Privacy Policy
Effective 2026-07-25 · Version 1.0.0
This Privacy Policy describes how the Emu team (“Emu”, “we”, “us”) collects, uses, stores, and shares your personal data when you use the Emu mobile application (the “App”) and the website at getemu.app (together, the “Service”).
We are based in Australia. We process personal data in line with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), Brazil’s LGPD, and other applicable laws depending on where you are based.
Where we operate. The Service is not offered to, and is not intended for, residents of the European Economic Area (EEA), the United Kingdom, or Switzerland. The App is not made available on those App Store storefronts. If you are in one of those regions, please do not use the Service.
1. What we collect
We collect only what we need to run the Service.
Account data
- A user identifier issued by our authentication provider (Supabase Auth)
- Your email address (if you sign in with email)
- Your name (if you provide it during email sign-up)
- Whether your account is anonymous
- Account creation and update timestamps
- The timestamp of your most recent authenticated request, used to detect dormancy and decide whether to send re-engagement reminders
If you sign in with Apple or Google, we receive an identity token from that provider. We do not receive your Apple or Google password, and we do not request anything else from those providers beyond the minimum needed to identify your account.
Usage data
Inputs you provide when asking for a suggestion (such as your mood, who you’re with, time available, transport, and any notes), the suggestions we return to you, details of the adventures you create or join, and how you respond to them, such as reactions and written feedback. We also keep counters needed to enforce free-tier limits.
Location data
To find places or spots for you, we need to know where to search. You provide this in one of three ways:
- GPS from your device (with your operating-system permission),
- A place or address you type in, which we look up via Google Places, or
- An area you pick on the map in the App.
What we do with it: your chosen location is used only to (a) search for nearby venues via Google Places, (b) fetch local weather and air quality, (c) give our AI enough context to pick a relevant spot, and (d) display travel time to the suggestion. That’s it. We don’t use it to build advertising profiles, infer anything about you, or track your movements over time.
Solo suggestions: we do not keep your location. For a solo suggestion, the location you provide travels with your request, is used to generate the suggestion, and is automatically erased from our systems within a few hours of the request finishing. We never log your movements, and we never track you in the background.
Adventures planned with friends: the search area you pick is saved with your picks. When you add your picks to a co-planned adventure, the area you choose on the map (a coordinate and search radius) is stored with the adventure so the group’s suggestion can be generated and, if the members want changes, reworked. This is a spot you deliberately picked for the outing, not a log of where you’ve been. It is never shown to the other members of the adventure, and it is deleted with the adventure or with your account, whichever comes first.
You can revoke location permission at any time in your device settings. The App keeps working. You can type a place or pick an area on the map instead.
We also do not store the coordinates of the places we suggest to you. We only save a stable Google “place ID” so we can fetch fresh details (including coordinates) from Google when you revisit the place from your history. See Section 6 for details.
Invite list (people you add)
If you plan adventures with friends, you can build an invite list. You can type a person’s details in yourself, or grant the App permission to read your device contacts and pick people from there. Contacts access is optional; the feature works without it.
- We store only the people you choose, never your whole address book.
- We store only their name and phone number. Nothing else from the contact card is collected.
- We use this data only to run the invite flow: showing you who you’ve invited, recognising an invitee when they join one of your adventures through its invite link, and connecting adventures you plan with the people you’ve invited (an invitee who already uses Emu may see your adventure in their own app).
- Emu never contacts the people you add. We do not send them SMS, email, or messages of any kind. You share your adventure invite link yourself, from your own device.
- We never sell invite list data, share it for advertising, or use it for marketing.
- You can edit or delete any contact in the App at any time. Deleting your account permanently deletes your invite list with it.
Information others may provide about you
Just as you may add people to your invite list, another Emu user may add your name and phone number to theirs to invite you to an adventure. If that happens, we hold that name and phone number as part of that user’s invite list, under the same rules described above: invite purposes only, never contacted by us, never sold or shared.
You do not need an Emu account to have this data removed. See Section 9 for how to ask us to show, correct, or delete a contact entry that describes you.
Device data
- A device identifier issued by your operating system (or a unique identifier we generate locally if none is available), used to prevent abuse such as creating many anonymous accounts from the same device.
