YATTA is a free multi-festival timetable app for the web and mobile. This policy explains, in plain language, what personal data YATTA handles, why, and what rights you have. We have tried to keep it honest and specific: it describes what the app actually does today, and flags a few features that are only planned so you know the difference.
One thing worth saying up front: YATTA's backend is self-hosted on the operator's own Raspberry Pi server (at yatta.theorangecourier.com), running a lightweight database called PocketBase. Your account and plan data are not sitting on a big third-party cloud platform — they live on hardware the operator controls directly. We think that is a genuine privacy benefit and we want to be clear about it.
Last updated: 23 July 2026
1. Who we are and how to contact us
YATTA is operated as an independent, self-hosted project. The operator of YATTA is the data controller for the personal data described in this policy — that is, the person who decides why and how your data is used.
You can reach us about privacy, or anything else, through the in-app contact form: Settings → Help → Contact support (the /support page). It reaches the operator directly and is open to everyone — you do not need an account to use it, so people who cannot log in, and supervisory authorities, can reach us there too. You can also email us at support@theorangecourier.com.
If you need the controller’s full legal identity or a postal address — for example to make a formal data-protection request — please ask through that form and we will provide it.
2. What we collect, why, and the legal basis
Most of YATTA works without an account. You can browse festivals, build a personal timetable, mark must-see acts and add notes, all without signing up. When you are not signed in, that plan data is kept only on your own device (in your browser or app storage) and is not sent to our server. You only need an account if you want your plan to sync across devices, join crews, or use features like sharing and export.
Is providing your data required? Providing personal data is not a statutory requirement. It is a contractual necessity only for the account-based features: if you want cross-device sync, crews, sharing or export, you must provide an email address (or a Telegram identity) and the associated account data. The only consequence of not providing it is that those specific features are unavailable — the rest of the app continues to work without an account.
Here is what we collect when you do use the account-based features, why, and the legal basis under the GDPR.
Account and sign-in
- Email address — used as your account identity, for login, and so we can reply to you about support. If you sign in with Telegram only and never add an email, the system assigns a placeholder internal address so the account can exist; it is not a real inbox.
- Password — stored only as a secure one-way bcrypt hash, never in plain text. If you sign in with Telegram first, a random password is generated for you behind the scenes.
- Display name — shown to you and, where relevant, to crew members and on any plan you choose to make public.
- Account security data — a signing key and login tokens that keep your session valid. These are standard authentication internals.
- Verification and account status flags — e.g. whether your email is verified, your role, and your premium status.
Legal basis: performance of a contract (Article 6(1)(b)) — we need this to give you the account and features you asked for.
Sign in with Telegram (optional)
If you choose to sign in with Telegram, Telegram sends us a signed set of profile details which we store on your YATTA account:
- Your Telegram user ID (used to link and recognise your account),
- Your Telegram username,
- Your Telegram display name (used to set your YATTA display name), and
- A link to your Telegram profile photo (the image itself stays on Telegram's servers).
To make this login work, our server also briefly creates a one-time link code, and a short-lived login token is passed back to the app in the return web address before being used and cleared. We verify Telegram's data ourselves using a cryptographic check; YATTA does not make a separate call out to Telegram's servers to do this.
Account merging: if you link Telegram to an account and a separate account already exists for that same Telegram identity, we combine the two into a single account — your plans and favorites, crew memberships, contribution points and summary, referral codes and premium status are moved into the surviving account, and the duplicate account record is then deleted. This keeps you to one identity rather than two.
Legal basis: your consent (Article 6(1)(a)), because you choose to use Telegram login; and performance of a contract for the account it creates.
Your festival plans and social features
When you are signed in, the following are stored on our server so they sync across your devices:
- Favorited / pinned acts for each festival edition (your saved timetable),
- Must-see priority flags on acts,
- Free-text notes you attach to acts (please remember these can hold anything you type, so avoid putting sensitive personal information in them),
- Star ratings (1–5) you give to performances,
- Crews you create or join, your crew membership and role, and crew invite codes, and
- Your referral code and any referral relationship, if you use referrals.
