CityInEurope

Legal · Privacy

Privacy policy

CityInEurope is a free, ad-free guide to what's on in Budapest. We keep as little about you as we can, never sell it, and let you delete it in one click.

Last updated 23 September 2026

01

Who we are

CityInEurope (cityineurope.com) is a non-commercial project. It is the controller of the personal data described here. Contact: catatonian@gmail.com.

02

Using the site without an account

You can browse events and places without signing up. We do not use advertising or third-party tracking cookies and we do not build visitor profiles.

If you allow location access, your position is sent only with the search request to sort results by distance; it is not stored. Radars you save without an account stay in your browser's local storage.

03

What we store when you sign up

Your email address and, if you choose a password, a salted scrypt hash of it (never the password itself). A session token is stored as a SHA-256 hash for 30 days.

Everything you add yourself: display name, favourites, events you attend and your ratings, notes, lists, radars, children's ages, an optional home location, notification preferences and push subscriptions.

04

Signing in with Google, Apple or Facebook

If you use social sign-in we receive only your account identifier at that provider, your email address and your name. We use them solely to create and sign you in to your CityInEurope account. We do not post anything on your behalf and do not access your contacts, files or other data.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

05

Why we use it

To run your account and the features you switch on: saved items, reminders, radar alerts, the weekly email and recommendations. The legal basis is performing the service you asked for (GDPR Art. 6(1)(b)); optional notifications rely on your consent, which you can withdraw at any time in Account.

06

Who processes it

Data is stored on our own server in Germany (netcup GmbH). Emails are delivered by Resend. Browser push messages pass through your browser vendor's push service. Event descriptions from public sources are translated and classified with Anthropic's Claude; your personal data is never sent for this.

We never sell or rent personal data and never share it for advertising.

07

Cookies

Only strictly necessary cookies: kesif_session keeps you signed in, and kesif_oauth (10 minutes) protects a social sign-in against forgery. No consent banner is needed because nothing else is set.

08

How long we keep it

Account data is kept until you delete your account. Expired sessions are removed automatically. Server backups are kept for 7 days.

09

Your rights

You can view and edit your data in Account and delete your account there at any time — this immediately removes your profile, sessions, linked sign-ins, favourites, notes, lists and push subscriptions.

You also have the right to access, rectify, port or restrict processing of your data and to object. Write to catatonian@gmail.com. You may lodge a complaint with a supervisory authority, in Hungary the NAIH (naih.hu).

10

Children

The site helps parents find activities for children, but accounts are meant for adults. Children's ages you add are stored as numbers only, without names.

11

Changes

If this policy changes materially we will update the date above and, for members, mention it in the next email.

Terms of use