Plain-language policy
Privacy at Geertje
Effective 28 July 2026
Geertje is an iPhone sticker creator with an optional personal WhatsApp linked-device inbox. Linking is controlled by Geertje's server and may be paused or unavailable. You can create stickers without linking WhatsApp.
What leaves your iPhone
When you tap Make, Geertje sends the photos you selected, the style and creative direction you reviewed, a random installation identifier, and a request identifier to Geertje's generation service. Photos you do not select are not sent by Geertje.
If you choose Google Photos, Google handles sign-in and photo selection. Google Sign-In may process account and device information described in the App Store privacy label, while Geertje uses the resulting credential only to operate the picker. You can choose Disconnect Google Photos in Geertje Settings to revoke every Google OAuth scope granted to Geertje and clear the local Google session.
How generation works
Requests pass through Geertje services hosted on Cloudflare. The image-generation request is processed by Google Gemini; OpenAI may be used as a fallback when Gemini is unavailable. Generated results are returned to the app and held in Cloudflare R2 so an interrupted request can be recovered. Production is configured to attempt hourly deletion after results become 48 hours old. A scheduled production deletion has not yet been independently observed, so Geertje does not currently promise deletion by a specific hour.
Optional linked WhatsApp inbox
If the server reports that linked access is available and you choose Connect WhatsApp, Geertje uses WhatsApp's Linked Devices flow. Geertje does not ask for your WhatsApp password. Pairing alone grants access to no chats: you must then choose All or search and select existing conversations before Geertje may retain or use them.
To begin pairing, you enter your WhatsApp phone number in Geertje. The app sends it to the linked service, which stores the raw number in tenant and link-state records for pairing and reconnection until you unlink WhatsApp or delete the cloud account. After WhatsApp verifies the device, the service also receives WhatsApp JID/LID identity values. Secret-key HMAC aliases are used for canonical lookup and anti-abuse evidence, but not every operational linking field is HMAC-only.
For the scope you save, Geertje may process chat titles and identifiers, participant display information, message and reaction bodies, reply references, timestamps, unread state, and opaque references to supported media. This lets the app show the linked inbox, send text or an already-captured sticker, reconcile unread state, and respond to /geertje in allowed conversations.
The linked service tenant-encrypts stored inbox message/reaction payloads, reply payloads, and proposal sticker files. Its tenant-isolated SQLite control tables are not encrypted as a whole: they can contain the raw pairing phone number, verified JID/LID values, scoped chat identifiers, and operational proposal fields such as chat/requester identifiers, display names, and the sticker instruction until unlink or account deletion. It does not eagerly retain raw photo, video, audio, or document bodies. View-once and ephemeral message bodies are excluded from analysis and retained only as contentless unsupported envelopes. A recently observed, non-view-once sticker may remain briefly in the live linked process so you can resend it; after restart or eviction that send fails instead of retaining an unrestricted file or URL.
Geertje shows the linked device's best available snapshot, not a complete WhatsApp archive. Messages from before linking or before you save scope may be absent, and WhatsApp may not offer all earlier history to a linked device. Read and send operations outside your saved scope fail closed. Changing scope erases the prior encrypted inbox snapshot before the new scope begins.
WhatsApp and Meta operate WhatsApp under their own terms and retention practices. Geertje is independent and is not affiliated with, endorsed by, or sponsored by WhatsApp or Meta.
Who controls your data
Geertje is operated by Alberto Becerra under the business name Bonbon Creative Arts, Anna van Burenstraat 13h, 1055 VL Amsterdam, Netherlands. Alberto Becerra, operating as Bonbon Creative Arts, is the data controller for the generation account, linked-inbox service, app analytics, support requests, and other processing described here. Apple, Google, Meta/WhatsApp, Cloudflare, OpenAI, and PostHog may also act as independent controllers for parts of their own services under their terms. Contact the Geertje controller at privacy@geertje.app.
Why Geertje may process data
- Contract: to create, recover, save, and account for stickers and credits you request.
- Legitimate interests: to keep the service secure and reliable, prevent fraud and duplicate credit grants, and understand coarse session-level performance without building advertising profiles.
- Legal obligations: to keep records required for tax, accounting, consumer-protection, or law-enforcement obligations.
- Your choice or permission: iOS notification and photo permissions, and the optional Google Photos authorization, remain under the controls supplied by Apple and Google. You can withdraw them without affecting earlier lawful processing.
Account and purchase records
Geertje creates a pseudonymous generation account after you accept the in-app privacy notice. The service stores a hashed installation alias, account identifier, credit balance, generation accounting events, and Apple-signed purchase evidence. It never receives your payment-card details.
Purchase and minimal anti-fraud records are retained as needed to prevent a transaction being granted twice, preserve ledger integrity, and meet financial or legal obligations. Raw App Store signed data is stored only as a cryptographic hash.
If Geertje's official WhatsApp trial is later enabled, the service retains irreversible trial receipts and secret-key HMAC aliases after account deletion so the same WhatsApp identity or merged canonical account cannot receive a second one-time trial. Operational deletion tombstones also block delayed queues, in-flight linking, or retries from recreating deleted bot data or sending after deletion. They contain account identifiers and keyed HMAC values, not raw phone numbers or message bodies. No fixed automatic deletion period is currently promised for this anti-abuse evidence; it remains while necessary to enforce the one-time benefit, prevent recreation after deletion, protect ledger integrity, or meet a legal claim. The official bot and trial are disabled unless the server explicitly enables them.