Your plans, notes and ratings are private to you by default (only you, and where strictly necessary an administrator, can read them). Your individual pins and ratings are never shown to other users with your identity attached — but they are counted anonymously into aggregate figures we display to everyone, for example how many people have pinned an act (a "crowd level" count) and an act's average star rating. These aggregates contain only totals and averages, never your identity. Two further things are more visible by design, and only when you opt in:
- Public / shared plans: if you publish a plan to share it, that shared copy — including your display name and your pinned acts — becomes publicly readable by anyone with the link. This only happens when you choose to publish it.
- Crews: crew names, membership and invite codes are readable by any signed-in YATTA user. This means other signed-in users can see who is in a crew and members' display names. Only join a crew if you are comfortable with that.
Referral codes are similarly readable by any signed-in YATTA user (like crew invite codes); the underlying referral relationship — who referred whom — is restricted to you as the referrer and to an administrator.
When you are not signed in, all of this stays on your device only (see section 5) and is not uploaded. If you later sign in, your on-device favorites can be migrated up to your account.
Legal basis: performance of a contract (Article 6(1)(b)) for delivering the plan and social features you use.
Premium whitelist
To grant free Premium to specific supporters, an administrator may add you to a premium whitelist. This stores your email address and/or your Telegram user ID, an optional short internal note, and a record of which administrator added you. The list is admin-managed and used only to match your account and unlock Premium; it is not shown to other users. If you are removed from the whitelist, or ask us to remove you, your entry is deleted.
Legal basis: performance of a contract (Article 6(1)(b)) in providing you the Premium features intended for you, and our legitimate interest (Article 6(1)(f)) in administering free-Premium arrangements for supporters.
Contribution reports
YATTA lets you submit corrections to festival timetables and earns you contribution points for accepted ones. A report stores what you submitted (category, a free-text message, an optional source link and suggested fix), a snapshot of your name/email as the reporter, and the review outcome — which includes a reviewer's note about your submission and the points awarded — plus a points ledger and summary tied to your account. The reviewer's note is retained and is readable by you and by administrators. Earning 300 lifetime points automatically unlocks premium features for you.
Legal basis: performance of a contract, and our legitimate interest (Article 6(1)(f)) in maintaining accurate timetable data.
Support messages
When you contact support, we store your message (free text — again, please don't include sensitive details you don't need to), your email if you provide one, your user ID if you are signed in, and basic context (such as whether you wrote in from the web or the app). Support messages are readable only by an administrator.
Legal basis: performance of a contract and our legitimate interest in answering your query.
Anti-spam captcha on the support form
The support form is protected against bots by Cloudflare Turnstile (see section 3). Turnstile checks that you are a real person; the content of your support message is not sent to Cloudflare.
Legal basis: our legitimate interest (Article 6(1)(f)) in preventing spam and abuse.
Advertising
YATTA shows a first-party "house" banner promoting YATTA Premium, served from our own backend. For this house banner we record simple, first-party ad analytics: for each impression or click we store the campaign, the type (impression or click), the festival edition, the platform (web or mobile), and your user ID if you are signed in (blank if you are not). We do not collect your IP address or user-agent for these first-party ad analytics, and there is no advertising cookie or advertising SDK behind the house banner.
In addition, on the web version, non-premium users are shown a banner from a third-party ad network, A-ADS (see section 3). When your browser loads this banner, it makes a request to A-ADS, which necessarily reveals your IP address and the standard referrer information that any browser sends when loading content. The A-ADS banner is cookieless; we do not pass A-ADS your user ID, your plan, your ratings or our campaign data.
On the mobile apps (iOS and Android), non-premium users are instead shown a banner from Google AdMob. To serve the ad, Google's AdMob SDK collects a resettable per-app device identifier (on iOS, the vendor identifier — IDFV), coarse location derived from your IP address, and ad interaction/diagnostic data, and shares these with Google as an independent controller for advertising purposes. We always request non-personalised ads. The app does not track you: it never asks for tracking permission, so on iOS your advertising identifier (IDFA) is not available to us or to Google — iOS returns only zeros — and we do not link your data with data from other companies' apps or websites, nor share it with data brokers. We do not send AdMob your account, plan, ratings or campaign data.