- Your IP address, used in memory to enforce rate limits. We do not store raw IP addresses.
Notification data
If you enable push notifications, we store the push token issued by your device’s operating system so we can deliver notifications to it. We also keep an internal log of what we sent and when, so we can measure delivery reliability and avoid sending you the same nudge twice. The log does not contain personal information beyond the link to your account and is deleted with your account.
Subscription data
If you purchase a subscription, our subscription provider (RevenueCat) receives your account identifier and the product you bought. We receive the resulting subscription status. Apple or Google processes your payment directly; we never see your card details.
Consent records
When you accept our Terms and confirm you are 18 or older, we keep a record of your consent so we can demonstrate it was given. Alongside each consent record we store a one-way cryptographic hash of the IP address the consent came from, never the raw address.
A note on free-text fields
Emu has several free-text fields, including notes on your picks and feedback on adventures and stops. Please do not type information about your health, race, religion, political views, sexual orientation, or other sensitive personal information in them. We do not solicit, infer, or store sensitive characteristics. We do not share what you type with advertisers, and we do not use your inputs to identify you or infer sensitive attributes.
Your free-text inputs are stored alongside the action they relate to and are deleted with your account.
Information about the people you’re with
For solo suggestions, we ask who you’re with so the AI can tailor the suggestion to your context, and we collect only a broad category (such as “partner” or “friends”). No names, no contact details, no identifying information. Planning an adventure with people you invite works differently and is described in the invite list sections above and in Section 2.
Sources of personal information
We collect personal information from:
- You directly, when you sign up, accept our Terms, or use the App (for example, your email address, your sign-up choices, your suggestion inputs, your invite list, and any free-text notes).
- Other Emu users, when someone adds your name and phone number to their invite list to invite you to an adventure.
- Your device, including identifiers issued by your operating system, your IP address (held in memory only), your approximate or precise location (with your permission), contacts you choose to import (with your permission), and your push notification token.
- Authentication providers (Apple, Google, and Supabase Auth) when you sign in, in the form of an identity token and a user identifier.
- Our subscription provider (RevenueCat) for your subscription status.
- Google for venue, weather, and air quality data tied to a specific suggestion request.
2. Planning with friends
Premium users can plan an adventure together with the people they invite. Because this involves more than one person, here is exactly who can see what.
Adventure invite links
Each co-planned adventure has one invite link containing a long, unguessable code. Anyone who holds the complete link can see the adventure’s title on the invite preview page, so share the link only with the people you want to invite. The host can generate a new link at any time, which immediately invalidates the old one. Invite pages are excluded from search engines.
Joining
To join through an invite link, you sign in and enter your phone number. We use it only to check that you are one of the people the host invited; it is not stored from the join request, and no profiling is involved. If you are not on the host’s invite list, you cannot join.
What an adventure’s members can see
- The host sees the names of the people they invited (the names come from the host’s own invite list), who has joined, and who has submitted picks.
- Everyone in the adventure sees the shared adventure: the title, the proposed day, the deadline, and the generated itinerary.
- Your individual picks are private. The vibe, time, transport, area, and notes you submit are used to generate the group adventure and are never shown to the host or to other members.
- Reactions are anonymous. When members react to stops in an adventure, the group sees only combined counts and unattributed reasons. Reactions are never shown as coming from a specific person, to the host or to anyone else.
- Other members never see your phone number. The person who invited you already has it in their own invite list; Emu does not reveal it to anyone else.
Leaving and deleting
Removing an adventure from your list removes it for you only; the other members are unaffected. If you delete your account, all your personal data is erased as described in Section 8, and any invite list entries that linked to your account are unlinked from it. One honest caveat: if another user added your name and phone number to their invite list, that entry is part of their address book and remains with them after your account is gone. Section 9 explains how to have such an entry deleted.
3. Sensitive personal information
Several privacy laws apply heightened protection to “sensitive personal information.” This includes:
- Under the California Privacy Rights Act (CPRA), Maryland’s MODPA, and similar US state laws: precise geolocation (a location identifying you within a radius of 1,850 feet).
- Under Australian Privacy Principle 3.3: information about your racial or ethnic origin, political opinions, religious beliefs, philosophical beliefs, trade union membership, sexual orientation, sex life, criminal record, and health or genetic information.
