Skip to content

Privacy policy

What we keep, why, for how long and how to erase it. Written against the code we run today, not against a template.

Last reviewed: 26 September 2026 · Version 1.1

1. Who processes your data

Data controller: Alexander Shurygin · NIF Y4277540Z · Plaza Equipo Crónica, 5 · 46023 València (Valencia), España · alexandr.shurigin@gmail.com (opens in a new tab). An individual, not a company: he decides what is stored, and he is the person you write to. Saying so here is what article 10 of the LSSI-CE (opens in a new tab) requires.

CityVibe (cityvibe.guide) is a catalogue of events in Spain. You can use almost all of the site without telling us anything: searching, filtering, reading an event page and opening the organiser's link needs no account.

We have no data protection officer: we do not process data on a large scale or any special categories, so article 37 of the GDPR (opens in a new tab) does not require us to appoint one. If that changes, we will say so here.

2. What we keep, why, and on what legal basis

2.1 Your account (only if you sign in with Google or Telegram)

  • Internal identifier (UUID)

    Where it comes from
    We generate it
    What for
    Being you in our database
  • Provider identifier (Google's “sub”, your numeric Telegram id)

    Where it comes from
    From the provider, already verified
    What for
    Recognising you next time
  • Email address

    Where it comes from
    From Google, if you sign in with Google
    What for
    Telling accounts apart. We do not send email
  • Name and profile picture

    Where it comes from
    From Google or Telegram
    What for
    Greeting you by name on the site and in alerts
  • Language, city and time zone

    Where it comes from
    You choose them
    What for
    Showing you the site in your language and writing to you at your city's hour

Legal basis: performance of the contract — article 6(1)(b) GDPR (opens in a new tab). You asked for an account; without this data there is no account.

Two things worth knowing:

  • We never merge accounts by email address. If you sign in with Google and later with Telegram and both carry the same address, they stay two separate accounts until you link them yourself from your profile. An email address does not prove who you are.
  • If an address already belongs to another account, the new account is created without an address; nothing is merged.

2.2 Your alerts

We keep what you asked to be told about: cities, categories, maximum price, frequency (straight away or a daily digest), the time slot you prefer and the channel.

Legal basis: contract (article 6(1)(b)). It is literally the service you asked for.

2.3 Telegram

If you press Start in our bot we keep your Telegram id and the timestamp that says “this person can be written to”. When Telegram tells us you have blocked the bot we erase that mark and stop trying. We never store the text of your messages to the bot.

Legal basis: contract. Your “Start” is the request.

2.4 Delivery log

For every alert we send you we keep: to whom, about which event, through which channel, when it was due, when it left, whether it succeeded and, if it failed, the technical reason. We do not store the text of the message.

What it is for: not writing to you twice about the same event (it is the anti-duplicate key), retrying what failed, and knowing when to stop insisting. After 180 days we blank the times and the failure reason on every settled delivery: only your identifier, the anti-duplicate key and the status stay. A year of “this person looks at their phone at 13:45” is not something we need.

Legal basis: contract, and also legitimate interest (article 6(1)(f) (opens in a new tab)) in not becoming a bot that repeats the same alert. Getting the same alert twice is the number one reason anyone mutes a bot: avoiding it helps you before it helps us.

What we do NOT do: today we do not record whether you open an alert or click it. The columns exist in the database but no code writes them. If we ever start measuring it, we will say so here before we do, with its legal basis and its erasure period.

2.5 Browser push notifications

If you turn push notifications on, your browser gives us a delivery address (an “endpoint” of your browser's push service) and two encryption keys. They tell us neither who you are nor where you are; they only let your browser receive the message.

Legal basis: contract, plus the permission your own browser asks you for.

2.6 Technical logs

Our own servers write no request log: we switched it off, because that line carried the IP address of whoever is asking and the whole query — which is what someone types into the search box. The logs that do exist are our infrastructure providers' (section 4): they include the time, the path requested, the response code and the IP address the request came from, and they exist to spot breakdowns and attacks.

What we never write in our own logs: IP addresses, email addresses, names, session tokens, Telegram “initData” or request bodies. When we log something about a person, it is their internal identifier and nothing else. Not even in the internal admin panel: of every sign-in attempt we keep a pseudonym derived from the address, not the address.

Legal basis: legitimate interest (article 6(1)(f)) in keeping the service up and secure.

Retention: whatever each provider keeps, because those logs are theirs and not ours. Vercel keeps runtime logs for up to 30 days on the plan we are on (Runtime Logs (opens in a new tab)); DigitalOcean keeps build and deploy logs for 90 days and does not archive runtime logs at all: they are live only, and we forward them nowhere (App Platform (opens in a new tab)).

