Privacy policy
What we keep, why, for how long and how to erase it. Written against the code we run today, not against a template.
Last reviewed: 26 September 2026 · Version 1.1
1. Who processes your data
CityVibe (cityvibe.guide) is a catalogue of events in Spain. You can use almost all of the site without telling us anything: searching, filtering, reading an event page and opening the organiser's link needs no account.
We have no data protection officer: we do not process data on a large scale or any special categories, so article 37 of the GDPR (opens in a new tab) does not require us to appoint one. If that changes, we will say so here.
2. What we keep, why, and on what legal basis
2.1 Your account (only if you sign in with Google or Telegram)
Internal identifier (UUID)
- Where it comes from
- We generate it
- What for
- Being you in our database
Provider identifier (Google's “sub”, your numeric Telegram id)
- Where it comes from
- From the provider, already verified
- What for
- Recognising you next time
Email address
- Where it comes from
- From Google, if you sign in with Google
- What for
- Telling accounts apart. We do not send email
Name and profile picture
- Where it comes from
- From Google or Telegram
- What for
- Greeting you by name on the site and in alerts
Language, city and time zone
- Where it comes from
- You choose them
- What for
- Showing you the site in your language and writing to you at your city's hour
Legal basis: performance of the contract — article 6(1)(b) GDPR (opens in a new tab). You asked for an account; without this data there is no account.
Two things worth knowing:
- We never merge accounts by email address. If you sign in with Google and later with Telegram and both carry the same address, they stay two separate accounts until you link them yourself from your profile. An email address does not prove who you are.
- If an address already belongs to another account, the new account is created without an address; nothing is merged.
2.2 Your alerts
We keep what you asked to be told about: cities, categories, maximum price, frequency (straight away or a daily digest), the time slot you prefer and the channel.
Legal basis: contract (article 6(1)(b)). It is literally the service you asked for.
2.3 Telegram
If you press Start in our bot we keep your Telegram id and the timestamp that says “this person can be written to”. When Telegram tells us you have blocked the bot we erase that mark and stop trying. We never store the text of your messages to the bot.
Legal basis: contract. Your “Start” is the request.
2.4 Delivery log
For every alert we send you we keep: to whom, about which event, through which channel, when it was due, when it left, whether it succeeded and, if it failed, the technical reason. We do not store the text of the message.
What it is for: not writing to you twice about the same event (it is the anti-duplicate key), retrying what failed, and knowing when to stop insisting. After 180 days we blank the times and the failure reason on every settled delivery: only your identifier, the anti-duplicate key and the status stay. A year of “this person looks at their phone at 13:45” is not something we need.
Legal basis: contract, and also legitimate interest (article 6(1)(f) (opens in a new tab)) in not becoming a bot that repeats the same alert. Getting the same alert twice is the number one reason anyone mutes a bot: avoiding it helps you before it helps us.
What we do NOT do: today we do not record whether you open an alert or click it. The columns exist in the database but no code writes them. If we ever start measuring it, we will say so here before we do, with its legal basis and its erasure period.
2.5 Browser push notifications
If you turn push notifications on, your browser gives us a delivery address (an “endpoint” of your browser's push service) and two encryption keys. They tell us neither who you are nor where you are; they only let your browser receive the message.
Legal basis: contract, plus the permission your own browser asks you for.
2.6 Technical logs
Our own servers write no request log: we switched it off, because that line carried the IP address of whoever is asking and the whole query — which is what someone types into the search box. The logs that do exist are our infrastructure providers' (section 4): they include the time, the path requested, the response code and the IP address the request came from, and they exist to spot breakdowns and attacks.
What we never write in our own logs: IP addresses, email addresses, names, session tokens, Telegram “initData” or request bodies. When we log something about a person, it is their internal identifier and nothing else. Not even in the internal admin panel: of every sign-in attempt we keep a pseudonym derived from the address, not the address.
Legal basis: legitimate interest (article 6(1)(f)) in keeping the service up and secure.
2.7 What we do not do, said plainly
- There is no analytics. No Google Analytics, no Plausible, no PostHog, no pixels, no Vercel Analytics. None.
- There is no advertising and there are no advertising cookies.
- We do not sell or share your data with anyone.
- We do not profile you and we take no automated decisions that affect you (article 22 GDPR (opens in a new tab)).
- We do not guess your city from your IP address. Your city is stored only if you choose it.
