Gatherjar › Privacy
Privacy Policy — Gatherjar
Last updated: 7 October 2026
This policy explains what happens to data when you use Gatherjar (the “App”), the event planning website published by Cronomz — “we”, “us”.
Contact: cronomzstudio@gmail.com
Gatherjar keeps what you put into an event (its details, the guests’ names and answers) so everyone with the event link sees the same plan. There are no accounts, no ads and no analytics. We never sell or share your data. Venue search and maps come from Google, and the App runs on Cloudflare.
1. The short version
| Do I need an account? | No. Hosts and guests are recognised by a secret link and a cookie on their device. Anyone can choose to sign in with Google so their events follow them to any device (section 2a). It is never required. |
| Who can see my event? | Anyone who has the event link. Treat the link like a group chat invite: share it only with people you want there. |
| What do guests have to give? | A name, typed or tapped from the host’s list of who’s invited. A phone number is optional and only the host sees it. |
| Do you run ads, analytics or tracking? | No. There is no advertising, analytics or tracking code in the App. |
| Do you sell my data? | No. We never sell, rent or share personal data. |
| How do I delete things? | Hosts can delete the whole event, and guests can remove themselves, right in the App (section 7). |
2. What we store about an event
When you create or answer an event, our database (Cloudflare D1, see section 6) stores:
- The event — its title, description, the host’s name, date and time or dates (or the date options), place (or the place options, including a Google place ID when a place was picked from the venue finder), time zone (which the host can change), whether and when the host cancelled it (with their note to guests, if they wrote one), the date before the host last moved or postponed it, the place before the host last changed it, whether it’s an online event (a video call, whose link is stored as the place’s link), the host’s language (so the invitation opens in it), colour, seat limit, polls, bring list and announcements, and, if the host adds them, the names of the people they’re inviting (so guests can tap their name instead of typing it). If someone on that list removes themselves from the event, their name stays on the host’s list, marked as not coming, so the host’s updates stop asking them.
- The schedule and budget — the stops the host adds to each day (time, place, address, Google place ID, map link, note) and their costs, in the event’s currency, and how many people the host expects (shared costs are split among at least that many). The currency is guessed from the host’s country when the event is made.
- Each guest — the name they typed, their phone number if they chose to give one, whether they’re coming and how many people they bring (and how many of them are children, if they say) (when the host picks a date, a guest who hasn’t answered yet gets the answer from their vote for that date, and is asked to confirm it), their poll answers, the places they suggested, the bring-list items they claimed and, if they wrote one, what exactly they’re bringing. The host is added as a guest of their own event, marked as going.
- Your dashboard — the list of your events, what needs you, and your most frequent places and people are worked out from the events above each time you open it. Nothing extra is stored for it, and it only uses events you host, joined, or are treasurer of on that device. When you open a new event on a device that already answered others, the name you used there is offered so you don't have to type it again; it never leaves your device's own events.
- A fingerprint of each secret link — we store a one-way hash of the host and guest links, not the links themselves, so we can recognise you without being able to recreate your link.
2a. If you sign in with Google
Signing in is optional, for hosts and guests. If you choose Sign in, Google asks you to share your basic profile with Gatherjar, and we store:
- your Google account ID, email address and name, so we can recognise you next time;
- which events are linked to your account: events you host, and the events you joined as a guest, on the browser where you sign in or while signed in;
- a sign-in session for each browser you use, stored only as a scrambled (hashed) form of the session cookie, which expires after 60 days without use.
We use the email address only to show which account is signed in, and other people never see it: in an event you appear with the name you typed there. We only email you if you turn on reminder emails (section 2c), and we don’t receive your Google password, contacts or anything else from your Google account. Google handles the sign-in under the Google Privacy Policy.
Deleting your account: tap your initials at the top of your events → Delete account. The account and its sessions are deleted straight away. Your events stay and keep working with their host links; delete them separately if you want them gone.
2b. Guests the host removed
When a host removes a guest and chooses to stop them joining again, we keep a scrambled (hashed) form of that guest’s link for the event, so their browser can’t rejoin it, and, if they were signed in, a note of their account so it can’t rejoin either. Both are deleted with the event.
