Privacy Policy
Last updated 13 August 2026
Atsuma is a private group-coordination app. It holds messages, events, photos and shared expenses for small groups of people who know each other. That is personal data, and this page explains exactly what is collected, why, who else touches it, and how long it stays.
Who is responsible
Atsuma is operated by Ahmed Abushaban, who is the data controller for both the Atsuma app and the atsuma.app website.
Contact: support@atsuma.app. A postal address for the controller is available on request to that address.
What is collected, and why
| Data | Why | Lawful basis (UK/EU) |
|---|---|---|
| Email address, username, display name, date of birth | To create and secure your account, and to confirm you are old enough to use the service | Performance of a contract |
| Profile photo, bio, home currency | So other members of your groups recognise you, and so amounts display correctly | Performance of a contract |
| Messages, events, itineraries, polls, checklists, photos and videos you post | This is the content of the service. It is shown to the other people in your group | Performance of a contract |
| Expense entries, splits and settlements | To calculate who owes what within a group | Performance of a contract |
| Live location, when you choose to share it | To show your position to a group for a limited period. Off by default and always started by you | Consent |
| Event and itinerary locations | So people know where a gathering is | Performance of a contract |
| Push notification token | To send notifications to your device. Only if you allow notifications | Consent |
| Calendar availability, if you connect a calendar | To show when you are free. Only busy/free windows are used, never event titles or details | Consent |
| App version, last-seen time, basic diagnostics | To keep the service working and to investigate faults | Legitimate interests |
Atsuma does not show advertising, does not sell personal data, and does not use your content to profile you or to train machine-learning models.
Location, in detail
Location is handled three different ways, and the differences matter.
Live location sharing
When you start sharing live location with a group, your coordinates are stored with an expiry time. A job runs every minute and permanently deletes every entry whose expiry has passed. Nothing is archived and no history is kept. Stop sharing, or let it run out, and the data is gone within the minute.
A location you send in a chat
If you attach a location to a message, that location is part of the message. It stays as long as the message stays, and it is deleted when the message is deleted. It is not covered by the sweep above.
Event and itinerary locations
A venue on an event, or a stop on an itinerary, is content the organiser entered. It stays with the event and is deleted when the event is deleted.
Who else processes your data
Running Atsuma means using infrastructure providers. Each is listed with what it actually touches.
| Provider | What it handles | Where |
|---|---|---|
| Supabase | The main database and account authentication | Tokyo, Japan |
| Cloudflare (R2, Images, Workers) | Photos, videos and other media; the atsuma.app website | Global network, nearest point of presence |
| Google Firebase | Push notification delivery. Handles a device token, not message content | Global |
| Google Maps Platform | Map display and place search. Receives location queries when you use those features | Global |
| Apple and Google | App distribution and push delivery on their platforms | Global |
| RevenueCat | Subscription status, once paid plans launch. Not in use during the beta | Global |
International transfers
The database is in Japan. If you are in the UK or EU, your data is transferred outside that region. Japan has an adequacy decision from the European Commission, meaning transfers to Japan are permitted without additional safeguards. Other providers above operate globally and rely on standard contractual clauses.
People who are invited but do not have an account
Someone can be invited to an event through a link without creating an account. If they reply, Atsuma stores the name they typed, their reply, and an email address if they chose to give one. That is used to show the organiser who is coming and, if they gave an email, to tell them if plans change.
Guests are shown the minimum needed. Before they reply they see the event title, date, rough area and a headcount — not the exact address, not who else is coming, and no expense figures. A guest can ask for their reply to be removed by emailing support@atsuma.app, or by asking the organiser.
How long data is kept
- Live location — deleted within a minute of expiring.
- Your content — messages, photos, events, expenses — kept until you or your group deletes it. Deleting your account removes most of it immediately, but not shared expense entries; see Deleting your account.
- Your account — deletion is immediate and cannot be undone. Your real name is kept on shared expense entries so the other members can still settle up; everywhere else it becomes “Deleted User”. Full detail under Deleting your account.
- Guest replies — kept with the event. Access through the invite link lapses roughly 30 days after the event ends, though the record remains until the event is deleted.
- Diagnostics — short-lived, kept only as long as needed to investigate faults.
Deleting your account
You can delete your account from inside the app — Settings → Delete Account — or, if you no longer have it installed, from the account deletion page. Deletion happens immediately and cannot be undone. There is no grace period.
What is deleted
Your account and sign-in; your profile photo, bio and username; your posts, stories, reactions, comments and notifications; events you created, along with their albums and invitations; and every photo you uploaded to any album, including albums belonging to other people. Those photos are removed for everyone who could see them, and the other people in those albums cannot recover them. The app tells you how many before you confirm.
What is kept — and what happens to your name
Two different things happen to your name, and the difference is the point:
- On shared expenses, your real name is kept indefinitely. Expense entries, splits, settlements and expense-group membership keep the name you used. This is personal data that survives the deletion of your account, and it is retained deliberately: other members' balances are calculated from those entries, and a balance nobody can put a name to is a debt nobody can settle. What is removed is the link to your account — the entry becomes a name with no account behind it, the same as somebody added to a group by name who never signed up.
- Everywhere else, your name becomes “Deleted User”. Your profile, group chats, posts and comments all show “Deleted User”. Messages you sent stay in their conversations for the people still in them, attributed that way.
Expenses and group messages are kept for the same underlying reason: removing them would silently rewrite a shared record that other people depend on and did not ask to have changed.
If you want your name removed from shared expenses as well, email support@atsuma.app and the request will be considered. It is not automatic: removing a name means editing entries other people's balances are calculated from, so each request is judged on its own facts, and the other members of that group will see the change.
Your rights
Depending on where you live you may have the right to access your data, correct it, delete it, object to processing, withdraw consent, or receive a copy in a portable format. You can delete your account from within the app at any time, or from the account deletion page if you no longer have the app installed — deletion keeps your name on shared expense entries, as described above. For anything else, email support@atsuma.app.
If you are in the UK or EU and are unhappy with how a request was handled, you can complain to your national data protection authority. In Japan, the Personal Information Protection Commission handles the equivalent role.
Children
Atsuma is not intended for children under 13, and in some regions the minimum age is higher. Accounts record a date of birth so that age-inappropriate features can be restricted. If you believe a child has created an account, email support@atsuma.app and the account will be reviewed and removed if confirmed.
Security
Data is encrypted in transit. Access to group content is enforced at the database level, so a person who is not in a group cannot read its data even if they know it exists. Access to invited guests is restricted to a narrow, explicitly defined set of information.
No system is perfectly secure. Atsuma does not currently offer end-to-end encryption for messages, which means message content is readable on the server. This page will be updated if that changes.
Changes to this policy
If this policy changes in a way that materially affects you, you will be notified in the app. The date at the top always reflects the current version.