This Privacy Policy explains how Nocturify collects, uses, stores, shares and protects personal data when You use the Nocturify mobile application, website and related services.
Nocturify is designed around privacy by design and data minimisation. We aim to collect only information reasonably necessary to operate the platform, personalise Your experience, maintain trustworthy nightlife information, provide community features and improve the service.
1. Who is responsible for Your data?
Nocturify is currently operated by:
MB „Bereisa Solutions“ (a Lithuanian small partnership, mažoji bendrija or MB) Company code: 306983763 VAT number: LT100017378516 Registered address: Vingių g. 25, Padvarių k., LT-97157 Kretingos r., Lithuania Country: Lithuania Website: https://nocturify.com
For privacy questions, requests concerning Your personal data or general user support, contact:
MB Bereisa Solutions acts as the data controller for personal data processed through Nocturify unless otherwise stated.
2. Who can use Nocturify?
Nocturify is intended only for persons aged 18 or older.
When creating an account, You are required to confirm that You are at least 18 years old.
For an ordinary consumer account, Nocturify does not require You to provide a full legal name, full date of birth, identity document, home address or telephone number solely to establish Your identity or confirm Your age.
If we become aware that an account belongs to a person who is not eligible to use Nocturify, we may restrict or delete the account where appropriate.
3. Personal data we collect
The information we process depends on how You use Nocturify.
3.1 Account and authentication information
When You create or manage an account, we may process:
- Your email address;
- authentication identifiers;
- account verification status;
- authentication and session information;
- account language;
- information necessary for password recovery, email changes and account security;
- records showing acceptance of applicable legal documents.
You may also be able to authenticate through third-party identity providers such as Google or Apple. When You use one of these providers, Nocturify receives information necessary to authenticate and maintain Your account according to the information and permissions made available through that provider.
Google and Apple may separately process information relating to Your use of their authentication services according to their own privacy terms.
Passwords are handled through our authentication infrastructure and are not stored by Nocturify as readable plain-text passwords.
3.2 Profile and preference information
You may provide information used to personalise Nocturify, including:
- display name or nickname;
- profile image;
- preferred city;
- nightlife preferences;
- venue preferences;
- music preferences;
- age-group selection;
- gender, where You choose to provide it;
- other preference information made available through the application.
Optional preference information helps Nocturify personalise Your experience and may also contribute to aggregated audience insights as described in this Privacy Policy.
For an ordinary consumer account, Nocturify does not require You to publicly disclose Your real identity.
3.3 Favorites and account activity
When You use Nocturify, we may process information about features and actions associated with Your account, including:
- venues saved as favorites;
- preferences and settings;
- onboarding status;
- reports submitted through the platform;
- NightMiles activity and transaction history;
- other account-linked actions necessary to provide requested features.
These records are not intended to create a public profile of Your nightlife activity.
3.4 Technical crash and error diagnostics
To detect crashes and diagnose technical errors, maintain the reliability and security of Nocturify, and investigate technical problems, Nocturify uses Sentry as an external technical service provider/processor for mobile application crash and error diagnostics.
Sentry may process minimized technical diagnostic information, such as the app version and native build number, production or staging environment, operating system and version, device technical class or model where safely supplied, exception type, a sanitized exception message, stack-trace information and a bounded generic technical failure category. Nocturify configures this monitoring to minimize personal information and uses technical controls to filter and redact diagnostic data.
Nocturify does not intentionally send to Sentry precise location coordinates, Report Live contents, AI prompts or responses, private preferences, email, name, profile identifiers, authentication credentials or tokens, Authorization headers, Supabase session objects, notification tokens, passwords, invitation, verification, reset or change-email tokens, or signed Storage or Partner upload URLs. Diagnostic information is retained according to Nocturify's configured service/provider settings and applicable retention and data-minimisation rules.
3.5 Public website access
When You access the public Nocturify website, technical request information may be processed as necessary to deliver the requested pages and assets, maintain security, prevent abuse and diagnose technical problems. Depending on the request, this may include an IP address, browser or user-agent information, the requested URL, request headers, timestamps and other technical delivery or security metadata.