Precise location. We use your location only to find places near you, fetch local weather, and give our AI context to pick a relevant spot. This is strictly necessary to deliver the suggestion you asked for; we collect nothing beyond it. We do not use location to infer characteristics about you, build advertising profiles, or share it with third parties beyond the subprocessors listed in Section 6, and we never sell it. As described in Section 1, solo request locations are erased within a few hours of processing; the only location we retain is a search area you deliberately chose for a co-planned adventure, kept for the life of that adventure.
Other sensitive categories. We do not solicit, collect, infer, or process information about your race, religion, political opinions, sexual orientation, or health. If something like that ends up in a free-text field (see Section 1), we do not use it to infer sensitive attributes, build a profile of sensitive characteristics, or share it with advertisers.
If you are a California resident, you have the right to limit our use of sensitive personal information; see Section 14 for how to exercise that right.
4. Why we use your data
We use your personal information for the following purposes:
- To provide and improve the Service: creating your account, generating suggestions and refining them based on your past interactions, processing your location, running co-planned adventures (invites, joining, combining the members’ picks, showing the shared adventure), enforcing free-tier limits, delivering your subscription.
- With your consent: accepting our Terms and age confirmation, and granting device permissions such as location and contacts access. You can withdraw consent at any time in your device settings or by deleting your account.
- To meet legal obligations: retaining consent records, responding to lawful requests from authorities.
- To protect our legitimate interests: preventing fraud and abuse (rate limiting, device-level checks), maintaining security, supporting customers. Holding invite list data that a user provides about another person also relies on our and that user’s legitimate interest in delivering the invite they asked for, always subject to the affected person’s rights in Section 9.
We do not use your data for targeted advertising. We do not sell your personal data. We do not share it with data brokers.
5. AI and automated decision-making
Emu uses Anthropic’s Claude large language model to pick venue suggestions, from a single spot to a multi-spot itinerary, and to write the titles and descriptions of generated adventures. This is a form of automated decision-making (ADM). In line with Australian privacy law (APPs 1.7 to 1.9, transparency obligations taking effect by 10 December 2026), we disclose the following.
Categories of personal information the AI uses
- The location or search area used for the request
- Your suggestion inputs (such as your mood, who you’re with, time available, transport, and any notes)
- For co-planned adventures: each participating member’s picks, and the members’ anonymous reactions when an adventure is reworked
- The local day of week and time, and the weather forecast for the area
- A list of nearby places retrieved in real time from Google Places
- Your prior interactions with the app (only to avoid suggesting you the same venues again).
Logic involved
The AI is instructed to pick venues matching the context provided. It uses real-time Google Places results for factual venue details (not its own training data) and accounts for opening hours and weather where relevant. For group adventures it reconciles the members’ combined picks into one adventure. Joining an adventure through its invite link involves no AI at all: it is an exact phone-number comparison, described in Section 2.
Envisaged consequences
The consequence is a venue suggestion or a multi-spot itinerary. Following it may influence your time, movement, or spending for the next few hours, which are the normal consequences of any leisure-planning tool. The ADM does not produce a legal or similarly significant effect on you (it is not used for credit, employment, insurance, law enforcement, or any other legally-consequential decision). You are always free to ignore, dismiss, or shuffle for another suggestion, and a host can rework a group adventure.
Your safeguards
- Explainability: every suggestion includes a “why this pick” rationale.
- Human override: you can shuffle, skip, or start over at any time; hosts can rework a group adventure based on the members’ reactions.
- No sensitive inference: we do not use the AI to identify you or infer sensitive characteristics (such as race, religion, health, or sexual orientation).
- Real-time source verification: venue details come from Google Places at the moment of each request, not from the AI’s training data.
- Limited use of history: we use your past interactions only to avoid suggesting you the same venues again; we do not profile you for advertising, infer sensitive characteristics, or share this data outside the subprocessors listed in Section 6.
Training and retention by Anthropic
Anthropic processes our API traffic under its Commercial Terms of Service, which state that Anthropic does not train its models on our Customer Content. Retention of API traffic is governed by Anthropic’s Data Processing Addendum. See Anthropic’s Commercial Terms.
