bilitly

Privacy

What Bilitly knows about you

A plain-language notice. It says only what the app actually does, so if a paragraph below is missing, that thing does not happen.

Last updated 30 September 2026

The short version

Small on purpose

You can use the planner, the Day planner and the Trip desk without an account and without telling us who you are. An account exists so a photo, a comment or a meetup has a name on it, and, if you choose to tell us, so your passport and permit follow you to another phone. There are no advertising cookies, no analytics and no tracking pixels anywhere in Bilitly. We do not sell anything about you, and we do not build a profile of you for advertisers.

You can delete your account yourself, at any time, from Settings. It takes your profile, your postcards and photos, your comments, your likes, your follows, your meetups, your travel map, your tags, your chat messages, your passport and permit and your settings with it; the section "What deleting your account removes" below names every item and the two things that stay. Bilitly is new enough that Settings may still tell you deleting is not switched on yet; if it does, ask us and we will do it by hand.

Who

Who is responsible for this

Bilitly is run by its founder in the Netherlands. A registered name and a postal contact address are being set up, and this page will carry them as soon as there is something real to publish. We would rather say that than print a name that does not exist yet.

We do not have a public inbox yet, so for now please reach us through whoever shared Bilitly with you. This page will carry an address as soon as there is one to publish. Most of what you would write to ask for you can do yourself from Settings, without asking anyone.

Bilitly used to be called Gardesh, at gardesh.nl. Your account, your postcards and the settings saved with your account are the same; at the new address you may need to log in once more.

Your data

What an account stores

Signing up creates a login and a public profile. The login is your email address and your password; the password is stored by our database provider as a hash, and nobody at Bilitly can read it.

Login
your email address and a password (hashed). Your email is never shown to other members.
Profile, required
your name as you type it, and a username (your @handle).
Profile, optional
a city, a short bio, interests, languages, a line about what you are up for, and a profile photo.
Who can see the profile
anyone on Bilitly, signed in or not. Your email is not part of it.
Who you follow
following stores which account follows which. Your profile shows how many people you follow and how many follow you, and a signed-in member can open both lists. Treat them as public: they are not secret on the database side either. You can take anybody off your own followers list; they are not told, and they can follow you again. Members can also find you by name or username on the People page.
Date
when the account was created.

Signup then asks two optional questions, the country of your passport and which residence permit or Schengen visa you hold; what happens to those two answers is written under “Your passport and permit” below. Nothing else about you is collected at signup: we do not ask for your university, your address or your phone number, and the app has no field for any of them.

One check happens on the password you choose. When you create a password we check whether it already appears in a public list of passwords from known data breaches. Your password does not leave your phone or laptop for this: it is hashed in your browser and only the first five characters of that hash are sent, first to our server and from there to the Pwned Passwords service. Those five characters match hundreds of thousands of different passwords, so neither we nor that service can tell which one is yours. If the check cannot run, your signup goes ahead anyway.

Your data

Your passport and permit

Once your account exists, Bilitly asks two optional questions: the country of your passport, and which residence permit or visa you hold (a permit from a Schengen country, a Schengen visa, another permit such as an Irish, Cypriot or UK one, or none). You can skip both, and answer, change or remove them later in Settings.

What is stored
your passport country as a two-letter code, your permit or Schengen visa answer, and when you last changed them.
Where
in a private table in our database that only you can read, change or delete, while you are logged in. It is not part of your profile, other members and visitors cannot read it, and none of our screens shows it to anybody else. And in your own browser, next to the planner answers described below.
Why
so the planners and Explore can tell which places you can visit without a visa. When you change them in a planner while you are logged in, your account gets the change too, so the next phone or laptop you log in on has the same answers.

Explore sends them to our own server. To suggest places near you that your passport and permit can reach, Explore sends our own server your passport country and your permit or Schengen visa answer together with your town. They are used to pick places and for nothing else: they are never passed to a third party and never written to a log.