- There are no accounts for under-14s. The service is aimed at adults. We publish family events, but the person creating the account is the adult. We make no attempt to infer anyone's age. If we find an account belonging to a child under 14, we delete it (article 7 LOPDGDD (opens in a new tab)).
3. How long we keep it
- Account, preferences, alerts
- As long as you have the account
- Delivery log
- As long as you have the account (it is what stops an alert repeating). After 180 days the times and the failure reason are blanked
- Push subscriptions
- Until you turn them off or delete the account
- All of the above
- Erased immediately when you delete your account (section 5)
- Technical logs
- Up to 30 days at Vercel; 90 days for DigitalOcean's deploy logs. We keep none of them ourselves
4. Who else sees anything
These providers process data on our behalf (processors, article 28 GDPR (opens in a new tab)):
Vercel
- What for
- Serving the website and the Mini App
- Where
- Region “fra1” (Frankfurt, Germany)
- What they see
- Requests and their IP addresses
DigitalOcean App Platform
- What for
- Hosting the API, the worker and the scheduler
- Where
- Region “fra” (Frankfurt, Germany)
- What they see
- Requests and their IP addresses
DigitalOcean Managed Databases
- What for
- The PostgreSQL database
- Where
- Region “fra1” (Frankfurt, Germany)
- What they see
- Everything in section 2
DigitalOcean Managed Databases (Valkey)
- What for
- The task queue
- Where
- Region “fra1” (Frankfurt, Germany)
- What they see
- Internal task messages
In addition:
- Telegram inevitably receives the messages we send you and your chat id: it is the channel you asked us to write through. Telegram is an independent controller of what it does with that information; its policy is its own (telegram.org/privacy (opens in a new tab)).
- Google is involved only during sign-in, if you choose that button, and returns your identifier, your verified email address, your name and the URL of your picture.
Everything above sits in the European Union, in Frankfurt. And today no artificial intelligence service receives anything from us: the production servers carry no Anthropic key, nor any other AI provider's, so machine translation of event text is switched off. Even when it is on, all that leaves here is the title and description the source published — never anything of yours. So apart from Telegram and Google, which are involved because you chose them and which answer for themselves, there is no international transfer at all. The day we switch it on, we will write it here first.
5. How to delete your account, and what exactly disappears
In Your profile → Delete account (or by calling “DELETE /users/me”). There is no email confirmation, no grace period and no way back: your user row is deleted on the spot and the database takes with it, in the same operation, everything that pointed at you:
- Your sign-in identities (Google, Telegram).
- Your alerts and their city filters.
- And their category filters.
- Your push subscriptions.
- Your delivery log.
Four of those tables point straight at your account and the two filter tables hang off your alerts: six in all, and there is not one more in the whole database. After deletion, any session still open on another device resolves to nobody: there is no need to wait for it to expire.
The only thing that survives is the technical log line saying “account deleted” with your former internal identifier: it no longer leads to a person and it is our proof that we honoured the request.
Signing out on every device is a different thing and deletes nothing: it increments an internal counter that invalidates every session cookie ever issued to you at once.
6. Your rights
You may exercise, at any time and free of charge, the rights in articles 15 to 22 of the GDPR (opens in a new tab):
- Access — knowing what we hold
- Write to alexandr.shurigin@gmail.com (opens in a new tab) and we will send you a copy
- Rectification — correcting it
- Your name, language and city you change yourself in Your profile
- Erasure — deleting it
- Your profile → Delete account, immediate (section 5)
- Portability — taking it with you
- Ask by email and we send it as machine-readable JSON
- Objection and restriction
- By email; turning your alerts off is also enough
- Withdrawing your consent
- For push, in your browser; for Telegram, by blocking the bot
We answer within one month at most (article 12(3) GDPR). If you think we have not done it properly, you can complain to the Spanish Data Protection Agency (aepd.es (opens in a new tab)), C/ Jorge Juan 6, 28001 Madrid. We would be grateful if you wrote to us first: it is almost always faster.
7. Security
What we do, in short: the session travels in an encrypted cookie only our server can open, marked “HttpOnly”, “Secure” and with the “__Host-” prefix; the browser never talks to our API directly; the identity of whoever calls the API travels in a signed token that expires in 60 seconds; and secrets live in environment variables, never in the code.
No system is infallible. If a breach happens that puts your rights at risk, we will tell you and notify the AEPD within the 72 hours set by article 33 GDPR (opens in a new tab).
8. Changes
If we change something that really affects you — a new purpose, a new provider, analytics — we will announce it on the site before it takes effect. The date above is that of the last review.