Friendlore Privacy Policy
Draft. This text has not been reviewed by a lawyer yet and may still change. Text in [brackets] is still to be filled in. This is an English translation of the Dutch text; if they differ, the Dutch text applies.
In short
- Friendlore is an app for planning events and sharing them with people you follow.
- We only use your data to make the app work, to keep the app safe, and because the law sometimes requires it. We do not sell your data, and we do not show ads.
- What you share is seen by other users, depending on your settings: everyone sees your name, profile photo and bio; only the people allowed to see them see your events and photos.
- Your data is stored on servers in the European Union.
- You can always delete your account and almost all of your data yourself in the app (what we still keep is in section 7).
- If you flag something as inappropriate (a report), we keep a copy of what you report. That copy stays even if its creator deletes it, so we can handle the report properly. Afterwards we delete the copy (see "How long do we keep your data?").
- You must be at least 13 to use Friendlore. If you are under 16, your account is private, and it stays that way until you turn 16.
Below you can read everything in detail.
1. Who are we?
Friendlore is offered by:
Ruud van Zwieten
Loenen aan de Vecht
Email: privacy@friendlore.app
We are the controller of your personal data: we decide why and how your data is processed. We have no data protection officer (DPO), because we are not required to have one. For any privacy question you can email privacy@friendlore.app.
2. What data do we use, for what, and on what basis?
The law (the GDPR) says we need a legal basis for every use of your data. We use these bases:
- Contract (Article 6(1)(b) GDPR): we need the data to provide the app you use.
- Legitimate interest (Article 6(1)(f) GDPR): we have a good reason, for example keeping the app safe. We have weighed that your interests do not outweigh it. You may object to this (see section 8).
- Legal obligation (Article 6(1)(c) GDPR): the law requires it, for example the EU Digital Services Act (DSA) for reports of illegal content.
| Data | What for | Basis |
|---|---|---|
| Account data: email address, password (we only keep an encrypted version, never the password itself), display name | Creating your account, signing in, resetting your password, sending you the emails that come with your account (confirmation, forgotten password) | Contract |
| Date of birth | Checking that you are old enough, and keeping accounts under 16 private. Your date of birth is never shown to others, and you cannot see or change it in the app either. | Legitimate interest (protecting the minimum age and minors) |
| Agreement to the terms: which version and when | Being able to show that you agreed, and asking you to agree again when the terms change | Legitimate interest |
| Profile: display name, bio, profile photo, whether your account is private, who may tag you, who may invite you | Showing your profile to others, and applying your settings | Contract |
| Events you create: title, description, location (the text you enter yourself, and optionally a city), start and end time, category, cover photo, who may see it and who may join | Showing your event to the people allowed to see it | Contract |
| Attendance and invitations: whether you are going to an event, who you invite, who invites you, and your answer | Showing the guest list, delivering invitations, letting the organizer see who is coming | Contract |
| Following: who you follow, who follows you, follow requests | Filling your feed, protecting private accounts | Contract |
| Moments: photos (1 to 5 per moment), caption, who you tag, likes and comments | Showing your photos to the people allowed to see your profile | Contract |
| Updates from organizers, and whether you muted them | Keeping people who are going to an event informed | Contract |
| In-app notifications and your feed: what happens around you and the people you follow (for example "X is going to Y", "the time of Y has changed") | Showing you what is new | Contract |
| Blocks: who you blocked | Making sure you no longer see each other's content | Contract and legitimate interest (safety) |
| Reports (when someone flags content or an account as inappropriate): who reports, what is reported, the reason and any explanation, and a copy of the reported content (text and photos) | Assessing and handling reports (required by the DSA, Articles 16 and 17), also when the creator has deleted the content in the meantime; keeping evidence for an appeal, a legal dispute or a police request | Legal obligation for the handling (DSA Articles 16 and 17). For keeping the copy after deletion: legitimate interest (a safe platform, being able to assess appeals properly) and establishing or defending legal claims (Article 17(3)(e) GDPR) |
| Moderation decisions: which measure we took (for example content removed, account suspended), why, and who decided | Sending you an explanation, making an appeal possible, recognising repeated violations | Legal obligation (DSA Article 17) and legitimate interest |
| Security and abuse: your user id in counters that track how often you do something (such as reporting or inviting), IP address in our server's log files | Preventing spam and abuse, detecting outages and attacks | Legitimate interest |
| Crash reports: what went wrong, your phone's model and Android version, the app version. Not your name, email address, user id or IP address. | Finding and fixing bugs in the app | Legitimate interest |
| Speed measurements: how long a screen took to load, without a user id | Keeping the app fast | Legitimate interest |
| [IF PUSH NOTIFICATIONS ARE IN V1] A device token for push notifications | Sending you a notification on your phone, for example for an invitation | Contract. You can turn push notifications off in your phone settings. |
| Contact with us: your email and what you write to us | Handling your question, request or objection | Contract and legitimate interest |
We do not use your data for: advertising, selling it to others, or profiling. We take no decisions about you that are made only by a computer (Article 22 GDPR). A human always decides on reports. Automatic limits (for example a maximum number of reports per hour) only limit how often you can do something.