To remove them, open Settings and choose Remove passport and permit. That deletes the row from our database and forgets them in the browser you are using. Another browser where you are logged in forgets them the next time Bilitly loads there, unless you changed them in that browser more recently. Deleting your account deletes the row too.

Your data

Photos, stories and comments

A postcard stores the photo, the place and country you named, your story if you wrote one, any tags you added, and the date. Likes store which account liked which postcard. Comments store the text you wrote, an optional rating, and the date. Each postcard is for Everyone or for Mutual followers. Everyone means anyone, also without an account. Mutual followers means you and the members you follow who follow you back; its pin, replies, likes and tags are shown to the same people, and it never appears on a town or trip page. If either of you stops following, they stop seeing it, but a photo link already opened can keep working for up to 15 minutes, and anyone who can see a postcard can save it. We can see every postcard ourselves, to handle reports. The tags you add to a postcard and the #hashtags you write in a story or a comment are also stored as a separate, structured list, for search and statistics, and they go when the postcard or comment goes.

Your photo is re-encoded before it is uploaded. Your browser redraws the image at a maximum of 1600 pixels on the long side and saves it again as WebP, or as JPEG where your browser cannot write WebP. It also saves a second, smaller copy, drawn the same way, which is the one the wall shows. Redrawing an image like that discards the camera's metadata block, which is where the GPS coordinates, the date and the camera serial number live. So the photo we store, and the photo everyone else sees, does not carry the location your camera recorded. The photos of a postcard for Everyone are stored in a public bucket, which means the image address works for anyone who has it, including after you share it outside Bilitly. The photos of a postcard for Mutual followers are stored in a bucket that is not public: a link to one is made only for somebody who may see the postcard, and it stops working within 15 minutes.

You can delete your own postcards and your own comments at any time, and deleting your account deletes all of them with it. The owner of a postcard can also remove any comment left on it, so a comment you write on somebody else's postcard can be removed by them.

A like is not private: your name can be seen next to a postcard you liked. In the app the list opens for signed-in members; the like itself can be read by anyone who can see the postcard, with or without an account.

Your data

Your travel map, and the places you pin

When you pick a place from the search while posting a postcard, we store that place with it: its name, its country and its position rounded to about 100 metres. We never store the position your phone or your photo reports: photos are redrawn in your browser before upload, which removes their location data.

A pinned postcard appears on the travel map on your profile and on the page of that place, next to other members' postcards of the same place. The map shows where, never when: no dates, and nothing is ordered by time. A postcard itself still shows how long ago it was posted, on the wall and on its own page, whether it is pinned or not. On the map a pin is drawn at its town or city, never closer, however far in you zoom; members who can see your map can still read the rounded position itself.

Members who are signed in can see your travel map when they open your profile. People who are not signed in cannot. In Settings you can switch on "Only I can see my travel map". Then nobody else can read the positions and your postcards leave the shared place pages. It does not hide a place name written on a postcard that is still on the wall.

Deleting a postcard deletes its pin. Deleting your account deletes all of them.

Your data

Your postcard as a trip idea

Bilitly can show a postcard of yours that is for Everyone as a trip idea on the City guide page of the place it names, on Can I go?, in the Day planner and in the list of members' places in its country, and adds "Get there" links under it. This uses only the place, the country and the tags you gave the postcard, which are already public. On that list a place is named as it was written on its newest postcard, with up to three of the tags on its postcards and the month of the newest one, never a day or a time. It never uses your pin, the city on your profile, where you are now, or your passport and permit.

We do this because helping students find places through other students is what Bilitly is for (our legitimate interest). You can object at any time, without giving a reason: switch off "Show my postcards on town and trip pages" in Settings. Your postcards then stay on the wall and on your profile, but are no longer put forward.

Nobody is told who opened "Get there", we do not record it, and partner links carry nothing about you or the member who posted.

If somebody reports your postcard, it stops being a trip idea while we look, and we tell you.

