Privacy Policy

Effective 7 August 2026 · Version 1.2 · Applies to the VeXpo app for iOS and Android

1. Who we are

This privacy policy explains how personal data is handled when you use the VeXpo mobile app, the official companion app for VeXpo 2026.

The data controller, the party responsible for your personal data, is the organizer of VeXpo 2026:

Vtuber Expo Ltd.
203 West Street Fareham, Hampshire, PO16 0EN United Kingdom
support@vexpo.uk

The app and its backend are developed and operated by Gigadrive UG (haftungsbeschränkt), Germany, acting as our data processor under a data processing agreement and only on our documented instructions.

Depending on where you live, the UK General Data Protection Regulation (UK GDPR) and/or the EU General Data Protection Regulation (EU GDPR) apply to this processing.

2. At a glance

  • No sign-up. The app never asks for your email address, phone number, real name, photo, or any credentials. Your account is an anonymous, randomly generated profile tied to your device.
  • The camera only reads QR codes. Frames are processed on your device and are never stored or uploaded.
  • Your precise GPS location never leaves your device. It is used only to show your position on the venue map, and only if you turn that on.
  • Everything is deleted after the event. All attendee data is retained for no longer than 90 days after VeXpo 2026 concludes.
  • No ads, no sale of data, no cross-app tracking. We do not sell your data and we do not track you across other companies’ apps or websites.

3. What we collect

a. Account & identifiers

When you first open the app, it creates an anonymous account consisting of:

  • a random player ID (a UUID) that identifies your profile;
  • a randomly generated username, which you can change in the app (2 to 32 characters). Usernames appear on the in-app leaderboard together with your score (level and experience points, or points, depending on the event), and the leaderboard is served from a publicly reachable endpoint, so treat your username as public information and pick one you are comfortable showing;
  • a sign-in secret that stays on your device (our servers keep only a salted hash of it), and a friend-code secret that we store to validate friend requests.

Your personal QR code contains your player ID together with a short code that changes every 30 seconds. Anyone who scans or photographs your QR code learns your player ID, so only show it to people you want to connect with.

The account is bound to your device. If you delete the app or lose the device, the account cannot be recovered, precisely because we hold nothing that could identify you to restore it.

b. Device & connection data

When the app registers or signs in to our servers, we record the following. Sign-ins also happen automatically in the background, roughly every 15 minutes while you actively use the app:

  • your IP address and an approximate location derived from it by our hosting provider (continent, country, region, city, postal code, approximate coordinates, and timezone). This is coarse, network-based geolocation, not GPS;
  • the technical user-agent string sent by the app’s network layer;
  • device and app metadata: platform, operating system name and version, device manufacturer, model and type, whether the app runs on a physical device, app identifier, app version and build, update and runtime identifiers, update channel, language, and timezone.

When you change your username, we also keep a record of the previous and the new name together with the connection and device data listed above, so organizers can look into impersonation or abuse reports and answer support requests.

While the app communicates with our servers we also record activity data in five-minute intervals (when your profile was active and how many requests it made), used for attendance statistics, operating the event, and preventing abuse.

c. Usage data (analytics)

To understand how the app is used and improve it, we collect in-app interaction events (for example which screens are viewed, use of the QR scanner, whether adding a friend or claiming a sticker succeeded, and taps on booth links) together with technical information about your app and device, and session replays. In replays, text you type and images are masked before they leave your device, and sensitive views such as your personal QR code and your Player ID are always masked; other on-screen content, such as usernames displayed in the app, can appear in a replay. Analytics data is processed by PostHog on servers in the European Union and is associated with your player ID and username; PostHog also processes your IP address to operate the service. You can object to analytics at any time by contacting us (section 8).

d. Content you create in the app

Using the app’s features creates the following data:

  • your username (see above);
  • your sticker collection: which stickers you claimed, with timestamps;
  • your friend connections: who you added, with timestamps. Removed friendships are kept internally (not shown to anyone) so experience points cannot be farmed by repeatedly re-adding the same person;
  • your schedule favorites (“My Schedule”);
  • your booth favorites: which booths you saved, with timestamps.