Sensitive data: we never ask for sensitive data such as your religion, health or sexual orientation. Note: a photo or event you share can sometimes say something about this. Think about that before you share something.
Location: the app does not use your phone's GPS. An event's location is only the text you type yourself. For photos we remove the location data (EXIF) before they are stored.
3. Who can see what?
| What | Who sees it |
|---|---|
| Your display name and profile photo | All Friendlore users, also if your account is private. Other users can find you by name through search. |
| Your bio | All users, also if your account is private |
| Your moments and the lists on your profile (events you organize and events you are going to) | Everyone for a public account. For a private account only your followers. Everyone sees your name, profile photo, bio and the number of followers and people you follow. |
| That you are going to a particular event | For a public account: everyone who may see that event, through the guest list. For a private account: only your followers and the event's organizer. Others only see that one more person is going (the count). |
| Your followers and following lists | Everyone for a public account; for a private account only you and your followers. The number of followers is always visible. |
| An event | Depending on what you choose: everyone (public), your followers, or invited people only. People who are going or invited can also see the event. |
| Who is going to an event | Everyone who may see the event. People with a private account are only on the guest list for their followers and the organizer. |
| Who is invited and who chose "not going" | Only the organizer |
| Your date of birth | Nobody |
| What you report | Only our moderators. The person you report is not told who reported them. |
| Who you blocked | Only you |
Someone you block can no longer see your content, and you no longer see theirs.
4. Who receives your data?
We do not sell your data. We do use companies that help us run the app. They are processors: they may only use your data for us, and we have a data processing agreement with them.
| Party | What they do | Where |
|---|---|---|
| Supabase Inc. | The database, sign-in, photo storage and our server functions | The data is in an Amazon Web Services data centre in Paris (France). Supabase is an American company (see section 5). |
| [EMAIL PROVIDER] | Sending emails about your account | [COUNTRY/REGION], TODO |
| Sentry (Functional Software Inc.) | Crash reports | Frankfurt (Germany), TODO: confirm once set up |
| Canny (Canny Inc.) | Our feedback board. It opens in your browser only when you tap Give feedback; the app itself sends nothing to Canny. On the board, Canny receives your IP address, browser details and cookies, and what you choose to post there (your name and email address if you sign in on the board, your ideas, comments and votes). | United States (see section 5) |
| Distributing the app through Google Play. Google uses data as an independent controller for this, under Google's privacy policy. Also: hosting our website (Firebase Hosting) [and push notifications through Firebase Cloud Messaging, if they are in v1]. | Worldwide (see section 5) |
We may also have to share data with the police, the courts or a regulator when the law requires it. If we suspect that someone's life or safety is in danger, we report it to the police (DSA Article 18).
5. Does your data leave the European Union?
Your data is stored in the European Union. Some of our processors are American companies (Supabase, Sentry, Google, Canny). They may therefore be able to access data from the United States, for example for maintenance or support. Canny stores the data of the feedback board in the United States. That is only allowed with appropriate safeguards:
- the EU-US Data Privacy Framework, if the company is certified under it (a decision of the European Commission, Article 45 GDPR), or
- the European Commission's standard contractual clauses (Article 46 GDPR).
TODO (lawyer): determine per processor which safeguard applies, and whether a transfer impact assessment is needed.
