Part 1 — The short version
This part is the one that matters. It is written for a 13-year-old, because most people using gassed are 13 to 18.
What gassed knows about you
- Your phone number. It is how you log in. Nobody else on gassed ever sees it.
- Your date of birth. Nobody else sees it either.
- Your real name, your school, your year, and your gender.
- Your survey answers, if you filled them in. They were optional.
- Everything you post: your votes, your polls, your likes, your messages, your stories.
The selfie
When you join, you take one selfie. It is sent to a company called Didit, whose software guesses how old the face looks, and then it is thrown away. Nobody at gassed looks at it. It is not saved on your phone, on our computers, or on theirs. What we keep is three things: that you did the check, the birthday you gave, and whether it passed.
The one thing we keep even if you delete your account
We keep a scrambled version of your phone number and your birthday. It is not readable — it cannot be turned back into your number. We keep it so that deleting your account and signing up again does not give you a fresh set of age checks. Without it, anyone who failed the age check could just start over. If your account was banned, we also keep the date of the ban against that scrambled number, so that deleting the account and signing up again on the same number does not undo the ban. We delete the record 12 months after your last age check, or 12 months after a ban, whichever is later.
Voting
No screen in gassed shows anyone who voted for who. Not the winner, not the person who made the poll, not your friends.
But we can see it. Votes are stored with the voter's account attached, because that is how the counting and the hints work. We do not look at them for fun, and no feature shows them to anyone. If the police or a court legally require us to hand something over, we have to, and a vote is something we could be made to hand over. That is true of every app; we would rather say it than let you find out later.
Ninety days after a poll closes, we remove the link between each vote and the account that cast it. The count stays. Who cast it is gone — from us too.
The paid hint
If you win a poll, you can pay (or spend gas) for one clue about one person who voted for you. The clue is one of: their year, their subject, their gender, or their first initial. We only use a clue if at least five people at your school share it. You get one clue per win, ever. It never tells you their name.
The clue comes attached to that person's random voting handle, like "Velvet Comet". That handle stays the same until they change it. So if you win several polls and the same person votes each time, the clues can pile up against one handle. Anyone can change their handle for free in Settings, any time.
Your messages are checked by a computer
Every chat message, story caption and group name is sent to Google's Gemini AI before anyone can read it. It decides: fine, hold for a person to look at, or block. If it breaks, nothing gets through — we would rather your message be delayed than let something harmful past.
What we never do
- We never show a photo of you. There are no profile pictures.
- We never sell your data.
- We never show you ads.
- We never track what you do outside gassed.
- We never use your data to train anyone's AI. [to be confirmed before launch]
What you can do
- See everything we have on you: Settings → Your data. It is instant.
- Delete your account: Settings → Delete account. It is instant, and there is no email to send.
- Change your handle: Settings → Shuffle.
- Stop people making polls about you: Settings.
- Block someone, or report anything, from the app.
If you are not happy
Tell us first: support@getgassed.app. Put My data at the start of the subject line so we see it quickly.
If we do not fix it, you can complain to the Information Commissioner's Office (the ICO). They are the UK's data protection regulator and complaining is free. [to be confirmed before launch]
You do not need a parent's permission. In the UK, 13 is the age at which you can agree to an app using your data on your own. You can still ask a parent or carer for help with anything on this page, and we would rather you did.
Part 2 — Who we are
We are the "data controller" for everything described here. That means we decide what is collected and why, and we are the ones responsible for it. For anything about your data, write to support@getgassed.app.
[to be confirmed before launch]
Part 3 — What we collect, why, and for how long
This is the Article 13 detail. Each row is one purpose. The notes underneath the table are part of it.
