How Gast handles your data — in plain language, because the whole point of Gast is that there's very little of it to handle.
This is a working draft. It sets out how Gast is designed to handle data, but it is being finalised by qualified legal counsel before it becomes final. Items shown as brackets are placeholders still to confirm.
Gast (“Gast”, “we”, “us”, “our”) is a travel loyalty-points tracking service provided by Operating entity — Swedish AB, to be registered, reg. no. org.nr to follow, established at registered address, Sweden.
For the purposes of the EU General Data Protection Regulation (GDPR) and Swedish data-protection law, the operator named above is the data controller of the personal data described in this policy.
Contact for all privacy and support matters: support@getgast.app
We have not appointed a Data Protection Officer. We are not required to under Article 37 GDPR: we are not a public authority, and our core activities do not involve large-scale regular and systematic monitoring of individuals or large-scale processing of special-category data. Sweden imposes no broader DPO obligation. You can reach a real person about any privacy question at the address above.
This policy applies to:
The App Store itself is operated by Apple under Apple’s own privacy policy, not this one.
We deliberately collect as little as possible. We never collect or store your loyalty-programme passwords or log in to your loyalty accounts on your behalf (see section 5).
| Data | Why we process it | Legal basis (GDPR Art. 6) | Retention |
|---|---|---|---|
| Email address | Create/secure your account, magic-link sign-in, subscription receipts | Performance of a contract (6(1)(b)) | Until you delete your account |
| Loyalty data — programmes you hold, balances, dates, tier/status labels you enter | The core service: showing balances, total estimated value, expiry alerts, and guidance | Performance of a contract (6(1)(b)) | Until you delete the entry or your account |
| Anonymous device / user identifier | Let you use the App before creating an account (anonymous-first onboarding) | Legitimate interests (6(1)(f)) — enabling a frictionless, no-signup experience | Until deletion or until linked to an account |
| Screenshots and forwarded statement emails you choose to submit | AI-assisted extraction of a balance and any expiry/last-activity date | Performance of a contract (6(1)(b)) | Processed transiently; see section 4 |
| Subscription status (Gast Plus entitlement) | Grant and manage access to paid features | Performance of a contract (6(1)(b)) | For the life of the entitlement per Apple / our subscription provider |
| Product analytics events (via TelemetryDeck) | Understand feature usage and improve the product | Legitimate interests (6(1)(f)) | Held in aggregated / pseudonymised form |
| Marketing-consent flag | Record whether you opted in to marketing email | Consent (6(1)(a)), captured separately from sign-up | Until you withdraw consent |
Is providing this data mandatory? Your email and the loyalty data you enter are necessary to provide the App’s core functions — without them the service cannot work. Marketing consent and (where consent-based) analytics are always optional and never a condition of using Gast.
Payment data. All payments and card details are handled entirely by Apple through the App Store. Gast never sees, receives, or stores your payment-card information.
Some paid features use artificial intelligence:
To provide these features, the relevant input (a screenshot, a forwarded email, or a structured summary of your holdings) is sent to our AI processing provider, Anthropic, PBC (operator of the Claude API), acting as our processor. This provider is located in the United States; see section 8 on international transfers.
We send only what is needed for the specific task, the processing is server-side and metered, and your data is not used to train the AI provider’s models. By default, Anthropic deletes API inputs and outputs from its systems within 30 days. Where a request is flagged for a potential usage-policy violation, Anthropic may retain it longer to investigate.
On our side, we do not store the raw inputs. A screenshot you submit is passed through our server to the AI provider in a single request and is never written to our database, storage, or logs — only the extracted balance and date are saved to your wallet. A statement email you forward is received and held by our email provider (Resend); our server reads it only to extract the balance and date, which are saved to your wallet, and we never copy the email body into our own systems. Failed or low-confidence extractions are discarded — we keep no images or emails from them, and we build no training or matching dataset from your inputs.
Not automated decision-making with legal effect. The advisor and “Points or Cash?” outputs are informational guidance only. They do not produce legal or similarly significant effects about you, and you are not subject to a decision based solely on automated processing within the meaning of Article 22 GDPR. Point valuations and recommendations are estimates, not guarantees, and are not financial advice.