Limits of the AI
The AI is a probabilistic system. Suggestions may be inaccurate or outdated. The suggestion is assistance, not professional advice. Verify critical details such as opening hours, accessibility, or area safety before you go.
6. Who we share data with
We share personal data only with the service providers (“subprocessors”) that keep the Service running. Each is bound by a written contract (a Data Processing Agreement or equivalent) that restricts their use of your data to delivering the specific service we engage them for. In particular, our AI provider is contractually prohibited from using your data to train its models.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Authentication, database | United States / EU |
| Anthropic (Claude) | AI suggestion generation | United States |
| Maps display, place and venue data, weather and air quality data | United States / global | |
| RevenueCat | Subscription billing management | United States |
| Expo | Push notification delivery (relay to Apple Push Notification service) | United States |
| Apple / Google Play | App distribution and payment processing | Global |
Invite list data (the names and phone numbers described in Section 1) is stored in our database (Supabase) and is not sent to any other provider.
Google Places caching: we comply with the Google Maps Platform Terms of Service. We only retain the Google “place ID” (a stable identifier) for places we have suggested to you. Other Google place data (name, address, coordinates, photos, ratings) is fetched in real time on each request and not cached beyond what Google’s API policies permit. Google’s handling of data is described in the Google Privacy Policy.
We may also share data when required by law, to protect our rights or the safety of users, or if our business is sold or reorganised (you will be notified before any change of controller takes effect).
7. International transfers
We are based in Australia. Some of our subprocessors operate overseas (see Section 6 for the list of countries). Where we transfer personal data outside Australia we take reasonable steps to ensure each subprocessor handles it consistent with the Australian Privacy Principles, in accordance with Australian Privacy Principle 8.
8. How long we keep your data
- Account data and adventure history: for as long as your account is active.
- When you delete your account: we deactivate it immediately and permanently erase all of your personal data after a 7-day grace period (the grace period lets you recover the account if you change your mind). The grace period is automated.
- Consent records: retained while your account exists; deleted together with your account.
- Solo request locations: automatically erased within a few hours of the request finishing; never retained.
- Co-planned adventure search areas: the area you pick is stored with your picks and deleted with the adventure or with your account, whichever comes first.
- Invite list contacts: kept until you delete the contact or your account. If your account is deleted, links from other users’ contact entries to your account are removed; the entries themselves belong to those users (see Section 2).
- Rate-limiting data (IP, device counts): held in memory only and cleaned up every few minutes; not persisted.
- Subscription records: the records we hold are linked to your account and are deleted with it. Apple and our subscription provider (RevenueCat) retain transaction records under their own policies, which are independent of ours.
9. Your rights (all users, and people who aren’t users)
Wherever you live, you can ask us to:
- Access a copy of the personal data we hold about you
- Correct inaccurate data
- Delete your account and personal data
- Restrict or object to certain processing
- Port your data (receive it in a machine-readable format)
- Withdraw consent at any time (without affecting the lawfulness of prior processing)
- Lodge a complaint with your data protection authority
You can delete your account directly from the App’s profile screen. For all other requests, including data access and portability (export), email us at support@getemu.app from the address associated with your account. We will respond within 30 days (or the shorter period required by your local law).
If you don’t have an Emu account
If someone added your name and phone number to their invite list, you can ask us to show you, correct, or delete that entry even though you have no account with us. Email support@getemu.app with the subject line “Contact removal” and the name and phone number in question. We verify these requests by matching the details you provide against what we hold, and we may confirm control of the phone number before deleting.
10. Push notifications and other communications
If you enable push notifications in the App, we use them to let you know about things like activity on adventures you’re part of (for example, a member joining, a host’s reminder to add your picks, or a ready adventure), subscription renewal reminders, important service updates, and reminders if you haven’t opened the App in a while. You can turn them off at any time in your device settings.
We do not send marketing SMS, and we never send SMS or email to the people in your invite list. We may send transactional email (account, billing, security) to the address you provided. You can opt out of non-transactional email by using the unsubscribe link in any message or by emailing support@getemu.app.
11. Cookies and tracking
The mobile App does not use cookies. The website at getemu.app uses only strictly necessary cookies needed to serve the site. If we add analytics or advertising cookies in the future, we will update this policy and show you a consent banner first.
