Legal

Privacy Policy

Last updated: September 19, 2026

1. Who We Are

JibberJabber ("we", "us", "our") is a social events platform operated by JibberJabber Ltd. Our app and website are available at https://jibberjabber.live. If you have any questions about this policy, contact us at privacy@jibberjabber.app.

2. Information We Collect

Account information: When you register, we collect your name, email address, and profile photo (optional). If you sign in with Google, Apple, or Snap, we receive your public profile data (such as your name, email, and profile photo) from that provider — if you haven't set your own profile photo, we may use the one provided by Google or Apple to fill it in.

Location data: With your permission, we use your device's location to personalise your event feed and show you nearby events. This is only ever collected when you grant location permission, and is shared with our event-discovery data providers (see Section 4) solely to return relevant local results.

Contacts (optional): If you turn on Birthday Photos in Calendar Settings, JibberJabber requests access to your device contacts to match a synced birthday calendar event to that contact's name and photo. This matching happens entirely on your device — your contact list is never uploaded to or stored on our servers, and this feature is off by default.

Google Calendar data: Connecting Google Calendar is entirely optional and requires your explicit sign-in and consent. If you connect it, we request Google's calendar and userinfo.email scopes for two things: (1) reading your event titles, dates, times, and locations so they appear in your JibberJabber calendar, and (2) generating a real Google Meet video-call link when you request one for a JibberJabber event — this briefly creates a placeholder event on your Google Calendar to mint the link, then deletes it immediately. We do not otherwise write, move, or delete events on your Google Calendar, and we do not read email content or any other Google data. Your Google access and refresh tokens are stored in a restricted, owner-only database table (separate from your public profile) that only you and our backend can access. You can disconnect Google Calendar at any time from Settings — this revokes the stored tokens and removes events that were synced from Google.

Google Tasks data: Connecting Google Tasks is also optional. If you connect it, we request Google's tasks and userinfo.email scopes to read your task titles, due dates, and completion status into your JibberJabber calendar, and to write back the completion status when you check off a synced task in JibberJabber. We do not access any other Google account data. Tokens are stored the same restricted way as Google Calendar tokens, and you can disconnect Google Tasks at any time from Settings, which revokes the tokens and removes the synced tasks.

Our use of Google user data: JibberJabber's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We only use Google Calendar and Google Tasks data to power the user-facing scheduling features described above — never for advertising, and never read by a human except where you've reported a problem or where required for security, abuse-prevention, or legal compliance purposes.

Bella AI data: When you chat with Bella, our in-app AI assistant, your messages (including voice notes, if you send one) are sent to Google's Gemini API to generate a response. To make Bella's answers useful, we also share limited context with Gemini as part of the conversation: your name, city, interests, and account type; relevant calendar events; saved Bella preferences and notes; and, when you ask Bella to help coordinate plans, the names of friends involved and their availability. This data is sent only to generate that conversation's response and to let Bella take the actions you ask for (like adding a calendar event) — it is not used by us for advertising.

Events and tickets: We store events you create, save, or purchase tickets for, along with payment confirmation data (not card numbers — those are handled by Stripe).

Chat messages: Direct and group messages are stored on our servers to enable real-time messaging. Messages are participant-scoped — only people in a conversation can read them.

Usage data: We use PostHog to collect app usage analytics — the screens you visit, the buttons and elements you tap, and key actions like sending a message, viewing an event, or converting on a subscription paywall. When you're signed in, these events are linked to your account (your user ID, name, username, email, subscription tier, and account type) so we can understand how people use JibberJabber and improve the product. PostHog does not record your screen or session as video, and this data is not sold to third parties.

Device information: We may collect your device type, OS version, and push notification token to deliver notifications.

3. How We Use Your Information

  • To provide, maintain, and improve the JibberJabber service
  • To send you push notifications for events and messages (you can opt out at any time)
  • To process ticket purchases and manage your subscription via Stripe and RevenueCat
  • To personalise event recommendations via our Bella AI assistant
  • To respond to your support requests
  • To comply with legal obligations

4. Third-Party Services

We integrate with the following third-party services, each governed by their own privacy policy:

