Back to home
Legal

Privacy Policy

Last updated: 4 July 2026

This English translation is provided for convenience. The Icelandic version is the legally binding text — read it here.

1. Who is the data controller?

Vinir is developed by an individual and is not operated by a separate legal entity (ehf. or other company) at this time. The controller of personal data processed in Vinir is:

  • Name: Berglind Dan Róbertsdóttir
  • Status: Individual (independent app developer)
  • Icelandic ID number (kennitala): 101100-3240
  • Email: vinir@vinirapp.is

Contact us at the email address above if you have questions about how we process personal data or if you wish to exercise your rights under Icelandic Act No. 90/2018 on the Protection of Privacy and Processing of Personal Data and the EU General Data Protection Regulation (GDPR).

If a separate legal entity (e.g. ehf.) is later established to operate Vinir, this policy will be updated, the new controller announced, and users will receive clear notification of the change.

2. What information do we collect?

We collect the following information when you use Vinir:

Identifying information you give us

  • Name
  • Email address
  • Phone number
  • Profile picture (optional)
  • Date of birth (used for age verification, 13+; see section 9)
  • Identifiers from your Apple ID or Google account when you sign up using "Sign in with Apple" or "Sign in with Google"

Content you create in the app

  • Friend groups, friendships and partner status
  • Invite lists (your own contact lists with names and optional email tags)
  • Events and meetups you create or are invited to
  • Co-hosts you invite to plan with you
  • Descriptions, cover images and URLs to ticketing or event web pages
  • Dates and times you select in availability polls (voting / time proposals)
  • Comments, reactions, @-mentions of other users, and RSVP responses
  • Images you add to comments
  • Addresses and locations of events that you enter
  • Working hours you set
  • Shift schedules you upload (image or PDF) and the output of analyzing them

Waitlist email (pre-launch)

When you submit your email address to the waitlist on vinirapp.is (before the app is available on the App Store), we store it in order to notify you when the app launches. The email is not used for any other purpose, sold, or shared with third parties. You can request removal from the list by emailing vinir@vinirapp.is. The list is deleted immediately after the launch announcement has been sent.

Invitations to people outside the app

When you invite someone who does not already have a Vinir account, we store their email address and/or phone number until they accept the invitation or you withdraw it. See section 7 for the legal basis.

Technical information

  • Technical user identifier and device identifier for push notifications
  • iOS version and device model
  • Time of registration and most recent sign-in
  • Incidents (crash logs, error reports) if the app crashes

What we do NOT collect

  • We do not collect your location
  • We do not read your contact list unless you share a contact directly through the invite flow
  • We only read the calendar entry you choose to add — we do not access your calendar content as a whole
  • We do not track you across other apps or websites (no advertising trackers, no third-party analytics)
  • We do not collect payment information — the app is free and no billing takes place inside it

3. What do we use the information for?

We use your personal data to:

  • Create and maintain your user account
  • Authenticate you (phone number, Apple, Google) and protect your account (e.g. Face ID lock on the device)
  • Show you events, meetups, friends, groups and a partner that you are part of
  • Send push notifications about invitations, RSVPs, polls, comments, @-mentions and reminders
  • Share events with your partner as shadow entries on their calendar when you enable that sharing
  • Analyze a shift schedule you upload so the app can show when you are working when meetups are being planned
  • Add meetups to your calendar when you choose
  • Let you find friends by name, username or email
  • Comply with legal obligations (e.g. responding to inquiries from the Icelandic Data Protection Authority)
  • Combat misuse, fraud and breaches of the terms of service

4. What is our legal basis?

Processing of personal data is based on the following bases under Article 9 of Act No. 90/2018 / Article 6 of the GDPR:

  • Contract (Art. 6(1)(b)) — To provide the service you agreed to in the terms of service (authentication, profile, events, friends, push notifications, etc.).
  • Legitimate interests (Art. 6(1)(f)) — To protect the system, prevent misuse and improve the service. You can object to this processing at any time.
  • Consent (Art. 6(1)(a)) — For optional features such as calendar access, Face ID, push notifications and shift schedule upload. You can withdraw consent at any time in your device settings or in the app.