Analytics
Geertje sends limited product-interaction, latency, and failure-category events to PostHog's EU service. Events use a new random identifier each app session. They do not include photos, prompts, sticker images, names, email addresses, chat content, or advertising identifiers. Geertje does not use this data for tracking or advertising.
How long data is kept
- Recoverable generated results are covered by a configured hourly cleanup after becoming 48 hours old. A scheduled production deletion has not yet been independently observed, so no deletion-by-a-specific-hour promise is currently made.
- Generation operations, balances, and the pseudonymous account remain while the cloud account is active and are removed or de-identified as described below when you delete it.
- Linked-inbox content remains while your linked account and saved scope remain active, subject to storage caps and deletion when you change scope, unlink, or delete the account. The code includes a 90-day and 10,000-message retention control, but its production schedule has not yet been externally verified, so Geertje does not currently promise automatic age-based deletion on a particular day.
- Linked notification receipts, completed delivery history, and unread-event records are designed to be pruned after 30 days. This operational schedule must be verified in the production release environment before launch.
- Session-scoped PostHog EU analytics may be retained for up to 84 months under the current PostHog EU project plan. Geertje uses a new random identifier each app session and excludes photos, prompts, sticker images, names, email addresses, chat content, and advertising identifiers.
- Support correspondence is retained only while it is needed to answer the request, protect the service, handle a dispute, or meet a legal obligation. Geertje does not currently promise an automatic 24-month mailbox deletion schedule.
- Minimal purchase and accounting evidence is kept for the period required by Dutch tax and accounting rules, normally seven years. A transaction fingerprint may be kept longer where necessary to prevent the same consumable purchase being granted twice or to establish, exercise, or defend a legal claim.
- Keyed-HMAC one-time-trial and anti-recreation evidence may remain after deletion without a fixed automatic expiry, as described above. Re-consenting can clear an operational account tombstone, but it does not reset an irreversible trial receipt.
- Locally saved stickers remain until you delete the local library or remove the app. Google OAuth credentials remain in Google's Sign-In storage until you disconnect, sign out locally, revoke access in Google, or remove the app's stored data.
Notifications
Notification permission is optional and is not used for advertising. Geertje can schedule a local completion alert after usable stickers are ready.
After you connect a canonical linked inbox, Geertje may also register this installation with Apple Push Notification service (APNs). The linked push payload contains only an opaque one-time receipt and an opaque binding epoch. It does not contain a WhatsApp chat or message ID, account ID, name, message text, status, or route. The app uses the current linked credential to resolve the destination and authoritative unread count. APNs is an acceleration channel: opening or foregrounding the app reconciles durable server state when a push is missed or delayed. Scope changes, relinking, unlinking, and account deletion invalidate earlier routes and registrations.
Remote notification delivery depends on Apple, the linked service, a valid device token, and the server-controlled availability state. The production sandbox and TestFlight delivery matrix must pass before Geertje claims this feature is generally available.
What stays local
Stickers you save in Geertje's library remain on your iPhone until you delete them in Settings or remove the app. Your original photos remain governed by Apple Photos or Google Photos.
Your choices and deletion
- Use Apple Photos' permission controls to change which photos Geertje can access.
- Disconnect Google Photos in Geertje Settings to revoke Geertje's Google OAuth grant and clear its local Google session. You can also revoke access in your Google Account.
- Delete all locally saved stickers in Geertje Settings.
- Change linked-inbox scope. Saving a new scope erases the prior encrypted inbox snapshot before capture begins under the new choice.
- Unlink WhatsApp in Geertje Settings. Local read access ends immediately. Geertje uses a deletion-only credential to erase the server tenant, linked authentication state, encryption key, inbox content, notification registrations/receipts, unread state, and pending deliveries. If the server is temporarily unreachable, the app retains only that deletion capability and retries on launch or foreground. You can also revoke Geertje from WhatsApp's Linked Devices screen.
- Delete your cloud generation account in Geertje Settings. This revokes credentials, coordinates deletion of any linked inbox and official-bot binding, deletes generated cloud results and generation operations, removes installation aliases, and removes unused credits.
After cloud account deletion, minimal pseudonymous App Store transaction/accounting evidence and the keyed-HMAC anti-abuse evidence described above may remain to prevent duplicate grants, a second one-time trial, or data recreation after deletion. A later reinstall can create or reactivate an account, but the deleted free allowance and unused consumable credits are not restored.
Your European privacy rights
Depending on the law that applies, you can ask to access, correct, delete, restrict, or receive a portable copy of your personal data. You can object to processing based on legitimate interests and withdraw a permission or consent for future processing. These rights can have legal exceptions, including records Geertje must retain.
Email privacy@geertje.app from a context that lets Geertje safely verify the relevant account. Geertje will respond without undue delay and normally within one month. You may also complain to your local supervisory authority; in the Netherlands this is the Autoriteit Persoonsgegevens.
Processors
Geertje uses Cloudflare for edge processing and temporary result storage, Google Gemini and potentially OpenAI for image generation, PostHog EU for limited analytics, Apple for App Store purchases, APNs, and system services, Google only when you choose Google Photos, and WhatsApp/Meta when you choose the linked-device or official-bot features.
Security and transfers
Network traffic uses encrypted HTTPS connections. Providers may process data in countries outside yours under their applicable safeguards and terms. No internet service can promise absolute security, so Geertje minimizes what it sends and how long generated results remain recoverable.
Children
Geertje is not directed to children under 13. Do not use the service to submit content you do not have permission to use.
Contact
Questions or privacy requests: privacy@geertje.app. Support: support@geertje.app. Do not email private photos, access tokens, credentials, or full App Store receipts.