apply to — title, description, location postcode, venue or address notes where provided, timing and duration, maximum number of participants, categories, languages, cost information, an optional event link, accessibility notes (wheelchair accessible, sensory-friendly, dogs allowed), and optional age, gender, or language filters for participants.
Why: To provide the core hangout discovery and coordination service.
Legal basis: Performance of a contract (Article 6(1)(b) GDPR).
Kept for: We aim to delete hangout data after the hangout has ended. If a hangout is cancelled before it takes place, its data (including group chat) is kept until either the original scheduled end time passes, or one hour after every participant has seen the cancellation notice — whichever happens first — so the chat remains available to participants during that window. Data may be retained longer where needed for safety, abuse prevention, or legal reasons.
3h) Chat messages+
What: Text messages you send within hangout group chats, and a timestamp of when you last read the chat.
Why: To enable hangout participants to coordinate plans, and to know when an unread-messages reminder email is worth sending (at most one per streak of unread messages).
Legal basis: Performance of a contract (Article 6(1)(b) GDPR).
Kept for: The chat closes automatically when the hangout ends. We aim to delete message data at the same time, except where retention is needed for safety or legal reasons.
3i) Friends+
What: Your list of confirmed friends, pending friend requests (sent and received), and your personal friend link/QR code (a random code that reveals no other data).
Why: To let you form friendships with other users — friends can see each other's nickname, their hangouts are prioritised in your feed, and they can view and apply to hangouts you've marked as "friends only."
Who can see it: Your friends list is private — no one but you can view it, including your own friends viewing each other. Your friend link shows a stranger only your nickname or username and avatar before they log in.
Legal basis: Performance of a contract (Article 6(1)(b) GDPR).
Kept for: Until you end the friendship or delete your account. On self-service account deletion, all friendships and friend requests are deleted immediately, independent of the 30-day retention period that applies to other account data (see section 3a).
3j) Hangout proposals+
What: When you propose a hangout directly to a friend, this covers the same hangout details as section 3g, plus the time(s) proposed during negotiation (including counter-offers) and who proposed the current time.
Why: To let two friends agree directly on a hangout time before it becomes a hangout visible to anyone else.
Who can see it: Only the proposer and the invited friend. Once both agree on a time, it becomes a regular hangout (see section 3c), and the original negotiation data is deleted once that hangout ends and is cleaned up.
Legal basis: Performance of a contract (Article 6(1)(b) GDPR).
Kept for: A proposal that receives no response within 7 days expires automatically. Declined or expired proposals are permanently deleted 30 days later. If a proposal is accepted, its negotiation data is deleted once the resulting hangout ends and is cleaned up (see section 3g).
3k) Communications with us+
What: Emails or messages you send us via Contact.
Why: To respond to your enquiry and keep a record of support interactions.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR).
Kept for: As long as reasonably necessary to resolve the matter.
3l) Campaign attribution+
What: If you register after arriving via a marketing link carrying campaign parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term), we record those values once, at the moment your account is created. Nothing is recorded if you did not arrive via such a link.
Why: To measure which marketing channels and campaigns lead to registrations.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR) — measuring marketing effectiveness.
Kept for: As long as your account is active. Deleted when you delete your account, on the same schedule as the account data described in section 3a.
3m) Referral attribution+
What: Whether you registered via another member's personal referral link (see section 3i) — not which member referred you. This stays "no" if you did not arrive via such a link.
Why: To measure how many registrations come from members referring other members.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR) — measuring referral effectiveness.
Kept for: As long as your account is active. Deleted when you delete your account, on the same schedule as the account data described in section 3a.
3n) Feature suggestions and votes+
What: The title and description of a feature you propose, whether you chose to show your username or post as "Anonymous User", and a record of which suggestions you voted for.
Why: To run a feature-request board where users can propose and vote on what we should build next.
Who can see it: Suggestion text and vote counts are visible to all signed-in users. If you post anonymously, your account is never linked to the suggestion in anything other users or admins can see. Your individual votes are never shown to anyone.
Legal basis: Legitimate interests (Article 6(1)(f) GDPR) — specifically, understanding what our users want us to build.
