Yetty
Terms of use Home Español

Privacy Policy

Last updated: October 1, 2026

This policy explains what personal data Yetty (the travel mobile app) and this website (yettyapp.com) process, for what purpose, under what legal basis, who it is shared with, and what rights you have. It is written to be understood; if anything is unclear, write to us at support@yettyapp.com.

1. Data controller

The data controllers responsible for your data are Gonzalo Rodríguez Monterroso and Daniel Tijeras Casado, who jointly develop and operate Yetty.

Contact for any privacy matter: support@yettyapp.com.

2. This website does not use cookies

yettyapp.com is a static informational page. It does not install cookies, does not use analytics tools, does not include trackers and does not load third-party resources (external fonts, scripts or images). Visiting it does not collect any data about you. The rest of this policy refers to the mobile app.

2 bis. Minimum age to use Yetty

You must be at least 14 years old to create a Yetty account. This is the age set by Spanish law (art. 7 of Organic Law 3/2018, LOPDGDD) from which a person can consent on their own to the processing of their personal data. Below that age, consent from a parent or legal guardian would be required, and Yetty has no system to request and verify it, so it simply does not admit those accounts.

The check is performed on the server, based on the date of birth declared at sign-up, not only on the registration screen: a request made outside the app is rejected the same way.

Signing in with Google does not skip this check. Google does not tell us anyone's age, so whoever creates their account this way is still asked for their date of birth before the account is created, and the server checks it with the same rules and the same limit. There is no way to open a Yetty account without declaring a date of birth.

Keep in mind that 14 is the Spanish threshold. Other European Union countries chose a higher one when implementing art. 8 of the GDPR — 16 in Germany and the Netherlands, 15 in France. If you reside in one of them and are between 14 and that age, you need authorization from a parent or guardian to use the service.

If we detect, or are told, that an account belongs to someone under 14, we delete it along with their data. If you are a parent or guardian and believe such an account exists, write to us at support@yettyapp.com and we will handle it as a priority.

Some features additionally require being an adult; this is detailed in section 5.5.

3. What data the app processes

  • Account data: username, email address, password (stored encrypted) and date of birth. The date of birth is requested once at sign-up and cannot be changed from the app; correcting a genuine error requires contacting support. If you sign in with Google, your account has no password until you decide to set one from Settings.
  • If you sign in with Google: you can create your account and log in with your Google account instead of a password. In that case Yetty never sees or receives your Google password: you type it on Google's own screen, and what reaches our server is only a certificate signed by Google, valid for one hour, from which we read your email address, confirmation that Google has verified it, your name and your profile photo. Of all that, we store the email and a Google account identifier, which is what lets us recognize you next time; the name is only used to suggest a username, which you can change before creating the account, and the photo is not stored. Google, for its part, knows you used your account to sign in to Yetty, and it processes that under its own privacy policy. Yetty does not get access to your Gmail, your contacts, your photos, or any other data from your Google account.
  • What Google doesn't tell us, and why we ask you: your Google account does not contain your nationality — that data doesn't exist in any of its services — and it doesn't hand over your date of birth. That's why, if you sign in with Google and didn't already have an account, we ask you once for your username, date of birth and nationality: exactly the same data as in email-and-password registration, not one field more.
  • Profile: avatar chosen within the app, traveler profile (e.g. adventurous, sociable or chill) and, if you choose to write it, your Instagram handle (optional).
  • Content you publish: points of interest, photos, ratings, alerts (roadworks, closures, queues) and their confirmations or denials.
  • Travel preferences: the data you enter to generate itineraries (destination, dates, budget, pace).
  • Internal usage data: balance and movements of the app's internal currency ("footprints"), progress in mini-games and the contact-exchange history described below.
  • Session: when you log in, a session identifier (a random value) is created and stored on your phone and, in summarized form, on our server along with the creation date and last-used date. This is what lets you avoid typing your password every time, and what lets you log out remotely if you lose your phone. It expires after six months of inactivity, and is invalidated when you change your password.
  • Notification identifier: if you accept receiving notifications, the identifier your phone obtains from Google's push-notification system, linked to your account.
  • Login attempts: to prevent someone from brute-forcing your password, we keep a count of failed attempts for a limited time. Neither the email nor the IP address is stored in plain text, only an irreversible cryptographic digest that lets us count attempts without identifying who made them.
  • Location and visited places: your device's location, to center the map, show you what's nearby and — only if you enable automatic marking — suggest adding to your passport the countries and cities where you've been. Your passport (the list of marked countries and cities, with the date each was marked) is stored on our server, whether you fill it in by hand or accept a suggestion from automatic marking. This is explained in detail in section 3.1.