| # | What we do with it | What we collect | Why we are allowed to (lawful basis) | How long we keep it | Who else sees it |
|---|---|---|---|---|---|
| 1 | Create your account and sign you in | Your phone number; the one-time code we text you | Contract — Article 6(1)(b). We cannot give you an account without an account | Until you delete your account. Deletion is immediate and cascades through the database | Supabase (our hosting); Twilio (sends the text) — note A |
| 2 | Check you are old enough to be here | Your date of birth; one selfie (note B); the estimate the vendor returns | Legal obligation — Article 6(1)(c) — under the Online Safety Act 2023, or legitimate interests — Article 6(1)(f). See note C | The selfie: not stored anywhere, by us or by the vendor. The record of the check: until you delete your account | Didit (estimates the age from the selfie); Supabase |
| 3 | Stop the age check being restarted, and a ban being undone, by deleting the account | A scrambled (keyed HMAC-SHA256) version of your phone number and of your birthday; counts of failed and unreadable scans and of appeals; if an account on the number was banned, the date of the ban | Legitimate interests — Article 6(1)(f): keeping under-13s and adults off a service used by children, and keeping out someone we have already banned. See note D | 12 months after your last age check, or 12 months after a ban, whichever is later. It survives account deletion, which is its whole purpose | Nobody. It stays in our database |
| 4 | Let you appeal an age decision to a person | A photo of a document showing your date of birth; the outcome; which moderator decided | Same as row 2. Ofcom's codes expect an appeal route against an age decision | The photo: deleted when the decision is made, and within 7 days whatever happens. The outcome row: until you delete your account | One of our moderators, through a link that works for 60 seconds. Supabase stores the file in a private bucket — note E |
| 5 | Show you your school's feed, and run polls and votes | Which poll, which option, and which account voted; the time; likes | Contract — Article 6(1)(b) | The link between a vote and your account is removed 90 days after the poll closes; the vote stays as a count. Before that, your votes go with your account. Likes go with your account. Polls you created stay up with the creator removed — notes F and G | Nobody sees who voted. We can, for 90 days — note G |
| 6 | Give you one paid clue about a voter | The winning poll, the clue we picked, the voter's handle at that moment, and the App Store transaction id | Contract — Article 6(1)(b) | Until you delete your account | RevenueCat and Apple see the purchase, not the clue |
| 7 | Chat, group chats, stories, friends, blocks | The text you write; who is in a thread; who you are friends with; who you blocked | Contract — Article 6(1)(b) | Messages you sent are deleted with your account. Stories are deleted 24 hours after they are posted — note H | The people you sent them to. Google (Gemini) checks the text first — row 8 |
| 8 | Keep people safe: check content before it is delivered | The full text of every message, story caption, group name, custom poll blank and display name | Legal obligation (Online Safety Act 2023 safety duties) and legitimate interests — Article 6(1)(f) | The text is sent to Google for the check and is not stored by us in full. We store the first 200 characters, the verdict, the reason and your account id in a moderation log, for 24 months — note I | Google (Gemini); our moderators |
| 9 | Suggest poll prompts about a classmate | That person's survey answers | Legitimate interests — Article 6(1)(f). See note J | The survey answers stay until that person deletes their account | Google (Gemini). The classmate who asked never sees the answers, only the suggestions |
| 10 | Help you find your school | What you type; your device location, only if you tap "Schools near me"; your IP address | Consent for the location (you grant it in the OS prompt and can withdraw it in Settings) — Article 6(1)(a). Legitimate interests for the rest | Your location is not stored. Your IP address sits in a rate-limit counter for up to 2 days — note K | Google Places, but only if you tap "Search more widely" — note L |
| 11 | Send you notifications | A push token for this device; which kinds of notification you want | Consent for the OS permission; contract for the rest | Until you delete the account, turn notifications off, or use a 21st device | Expo's push service, then Apple's push service. The text is generic — note M |
| 12 | Take payments and run subscriptions | Your account id, used as your customer id at RevenueCat; what you bought; when it expires | Contract — Article 6(1)(b) | Until you delete your account. RevenueCat and Apple keep their own records — note N | RevenueCat; Apple |
| 13 | Fix crashes and errors | The error, and your account id | Legitimate interests — Article 6(1)(f): a working app | [to be confirmed before launch] | Sentry — note O |
| 14 | Act on reports and enforce the rules | What you reported and why; actions taken against an account; whether an account is warned, limited or banned. A ban is also written, as a date, onto the scrambled-number record in row 3 | Legal obligation and legitimate interests, as row 8 | Reports and moderators' actions: 24 months, longer only while a report is still open or under a legal hold — note P. Whether you are warned, limited or banned: until a person lifts it or you delete your account. The ban date in row 3 goes after 12 months | Our moderators |
Notes
A — Twilio. The text message with your code is sent through Supabase Auth's
built-in SMS provider, which is Twilio. Your phone number is stored by Supabase
Auth (in auth.users), not in your profile. Your profile only records that a
number was verified. [to be confirmed before launch]
B — The selfie, precisely. The photo is taken in gassed's own camera screen.