This processing does not mean that Nocturify itself persistently stores every item of technical request information. Some information is processed transiently by the hosting and delivery infrastructure used to provide the website.
The public website is hosted and delivered through Vercel, including Vercel's content-delivery and caching infrastructure. Nocturify has not integrated Vercel Web Analytics or Vercel Speed Insights into the current public website, and the production website does not include a visitor-facing Vercel Toolbar integration.
3.6 Public Contact and Venue Partner enquiry forms
If You submit the public Contact form, we may process Your name, email address, selected topic, message, locale, submission time and a technical submission identifier or related delivery metadata. We use this information to validate and route the enquiry, respond to You, deliver the message to the appropriate Nocturify mailbox, prevent abuse and maintain operational reliability. Submitting this form does not create a Nocturify account.
If You submit the public Venue Partner enquiry form, we may process the venue name, city, contact name, business email address, optional telephone number, optional website or social-media link, optional message, locale, submission time and a technical submission identifier or related delivery metadata. We use this information to assess and respond to an expressed venue-partnership interest, identify the relevant venue and contact, deliver the enquiry, allow a direct reply, prevent abuse and maintain operational reliability. Submitting an enquiry does not approve a partnership, create a Partner account or constitute acceptance of a commercial agreement.
Anonymous browsing of the public website does not initialize Supabase Auth or create a Supabase user session. Only after You explicitly submit a Contact form, Venue Partner enquiry or launch-notification request is the submitted information sent to the applicable Supabase Edge Function for validation, abuse prevention and server-side processing. The production Supabase project database is configured in the eu-central-1 region; Edge Function execution or other provider processing may use infrastructure determined by the provider and service configuration.
After validation, Nocturify uses Resend as a server-side transactional email provider to deliver the enquiry to the appropriate Nocturify mailbox. Your browser does not contact Resend directly. The submitted contact details and message may be processed as email-delivery content, and the submitted email or business email may be used as the Reply-To address. Nocturify's form backend does not persist the raw enquiry body in a dedicated public-form database table.
3.7 Launch notification waitlist
If You explicitly submit the clearly labelled launch-notification form, we collect the email address You submit. We also store limited operational metadata: the language of the page used to sign up, the fixed signup source, subscription status, and server-generated creation and update timestamps. The email address is trimmed and converted to lower case so that one normalized email address corresponds to one waitlist subscriber. Duplicate submissions do not create another subscriber record or another owner notification and receive the same generic response.
We use this information to maintain the waitlist and send the Nocturify launch notification and closely related launch updates that You request. This signup does not create a Nocturify account or a general newsletter subscription and does not authorize unrelated marketing, third-party advertising, profiling, sale of data or ad targeting.
The subscriber record in Supabase is the durable source of truth. For each genuinely new signup, the server uses Resend to send an operational notification to Nocturify at business@nocturify.com containing the submitted email address, page language, signup source and signup time. The browser does not contact Resend directly. The subscriber remains stored if delivery of that operational notification fails.
3.8 Public-form abuse prevention
Nocturify uses proportionate technical controls to protect public forms, including the launch-notification form, from spam, abuse and service disruption. The trusted client IP address and normalized email address are used to derive scoped cryptographic identifiers. The rate-limit system stores derived hashes, applicable time-window and expiry information, and request counts. It does not store the raw IP address, raw email address or raw form body in those counters. For waitlist submissions, the trusted client IP address is processed transiently and is not stored in the waitlist or rate-limit records. The submitted email address is intentionally stored in the waitlist as described above, but not in the rate-limit counters.
Current rate-limit windows include 10-minute, one-hour and one-day periods. The longest counter lifetime is approximately one day, and expired rows are removed during limiter maintenance activity.
3.9 Cookies, browser storage and external links on the public website
At launch, the public website does not use optional analytics, advertising or marketing cookies, social tracking pixels, or persistent localStorage, sessionStorage or IndexedDB for those purposes. It does not currently use Google Analytics, Meta Pixel, TikTok Pixel, LinkedIn Insight, Vercel Web Analytics or Vercel Speed Insights. Website language selection is URL-based and does not require a cookie.