2c. Reminders
Reminders are optional. They are sent the day before an event, when a vote is about to close, when someone hasn’t answered yet, and when bring-list items are still unclaimed, never at night in the event’s time zone. Each reminder is sent once.
- On your phone (notifications). If you choose Remind me on this phone and allow notifications, your browser gives us a notification address and encryption keys for this browser. We store them with the event you turned reminders on for (and which guest you are, or that you are the host) and the language to write in. Besides reminders, guests get the host's announcements for that event and a note when they get a place from the waitlist. Messages are encrypted for your browser and delivered by your browser’s own push service (for example Google for Chrome, Apple for Safari, Mozilla for Firefox), which can’t read them. Turning the switch off, blocking notifications, or deleting the event removes this.
- By email. Only if you signed in and choose Email me reminders. We send them to your Google account’s email address through Resend, our email provider, under the Resend privacy policy. Every email has an Unsubscribe link, and you can switch them off in any event.
- Through WhatsApp. The host’s Remind people screen prepares messages that the host sends from their own WhatsApp. We don’t send these and receive nothing back.
- In your calendar. Add to calendar files include alarms that your calendar app shows itself. Nothing is sent to us.
To avoid sending a reminder twice, we keep a note of which reminders went out for each event. It is deleted with the event.
2d. The money jar
If the host collects money for an event, Gatherjar never holds or moves the money: guests pay the host or treasurer directly, through their own bank or e-wallet, and Gatherjar only keeps track. We store:
- The jar — the amount, the due date, a note, and the ways to pay the host enters (for example a bank account number and name, an e-wallet number, a payment link, or a payment QR image). These are shown to everyone with the event link, because guests need them to pay.
- Payments — when a guest taps I’ve paid: the amount, an optional note, and an optional screenshot of the transfer, plus whether the host or treasurer confirmed it and who did, and, if the guest can’t come, whether the host refunded it or kept it. Screenshots can show names and account numbers, so only the host, the treasurer and the guest who sent it can open them.
- The money report — other income and expenses the host or treasurer adds, with optional receipt photos. Guests see it only if the host chooses to show it.
- Treasurers — the name the host gives and a scrambled (hashed) form of their private link.
Images are stored in Cloudflare R2 (see section 6) and served only through Gatherjar, which checks who is asking. Screenshots and receipts are deleted automatically 90 days after the event (the payment records stay, without the image). When a guest removes themselves or is removed, payments nobody confirmed (and their screenshots) are deleted; confirmed and refunded payments stay in the host’s records under the guest’s name, so the jar keeps matching the money the host actually holds and a refund can be recorded; deleting the money jar or the event deletes all of its payments, report, images and QR code.
3. Who can see what
- Everyone with the event link sees the event details, the schedule and budget, the guest list with names and answers, the names the host listed as invited who haven’t answered yet, the bring list, announcements and poll results. Names next to poll answers are hidden from guests if the host made that poll anonymous; the host still sees them. A name is not proof of who someone is: anyone with the link can tap a name from the host’s list, so share the link only with the people you’re inviting.
- The host and treasurer see who has paid and how much, and payment screenshots. Guests see their own payments, the total collected, and names only if the host chooses to show who has paid.
- Only the host sees guests’ phone numbers. The App uses them only to give the host a WhatsApp button for that guest.
- We can see stored events when needed to keep the App running, fix a problem or answer a support request. We don’t read events otherwise and we don’t use them for anything else.
4. Cookies and storage on your device
| Name | What it’s for |
|---|---|
Host cookie (gj_h_…) | Remembers that you are the host of an event on this device. Lasts one year. |
Guest cookie (gj_g_…) | Remembers which guest you are in an event, so you can change your answers. Lasts one year. “Not you?” removes it (and, if you choose, deletes what was saved under that name). |
Sign-in cookie (gj_s) | Only if you sign in with Google: keeps you signed in on this browser. Lasts 60 days and is renewed while they use Gatherjar. “Sign out” removes it. |
Sign-in check (gj_oauth) | Only while signing in: protects the trip to Google and back. Lasts 10 minutes. |
Language cookie (lang) | Remembers English or Indonesian if you choose one. Lasts one year. |
| Browser storage | The name you used as a host (to fill it in next time), the last area you searched for venues, and which events you turned phone reminders on for. These never leave your device. |
These are all needed for the App to work. There are no advertising or tracking cookies.