We do not process your phone number. That field doesn't exist in the app, and the Instagram field actively rejects any text that looks like a phone number. We also don't process your surname or postal address. We do use your device's location, under the terms of section 3.1: never in the background and never as a history of your movements.

3.1 Location and automatic marking of countries and cities

What we use location for. The app queries your device's location to center the map where you are, show you points of interest and alerts near you, and, if you turn it on, for the automatic marking described here. It only queries it while the app is open and in the foreground. Yetty does not request background location permission (ACCESS_BACKGROUND_LOCATION on Android, "Always" on iOS), so it cannot know where you are when you're not using the app.

What automatic marking is. It's a feature that's off by default, toggled from Settings → Privacy. While it's on, and only with the app open, Yetty occasionally checks — at most once every fifteen minutes — what country and city you're in, and when it detects you've stayed somewhere, it suggests adding it to your passport. It never marks anything without asking you first, and if you say no, it won't ask about that place again.

What is stored and what isn't. What's sent to our server is only the result you accept: the country or city added to your passport, with its date. No coordinates are sent, no routes, no history of where you've been. The intermediate readings used to decide whether you've stayed somewhere (country, city and time of each check) stay on your own device, never leave it, and are deleted as soon as you accept or reject the suggestion or turn off the toggle.

Legal basis. The countries-and-cities passport is a core feature of the app and can be filled in by hand without enabling anything: its processing is based on performance of the contract (art. 6.1.b GDPR). Automatic marking, on the other hand, is based on your consent (art. 6.1.a), given when you turn on the toggle and grant location permission, which you can withdraw at any time by turning it off or revoking the permission in your phone's settings, without explanation and without affecting the rest of the app.

Retention. Your passport is kept for as long as your account exists, like the rest of your profile data, and you can remove any country or city from it whenever you want, from within the app.

Who sees it. The passport is part of your profile and follows your privacy settings: you can choose to let your followers see it, only your friends, or no one, and exclude specific people.

4. Why we use the data and under what legal basis

PurposeLegal basis (GDPR)
Create and maintain your account and provide the app's features (map, itineraries, alerts, mini-games, footprints)Performance of a contract (art. 6.1.b)
Identify you with your Google account, as an alternative to a password, to create your account and log you inPerformance of a contract (art. 6.1.b). It's an alternative way of identifying you, not an additional processing activity: only your email and basic profile are used, and only when you tap the button
Generate personalized AI itineraries from your travel preferencesPerformance of a contract (art. 6.1.b)
Let two users who both consent exchange their Instagram contactExplicit consent (art. 6.1.a), withdrawable at any time
Moderate published content and manage blocks and reportsLegitimate interest in keeping the community safe (art. 6.1.f) and app-store obligations
Use your device's location, with the app open, to center the map and show you what's nearbyPerformance of a contract (art. 6.1.b)
Automatic marking: suggest adding to your passport the countries and cities where you've stayed (section 3.1)Consent (art. 6.1.a), off by default and withdrawable at any time
Show ads in the appConsent, managed through the ad system itself (art. 6.1.a)
Respond to your support inquiriesLegitimate interest (art. 6.1.f)

5. Contact exchange between users

Yetty lets two adults who have met within the app exchange a single piece of contact information: their Instagram handle, if they've entered it on their profile. It works like this:

  1. You enter your Instagram handle on your profile. You can choose not to: it's entirely optional.
  2. Someone else proposes exchanging contact with you.
  3. You accept or decline. Nothing is shared until you accept. Contact is never shared automatically or by default.
  4. Only after you accept can both sides see each other's contact.

