GGeertje

Plain-language policy

Privacy at Geertje

Effective 28 July 2026

Geertje is an iPhone sticker creator with an optional personal WhatsApp linked-device inbox. Linking is controlled by Geertje's server and may be paused or unavailable. You can create stickers without linking WhatsApp.

What leaves your iPhone

When you tap Make, Geertje sends the photos you selected, the style and creative direction you reviewed, a random installation identifier, and a request identifier to Geertje's generation service. Photos you do not select are not sent by Geertje.

If you choose Google Photos, Google handles sign-in and photo selection. Google Sign-In may process account and device information described in the App Store privacy label, while Geertje uses the resulting credential only to operate the picker. You can choose Disconnect Google Photos in Geertje Settings to revoke every Google OAuth scope granted to Geertje and clear the local Google session.

How generation works

Requests pass through Geertje services hosted on Cloudflare. The image-generation request is processed by Google Gemini; OpenAI may be used as a fallback when Gemini is unavailable. Generated results are returned to the app and held in Cloudflare R2 so an interrupted request can be recovered. Production is configured to attempt hourly deletion after results become 48 hours old. A scheduled production deletion has not yet been independently observed, so Geertje does not currently promise deletion by a specific hour.

Optional linked WhatsApp inbox

If the server reports that linked access is available and you choose Connect WhatsApp, Geertje uses WhatsApp's Linked Devices flow. Geertje does not ask for your WhatsApp password. Pairing alone grants access to no chats: you must then choose All or search and select existing conversations before Geertje may retain or use them.

To begin pairing, you enter your WhatsApp phone number in Geertje. The app sends it to the linked service, which stores the raw number in tenant and link-state records for pairing and reconnection until you unlink WhatsApp or delete the cloud account. After WhatsApp verifies the device, the service also receives WhatsApp JID/LID identity values. Secret-key HMAC aliases are used for canonical lookup and anti-abuse evidence, but not every operational linking field is HMAC-only.

For the scope you save, Geertje may process chat titles and identifiers, participant display information, message and reaction bodies, reply references, timestamps, unread state, and opaque references to supported media. This lets the app show the linked inbox, send text or an already-captured sticker, reconcile unread state, and respond to /geertje in allowed conversations.

The linked service tenant-encrypts stored inbox message/reaction payloads, reply payloads, and proposal sticker files. Its tenant-isolated SQLite control tables are not encrypted as a whole: they can contain the raw pairing phone number, verified JID/LID values, scoped chat identifiers, and operational proposal fields such as chat/requester identifiers, display names, and the sticker instruction until unlink or account deletion. It does not eagerly retain raw photo, video, audio, or document bodies. View-once and ephemeral message bodies are excluded from analysis and retained only as contentless unsupported envelopes. A recently observed, non-view-once sticker may remain briefly in the live linked process so you can resend it; after restart or eviction that send fails instead of retaining an unrestricted file or URL.

Geertje shows the linked device's best available snapshot, not a complete WhatsApp archive. Messages from before linking or before you save scope may be absent, and WhatsApp may not offer all earlier history to a linked device. Read and send operations outside your saved scope fail closed. Changing scope erases the prior encrypted inbox snapshot before the new scope begins.

WhatsApp and Meta operate WhatsApp under their own terms and retention practices. Geertje is independent and is not affiliated with, endorsed by, or sponsored by WhatsApp or Meta.

Who controls your data

Geertje is operated by Alberto Becerra under the business name Bonbon Creative Arts, Anna van Burenstraat 13h, 1055 VL Amsterdam, Netherlands. Alberto Becerra, operating as Bonbon Creative Arts, is the data controller for the generation account, linked-inbox service, app analytics, support requests, and other processing described here. Apple, Google, Meta/WhatsApp, Cloudflare, OpenAI, and PostHog may also act as independent controllers for parts of their own services under their terms. Contact the Geertje controller at privacy@geertje.app.