Premium and admin users see no ads at all — no house banner, no A-ADS, and no AdMob.
Legal basis: our legitimate interest (Article 6(1)(f)) in supporting a free service through advertising. You can remove all ads by using Premium.
App-store purchases
On the mobile apps, Premium is purchased through the platform's in-app purchase system — Apple in-app purchase on iOS and Google Play Billing on Android. Apple or Google processes the payment and holds your card and billing details; YATTA never receives or stores your card data. After a purchase, the app sends our server an opaque store receipt/token which we validate with Apple/Google to activate Premium on your account and to restore or verify your entitlement. We keep a minimal record that your account holds Premium — the plan, the store it came from, and the receipt/transaction identifier. On the web, Premium can instead be obtained through our web payment providers or, optionally, earned through verified contributions. Managing, cancelling or requesting a refund for a mobile subscription is done through your Apple or Google account settings.
3. Third parties and international transfers
YATTA is deliberately light on third parties. We do not use analytics platforms, and we do not use third-party clouds for your account and plan data — that all stays on our self-hosted server. The external recipients today are:
- A-ADS (the A-ADS advertising network) — on the web version, for non-premium users. When your browser loads the A-ADS banner, it sends A-ADS your IP address and standard referrer/request information. The banner is cookieless and we do not pass A-ADS your user ID, plan, ratings or campaign data. A-ADS operates internationally, so this involves a transfer outside the EU/EEA. Premium and admin users are not shown this banner, and it is not used in the mobile app.
- Google LLC (AdMob) — on the mobile apps, for non-premium users. To serve the banner, Google's AdMob SDK collects and receives a resettable per-app device identifier (IDFV on iOS), IP-derived coarse location, and ad interaction/diagnostic data, acting as an independent controller for advertising. Ads are always requested non-personalised; the advertising identifier (IDFA) is not accessed because the app never requests tracking permission, and there is no cross-app or cross-site tracking. We do not pass Google your account, plan, ratings or campaign data. Google operates internationally. Not used on the web version.
- Cloudflare, Inc. (Turnstile captcha) — when the support page loads and when you submit it, Cloudflare's captcha receives your IP address and technical challenge/interaction signals, and may set its own client-side token. Our server also sends Cloudflare the captcha token to verify it; our server does not send Cloudflare your IP address — the IP Cloudflare sees comes from your own browser loading the widget. The content of your support message is not sent. Cloudflare is a US-based company and processing may occur outside the EU/EEA.
- Telegram Messenger Inc. — only if you use Telegram login. When the login widget loads, your browser contacts Telegram (revealing your IP and that you use YATTA), and Telegram provides the signed profile data described in section 2. Telegram operates internationally.
- Google LLC (fonts and rendering engine) — on the web version, your browser fetches the app's rendering engine and some fallback fonts from Google's servers (gstatic.com) at runtime. This sends your IP address and standard request information to Google; no account, plan, or identifying content is sent. Google operates internationally.
- Internet Security Research Group (Let's Encrypt) — provides the HTTPS security certificate for our site. This is infrastructure only: Let's Encrypt sees certificate-related traffic, not your personal data.
- Apple Inc. / Google LLC (in-app purchases) — when you buy Premium in the mobile app, Apple (iOS) or Google (Android) processes the payment as an independent controller and holds your card/billing details; YATTA receives only an opaque receipt/transaction token, which it validates to activate your Premium. They operate internationally.
Where a third party processes data outside the EU/EEA, such transfers rely on the appropriate safeguards under the GDPR (such as adequacy decisions or standard contractual clauses) provided by those companies.
We do not use Firebase or Google Analytics. (Some unused code for a Firebase backend exists in the project's history but is not active in the live app and receives no data.) On the mobile apps we use Google AdMob for the banner ad shown to non-premium users, as described in the Advertising section above; there is no AdSense.
4. Cookies and local storage
YATTA does not use advertising or cross-site tracking cookies of its own. We use your browser's or device's local storage for functional purposes only:
- To keep you signed in across reloads (a stored authentication token). This token is your session credential — treat it like a password on a shared device.
- To remember preferences, such as your light/dark theme choice.
- To hold your on-device festival plan (favorites, priority flags, notes) when you are not signed in.
