Legal
Privacy Policy
Effective 2026-09-11, version 1.1. This policy is in effect for every part of the Gether Service.
This Privacy Policy describes how Gether ("Gether", "we", "us") collects, uses, keeps and shares personal information when you visit trygether.com or gethr.link, join the waitlist, sign up for text messages, contact support, or use the Gether app and the collateral-backed spending account and card program (together, the "Service"). It applies to everyone who uses any part of the Service. Gether is in a waitlist phase and the account and card program are not yet open to the public; this policy already describes them so that you know what to expect before you create an account. By using the Service you acknowledge that you have read this policy.
1. Who is responsible for your information
Gether operates the websites trygether.com and gethr.link, the Gether app, the waitlist, the text message program and the Service. Gether is responsible for the personal information described in this policy, except where this policy says that a partner collects information under its own responsibility (section 5).
You can reach us about anything in this policy at support@trygether.com. Put "privacy" in the subject line so it is routed to the right person. More ways to reach us are on gethr.link/support.
The Service is offered in the United States. Your information is stored and processed in the United States. If you use the Service from elsewhere, you are sending your information to the United States, where the law may differ from the law where you live, and you consent to that transfer by using the Service.
2. Words this policy uses
- "Personal information" means information that identifies you, relates to you, or could reasonably be linked to you or your household. It does not include information that has been de-identified so that it can no longer reasonably be linked to you, or information that is publicly available from government records.
- "Sensitive personal information" means the subset that the law treats with extra care: government identification numbers, account credentials, the contents of your communications with us, precise location, and information about your financial accounts. This policy says where each is collected and how it is limited.
- "Service" means everything in the first paragraph: the websites, the app, the waitlist, the text message program, and the collateral-backed spending account and card program.
- "Partner" means a company that provides part of the Service under its own name and its own obligations, such as the card-issuing partner. "Service provider" means a company that processes information on our instructions and may not use it for anything else.
- "You" means anyone who uses any part of the Service, whether or not you have an account.
3. What we collect
What we collect depends on how you use the Service. Each part is listed separately so you can see exactly what a given action gives us. Section 4 lists the same information by legal category.
3.1 When you visit the websites
- Server logs: the IP address of your device, the time of the request, the page requested, the referring page if your browser sends one, and your browser's identification string. These are kept by our hosting provider to run and secure the sites, and are used by us only to investigate an attack or an outage.
- No cookies are set on the public pages of the websites. Signing in to the app sets two session cookies, described in section 9.
- No third-party analytics or advertising trackers run on the Gether websites. Every request your browser makes on our pages goes to us.
- After you submit the waitlist form or the text message form, your browser keeps a note in that tab only that you have done so, so the form does not ask you twice. It is not sent to us and it is gone when the tab closes.
3.2 When you join the waitlist
- Your email address, and the time you joined. Nothing else from the form is saved. The form refuses addresses at known throwaway inbox providers and does not save those attempts.
3.3 When you sign up for text messages
Your mobile number, your consent record and, later, records of the messages sent to you. Section 8 is the full notice for text messages.
3.4 When you contact support
- What you write to us, what we write back, the address you write from, and any reference number you include so we can find the attempt you are asking about.
- We do not record support calls, because we do not offer support by telephone.
3.5 When you create an account and use the app
Directly from you:
- Account information: your name, email address, phone number, and the credentials you create, including any authenticator app enrolment and recovery codes in the form we store them.
- Identity information: your date of birth, residential address, government identification documents, a photograph or likeness capture, your tax identification number where the program requires it, and anything else the identity check asks you for. Section 5 explains who collects this and where it goes.
- Records of your consents: which document version you accepted, when, and from which device and network address.
- Referral information: if you refer someone, the code you shared and the fact that it was used. If you give us another person's contact details for any reason, you confirm that you have their permission and that they know we will hold them.
3.6 From your use of the account
- Financial and transaction information: the assets you pledge, the value we place on them, your spending power, your draws, your repayments, your card transactions, your statements, and the ledger entries that account for all of it.
- Wallet and blockchain information: the addresses we give you, the addresses you send from or withdraw to, and the transfers between them. Section 10 explains why this category is different from every other.
