gassed

Privacy Notice

What gassed knows about you, why, for how long, and who else sees it. Part 1 is the short version, written for a 13-year-old. See also the Terms of Service.

On this page
  1. Part 1 — The short version
  2. Part 2 — Who we are
  3. Part 3 — What we collect, why, and for how long
  4. Part 4 — Where your data is kept, and who we send it to
  5. Part 5 — Your rights
  6. Part 6 — Decisions made by computers
  7. Part 7 — Things we deliberately do not do
  8. Part 8 — Changes to this notice

Part 1 — The short version

This part is the one that matters. It is written for a 13-year-old, because most people using gassed are 13 to 18.

What gassed knows about you

The selfie

When you join, you take one selfie. It is sent to a company called Didit, whose software guesses how old the face looks, and then it is thrown away. Nobody at gassed looks at it. It is not saved on your phone, on our computers, or on theirs. What we keep is three things: that you did the check, the birthday you gave, and whether it passed.

The one thing we keep even if you delete your account

We keep a scrambled version of your phone number and your birthday. It is not readable — it cannot be turned back into your number. We keep it so that deleting your account and signing up again does not give you a fresh set of age checks. Without it, anyone who failed the age check could just start over. If your account was banned, we also keep the date of the ban against that scrambled number, so that deleting the account and signing up again on the same number does not undo the ban. We delete the record 12 months after your last age check, or 12 months after a ban, whichever is later.

Voting

No screen in gassed shows anyone who voted for who. Not the winner, not the person who made the poll, not your friends.

But we can see it. Votes are stored with the voter's account attached, because that is how the counting and the hints work. We do not look at them for fun, and no feature shows them to anyone. If the police or a court legally require us to hand something over, we have to, and a vote is something we could be made to hand over. That is true of every app; we would rather say it than let you find out later.

Ninety days after a poll closes, we remove the link between each vote and the account that cast it. The count stays. Who cast it is gone — from us too.

The paid hint

If you win a poll, you can pay (or spend gas) for one clue about one person who voted for you. The clue is one of: their year, their subject, their gender, or their first initial. We only use a clue if at least five people at your school share it. You get one clue per win, ever. It never tells you their name.

The clue comes attached to that person's random voting handle, like "Velvet Comet". That handle stays the same until they change it. So if you win several polls and the same person votes each time, the clues can pile up against one handle. Anyone can change their handle for free in Settings, any time.

Your messages are checked by a computer

Every chat message, story caption and group name is sent to Google's Gemini AI before anyone can read it. It decides: fine, hold for a person to look at, or block. If it breaks, nothing gets through — we would rather your message be delayed than let something harmful past.

What we never do

What you can do

If you are not happy

Tell us first: support@getgassed.app. Put My data at the start of the subject line so we see it quickly.

If we do not fix it, you can complain to the Information Commissioner's Office (the ICO). They are the UK's data protection regulator and complaining is free. [to be confirmed before launch]

You do not need a parent's permission. In the UK, 13 is the age at which you can agree to an app using your data on your own. You can still ask a parent or carer for help with anything on this page, and we would rather you did.


Part 2 — Who we are

We are the "data controller" for everything described here. That means we decide what is collected and why, and we are the ones responsible for it. For anything about your data, write to support@getgassed.app.

[to be confirmed before launch]


Part 3 — What we collect, why, and for how long

This is the Article 13 detail. Each row is one purpose. The notes underneath the table are part of it.

