Privacy Policy
Last updated: June 25, 2026
This policy describes how this application (the “Service”) collects, uses, stores, and protects personal information.
By using the Service, you acknowledge that you have read this Privacy Policy.
Data Controller
The data controller responsible for your personal data is:
Tzu Yao Chen
Helsingborg, Sweden
Email: karta14184@gmail.com
If you have questions about this policy or how we process personal data, contact us at the email above.
1. Data We May Collect
- Account and authentication: email address (if provided by you or your sign-in provider), display name, profile photo (if provided), unique account identifiers, and information received from authentication providers such as Google Sign-In or Sign in with Apple.
- Profile and preferences: avatar, bio, gender (if you choose to provide it), school or intended school, country/region selections, interest categories, and similar information you choose to provide.
- Content you create: posts, comments, in-app shares/reposts, meetup event details you submit, reports you file, and related timestamps.
- Anonymous mode: when you post or comment anonymously, your display name may be hidden from other users, but we may still store account identifiers and moderation-related metadata needed to operate the Service, enforce our policies, and investigate abuse.
- Meetup information: event titles, descriptions, dates/times, capacity, participation status, and location text you enter manually (such as municipality or address). The Service does not collect device GPS location for meetups unless a future version explicitly requests permission and this policy is updated.
- Device and technical data: device model, operating system version, app version, IP address, and basic diagnostic or performance data that our infrastructure providers may process when you use the Service.
- Push notification tokens if you enable notifications.
2. Purposes
We use information to:
- Provide, operate, maintain, and improve the Service;
- Rank and sort feeds (for example, by popularity or recency);
- Authenticate users and secure accounts;
- Moderate content and enforce our policies;
- Investigate abuse, fraud, security incidents, and violations of our terms;
- Communicate important updates, notices, and service-related information;
- Comply with legal obligations;
- Perform other purposes described in this policy or disclosed with your consent.
3. Where Data Is Stored
We use Google Firebase (including Authentication, Cloud Firestore, Cloud Storage, Cloud Messaging, and related services) and other infrastructure providers.
Data may be stored and processed in regions configured within our Google Cloud and Firebase projects, which may include the European Union or other jurisdictions.
4. Retention
We retain information for as long as necessary to fulfill the purposes described in this policy, provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements.
When information is no longer needed, we delete, anonymize, or securely dispose of it within a reasonable period, subject to legal retention requirements.
Reports submitted by users may be retained for moderation, safety, audit, and legal compliance purposes even after the reported content is removed.
5. Account Deletion
You may request deletion of your account and associated personal information through in-app settings (Manage accounts → Delete account), if available, or by contacting us.
When you delete your account, we will, within a reasonable period:
- Delete your Firebase Authentication account;
- Delete your primary profile documents (such as users/{uid} and publicProfiles/{uid});
- Delete certain account-linked data stored under your user profile (such as saved posts lists and push notification tokens).
Some information may remain after deletion where technically or legally necessary, including:
- Posts, comments, meetup records, or reports that were already stored in shared collections (these may remain visible but may no longer be linked to an active profile, depending on how the content was stored);
- Backups, logs, or security records retained for a limited period;
- Information we must retain to comply with law, prevent fraud, resolve disputes, or enforce our agreements.
6. Sharing
We do not sell personal information.
We may share information:
- With service providers and subprocessors that help operate the Service (such as Google Firebase / Google Cloud);
- When required by law, regulation, court order, or legal process;
- To protect rights, safety, security, users, or the public;
- In connection with a merger, acquisition, financing, reorganization, or sale of assets.
7. Your Rights (including GDPR)
If you are in the European Economic Area (EEA), the United Kingdom, or another jurisdiction with similar data protection laws, you may have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you;
- Rectification — request correction of inaccurate or incomplete data;
- Erasure — request deletion of your personal data in certain circumstances;
- Restriction — request that we limit processing in certain circumstances;
- Objection — object to processing based on our legitimate interests;
- Data portability — request a copy of certain data in a structured, commonly used, machine-readable format;
- Withdraw consent — where processing is based on consent, withdraw consent at any time (this does not affect the lawfulness of processing before withdrawal).
To exercise these rights, contact:
Tzu Yao Chen
karta14184@gmail.com
We will respond to valid requests within one (1) month, as required by the GDPR. That period may be extended by up to two (2) additional months where necessary, considering the complexity and number of requests. We will inform you if an extension is needed.
We may need to verify your identity before responding. We will not charge a fee for exercising your rights unless your request is manifestly unfounded or excessive.
Right to lodge a complaint
If you believe our processing of your personal data violates applicable law, you have the right to lodge a complaint with a supervisory authority.
If you are in Sweden, you may contact:
Integritetsskyddsmyndigheten (IMY)
Website: https://www.imy.se
If you are in another EEA country, you may also lodge a complaint with the data protection authority in your country of habitual residence, place of work, or place of the alleged infringement.
Automated decision-making
We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
8. Children
The Service is not directed to individuals under sixteen (16) years of age, or under the minimum age required by applicable law in your jurisdiction, whichever is higher.
We do not knowingly collect personal information from children under the minimum age required by applicable law.
If you believe a child has provided personal information in violation of this policy, please contact us and we will take appropriate action.
9. Legal Bases for Processing (GDPR)
Where the GDPR applies, we process personal information on one or more of the following legal bases:
- Contract — processing necessary to provide the Service you request (Article 6(1)(b) GDPR);
- Legal obligation — processing necessary to comply with applicable law (Article 6(1)(c) GDPR);
- Legitimate interests — operating, securing, moderating, and improving the Service, preventing abuse, and protecting users, where those interests are not overridden by your rights (Article 6(1)(f) GDPR);
- Consent — where required, such as for optional features or communications based on consent (Article 6(1)(a) GDPR).
You may withdraw consent at any time where processing is based on consent, subject to applicable law.
10. Public Content
The Service is a social platform that allows users to publish content visible to other users.
Information you choose to make public, including posts, comments, profile information, usernames, avatars, meetup details, and other public content, may be viewed, copied, shared, quoted, archived, indexed, or reposted by other users or third parties.
When you use anonymous mode, other users may see an anonymous label instead of your display name, but you should still treat your content as potentially identifiable or traceable for moderation and safety purposes.
Please carefully consider what information you choose to publish publicly.
11. Security
We implement reasonable technical, administrative, and organizational measures designed to protect personal information against unauthorized access, disclosure, alteration, loss, misuse, or destruction.
However, no method of electronic transmission, storage, or security measure is completely secure, and we cannot guarantee absolute security.
12. International Transfers
Your personal data may be processed in countries outside your country of residence, including countries that may not provide the same level of data protection as your home jurisdiction.
Where personal data is transferred from the EEA or UK to countries without an adequacy decision, we rely on appropriate safeguards as required by applicable law, such as standard contractual clauses approved by the European Commission or equivalent mechanisms offered by our infrastructure providers (including Google Cloud / Firebase).
13. Changes to This Policy
We may update this Privacy Policy from time to time.
Material changes will be communicated through the Service or by other reasonable means.
The updated version becomes effective when posted.
14. Contact
For privacy-related questions, data subject requests, or complaints, contact:
Tzu Yao Chen
Helsingborg, Sweden
karta14184@gmail.com