Effective date: 15 September 2026
"Where next?" is a conversational event-discovery app for Berlin, built by the team behind nirbai.com. This policy is specific to the "Where next?" app (a distinct application with its own App Store/Play Store listing and bundle identifier, separate from the nirbai.com companion app). If you are looking for the privacy policy for the nirbai.com web app instead, see that page.
When you send a message, we store the text of your message and the app's reply, so that follow-up questions ("what about Saturday instead?") work correctly. Alongside the conversation, we keep a small structured record of your current search — things like the date range, city, and time-of-day filters you're currently browsing with. This is what lets the app understand a short follow-up without you having to repeat your whole request.
This data is user-generated content and may incidentally contain personal details if you choose to type them (for example, if you mention who you're going with). We do not ask for this information and don't use it for anything beyond answering your question and, if you opt in to recommendations, suggesting events you might like.
The first time you open the app, it registers your device with our servers and receives a signed device token in return. This creates an anonymous user record on our side, identified only by a one-way (salted, cryptographically hashed) fingerprint of your device — never your device's raw identifier, and never your name, email, or phone number. This anonymous record is what lets your conversation persist across app restarts, and what our per-device usage limits (below) are tied to.
If you choose to sign in with Apple or Google, your anonymous history is merged into your signed-in account rather than being duplicated or lost. We receive only the name and email address those providers choose to share with us.
If you sign in, you can mark events as "interested." We store which events you saved so they stay on your Interested list across devices.
We may also build a short interest profile from your recent conversations, saved events, and what you dismiss, and use it to send occasional "for you" recommendations (in the app and, if you allowed notifications, as a push). This profile is derived on our servers; it is not sold or used for advertising.
Notifications are optional. If you grant permission, we store a push token for your device, plus the platform (iOS or Android) and timezone, so we can deliver recommendations at a sensible local time. We refresh a last-seen timestamp when you open the app so we don't keep sending to abandoned installs. Turning notifications off on your device stops delivery; we do not send marketing from third parties.
To keep the app fast and available for everyone and to prevent abuse of a service that costs us money to run per message, we keep short-lived counters of how many messages your device has sent per hour and per day. These counters expire automatically (within a day) and are not used for anything other than enforcing these limits. We also keep a similarly short-lived, one-way hashed fingerprint of the network address your requests come from, purely to stop a bad actor from resetting their limit by reinstalling the app — we never store your actual IP address, and the hash is discarded once the usage window it was created for ends.
If you grant permission, the app uses your device's location — only while the app is open and in use, never in the background — to find things happening near you and to show how far an event is. Your precise coordinates are used in memory, on our servers, for the duration of that one request, to run the search and compute distances. Before anything is saved to our database or sent to our monitoring tools, your location is rounded down to roughly a city-district level of precision (about a kilometre). We never store your exact GPS coordinates.
If you decline location access, the app will ask which neighbourhood of Berlin you're interested in instead, in the conversation itself — there is no separate settings screen you need to find.
The app records a small, fixed set of product-usage events on the device (for example: a conversation started, a card was tapped, a "get tickets" link was opened) so we can tell whether the app is working. These events do not include the text of your messages, the specific event names you searched for, or precise coordinates. We do not currently send this usage data to a third-party analytics vendor. If that changes, we will name the vendor here before they receive any data.
We use Sentry to learn about crashes and errors so we can fix them. Before a crash report leaves your device, we strip free-text message fields and round any location-shaped data to the same coarse precision described in section 2.6. Sentry may separately collect standard device/OS diagnostic information (device model, OS version, app version) as part of a crash report.
We typically keep conversations and their messages for up to 90 days after last activity. If you want it gone sooner, email the address in section 9 with the subject "Delete my Where next? data." We will remove:
We do not sell your data. We do not share it with data brokers or advertisers. The following processors act on our behalf, each under a data processing agreement, and only to provide the app's core functionality:
| Processor | What they process | Purpose |
|---|---|---|
| Amazon Web Services (AWS) | App data at rest (database, application servers) and, if you sign in, account authentication (Cognito). | Hosting, infrastructure, and optional sign-in |
| Google (Gemini API) | The text of your message and relevant candidate event data, for the duration of generating a reply or a recommendation. No name, no email, no precise location. | Generating conversational replies and personalized event suggestions |
| Langfuse | A pseudonymous copy of prompts and replies (identified by a one-way hash, never your account id, name or email) and coarse location only, for a limited retention window. | Monitoring and improving the quality of the AI's answers |
| Sentry | Crash reports and performance data, scrubbed as in section 2.8. | Diagnosing and fixing app crashes and errors |
| Expo (push delivery) | Your device's push token, only if you granted notification permission. | Delivering optional recommendation notifications |
| Apple / Google | Standard app-store delivery; DeviceCheck on iOS; and — only if you choose to sign in — the name and email your Apple/Google account shares with us. | App distribution, install integrity, and optional sign-in |
Our hosting and some of our processors (notably Google, for AI inference) process data in the United States. Where that happens, the transfer is covered by the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, supplemented by standard contractual clauses. What actually leaves our own systems in an AI call is a short piece of free text (your message) and a list of public event listings — never your name, email, or precise location, since those are removed or coarsened first. If data residency requirements change in the future, our AI provider offers an equivalent EU-hosted option we can switch to without changing how the app works.
Depending on where you live, you may have the right to:
To exercise these rights, contact us at the address in section 9.
"Where next?" surfaces event listings that may reference nightlife, alcohol-serving venues, and age-restricted events, and is not directed at children. It carries an age rating reflecting this on the App Store and Google Play. We do not knowingly collect data from children under the applicable age of digital consent in their country.
We may update this policy as the app changes. Material changes will be reflected here with an updated effective date. Questions about this policy can be sent to our support address.