- Device and usage information: device identifiers, IP address, browser and app version, notification tokens if you turn notifications on, and the actions you take in the app. These are used to operate the Service, to keep your account secure and to investigate problems.
- Assistant conversations: if you use the in-app assistant, the questions you ask it and the answers it gives.
- Security events: sign-ins and failed sign-ins, password and authenticator changes, card freezes and unfreezes, and the network addresses and devices involved, so that we can tell you when something happens on your account and can investigate if it was not you.
3.7 From other sources
- From our card-issuing partner and its identity verification provider: the outcome of your identity check and a limited set of verified identity fields (section 5).
- From the card network and the issuer, through our partner: authorization requests, settlements, disputes and chargebacks relating to your card.
- From public blockchains: the balances and transfers at the addresses associated with your account, which anyone can read.
- From public price sources: the prices used to value what you pledge. These are not about you, but they determine figures that are.
3.8 What we do not collect
- We do not buy personal information from data brokers.
- We do not collect precise location.
- We do not read your contacts, your photos beyond the capture you take for identity verification inside our partner's flow, or your other apps.
- We do not collect biometric identifiers ourselves. The likeness capture in identity verification is taken and processed by our card-issuing partner's provider under its own notice, and we receive only the outcome.
- We do not collect information about your race, religion, health, sexual orientation, or union membership, and we ask you not to send it to us.
4. The same information, by legal category
Several state privacy laws ask that a policy list the categories of personal information collected in the previous twelve months, the sources, the purposes, and the categories of recipients. This section does that in one place. Every entry is explained in full elsewhere in this policy.
- Identifiers (name, email address, phone number, IP address, device identifiers, account identifiers, wallet addresses). Source: you, your device, our partner, public blockchains. Purpose: to provide, secure and support the Service. Disclosed to: service providers, the card-issuing partner and issuer, the messaging and email providers.
- Government identification and other records (date of birth, residential address, identification documents, tax identification number). Source: you, through our partner's hosted flow. Purpose: identity verification and the program's legal obligations. Disclosed to: the card-issuing partner and its provider, which collect it directly. Not sold.
- Financial information (assets pledged, balances, draws, repayments, card transactions, statements). Source: your use of the Service, the card network through our partner, public blockchains. Purpose: to provide the Service and meet its legal obligations. Disclosed to: the card-issuing partner and issuer, the settlement provider, infrastructure providers.
- Internet and device activity (pages requested, app actions, browser and app version, security events). Source: your device. Purpose: to operate, secure and troubleshoot the Service. Disclosed to: infrastructure providers.
- Approximate location (inferred from IP address only, never precise). Source: your device's network address. Purpose: security and fraud prevention. Disclosed to: infrastructure providers.
- Communications (support messages, assistant conversations, text message replies). Source: you. Purpose: to answer you and to keep a record of what was said. Disclosed to: the model provider for assistant questions, the messaging provider for text replies.
- Consent records (which document, which version, when, from where). Source: your device. Purpose: to prove consent and to honour your choices. Disclosed to: carriers or messaging platforms reviewing the text message program, if required.
- Inferences: we draw none for advertising or profiling. The Service computes spending power and risk levels from prices and rules, not from inferences about you.
- Sensitive personal information (government identification numbers, account credentials, financial account information, the contents of your communications with us): collected only as listed above, used only to provide the Service you asked for, to secure it, to meet legal obligations and to prevent fraud, and never for advertising. We do not sell it and we do not share it for cross-context behavioral advertising.
5. Identity verification, and who actually performs it
Identity verification is not run by Gether. It runs in a hosted flow operated by our card-issuing partner, using that partner's own identity verification provider. When you complete verification, the documents and the identity data you submit go to that partner and its provider under the partner's own privacy terms, which are shown to you inside that flow. Gether receives the outcome of the check and a limited set of identity fields needed to open and operate your account. Gether does not receive or store the raw verification session, the images of your documents, or your likeness capture.
Gether does not itself screen your identity information against sanctions or watch lists. Any such screening is performed by the card-issuing partner and its issuer under their own obligations.
Because the partner collects this information directly, requests about the documents and images you submitted are answered by the partner under its own policy. Tell us and we will pass the request on and tell you where it went.
