Privacy Policy
Last updated 14 August 2026.
This policy covers https://zyggy.app — the Zyggy waitlist. It does not yet cover the Zyggy mobile app, which is not released. When the app launches, a fuller policy will cover the data it needs, and we will email you before that happens. See When the app launches.
Zyggy is run by Honk Labs S.R.L (CUI: RO50924164), a company registered in Romania. We are the data controller for everything described here. You can reach us at contact@zyggy.app.
The short version
We ask for your email address so we can tell you when Zyggy opens. We send you one email to confirm it's really you, and after that, almost nothing until launch. We don't sell your address, we don't share it for anyone else's marketing, and you can have it deleted at any time by clicking one link.
Everything below is the same thing said precisely.
What we collect, and why
When you join the waitlist
| What | Why | Kept |
|---|---|---|
| Your email address | To send the confirmation, and to tell you when Zyggy opens | Until you unsubscribe or ask us to delete it |
| The time you signed up, and the exact consent wording shown to you | To prove your consent was freely given and informed, which the law requires us to be able to do | As above |
| Which page or link brought you here (source, UTM parameters, referrer) | To learn which of our posts actually work | As above |
| Your country | To decide which cities to open in first — Zyggy is a proximity app and is useless in a city with eleven people in it | As above |
Collected automatically, and immediately made unreadable
| What | Why | Kept |
|---|---|---|
| Your IP address | To stop one person or bot signing up thousands of times | Never stored as-is. It is put through a keyed one-way hash the moment it arrives, and the result is deleted after 30 days |
| Your browser's user-agent string | Same | Same treatment, same 30 days |
We want to be exact about this, because "we hash your IP" is often said and rarely means much: a plain hash of an IP address is not anonymous, because there are only about four billion of them and they can all be tried in minutes. We use a keyed hash (HMAC-SHA256) with a secret that is never stored alongside the data, so the result cannot be worked backwards even by someone who steals the whole database.
What we do not collect
No cookies for advertising or tracking. No third-party advertising pixels. No location. No birth data — that comes later, in the app, and only if you choose to use it. We do not buy email lists and we do not append data about you from other sources.
Why we're allowed to (legal basis)
- Your email address, and sending you email: your consent (GDPR Article 6(1)(a)). You give it by entering your address and clicking the button, and you confirm it by clicking the link in the email we send. We keep a record of the exact wording you were shown. You can withdraw it at any time, and withdrawing it is as easy as giving it — one click, no login, no questions.
- The hashed IP and user-agent: our legitimate interests (Article 6(1)(f)) in keeping the form from being abused. We considered the effect on you and concluded it was minimal, because the data is unreadable on arrival and gone within a month.
- Country: legitimate interests, for the same reason, at country level only. We do not know or store your city, and we never store your location.
Double opt-in, and why you get that email
You will not receive anything from us until you click the link in the confirmation email. If you never click it, we delete the record within 30 days.
This is partly the law and partly self-interest: it means nobody can add your address to our list but you, and it means that when we finally send the one email that matters, it arrives rather than landing in spam.
Who else touches your data
We use a small number of companies to run the service. They act on our instructions only, under contract, and none of them may use your data for their own purposes.
| Who | What they do | Where |
|---|---|---|
| Resend | Delivers our email | US / EU |
| Northflank | Runs our servers and database | EU |
| Cloudflare | Protects the form from bots (Turnstile), and serves the site | Global |
| Plausible Analytics | Counts page visits, without cookies and without tracking individuals across sites | EU |
Where any of these involves your data leaving the EEA, it is covered by Standard Contractual Clauses or an equivalent safeguard. We will name the specific mechanism on request.
We never sell your data, and we never share it for anyone else's marketing. If Zyggy is ever acquired, your data may transfer to the buyer — we will email you before that happens, and you will be able to delete your record first.
How long we keep things
- Unconfirmed signups: 90 days, then deleted automatically. No confirmation means no consent, so we have no business keeping it for long.
- Confirmed signups: until you unsubscribe or ask us to delete it, or until the waitlist has served its purpose and we retire it. There is no fixed limit, because we don't yet know the date Zyggy opens — see below.
- Hashed IP and user-agent: 30 days, then deleted automatically.
- Unsubscribes: we keep a record that you unsubscribed. It is the only reliable way to guarantee we don't email you again, and it's the minimum needed to do that.
If it takes us a long time
Building Zyggy properly may take longer than we'd like, and we would rather say so than quietly sit on your address.
So: if a year passes without us contacting you, we will write once and ask whether you still want to be on the list. If you don't reply, we'll remove you. Consent given a long time ago, for something that never arrived, isn't really consent any more — and an email out of the blue two years later is indistinguishable from spam, however well-intentioned we are.
We'd also rather you didn't forget who we are, so expect the occasional short note in the meantime. That is the whole reason the consent wording mentions them.
Your rights
Under the GDPR you can ask us to:
- give you a copy of what we hold about you;
- correct anything wrong;
- delete it — and for the waitlist, this is instant and needs no request: the unsubscribe link in every email removes you;
- restrict or object to how we use it;
- port it to another service;
- withdraw your consent, at any time, without giving a reason. This does not affect anything we did lawfully before you withdrew it.
Email contact@zyggy.app and we will respond within one month. We will not ask you to justify the request, and exercising any of these rights costs you nothing.
If you believe we have breached data protection law, tell us with the details and we will investigate and write back with the outcome and what we intend to do about it. You can also complain to the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) at https://www.dataprotection.ro, or to the supervisory authority where you live. We would rather you told us first, but you are not obliged to.
Children
Zyggy is for adults. The waitlist is not aimed at anyone under 18, and the app will be 18+. If you believe a child has given us their address, email contact@zyggy.app and we will delete it.
Security
Data is encrypted in transit (HTTPS everywhere) and at rest. Access to the production database is limited to the people who need it. IP addresses are hashed before they are ever written down. Confirmation links are signed, expire after seven days, and are stored only as a hash — so even a stolen database yields no working links.
No system is perfect. If we ever suffer a breach that puts you at risk, we will tell you and the regulator within the deadlines the law sets, and we will tell you what actually happened.
When the app launches
The Zyggy app will need more than an email address to work: your birth date, time and place to calculate your chart, and — only if you turn it on — proximity data to count crossings.
We are designing that so the app never records where you have been. Crossings are counted as a number, without a time and without a place, and there is a switch in Settings that stops the count entirely. None of that applies yet, because the app doesn't exist yet. When it does, we will publish a full policy and email you about it before you are asked to give us anything.
Changes
If we change this policy in a way that affects you, we will email everyone on the list. Smaller corrections will be noted here with a new date. The version history lives in our public code repository, so you can see exactly what changed and when.
Not yet reviewed by a lawyer. This document accurately describes what the system does, but it must be reviewed by a qualified data protection adviser, and the placeholders above filled in, before the waitlist accepts a single real signup.