# What we do with it What we collect Why we are allowed to (lawful basis) How long we keep it Who else sees it
1 Create your account and sign you in Your phone number; the one-time code we text you Contract — Article 6(1)(b). We cannot give you an account without an account Until you delete your account. Deletion is immediate and cascades through the database Supabase (our hosting); Twilio (sends the text) — note A
2 Check you are old enough to be here Your date of birth; one selfie (note B); the estimate the vendor returns Legal obligation — Article 6(1)(c) — under the Online Safety Act 2023, or legitimate interests — Article 6(1)(f). See note C The selfie: not stored anywhere, by us or by the vendor. The record of the check: until you delete your account Didit (estimates the age from the selfie); Supabase
3 Stop the age check being restarted, and a ban being undone, by deleting the account A scrambled (keyed HMAC-SHA256) version of your phone number and of your birthday; counts of failed and unreadable scans and of appeals; if an account on the number was banned, the date of the ban Legitimate interests — Article 6(1)(f): keeping under-13s and adults off a service used by children, and keeping out someone we have already banned. See note D 12 months after your last age check, or 12 months after a ban, whichever is later. It survives account deletion, which is its whole purpose Nobody. It stays in our database
4 Let you appeal an age decision to a person A photo of a document showing your date of birth; the outcome; which moderator decided Same as row 2. Ofcom's codes expect an appeal route against an age decision The photo: deleted when the decision is made, and within 7 days whatever happens. The outcome row: until you delete your account One of our moderators, through a link that works for 60 seconds. Supabase stores the file in a private bucket — note E
5 Show you your school's feed, and run polls and votes Which poll, which option, and which account voted; the time; likes Contract — Article 6(1)(b) The link between a vote and your account is removed 90 days after the poll closes; the vote stays as a count. Before that, your votes go with your account. Likes go with your account. Polls you created stay up with the creator removed — notes F and G Nobody sees who voted. We can, for 90 days — note G
6 Give you one paid clue about a voter The winning poll, the clue we picked, the voter's handle at that moment, and the App Store transaction id Contract — Article 6(1)(b) Until you delete your account RevenueCat and Apple see the purchase, not the clue
7 Chat, group chats, stories, friends, blocks The text you write; who is in a thread; who you are friends with; who you blocked Contract — Article 6(1)(b) Messages you sent are deleted with your account. Stories are deleted 24 hours after they are posted — note H The people you sent them to. Google (Gemini) checks the text first — row 8
8 Keep people safe: check content before it is delivered The full text of every message, story caption, group name, custom poll blank and display name Legal obligation (Online Safety Act 2023 safety duties) and legitimate interests — Article 6(1)(f) The text is sent to Google for the check and is not stored by us in full. We store the first 200 characters, the verdict, the reason and your account id in a moderation log, for 24 months — note I Google (Gemini); our moderators
9 Suggest poll prompts about a classmate That person's survey answers Legitimate interests — Article 6(1)(f). See note J The survey answers stay until that person deletes their account Google (Gemini). The classmate who asked never sees the answers, only the suggestions
10 Help you find your school What you type; your device location, only if you tap "Schools near me"; your IP address Consent for the location (you grant it in the OS prompt and can withdraw it in Settings) — Article 6(1)(a). Legitimate interests for the rest Your location is not stored. Your IP address sits in a rate-limit counter for up to 2 days — note K Google Places, but only if you tap "Search more widely" — note L
11 Send you notifications A push token for this device; which kinds of notification you want Consent for the OS permission; contract for the rest Until you delete the account, turn notifications off, or use a 21st device Expo's push service, then Apple's push service. The text is generic — note M
12 Take payments and run subscriptions Your account id, used as your customer id at RevenueCat; what you bought; when it expires Contract — Article 6(1)(b) Until you delete your account. RevenueCat and Apple keep their own records — note N RevenueCat; Apple
13 Fix crashes and errors The error, and your account id Legitimate interests — Article 6(1)(f): a working app [to be confirmed before launch] Sentry — note O
14 Act on reports and enforce the rules What you reported and why; actions taken against an account; whether an account is warned, limited or banned. A ban is also written, as a date, onto the scrambled-number record in row 3 Legal obligation and legitimate interests, as row 8 Reports and moderators' actions: 24 months, longer only while a report is still open or under a legal hold — note P. Whether you are warned, limited or banned: until a person lifts it or you delete your account. The ban date in row 3 goes after 12 months Our moderators

Notes

A — Twilio. The text message with your code is sent through Supabase Auth's built-in SMS provider, which is Twilio. Your phone number is stored by Supabase Auth (in auth.users), not in your profile. Your profile only records that a number was verified. [to be confirmed before launch]

B — The selfie, precisely. The photo is taken in gassed's own camera screen. It exists in the app's memory for the length of one request. It is sent to our own server function, which passes it straight to Didit's age-estimation API with save_api_request=false, which is Didit's switch for "analyse this and keep nothing". The only thing sent alongside it is an internal reference number for the check — never your name, phone number or account id. The reply is read once, turned into pass/fail and one of three broad age bands (13–15, 16–17, 18+), and discarded. There is no column anywhere in the database for a photo, for an estimated age, or for a vendor session id. [to be confirmed before launch]

C — The lawful basis for the age check. [to be confirmed before launch]