6. How long do we keep your data?
| Data | How long |
|---|---|
| Your account, profile and everything you share | As long as your account exists. If you delete something (an event, a moment, a comment), it is gone at once; photos are wiped from storage within minutes. |
| Your account after deletion | Deleted at once (see section 7). |
| In-app notifications and your feed | [12 months], then deleted automatically |
| Invitations to events that are over | [30 days] after the event |
| Reports, and the copy of the reported content | Until 180 days after our last decision on the report. That is the period in which an appeal is possible. Longer only if an appeal, legal proceedings or a police request is running at that moment; then until it is finished. After that we delete the copy and keep only anonymous figures (type of report, outcome, date). |
| Moderation decisions | Until [6 months] after the decision; longer if an appeal or proceedings are running. After that only anonymous figures. For a permanent ban we keep an encrypted (hashed) version of the email address and the reason for the ban for [2 years], to prevent someone from creating a new account straight away. TODO (lawyer): confirm the period and the data. |
| Abuse counters | 24 hours |
| Speed measurements | 30 days |
| Crash reports | 30 days |
| Server logs (with IP address) | [TODO: fill in Supabase's period] |
| Backups | [7] days. Data you delete may therefore still be in a backup for up to [7] days, which is only used to restore the service after an outage. |
| Data of a sign-up you did not finish (on your phone) | At most 30 days |
| An account whose sign-up was not finished (for example because you are too young) | Deleted automatically after [30 days] |
| Emails you send us | As long as needed to handle your question, and then at most [12 months] |
7. Deleting your account
You can always delete your account yourself: Settings → Delete account. You have to enter your password for this. Can you no longer use the app? Then you can request deletion through https://friendlore.app/en/delete-account or by emailing privacy@friendlore.app.
What happens then:
- Deleted at once: your account, your profile, your events, your moments and photos, your comments and likes, your attendance, invitations, follow relations, blocks and the notifications you received.
- People who were going to your upcoming events get a notification that the event is cancelled. That notification still contains the event's title and location, but no longer your name.
- What we still keep:
- reports that others made about you or your content, with the copy of the reported content, for as long as section 6 says;
- reports you made, with the copy, but without your name;
- moderation decisions about your account, for as long as section 6 says;
- data in backups, for at most [7] days.
8. Your rights
You have these rights:
- Access (Article 15 GDPR): knowing what data we have about you.
- Rectification (Article 16): having incorrect data corrected. You can change most things yourself in the app. Did you enter a wrong date of birth? Email us.
- Erasure (Article 17): see section 7.
- Restriction (Article 18): asking us to temporarily do less with your data, for example while we investigate a complaint.
- Portability (Article 20): receiving your data in a file you can take with you.
- Objection (Article 21): objecting to use based on legitimate interest.
Send your request to privacy@friendlore.app, from your account's email address. That way we know the request comes from you. We respond within one month. If the request is complicated, this can be extended by two months; we will tell you so within the first month. A request is free.
Complaint? If you cannot resolve it with us, you can file a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens (www.autoriteitpersoonsgegevens.nl), or with the privacy regulator in the EU country where you live.
9. Minimum age
You must be at least 13 to use Friendlore. We ask for your date of birth when you sign up. If you are younger, you cannot create an account. After such a refusal you cannot enter another date of birth for 24 hours; for that we keep only the time of the refusal (not the date you entered), on your device and, if you already have an account, with your account. After the 24 hours it is deleted (on your device the next time the app is opened). If we find out that someone is under 13, we delete the account. Are you a parent or guardian and do you think your child under 13 has an account? Email us at privacy@friendlore.app.
If you are 13, 14 or 15, your account is always private: only followers you approve see your events and moments. You can only make your account public once you are 16.
10. Security
- All connections between the app and our servers are encrypted (HTTPS).
- Passwords are only stored encrypted (hashed).
- Photos are kept in protected storage. Only people allowed to see a photo get a temporary link.
- Access to data is protected in the database itself: the app can only see what you are allowed to see.
- Moderators work in an admin environment they sign in to with an extra security step (two-factor authentication). Every measure they take is recorded.
Does something go wrong anyway (a data breach)? Then we report it to the Autoriteit Persoonsgegevens within 72 hours when required. If there is a high risk for you, we will tell you too.
11. Data on your phone
The app keeps a few things on your phone, so that it works quickly and well:
- your sign-in session, so you stay signed in;
- a copy of your feed and notifications, so the app opens quickly. The app uses that copy for at most 3 minutes; it is wiped when you sign out and when you delete your account;
- if you have not finished signing up yet: your email address, your name, your date of birth and your agreement to the terms, for at most 30 days.
This is needed to make the app work. That is why we do not ask for separate consent. The app uses no advertising or tracking cookies.
12. Changes to this privacy policy
We may change this privacy policy, for example when the app changes. For an important change we will tell you in advance in the app, and by email. The date and version number at the top show which version applies. Earlier versions are at https://friendlore.app/en/privacy/archive.
Note: for a change to the terms of use we do ask you to agree again (see the terms of use). You do not have to accept this privacy policy: it explains what we do.
13. Contact
Ruud van Zwieten
Loenen aan de Vecht
Email: privacy@friendlore.app