The launch-notification form does not persist the submitted email address in cookies, localStorage, sessionStorage or IndexedDB. The email address is stored server-side only after You explicitly submit the form.
If optional tracking or browser storage requiring consent is introduced in the future, Nocturify will update its disclosures and implement any consent controls required before that technology is used.
The website's Facebook, Instagram, TikTok and LinkedIn controls are ordinary outbound links. No social SDK, widget or tracking pixel is loaded merely because a Nocturify page is displayed. If You choose an external link, the destination provider's own terms and privacy practices apply.
The public website may also link to the Partner service at partners.nocturify.com. Merely browsing the public website does not initialize a Partner Dashboard session or authentication. If You intentionally navigate to the Partner service, the privacy and contractual framework applicable to that service may apply.
4. Private-by-default consumer information
Nocturify is designed so that ordinary consumers do not receive unrestricted access to other consumers’ private account information.
Other consumers are not provided access through normal Nocturify functionality to information such as another user’s:
- email address;
- authentication information;
- private preferences;
- favorites;
- NightMiles history;
- private account activity;
- precise location information;
- private report history.
If Nocturify introduces an intentionally public community feature in the future, the information made public and the applicable privacy controls will be clearly identified.
5. Location and GPS information
Nocturify uses location only for specific product functions.
Depending on the feature You use and the permissions You grant, location may be used to:
- identify a supported city;
- show venues near You;
- calculate distance to venues;
- verify that a community report is being submitted near the relevant venue.
Nocturify currently uses foreground location access. We do not intentionally track Your location continuously in the background.
GPS-verified reports
When You submit a live venue report, Nocturify may temporarily use Your device coordinates and location accuracy to determine whether You are sufficiently close to the selected venue.
The current reporting process uses those coordinates for verification and records whether the report passed GPS verification. The current report-submission process does not intentionally store the raw submitted GPS coordinates in the resulting report record.
Nocturify is therefore not designed to create a continuous historical record of Your movements.
You may deny location permission. Some location-dependent functionality may then be unavailable or less accurate, while other parts of Nocturify remain usable.
Additional information is provided in the Nocturify Location & GPS Disclosure.
6. Reports and community activity
Nocturify allows eligible users to submit information about current venue conditions.
A report may include structured information such as:
- crowd level;
- queue conditions;
- atmosphere or similar venue conditions;
- the venue concerned;
- submission time;
- verification status;
- other information supported by the reporting feature.
Reports are associated with an account internally so that Nocturify can enforce security, reporting limits, NightMiles rules, abuse prevention and data integrity.
Community information may be validated, combined or aggregated before being presented to other users or venues.
Nocturify is designed to show useful nightlife signals without unnecessarily identifying the individual users who contributed those signals.
7. NightMiles
NightMiles is Nocturify’s community participation and rewards system.
When You earn or use NightMiles, we may process account-linked records necessary to:
- calculate Your NightMiles balance;
- record qualifying activity;
- prevent duplicate, manipulated or fraudulent rewards;
- maintain transaction history;
- operate eligible rewards or redemption features.
NightMiles records are not intended to function as a public record of Your nightlife activity.
8. Aggregated insights for venues
Nocturify may use community reports, venue interactions, preferences and other platform activity to create aggregated statistics and insights for venues and venue partners.
These insights may include, for example:
- the number of Nocturify users contributing qualifying activity relating to a venue;
- aggregated music or nightlife preferences;
- aggregated age-group distributions;
- aggregated gender distributions where users have chosen to provide gender information;
- crowd, queue and atmosphere trends;
- reporting patterns;
- venue engagement trends;
- comparisons between different periods;
- other aggregated audience or venue-level statistics.
For example, a venue may be able to understand that a certain percentage of qualifying users prefer a particular music style, or that a certain proportion of verified reports during a period described the venue as crowded.
These analytics are intended to describe audiences, groups and trends rather than individual consumers.
