Who is responsible
Coviva is a group-travel planning app operated by Patrik Šťastný, an individual based in the Slovak Republic ("Coviva", "we", "us").
We are the data controller for the personal data described here, within the meaning of the EU General Data Protection Regulation (GDPR). You can reach us at info@coviva.app about anything in this policy.
You can browse Explore without an account. In that case we hold no account data about you at all — only the technical request data described at the end of section 2.
What we collect and why
We collect only what the features you use actually require. Each table names the legal basis under GDPR Article 6.
Your account and profile
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Signing in with a one-time code, and reaching you about your account | Contract |
| Display name, short bio, profile photo | Identifying you to the other members of your groups | Contract |
| Interface language | Showing the app in your language; stored on your device only | Contract |
What you create in a group
| Data | Purpose | Legal basis |
|---|---|---|
| Group name, destination, cover photo, membership and invite codes | Running the group | Contract |
| Chat messages and the photos attached to them | Group chat | Contract |
| Expenses: amount, currency, who paid, how it is split, description, receipt photo | Splitting costs and showing who owes whom | Contract |
| Documents you upload, plus their file name, size and type | The group's shared document folder — tickets, bookings, insurance | Contract |
| Places you save or publish: name, description, category, tags, coordinates, photos, likes | Group planning and, if you publish a place, the public Explore feed | Contract |
| Notes, checklist items, polls and your votes, accommodation entries | Group planning features | Contract |
Location
| Data | Purpose | Legal basis |
|---|---|---|
| Precise device location | Showing places near you in Explore and the distance on a place card. Used on your device and sent to the map and place-search services; we do not store it. | Consent |
| Live location in a group: coordinates, accuracy, timestamp and the expiry time you chose | Showing your position on the group map. Off by default, started only by you, for a duration you pick, and it stops on its own when that time is up. It runs only while the app is open — we never collect your location in the background. | Consent |
You can withdraw location consent at any time by turning sharing off in the group or revoking the permission in your device settings. The rest of the app keeps working.
Camera and photo library
The app asks for camera access to scan group invite QR codes and photograph receipts, and for photo library access so you can attach pictures to places, expenses, group covers, chat and your profile. We only ever receive the individual files you pick — never your library as a whole.
Notifications
| Data | Purpose | Legal basis |
|---|---|---|
| Push notification token and platform (iOS / Android) | Delivering notifications to the right device | Contract |
| Your per-type notification settings | Respecting which notifications you asked for | Contract |
Reports and moderation
If you report a place or another user's profile, we store what you reported, the optional reason you wrote, and that the report came from you — so we can act on it and so the same thing is not reported twice.
Legitimate interest keeping the app free of abusive content.
Technical data
Our hosting providers automatically log requests to our servers — IP address, timestamp and what was requested. We use these logs to keep the service running and to detect abuse. This applies to everyone using the app, including guests browsing Explore without an account.
Legitimate interest security, abuse prevention and availability.
What we don't do
- We don't sell, rent or trade your personal data.
- We don't show ads, and the app contains no advertising SDK.
- The app contains no analytics, attribution or tracking SDK, and we don't track you across other apps or websites.
- We don't offer third-party social login, so no social network learns that you use Coviva.
- We don't process payments. Expense splitting is a shared ledger between members — no money moves through the app, and we never see a card or bank account.
- We don't make automated decisions that produce legal or similarly significant effects on you.
- We don't build marketing profiles of you.
Who can see your data
The other members of your groups
Anyone who is in a group with you can see:
- Your display name, profile photo and bio.
- The email address you signed in with — it is shown to fellow members alongside your name.
- Everything you post in that group: messages and photos, expenses and receipts, documents, notes, checklist items, poll votes and saved places.
- Your live location on the group map, but only while you are actively sharing it.
Group content is restricted to that group's members at the database level. People in one of your groups cannot see anything from your other groups.
Everyone
A place you choose to publish appears in the public Explore feed together with its photos, description and the profile of whoever added it. Photos attached to a published place, profile photos and group cover images are stored on a public media domain, which means anyone holding the exact link can open the file without signing in. Documents and receipt images are not stored this way — see section 7.
Nobody else, unless the law requires it
We may disclose data if we are legally obliged to — a valid order from a competent authority — or where it is necessary to establish, exercise or defend legal claims.
Service providers we use
A small number of vendors help us run the app. Each processes data on our instructions under a data processing agreement, and none of them use your data for their own purposes.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Sign-in, database, realtime updates and server-side functions. Hosted in the EU (Stockholm). | All account and group data |
| Cloudflare | Storage for photos and documents, and the service that issues upload and download links | Your uploaded files, your IP address |
| Brevo | Sending your one-time sign-in code by email | Your email address |
| Google (Firebase Cloud Messaging) and Apple (APNs) | Delivering push notifications to your device | Your push token and the notification text |
| Google (Gemini API) | Generating destination tips — see section 6 | The destination, interests and note your group entered |
| OpenFreeMap | Map tiles | Your IP address and the map area you are viewing |
| OpenStreetMap (Nominatim) | Searching for places and addresses | Your IP address and what you searched for |
| Open-Meteo | Weather forecast and destination look-up for a group | The coordinates of the group's destination — not your device location |
| Frankfurter | Currency exchange rates for expenses | Currency codes only — no personal data |
The map, place-search and weather services are called directly from your device, so they see your IP address the way any website you visit would. We don't send them your name, email or account identifier.