Your data

Being tagged on a postcard

A member can tag you on a postcard only if you follow each other. Your name then shows on that postcard and the postcard shows under "Tagged" on your profile. You can remove your tag at any time, and it cannot be added back to that postcard. A tag never adds a place to your travel map. Postcards you are tagged on stay under Tagged on your profile also when your travel map is hidden.

Your data

Meetups (Going out)

A meetup stores what you are doing, a title, the city, when, an optional note, an optional size limit, and who has joined. The exact place, the note and the precise coordinates are kept apart from the rest and are readable only by the host and by the people the host has personally approved. Everyone else sees the city and a location rounded to roughly a kilometre, which is enough for a “near you” sort and not enough to find the venue.

Following somebody is not a way in. Asking to join stores your account against that meetup while the host decides; the host sees your name and profile, which is the point of asking. A host declining, or removing you later, closes the exact location again.

Your data

The meetup chat

Each meetup has one group chat. Only the host and the people the host let in can read and write it. If the host removes you, you lose access at once.

Chat messages are not end-to-end encrypted. The members of that meetup can read them, and so can we, as the operator, through the database, when we look into a report or a fault.

You can erase a message you wrote: its text is removed at once and a line saying it was deleted stays. The host of the meetup can erase any message in its chat in the same way, and the line saying it was deleted still names who wrote it. All messages go when the meetup is deleted, and yours go when you delete your account, except a copy kept with a report, described next. We send no email and no notification about chat messages. Which messages you have read is kept on your device only, and it is cleared from a browser when you log out there.

If a member of that meetup reports a chat message, a copy of it is kept with the report, so we can still read it if it is erased or the meetup is deleted later. That copy also stays if the person who wrote it deletes their account, the same way a meetup safety report does. It goes when the report goes, and we remove reports of chat messages, with their copies, after 12 months.

Your data

Reports

If you report a postcard, a comment, a profile or a meetup, we store which account reported which thing, the reason you typed, and the date, so that it can be looked at. Reports are not public and the person you reported is not told who reported them.

With the report we keep a copy of what was reported, as it was at that moment, so it can still be looked into if it is changed or deleted later: for a postcard its story, place and photo address; for a comment its text; for a profile the name, username, bio, city and photo address; for a chat message its text; for a meetup its title, city and time and who hosts it, never the exact place. Each copy says whose it was. It stays with the report even when the thing itself, or the account that made it, is deleted, and we remove these copies 12 months after the report. A report you filed stays if you delete your account, with your name taken off it.

Your data

The planner answers, and what they are not

The passport, the residence answer, the home city and the budget you type into “Can I go?”, the Day planner and the Trip desk are saved in your own browser, in its local storage, on that device, and clearing your browser data removes them there. The home city and the budget are not attached to your account and do not travel to another device. The passport and the residence answer are, while you are logged in, as “Your passport and permit” above explains.

They are sent to our own server for one reason: to work out an answer and send it back. The answer is computed and the request ends; nothing about it is written to a database. Our server logs are deliberately narrow and pass through a list of permitted fields, and your home city, the places you type and anything free-text are not on that list, so they cannot be written to a log by accident.

Explore uses the same home city. To put photos of places near you on the wall, Explore sends our own server the home city you gave the planners (with its country when that is the Netherlands, Belgium or Germany) and, if you are logged in and it is a different one, the city on your profile. When neither is a town in the city guide, Explore offers “Use my location”. Only a tap on it asks your browser for your position, and the nearest town in the city guide is then worked out in your browser, so the one thing that leaves it is which of the guide's towns that is. Your position itself is not sent, not stored and not logged. Our server answers from the city guide files that ship with the app and asks no other service anything; the answer is kept in that open tab until you close it, and nothing about it is written to a database.

