Privacy Notice
This notice explains what personal data GearManifest ("the Service") collects, why, and what rights you have. It applies to everyone who creates a GearManifest account.
1. Who is responsible for your data (the "controller")
GearManifest is operated by Simo Parviainen, as a private individual based in Finland — GearManifest is not currently operated through a registered business (no toiminimi, no Y-tunnus / Business ID). For data protection purposes, Simo Parviainen is the GDPR data controller for GearManifest.
- Name: Simo Parviainen
- Operating as: a private individual in Finland (no registered business / Y-tunnus)
- Contact for privacy questions and data-rights requests: Hi@polkuopas.fi
This email address is the controller's designated contact point for all privacy questions, data-subject-rights requests, and complaints under this notice.
2. What data we collect
We collect only what the product needs to work. Specifically:
Account data
- Your email address, used to send you a magic-link sign-in email. We do not use passwords.
- Display name (optional, set in Settings).
- Your preferred weight unit (g/kg/oz/lb) and preferred currency — display preferences only, stored so the app remembers your choice.
- Two fields (
bio,location) exist in our database schema as stubs for a possible future profile feature. They are not currently exposed anywhere in the product and, if unused, hold no data about you.
Gear and build data
This is the core content you create in GearManifest:
- Gear items — the things in your inventory: name, brand, model, weight, price, your own notes, category, condition, and (if you used the AI lookup) a confidence marker showing whether a field came from you or from an AI estimate.
- Wishlist items — gear you've marked as "wished" rather than owned.
These are stored as regular gear items with a
wishedstatus; we're calling this out explicitly so it's clear wishlist entries are not silently treated as something other than your inventory data. - Builds — named loadouts you create (e.g. "3-day summer trip"), including trip context you choose to record: trip type, season, group size, duration, and free-text notes.
- Build items — which gear items belong to which build, and per-build overrides (e.g. whether an item is worn vs. packed, or a consumable) for that specific build.
AI SKU-lookup inputs
When you use the "look up specs" feature on a gear item, GearManifest sends the product name and model you typed — plus, only if you started the lookup from a specific gear category or item type, a closed-vocabulary hint naming that category/item type from our fixed lists — to Google's Gemini API to fetch likely specifications (weight, etc.). This request is made from our server, not your browser, and does not include your email, account ID, free-text notes, or any other information that identifies you. Google processes this as a short-lived API request; see "Processors," below.
What we do not collect
We do not collect payment information (GearManifest has no paid tier in its current version), government ID numbers, precise device location, or biometric data.
3. Why we process your data (lawful basis)
- Account, gear, and build data — processed under Art. 6(1)(b) GDPR (necessity for performance of a contract): this data is what lets us provide the inventory and build-planning service you signed up for. We don't have a separate consent flow for this because the processing is the product.
- AI SKU-lookup data — the same basis (Art. 6(1)(b)): looking up specs is a feature you actively trigger, and only the minimum data (product name/model) needed to answer your request is sent.
- Product analytics (PostHog) — GearManifest currently runs PostHog
configured to store no persistent identifier on your device: no
cookies, no
localStorage, memory-only session state, noidentify()calls linking events to your account, and autocapture turned off. Because nothing is stored on or read from your device, this configuration falls outside the scope of ePrivacy Directive Art. 5(3) (which governs storage of/access to information on a user's device) — which is why you will not see a cookie-consent banner for analytics. To the extent this minimal, non-persistent processing touches personal data at all (e.g. transient, session-scoped event data), we rely on our legitimate interest (Art. 6(1)(f) GDPR) in understanding aggregate, non-identifying product usage to improve GearManifest, weighed against the low impact on you given the cookieless, non-identifying configuration. If PostHog's configuration ever changes to use persistent identifiers, cookies, or account-linked tracking, we will introduce a proper consent mechanism before making that change, and this notice will be updated. - We do not rely on a vague "legitimate interest" basis for your core account, gear, or build data — that data has a specific contractual basis as described above.
We may also produce and license aggregated, anonymized, non-identifying statistics about gear trends — for example, which categories or types of gear are commonly owned or wished for — to industry partners. These statistics are always about many users in aggregate; they never include, and are not derivable back to, any individual's inventory, username, email address, or any other identifier. We will never sell or license your individual inventory, your identity, or anything that could single you out.