Who can see what:

  • the leaderboard shows your username and your score (level and experience points, or points, depending on the event) and is served from a publicly reachable endpoint;
  • friends can see your username, level, rank, when your account was created, and your sticker collection;
  • authorized event staff can view attendee profiles, activity, connections, and the device and connection data above in an access-controlled admin panel, for running the event and handling abuse.

e. Diagnostics

If the app crashes or misbehaves, a crash report is sent to Sentry, our error-monitoring provider in the United States. Crash reports include technical details of the error, device and app metadata, and your IP address. To diagnose hard-to-reproduce problems, a small share of sessions (and sessions in which an error occurs) additionally record a screen replay in which text and images are masked. The app also reports startup and update performance metrics to Expo (EAS), the service that delivers app updates, together with app and device information and a per-installation identifier that is not linked to your player profile; checking for and downloading app updates likewise contacts Expo’s servers.

f. Camera

The camera is used solely to scan QR codes for adding friends and claiming stickers. Camera frames are decoded on your device and are never stored, recorded, or uploaded. Only the data encoded in a successfully scanned QR code is sent to our servers: for a friend scan, the other attendee’s player ID and a short one-time code; for a sticker scan, the sticker’s code. The camera is active only while the scanner screen is open, and only after you grant the OS camera permission.

g. Precise location (on-device only)

The venue map can show a “you are here” marker. If you enable it and grant the OS location permission, your GPS position is read while the map is open, in the foreground only, and is used exclusively to draw the marker on the floor plan. Your precise location is never transmitted to us or to anyone else and is never stored. As with any screen, the map can appear in the session replays described in sections 3c and 3e. You can withdraw the permission at any time in your device settings; the map works fully without it.

4. Why we process your data (purposes & legal bases)

DataPurposeLegal basis
Account, content you create, core featuresProviding the app and its features (stickers, friends, schedule, map, leaderboard)Performance of a contract (Art. 6(1)(b) GDPR)
Device & connection data, access recordsSecurity, abuse and fraud prevention, troubleshootingLegitimate interests (Art. 6(1)(f) GDPR)
Usage data (analytics)Understanding and improving the app and the eventLegitimate interests (Art. 6(1)(f) GDPR); you may object at any time
DiagnosticsDetecting and fixing crashes and errorsLegitimate interests (Art. 6(1)(f) GDPR)
Camera, precise locationOn-device features you explicitly enableConsent via the OS permission (Art. 6(1)(a) GDPR), withdrawable in device settings

We do not use your data for automated decision-making or profiling with legal effect, we do not sell it, and we do not use it for advertising.

5. Who we share data with

Your data is processed on our behalf by Gigadrive UG (haftungsbeschränkt) as our data processor (see section 1). To run the service, the processor engages a small number of service providers (sub-processors) under data processing agreements:

ProviderPurposeLocation
Vercel Inc.Hosting and content delivery for the app’s backend; derives the approximate IP locationUSA / global edge network
PlanetScale, Inc.Managed PostgreSQL database storing the data described in section 3EU region
Functional Software, Inc. (Sentry)Crash and error diagnosticsUSA
PostHog Inc.Product analytics and masked session replayEU-hosted (Frankfurt)
650 Industries, Inc. (Expo)App update delivery (EAS Update) and launch performance metricsUSA
Apple Inc. / Google LLCApp distribution and operating-system services (independent controllers)USA

Images the organizer uploads (floor plans, booth logos, banners) are stored and delivered by Gigadrive Network, which is infrastructure operated by Gigadrive UG (haftungsbeschränkt) itself rather than a separate company, so it is not a further sub-processor. Your IP address reaches it when the app loads those images, in the same way it reaches the rest of the processor’s systems.