Why Geertje may process data

Account and purchase records

Geertje creates a pseudonymous generation account after you accept the in-app privacy notice. The service stores a hashed installation alias, account identifier, credit balance, generation accounting events, and Apple-signed purchase evidence. It never receives your payment-card details.

Purchase and minimal anti-fraud records are retained as needed to prevent a transaction being granted twice, preserve ledger integrity, and meet financial or legal obligations. Raw App Store signed data is stored only as a cryptographic hash.

If Geertje's official WhatsApp trial is later enabled, the service retains irreversible trial receipts and secret-key HMAC aliases after account deletion so the same WhatsApp identity or merged canonical account cannot receive a second one-time trial. Operational deletion tombstones also block delayed queues, in-flight linking, or retries from recreating deleted bot data or sending after deletion. They contain account identifiers and keyed HMAC values, not raw phone numbers or message bodies. No fixed automatic deletion period is currently promised for this anti-abuse evidence; it remains while necessary to enforce the one-time benefit, prevent recreation after deletion, protect ledger integrity, or meet a legal claim. The official bot and trial are disabled unless the server explicitly enables them.

Analytics

Geertje sends limited product-interaction, latency, and failure-category events to PostHog's EU service. Events use a new random identifier each app session. They do not include photos, prompts, sticker images, names, email addresses, chat content, or advertising identifiers. Geertje does not use this data for tracking or advertising.

How long data is kept

Notifications

Notification permission is optional and is not used for advertising. Geertje can schedule a local completion alert after usable stickers are ready.

After you connect a canonical linked inbox, Geertje may also register this installation with Apple Push Notification service (APNs). The linked push payload contains only an opaque one-time receipt and an opaque binding epoch. It does not contain a WhatsApp chat or message ID, account ID, name, message text, status, or route. The app uses the current linked credential to resolve the destination and authoritative unread count. APNs is an acceleration channel: opening or foregrounding the app reconciles durable server state when a push is missed or delayed. Scope changes, relinking, unlinking, and account deletion invalidate earlier routes and registrations.

Remote notification delivery depends on Apple, the linked service, a valid device token, and the server-controlled availability state. The production sandbox and TestFlight delivery matrix must pass before Geertje claims this feature is generally available.

What stays local

Stickers you save in Geertje's library remain on your iPhone until you delete them in Settings or remove the app. Your original photos remain governed by Apple Photos or Google Photos.

Your choices and deletion

After cloud account deletion, minimal pseudonymous App Store transaction/accounting evidence and the keyed-HMAC anti-abuse evidence described above may remain to prevent duplicate grants, a second one-time trial, or data recreation after deletion. A later reinstall can create or reactivate an account, but the deleted free allowance and unused consumable credits are not restored.

Your European privacy rights

Depending on the law that applies, you can ask to access, correct, delete, restrict, or receive a portable copy of your personal data. You can object to processing based on legitimate interests and withdraw a permission or consent for future processing. These rights can have legal exceptions, including records Geertje must retain.

Email privacy@geertje.app from a context that lets Geertje safely verify the relevant account. Geertje will respond without undue delay and normally within one month. You may also complain to your local supervisory authority; in the Netherlands this is the Autoriteit Persoonsgegevens.

Processors

Geertje uses Cloudflare for edge processing and temporary result storage, Google Gemini and potentially OpenAI for image generation, PostHog EU for limited analytics, Apple for App Store purchases, APNs, and system services, Google only when you choose Google Photos, and WhatsApp/Meta when you choose the linked-device or official-bot features.

Security and transfers

Network traffic uses encrypted HTTPS connections. Providers may process data in countries outside yours under their applicable safeguards and terms. No internet service can promise absolute security, so Geertje minimizes what it sends and how long generated results remain recoverable.

Children

Geertje is not directed to children under 13. Do not use the service to submit content you do not have permission to use.

Contact

Questions or privacy requests: privacy@geertje.app. Support: support@geertje.app. Do not email private photos, access tokens, credentials, or full App Store receipts.