4. Who else processes your data (our processors)
We use the following service providers ("processors") to run GearManifest. Formal Data Processing Agreements (Art. 28 GDPR) are not yet in place with every processor listed below. We will update this notice once they are, and we will not claim signed agreements exist until they do.
| Processor | Role | Data involved | Region |
|---|---|---|---|
| Supabase | Database, authentication, and file storage | Account data, gear/build data, session tokens | EU (Frankfurt, eu-central-1) |
| Vercel | Application hosting | All data in transit to/from the app | EU hosting region (Vercel's EU infrastructure) |
| Google (Gemini API) | AI processing for the SKU-lookup feature | Product name and model, plus — only if you started from one — a closed-vocabulary category/item-type hint from our fixed lists. No free text, no account or personal identifiers | See note below — the contracting Google entity for this feature is, as best we can currently establish, EU-based (Ireland), not US-based |
| PostHog | Product analytics | Minimal, non-persistent, cookieless event data (see Section 3) | EU Cloud (eu.i.posthog.com) |
| Brevo | Sending sign-in (magic-link) and account emails | Your email address, email content | Brevo is EU-headquartered (France). Brevo's specific data-residency/storage-region setting for our account has not yet been confirmed — pending verification |
On Google (Gemini API) and international transfer: GearManifest's
SKU-lookup feature calls the Gemini API through the founder's Google Cloud
Billing account, which makes this a Paid Service under Google's terms
(an active Cloud Billing account is required for Gemini API access to count
as "paid" — see docs/adr/0005-sku-lookup-provider-and-ai-as-reviewed-suggestion.md).
That distinction matters for two separate reasons:
- Which Google entity we're dealing with. Google's Gemini API Additional Terms of Service state that, for Paid Services, "Google" means the entity identified in Google's Cloud contracting-entity terms based on the customer's billing address. That page lists, for a billing address in the "EMEA" region other than France, Italy, or Poland — which covers Finland, where this account is billed from — the contracting entity as Google Cloud EMEA Limited, an Irish company (70 Sir John Rogerson's Quay, Dublin 2, Ireland). That is a different, EU-based Google affiliate from both Google LLC (the US parent company) and Google Ireland Limited (a separate Google affiliate that Google's own general Terms of Service name as the provider of Google's consumer services in the EU — not the entity its Gemini API contracting-entity terms name for this feature). If the billing address on that Cloud Billing account ever changes to outside that region, this determination — and everything below it — would need to be revisited. Sources: Gemini API Additional Terms of Service (effective March 23, 2026) and the Google Contracting Entity terms it points to for Paid Services, plus (for the Google Ireland Limited distinction) Google's general Terms of Service — all read 2026-09-21.
- How the data is used. For Paid Services, Google's terms state that Google does not use our prompts or responses to improve its own products, and processes them under its Data Processing Addendum for Products Where Google is a Data Processor rather than under the looser terms that apply to Google's free/unpaid API tier.
Because the contracting entity's own address is inside the EEA, sending the product name and model (and, where applicable, a category/item-type hint) to it is not, on the face of it, a transfer of your personal data out of the EEA in the way it would be to a US-headquartered provider. We are stating this plainly rather than more strongly, for two reasons we'd rather name than gloss over: first, Google's own terms note that even for Paid Services it may log prompts and responses for a limited time for abuse-prevention purposes, and that this data "may be stored transiently or cached in any country in which Google or its agents maintain facilities" — so we cannot claim processing never touches infrastructure outside the EEA, only that the contracting entity does not. Second, as with the other processors on this page, no formal DPA has yet been separately accepted for this feature (Section 4's opening note applies here too; see also GM-053's open gap, flagged in that ticket's own log). As always, please don't put personal information into the free-text fields you send to the lookup feature.
5. How long we keep your data
- While your account is active, we keep your data for as long as you keep your account — there's no automatic expiry on an active account.
- If you delete your account, your data is fully and permanently removed from our active systems within 30 days. We also keep daily database backups for disaster recovery; a backup still holding your data is deleted automatically within 7 days, so nothing remains restorable after that — well inside the 30-day figure above. (Point-in-time recovery is a separate feature and is not enabled.)
6. Your rights and how to exercise them
Under GDPR you have the right to access, correct, export, delete, restrict, and object to our processing of your data, and the right to withdraw any consent you've given. In practice:
- Export your data: self-service export (JSON or CSV) from your account settings, available now. If you would rather we did it for you, email Hi@polkuopas.fi.
- Delete your account and data: self-service account deletion from your account settings, available now. It triggers the 30-day full purge described above. If you would rather we did it for you, email Hi@polkuopas.fi.
- Anything else (access, correction, restriction, objection): email Hi@polkuopas.fi. We will respond within one month of your request, as required by GDPR; in complex cases we may extend this by a further two months, and we'll tell you if we do.
7. Complaints
If you believe we've mishandled your data, we'd like the chance to fix it — email Hi@polkuopas.fi first. You also have the right to lodge a complaint directly with Finland's data protection authority:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) https://tietosuoja.fi/en/home
8. Cookies and similar technologies
The cookie that keeps you signed in
GearManifest uses one essential cookie: the Supabase authentication session cookie, which keeps you signed in. This is strictly necessary for the Service to function and is exempt from consent requirements under ePrivacy Art. 5(3).