- To remember crew IDs you created or joined, so they show up on your Crews screen.
Third-party components you interact with may set their own storage outside our control — notably the A-ADS banner on the web (which is cookieless but is served in a cross-origin frame), Cloudflare Turnstile on the support form, and Telegram's login widget if you use it.
The app is intended to be usable offline via cached festival data bundled with the app. A full offline "app-shell" cache (a service worker) is planned but not effective in the current build.
5. Data retention
We do not currently run automatic scheduled deletion of records; in practice data is kept until it is manually removed or you ask us to erase it. Our approach to how long we keep each category is:
- Account and plan data — kept while your account exists. When you delete your account (see section 6), the associated data is removed from our server immediately. \1
- In-app purchase records — that your account holds Premium, the plan, the store (Apple/Google) and the receipt/transaction identifier, kept while the entitlement is active and for as long as needed for accounting, refunds and restore-purchases, then deleted with your account or on request.
- Contribution reports, points ledger and summary — the ledger and summary are kept for as long as your account exists, because your lifetime points determine your Premium benefit (note that Premium unlocked by reaching 300 points is set to last 365 days before it needs to be re-earned or renewed).
- On-device data (anonymous plans, preferences, sign-in token) — stays on your device until you clear it, sign out, or clear your browser/app storage. Signing out clears your stored session token.
- Support messages — kept until manually deleted; we aim to remove them once your query is resolved and no longer needed for reference (for example, an ongoing dispute), and they can be deleted sooner on request.
- Ad analytics events (for the first-party house banner) — simple counters tied at most to a user ID; retained for performance measurement and deleted on request together with your account.
If you want any specific data deleted, contact us using either method in section 1 and we will action it manually.
6. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase your data ("right to be forgotten");
- Restrict processing in certain circumstances;
- Data portability — receive your data in a usable format;
- Object to processing based on legitimate interests (including our use of advertising to support the free service);
- Withdraw consent at any time where we rely on consent (for example, Telegram login), without affecting processing already carried out; and
- Lodge a complaint with your local data protection supervisory authority.
How to exercise your rights. You can delete your account yourself at any time — in the app or the web app, go to Settings → Danger zone → Delete account. This permanently erases your account and its associated data; there is nothing to wait for. Step-by-step instructions are at yatta.theorangecourier.com/delete-account. Other data-subject requests (access, rectification, portability) are handled by the operator — contact us through Settings → Help → Contact support and we will action them, and we can provide a copy of your personal data for access and portability requests.
You can manage or clear on-device data yourself at any time by signing out or clearing your browser/app storage. Separately, Premium users can export their pinned timetable as a calendar (.ics) file or an image directly from the app. Please note this export is a convenience feature covering only your pinned acts — it is not a full portability export and does not include, for example, your email, ratings, notes, reports, crews, referrals or support messages; for a complete copy of your data, use the manual request process above.
7. Children
YATTA is intended for an adult, 18+ audience (the festivals it covers are generally 16–18+ events, and the app shows mature-rated ads). We ask that you do not create an account or use the account-based features unless you are at least 18 years old. We do not currently verify age — there is no age gate or date-of-birth step at sign-up — so this is a condition of use rather than a technical control, and we rely on users to respect it. YATTA is not directed at, or intended for, children. If you believe a child has provided us with personal data, please contact us at support@theorangecourier.com and we will delete it.
8. Security
We take reasonable measures to protect your data:
- The backend is self-hosted on the operator's own server rather than a third-party cloud, reducing the number of parties with access to your data.
- All traffic is served over HTTPS, using a certificate from Let's Encrypt.
- Passwords are stored only as secure hashed values, never in plain text.
- Sensitive data such as support messages, account details, plans and admin functions are restricted — your plans, notes and ratings are readable only by you (and, where strictly necessary, an administrator), and support messages and the premium whitelist are admin-only.
No system is perfectly secure, but we aim to keep your data safe and to be transparent if anything goes wrong.
9. Changes to this policy
We may update this policy from time to time — for example, when we add or change a feature. When we make a material change, we will update the "Last updated" date above and, where appropriate, notify you in the app. Please check back occasionally.