Last updated: 2026-09-10
Project Easy exists to pull people from screens back into life. We honor that principle in data too — we collect as little as possible. Below you'll find exactly what, why, and for how long.
At sign-up we only take: • Name (your display name) • Email address (login and OTP) • Password (bcrypt-hashed — even we can't read it; no password is stored for Google sign-in) • Account type (Individual / Organisation) • Phone number (optional; stored in E.164 format, used only to let friends find you, never shown publicly, never used for marketing; you continue with the same number in the mobile app) • KVKK/GDPR consent (moment and policy version) If you sign in with Google we receive only your name, email and profile photo from Google. We access nothing else in your Google account. During onboarding and in your profile you may optionally share preferences — interests, energy, social preference, preferred city and age range — solely so we can recommend better.
To recommend the right event to the right person we record some in-app interactions: the cards you view and tap, events you like and save, what you add to your calendar, plans you create or join, and the city and category filters you choose. This is used only to personalise your Flow, reduce content you won't care about and measure event variety in your city. Profiling is for in-app recommendations only and has no legal or similarly significant effect. You can object to personalisation at any time — write to us and we reset your recommendation history.
If you enable “Near me”, your browser sends us an approximate location (lat/lng); we use it only to sort the current list by distance and do not store it on your account. Location permission is optional — picking a city works too. To place events and venues on a map we geocode their addresses with OpenStreetMap (Nominatim) — that concerns event data, not you.
Only to run the app for you: verify your account, personalise recommendations, match your plans and friend requests, send invites and notifications, deliver OTP codes. No ads; we never sell your profile.
We do NOT share your data with third parties. Only these technical providers process limited data: • Sign-in: Google (only if you choose Google sign-in) • Email delivery (OTP / invites): Resend • Hosting and database: Emergent infrastructure + MongoDB • Translation and Easy AI: Google Gemini — event texts and your chat messages only; no account data • Event data and images: Ticketmaster/Biletix, Wikipedia, OpenStreetMap and the events' own source pages — none of your data goes there Plans you share and “Shall we go together?” invites are visible only to the people you pick. Providers may not use your data for their own purposes.
No tracking cookies. Your browser only keeps: your session token (to stay signed in), language, chosen city and the “Near me” setting. The session token is removed when you sign out.
As long as your account is open. Interaction data is kept for at most 24 months, then anonymised. To delete your account email info@projecteasy.org — we permanently erase everything within 30 days (except legal retention duties).
You have the right to: • Know what data is held • Correct wrong data (most of it you can edit in your profile) • Erasure (right to be forgotten) • Portability • Object to personalisation and profiling, withdraw consent Write to us to exercise any of these — we answer within 30 days.
Questions, deletion requests or concerns: info@projecteasy.org
This policy is guided by Türkiye KVKK (6698) and EU GDPR. It's a living document — if anything material changes, we'll tell you.