It exists in the app's memory for the length of one request. It is sent to our
own server function, which passes it straight to Didit's age-estimation API with
save_api_request=false, which is Didit's switch for "analyse this and keep
nothing". The only thing sent alongside it is an internal reference number for
the check — never your name, phone number or account id. The reply is read once,
turned into pass/fail and one of three broad age bands (13–15, 16–17, 18+), and
discarded. There is no column anywhere in the database for a photo, for an
estimated age, or for a vendor session id. [to be confirmed before launch]
C — The lawful basis for the age check. [to be confirmed before launch]
D — The ledger, plainly. When you attempt an age check, we work out two keyed hashes: one from your phone number, one from your phone number plus the birthday you typed. A keyed hash is a one-way scramble that needs a secret key to produce. The key lives in our server function's secrets, not in the database, so a copy of the database alone cannot turn the hashes back into your number. The row counts how many scans failed, how many were unreadable, how many appeals you used, and pins the birthday to the first one that got a verdict. We keep it after you delete your account on purpose: without it, "delete, reinstall, sign up again" would hand back a fresh set of attempts and a free choice of birthday, and the limits would mean nothing. It holds no name, no number and no birthday. If an account on the number is banned for repeatedly breaking our community guidelines, the row also records the date of the ban, and for 12 months from that date the number cannot be used to make a new account. The app tells you this plainly if it applies to you, and a person can review it (Part 7 of the Terms). A warning or a temporary limit is never recorded against the number.
The 12-month figure is enforced by an hourly job that deletes every ledger row 12 months after its last change — last scan, last appeal, or ban, whichever is latest (migrations 0060 and 0061). It is not a lazy delete that waits for the number to come back.
E — The appeal document. The photo goes into a Supabase Storage bucket marked private, with no access rule for any signed-in user at all — only our server functions can read or write it. A moderator opens it through a link that expires after 60 seconds. It is deleted as soon as the decision is made; an hourly job deletes anything older than 7 days whether it was decided or not, and the same sweep runs every time a moderator opens the queue. Nothing is copied off the document: not the number, not the photo, not anything else. The record that survives is who asked, when, what was decided and by whom.
F — Polls after you leave. A poll you created stays up. The link back to you is removed at the database level (the creator column is set to null). Nobody could see who created it while you were here either.
G — Votes are anonymous to users, not to us. No screen in gassed shows who voted for whom, and the database is set up so that a normal app query structurally cannot return it: the permission to read the voter column has been revoked from every signed-in user, and votes are served only through views that return counts. The app also never tells the person who made a poll who voted in it.
We hold the link ourselves. We use it for two things: counting, and picking the one random voter a paid hint describes. We do not have a report, a dashboard or a screen that lists votes by person. A court order or a police request made under the right legal power would still reach it, and we would have to comply.
We keep the link for 90 days after the poll closes — long enough to serve the one paid clue and to answer a safeguarding or police question about a poll — and then an hourly job removes it (migration 0063). The vote stays as a count. After that, nobody, including us, can say who cast it, and a request for it could not be answered.
H — Stories. A story stops being visible to anyone 24 hours after it is posted, and an hourly job deletes the row within the hour after that (migration 0063). One exception: a story someone has reported is kept — unseen by anyone but a moderator — until the report is closed, or, if it is part of a case we have had to preserve (note P), until that hold ends.
I — The moderation log. Every check writes a row, whether the content was allowed, held or blocked — that is what lets a person audit whether the AI is too strict. The row holds the first 200 characters of what was written, the verdict, the categories, the AI's one-line reason, the model used, and your account id. When you delete your account, the account id is removed from the row, but the 200 characters stay. Rows are deleted 24 months after they were written, by an hourly job (migration 0063) — the same period as note P, so a decision and the verdict behind it go together. A row is kept longer only while it is still waiting for a person to look at it, or while a report about the same content is open or under a legal hold.