This is a core security design choice, not just a policy statement.
We do not sell your personal data. We share it only with the service providers (“sub-processors”) that help us run Gast, each bound by a data-processing agreement and permitted to use the data only on our instructions.
| Sub-processor | Role | Data touched | Region | EU→US transfer safeguard |
|---|---|---|---|---|
| Supabase | Hosting, database, authentication | All stored user data | EU region selected | N/A (EU) |
| Resend | Transactional and inbound email (magic links, receipts, statement forwarding) | Email content and addresses | EU region selected | N/A (EU) |
| Anthropic (Claude API) | AI parsing and advisor | Screenshots, forwarded emails, portfolio summaries | United States | Standard Contractual Clauses (DPA), DPF as secondary basis |
| RevenueCat | Subscription management | Subscription identifiers | United States | Standard Contractual Clauses (DPA) |
| TelemetryDeck | In-app product analytics | Pseudonymised event data | EU | N/A (EU) |
| Umami (Umami Cloud) | Website analytics (cookieless) | Aggregated, non-identifying visit data | EU | N/A (EU) |
| Apple | App distribution and payments | Account and payment data (held by Apple) | US / global | Apple’s Standard Contractual Clauses |
We may also disclose data where required by law, to enforce our Terms, or to protect the rights, safety, or property of our users or ourselves.
Wherever a provider offers an EU region, we select it (Supabase, Resend, TelemetryDeck). Some providers necessarily process data in the United States (Anthropic, RevenueCat, Apple).
Where personal data is transferred outside the European Economic Area (to the US sub-processors above), we rely on an appropriate safeguard under Chapter V GDPR.
Our primary safeguard is the European Commission’s Standard Contractual Clauses (2021 SCCs), which each of our US providers incorporates into its data-processing agreement (Anthropic, RevenueCat, and Apple). Where a provider is also certified under the EU–US Data Privacy Framework, that certification serves as a secondary adequacy basis. We keep a Transfer Impact Assessment on file for these transfers and apply supplementary measures (such as EU-region hosting for stored data and encryption in transit) where appropriate.
We rely on the SCCs as the lead mechanism deliberately, so that our transfers remain lawful regardless of the ongoing legal uncertainty around the Data Privacy Framework. You may request a copy of the relevant safeguards at support@getgast.app.
We keep personal data only as long as needed for the purposes above:
When you delete your account, we delete or irreversibly anonymise your personal data within a reasonable period, except where retention is legally required.
Under the GDPR you have the right to:
In-app tools. You can access, export, and delete your data directly in the App under Settings → data. Account deletion is fully self-service.
To exercise any right, use the in-app tools or contact us at support@getgast.app. We respond within the timeframes set by the GDPR (normally one month).
Right to complain. You may lodge a complaint with a data-protection supervisory authority. Our lead authority is the Swedish Integritetsskyddsmyndigheten (IMY) (imy.se); you may also complain to the authority in your own EU country of residence.
We only send marketing email if you have separately opted in. You can withdraw consent at any time via the unsubscribe link in any marketing email or in the App. Service and transactional messages (magic links, receipts, essential alerts) are not marketing and are sent as part of providing the service.
The App does not use advertising cookies or third-party tracking cookies.
The Website (getgast.app) is a marketing and information site with no accounts or logins. It:
Any website server logs (e.g. a truncated/hashed IP, needed for security and delivery) are kept for a short period on the basis of our legitimate interest in operating a secure site.
Gast is not directed at children. You must be at least 16 years old to use Gast. We do not knowingly collect personal data from anyone below that age; if we learn that we have, we will delete it.
We use industry-standard measures to protect your data, including EU-region hosting where available, row-level access controls, encryption in transit, and keeping all provider credentials server-side. No system is perfectly secure, but not storing loyalty credentials materially reduces the risk to you.
We may update this policy as the product or the law changes. We will post the updated version here with a new “last updated” date and, for material changes, notify you in the App or by email.
Questions or requests: support@getgast.app
Controller: Operating entity — Swedish AB, to be registered, registered address, Sweden.