Gemio

Privacy

Version 2026-08-27

Gemio is designed to be private by default. You can explore the globe without an account, and nothing you add becomes public unless you choose to make it public.

1. What we collect

Account data. When you create an account we store your email address and authentication identifiers. If you sign in with Google, we receive your email, basic profile information and, if you choose it, your Google profile photo. We never receive your Google password.

Profile data. Optional handle, display name, bio, coarse location, website and links, and an optional profile photo. Profiles are private by default: none of this is shown publicly unless you explicitly turn on the public profile setting.

Content you add. Memories and other location-anchored notes you write, including their coordinates, the historical time you give them, and whether you marked them public or private. Private entries are visible only to you.

Square and transaction data. Squares you claim, their coordinates and size, reservations, the Terms version you accepted and when, listing state and any interest you register.

Payment data. Payments are processed by Stripe. Gemio does not receive or store full card numbers. We store the payment reference, amount, currency, status and the identifiers Stripe returns so we can confirm and support a claim.

Usage and technical data. We record a small set of product events (for example viewing a location, starting a claim, completing a claim) to understand how the service is used, together with standard technical data such as IP address, request time and user agent that our hosting and backend providers log for security and reliability.

Map, search and location. Map tiles and place search are served by third-party map and geocoding services, which receive the map area or search term needed to answer the request. If you use the “find me” control, your browser asks for permission first and the position is used to move the map; we do not store it as a location history.

2. Why we use it, and on what basis

To provide the service — accounts, claiming, Squares, memories and profiles — because it is necessary to perform our contract with you.

To process payments and keep records of transactions, for contract performance and to meet legal accounting and tax obligations.

To keep the service secure, prevent abuse and fix problems, and to understand aggregate product usage, based on our legitimate interests in running a safe and working service.

Publishing your profile or a public memory happens only on your instruction — you choose, and you can change it later.

3. What is public

By default nothing identifies you publicly. Squares and activity are shown with neutral labels such as “Square holder” or “Anonymous”. If you turn on a public profile, the handle, display name, photo, bio, coarse location, website and links you chose become visible at your profile page and next to your public activity. Your email address is never shown publicly.

Public memories are readable by signed-in users at the location they are anchored to. Anonymous visitors see only that memories exist, not their text. You can edit or delete your own memories at any time.

4. Service providers

We use a small number of processors to run Gemio: our backend and authentication platform (database, accounts and file storage), our application hosting platform, Stripe for payments, Google for optional sign-in, and third-party map tile and geocoding services. They process data on our instructions or, in Stripe’s and Google’s case, also as controllers for their own payment and authentication purposes.

5. International transfers

Some of these providers operate outside the European Economic Area. Where that is the case, transfers rely on the mechanisms those providers offer, such as the European Commission’s standard contractual clauses.

6. Retention

Account, profile, Square and memory data is kept while your account exists. Transaction records are kept as long as needed for accounting and legal purposes, typically several years. Expired reservations and product event records are kept only as long as they are useful for operating and improving the service. When you delete content, it is removed from the service; ownership and provenance records tied to a completed purchase are retained.

7. Cookies and local storage

Gemio uses browser storage to keep you signed in and to remember basic preferences such as the destination you were heading to before signing in. We do not run advertising or cross-site tracking.

8. Your rights

Subject to applicable law you can request access to your data, correction, deletion, restriction, objection and portability, and you can withdraw consent where processing is based on it. You can edit or remove most of your data directly in your profile settings. If you are in the EEA or UK you can also complain to your local data protection authority.

9. Contact

To exercise a right or ask a privacy question, contact Gemio through the service using the account you signed in with, so we can verify the request relates to your data.

10. Changes

We may update this policy as the service evolves. The version date at the top always shows the current version, and material changes will be communicated in the service.

See also the Terms.