J — Prompt suggestions. When you start making a poll about a classmate, their survey answers — their own words about themselves — are sent to Google's Gemini so it can suggest which of the 40 fixed prompts suits them. The classmate never sees the answers.
K — IP addresses. The rate limiter writes a row keyed on your IP address when you search for a school without being signed in. Rows are deleted after 2 days by an hourly job.
L — Google Places. Everyday school search runs against our own directory, built from public registers, and never touches Google. Google is used only when you tap "Search more widely" because your school was not in our list. When you do, what you typed and — if you turned location on — your exact coordinates are sent to Google.
The location permission prompt now says the same thing this note does. The
string in app.json reads: "gassed uses your location, only while the app is
open, to show nearby schools first when you search. We don't store it. If you
search more widely it is sent to Google to find schools near you. Search works
fine without it."
M — Notifications. The text of a notification never contains a message, a name or a poll. It says things like "Someone just voted on a poll about you" or "New message." The push token goes to Expo's push service and then to Apple.
N — RevenueCat and Apple. We never see your card. Apple takes the payment. RevenueCat tells us whether a purchase is real. Your account id is used as your customer id at RevenueCat, so RevenueCat can link purchases to an account. [to be confirmed before launch]
O — Sentry. Crash reporting is off unless a key is configured. When it is on, we strip cookies, headers and query strings from the report, and the only thing about you attached is your account id. [to be confirmed before launch]
P — Moderation records. Reports you file and actions moderators take are
kept for 24 months from the day they were written, and then deleted by an
hourly job (migration 0063). Two things are kept longer: a report nobody has
closed yet, together with the actions and verdicts about the same content; and
a report we have placed under a legal hold. A hold is a date, not a flag — set
only by us, only when content has been or is being reported to the police or
the National Crime Agency (docs/legal/CSEA_PROCEDURE.md), and reviewed on
that date. The enforcement ladder only counts actions from the last 180 days,
so this deletion never changes anyone's standing; whether you are warned,
limited or banned is kept separately, until a person lifts it or you delete
your account. If you tap a helpline number or link on our support card, your
phone's own dialler, mail or browser app opens. We do not send anything to
those organisations and do not record that you tapped.
Part 4 — Where your data is kept, and who we send it to
[to be confirmed before launch]
Everyone we send data to, and what for:
| Who | What they get | What they are to us |
|---|---|---|
| Supabase | Everything | Processor — [to be confirmed before launch] |
| Twilio (through Supabase Auth) | Your phone number, the code | Processor (sub-processor of Supabase) — [to be confirmed before launch] |
| Google (Gemini API) | The text of messages, captions, group names, display names; classmates' survey answers | Processor — [to be confirmed before launch] |
| Google (Places API) | What you typed, and your coordinates if you turned location on | Probably an independent controller — see note L |
| Didit | One selfie, and an internal reference number | Processor — [to be confirmed before launch] |
| RevenueCat | Your account id and purchase records | Processor — [to be confirmed before launch] |
| Apple | The payment, and push notification delivery | Independent controller for the purchase |
| Expo (EAS) | Push tokens and notification text; hosts the API routes | Processor — [to be confirmed before launch] |
| Sentry | Error reports with your account id | Processor — [to be confirmed before launch] |
International transfers. [to be confirmed before launch]
We do not sell data. We do not share it with advertisers. There are no advertising identifiers, no ad SDKs and no analytics SDKs in the app.
Part 5 — Your rights
You have these rights over your own data. They are free to use. We have to answer within one month.
| Right | How it works here |
|---|---|
| See your data (access) | Settings → Your data. It returns a JSON file with everything we hold, straight away, up to three times an hour |
| Get a copy to take elsewhere (portability) | The same export. It is machine-readable JSON |
| Correct something wrong (rectification) | Your name, year, gender, survey answers and handle are editable in Settings. Your date of birth and your school are locked after sign-up — see below |
| Delete your account (erasure) | Settings → Delete account. Immediate, no email, no waiting period. What stays: the polls you created (with you removed), the keyed hashes in row 3, and moderation records (for up to 24 months — note P). Deleting the account does not delete the row 3 record: it is kept so the age checks cannot be restarted, and if the account was banned it keeps the date of the ban, so the number cannot open a new account for 12 months (Terms 6.6) |
| Object to processing based on legitimate interests | Email support@getgassed.app with My data at the start of the subject line |
| Restrict processing while something is disputed | Same route |
| Withdraw consent where consent is the basis | Turn off location and notification permissions in your phone's settings, at any time |
| Complain to the regulator | The Information Commissioner's Office. [to be confirmed before launch] |
What is in your export. One JSON file, built from the database at the
moment you ask (src/app/api/account/export+api.ts):
- Account — the phone number you signed up with, your email if you gave one, and when the account was made and last signed in.
