Friendlore

Friendlore Privacy Policy

Draft. This text has not been reviewed by a lawyer yet and may still change. Text in [brackets] is still to be filled in. This is an English translation of the Dutch text; if they differ, the Dutch text applies.


In short

Below you can read everything in detail.


1. Who are we?

Friendlore is offered by:

Ruud van Zwieten
Loenen aan de Vecht
Email: privacy@friendlore.app

We are the controller of your personal data: we decide why and how your data is processed. We have no data protection officer (DPO), because we are not required to have one. For any privacy question you can email privacy@friendlore.app.

2. What data do we use, for what, and on what basis?

The law (the GDPR) says we need a legal basis for every use of your data. We use these bases:

DataWhat forBasis
Account data: email address, password (we only keep an encrypted version, never the password itself), display nameCreating your account, signing in, resetting your password, sending you the emails that come with your account (confirmation, forgotten password)Contract
Date of birthChecking that you are old enough, and keeping accounts under 16 private. Your date of birth is never shown to others, and you cannot see or change it in the app either.Legitimate interest (protecting the minimum age and minors)
Agreement to the terms: which version and whenBeing able to show that you agreed, and asking you to agree again when the terms changeLegitimate interest
Profile: display name, bio, profile photo, whether your account is private, who may tag you, who may invite youShowing your profile to others, and applying your settingsContract
Events you create: title, description, location (the text you enter yourself, and optionally a city), start and end time, category, cover photo, who may see it and who may joinShowing your event to the people allowed to see itContract
Attendance and invitations: whether you are going to an event, who you invite, who invites you, and your answerShowing the guest list, delivering invitations, letting the organizer see who is comingContract
Following: who you follow, who follows you, follow requestsFilling your feed, protecting private accountsContract
Moments: photos (1 to 5 per moment), caption, who you tag, likes and commentsShowing your photos to the people allowed to see your profileContract
Updates from organizers, and whether you muted themKeeping people who are going to an event informedContract
In-app notifications and your feed: what happens around you and the people you follow (for example "X is going to Y", "the time of Y has changed")Showing you what is newContract
Blocks: who you blockedMaking sure you no longer see each other's contentContract and legitimate interest (safety)
Reports (when someone flags content or an account as inappropriate): who reports, what is reported, the reason and any explanation, and a copy of the reported content (text and photos)Assessing and handling reports (required by the DSA, Articles 16 and 17), also when the creator has deleted the content in the meantime; keeping evidence for an appeal, a legal dispute or a police requestLegal obligation for the handling (DSA Articles 16 and 17). For keeping the copy after deletion: legitimate interest (a safe platform, being able to assess appeals properly) and establishing or defending legal claims (Article 17(3)(e) GDPR)
Moderation decisions: which measure we took (for example content removed, account suspended), why, and who decidedSending you an explanation, making an appeal possible, recognising repeated violationsLegal obligation (DSA Article 17) and legitimate interest
Security and abuse: your user id in counters that track how often you do something (such as reporting or inviting), IP address in our server's log filesPreventing spam and abuse, detecting outages and attacksLegitimate interest
Crash reports: what went wrong, your phone's model and Android version, the app version. Not your name, email address, user id or IP address.Finding and fixing bugs in the appLegitimate interest
Speed measurements: how long a screen took to load, without a user idKeeping the app fastLegitimate interest
[IF PUSH NOTIFICATIONS ARE IN V1] A device token for push notificationsSending you a notification on your phone, for example for an invitationContract. You can turn push notifications off in your phone settings.
Contact with us: your email and what you write to usHandling your question, request or objectionContract and legitimate interest

We do not use your data for: advertising, selling it to others, or profiling. We take no decisions about you that are made only by a computer (Article 22 GDPR). A human always decides on reports. Automatic limits (for example a maximum number of reports per hour) only limit how often you can do something.

Sensitive data: we never ask for sensitive data such as your religion, health or sexual orientation. Note: a photo or event you share can sometimes say something about this. Think about that before you share something.

Location: the app does not use your phone's GPS. An event's location is only the text you type yourself. For photos we remove the location data (EXIF) before they are stored.

3. Who can see what?

WhatWho sees it
Your display name and profile photoAll Friendlore users, also if your account is private. Other users can find you by name through search.
Your bioAll users, also if your account is private
Your moments and the lists on your profile (events you organize and events you are going to)Everyone for a public account. For a private account only your followers. Everyone sees your name, profile photo, bio and the number of followers and people you follow.
That you are going to a particular eventFor a public account: everyone who may see that event, through the guest list. For a private account: only your followers and the event's organizer. Others only see that one more person is going (the count).
Your followers and following listsEveryone for a public account; for a private account only you and your followers. The number of followers is always visible.
An eventDepending on what you choose: everyone (public), your followers, or invited people only. People who are going or invited can also see the event.
Who is going to an eventEveryone who may see the event. People with a private account are only on the guest list for their followers and the organizer.
Who is invited and who chose "not going"Only the organizer
Your date of birthNobody
What you reportOnly our moderators. The person you report is not told who reported them.
Who you blockedOnly you

Someone you block can no longer see your content, and you no longer see theirs.