Nocturify does not provide venues with the underlying individual user profiles used to calculate these aggregated statistics.
Through venue analytics, venues do not receive unrestricted access to individual users’:
- email addresses;
- authentication information;
- passwords;
- precise location history;
- individual favorites;
- individual NightMiles history;
- private account records.
Nocturify may apply minimum audience thresholds, aggregation, de-identification or similar privacy safeguards where appropriate to reduce the risk that an aggregated statistic could be used to identify a particular individual.
Where an audience segment is too small to provide an appropriate level of privacy, Nocturify may withhold the statistic or display that there is not enough data.
Commercial relationships with venues do not give venues unrestricted access to consumer personal data.
Venue partnerships, advertising relationships or other commercial arrangements also do not change the underlying factual nightlife information presented by Nocturify.
9. AI-powered features
Nocturify includes or is developing AI-assisted features such as:
- Home AI;
- Venue AI summaries;
- Ask Nocturify.
Our guiding principle is:
Nocturify determines the facts. AI explains the facts.
Authoritative venue information, opening status, live activity, events, recommendations and other factual product states are determined by Nocturify’s systems and verified data rather than being invented by a language model.
Certain Nocturify AI explanation functions on the Home screen may use a third-party AI service provider. Where this occurs, Nocturify shares only the minimum structured information needed to assist with planning an explanation of results that Nocturify has already approved.
For this Home-screen AI explanation-planning function, the third-party AI service provider does not receive raw GPS coordinates, user identity, raw user profiles, raw preferences, raw individual community reports, ranking scores, partner or commercial status, or raw venue data.
The provider does not determine venue eligibility, which venues appear, venue order, factual venue states, trust or verification results, or personal-fit calculations.
Nocturify will update this Privacy Policy and the AI Transparency notice where material changes to personal-data processing require it.
10. Legal acceptance records
When You create an account or when material legal terms require renewed acceptance, Nocturify may record:
- which legal documents were accepted;
- the applicable document versions;
- the date and time of acceptance;
- relevant language or acceptance context;
- Your internal account identifier.
These records allow Nocturify to establish which version of its terms and disclosures applied when You used the service.
11. Why we process personal data
We process personal data for purposes including:
- creating and maintaining Your account;
- authenticating You and protecting account security;
- providing venue discovery and nightlife information;
- personalising recommendations according to Your preferences;
- providing favorites, reports, NightMiles and other requested functionality;
- verifying the integrity of community reports;
- generating aggregated venue and audience insights;
- preventing abuse, fraud, manipulation and unauthorized activity;
- providing support and responding to requests;
- maintaining the launch-notification waitlist and sending the Nocturify launch notification and closely related launch updates You request;
- preventing duplicate waitlist entries and securing the launch-notification form against spam and abuse;
- maintaining platform reliability and security;
- improving Nocturify and understanding the performance of its features;
- complying with applicable legal obligations;
- establishing, exercising or defending legal claims where necessary.
We do not sell Your personal data.
12. Legal bases for processing
Under the General Data Protection Regulation (GDPR), the legal basis depends on the processing activity.
Performance of a contract
We process information where necessary to provide the Nocturify service You request, including account functionality, preferences, favorites, reports, NightMiles and core platform features.
Legitimate interests
We may process information where necessary for legitimate interests such as:
- securing Nocturify;
- preventing fraud and abuse;
- maintaining trustworthy community information;
- producing privacy-protective aggregated insights;
- diagnosing service failures;
- understanding and improving platform reliability;
- protecting users, venues and the platform.
For the public website, these legitimate interests may include operating, securing and delivering the website; diagnosing technical failures; responding to ordinary Contact enquiries; preventing duplicate waitlist entries; and preventing spam, abuse and service disruption through proportionate rate limiting and other safeguards.
Processing a Venue Partner or other business enquiry may be necessary to take steps requested by You before a potential contractual relationship and/or may be based on our legitimate interests in receiving and responding to business enquiries, depending on the context.
Where we rely on legitimate interests, we consider whether those interests are overridden by Your rights and freedoms.