It's a reciprocal exchange, not a one-sided disclosure: you can't propose or accept an exchange without having your own Instagram saved, and deleting yours means you stop seeing other people's. Your contact doesn't appear anywhere else in the app: not in listings, not in search, not on the map, not on public profiles.

Whoever receives your contact is another user, not Yetty: it's a disclosure to a third party based on your explicit consent. To be able to prove that consent, every exchange is logged with its request date, acceptance date and, if applicable, withdrawal date; withdrawing doesn't delete the record, it marks it as withdrawn.

5.1 When your contact stops being visible

Your contact stops being shown when any of these happen:

  • 30 days pass since the exchange was accepted.
  • Either party withdraws consent.
  • Either party blocks the other.
  • You delete your Instagram handle from your profile (or the other person deletes theirs: reciprocity works both ways).
  • You delete your account.

The 30-day limit caps the cumulative exposure of your contact: at any given time, only people with a recent exchange have it on hand. That said, neither the time limit nor the withdraw button undoes what's already been seen: data that has been shown may have been copied or noted down, and we have no way to prevent that. We warn you about this at the exact moment you accept.

5.2 Deleting your Instagram is not the same as withdrawing consent

  • Withdrawing (person to person) ends the exchange with that person. Sharing again requires a new exchange.
  • Deleting your Instagram makes the data disappear: no one sees anything and you don't see anyone else's either. But the exchanges themselves still exist; if you later enter a different handle, people with an active exchange will see the new one without needing additional consent. The app warns you about this, showing the number of exchanges affected, before confirming the deletion. If you really want to cut ties with someone, use Withdraw.

5.3 How to withdraw consent

With a single tap, from the other person's profile or from your list of exchanges. No password, no explanation needed, no waiting, no need to write to anyone: withdrawing consent is as easy as giving it (art. 7.3 GDPR). Either party can withdraw. You can also view your full consent history in the app: who you gave your contact to, when, and whether and when you withdrew it.

5.4 Blocking, reporting and limits

  • Blocking is available on any user's profile. When you block someone, they can no longer request your contact and, if there was an accepted exchange, it's withdrawn automatically. The blocked person isn't notified, and unblocking doesn't restore the contact.
  • Reporting is in the same place and is independent of blocking. Reasons include: harassment, sexual content, impersonation, spam, suspicion of being a minor, hate speech and others. Reports are kept on record for review and are not deleted once closed.
  • There's a limit of 10 contact requests per day per user, to curb mass use of the feature.

5.5 Minors

Contact exchange is not available to anyone under 18. A minor cannot save an Instagram handle, nor propose, nor accept an exchange; nor can anyone request contact from a minor. The check happens on the server, not only on screen, and is repeated on every operation. We chose 18 — rather than the 14 or 16 consent thresholds — because what's being authorized here is for an unknown adult to message someone located on a map, and that risk deserves the highest bar.

