What's That? What's That?

Privacy Policy — "What's That?"

Effective date: 8 January 2026
Version: 1.0.0

This Privacy Policy explains how we collect, use, disclose, and protect information about you when you use the "What's That?" mobile application and related services (the "Service").

By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.

1) Who we are

2) What we collect

We collect the types of data described below. Exact fields depend on how you use the Service and OS permissions you grant.

Avoid sensitive data: Please avoid uploading images or text that reveal highly sensitive personal information (e.g., medical, financial, government IDs). While our app is designed for places/objects, images may inadvertently capture people or personal data.

3) Sources

4) How we use data and legal bases (GDPR)

We do not use your personal information for third-party advertising. We do not sell or "share" (as defined by CPRA) your personal information.

5) AI providers and model training posture

6) Sharing and recipients

We share data with service providers who act on our behalf to provide the Service:

We may also disclose information if required by law or to protect our rights, users, or the Service, and in connection with corporate transactions.

7) Share links (user-initiated)

If you create a share link for a discovery, the link uses a non-guessable identifier (e.g., UUID). Anyone who has the link can view the shared page and may re-share it. We do not list or index share links in our app, and we set pages to discourage search indexing where supported, but we cannot control third-party indexing or resharing. We do not include precise GPS coordinates or EXIF location data on shared pages; however, the image itself may imply a general location (e.g., recognizable landmarks). You can stop future access by deleting the discovery or disabling the share link (where available); previously shared copies or reposts may persist.

8) International transfers

Our primary infrastructure (Supabase) is hosted in the European Union (Germany, Frankfurt region). AI service providers (Anthropic Claude, Google Gemini, OpenAI, Fish Audio) and mapping providers (Google Places) may process data in the United States and other countries. Apple processes push notifications globally. Where data is transferred outside the EEA/UK, we rely on safeguards such as Standard Contractual Clauses (SCCs) and provider Data Processing Agreements (DPAs). Contact us at privacy@chalabs.xyz for copies of relevant transfer mechanisms where legally permissible.

9) Retention

10) Security

We use technical and organizational measures designed to protect personal information (e.g., TLS in transit, encryption at rest, role-based access controls including database row-level security, private storage buckets with signed URLs, least-privilege access, and audit logging). No system is perfectly secure; we cannot guarantee absolute security. You should keep your device and account credentials secure.

11) Your rights (GDPR/UK GDPR)

Subject to exceptions, you can request: access, rectification, deletion, restriction, objection to processing, and portability. Where processing is based on consent (e.g., location, notifications), you can withdraw consent at any time in OS settings or in-app.

To exercise your rights, email privacy@chalabs.xyz with your request. We will respond within 30 days. We may need to verify your identity before processing your request. You may lodge a complaint with your supervisory authority.

12) California privacy (CCPA/CPRA)

We do not sell or share your personal information. You have rights to know, access, delete, and correct certain information. You can designate an authorized agent. Sensitive information (precise location) is used only to provide the Service you request and is not used for inferring characteristics.

13) Children

The Service is not directed to children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child provided personal information, contact us and we will take appropriate steps.

14) Cookies/SDKs/Tracking

We do not embed third-party analytics or advertising SDKs at this time. If we add analytics or crash reporting in the future, we will update this Policy and, where required, provide controls or obtain consent. Browsers' "Do Not Track" signals are not consistently honored by mobile apps; we currently do not respond to DNT.

15) Automated decision-making

The Service uses AI to generate descriptive content for images, but we do not make automated decisions that produce legal or similarly significant effects about you.

16) Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will notify you (e.g., in-app or by email). Continued use of the Service after changes take effect means you accept the updated Policy.

17) Contact

Questions or requests: privacy@chalabs.xyz
Postal mail: Eduarda Smiļģa iela 32 – 19, Rīga, LV-1002