6. Why we use it
We do not use your personal information to build advertising profiles. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use sensitive personal information for any purpose other than those listed above.
- To provide the Service: to run the websites, to keep the waitlist and tell you when access opens, to send the text messages you signed up for, to open and maintain your account, to value what you pledge, to calculate spending power, to authorize and record card transactions, to service your balance, and to process deposits and withdrawals.
- To meet legal obligations: identity verification through our partner, record keeping, tax reporting where the program requires it, responding to lawful requests, and the anti-money-laundering obligations that apply to the program.
- To prevent fraud and abuse, and to keep accounts and the Service secure, including rate limiting, bot detection on our forms, monitoring for unauthorized access, and investigating suspicious activity.
- To communicate with you about your account: required notices, statements, security alerts, transaction alerts and support replies.
- To answer your questions, including through the in-app assistant.
- To enforce our terms and to protect the rights, property and safety of Gether, our members and the public, including by pursuing or defending claims.
- To improve and troubleshoot the Service, using records of what happened rather than profiles of who you are.
- To comply with a sale, merger or reorganisation of our business, as described in section 7.
6.1 Lawful bases, where the law asks for one
- Performance of a contract with you: everything needed to provide the Service you asked for, from the waitlist email to a card authorization.
- Compliance with a legal obligation: identity verification, record keeping, tax reporting, and responses to lawful requests.
- Our legitimate interests, balanced against yours: securing the Service, preventing fraud and abuse, enforcing our terms, defending claims, and improving what we build. Where we rely on this basis you can object, and we will stop unless the interest is compelling or the law requires the processing.
- Your consent: text messages, notifications you turn on, and any use we describe to you and ask you to agree to. You can withdraw consent at any time and we tell you how in each case.
6.2 De-identified and aggregated information
We may create de-identified or aggregated information from personal information, for example the number of members in a state or the share of authorizations declined for insufficient spending power. Once information can no longer reasonably be linked to you, it is not personal information and we may use and share it for any purpose. We commit to keep it de-identified, not to attempt to re-identify it except to check that our de-identification works, and to require the same of anyone we share it with.
7. Who we share it with, and what leaves our systems
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except with the provider that delivers the messages, with a service provider supporting Gether such as customer support, or as required by law or by a carrier or messaging platform reviewing the program.
We do not sell personal information to anyone, we do not rent or trade lists, and we do not disclose personal information to third parties for their own direct marketing. Every service provider named above by category is bound by a written agreement to use the information only to provide the service to us, to protect it, and to return or delete it when the work ends.
- Our card-issuing partner and the issuer behind it: your identity data, your account data and your transaction data, so that a card can be issued and transactions processed. This is the largest outbound flow and it is not optional: there is no card without it.
- Identity verification: as described in section 5.
- Infrastructure providers: hosting, databases, caching, key management and error reporting. These providers hold personal information as a consequence of running the systems, including in logs and backups, and act only on our instructions.
- Communications providers: an email provider for the waitlist and account email, and a messaging provider for text messages. The content of a notice, which can include a transaction amount and a merchant name, goes to that provider in order to be delivered.
- Price and settlement providers: the value of what you pledge is read from public price feeds, and a draw against your collateral is settled through a settlement provider. These providers receive wallet addresses and amounts.
- The in-app assistant: when you ask it a question, your question and the account context needed to answer it are sent to a third-party model provider, which processes them on our instructions to produce the answer. Do not put your password, your recovery codes or your identity document numbers into the assistant; it does not need them and we do not want them sent.
- Professional advisers, auditors and insurers, under confidentiality.
- Law enforcement, regulators and courts, where we are required to disclose, where disclosure is necessary to establish or defend a legal claim, or where we believe in good faith that disclosure is necessary to prevent fraud, to protect someone's safety, or to protect the rights and property of Gether or our members. In some cases the law prohibits us from telling you that we have disclosed.
- A buyer or successor, if our business or a part of it is sold, merged or reorganised, including during the negotiation of such a transaction, under the same commitments made in this policy.
- Anyone you direct us to share with, such as a person you ask us to send a statement to.
