Cookies Policy, Gutsy Ltd

Effective Date: 18 August, 2026 · Version 1.1

1. Introduction

This Cookies Policy explains how GUTSY LTD ("we", "us", "our") uses cookies and similar technologies when you use our mobile application, Just Gutsy (the "App").

This policy should be read alongside our Privacy Policy. It explains what these technologies are, why we use them, and your rights to control our use of them.

2. What Are Cookies and Similar Technologies?

Cookies are small text files that are stored on your device. However, in a mobile app context, the term is often used more broadly to include other similar technologies, such as Software Development Kits (SDKs).

An SDK is a third-party piece of code embedded within our App that allows our partners to collect information about how you interact with the App. We use these technologies to help our App function, understand how you use our service, and for analytics purposes.

This policy covers technologies that store or access information on your device. Server-side infrastructure that powers the App (such as our database, photo storage, and server-side logic, all provided by Google Firebase) does not store information on your device and is described in our Privacy Policy instead.

3. Why Do We Need This Policy?

Under the UK's Privacy and Electronic Communications Regulations (PECR) and equivalent national ePrivacy legislation applicable within the European Economic Area, we are required to provide you with clear and comprehensive information about the technologies we use and to obtain your consent before placing any non-essential cookies or SDKs on your device.

4. What Technologies Do We Use?

We use three categories of technologies in our App, described below.

a) Strictly Necessary Technologies

These are essential for the App to function correctly. They cannot be opted out of, as the App cannot operate without them. No personal data collected by these technologies is used for tracking or analytics purposes.

Provider Technology Purpose Data Collected
Google LLC Firebase Authentication SDK To manage secure user login via phone-number verification, maintain your authenticated session, and protect your account. Session tokens and authentication credentials stored locally on your device.
Google LLC Firebase App Check (App Attest on iOS, Play Integrity on Android) To verify that requests to our backend originate from a genuine, unmodified installation of the App, protecting against fraud and abuse. An attestation token generated on your device and included in requests to our backend so we can verify the request came from the genuine App. The token itself does not contain personal data but is unique to your App installation.
Google LLC Firebase Remote Config SDK To allow us to update App settings, feature configurations, and the minimum supported App version without requiring a full App update. Configuration values cached locally on your device. No personal data collected.
Google LLC Google Maps SDK To render maps and location-based features, including the discovery map of nearby traveller activity and meetups. This is core App functionality. Map tile requests and SDK operational and diagnostic telemetry transmitted to Google as part of the SDK's normal operation. This transmission is essential to the map functionality and is not gated by your analytics consent choice. See our Privacy Policy §5 for details of Google's processing.
RevenueCat, Inc. RevenueCat (purchases) SDK To manage premium subscription entitlements and reconcile purchases across the Apple App Store and Google Play. A pseudonymous application user identifier and subscription lifecycle events (purchase, renewal, cancellation). No name, phone number, email, or profile content.

b) Analytics, Performance & Crash-Reporting Technologies (Consent Required)

These technologies collect information about how you use our App, including in-app navigation, feature usage, timing, crash reports, and session replays in which all text and images are masked before transmission. They help us understand usage patterns, fix bugs and stability issues, and improve the App.

None of these technologies is activated unless you explicitly consent when first opening the App, and you can withdraw consent at any time via the toggle in Settings. If you decline, no analytics, performance, crash, or session-replay data is collected from your device.