Event content in the app can link to external websites, for example a booth’s website or social profiles. If you open such a link, it loads in an in-app browser and the operator of that site receives your IP address and processes your data under its own privacy policy.

Beyond these providers, we only disclose personal data where we are legally required to do so.

6. International transfers

Your data is stored and processed in the United Kingdom and the European Union and, for the providers noted above, in the United States. Where data is transferred outside the UK/EEA, it is protected by appropriate safeguards: the EU-US Data Privacy Framework where the provider is certified, and/or the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum.

Some providers keep your data in the EU but are US companies (PlanetScale and PostHog). Where their personnel can access EU-hosted data in order to support the service, the same safeguards apply.

7. How long we keep your data

  • While you use the app: your account data is kept for as long as your account exists.
  • If you delete your account (Settings → Profile → Delete account in the app, or through the online request form): it is deactivated immediately (hidden from the leaderboard and from your friends) and permanently erased, together with all associated data, after a 14-day grace period.
  • Deletion and export requests themselves: when you use the request form we record the details you give us, along with your IP address and browser user agent, so we can prevent abuse of the form and cross-check that the account is yours. Once the request is closed, those details are stripped after 90 days and only a record that the request was made and handled is kept.
  • After the event: regardless of the above, all attendee data is retained for a maximum of 90 days after VeXpo 2026 concludes and is then securely deleted.
  • Copies held by our diagnostics and analytics providers expire on those providers’ standard retention schedules.

8. Your rights

Under the UK GDPR and EU GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected (you can change your username directly in the app);
  • have your data erased, with in-app account deletion, through the online request form, or by contacting us;
  • restrict or object to processing, including objecting to analytics based on legitimate interests;
  • receive a copy of data you provided in a portable format, which you can download yourself from the request form;
  • withdraw consent at any time (for camera and location, via your device settings);
  • complain to a supervisory authority: in the UK, the Information Commissioner’s Office (ico.org.uk), or your local EU data protection authority.

The quickest way to exercise your erasure and access rights is the online request form, which works whether or not you still have the app installed.

Accounts are anonymous: we hold no email address or password for you, and usernames are not unique, so there is nothing we can match you against automatically. To close that gap the app gives you a privacy code under Settings → Privacy. Save it somewhere safe while you still have the app — with that code and your Player ID, the request form verifies you on the spot and erases your account or hands you your data immediately, with no waiting and no further questions.

Without a privacy code we cannot verify you from the form alone, because your Player ID is not secret (it is printed in your friend QR code) and your username may be shared with other attendees. In that case the form records your request and Vtuber Expo Ltd. reviews it by hand: tell us your username, roughly when and in which city you last used the app, and what device you used, and we may ask you to confirm control of the account before we erase anything or release any data. Where we genuinely cannot establish that an account is yours, we will tell you so rather than act on a guess — under Article 11 of the GDPR we are not required to collect additional information about you purely to identify you.

You can also email support@vexpo.uk for any of the other rights above. We respond within one month.

9. Children

The app is intended for general event audiences and is not directed at children under 13. We do not knowingly collect personal data from children; the app collects no name, photo, or contact details from anyone. Parents or guardians who believe a child is using the app can delete the account in the app or contact us for erasure.

10. Security

All communication between the app and our servers is encrypted in transit (TLS). Sign-in secrets are stored only as salted hashes and your credentials are kept in your device’s secure storage (Keychain on iOS, Keystore on Android). Access to attendee data is restricted to authorized event staff and the operator’s operations personnel. The app handles no payment data.

11. Changes to this policy

We may update this policy as the app evolves. The current version is always published at this address, with the effective date and version number shown at the top. Material changes will be announced in the app.

12. Contact

Data controller: Vtuber Expo Ltd., 203 West Street Fareham, Hampshire, PO16 0EN United Kingdom. Privacy contact: support@vexpo.uk.
App developed and operated by Gigadrive UG (haftungsbeschränkt) as data processor.