- Profile and survey answers — everything on your profile, and the answers you gave at sign-up.
- Subscription — your plan and its renewal date.
- Polls you created — including any prompt you typed yourself, and whether a moderator removed it.
- Polls you appeared in — which polls named you as an option, and when. Not who voted, and not the tallies.
- Votes you cast, polls you liked — your own votes and likes only. Votes from polls that closed more than 90 days ago are not there: the link between them and you has been removed, so they can no longer be looked up (note G).
- Reveals you bought — each hint and the handle it named.
- Stories you posted.
- Friends and friend requests — each request you sent or received, the other person's display name, and whether it was accepted.
- Chats — the chats you are in and the ones you started (name, whether it is a group, when you joined). Only your own messages, with whether each was delivered, held or blocked. Not other people's messages or member lists.
- Notifications you received — including the text of any warning or notice.
- Gas — every Gas you earned or spent, and why.
- People you blocked.
- Devices registered for push — platform and notification settings, not the token.
- Age checks and appeals — each attempt, the birthday tested, the outcome and the rule applied. No selfie, estimate or document is stored, and the appeal photo is deleted on decision (the export shows when).
- Reports you filed.
- Reports about you — reports against your profile, polls or stories: what was alleged, when, and how a person resolved it. Never who reported you. Reports on private chat messages are not listed, because the date would identify the reporter; any resulting action is shown.
- Moderation decisions about you — content removals, report outcomes and account-standing changes, with dates, and the outcome code for each. Never the moderator's identity or anything they typed.
- AI moderation checks — every time the automated screen flagged or blocked something you wrote (the excerpt, the verdict, the categories and reason), plus a count of how many pieces of content passed.
- Account standing — whether you have been warned, limited or banned, when, and how many upheld findings that rests on. Absent if you never have.
- Not included, because it cannot be looked up by account — the phone-hash ledger in row 3, and hints other people bought about you (stored by handle, not by account).
Your date of birth and your school cannot be edited. Both are locked in the database after your account is created. The date of birth is locked so nobody can pass the age check as one age and then change it. The school is locked because it controls who can see you.
That is a real limit on the right to rectification under Article 16. Someone who mistypes their birthday is stuck with it. If yours is wrong, email support@getgassed.app with My data in the subject and a person will look at it.
Part 6 — Decisions made by computers
Three things in gassed are decided automatically:
- The age check. A computer estimate of how old your face looks decides whether you can have an account. If it fails you twice, you can send a document to a person instead, and a person makes the final call.
- Content screening. Google's Gemini decides whether a message is delivered, held for a person, or blocked. A held message goes to a person. A blocked message is blocked with no human review and no appeal route in the app.
- The enforcement ladder. After a moderator upholds a report, warnings, 7-day limits and bans are applied automatically by counting upheld actions. The counting is automatic; every action it counts was taken by a person.
Part 7 — Things we deliberately do not do
Written down because the Children's Code asks services to be explicit about what they have turned off.
- No profiling for content. What the feed shows you is worked out on your own phone. The server does not learn what you vote on.
- No advertising. No ad network, no ad identifier, no ATT prompt.
- No analytics product. There is no analytics SDK in the app at all.
- No profile photos. There is no upload anywhere. Avatars are drawn from initials.
- Your contacts stay on your phone. The invite screen reads them so you can pick someone to text, and it hands the message to your phone's own Messages app. No contact reaches our servers.
- Location is off until you ask for it. It is used for one search and not stored.
- No read receipts, no "online now", no typing indicators. They do not exist in the app for anyone.
Anyone at your school can put you in a poll unless you turn it off. "Pause polls about me" is a setting you have to find.
Part 8 — Changes to this notice
[to be confirmed before launch]