Play and go out uses the same town, or a rough position. To list places to bowl, play padel, swim or go out near you, the page sends our own server the id of one town in its list: the one you pick, or the home city you gave the planners, or the city on your profile, when either names exactly one town in that list. It also offers “Use my location”. Only a tap on it asks your browser for your position, and your browser rounds it to two decimals, about a kilometre, before it sends it; our server refuses a more precise one. That rounded position is used to work out distances and for nothing else: it is not stored, not logged, not cached and never passed to anyone. Our server answers from files that ship with the app and asks no other service anything.

Get there uses the same answers. When you open "Get there" under a postcard, it sends our own server that postcard's place and country and, when this browser has them, your passport and permit, only to show your own visa line. The home city you gave the planners, or type in "Get there", goes into the route links and, for a train in the Netherlands, to NS, as on the planner cards. None of it is stored or logged, and the member who posted is never told.

Tracking

No analytics, no advertising, no pixels

There is no analytics package in Bilitly: no Google Analytics, no tag manager, no Plausible, no PostHog, no Mixpanel, no Segment, no advertising network and no tracking pixel. We do not set a cookie to follow you, and there is no cookie banner because there is nothing to ask you to accept.

What we do store in your browser, all of it on your device and none of it sent anywhere: the session that keeps you logged in, the planner answers described above, the postcards you have kept, the country you last looked for a trip near home in, which postcards you chose to see on Explore (all of them, those with a story, or photos only), the fact that you have read the safety note on the meetup page, which chat messages you have already seen, when you last looked at the postcards you are tagged on, and, if you are an admin, whether your account may open the admin page. Clearing your browser data removes the lot.

One thing we process that is not stored with your account: your IP address. Our server counts how many requests arrive from one address in a minute, so that one visitor cannot make the app unusable for everyone else, and a university network shares one address between a lot of students. It is a count and a clock, it is not written next to your account, and it is not used to work out who you are.

Who else

Companies that hold it for us

Supabase
the database, the login and the photo storage. Servers in the EU (eu-west-1, Ireland).
Vercel
hosting: it serves the pages from the place nearest to you and runs our server code in Frankfurt, Germany (in the EU).

These are processors: they hold or move the data so that Bilitly can work, under their own terms, and they are not allowed to use it for their own purposes.

Who else

What our server asks other services while you plan

Some answers come from someone else's data. Our server asks for them on your behalf and without identifying you: the request comes from our server, carries a label that names Bilitly so the operator can reach us, and carries nothing about you, not your account, not your IP address and not a cookie.

OpenStreetMap
coordinates for a place name, and the things to do near it (Nominatim and Overpass).
Wikipedia
a thumbnail and a one-line description for a nearby spot.
NS
a real Dutch train between two stations: how long it takes, its changes and the fare NS quotes.
Travelpayouts
a recently seen cheapest fare between two airports.
Viator
bookable tours near a place you are reading about.
Pwned Passwords
five characters of a hash, only while you are creating a password (see above).

Two exceptions worth naming. Photos are not copied onto our servers: a place photo in the city guide or on Explore, and the photos in the planners, are loaded by your browser straight from Wikimedia's servers, so Wikimedia sees your IP address and, because a browser says which site it is coming from, that the request came from www.bilitly.com. And the live “look around” search does not run for a city or town the guide already covers: those places come from files that ship with the app, so no map server is asked anything about them. For anywhere else, a village in the Netherlands, Belgium or Germany that the guide does not cover included, it does run, and what leaves our server is the place name you typed, sent to OpenStreetMap's own search service and to a volunteer-run OpenStreetMap query server in Europe, with nothing about you attached to it. It also runs when the name does not point at exactly one of the guide's towns and arrives without its country: a name two of those countries share, such as Essen, or a town's name in another language, such as Bergen for Mons, because the guide does not guess which town was meant. The city guide lists every town it holds, so you can see which case you are in.

Who else

Some links open a partner site: a flight search, a hotel or hostel search, a train or bus search, a tour. Several of them carry a tag that tells the partner the visit came from us, and we may earn a commission if you book there. That costs you nothing and it does not change what Bilitly recommends or in which order.