D — The ledger, plainly. When you attempt an age check, we work out two keyed hashes: one from your phone number, one from your phone number plus the birthday you typed. A keyed hash is a one-way scramble that needs a secret key to produce. The key lives in our server function's secrets, not in the database, so a copy of the database alone cannot turn the hashes back into your number. The row counts how many scans failed, how many were unreadable, how many appeals you used, and pins the birthday to the first one that got a verdict. We keep it after you delete your account on purpose: without it, "delete, reinstall, sign up again" would hand back a fresh set of attempts and a free choice of birthday, and the limits would mean nothing. It holds no name, no number and no birthday. If an account on the number is banned for repeatedly breaking our community guidelines, the row also records the date of the ban, and for 12 months from that date the number cannot be used to make a new account. The app tells you this plainly if it applies to you, and a person can review it (Part 7 of the Terms). A warning or a temporary limit is never recorded against the number.

The 12-month figure is enforced by an hourly job that deletes every ledger row 12 months after its last change — last scan, last appeal, or ban, whichever is latest (migrations 0060 and 0061). It is not a lazy delete that waits for the number to come back.

E — The appeal document. The photo goes into a Supabase Storage bucket marked private, with no access rule for any signed-in user at all — only our server functions can read or write it. A moderator opens it through a link that expires after 60 seconds. It is deleted as soon as the decision is made; an hourly job deletes anything older than 7 days whether it was decided or not, and the same sweep runs every time a moderator opens the queue. Nothing is copied off the document: not the number, not the photo, not anything else. The record that survives is who asked, when, what was decided and by whom.

F — Polls after you leave. A poll you created stays up. The link back to you is removed at the database level (the creator column is set to null). Nobody could see who created it while you were here either.

G — Votes are anonymous to users, not to us. No screen in gassed shows who voted for whom, and the database is set up so that a normal app query structurally cannot return it: the permission to read the voter column has been revoked from every signed-in user, and votes are served only through views that return counts. The app also never tells the person who made a poll who voted in it.

We hold the link ourselves. We use it for two things: counting, and picking the one random voter a paid hint describes. We do not have a report, a dashboard or a screen that lists votes by person. A court order or a police request made under the right legal power would still reach it, and we would have to comply.

We keep the link for 90 days after the poll closes — long enough to serve the one paid clue and to answer a safeguarding or police question about a poll — and then an hourly job removes it (migration 0063). The vote stays as a count. After that, nobody, including us, can say who cast it, and a request for it could not be answered.

H — Stories. A story stops being visible to anyone 24 hours after it is posted, and an hourly job deletes the row within the hour after that (migration 0063). One exception: a story someone has reported is kept — unseen by anyone but a moderator — until the report is closed, or, if it is part of a case we have had to preserve (note P), until that hold ends.

I — The moderation log. Every check writes a row, whether the content was allowed, held or blocked — that is what lets a person audit whether the AI is too strict. The row holds the first 200 characters of what was written, the verdict, the categories, the AI's one-line reason, the model used, and your account id. When you delete your account, the account id is removed from the row, but the 200 characters stay. Rows are deleted 24 months after they were written, by an hourly job (migration 0063) — the same period as note P, so a decision and the verdict behind it go together. A row is kept longer only while it is still waiting for a person to look at it, or while a report about the same content is open or under a legal hold.

J — Prompt suggestions. When you start making a poll about a classmate, their survey answers — their own words about themselves — are sent to Google's Gemini so it can suggest which of the 40 fixed prompts suits them. The classmate never sees the answers.

K — IP addresses. The rate limiter writes a row keyed on your IP address when you search for a school without being signed in. Rows are deleted after 2 days by an hourly job.

L — Google Places. Everyday school search runs against our own directory, built from public registers, and never touches Google. Google is used only when you tap "Search more widely" because your school was not in our list. When you do, what you typed and — if you turned location on — your exact coordinates are sent to Google.

The location permission prompt now says the same thing this note does. The string in app.json reads: "gassed uses your location, only while the app is open, to show nearby schools first when you search. We don't store it. If you search more widely it is sent to Google to find schools near you. Search works fine without it."

M — Notifications. The text of a notification never contains a message, a name or a poll. It says things like "Someone just voted on a poll about you" or "New message." The push token goes to Expo's push service and then to Apple.