5. Venue search, maps and your location
- Venue search. When you use “Find a place”, the App sends what you typed (a place name, an area such as “Kemang”, and the kind of place) through our server to the Google Places API, which returns places with their rating, price and opening hours. We don’t store the search or the results; only the Google place ID of a place you choose is saved with the event.
- “Near me”. If you tap it and allow it, your browser gives the App your approximate location, which is sent through our server to Google with the search so results are nearby. It is not stored.
- Buka bersama times. “Use my location” for the maghrib time works out the time inside your browser. That location isn’t sent anywhere.
- Place details. When you open “Details” for a place, the App asks the Google Places API, through our server, for that place’s current rating, type, price level and opening hours. Only the place ID is sent. The answer is shown to you and not stored.
- Map card. In the same “Details” sheet, a Google map is loaded straight from Google into the page, and “Directions” opens Google Maps.
- Fonts. The App loads its typeface from Google Fonts.
For the map card and fonts your browser connects to Google directly, so Google receives your IP address and may use cookies, under the Google Privacy Policy. Place information is shown under the Google Maps Terms.
Daily search limit. To keep venue search free, each device can search, and open place details, a limited number of times a day. To count this, we store a daily counter next to a scrambled (hashed) form of your IP address. Counters from earlier days are deleted, so it is kept for one day at most.
6. Hosting and other services
- Cloudflare hosts the App, its database (stored in the Asia-Pacific region) and its image storage (R2). Like any web host, it handles your IP address and the pages you request. The App uses the country and time zone Cloudflare detects to suggest your language, holidays and time zone. See the Cloudflare privacy policy.
- Public holidays for countries other than Indonesia come from date.nager.at. Our server asks for a country’s holiday list; no information about you is sent.
- Exchange rates come from Frankfurter (the European Central Bank’s daily reference rates), to show a rough amount in your own currency next to costs in another one. Our server asks for the rate between two currencies; no information about you is sent.
- WhatsApp. Share buttons open WhatsApp with a message you can edit and send yourself. We receive nothing from WhatsApp.
7. How long we keep it, and deleting it
Events and their guest answers are kept so the link keeps working, until they are deleted:
- A whole event — the host opens Event settings → Postpone, cancel or delete → Delete event. The event is deleted with all its guests, answers, votes, schedule, bring list and announcements. (Cancelling instead keeps the event, marked as cancelled with the host’s note, until the host deletes it.)
- Yourself, as a guest — tap your name at the top of the event and choose Remove me from this event. Your name, phone number, answers, votes and bring-list claims are deleted. Money you paid that the host confirmed stays in the host’s records under your name (see section 2d).
- An answer under the wrong name — tap the name at the top of the event, choose Not you? and then Remove it and pick my name. Everything saved under that name on this device is deleted the same way.
- A guest, as the host — the host can remove any guest from the People tab, which deletes the same data.
- Your account — see section 2a.
- Can’t use the App? Email us the event link (and, for your own answers, the name you used) and we’ll delete it for you.
Deleted events are removed from the database straight away. Cloudflare may keep backups of the database for a limited time (up to 30 days) before they expire.
8. What we do not do
- We do not show ads, and we do not use analytics, advertising, attribution or crash-reporting code.
- We do not sell, rent or trade personal data, or use it for advertising.
- We do not ask for passwords or contacts, and nobody has to give an email address. People share theirs only if they choose to sign in with Google.
- We do not send messages to your guests on your behalf; you share the link yourself. Guests only get reminders they switched on.
9. Your rights
You have the right to access, correct, delete and object to the processing of your personal data. Guests can change their name, phone number and answers in the event at any time. For anything else, write to us. If you believe your data has been handled unlawfully, you may complain to your local data protection authority.
10. Children
Gatherjar is not directed to children under 13, and we do not knowingly collect personal data from children.
11. Changes to this policy
If Gatherjar starts handling data differently, for example by adding accounts or paid features, this policy is updated before that change goes live, and the “Last updated” date above changes with it.
12. Contact
Cronomz
Email: cronomzstudio@gmail.com