Legal
Privacy Policy
Last updated: 30 June 2026
This Privacy Policy explains what personal data Prost collects, why we collect it, how long we keep it, and the rights you have over it. Prost is operated from Germany and complies with the EU General Data Protection Regulation (GDPR).
1. Who is responsible
During the beta, Prost is operated by three individuals acting as joint data controllers, Derick David, Baran Ayaz and Aiden Dalley (collectively “The Prost Team”):
The Prost Team
Bürgermeister-Deichmann-Straße 31
28217 Bremen, Germany
Email: support@prosts.net
2. What we collect
2.1 Account data
Prost uses Sign in with Google on all platforms and Sign in with Apple on iOS. When you sign in, we receive a unique account identifier and, depending on your provider settings, your name and email address. During onboarding you choose a username, which is your visible identity in Prost. We do not collect passwords.
2.2 Session content
When you start or join a Night session, the following is stored and shared with the other participants of that session:
- Session name, start/end times, and the list of participants
- Photos and videos captured with the Prost Camera or imported from your photo library
- Venue names, resolved from your location via the Google Places API, forming the night’s venue trail
- Sidequest content: the photo or video proof you capture for a quest and your crew’s confirm/reject votes
- Session chat messages (encrypted, see Section 2.5)
2.3 Location data
Prost uses your precise location in two ways:
- Venue stamping: when you capture a photo, your location is used at that moment to resolve a venue name. We store the venue name string, not raw GPS coordinates, with the photo.
- Live session map: while you are in an active session, your location is shared in real time with the other participants of that session so your crew can find you. This includes background location while a session is live, if you grant that permission. Location sharing stops when the session ends, and stale location data is automatically cleaned up by our servers.
We do not track your location outside of active sessions.
2.4 Device permissions
- Camera & microphone: to capture photos and videos with sound during sessions.
- Photo library: to import photos into a Recap and to save your Recap cards.
- Motion data: to understand your activity during a session (e.g. for Recap stats).
- Notifications: we store a push notification token (Firebase Cloud Messaging) to deliver session and message notifications. You can disable notifications at any time in your device settings.
All permissions are optional and requested in context; denying them limits only the related feature.
2.5 Messages
Direct messages and session chat messages are encrypted with AES-256-GCM before being stored on our servers. Message content is not readable in plaintext at rest.
2.6 Social graph and stats
If you follow other users, we store your follow relationships and pending follow requests. We also derive aggregate stats from your sessions, nights out, unique venues visited, weekly streaks, to power your profile, achievements, and the opt-in leaderboard. You only appear in leaderboard rankings if you opt in via Settings, and rankings are never based on how much anyone drank.
2.7 Safety and moderation data
If you block or report another user, we store your block list and the report (reported account, reason category, and optional note) so our team can review it and enforce our Community Guidelines.
2.8 What we do not collect
- No contact list or address book access
- No advertising identifiers, no ad networks
- No third-party analytics or tracking SDKs
- No raw GPS history attached to your photos
3. Why we process your data (legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the app: accounts, sessions, Recaps, messaging | Contract performance, Art. 6(1)(b) |
| Live location sharing during sessions | Consent, Art. 6(1)(a), via your permission grant; withdraw any time in device settings |
| Safety, moderation, abuse prevention | Legitimate interest, Art. 6(1)(f) |
| Legal obligations (e.g. responding to lawful requests) | Legal obligation, Art. 6(1)(c) |
4. Who processes your data
Prost is built on Google Firebase (Google Ireland Ltd. / Google LLC), which provides authentication, databases, file storage, server functions, and push notifications under data processing terms with us. Venue names are resolved through the Google Places API. Where data is transferred outside the EU/EEA, transfers are protected by the EU–US Data Privacy Framework and/or Standard Contractual Clauses.
We do not sell, rent, or trade your personal data. Ever.
5. How long we keep your data
- Session content: kept until you delete it. You can delete individual photos, Recap cards, or entire sessions in the app at any time.
- Live location: held only during an active session; removed when the session ends and swept by automatic cleanup.
- Account data: kept while your account exists. When you delete your account, your data is permanently erased after a 30-day grace period (see below).
- Reports: kept as long as needed to handle the report and enforce our guidelines.
6. Deleting your account
You can delete your account at any time in the app: Profile → Settings → Delete Account. Deletion takes effect after a 30-day grace period, after which all personal data associated with your account is permanently removed in accordance with GDPR Art. 17. Full instructions are on our account deletion page.
7. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Erase your data (“right to be forgotten”)
- Restrict or object to processing
- Receive your data in a portable format
- Withdraw consent at any time (e.g. revoke location permission in device settings)
To exercise any of these rights, email support@prosts.net. You also have the right to lodge a complaint with your local data protection authority; for Bremen, that is the Landesbeauftragte für Datenschutz und Informationsfreiheit der Freien Hansestadt Bremen.
8. Age requirement
Prost is for adults 18 and over. We do not knowingly collect data from anyone under 18. If we learn that a user is under 18, we terminate the account and delete its data. See our Child Safety Standards.
9. Security
Data in transit is protected with TLS. Direct messages are encrypted at rest with AES-256-GCM. Access to production data is restricted and controlled through Firebase security rules. No system is perfectly secure, if you believe your account is compromised, contact support@prosts.net immediately.
10. Changes to this policy
If we make material changes to this policy, we will notify you in the app at least 30 days before they take effect. The current version is always available at prosts.net/privacy.
11. Contact
Questions about privacy? Email support@prosts.net or write to the address in Section 1.