N — RevenueCat and Apple. We never see your card. Apple takes the payment. RevenueCat tells us whether a purchase is real. Your account id is used as your customer id at RevenueCat, so RevenueCat can link purchases to an account. [to be confirmed before launch]

O — Sentry. Crash reporting is off unless a key is configured. When it is on, we strip cookies, headers and query strings from the report, and the only thing about you attached is your account id. [to be confirmed before launch]

P — Moderation records. Reports you file and actions moderators take are kept for 24 months from the day they were written, and then deleted by an hourly job (migration 0063). Two things are kept longer: a report nobody has closed yet, together with the actions and verdicts about the same content; and a report we have placed under a legal hold. A hold is a date, not a flag — set only by us, only when content has been or is being reported to the police or the National Crime Agency (docs/legal/CSEA_PROCEDURE.md), and reviewed on that date. The enforcement ladder only counts actions from the last 180 days, so this deletion never changes anyone's standing; whether you are warned, limited or banned is kept separately, until a person lifts it or you delete your account. If you tap a helpline number or link on our support card, your phone's own dialler, mail or browser app opens. We do not send anything to those organisations and do not record that you tapped.


Part 4 — Where your data is kept, and who we send it to

[to be confirmed before launch]

Everyone we send data to, and what for:

Who What they get What they are to us
Supabase Everything Processor — [to be confirmed before launch]
Twilio (through Supabase Auth) Your phone number, the code Processor (sub-processor of Supabase) — [to be confirmed before launch]
Google (Gemini API) The text of messages, captions, group names, display names; classmates' survey answers Processor — [to be confirmed before launch]
Google (Places API) What you typed, and your coordinates if you turned location on Probably an independent controller — see note L
Didit One selfie, and an internal reference number Processor — [to be confirmed before launch]
RevenueCat Your account id and purchase records Processor — [to be confirmed before launch]
Apple The payment, and push notification delivery Independent controller for the purchase
Expo (EAS) Push tokens and notification text; hosts the API routes Processor — [to be confirmed before launch]
Sentry Error reports with your account id Processor — [to be confirmed before launch]

International transfers. [to be confirmed before launch]

We do not sell data. We do not share it with advertisers. There are no advertising identifiers, no ad SDKs and no analytics SDKs in the app.


Part 5 — Your rights

You have these rights over your own data. They are free to use. We have to answer within one month.

Right How it works here
See your data (access) Settings → Your data. It returns a JSON file with everything we hold, straight away, up to three times an hour
Get a copy to take elsewhere (portability) The same export. It is machine-readable JSON
Correct something wrong (rectification) Your name, year, gender, survey answers and handle are editable in Settings. Your date of birth and your school are locked after sign-up — see below
Delete your account (erasure) Settings → Delete account. Immediate, no email, no waiting period. What stays: the polls you created (with you removed), the keyed hashes in row 3, and moderation records (for up to 24 months — note P). Deleting the account does not delete the row 3 record: it is kept so the age checks cannot be restarted, and if the account was banned it keeps the date of the ban, so the number cannot open a new account for 12 months (Terms 6.6)
Object to processing based on legitimate interests Email support@getgassed.app with My data at the start of the subject line
Restrict processing while something is disputed Same route
Withdraw consent where consent is the basis Turn off location and notification permissions in your phone's settings, at any time
Complain to the regulator The Information Commissioner's Office. [to be confirmed before launch]

What is in your export. One JSON file, built from the database at the moment you ask (src/app/api/account/export+api.ts):

Your date of birth and your school cannot be edited. Both are locked in the database after your account is created. The date of birth is locked so nobody can pass the age check as one age and then change it. The school is locked because it controls who can see you.

That is a real limit on the right to rectification under Article 16. Someone who mistypes their birthday is stuck with it. If yours is wrong, email support@getgassed.app with My data in the subject and a person will look at it.


Part 6 — Decisions made by computers

Three things in gassed are decided automatically:

  1. The age check. A computer estimate of how old your face looks decides whether you can have an account. If it fails you twice, you can send a document to a person instead, and a person makes the final call.
  2. Content screening. Google's Gemini decides whether a message is delivered, held for a person, or blocked. A held message goes to a person. A blocked message is blocked with no human review and no appeal route in the app.
  3. The enforcement ladder. After a moderator upholds a report, warnings, 7-day limits and bans are applied automatically by counting upheld actions. The counting is automatic; every action it counts was taken by a person.

Part 7 — Things we deliberately do not do

Written down because the Children's Code asks services to be explicit about what they have turned off.

Anyone at your school can put you in a poll unless you turn it off. "Pause polls about me" is a setting you have to find.


Part 8 — Changes to this notice

[to be confirmed before launch]


Back to top ↑