Legal
Privacy Policy
Last updated: September 19, 2026
GateMate is built by QAlytics LLC (dba GateMate™). This policy explains what we collect, why, how long we keep it, and how to get rid of it. If something here doesn't match what the app does, treat it as a bug and tell us: info@gatemate.net.
1. What we collect
Account
- Email address, and a hashed password (we never store the password itself)
- Display name, handle, and — if you add them — a bio, profile photo, industry, interests and home city
- Your Instagram handle, if you choose to add it. It is shown to people in rooms you're in
Sign in with Apple (optional)
If you use Apple to sign in and choose "Hide My Email", we only ever receive Apple's private relay address. We store an encrypted Apple token so that deleting your GateMate account also revokes GateMate's access to your Apple ID.
Sign in with Google (optional)
If you use Google to sign in, Google tells us your email address, your name and a link to your Google profile picture — nothing else. We store a Google account identifier so the same Google account signs you back in even if you later change your email. If an account with that email already exists, the two are linked rather than duplicated. We receive no advertising identifier from Google and we do not read anything else from your Google account. You can delete a Google-created account in the app like any other: Settings → Account → Delete account.
Phone number (optional)
You can verify a phone number to earn the blue "verified" mark. We store the number and the date it was verified. Verification codes are sent by Twilio and expire in minutes. Your number is never shown to other members and is never used for marketing.
What you create
- Messages you send in a room's chat, and direct messages
- Photos and short video clips you add to a room album, voice notes you record in direct messages, and your profile photo
- Reactions, votes, saved rooms, follows and connections
- Reports and feedback you send us
Voice notes and dictation (optional)
If you record a voice note in a direct message, the recording is the message. It is stored the same way your photos are and it is deleted when the message is deleted. It is not transcribed automatically. A transcript is produced only if a listener taps "Read it" — at that point the recording is sent to OpenAI's Whisper speech-to-text service, acting only as our processor, purely to turn speech into text, and the transcript is saved on the message so it does not have to be produced twice.
If you use the microphone button in room chat, that is dictation — a keyboard, not a recording. The audio is turned into text and the audio itself is discarded immediately. Only the words you then choose to send are kept.
Microphone access is when-in-use only. We ask for it the first time you press a microphone button, never before, and the app cannot record in the background.
Where you've been in the app
- Which rooms you joined, when you arrived and left, and whether you were visible or invisible in them
- A private history of your nights (place, date, how long you stayed, how many people you kept). This is visible to you alone. There is no setting, tier or endpoint that shows it to anyone else, and you can delete any night from it in one tap
Location — three specific moments, never in the background
GateMate never tracks you in the background, never builds a location history, and never shows your position to another member. Your device's location is read only when:
- First launch — to check whether your city has live rooms yet
- "Rooms near me" — when you tap it, to list public rooms within walking distance or up to 50 km
- Checking in at the door — only for rooms where the host requires attendees to actually be at the venue
For (3) we keep your most recent check-in coordinate, overwritten each time, purely to spot physically impossible jumps between venues (someone faking their way into a room they're not at). It is not a trail: one point, replaced on the next check-in, deleted with your account. You can always join a room by typing its code without granting location at all.
Device and diagnostics
Device type, operating system, app version, crash and performance logs, and — only if you turn notifications on — a push token from Apple or Google so we can deliver them.
Usage analytics (our own, not a third party's)
Which features you use, recorded against your account ID, so we can tell what's working. No advertising identifiers, no cross-app tracking, no ad networks — GateMate has never run ads.
Network
Your IP address is processed as requests arrive, for rate limiting and abuse prevention, and to alert us to suspicious admin sign-ins (where an approximate city is derived via ip-api.com). It is not stored on your profile.
2. What we do with it
- Run the product: let you into rooms, show you who's there, deliver messages and photos
- Keep people safe: moderation, reports, blocks, and detecting fake presence or fake accounts
- Send transactional email (sign-in, room invites, recaps) and, if you opted in, notifications
- Fix bugs, measure whether features work, and answer support requests
- Enforce our Terms
We do not sell your personal information, we do not share it with advertisers, and we do not run ads.