2.7 What we do not do, said plainly

  • There is no analytics. No Google Analytics, no Plausible, no PostHog, no pixels, no Vercel Analytics. None.
  • There is no advertising and there are no advertising cookies.
  • We do not sell or share your data with anyone.
  • We do not profile you and we take no automated decisions that affect you (article 22 GDPR (opens in a new tab)).
  • We do not guess your city from your IP address. Your city is stored only if you choose it.
  • There are no accounts for under-14s. The service is aimed at adults. We publish family events, but the person creating the account is the adult. We make no attempt to infer anyone's age. If we find an account belonging to a child under 14, we delete it (article 7 LOPDGDD (opens in a new tab)).

3. How long we keep it

Account, preferences, alerts
As long as you have the account
Delivery log
As long as you have the account (it is what stops an alert repeating). After 180 days the times and the failure reason are blanked
Push subscriptions
Until you turn them off or delete the account
All of the above
Erased immediately when you delete your account (section 5)
Technical logs
Up to 30 days at Vercel; 90 days for DigitalOcean's deploy logs. We keep none of them ourselves

4. Who else sees anything

These providers process data on our behalf (processors, article 28 GDPR (opens in a new tab)):

  • Vercel

    What for
    Serving the website and the Mini App
    Where
    Region “fra1” (Frankfurt, Germany)
    What they see
    Requests and their IP addresses
  • DigitalOcean App Platform

    What for
    Hosting the API, the worker and the scheduler
    Where
    Region “fra” (Frankfurt, Germany)
    What they see
    Requests and their IP addresses
  • DigitalOcean Managed Databases

    What for
    The PostgreSQL database
    Where
    Region “fra1” (Frankfurt, Germany)
    What they see
    Everything in section 2
  • DigitalOcean Managed Databases (Valkey)

    What for
    The task queue
    Where
    Region “fra1” (Frankfurt, Germany)
    What they see
    Internal task messages

In addition:

  • Telegram inevitably receives the messages we send you and your chat id: it is the channel you asked us to write through. Telegram is an independent controller of what it does with that information; its policy is its own (telegram.org/privacy (opens in a new tab)).
  • Google is involved only during sign-in, if you choose that button, and returns your identifier, your verified email address, your name and the URL of your picture.

Everything above sits in the European Union, in Frankfurt. And today no artificial intelligence service receives anything from us: the production servers carry no Anthropic key, nor any other AI provider's, so machine translation of event text is switched off. Even when it is on, all that leaves here is the title and description the source published — never anything of yours. So apart from Telegram and Google, which are involved because you chose them and which answer for themselves, there is no international transfer at all. The day we switch it on, we will write it here first.

5. How to delete your account, and what exactly disappears

In Your profile → Delete account (or by calling “DELETE /users/me”). There is no email confirmation, no grace period and no way back: your user row is deleted on the spot and the database takes with it, in the same operation, everything that pointed at you:

  1. Your sign-in identities (Google, Telegram).
  2. Your alerts and their city filters.
  3. And their category filters.
  4. Your push subscriptions.
  5. Your delivery log.

Four of those tables point straight at your account and the two filter tables hang off your alerts: six in all, and there is not one more in the whole database. After deletion, any session still open on another device resolves to nobody: there is no need to wait for it to expire.

The only thing that survives is the technical log line saying “account deleted” with your former internal identifier: it no longer leads to a person and it is our proof that we honoured the request.

Signing out on every device is a different thing and deletes nothing: it increments an internal counter that invalidates every session cookie ever issued to you at once.

6. Your rights

You may exercise, at any time and free of charge, the rights in articles 15 to 22 of the GDPR (opens in a new tab):

Access — knowing what we hold
Write to alexandr.shurigin@gmail.com (opens in a new tab) and we will send you a copy
Rectification — correcting it
Your name, language and city you change yourself in Your profile
Erasure — deleting it
Your profile → Delete account, immediate (section 5)
Portability — taking it with you
Ask by email and we send it as machine-readable JSON
Objection and restriction
By email; turning your alerts off is also enough
Withdrawing your consent
For push, in your browser; for Telegram, by blocking the bot

We answer within one month at most (article 12(3) GDPR). If you think we have not done it properly, you can complain to the Spanish Data Protection Agency (aepd.es (opens in a new tab)), C/ Jorge Juan 6, 28001 Madrid. We would be grateful if you wrote to us first: it is almost always faster.

7. Security

What we do, in short: the session travels in an encrypted cookie only our server can open, marked “HttpOnly”, “Secure” and with the “__Host-” prefix; the browser never talks to our API directly; the identity of whoever calls the API travels in a signed token that expires in 60 seconds; and secrets live in environment variables, never in the code.

No system is infallible. If a breach happens that puts your rights at risk, we will tell you and notify the AEPD within the 72 hours set by article 33 GDPR (opens in a new tab).

8. Changes

If we change something that really affects you — a new purpose, a new provider, analytics — we will announce it on the site before it takes effect. The date above is that of the last review.