We do not use any non-essential cookies. Our analytics (PostHog) is configured to be cookieless and store nothing on your device — see Section 3 for the full explanation of why no cookie-consent banner is shown. This is a deliberate, documented configuration choice, not an oversight.
Settings we save in your browser
Cookies are not the only way a site can keep something on your device.
GearManifest saves two kinds of setting in your browser's own storage
(localStorage). One of the two is saved per build, so if you look in that
storage you may find more than two entries. Each one does nothing but
remember a choice you made in the app. Neither identifies you, neither is
read by our analytics, and neither is ever sent to us or to anyone else.
| What it remembers | Key name in your browser | How long it stays |
|---|---|---|
| Your light or dark theme choice, so the app opens in the mode you picked — on every page, including the public ones, and while you are signed out | gearmanifest-theme, holding the single word light or dark | Until you clear this site's data in your browser. There is no expiry date |
| That you closed the suggestion panel on one of your builds, so it stays closed for that build | gearmanifest:build-suggestions-dismissed:<build id> — one key per build you close it on, with that build's own id in the key name | Until you clear this site's data in your browser. There is no expiry date |
You set the theme in Settings, under Appearance. You close a suggestion panel with the "Dismiss suggestions" button on the build itself.
Signing out removes neither of them, because neither is tied to your account — they belong to the browser. To remove them, clear this site's data in your browser's own settings. The app then goes back to its defaults, which are the light theme and the suggestion panel shown. Clearing them does not affect your account or your gear.
We do not ask for your consent before saving these, because each one does nothing except carry out a choice you made in the app. Under ePrivacy Art. 5(3) that holds only if we tell you the choice is kept, which is what this section does. If we ever save anything else on your device, it will be listed here.
Trying GearManifest before you sign up
If you build a gear list on the /trial page without an account, that list
is saved only in your browser's own storage (localStorage), under the key
gearmanifest:trial:v1. It holds the items you add there — name, brand,
category, weight, and your worn/consumable/quantity choices — and one
randomly generated id used only to avoid saving the same list twice if you
create an account afterwards. It contains no name, email address, or
anything else that identifies you, and it is a different kind of storage
from the two preference entries above, so it gets its own line here rather
than being folded into that table.
This is strictly necessary for a service you explicitly asked for — building and seeing a gear list before creating an account — so it is exempt from consent requirements under ePrivacy Art. 5(3), on that specific footing, stated here rather than assumed to carry over from the essential cookie or the settings above.
Nothing in it is sent to us, or to anyone else, unless and until you choose to create a free account, at which point it is saved to your new account and cleared from your browser. The trial page also has its own "Clear this list" button, which removes it immediately, at any time, whether or not you go on to create an account. Clearing this site's data in your browser removes it too.
Returning you to what you were doing, after you sign in
If you follow a link that requires signing in first — for example, a crew
invite link — GearManifest briefly remembers, in your browser's own storage
(sessionStorage, under the key gm-signin-next), the page it should return
you to once you've signed in, so you land back on that page instead of the
general dashboard. It holds nothing but that one page path — no name, email
address, invite token, or anything else that identifies you or what the link
was for.
This is strictly necessary for the sign-in flow you asked to complete, so it
is exempt from consent requirements under ePrivacy Art. 5(3) on that footing.
Unlike the settings above, sessionStorage clears itself automatically when
you close that browser tab — GearManifest does not need to do anything
further to remove it, and it is never sent to us or to anyone else.
8a. Sharing with a Crew
If you join or create a Crew, other active members of that Crew can see: your display name, and — only for the specific gear items you choose to share — that item's name, category, and weight, and who is currently carrying it. They cannot see your price, your notes, or any item you haven't shared.
Crew invites are link-only: we never collect or store an invitee's email address to send an invite.
Sharing an item is something you actively choose, item by item, from your own inventory — it is not on by default.
If you leave a Crew, or are removed from one, the items you shared stop being visible to that Crew immediately; your own inventory and builds are never affected. If you leave voluntarily, a fresh invite link can bring you back into the same Crew later. If you are removed by the Crew's creator, that is final for that Crew — no invite link, old or new, will let you back in.
Deleting your GearManifest account (Section 5) removes your own Crew memberships and anything you shared, in the same purge. If you created a Crew, deleting your account also deletes that Crew entirely — including every other member's membership in it and everything they shared into it. There is currently no way to transfer a Crew to someone else first, so creating one means your account is the one whose deletion ends it for everyone in it.
Your data export (Section 6) contains your own gear and builds only — it does not include items other Crew members have shared with you.
9. Changes to this notice
We'll update this notice as the product changes. Material changes will be reflected here, with the "last updated" date above changed to match.