6. Who the data is shared with

  • Other users: your username, avatar and the content you publish (points of interest, photos, ratings, alerts) are visible in the app to the community. Your Instagram handle, only through the exchange described above, one-to-one and with your prior acceptance. It's never sent to Instagram/Meta: the app only stores a piece of text and never calls any of its APIs.
  • Hosting: the server where the service and the database live, located in the European Union.
  • Automatic AI moderation of photos and itineraries (DeepSeek and Google Gemini): when you propose a point for the public map, the photo you uploaded is sent to an AI model along with the title and description, to check that the image matches the place described and doesn't break the rules. And when generating an itinerary, your travel preferences (destination, dates, budget, pace, traveler profile) are sent along with your age range and nationality, to tailor the suggestions. If you use "I don't know where I want to go," the answers to that questionnaire are sent (trip type, continents, dates or season, budget, climate, food, languages) and, only if you've accepted AI use for itineraries, the list of countries in your passport, so suggestions can take into account where you've been. Your username, email and exact date of birth are not sent.
  • Email: the provider that delivers welcome emails and password-recovery emails receives your email address.
  • Translation (DeepL and Microsoft Azure Translator): the text you write in your points of interest and stories is sent to these services to display it in the reader's language. They receive the text, not who wrote it.
  • Identification with your Google account: if you choose to sign in with Google, it is Google that verifies you are who you say you are and hands us the signed certificate described in section 3. Google acts here as an independent controller of its own service, and therefore knows you use Yetty and when you log in, under its own privacy policy. We don't send Google any of your app data. You can revoke Yetty's permission at any time from your Google account's security section; this does not delete your Yetty account — for that, use Settings → Delete account — the only thing that changes is that Google will ask you for permission again next time you tap the button.
  • Mobile notifications (Firebase Cloud Messaging, by Google): to be able to send you notifications, your device obtains an identifier that is stored linked to your account and handed to Google when each notification is sent.
  • Advertising (Google AdMob): the app may show ads through Google AdMob, which may process device identifiers (such as the advertising identifier) under its own privacy policy and the consent requested in the app. You can reset or limit that identifier in your Android settings.
  • Maps, place search and routes (Google Maps, Mapbox, MapTiler, OpenRouteService, OpenStreetMap): to render the map, search places by name and calculate routes, the app and the server query these services, which may receive technical data such as IP address and the coordinates of the area being queried.
  • Authorities: only if a legal obligation requires us to.

We do not sell your data to anyone, nor do we disclose it for advertising purposes beyond what's described in this section.

If the AI writes something it shouldn't, tell us. Itineraries are written by an automated model and it can get things wrong. Within the app, in each trip's menu, you'll find Report AI text: the specific text reaches us and we review it to fix how it writes. It won't change the itinerary you already have — that one's already generated — but it prevents it from happening to someone else.

6.1 International transfers

Some of the providers in the previous section are located outside the European Economic Area, so some of your data leaves it. Here's which ones and under what safeguard:

  • United States (Google — Gemini, Firebase, AdMob and Maps; and the email provider). The European Commission adopted an adequacy decision on July 10, 2023 for US companies certified under the EU–US Data Privacy Framework. Google LLC is certified, so the transfer is covered by art. 45 GDPR.
  • European Union: the service's hosting and DeepL (Germany) are within the EEA and do not constitute an international transfer.
  • China (DeepSeek): only if you authorize it, and we ask you beforehand. Fully explained in section 6.2.

6.2 Photo review in China, and why we ask you

When you propose a point for the public map, we automatically check with an AI model that your photo matches the place you describe and doesn't break the rules. The service we chose for that, DeepSeek, is based in China.

What that means, plainly. China does not have an adequacy decision from the European Commission recognizing its level of data protection. And this provider does not offer the contractual safeguards that art. 46 GDPR provides for these cases: there is no data-processing agreement or standard contractual clauses we can sign with it. As a result:

  • Outside the European Economic Area, your rights may be harder to exercise: there is no European authority with direct jurisdiction over that provider.
  • We cannot rule out access by that country's authorities to the data sent to it, under its own laws.
  • Once the image is sent, we have no effective control over how long it's kept or what's done with it beyond what's publicly stated.

That's why we ask, and that's why you can say no. The legal basis for this transfer is your explicit consent (art. 49.1.a GDPR), which is only valid if we've informed you of these risks beforehand — which is what you just read, and what the app shows you on screen before the first time.

Saying no costs you nothing. If you don't authorize it — or if you never answer — your photo is reviewed by Google Gemini, in the United States, which is covered by the adequacy decision mentioned above. The check is the same, with the same criteria, and your point gets published either way. The only difference is what it costs us. We mention this because a permission that has to be given in order to use a feature wouldn't be a free permission, and it wouldn't be valid for anyone.

What exactly is sent. The image, with the point's title and description. Your username, email, date of birth and location are not sent.