  • Supabase — database, authentication, and file storage
  • Stripe — payment processing (we never store card details). Event organisers and streamers who choose to receive payouts complete a separate onboarding flow hosted directly by Stripe (Stripe Connect), during which Stripe collects identity and bank details (such as name, date of birth, tax ID, and bank account number) directly from them. JibberJabber never receives or stores this information — it is held solely by Stripe under its own privacy policy
  • RevenueCat — subscription management
  • Google — Sign in with Google; optional Google Calendar sync (calendar scope) and optional Google Tasks sync (tasks scope), both user-initiated and disconnectable at any time in Settings
  • Apple — Sign in with Apple
  • Google (Gemini API) — powers our Bella AI assistant; processes your messages and the conversation context described in Section 2 to generate responses. Google's handling of this API data is governed by Google's own privacy policy and Gemini API terms
  • Mux — hosts and streams live-stream video for our live streaming feature
  • PostHog — product analytics; receives app usage events (screens viewed, taps, feature usage) and, for signed-in users, an account identifier plus your name, username, email, and subscription tier so events can be linked to your account. Governed by PostHog's own privacy policy
  • Resend — delivers transactional emails we send you (such as calendar invites and birthday wishes); receives your email address for this purpose only
  • Sentry — crash and error reporting; receives technical diagnostic data (device type, OS version, app version, and the error itself) when the app crashes or hits an unexpected error, to help us fix bugs
  • Expo / EAS — push notifications and app distribution
  • Ticketmaster, RAWG, TMDB, PandaScore, AllEvents, PredictHQ — public event and content discovery data; when you permit location access, your city-level location and search queries may be sent to these providers solely to return relevant local events

5. Data Sharing

We do not sell your personal data. We share data only:

  • With service providers listed above, strictly to operate the service
  • When required by law or court order
  • To protect the safety of users or prevent fraud
  • With your explicit consent (e.g. sharing an event link publicly)

5a. International Data Transfers

We and our service providers (including Supabase, Stripe, RevenueCat, Mux, Resend, Sentry, and Google) may process and store your data in the United States or other countries outside your own, including outside the European Economic Area (EEA) and United Kingdom. Where we transfer personal data from the EEA or UK to a country that has not received an adequacy decision, we rely on appropriate safeguards, such as Standard Contractual Clauses, with those providers.

6. Data Retention and Account Deletion

We retain your account data for as long as your account is active. You can request deletion of your account and personal data at any time by contacting us at privacy@jibberjabber.app (a self-serve in-app deletion option is also available).

Once a deletion request is confirmed, we erase your profile, memories, calendar events, AI conversation data, social graph (follows/followers), notifications, and reactions within 30 days, except where we are required or permitted to retain certain records, specifically:

  • Financial and ticketing records (purchase and payout history) — retained for up to 7 years to comply with tax and accounting law
  • Fraud-prevention and safety records (e.g. reports, moderation actions, abuse investigations) — retained as needed to protect users and the platform
  • Records subject to a legal hold — retained for as long as required by an active legal, regulatory, or law-enforcement obligation

These retained records are kept solely for the stated purpose, access is restricted, and they are deleted once the underlying legal or safety basis for retention no longer applies.

Messages you've sent: we remove your name and profile link from messages within shared conversations, but the message text (and any photos, videos, or voice notes attached) may remain visible to the other participants in that conversation, to preserve their conversation history — the same approach used by most messaging platforms.

7. Your Rights

Depending on your location, you may have rights under GDPR (UK/EU) or other applicable laws, including:

  • Access: Request a copy of your data
  • Correction: Update inaccurate data
  • Deletion: Request account and data deletion
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to certain processing

To exercise any of these rights, email us at privacy@jibberjabber.app.

7a. California Residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), gives you additional rights over your personal information.

We do not sell or share your personal information. JibberJabber does not sell personal information for monetary or other valuable consideration, and we do not share personal information with third parties for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA.

You have the right to:

  • Know / Access: Request what personal information we collect, use, and disclose about you, and receive a copy of it
  • Delete: Request deletion of your personal information, subject to certain legal exceptions
  • Correct: Request correction of inaccurate personal information
  • Opt out of sale or sharing: Not applicable — we do not sell or share your personal information, but you have this right regardless
  • Limit use of sensitive personal information: We only use sensitive personal information (such as precise location, if applicable) to provide the service you request, and not for purposes requiring an opt-out under the CCPA/CPRA
  • Non-discrimination: We will not deny you service, charge you a different price, or provide a different level of quality because you exercised any of these rights

To exercise any of these rights, email us at privacy@jibberjabber.app. We may need to verify your identity before fulfilling your request. We will respond within 45 days of receiving a verifiable request; if we need more time, we may extend this by an additional 45 days (90 days total), and we will notify you of the extension and the reason for it within the initial 45-day period.

8. Children's Privacy

JibberJabber is not intended for users under 13 years of age. We do not knowingly collect data from children. If you believe a child has provided us data, please contact us and we will delete it promptly.

9. Security

We use row-level security (RLS) on all database tables, encrypted connections (TLS), and industry-standard authentication via Supabase Auth. Sensitive credentials are stored in server-side secrets, never in the app bundle.

10. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes via in-app notification or email. Continued use of JibberJabber after changes constitutes acceptance.

11. Contact Us

Questions or concerns? Email us at privacy@jibberjabber.app or visit our Support page.