12. Children
You must be 18 or older to use Emu. This is a contracting-age requirement (so you can validly accept our Terms and authorise subscription purchases), not a content restriction. During sign-up we ask you to confirm your age. We do not knowingly collect personal data from anyone under 18, and we do not knowingly collect personal data from children under 13 in the United States (as defined by COPPA). If you believe a child has provided us with personal data, email support@getemu.app and we will delete it.
13. Security
We use encryption in transit (TLS), managed databases with access controls, role-based access for our team, and vendor reviews for our subprocessors. No system is completely secure, but we work hard to keep yours safe.
14. United States: state-specific rights
California (CCPA/CPRA)
If you are a California resident you have the right to:
- Know the categories of personal information we collect, the sources, the business/commercial purpose, and the categories of third parties we share it with
- Access the specific pieces of personal information we hold about you
- Delete your personal information, subject to legal exceptions
- Correct inaccurate personal information
- Opt out of the sale or sharing of your personal information
- Limit the use and disclosure of sensitive personal information
- Not receive discriminatory treatment for exercising these rights
We do not sell or share your personal information (as “sale” and “sharing” are defined under the CCPA/CPRA), and we do not use sensitive personal information for purposes that would trigger your right to limit. This applies equally to information we hold about you because another user added you to their invite list. In the last 12 months we have not disclosed personal information for monetary or other valuable consideration.
To exercise any California right, email support@getemu.app with the subject line “California rights request”. You may also authorise an agent to act for you; we may require reasonable proof of authorisation.
California Shine the Light (Civ. Code §1798.83): we do not share personal information with third parties for their own direct-marketing purposes.
Nevada (SB 220)
Nevada residents have the right to opt out of the sale of certain covered information. We do not sell covered information, but if you would like us to record this preference, email support@getemu.app with the subject line “Nevada opt-out”.
Other states with comprehensive privacy laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, and other US states with comprehensive privacy laws have the right to access, delete, correct (where the law provides), and port personal data, and to opt out of sale, targeted advertising, and profiling for decisions that produce legal or similarly significant effects. We do not sell personal data, engage in targeted advertising, or use profiling to make legal or significant decisions about you. To exercise any right, email support@getemu.app with your state and the right you want to exercise.
Maryland residents: Maryland’s MODPA limits the collection and processing of sensitive data, including precise geolocation, to what is strictly necessary to provide the service you request, and prohibits its sale outright. Our practices meet this standard: location is used only to generate the suggestions you ask for, and we never sell it.
Minnesota residents: you additionally have the right to question the result of profiling and to obtain a list of the specific third parties to which we have disclosed your personal data. The subprocessors in Section 6 are that complete list.
If we deny your request, you may appeal by replying to our response. We will review the appeal within the period required by your state law.
15. Brazil (LGPD)
If you are in Brazil, the Lei Geral de Proteção de Dados (LGPD) gives you the right to confirmation of processing, access, correction, anonymisation, portability, deletion, information about sharing, information about the consequences of refusing to consent, and withdrawal of consent. Email support@getemu.app to exercise any of these rights. You can also complain to the Brazilian National Data Protection Authority (ANPD).
Where another user provides your name and phone number for an invite, we process that data on the basis of legitimate interest (LGPD Article 7, IX), limited strictly to the invite purposes described in Sections 1 and 2. You may object to that processing and request deletion at any time using the channel in Section 9, whether or not you have an account.
16. Australia
If you are in Australia, your rights are set out in the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). This policy has been written to meet the transparency obligations under APPs 1.7 to 1.9 relating to automated decision-making that take effect by 10 December 2026, as introduced by the Privacy and Other Legislation Amendment Act 2024. It also describes, as required by APP 1.4, the circumstances in which we collect personal information from someone other than the individual concerned (see “Information others may provide about you” in Section 1).
You can complain about how we handle your personal information to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. We will try to resolve your complaint internally first. Email support@getemu.app with the subject line “Privacy complaint”.
17. Changes to this policy
We may update this policy from time to time. If the changes are material, we will notify you in the App at least 30 days before they take effect and ask for fresh consent where required. The effective date and version number at the top of this page always reflect the current version. Previous versions are archived and available on request.
18. Contact
For anything privacy-related, email support@getemu.app. See also our Terms of Service.