AI-generated tips
A group can ask Coviva to suggest things to do at its destination. When someone taps generate, we send Google's Gemini API three things: the destination, the interests the group selected and the optional note the group wrote — plus the language the tips should be written in.
We deliberately do not send:
- your name, email address or account identifier;
- chat messages, group notes, checklist items, polls or saved places;
- anyone's location.
Google processes this input as our vendor under the Gemini API terms and does not use it to train its models. The tips that come back are stored on the group and visible to its members. Generation is limited to once a day per group.
How we protect it
- All traffic between the app and our servers is encrypted with HTTPS/TLS.
- Every table in our database enforces row-level access rules, so group content can only be read by members of that group — the check happens on the server, not in the app.
- Documents and receipt images live in a separate private storage bucket with no public address. They can only be opened through a signed link that we issue to a verified group member and that expires after 15 minutes.
- Your sign-in session is held in the platform's secure storage — Keychain on iOS, encrypted storage on Android — never in plain text.
- Uploads are checked on the server: we verify who you are and that you belong to the group before a file is accepted, and file sizes and per-group storage are capped.
- Our internal statistics screen is aggregate-only and deliberately excludes group names and group content.
No system is perfectly secure. If we discover a breach affecting your personal data, we will notify the Slovak supervisory authority within 72 hours and inform you directly where the law requires it.
How long we keep it
| Data | Kept for |
|---|---|
| Account and profile | Until you delete your account |
| Group content | As long as the group exists. When the last member leaves, the group and everything in it is deleted automatically. |
| Photos in chat | 30 days, then deleted from storage automatically |
| Documents and receipt images | 365 days, then deleted from storage automatically. The entry stays in the group's list, but the file itself is gone. |
| Profile photos, group covers, photos of places | Until the item they belong to is deleted |
| Live location | Sharing stops at the time you set. Your last transmitted position stays on the group record until the group is deleted or you delete your account, whichever comes first. |
| Push token and notification settings | While the app is installed and you are signed in. Both are deleted when you delete your account. |
| Reports | Until the report has been dealt with |
| Server request logs | A short period at our hosting providers, then discarded on their routine schedule |
Deleting your account
You can delete your account yourself, in the app: Profile → edit profile → delete account. It takes effect immediately and cannot be undone — you will not be able to sign back in with that account.
Because Coviva is a shared app, deletion is not a clean sweep of everything you ever typed. Here is exactly what happens.
Erased
- Your sign-in credentials: your email address, every session, and any outstanding one-time codes.
- Your name, bio and profile photo — the name is replaced with "Deleted user" and the photo file is deleted from storage.
- Any location you had shared with a group.
- Your push notification token and notification settings, so the device stops receiving anything.
- Any reports you had filed.
Kept, no longer connected to you
- Messages you sent, expenses you entered or paid, documents you uploaded, checklist items, poll votes and places you added.
- They stay so that the rest of the group keeps a usable trip — removing an expense would silently change what everyone else owes. They appear as belonging to "Deleted user", with no name, photo, bio or email attached.
- Places you had published publicly are switched back to private, so they leave the public Explore feed.
Your rights
Under the GDPR you have the right to:
- Access — receive a copy of the personal data we hold about you.
- Rectification — correct anything inaccurate. Most of it you can edit yourself in your profile.
- Erasure — have your data deleted; section 9 covers what the in-app deletion does and how to ask for the rest.
- Restriction — ask us to limit how we use your data while a dispute is being resolved.
- Objection — object to processing based on our legitimate interests.
- Portability — receive your data in a structured, machine-readable format.
- Withdraw consent — for location and notifications, at any time, in the app or in your device settings. This does not affect anything done before you withdrew it.
To exercise any of these, email us at info@coviva.app. We will respond within one month; if a request is complex we may extend that by two further months and will tell you if that happens. There is no charge unless a request is manifestly unfounded or repetitive.
Complaints
If you think we have handled your data badly, please tell us first — we would rather fix it. You also have the right to lodge a complaint with the Slovak supervisory authority:
If you live in another EU or EEA country, you may complain to your own national supervisory authority instead.
Children
Coviva is not intended for children under 16, and we do not knowingly collect data from them. If you believe someone under 16 has created an account, contact us and we will delete it.
International transfers
Your account and group data is stored in the European Union — our database, storage and server-side functions run in Supabase's Stockholm region.
Some of the providers in section 5 are established outside the EEA or operate global networks, so limited data — a push token and notification text, an email address, an IP address, or the destination text sent for tips — may be processed outside the EEA, including in the United States. Those transfers rely on the safeguards those vendors offer: the European Commission's Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
Changes to this policy
If we change how we handle your data, we will update the "Last updated" date at the top of this page. For material changes we will tell you in the app before they take effect, and where the law requires it we will ask for your consent again.
Contact
Questions about this policy, or about your data? Write to us.