Legal

Privacy Policy

Last updated: July 2026 · Gatekyp is operated from the United Kingdom

What we collect

We collect: your email address and name (required for account creation); fragrance data you add (bottle names, notes, wear logs, photos); device and session identifiers for security; payment information (processed by Stripe — we never see your full card number); usage analytics to improve the product; and, only if you choose to connect a calendar, limited calendar event data as described below.

How we use your data

Your data powers your personal Gatekyp experience — recommendations, analytics, AI features, and community features. We do not sell, rent, share, or monetise your personal data with third parties. We do not use your data for advertising.

AI features

When you use Ask AI, AI recommendations, or the bottle scanner, the relevant data (your collection details, wear history context, or the photo you scan) is sent to our AI processing providers — Groq, Anthropic, and Google's Gemini API — solely to generate the response you asked for. If you connect your own AI API key in Settings, those requests go to your chosen provider under your own account instead. Under our API terms with these providers, your data is not used to train their models and is not retained beyond the request window. See each provider's privacy policy for their data practices.

Calendar data (Google Calendar, Outlook, Apple Calendar)

What we access. If you choose to connect the Fragrance Calendar feature, we request read-only access to your calendar events via the Google Calendar API scope calendar.events.readonly (and, where offered, Microsoft or Apple calendar APIs). We read event titles, descriptions, locations, start/end times, and all-day flags for upcoming events in a rolling 60-day window from your primary calendar. Because the scope is read-only, Gatekyp cannot create, edit, or delete anything in your calendar — wear reminders are delivered as in-app or push notifications only and are never written to your calendar.

How we use it. Event data is used solely to classify the type of occasion (e.g. wedding, formal dinner, work meeting), fetch a weather forecast for the event's location and time, and suggest a matching fragrance from your own collection, with an optional reminder. Nothing else.

What is shared. We do not sell calendar data, use it for advertising, or use it to train AI models. When you ask for an AI fragrance suggestion for a specific event, the event's title, location, and a short snippet of its description are sent to our AI processing provider (or to the AI provider you have connected with your own key) for the sole purpose of generating that suggestion. These providers act as processors under terms that prohibit using the data for anything else, including training their models. No other third party receives calendar data.

How it is protected, retained, and deleted. Calendar OAuth tokens are encrypted at rest (AES-256-GCM) and synced event data is protected by row-level security so only your account can read it. Synced events are kept only while the feature is connected and are refreshed on each sync. Disconnecting your calendar (Settings → Calendar → Disconnect) immediately deletes your tokens and all synced event data; deleting your account does the same. Gatekyp's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Data storage & security

Your data is stored on Supabase (hosted on AWS in the EU). All data is encrypted in transit (TLS 1.3) and at rest (AES-256). Row-level security policies ensure only you can access your data — even our internal team cannot read your collection without your account credentials.

Passkeys & biometrics

If you register or sign in with a passkey, your biometric data (Face ID, Touch ID, fingerprint) never leaves your device. We store only a cryptographic public key. Your biometric data is never transmitted to or stored by Gatekyp.

Cookies

We use essential session cookies to keep you signed in and remember your preferences. We do not use third-party advertising or tracking cookies. You may disable cookies in your browser but this will affect functionality.

Data retention

We retain your data for as long as your account is active. You may request account deletion at any time by contacting privacy@gatekyp.com — all personal data will be deleted within 30 days, except where retention is required by law.

Your rights (UK GDPR)

You have the right to: access a copy of your personal data; correct inaccurate data; request deletion; restrict or object to processing; data portability. To exercise any of these rights, contact privacy@gatekyp.com. You also have the right to lodge a complaint with the ICO (ico.org.uk).

Third-party services

We use: Supabase (database & auth), Stripe (payments), Groq, Anthropic and Google Gemini API (AI features — see above), Google Calendar API and Microsoft Graph API (optional calendar sync — see above), OneSignal (push notifications), Cloudinary (image hosting), Vercel (hosting). Each has their own privacy policy governing their handling of data.

Contact

For all privacy-related requests: privacy@gatekyp.com

Your data is yours.

We don't sell it, share it, or use it for ads. Ever.

Open Gatekyp →