4. Who receives your data?

We do not sell your data. We do use companies that help us run the app. They are processors: they may only use your data for us, and we have a data processing agreement with them.

PartyWhat they doWhere
Supabase Inc.The database, sign-in, photo storage and our server functionsThe data is in an Amazon Web Services data centre in Paris (France). Supabase is an American company (see section 5).
[EMAIL PROVIDER]Sending emails about your account[COUNTRY/REGION], TODO
Sentry (Functional Software Inc.)Crash reportsFrankfurt (Germany), TODO: confirm once set up
Canny (Canny Inc.)Our feedback board. It opens in your browser only when you tap Give feedback; the app itself sends nothing to Canny. On the board, Canny receives your IP address, browser details and cookies, and what you choose to post there (your name and email address if you sign in on the board, your ideas, comments and votes).United States (see section 5)
GoogleDistributing the app through Google Play. Google uses data as an independent controller for this, under Google's privacy policy. Also: hosting our website (Firebase Hosting) [and push notifications through Firebase Cloud Messaging, if they are in v1].Worldwide (see section 5)

We may also have to share data with the police, the courts or a regulator when the law requires it. If we suspect that someone's life or safety is in danger, we report it to the police (DSA Article 18).

5. Does your data leave the European Union?

Your data is stored in the European Union. Some of our processors are American companies (Supabase, Sentry, Google, Canny). They may therefore be able to access data from the United States, for example for maintenance or support. Canny stores the data of the feedback board in the United States. That is only allowed with appropriate safeguards:

TODO (lawyer): determine per processor which safeguard applies, and whether a transfer impact assessment is needed.

6. How long do we keep your data?

DataHow long
Your account, profile and everything you shareAs long as your account exists. If you delete something (an event, a moment, a comment), it is gone at once; photos are wiped from storage within minutes.
Your account after deletionDeleted at once (see section 7).
In-app notifications and your feed[12 months], then deleted automatically
Invitations to events that are over[30 days] after the event
Reports, and the copy of the reported contentUntil 180 days after our last decision on the report. That is the period in which an appeal is possible. Longer only if an appeal, legal proceedings or a police request is running at that moment; then until it is finished. After that we delete the copy and keep only anonymous figures (type of report, outcome, date).
Moderation decisionsUntil [6 months] after the decision; longer if an appeal or proceedings are running. After that only anonymous figures. For a permanent ban we keep an encrypted (hashed) version of the email address and the reason for the ban for [2 years], to prevent someone from creating a new account straight away. TODO (lawyer): confirm the period and the data.
Abuse counters24 hours
Speed measurements30 days
Crash reports30 days
Server logs (with IP address)[TODO: fill in Supabase's period]
Backups[7] days. Data you delete may therefore still be in a backup for up to [7] days, which is only used to restore the service after an outage.
Data of a sign-up you did not finish (on your phone)At most 30 days
An account whose sign-up was not finished (for example because you are too young)Deleted automatically after [30 days]
Emails you send usAs long as needed to handle your question, and then at most [12 months]

7. Deleting your account

You can always delete your account yourself: Settings → Delete account. You have to enter your password for this. Can you no longer use the app? Then you can request deletion through https://friendlore.app/en/delete-account or by emailing privacy@friendlore.app.

What happens then:

8. Your rights

You have these rights:

Send your request to privacy@friendlore.app, from your account's email address. That way we know the request comes from you. We respond within one month. If the request is complicated, this can be extended by two months; we will tell you so within the first month. A request is free.

Complaint? If you cannot resolve it with us, you can file a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens (www.autoriteitpersoonsgegevens.nl), or with the privacy regulator in the EU country where you live.

9. Minimum age

You must be at least 13 to use Friendlore. We ask for your date of birth when you sign up. If you are younger, you cannot create an account. After such a refusal you cannot enter another date of birth for 24 hours; for that we keep only the time of the refusal (not the date you entered), on your device and, if you already have an account, with your account. After the 24 hours it is deleted (on your device the next time the app is opened). If we find out that someone is under 13, we delete the account. Are you a parent or guardian and do you think your child under 13 has an account? Email us at privacy@friendlore.app.

If you are 13, 14 or 15, your account is always private: only followers you approve see your events and moments. You can only make your account public once you are 16.

10. Security

Does something go wrong anyway (a data breach)? Then we report it to the Autoriteit Persoonsgegevens within 72 hours when required. If there is a high risk for you, we will tell you too.

11. Data on your phone

The app keeps a few things on your phone, so that it works quickly and well:

This is needed to make the app work. That is why we do not ask for separate consent. The app uses no advertising or tracking cookies.

12. Changes to this privacy policy

We may change this privacy policy, for example when the app changes. For an important change we will tell you in advance in the app, and by email. The date and version number at the top show which version applies. Earlier versions are at https://friendlore.app/en/privacy/archive.

Note: for a change to the terms of use we do ask you to agree again (see the terms of use). You do not have to accept this privacy policy: it explains what we do.

13. Contact

Ruud van Zwieten
Loenen aan de Vecht
Email: privacy@friendlore.app