Villages Ltd — Legal

Privacy Policy

Who this is from
Villages Ltd, registration in progress
Contact
support@villages.mobile
Effective date
[EFFECTIVE DATE — TO BE SET ON PUBLICATION]
Last revised
[REVISION DATE — TO BE SET ON PUBLICATION]

The short version

Villages is an app for a small group of neighbours who share one village. It deliberately sends you to a real place — your village's Town Hall — to do certain things, so it needs to know that you are standing there at that moment. It does not need to know where you live, and it does not ask.

Three things are worth knowing up front.

  1. We never ask where you live. There is no home address, no home location, no home verification anywhere in the product.
  2. Location is only ever read in the foreground, at the moment you act at the Town Hall, and your coordinates are not kept.
  3. A letter's words are held back until you collect it in person. That is enforced by the database itself, not by the app being polite about it.

The rest of this document explains all of that properly.

Who we are

Villages Ltd (registration in progress) provides the Villages app and is responsible for the personal information described here. You can reach us at support@villages.mobile about anything in this document.

Open decision

The entity is not yet registered. Counsel must confirm which legal person is the data controller in the period before registration completes, and whether any registration number, registered office address, data protection representative or DPO must appear here.

What we collect

Your account and profile

Your name, your handle, your email address, and — if you choose to add them — a short bio and an avatar image. Authentication is handled for us by Supabase; the password itself is not visible to us.

Your village

Which village you belong to and what role you hold in it. A Village Chief is the person who founded or now stewards the village; everyone else is a member.

Your house

A house in a village is a symbolic plot with a house number. It has no geographic meaning at all — it is not tied to a real address or to any coordinates, and nothing in the app is unlocked by being at it.

The things you post

Posts, comments and likes in your village's Town Hall feed. Gatherings you host — including the venue details and time you type in — and your RSVPs to other people's gatherings. Rituals you create or complete. Images you attach to any of that.

Letters

A letter is a private typed page between two members of the same village. It is typed, not photographed — there is no camera scan and no text recognition anywhere in the product. We store the sender, the recipient, the village, the state the letter is in, the times it moved between those states, and the text of the letter itself so that it can be handed over.

Your Story

During onboarding you are asked a series of questions. Your answers are stored, and they are sent to OpenAI to generate the short poem that appears on your profile. The generated poem is stored with your profile.

Notifications

If you allow push notifications, we store the push token your device gives us and your per-notice preferences, so we can send the notice and so we can stop sending it when you turn it off.

An in-app event log

We record a small set of named product events — for example that a Town Hall was opened, a letter was sent, a ritual was completed — with the village they happened in and a few plain properties. This log lives in our own database. It is not sent to a third-party analytics company. By design it does not carry coordinates, letter text, or your onboarding answers.

Subscription state

If you are a Village Chief who pays for village stewardship, we store the state of that subscription — whether it is active, in a grace period, expired, when it renews, and which product it is. Payment itself happens through Apple; we never see your card details.

What we do not collect

This list is deliberate, and it is enforced in the schema rather than left to good intentions.

  • No home address. We do not ask for one, store one, verify one or infer one.
  • No home location. There are no home coordinates and no home verification. Nothing is unlocked by "being at home", because the app has no idea where home is.
  • No doorstep or hand delivery. Letters do not go to houses. They go to the Town Hall.
  • No background location. The app does not track you while it is closed or in the background, and there is no movement history.
  • No camera-scanned letters. The scan-and-recognise pipeline was retired, and the private storage bucket it used is gone.

Living near your village's Town Hall is a suggestion we make in the copy. It is never a fact we check.

How location actually works

Town Hall presence is the single location primitive in the whole product. There is no other place where the app reads where you are.

When it is read. Only in the foreground, and only at the moment you take one of these actions at your village's Town Hall:

  • checking in at the Hall,
  • posting to the Town Hall feed,
  • dropping a letter off,
  • collecting a letter.

Nothing is captured between those moments.

What happens to the reading. Your coordinates are sent to the server, compared against the Hall's position, and not stored. What is kept alongside the action is the resulting distance from the Hall and the accuracy figure your device reported — nothing that could place you anywhere else.

What gets rejected. A location fix whose reported accuracy is worse than 150 metres, or which is more than about two minutes old, is refused. You will be asked to try again rather than quietly let through.

How long a check-in lasts. A Town Hall check-in expires 30 minutes after you make it.

How letters handle your words

The mechanic and the privacy protection are the same thing here, so it is worth being precise.

