Gigmo
Privacy Policy
Gigmo helps freelance musicians and performers manage their gigs, tasks and contacts. This policy explains what data the app stores, where it goes, and how you get rid of it.
1. Who is responsible
The controller for the processing described here is:
Daniel Ferrer
Zossener Straße 53
10961 Berlin, Germany
Email: privacy@gigmo.ai
Gigmo is an independent app, not a company product. If you are in the EU or the UK, the GDPR applies to this processing, and your rights under section 12 are enforceable against the controller named above.
2. The short version
- Your gigs, tasks, contacts and profile are stored in Google Firebase, in Google’s European multi‑region.
- We do not sell your data, we do not run advertising, and we do not share your content with anyone except the service providers listed in section 9.
- Google Calendar sync and email import are off until you turn them on.
- Deleting your account deletes your data — automatically and server‑side, not “on request”. See gigmo.ai/delete-account.
3. Data you give us by using the app
Your account
- Sign‑in details — your email address, and, if you sign in with Google, your Google account identifier and display name. Handled by Firebase Authentication. Gigmo never sees your Google password.
- Your profile — username, names, phone numbers, email addresses, postal addresses, websites and dates you choose to record, plus your app settings (notification preferences, gig types, custom fields, task templates, visibility settings).
- Your profile picture, if you set one.
Your work data
- Gigs — title, dates and times, venue name and address (including its map coordinates), fees and payment lines, notes, schedule, and the contacts you associate with the gig. A per‑gig change history is kept so collaborators can see what changed.
- Tasks — title, due date, notes, and the gig they belong to.
- Contacts — names, phone numbers, email addresses, postal addresses, role, contact type, notes and a picture, for the people you work with. See section 6.
- Files you attach — contracts, riders, stage plans, gig pictures. Stored in Firebase Cloud Storage.
- Availability and collectives — blocked date ranges, and the membership and shared gigs of any collective you join.
Sharing with other Gigmo users
When you share a gig with another Gigmo user, that gig — and the profile information your sharing settings allow — becomes visible to them. Contact requests record who asked, who was asked, and the answer. You control what others can see about you in the app’s privacy settings.
4. Data from your device
Each of these is requested only when you use the feature, and only after your operating system asks your permission:
| Permission | Used for | What leaves the device |
|---|---|---|
| Contacts | Importing people from your phone’s address book | Only the contacts you explicitly select. The rest are never uploaded. |
| Camera and photos | Profile pictures, gig pictures, scanning a document | Only the images you choose. Text recognition on a scanned image runs on your device. |
| Microphone | Speaking a gig instead of typing it | Your speech is transcribed by your device’s own speech service (Google or Apple, under their policies). Gigmo receives the resulting text. |
| Notifications | Reminders and gig updates | A push token identifying this installation, stored so we can send you notifications. |
| Address search | Autocompleting venue addresses | The address text you type is sent to the Google Places API. |
5. Google Calendar (optional)
If you connect Google Calendar, you grant Gigmo the
calendar.events scope, plus read access to your calendar list.
With it, Gigmo:
- reads events from the calendars you select, so gigs can be imported and double bookings are visible;
- creates, updates and cancels calendar events for your gigs.
So that this keeps working while your phone is off, a Google refresh token is stored on our server and is readable only by the sync worker. Gigmo does not add guests to your calendar events unless you explicitly turn that on for a specific gig.
Google API Services User Data Policy. Gigmo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is used only to provide the features above. It is never sold, never used for advertising, and never used to train AI models.
You can disconnect at any time in the app’s calendar settings, which revokes the token with Google and deletes it from our server.
6. Contacts you add — data about other people
Gigmo is an address book for your working life, so most contact records are personal data about someone else. You decide what goes in. In GDPR terms you are responsible for having a lawful basis for the details you record, and Gigmo processes them on your behalf and on your instructions.
- Contacts you add are visible to you, and to anyone you share the relevant gig with.
- Temporary contacts created for a one‑off gig are archived automatically once that gig is long past.
If you appear in someone else’s Gigmo contact list and want that record removed, write to privacy@gigmo.ai and we will pass the request on.