8. Text messages
This section is the SMS Privacy Notice for text messages from Gether under the program named "Gether account messages". It also stands alone at gethr.link/sms/privacy, and the SMS Terms are at gethr.link/sms/terms. You sign up at gethr.link/sms.
8.1 What we collect when you sign up
- Your mobile number, stored in international format.
- The exact consent sentence you agreed to, its version, and the date and time you agreed.
- The page or app screen where you agreed, the IP address of the device you used, and the browser or app identification string it sent. These are kept to prove that the consent came from you.
8.2 What we collect when messages are sent
- A record of each message Gether sent to your number: when, which category, and whether the carrier reported it delivered.
- Any reply you send to a Gether message, including STOP and HELP, and the date and time of the reply.
8.3 How we use it
To send you verification codes, sign-in and security alerts, card and transaction notifications, account updates and support replies about your own Gether account. To act on STOP, HELP and your other replies. To keep the record that you agreed, and the record that you cancelled if you do. To investigate a delivery problem or a complaint.
Gether does not use your mobile number or your consent record to send you marketing or promotional messages, and does not use them to build an advertising profile.
8.4 What we share, and what we never share
Your mobile number and the content of each message go to the messaging provider that delivers text messages for Gether, because delivery requires it. The content of a notification can include a transaction amount and a merchant name. The provider acts on our instructions and may not use your number for anything else.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text messaging originator opt-in data and consent will not be shared with any third parties, except with the provider that delivers the messages, with a service provider supporting Gether such as customer support, or as required by law or by a carrier or messaging platform reviewing the program.
Gether does not sell your mobile number.
8.5 How long we keep it
Your consent record, and your cancellation record if you cancel, are kept for as long as Gether needs to show that a message was sent with consent, which is at least four years after the last message sent to the number. Message records are kept for the same period. When the period ends the records are deleted or made anonymous.
8.6 Your choices
- Reply STOP to any Gether message to cancel. Message and data rates may apply.
- Reply HELP for help, or email support@trygether.com.
- To ask what we hold about your number, to correct it, or to ask for it to be deleted where the law allows, email support@trygether.com. We keep the consent and cancellation records described above even after a deletion request, because they show that we respected your choices.
8.7 Security
Your number and your consent record are stored with access limited to the systems that send messages and the people who operate them. Gether does not put your number in a message body, in a link, or in an address bar.
8.8 Changes and contact
Gether may change this notice. The date at the top is the date the current version took effect. A change to what is shared is told to you by text message before it applies.
Questions about this notice: email support@trygether.com. Gether's Privacy Policy, which covers the rest of the Service and carries this notice in full, is at gethr.link/privacy.
9. Cookies and similar technologies
- The public pages of trygether.com and gethr.link set no cookies.
- Signing in to the app sets two cookies: a short-lived access cookie and a longer-lived refresh cookie. Both are marked so that scripts cannot read them and so that they travel only over encrypted connections and only to our own domain. They exist to keep you signed in and are deleted when you sign out.
- The waitlist form and the text message form use your browser's session storage for a single note that you submitted, kept in that tab only.
- We do not use third-party cookies, pixels, fingerprinting or cross-site tracking of any kind.
- Because nothing on our sites tracks you, a Do Not Track or Global Privacy Control signal from your browser has nothing to switch off. We treat every visitor as if the signal were on.
10. Blockchain data is public and permanent
Some of what the Service does happens on a public blockchain. This section is here because it is the one part of this policy that no privacy right can undo.
- Deposits to the addresses we give you, withdrawals to addresses you nominate, and the on-chain movements between them are recorded on a public network. Anyone can read them. They are permanent.
- We cannot edit or delete a blockchain record. Nor can you. Nor can any regulator, court or authority order us to, because the record is not ours.
- A blockchain address is not a name, but it is a persistent identifier. Anyone who can connect an address to you, whether through an exchange, a public post, a leak, or analysis of transaction patterns, can then read everything that address has ever done and everything it will do in future.
- If you ask us to delete your personal information, and we do, the blockchain record stays exactly where it is and stays linked to the same addresses.
- Do not publish the addresses we give you if you do not want your activity with us to be linkable to you. We will never ask you to.