5. Who do we share the information with?

We never sell your personal data. We only share it with the following processors:

Google / Firebase (Google Ireland Limited)

Used for authentication, data storage (Firestore), profile picture storage (Storage), Cloud Functions and push notifications (FCM). Data is mostly hosted within the EEA. We have a data processing agreement (DPA) with Google. More information: policies.google.com/privacy.

Apple Inc.

When you use Sign in with Apple you receive an identifier from Apple. Apple does not send us identifying information beyond what you choose to share. Apple Push Notification Service delivers our push messages to your device. See apple.com/legal/privacy.

Anthropic, PBC (United States)

When you upload a shift schedule (image or PDF), it is sent to the Anthropic API (Claude model) for automated analysis via a Cloud Function. Anthropic processes the data according to its API terms and does not use it to train its models. This involves the transfer of personal data outside the EEA; the transfer is supported by the European Commission's Standard Contractual Clauses (SCCs). More information: anthropic.com/legal/privacy.

Google Maps / Apple Maps

When you tap a location in an event, an external maps app opens. We then send the location you entered to the maps app; we share no other information about you.

Other Vinir users

Other users see the content you share with them:

  • Friends see your name, profile picture, username and the events you share with them.
  • Group members see content you post in that group and your status regarding the group's meetups.
  • Event invitees see your name, profile picture and RSVP status for that event.
  • Partner (if you have accepted a partner relationship) sees a shadow of your events on their calendar if you have enabled that sharing.

Disclosure required by law

We may disclose information to authorities when required by law (e.g. by court order).

6. Where is the data stored?

Data in Firebase is primarily stored on servers within the EEA. When data is sent to Anthropic in the United States (during shift schedule analysis), it is temporarily transferred outside the EEA and is protected by the Standard Contractual Clauses (SCCs).

7. How long do we keep the data?

  • User account: Until you delete the account or request deletion.
  • Events and comments: Until you delete them or delete the account.
  • Cancelled events: Automatically deleted 10 days after cancellation.
  • External invitations (unaccepted): Up to 12 months or until you withdraw the invitation.
  • Shift schedule images/PDFs: Deleted immediately after processing by Anthropic; only the parsed output (start/end times per day) is retained.
  • Incidents / error reports: Up to 90 days (Firebase Crashlytics).
  • In-app notification history (bell): Up to the 50 most recent notifications per user.
  • Backup data: Up to 30 days after deletion from the main system.
  • Waitlist: Retained until the launch announcement is sent and deleted immediately afterwards. You can request earlier removal by email.

8. Your rights

Under data protection law you have the following rights:

  • Right to information and access to your data
  • Right to rectification of inaccurate information
  • Right to erasure ("right to be forgotten")
  • Right to restriction of processing
  • Right to object to processing based on legitimate interests
  • Right to data portability
  • Right to withdraw consent, where applicable

You can delete your account directly in the app (Profile → Settings → Delete account) or contact vinir@vinirapp.is.

You also have the right to file a complaint with the Icelandic Data Protection Authority (personuvernd.is).

9. Children

Vinir is intended for people 13 years and older. Users under 13 should not sign up. If you believe a child under 13 has signed up, please contact us and we will delete the account immediately. Users under 16 (under Icelandic implementation of Article 8 of the GDPR) need parental consent for processing based on consent.

10. Security

We use standard security measures to protect data: TLS encryption in transit, encryption at rest at Google Cloud, Firestore Security Rules limiting access, and staff access controls. No system is perfectly secure and we encourage you to use a strong password for your Apple ID/Google account.

11. Changes to this policy

We may update this policy when our service or applicable law changes. Material changes will be announced in the app itself or by email at least 14 days in advance.

12. Contact

Controller: Berglind Dan Róbertsdóttir (individual)
Email: vinir@vinirapp.is