The moment you tap such a link you are on their site, under their privacy policy, and they may set their own cookies. That is outside our control. Nothing about you is sent to them before you tap.

Videos on YouTube, in the city guide, is a plain link to a YouTube search for the town you are reading about. Nothing from YouTube is loaded on our pages: no video player, no picture and no request of any kind. YouTube only hears from you when you tap the link, and then it is YouTube's own site that opens, in a new tab, under Google's privacy policy. Bilitly has no YouTube key or account and learns nothing about what you watch.

Deleting

What deleting your account removes

Deleting your account is one action in Settings, it asks you to type your username and your password first, and it cannot be undone. It removes, item by item:

  • your profile: your name, your username, your profile photo, your city, your bio and everything else you filled in;
  • your postcards, with their photos and their stories;
  • your comments and your likes;
  • who you follow and who follows you;
  • your meetups, and your requests to join other people's;
  • your pins, which is your travel map;
  • the tags on you, and the tags you put on other people's postcards;
  • your messages in every meetup chat;
  • your passport and permit;
  • your settings for meetup emails and for your postcards;
  • your name on the reports you filed, which stay without it.

Two things stay, and both are about somebody else's safety rather than about you. Every report you filed stays as a record, with your name taken off it. And if somebody reported your postcard, comment, profile or chat message, the copy of it kept with that report stays, so it can still be read; we remove those copies 12 months after the report.

How long

How long we keep things

Your account and content
until you delete it. Deleting the account removes it.
A postcard or comment you delete
removed when you delete it.
A report you filed
kept. If you delete your account, the report stays as a record with your name taken off it.
A report about you
kept, with the reason the other person typed and a copy of what was reported as it was at that moment. Deleting your account removes the profile, postcard or comment itself; the copy kept with the report stays until 12 months after the report.
A copy kept with a report
the copy of a reported postcard, comment, profile or chat message, and the title, city, time and host of a reported meetup, are removed 12 months after the report; a report of a chat message goes with its copy. Nothing runs that automatically: somebody does it by hand, so it is a promise about what we do and not about what a machine enforces.
Server logs
kept short-term by our host for running and debugging the service. Our own log lines carry no free text of yours. One exception, because of how the place search works: what you type into the place search of the meetup location picker travels in the address of the request, so our host's request log keeps it for about an hour, and a shared cache keeps the search and its answer, never who asked, for up to eight days, so the same search is not sent to the search service again.
Planner answers in your browser
until you clear your browser data. If you log in on that browser, they are cleared from it when you log out or delete your account, so the next person on a shared computer does not see them. The home city and the budget are never on our servers.
Passport and permit on your account
until you remove them in Settings or delete your account.

Your rights

What you can ask for

Under the GDPR you can ask to see the personal data we hold about you, to have it corrected, to have it deleted, to limit or object to how it is used, and to get a copy of it. Most of that you can simply do yourself:

See it
your profile page shows everything that is public; Settings shows the email you log in with, and your passport and permit.
Correct it
edit your profile; edit or delete a postcard, a comment or a meetup.
Delete it
Settings, then Delete account. It cannot be undone. If Settings says deleting is not switched on yet, ask us and we will do it by hand.
Get a copy of it
there is no export button yet, so this one is by asking us.
Ask us
no public inbox yet, so for now reach us through whoever shared Bilitly with you. Nobody is turned away for asking that way.

If you think we have handled your data badly, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.

Age

Bilitly is for people aged 16 and over

You need to be at least 16 to make an account. We do not knowingly keep an account for anyone younger; if you tell us there is one, we will remove it.

Changes

When this page changes

When the app starts doing something new with your data, this page is updated first and the date at the top changes with it. Bilitly is small and this notice is meant to stay short enough that you can actually read it.

See also: Terms of use and Where our data comes from.