11. How long we keep it
We keep personal information for as long as we need it to provide the Service, and after that for as long as the law requires us to keep it. Those two periods are different, and the second one is longer.
- Waitlist: your email address until access opens and you are told, or until you ask to be removed, whichever is first.
- Text messages: your consent record and your cancellation record for at least four years after the last message sent to your number, as stated in section 8.
- Website server logs: a short rolling period set by our hosting provider.
- Support correspondence: for as long as the matter is open and for a period after it closes so we can answer a follow-up.
- Account, identity and transaction records: for the periods that financial record-keeping and tax law set for the program. Those periods run from the end of your relationship with us, not from the day you ask, and they are measured in years.
- Security events: for as long as needed to investigate and to show a pattern, and in any case no longer than the account records they relate to.
- Records of disputes, complaints and legal claims: until the claim and any limitation period is over.
- Backups: a copy of a record can persist in an encrypted backup for a bounded period after the live record is deleted, and is overwritten on the backup's own schedule. Backups are not searched or restored except to recover from a failure.
11.1 What that means for a deletion request
If you ask us to delete your personal information, we will not be able to delete all of it. We will delete or de-identify what we are not required to keep, and we will keep the rest for as long as we are required to, and no longer. Closing your account does not shorten that period and neither does a deletion request. If you want to know what would survive a deletion request in your specific case, ask us before you make one and we will tell you.
12. Your rights and choices
Depending on where you live, you may have the right to know what personal information we hold about you and how we use it, to receive a copy of it in a portable form, to correct it, to delete it, to limit or object to certain uses of it, and not to be treated differently for exercising any of these rights. Gether extends the following to everyone who uses the Service, wherever they live:
- Access and portability: email support@trygether.com and we will send you the personal information we hold about you in a readable, machine-portable form.
- Correction: tell us what is wrong and we will correct it. Identity information verified through our partner is corrected by repeating the verification, because we do not hold the source documents.
- Deletion: ask, and we will delete or de-identify what the law allows us to, and tell you what we kept and why (section 11.1).
- Marketing: we do not send marketing email or marketing text messages, so there is nothing to opt out of. Waitlist email is about access opening; reply or email us with the subject Remove me to leave the waitlist.
- Text messages: reply STOP to any message to cancel (section 8).
- Notifications: turn each channel on or off in the app's notification settings. Notices the law or your account agreement requires us to send are delivered by email while your account is open.
- Sale and sharing: we do not sell personal information or share it for cross-context behavioral advertising, so there is no sale or sharing to opt out of. We do not offer financial incentives in exchange for personal information.
- Sensitive personal information: we use it only for the purposes listed in section 6, so there is no further use to limit.
12.1 How we handle a request
- We verify that a request comes from you before acting on it, because acting on an unverified request is itself a breach. For an account holder that means signing in or confirming through the email address and phone number on the account. For a waitlist or text message signup that means confirming from the address or number we hold. We ask only for what verification needs.
- You may use an authorized agent. We will ask for proof that you gave the agent permission, and we may still confirm the request with you directly.
- We answer within the time the law where you live allows, and we tell you when to expect the answer. If we need longer than the first period the law sets, we tell you why before it ends.
- If we refuse a request in whole or in part, we tell you why. You can ask us to reconsider by replying to that answer; a different person reviews it and answers in writing. If you are still not satisfied, you may complain to the privacy regulator or attorney general where you live, and we will tell you how to reach them if you ask.
- We do not charge for a request unless the law allows a charge for repeated or excessive requests, and then we tell you the charge before we do the work.
- We keep a record of each request and what we did with it, for as long as the law requires.
12.2 Residents of California
If you live in California, the state's privacy law gives you the rights to know, to delete, to correct, to opt out of sale and sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising them. Section 4 is the notice at collection that law calls for. To exercise a right, use the routes in section 12; no account is needed to ask. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information beyond the purposes the law permits without an opt-in, so there is no sale, sharing or use to opt out of or limit; we honour any request you make regardless. We have not sold or shared personal information in the preceding twelve months. We do not disclose personal information to third parties for their direct marketing, so a request under the state's direct-marketing disclosure law will be answered with that fact.