Kept for: Until the suggestion is picked up for development, or you delete your own suggestion (which you can do at any time). Votes are deleted along with the suggestion they belong to, or when you delete your account.
3.3) Optional, and only with your consent
You choose whether to turn these on, and you can withdraw your consent at any time without losing access to belongi.
3o) Notification preferences+
What: Your notification preferences (e.g. whether you have enabled email notifications for hangout events such as application updates, acceptances, or reminders; whether you have separately enabled email and push notifications for a friend creating a new hangout and for a partner organiser publishing a new event; which hangout categories, if any, you have excluded from those notifications; and whether you have chosen to receive them even when they conflict with your connected calendar).
Why: To send you only the notifications you have opted into, and to honour opt-outs.
Legal basis: Consent (Article 6(1)(a) GDPR). Email notifications are optional — you can enable or disable them at any time in your account settings. Withdrawing consent does not affect the lawfulness of processing before withdrawal.
Kept for: As long as your account is active. Deleted when you delete your account.
The inactivity warning email described in section 3a is sent regardless of this setting, since it relates to your account's status rather than optional engagement content — the same treatment as verification and password-reset emails.
3p) Calendar connection+
What: If you connect your Google Calendar while proposing a hangout, we store an encrypted copy of the OAuth refresh token Google issues, plus a one-way hash of your Google account's stable identifier (used only to prevent the same Google account being connected to two different belongi profiles). We never store your calendar's content — no event titles, attendees, or locations. We only ever read live "free/busy" time blocks from Google at the moment you open a suggested-time view, and we don't retain that information afterward.
Why: To show you (and, where relevant, the friend you're proposing a hangout to) suggested free time slots when scheduling a hangout, without either of you needing to manually check your calendar.
Who can see it: Only you see the suggested slots derived from your own calendar, on your own screen. If you and a friend are proposing a hangout time to each other and both have connected a calendar, each of you sees slot suggestions based on the intersection of both calendars' free/busy data — never the other person's raw calendar or event details.
Legal basis: Consent (Article 6(1)(a) GDPR) — connecting a calendar is entirely optional and requires your explicit authorisation via Google's own consent screen. You can disconnect at any time from your profile, which also revokes belongi's access on Google's side.
Kept for: The encrypted refresh token and account hash are kept until you disconnect your calendar or delete your account, whichever happens first. Free/busy data is never stored — it's read from Google at the moment a suggested-time view is shown and discarded immediately afterward.
belongi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3q) Push notifications+
What: If you enable push notifications in your browser or the mobile app, we store the technical identifier needed to deliver them — in the browser, a push subscription (your browser's endpoint URL and encryption keys); in the mobile app, a device-specific push token. This identifier is linked to your account only to route notifications to your device.
Why: To deliver push notifications for hangout events (e.g. new applications, accepted applications, or a friend creating a new hangout), where you've enabled this.
Legal basis: Consent (Article 6(1)(a) GDPR) — push notifications require your explicit permission via your browser's or device's own prompt and are entirely optional.
Kept for: As long as your account is active and the identifier remains valid. Identifiers a delivery attempt reports as invalid (e.g. after uninstalling the app or revoking permission) are removed automatically. Deleted when you delete your account.
3r) Organiser events and reach statistics+
What: If your account has been granted organiser access, the events you publish: title, description, venue name and street address, postcode, date, time and duration, cost information, an optional event link, categories, languages, and accessibility notes (wheelchair accessible, sensory-friendly, dogs allowed). We also record, per event, the number of members who viewed it on each day and the number of hangouts members created from it. These are counts only. We do not store which member viewed which event: a temporary technical marker prevents the same member being counted twice in one day, and it is discarded within 48 hours.
Why: To display events to members, and to show organisers how many people their events reached.
Who can see it: Event details are visible to all logged-in members, together with the organiser's display name. Reach statistics are visible only to the organiser who published the event, and to our administrators.
Legal basis: Performance of a contract (Article 6(1)(b) GDPR) for publishing the event; legitimate interests (Article 6(1)(f) GDPR) for the aggregate reach statistics, which allow organisers to assess the value of the service and contain no personal data about viewers.