When you write a letter, it sits with you until you physically go to your village's Town Hall and drop it off. Your presence at the Hall is verified at that moment. From then, the letter waits at the Hall until the recipient physically goes there and collects it — their presence is verified too.

The text is released only on collection. Until then, an ordinary client cannot read the letter's text at all. This is not a matter of the app hiding a field: the database does not grant read access to that column to any ordinary account. The text comes back from exactly one operation — collecting the letter, standing at the Hall.

A notice that a letter is waiting carries no letter text. The push notification path is held inside the same restriction, so it is not capable of putting your words into a notification payload even by mistake.

Notices respect a night curfew. A letter dropped between 23:00 and 06:00 in the village's local time surfaces at 06:00. Villages default to Europe/London time. This too is enforced as a database read rule, which means that before that moment the recipient cannot see that the letter exists at all — not merely that they cannot read it.

Who else processes your information

We keep this list short on purpose.

Processors and what reaches them
Who What they do for us What reaches them
Supabase Database, authentication, file storage and our server functions Everything described above. Hosted in the eu-west-1 region.
Expo push service and Apple's push notification service Delivering push notifications to your device Your push token and the text of the notice. Never letter text.
OpenAI Two things only: automated safety screening of submitted content, and generating your "Your Story" poem from your onboarding answers The content being screened, and your onboarding answers. This content leaves the Supabase environment.
RevenueCat and the Apple App Store Subscription state for the paid village stewardship a Village Chief buys Subscription and purchase state. Members never pay and have no billing record.

Open decision

Counsel must set out the transfer mechanism and safeguards for any personal data that leaves the UK/EEA — in particular the content and onboarding answers sent to OpenAI — and confirm whether a transfer risk assessment and standard contractual clauses are required. Counsel must also decide whether Google Play and Android push are in scope for launch; the build currently carries configuration for them, but the shipping plan is Apple only.

Who can see what

  • Your profile is visible to other members of your village.
  • Town Hall posts, comments and likes are visible to members of your village who are entitled to read that feed.
  • Gatherings and RSVPs are visible to members of the village the gathering belongs to.
  • A letter is visible to its sender and its recipient only — and its text only to the recipient, only after collection.
  • A limited public directory of Town Halls exists so that people can find a village to join. It carries the Hall's venue information, not member information.
  • Blocking someone stops their new Town Hall items appearing in your feed.
  • Our moderators can see reported content and the content in the review queue.

How long we keep things

Your content stays until you delete it or delete your account. Beyond that, we are not going to invent numbers here.

Open decision

Retention windows have not been set for: the analytics event log, moderation reports and decision records, collected letters, expired Town Hall check-ins, or backups taken by our hosting provider after an account has been deleted. Counsel and the founder must set each of these before this policy is final, and this section must then state them plainly.

Deleting your account

You can delete your account from within the app. Deleting removes the files you own — your avatar and images you posted — and your authentication record, and the rows that depend on your account follow it.

One exception: if you are a Village Chief and your village has other members, you must transfer the Chief role to someone else first. The app will refuse the deletion and tell you so. This is to stop a village being left without a steward.

Open decision

There is currently no in-app data export. Counsel should confirm whether a portability route must exist at launch and, if so, how a request should be made and answered.

Security

Access to your data is controlled at the database level rather than in the app, so a bug in the interface cannot hand out something it should not. The clearest example is letters: the text is simply not readable by an ordinary account, no matter what the app asks for. Server functions run with narrow, explicitly granted access rather than blanket permissions.

No system is perfect, and we will not claim otherwise.

Your rights

Depending on where you live, you may have rights to see the information we hold about you, to correct it, to have it deleted, to object to some uses of it, or to complain to a regulator.

To ask about any of this, write to support@villages.mobile.

Open decision

The applicable data protection framework, the lawful basis relied on for each purpose, the supervisory authority to which a complaint can be made, and the response deadline we commit to are all outstanding. Counsel must settle them and this section must then name them specifically rather than in general terms.

Children

Open decision

The minimum age to use Villages has not been set, and no age gate has been decided. Counsel and the founder must set a minimum age, decide how it is checked at sign-up, and decide the position on parental consent. This must be resolved before submission, because the App Store age rating depends on it.

Changes to this policy

If we change what the app does with your information, we will change this document and update the revision date at the top.

Open decision

How material changes are notified — in-app notice, email, or both — and how much notice is given, are not yet decided.

Contact

support@villages.mobile
Villages Ltd, registration in progress

← All legal documents