12.3 Residents of other US states
If you live in a state with a comprehensive privacy law, you have rights to access, correct, delete and obtain a copy of your personal information, to opt out of targeted advertising, of the sale of personal information and of profiling that produces legal or similarly significant effects, and to appeal a decision we make about your request. We do not engage in targeted advertising, do not sell personal information, and do not profile you in that sense (section 13), so there is nothing to opt out of; the other rights are honoured as section 12 describes. To appeal, reply to our decision within the time your state allows; a different person reviews it and we answer in writing with the reasons and, if we refuse, with how to reach your attorney general.
12.4 Residents of Nevada
Nevada residents may direct a business not to sell their covered information. We do not sell covered information. If that changes, this policy will say so first and provide the address to send such a direction.
12.5 Residents of other countries
The Service is offered in the United States. If you use it from another country, your information is processed in the United States under this policy. Where the law of your country gives you rights beyond those listed in section 12, tell us which right you are exercising and we will honour it to the extent that law applies to us. You may also lodge a complaint with your local data protection authority.
13. Automated decisions
The Service decides automatically whether to approve a card authorization, how much spending power you have, and when your position is close to the level at which your collateral can be sold. These decisions are made by rules and by prices rather than by a person, and they affect your access to your own money. The rules are described on the how-it-works page and in the Account Agreement. If a decision affects you and you want it explained, email us; a person will look at the inputs the decision used and tell you what they were.
We do not use profiling to decide who may open an account or what terms they receive. Eligibility is decided by identity verification and by the collateral you pledge.
14. Security
We protect personal information with technical and organisational measures appropriate to a financial service: every connection to the Service is encrypted in transit; sessions are handled on the server; phone numbers are encrypted in our database; access to production systems is limited to the people who operate them; and our forms carry rate limits and bot detection. A description of our web architecture is published on the security page.
We hold no compliance certification and claim none. No system is perfectly secure, and we do not promise that yours will not be breached. If a breach affects your personal information, we will tell you and the authorities the law requires us to tell, without undue delay once we know what happened and what it means for you.
14.1 What you are responsible for
- Keep your password, your authenticator and your recovery codes to yourself. Gether never asks for them by email, text or phone, and a message that does is not from us.
- A verification code is for you alone. Do not read it to anyone or type it anywhere but the Gether screen that asked for it.
- Keep the email address and phone number on your account current. Notices sent to the details on your account count as delivered to you.
- Tell us at once if you believe someone else has used your account, your card or your number.
- Information you publish yourself, including a wallet address, a screenshot or a statement, is outside this policy once published.
15. Children
The Service is not directed to children. You must be at least eighteen years old to join the waitlist, sign up for text messages, or open an account. We do not knowingly collect personal information from anyone under eighteen. If you believe a child has given us information, contact us and we will delete what we are permitted to delete.
16. Links to other sites and services
The websites and the app link to other sites, including our partners' hosted verification flow, public blockchain explorers, and app stores. This policy does not cover those sites, and we are not responsible for their practices. Read their policies before you give them anything.
17. Changes to this policy
The version and date at the top are the version and date of the policy in effect. When we change this policy we publish the new version at the same address and keep the previous version available on request. Where a change materially affects how we use or share your information, we tell you before it takes effect, by email or by a notice in the app, and we record which version you were shown and when. Continuing to use the Service after a change takes effect means the new version applies to you; if you do not agree, stop using the Service and ask us to delete what we can.
18. Other documents
- SMS Terms: gethr.link/sms/terms. SMS Privacy Notice, standalone: gethr.link/sms/privacy.
- Terms of Service, Consent to Electronic Records and Signatures, and Account and Cardholder Agreement: under gethr.link/legal, where each is marked with its status on its own page. This Privacy Policy is in effect regardless of the status of those documents. If this policy and another document disagree about personal information, this policy governs.
- Security page: gethr.link/security.
- You can ask for this policy in another format, such as large print or plain text, by emailing us.
19. Contact
Email support@trygether.com for anything in this policy: a question, a request under section 12, a complaint, or a report of a security problem. Put "privacy" in the subject line. More ways to reach us are on gethr.link/support.