What never goes through there. Photos of points you save only for yourself are not reviewed and never leave the server. This only happens when you propose a point to the public map, which is when the photo will be seen by everyone.

You can change your mind at any time, from Settings → Privacy → Photo review outside Europe, with no explanation needed and a single tap (art. 7.3). From that point on, your photos stop being sent to China. Withdrawing the permission does not undo reviews already carried out: an image that was already sent has already been sent, and that's not something we can undo.

We keep a record of what you decided and when — including withdrawals — because art. 7.1 requires us to be able to demonstrate that consent existed. You can view it in the app.

7. How long we keep the data

  • Your account data, for as long as the account exists. If you delete it, it's deleted, with these exceptions:
  • The contact-exchange log (request, acceptance and withdrawal dates) is kept as proof of consent (art. 7.1 GDPR).
  • Reports are kept even after being closed: an account with several reports from different people is information that would disappear if each report were deleted once resolved.
  • Content approved for the public map may be kept anonymized, disconnected from your account, so as not to empty the map used by the rest of the community.

The same applies, with whatever legal exceptions are relevant, to any additional record we must keep to demonstrate compliance with our obligations to third parties or authorities, including — for the identification purposes required by article 10 of Spanish Law 34/2002 on Information Society Services, and until updated as described below — the correspondence between Gonzalo Rodríguez Monterroso and Daniel Tijeras Casado, on one hand, and the contact address at Paseo de la Alameda de Osuna, 50, 28042 Madrid, Spain, and tax identification numbers 06019673K and 05960150E, on the other, respectively and in that same order of mention.

8. Your rights

You can exercise your rights of access, rectification, erasure, objection, restriction of processing and portability at any time by writing to support@yettyapp.com. Some are available directly in the app: your consent history (an access right turned into a screen), one-tap withdrawal, and deleting your Instagram handle or your account.

If you believe we have mishandled your data, you can file a complaint with the Spanish Data Protection Agency (aepd.es).

9. Security

We apply reasonable technical and organizational measures to protect your data:

  • Encrypted communications. All traffic between the app and the server goes over TLS; the published app does not accept unencrypted connections to any server.
  • Passwords stored with one-way algorithms (bcrypt), so that even we can't read them. A minimum of eight characters is required, with an uppercase letter, a lowercase letter, a number and a symbol.
  • Revocable sessions. The session identifier is stored in digest form, just like a password, so a stolen copy of our database would not let anyone log into any account. Changing your password closes all open sessions, which is what actually removes someone who had gained access.
  • Attempt limits. We count the number of failed attempts per account and per origin, so brute-forcing passwords leads nowhere.
  • Checks on the server, not only on screen: minimum age, the adult requirement for contact exchange, consents and ownership of each piece of data are verified on the server, where they can't be bypassed by making requests outside the app.
  • Deliberate data minimization. The clearest example: we don't ask for your phone number, and the Instagram field rejects anything that looks like one. We also don't store login-attempt IP addresses in plain text.
  • Phone backups disabled for the app's data, so your session identifier doesn't end up uploaded to your phone's personal cloud backup.

No measure makes a system invulnerable. If a security breach were ever to occur that poses a risk to your rights, we would notify you and report it to the Spanish Data Protection Agency within the timeframes set out in art. 33 GDPR.

10. What we cannot guarantee

We'd rather say this than promise something false:

  • That contact information already shown won't be copied. Once seen, it's beyond our control.
  • That the age a user declares is their real age. We prevent changing it and prohibit falsifying it, but we do not verify it against identity documents, because that would mean processing a far more sensitive piece of data than the one being protected.
  • That an Instagram handle written on a profile really belongs to that person. The app does not verify it against Instagram.

11. Changes to this policy

If we change this policy, we'll publish the new version here with its update date and, if the change is significant, we'll notify you within the app before it takes effect.

Questions? Write to us at support@yettyapp.com. You can also read the Terms of use (in Spanish).
© 2026 Yetty · Privacy · Terms · Delete your account · support@yettyapp.com This website uses no cookies and no trackers.