barhioword of mouth, only better
Back to home

Privacy Policy

Last updated: 30 May 2026

1. Data controller

The data controller is Hugo Nectoux (autónomo), Spain, contactable at hugo@barhio.com and at the postal address shown in our Aviso Legal. For any privacy matter, write to hugo@barhio.com.

2. What data we collect and why

CategoryExamplesPurposeLegal basis (GDPR Art. 6)
Account dataemail, password hash, username, display name, avatar, bioCreate & manage your accountContract (6.1.b)
Saved placesplace IDs, visited/wishlist status, your 1–5★ ratings, notes, date savedCore service: your saved placesContract (6.1.b)
Listslist titles, descriptions, ordering, public/private flag, public slugCreate & share listsContract (6.1.b)
Social graphfriend requests, accepted friendshipsFriend features & friend ratingsContract (6.1.b)
Locationdevice location while using the mapCenter the map, show nearby/saved placesConsent (6.1.a) via OS permission
Device & pushExpo push token, device typeSend notifications you enabledConsent / Contract
Restaurant Probusiness contact, claim verification, billing statusProvide & bill the Pro serviceContract (6.1.b)
Payment datahandled by Stripe; we receive status, not full card dataProcess subscriptionsContract (6.1.b) / Legal obligation (accounting)
Capture inputsthe Instagram/Google Maps URL you choose to share to BarhioExtract a place from the URLConsent / Contract (you initiate it)
Google Maps importplaces you choose to import from your existing Google saved placesBulk-import them into your Barhio accountConsent (6.1.a) — you trigger and authorise it
Usage/diagnosticsbasic logs, error dataSecurity, maintenanceLegitimate interests (6.1.f)

3. AI-assisted place extraction

When you share a link (e.g. an Instagram URL) to Barhio, that URL is sent to Anthropic's Claude API (via our secure server function) to identify the place referenced, then matched against Google Places. We send the URL and minimal context — not your account identity beyond what is needed to return the result.

3b. Google Maps import

If you choose to import your existing Google Maps saved places, you authorise Barhio to read the places you select from your Google account and copy them into your Barhio account as your saved places. We import only the place data needed for that purpose and do not access unrelated Google account data. You can delete imported places individually or in bulk at any time.

4. How content is shared with other users

  • Your saves are private by default and visible only to accepted friends per your settings.
  • A public list is accessible to anyone with the link, including non-users, and shows the list name, places, and ratings you chose to include.
  • Friend ratings you give are visible, in aggregated and individual form, to your accepted friends on the relevant place page.

5. Recipients / processors

We share data with service providers acting on our instructions:

ProviderRoleData
SupabaseAuth, database, storage, realtime — EU regionAccount, saved places, lists, social graph, avatars
Google PlacesPlace lookupSearch terms, place IDs
MapboxMap renderingCoordinates / map tiles requests
Anthropic (Claude API)AI place extractionShared URLs
StripeRestaurant paymentsBilling data (restaurant users)
Expo (push)NotificationsPush token
VercelWeb hosting (public lists, dashboard)Web request data

We do not sell your personal data.

6. International transfers

Your core account data is stored in the EU/EEA (Supabase, EU region). Some processors are based in the United States and may process limited data there: Anthropic (shared URLs for place extraction), Stripe (restaurant billing), Google (Places lookups and, if you use it, Maps import), Mapbox and Vercel (web requests), and Expo (push tokens).

For these transfers we rely on appropriate safeguards under the GDPR — the EU Standard Contractual Clauses and/or, where applicable, the EU–US Data Privacy Framework. You can request details of the safeguards at hugo@barhio.com.

7. Retention

  • Account data: kept while your account is active.
  • On account deletion: personal data is deleted or anonymised, except data we must keep by law (e.g. invoicing/accounting records for restaurant subscriptions — generally kept for the periods required under Spanish tax and commercial law) and short-term backups.
  • Public-list copies already obtained by others (e.g. a shared URL screenshot) are outside our control.

8. Your rights

Under GDPR you may: access your data; rectify it; erase it; restrict or object to processing; port your data; and withdraw consent at any time (e.g. location, notifications) without affecting prior processing. Exercise these at hugo@barhio.com. You may also complain to a supervisory authority. As the controller is established in Spain, the lead authority is the AEPD (aepd.es); users in France may also contact the CNIL (cnil.fr).

9. Minors

The Service is intended for users aged 16 and over and is not directed at children. We do not knowingly collect data from anyone below that age.

10. Security

We use RLS at the database level, encrypted secrets, and provider-side security. No system is perfectly secure; we will notify you and the authority of qualifying breaches as required.

11. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you by purely automated means. Friend ratings are aggregations of human ratings, not profiling of you.

12. Changes

We will post updates here and change the "Last updated" date; material changes will be notified.

Contact: hugo@barhio.com

barhioword of mouth, only better
  • Privacy
  • Terms
  • Cookies
  • Contact
  • Instagram
© 2026 Barhio