3. Content moderation and AI
Every photo you upload, and the first frame of every video clip, is screened by an automated image-moderation service (Hive AI) before it is stored. Slurs are blocked in chat text on our servers; ordinary profanity is not filtered, because GateMate is for adults.
Three features send information to Google's Gemini models (through our integration provider):
- Icebreaker suggestions — the room's title and topic, not your messages
- Report triage — when someone reports a person or a message, the reason chosen, anything typed in the details box, and the reported message are classified so that threats, self-harm and anything involving a minor reach a human first. Reports our own filters dismiss as test data are never sent
- Room banner art — a room's title, category and venue label are used to generate a backdrop image for it. No photo of a person and no message is ever sent for this
None of it is used to train anyone's model, and none of it sees your DMs. A human being, not a model, decides every moderation outcome — the classification only decides what a human looks at first.
Speech-to-text is handled by OpenAI's Whisper model under the same terms: processor only, for the feature you asked for, never for advertising, never for profiling, and never used to train anyone's model.
4. Visibility controls
- Your visibility inside a room is yours to set — including going invisible
- Rooms are not publicly indexed; a code or an invite is the only way in
- You can block anyone. A blocked person can't see you, message you, or see your messages
- You can report any person or message; reports reach a human within 24 hours
- You can leave a room at any time, and you disappear from it immediately
5. How long we keep things
| Data | Kept for |
|---|---|
| Room chat | Goes dark ~12 hours after the last arrival and is removed from the app entirely. A copy is retained for 30 days ONLY so a moderator can act on a report — "we deleted the evidence" is not an answer to a harassment complaint |
| Room album photos | Unlock the morning after, then delete themselves 30 days later |
| Direct messages and connections | Until you delete them, or you delete your account |
| Your nights history | Until you delete a night, or your account |
| Account and profile | Until you delete your account |
| Diagnostics and analytics | Rolling, and not used to identify you individually |
6. Deleting your account
In the app: Settings → Delete Account. Deletion starts immediately and completes after a 48-hour window (so a mistaken tap, or someone else with your unlocked phone, can be undone). After that your profile, messages, photos, connections, phone number, location fix and nights history are gone.
You can also delete at gatemate.net/delete-account or by emailing info@gatemate.net; those are processed within 30 days.
Two narrow exceptions, both required to run a safe service: content already reported to moderation is retained for up to 30 days to resolve the report, and records we must keep by law.
7. Who we share data with
Only the services needed to run GateMate, each under contract to keep it confidential:
| Service | What it sees |
|---|---|
| Cloudflare R2 | Your uploaded photos and video clips |
| Twilio | Your phone number, to send a verification code |
| Hive AI | Images and first video frames, for moderation |
| Resend | Your email address, to send transactional email |
| Apple | Sign in with Apple, App Store distribution, crash reports, push delivery |
| Google (Firebase Cloud Messaging) | Push delivery on Android |
| Google Gemini (via our integration provider) | Reported text and the reported message, to triage safety reports; a room's title, category and venue label, to generate its banner art |
| OpenAI | Speech-to-text for voice-note transcripts and room-chat dictation. Receives only the audio being transcribed |
| AeroDataBox / FlightAware | Flight numbers and dates you ask us to track (no personal data) |
| ip-api.com | An IP address, to derive an approximate city for security alerts |
| MongoDB Atlas and our hosting provider | The database and servers GateMate runs on |
Our website also uses Microsoft Clarity for anonymous session analytics, loaded only after you accept the cookie banner. The app does not use Clarity.
8. Security
- Everything is encrypted in transit (HTTPS/TLS)
- Passwords are hashed with bcrypt and never stored in plain text
- Sessions use signed, expiring tokens; Apple refresh tokens are encrypted at rest
- Access to production data is limited to staff who need it
9. Children
GateMate is for people 18 and over. We don't knowingly collect information from anyone younger, and we delete such accounts when we find them.
10. Your rights
Depending on where you live you may have rights to access, correct, delete, export, or restrict use of your data, and to opt out of certain processing. California residents have additional CCPA rights. We do not sell personal information. Email info@gatemate.net and we'll action it.
11. Changes
We'll update this page as GateMate changes, and move the "Last updated" date. Material changes are announced in the app.
12. Contact
Email: info@gatemate.net · Company: QAlytics LLC dba GateMate™