Consent
Where applicable, we rely on Your consent for optional device permissions or other processing that legally requires consent.
When You explicitly submit the clearly labelled launch-notification form, we rely on Your consent to store Your waitlist details and send the Nocturify launch notification and closely related launch updates You requested. This consent does not extend to general or unrelated marketing. You may withdraw it at any time by contacting support@nocturify.com.
For example, Your device operating system may ask You to grant location permission before Nocturify can access foreground location.
You can withdraw device permissions through Your device settings.
Legal obligations
We may process or retain information where necessary to comply with obligations imposed by applicable law.
Accepting or acknowledging this Privacy Policy does not mean that consent is the legal basis for every processing activity described in it.
13. Who we share personal data with
We may share or make personal data available where necessary for operating Nocturify, complying with law, protecting the service or using service providers acting on our behalf.
This may include providers used for:
- database hosting;
- authentication;
- file storage;
- server-side application functionality;
- transactional authentication email;
- cloud infrastructure;
- security;
- customer support;
- third-party AI service providers used for limited explanation functions;
- analytics or marketing, if introduced in the future in accordance with applicable requirements.
Nocturify currently uses Supabase as a core backend infrastructure provider for database, authentication, storage and server-side functionality. For the public Contact and Venue Partner forms and the launch-notification form, Supabase Edge Functions process submitted information server-side after explicit submission, and the database supports the derived, short-lived abuse-prevention counters described above. Supabase stores the durable launch-waitlist subscriber record.
Vercel provides hosting, content delivery and caching for the public website and may process technical request information needed to deliver and protect the website.
Resend provides server-side transactional email delivery for validated Contact and Venue Partner enquiries and may process the submitted contact details and message as email content for that purpose. For each genuinely new launch-waitlist signup, Resend also delivers an operational notification to Nocturify containing the email address, page language, signup source and signup time. Resend is not the durable waitlist store, and duplicate submissions do not trigger another notification.
Authentication may also involve Google or Apple when You choose to use those sign-in methods.
Service providers process information according to their role, applicable contractual terms and applicable data-protection requirements.
Nocturify does not currently use third-party advertising or marketing-attribution SDKs in the mobile application.
If we introduce advertising, analytics, attribution or similar technologies in the future, including technologies used for platforms such as Meta or other advertising services, we will update this Privacy Policy and implement any notice, consent or other controls required by applicable law before using them where required.
We do not sell Your personal data to venues, advertisers or other third parties.
14. International data transfers
Some service providers may process personal data using infrastructure located outside Lithuania or elsewhere within or outside the European Economic Area.
Where personal data is transferred outside the European Economic Area, we will use an applicable lawful transfer mechanism where required, such as:
- an adequacy decision of the European Commission;
- Standard Contractual Clauses;
- another mechanism permitted under applicable data-protection law.
The exact infrastructure and transfer safeguards may depend on the provider and service configuration in use.
15. How long we keep personal data
We keep personal data only for as long as reasonably necessary for the purposes for which it was collected, including providing the service, protecting the platform, resolving disputes, enforcing agreements and complying with applicable legal obligations.
Different categories of information may require different retention periods.
Account-linked consumer data is generally removed when an eligible consumer account is deleted, subject to technical, security, fraud-prevention, legal or record-retention requirements that may apply to particular information.
Operational, security, legal or audit information may need to be retained for longer where deletion would undermine legitimate security, legal or accountability requirements.
Ordinary closed Contact enquiries and unsuccessful Venue Partner enquiries are normally deleted or anonymized approximately 12 months after the last meaningful interaction. Information may be retained longer where reasonably necessary for active correspondence, an accepted commercial relationship, accounting or statutory obligations, legal claims or disputes, fraud or security investigations, or a legal hold. Information relating to an accepted commercial relationship is handled under the applicable contractual and accounting retention framework. These periods describe Nocturify's operational handling and do not claim to control the separate backup or retention practices of service providers.