7. Email import (optional)
If you switch email import on, Gigmo issues you a private forwarding
address (import+…@gigmo.ai). Enquiries you forward there are
received by Cloudflare, which runs the gigmo.ai mail domain (Email Routing and
a Worker that parses the message), and passed to Gigmo, which stores:
- the sender’s name and address, the subject, the message text and any attachments;
- the time it was sent and received, and its SPF, DKIM and DMARC authentication results;
- what the AI extraction made of it, so you can accept or reject the suggestion.
Cloudflare handles the message in transit on its global network — the location that receives it depends on where the sending mail server is, and may lie outside the EU — and keeps nothing once it has been passed on; the stored copy lives in Frankfurt like the rest of your data (section 9).
These records delete themselves 30 days after arrival. Anything you accept into a gig, task or contact is then kept as ordinary app data. You can switch email import off, and change or retire the address, in the app’s settings.
8. AI processing
Gigmo uses Google Gemini models to turn text — an email, a message, or something you type or dictate — into a draft gig, task or contact. The text you submit is sent to Google Vertex AI, which currently serves these models from a global endpoint, so processing may take place outside the EU. Google acts as our processor for these calls; under the Google Cloud terms the content is not used to train Google’s models.
Every AI suggestion is shown to you for confirmation before anything is saved. The AI never writes to your data on its own.
9. Who else touches your data
| Provider | What for | Where |
|---|---|---|
| Google Firebase — Authentication, Firestore, Cloud Storage, Cloud Functions, Cloud Messaging, App Check, Remote Config | Accounts, database, files, server logic, push notifications, abuse prevention | Firestore, Storage and server functions in Google’s europe-west3 region (Frankfurt, Germany) |
| Google Crashlytics, Google Analytics for Firebase, Firebase Performance Monitoring | Crash reports, which screens are used, app speed | |
| Google Vertex AI (Gemini) | Turning text into draft gigs, tasks and contacts | Global endpoint |
| Google Calendar API | Calendar sync, if you enable it | |
| Google Places API | Venue address autocomplete | |
| Cloudflare — Email Routing, Workers | Receiving forwarded emails and passing them to Gigmo, if you enable email import | Cloudflare’s global network; in transit only, nothing is stored there |
That is the complete list. We do not sell personal data, we do not share it with advertisers or data brokers, and the app contains no advertising or tracking SDKs. Transfers outside the EU rely on the European Commission’s Standard Contractual Clauses as incorporated into each provider’s terms.
10. Why we are allowed to do this
- Performance of a contract (Art. 6(1)(b) GDPR) — your account, gigs, tasks, contacts and files. Without them the app does nothing.
- Your consent (Art. 6(1)(a)) — Google Calendar sync, email import, device permissions and optional notifications. Withdraw it at any time in the app; withdrawal does not undo processing that already happened.
- Legitimate interests (Art. 6(1)(f)) — crash reports, aggregate usage statistics and abuse prevention, so the app can be kept working and secure.
11. How long we keep things
- Your account data — until you delete your account.
- Imported emails — 30 days from arrival, automatically.
- Temporary contacts — archived automatically once their gig is long past.
- Crash and analytics data — kept by Google under Firebase’s own retention settings, and not tied to your gigs or contacts.
- Server logs — retained by Google Cloud Logging for 30 days by default.
12. Your rights
Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict or object to its processing, or hand it to another service in a portable form. Write to privacy@gigmo.ai; we answer within one month.
You also have the right to complain to a supervisory authority. In Germany that is the data protection authority of the federal state where you live.
13. Deleting your account
You can delete your account from inside the app, under Settings → Account → Delete account, or request deletion from the web at gigmo.ai/delete-account, which also lists precisely what is erased. Deletion is a server‑side cascade: your gigs, tasks, contacts, files, imported emails, forwarding address, notification tokens and calendar grant all go with the account, and the calendar token is revoked with Google.
14. Security
Data is encrypted in transit and at rest by Google Cloud. Access is enforced by Firebase Security Rules that check the requesting account on every read and write, so one user cannot reach another user’s data. Firebase App Check is enforced, so requests from anything other than a genuine Gigmo installation are rejected.
15. Children
Gigmo is not directed at children and is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has created an account, write to us and we will delete it.
16. Changes to this policy
If this policy changes in a way that matters, we will raise the version number at the top of this page and tell you in the app before the change takes effect. Older versions are available on request.