Privacy Policy

Winkly — Privacy Policy

Last updated: 12 September 2026

Kateryna Shyshkalova (“we”, “us”, “Winkly”) respects your privacy. This Privacy Policy explains what personal data we collect, how we use it, and your rights. It applies to the Winkly mobile application and related services (“Service”).

Winkly is currently operated by a private individual; responsibility will transfer to Winkly UG (haftungsbeschränkt) once that company is registered, and this policy will be updated accordingly.

If you are in the European Economic Area (EEA) or the United Kingdom, we process your data in accordance with the General Data Protection Regulation (GDPR) and UK GDPR. We also consider applicable international standards.


1. Data controller and contact

Data controller:
Kateryna Shyshkalova
Olching, Germany

Contact for data protection:
Email privacy@mywinkly.de, or use General settings → Support & legal → Contact Support in the app. General enquiries: info@mywinkly.de.

We are not currently required to appoint a Data Protection Officer; if that changes, the contact will be published here.


2. What personal data we collect

2.1 Account and identity

2.2 Profile information

Depending on your account type and which parts of the app you use:

You choose what to add; we store what you provide to show your profile to other users and to power features (e.g. discovery, matching, AI suggestions).

Date of birth and age. We store your date of birth to confirm you are 18 or older and to calculate your age. Other users only ever see your age, never your date of birth.

2.3 Communications and content

2.4 Technical and usage data

2.5 Device and permissions

2.6 Optional sensitive information (religion)

You may, entirely voluntarily, add religion to your profile. This is a special category of personal data under GDPR Art. 9. We process and display it only on the basis of your explicit consent (Art. 9(2)(a)), which we capture through the data-use notice before you enter any personal data (see section 3). You can remove it at any time, which withdraws that consent for the future. If you do not add it, we do not process it. (The former “allergies” field has been removed entirely.)

We do not sell your personal data.


3. Consent and the data-use notice

Before you enter any personal data, Winkly shows a data-use notice you must accept to continue. Your acceptance is recorded with the date and notice version; if we materially change the notice we ask you to agree again. This explicit consent is, in particular, the lawful basis for any optional sensitive field such as religion (section 2.6). You can withdraw consent at any time — by removing the optional data, turning analytics off, or contacting privacy@mywinkly.de. Withdrawal does not affect processing that already took place.


4. Why we use your data (purposes and legal basis)

Purpose Data used Legal basis (GDPR)
Create and manage your account Email, user ID, account type Art. 6(1)(b) contract
Provide profiles, discovery, matching, chat, planner, events Profile data, messages, planner, events Art. 6(1)(b) contract
Verify you are 18+ Date of birth Art. 6(1)(b)/(c)
Provide Winkly AI suggestions Allow-listed context Art. 6(1)(b) contract / Art. 6(1)(a) consent
Show optional religion on your profile Religion Art. 9(2)(a) explicit consent
Subscription and billing Account and subscription status Art. 6(1)(b) contract
Safety (block, report, abuse prevention) Relevant account and content data Art. 6(1)(f) legitimate interest, legal obligation
Product analytics User ID, account type, screens, event names (no PII) Art. 6(1)(a) consent
Legal and compliance As necessary Legal obligation, legitimate interest

Where we rely on legitimate interest, we have balanced our interests against your rights and you can object. Where the law requires consent, we obtain it first.


5. Who we share data with (processors)

We use a small number of processors to run Winkly. Each is bound by a data-processing agreement (GDPR Art. 28) and processes data only on our instructions. We do not sell your data.