Provider Technology Purpose Data Collected Retention
Google LLC Firebase Analytics / Google Analytics for Firebase To collect statistical data on how users interact with the App, helping us understand usage trends and prioritise new features. App instance ID, session data, screen views, in-app events, device type, and operating system. IP addresses are truncated before storage. Up to 14 months by default.
Google LLC Firebase Performance Monitoring SDK To measure App performance including startup time, network request latency, and screen rendering, helping us identify and resolve performance issues. Firebase installation ID, device model, operating system, network conditions, App start time, and performance trace data. 30 days in the Firebase console.
Google LLC Firebase Crashlytics SDK To automatically detect and report App crashes, helping us identify and fix stability issues. Crash reports contain technical information about the state of the App at the moment of failure not your messages, photos, or profile content. Device model, operating system version, App version, a persistent Crashlytics installation UUID, and crash stack traces. Crash reports are not linked to your account. 90 days in the Firebase console.
PostHog Inc. (EU-hosted at eu.i.posthog.com) PostHog Flutter SDK, including session replay To understand user journeys, diagnose UX friction points, and record session replays in which all text and images are masked before transmission. Helps us improve the App without relying on aggregate metrics alone. Pseudonymised device ID, session ID, screen views, in-app events, session replays (masked at capture), coarse device model and OS, and your Firebase Auth UID (a pseudonymised account identifier, linked once you sign in). Data is hosted in PostHog's EU data centre. Events: 12 months. Session replays: 30 days.

c) Communication Technologies (Device-Level Permission)

These technologies deliver push notifications relating to your use of the App, such as chat messages, meetup activity, and connection updates. Whether notifications are delivered is controlled by your operating system's push permission, which you can grant or withdraw at any time in your device settings.

Provider Technology Purpose Data Collected
OneSignal Inc. OneSignal SDK To deliver push notifications about chat messages, meetup activity, and other in-app events relating to your use of the App. Device push token and a pseudonymised OneSignal user ID linked to your account once you sign in.

5. Your Consent

When you first open the App, we will ask for your consent to use the Analytics, Performance & Crash-Reporting technologies described in Section 4(b). These technologies will only be activated if you explicitly agree.

Our consent request presents these technologies as a separate, optional choice from the core App functionality. Consent is not pre-selected. You can accept or decline independently, and declining will not prevent you from using the App.

Strictly Necessary technologies (§4a) do not require your consent, as they are essential for the operation of the App.

Push notification delivery (§4c) is not controlled through this in-app consent flow. It is controlled by the push-notification permission provided by your operating system.

If we add new non-essential technologies, or change the purposes of existing ones, we will ask for your consent again before activating them (see Section 7).

6. How to Manage Your Preferences and Withdraw Consent

You have the right to withdraw your consent at any time.

For Analytics, Performance & Crash-Reporting technologies (§4b): you can manage your preferences through the settings menu within our App. The analytics toggle is found under Settings and applies simultaneously to Firebase Analytics, Firebase Performance Monitoring, Firebase Crashlytics, and PostHog (including session replays). Opting out disables all four; opting back in re-enables all four. Opting out will not affect the core functionality of the App, but it will limit our ability to fix bugs and improve your experience based on usage and crash data.

For Communication technologies (§4c OneSignal push notifications): you control whether push notifications are delivered via your operating system's notification settings. You can revoke push permission at any time in your device settings, which will stop delivery without affecting your ability to use the App.

7. Changes to This Policy

We may update this Cookies Policy from time to time. We will notify you of any significant changes. Where changes affect the non-essential technologies we use or the purposes for which we use them, we will request your consent again through the App before activating any new or changed technologies. For administrative or clarificatory changes that do not affect your consent choices, your continued use of the App after notification will constitute acceptance of the updated policy.

Previous versions of this Cookies Policy (including version 1.0 dated April 6, 2026) are available upon request by contacting us at hello@justgutsy.com.

8. Contact Us

If you have any questions about our use of cookies or other technologies, please contact us at hello@justgutsy.com.

You also have the right to lodge a complaint about our use of cookies and tracking technologies with the Information Commissioner's Office (ICO) at www.ico.org.uk or by calling 0303 123 1113.

Individuals located in the European Union may also lodge a complaint with the supervisory authority in the Member State of their habitual residence, place of work, or the place of the alleged infringement. For users in France, this is the Commission Nationale de l'Informatique et des Libertés (CNIL) at www.cnil.fr.