Iboga Retreat

Privacy policy

Last updated: 1 October 2026 · Controller: George Gache

A retreat is built on trust, so we say plainly what data we take, why, how long we keep it and how you can delete it. If anything stays unclear, write to [email protected] and a person will answer.

Who we are

The website ibogajourney.net is operated by George Gache, a private individual. He decides what data is collected and why, so he is the data controller under the GDPR. For any question or request about your data, write to [email protected].

What we take, and why

When you apply or join the waiting list through the form on the site: your email address (required) and, if you choose to write them, your name, phone number and a message. Along with them we keep the edition you applied for, the language you filled the form in and the IP address you sent it from, to stop automated sign-ups. We use them to contact you for an interview and to tell you about the edition you chose.

At the interview. Every applicant is met personally, in a video interview, before the retreat. There we may ask about your health (including your heart), the medication you take, your use of substances and your psychological history, because whether the retreat is safe for you depends on them. If you are accepted, we also ask for an ECG and medical documents. This is health data, which is sensitive data. We process it only with your explicit consent and only to decide whether the retreat suits you and to prepare you safely. We do not publish it, we do not use it in marketing, and we pass it only to the people on the team who need it for your safety.

If you take part: the data needed to organise travel and your stay (name, contact details, flight details, room preferences) and, on site, the information needed for your safety.

When you write to us by email or WhatsApp: we receive your address or number and what you tell us, and we use it to answer you.

When you visit the site: our hosting provider, Cloudflare, sees your IP address and basic technical data from your browser, as any web server does, to deliver the site and keep it safe.

If you press “Accept all” in the cookie banner, Google Analytics, Microsoft Clarity and Meta Pixel are switched on: they receive data about your visit (pages viewed, device type, length of the visit and, for Clarity, clicks and scrolling on the page). Without “Accept all” these services are not loaded at all. We also use aggregate statistics that store no cookies and do not identify you: Cloudflare Web Analytics, Umami and Plausible.

What we don't do: we don't ask for data we don't use, we don't make automated decisions about you, and we never sell or rent data to anyone.

Meta Pixel and the form. If you pressed “Accept all”, Meta Pixel sends Meta your visit and the fact that you submitted the application form. For this collection we are joint controllers with Meta; what Meta then does with the data is Meta's responsibility (facebook.com/privacy/policy). Without “Accept all”, nothing is sent.

Research. The study at ibogaresearch.eu is a separate project with its own information notice. The notice on that site applies to it.

Legal basis

Where it goes

The request sent from the form passes through a function of the site and lands in our registration system, on a server run by ai-AI on our behalf. If our server cannot be reached at that moment, the request waits in Cloudflare storage until we pick it up, so it is not lost. Emails to you are sent from [email protected].

The providers who touch the data, each with their role:

Some of these providers are based outside the European Economic Area, mostly in the United States, and the retreat takes place in Tanzania. Where that is the case, the transfer relies on the safeguards the provider offers (the EU–US Data Privacy Framework or standard contractual clauses). The data the team in Zanzibar (Tanzania) needs reaches them because it is necessary for you to take part in the retreat you asked for (Art. 49(1)(b) GDPR); for health data we ask for your explicit consent to this transfer as well (Art. 49(1)(a)), after we have told you that Tanzania does not have a level of protection recognised by the EU. Telegram is not covered by the safeguards above: we use it only for internal notifications, and if you don't want your details to pass through it, write to us by email instead of using the form.

How long we keep it

What you can ask for

You have the right to know what data we hold about you, to correct it, to have it deleted, to ask us to stop using it, to receive it in a file you can take elsewhere, and to object to processing. You can withdraw a consent at any time, without affecting what happened before.

Write to [email protected]. We answer within a month at the latest, usually much sooner, and it is free.

If we answer badly or not at all, you can complain to the Romanian data protection authority, ANSPDCP, Bd. G-ral. Gheorghe Magheru 28-30, Bucharest, dataprotection.ro, or to the authority of your own country. We would rather sort it out with you directly, but the right is yours.

Children

The site and the retreat are for adults. We don't knowingly collect children's data. If you believe we hold any, tell us and we will delete it.

When this page changes

The date at the top is the last change. If we change something that matters (what we collect, why, or who receives it), we won't count on you coming back to check: we will announce it on the site.

See also the cookie policy and the terms of use.

See the full retreat

All the details of the next edition — dates, price, what's included, who guides you and how to apply — are on the main page.

The 25 March – 1 April 2027 retreat →
Limited to 12 people, by interview.
Continue