Processor Purpose Data categories Location / transfer basis
Supabase Database, authentication, file storage, serverless functions Account, profile, messages, usage EU region where available; otherwise under EU Standard Contractual Clauses
Google (Gemini API) AI concierge — suggestions Allow-listed profile subset (age, city, interests, dietary preference, budget) — never name, contacts, messages or exact location US; EU Standard Contractual Clauses
Anthropic (Claude API) AI concierge — secondary model Same allow-listed subset US; EU Standard Contractual Clauses
Google Places / Maps Venue and place lookups Coarse city/area and search terms; not your identity US; SCCs
Ticketmaster Real event listings in Events mode Coarse city/area and search terms SCCs
Sightengine (DRAFT — pending lawyer review and signed DPA; alternative under evaluation: Google Cloud Vision SafeSearch, EU endpoint) Automated safety check of profile photos and chat images for explicit, violent or illegal content The image itself and technical metadata; no name, profile text or messages France (EU); processing in the EU
Expo Push notifications Device push token US; SCCs
PostHog Product analytics — only after consent Pseudonymous usage events EU or US, under EU Standard Contractual Clauses where applicable
Sentry Crash reporting Diagnostic/crash data SCCs
Vercel Hosting the website Website request logs US; SCCs

Other users also see your profile and content according to the mode and settings you use. We may disclose data if required by law or to protect rights and safety. The current processor list always lives in this policy at mywinkly.de/privacy.


6. International transfers

Some processors are based outside the EEA/UK (e.g. the United States). Where data is transferred, we rely on European Commission adequacy decisions, or Standard Contractual Clauses (and, where applicable, a processor's certification under the EU–US Data Privacy Framework). Details are available on request via privacy@mywinkly.de.


7. How long we keep your data


8. Your rights

If you are in the EEA or UK you have the rights to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), objection (Art. 21), and to withdraw consent at any time (Art. 7(3)). You can export or delete your data in the app (General settings → Account) or contact privacy@mywinkly.de; we respond within the time the law requires (normally one month).

You also have the right to complain to a supervisory authority. The authority responsible for us is the Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach, Germany — https://www.lda.bayern.de. You may also contact the authority in your own country of residence.

If you are in California or a similar jurisdiction: we do not sell personal data, and you may have rights to know, delete, or correct your data and to non-discrimination; contact us to exercise them.


9. Children

The Service is only for people aged 18 and over. We enforce this at sign-up and in our database, and we do not knowingly collect data from anyone under 18. If you believe a minor is using Winkly, contact privacy@mywinkly.de and we will act.


10. Reporting illegal content (Digital Services Act)

You can report a profile, message, or any content using the in-app report button, or by emailing customer-care@mywinkly.de — you do not need an account to report. We review every report and may remove content, limit or suspend an account, or take no action; when we act, we tell the affected person what we did, why, and how to appeal. See our Community Guidelines for details.


11. Security

We use technical and organisational measures including: access control (row-level security so you can only access your own and permitted data); encrypted connections (HTTPS/TLS) and encryption of sensitive tokens at rest; storing only a coarsened version of location (never exact GPS); restricting the profile data sent to AI providers to a minimal allow-list; and rate-limiting and abuse protections. No system is completely secure; we will notify you and the relevant authority of a breach where the law requires.


12. Changes to this policy

We may update this Privacy Policy as Winkly evolves. We post the updated version and update the “Last updated” date; significant changes are notified in-app where practicable.


13. Cookies and similar technologies

Winkly is primarily a mobile app. We do not use advertising cookies and we do not sell your personal data.

Technology Purpose Required?
Authentication session Keep you signed in securely (Supabase Auth; secure storage on device) Yes — needed to use the Service
Local app storage Remember preferences (e.g. terms acceptance, language) Mostly essential; some optional
Analytics (PostHog) Aggregate app usage (screens, feature events); no name, email, or message content No — we ask for consent before enabling

On first use you can accept or decline non-essential analytics, and you can withdraw consent later in privacy settings or by contacting us. If you visit mywinkly.de, our hosting provider may process standard server logs (e.g. IP address, browser type) for security and operation; we use no third-party advertising trackers.


14. Contact

For privacy questions or to exercise your rights: privacy@mywinkly.de, or in the app under General settings → Support & legal.


By using Winkly, you confirm that you have read and understood this Privacy Policy. For the terms governing your use of the Service, see our Terms of Service.