Kept for: Event data is deleted once the event has ended, on the same basis as hangout data in section 3g. Reach statistics, together with the event's title and date needed to label them, are retained for one year after the event date and then deleted automatically. All statistics relating to an organiser's events are deleted immediately if that organiser's account is deleted.
4) What we do NOT collect
- No photos. belongi does not allow profile photos or photo sharing. Avatars are preset illustrations only.
- No precise location tracking. We collect a Berlin postcode for hangout matching. Exact addresses may be entered by organisers and shared only with accepted participants — we do not track your device location.
- No payment data. belongi does not process payments. Any costs associated with a hangout are handled directly between you and the organiser or venue.
- No marketing profiling. We do not use your data for advertising or sell it to third parties.
- No AI training. We do not use your data to train, fine-tune, or improve machine learning or AI models — ours or anyone else's.
- No calendar content. If you connect a calendar (see section 3p), we only ever read free/busy time blocks — never event titles, descriptions, attendees, or locations.
5) Who we share your data with
We do not sell your data. We do not share it with third parties for marketing purposes.
We may share data only with the following processors and in these limited circumstances:
- Hetzner Online GmbH — hosting and database infrastructure in the EU, under a Data Processing Agreement.
- Sweego — transactional and notification email delivery (e.g. verification, password reset, and hangout notifications), processing your email address and message content only on our instructions.
- Anthropic PBC — when you use the optional "pre-fill from URL" feature, the public content of the event page you paste is sent to Anthropic's Claude API (the Haiku model) to generate a short description. Only that page content is sent — never your profile or other hangout data.
- Google LLC — not as a processor acting on our behalf, but only if you choose to sign in with Google (see section 3a) or to connect your own Google Calendar (see section 3p). For sign-in, we receive your email address, your Google account identifier and, where your Google account shares one, your date of birth — once, at the moment you sign in; we request no ongoing access to your Google account. For the calendar, we request only the minimum permission needed to read free/busy time blocks, never event content. You grant either access directly via Google's own consent screen; calendar access can be revoked at any time from your profile, and any grant can be revoked from your Google account settings.
- Legal obligations — if we are required to disclose data by law, court order, or a competent authority.
- Safety — in exceptional cases where disclosure is necessary to prevent serious harm.
6) Your rights under GDPR
As a user in the EU, you have the following rights regarding your personal data:
- Access — you can request a copy of the personal data we hold about you.
- Rectification — you can ask us to correct inaccurate data.
- Erasure — you can ask us to delete your data ("right to be forgotten"), subject to legal retention requirements.
- Restriction — you can ask us to restrict processing of your data in certain circumstances.
- Portability — you can request your data in a structured, machine-readable format.
- Objection — you can object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, you can withdraw it at any time.
To exercise any of these rights, contact us. We will respond within 30 days.
7) Right to lodge a complaint
If you believe we have handled your data unlawfully, you have the right to lodge a complaint with a data protection supervisory authority.
In Germany, the relevant authority is:
The Federal Commissioner for Data Protection and Freedom of Information (BfDI)
Graurheindorfer Str. 153, 53117 Bonn, Germany
www.bfdi.bund.de
You may also contact the supervisory authority in the EU member state where you live or work.
8) Changes to this policy
If we make material changes to this Privacy Policy — particularly changes that affect how we process your personal data — we will notify you by email or via an in-app notice before those changes take effect, as required by GDPR Article 13(3).
For minor, non-material changes, the updated policy will be posted on this page with a revised date. The latest version is always available at Updates.
Attributions
Croodles - Doodle your face by vijay verma, licensed under CC BY 4.0. Used via DiceBear (remixed). Background colour added.
Icons by MingCute Icon, licensed under Apache License 2.0.
Imprint
Bárbara Araújo da Silva Borges
Weierbornstraße 73-75
53123 Bonn
Germany
Contact
For questions, safety concerns, support, privacy requests, or complaints about enforcement decisions, use our contact form:
Or email us directly at support@belongi.app
We are a small team and aim to respond you as soon as possible, within 30 days. Thanks for your patience!