We retain a launch-waitlist email address and its associated waitlist metadata only for the launch notification and closely related launch communications requested by the subscriber. We delete or anonymize the waitlist record when the subscriber withdraws or requests deletion, or no later than 12 months after the last launch-related communication, unless a longer period is required for a documented legal, security or dispute-related reason. Where a minimal suppression record is necessary to honor a prior opt-out, we retain only the minimum information reasonably necessary for that purpose.
Nocturify will maintain and review more specific operational retention rules where fixed retention periods are appropriate.
16. Account deletion
You can request deletion of an eligible consumer account through the account settings available in Nocturify.
Deleting an eligible consumer account removes the authentication identity and account-linked consumer records according to Nocturify’s deletion rules.
Certain operational accounts, including accounts connected to venue ownership, moderation, founder administration or other retained operational records, may require a separate assisted deletion or de-identification process so that Nocturify does not improperly destroy legally or operationally necessary records.
If self-service deletion is unavailable for such an account, contact:
Deletion of an account does not necessarily require deletion of information that Nocturify is legally required or otherwise lawfully entitled to retain.
17. Data security
Nocturify uses technical and organizational measures intended to protect personal data against unauthorized access, loss, misuse, alteration or disclosure.
Current measures include, where applicable:
- authenticated access controls;
- Row Level Security and database access policies;
- server-side authorization for sensitive operations;
- server-side validation and access controls for public forms;
- proportionate rate limiting using scoped derived identifiers rather than raw IP addresses or emails in limiter records;
- restricted service credentials;
- account verification;
- password recovery protections;
- controlled storage access;
- data minimisation;
- separation between staging and production environments.
No security system can guarantee absolute security.
You should protect Your account credentials and contact us if You suspect unauthorized account activity.
18. Your rights
Subject to the GDPR and applicable law, You may have the right to:
- receive information about how Your personal data is processed;
- access personal data we hold about You;
- request correction of inaccurate data;
- request deletion of Your data;
- request restriction of processing;
- object to certain processing based on legitimate interests;
- receive certain personal data in a portable format;
- withdraw consent where processing is based on consent;
- lodge a complaint with a competent data-protection supervisory authority.
These rights may be subject to applicable legal limitations or exceptions.
To exercise Your rights, contact:
If You joined the launch-notification waitlist, You may withdraw from launch-related communications or request deletion of Your waitlist record at any time by contacting support@nocturify.com. No public unsubscribe endpoint is currently offered.
We may need to verify Your identity before completing a request.
In Lithuania, the competent supervisory authority is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija). The Inspectorate provides procedures for complaints and data-subject requests. (Valstybinė duomenų apsaugos inspekcija)
19. Profile images
Nocturify does not currently operate a general public consumer-profile feature.
Profile images are intended for account/profile functionality and are not intended to create public consumer profiles.
Nocturify is implementing the appropriate storage and delivery controls for profile images before Closed Beta.
Do not upload a profile image that You do not have the right to use.
Venue images and public venue information are different from personal profile images and may intentionally be displayed publicly as part of venue discovery.
20. Automated processing and recommendations
Nocturify may use automated systems to rank, filter or recommend nightlife options based on factors such as:
- venue availability;
- location;
- verified activity;
- events;
- user preferences;
- other product signals.
These systems are intended to support nightlife discovery.
Nocturify does not currently use such automated processing to make decisions that produce legal effects or similarly significant effects concerning You within the meaning of Article 22 GDPR.
21. Changes to this Privacy Policy
We may update this Privacy Policy when Nocturify changes, our processing activities change or legal or regulatory requirements require an update.
The current version and effective date will be displayed with the Privacy Policy.
Where a material change requires renewed acceptance, Nocturify may ask You to review and accept the updated version before continuing to use relevant services.
Previous acceptance records may be retained where necessary to establish which version applied at a particular time.
22. Contact us
For questions about this Privacy Policy, Your personal data, account deletion or Your privacy rights, contact:
MB Bereisa Solutions Company code: 306983763 Vingių g. 25, Padvarių k. LT-97157 Kretingos r. Lithuania
Email: support@nocturify.com