At Frenby, the point is to help you meet people a few streets away, not to collect more about you than that takes. This policy sets out, as plainly as the law allows, what we collect, why, and how long we keep it. In short: we ask only for what the app needs, your neighbourhood location is rounded before it's ever saved, voice notes delete themselves on a timer and a location shared in a chat is removed an hour later, we never sell your data, and you can take your account, and everything in it, away whenever you like.
The controller within the meaning of Art. 4(7) GDPR is the provider of Frenby. Full identity, postal address and contact details are published in the Impressum (German legal notice, required under § 5 DDG), rather than repeated here.
| Data | Purpose | Lawful basis |
|---|---|---|
| Email address and password (stored only as a hash by Google) | Creating your account, signing in, password reset | Art. 6(1)(b) GDPR (contract) |
| If you use “Continue with Google”: your Google account identifier, email address, name and profile picture, as supplied to us by Google | Creating your account and signing you in. Your name prefills your profile and you can change it afterwards. The profile picture is stored on your Firebase authentication record but is not shown in the app; the photo on your profile is one you upload yourself | Art. 6(1)(b) GDPR (contract) |
| If you use “Continue with Apple”: your Apple account identifier and email address, plus your name if you choose to share it. Apple never sends us a profile picture. If you select “Hide My Email”, we only receive a relay address at privaterelay.appleid.com and never your real one | Creating your account and signing you in | Art. 6(1)(b) GDPR (contract) |
| Display name | Showing your profile to other users | Art. 6(1)(b) GDPR |
| Date of birth (day, month, year) | Checking the 18+ age requirement; your age is shown only if you enable it | Art. 6(1)(c) and (f) GDPR (youth protection, protecting the community) |
| Approximate location (rounded to roughly 70–111 m) and a geohash derived from it | Core feature: showing people near you and calculating distances | Art. 6(1)(a) GDPR (consent, via your operating system's location permission) |
| Neighbourhood (you choose it; suggested from your location) | Approximate area shown on your profile | Art. 6(1)(a) GDPR |
| First frenby badge: your display name, an area label (a roughly 5 km cell) and the time you claimed it | Publicly recording who was first in that area, for the badge feature | Art. 6(1)(b) GDPR (a feature you actively use) |
| Profile photo | Showing your profile | Art. 6(1)(a) GDPR |
| Optional profile details: about me, interests, languages, gender | Showing your profile, visibility filters | Art. 6(1)(a) GDPR |
| “Up for” status, optional note, expiry time | Telling others what you're up for | Art. 6(1)(b) GDPR |
| Visibility settings (visible to men / women / non-binary people) | Controlling who can see your profile | Art. 6(1)(b) GDPR |
| Last-active timestamp | Online status and “last seen” | Art. 6(1)(b) GDPR |
| Chat content: text messages, voice messages, shared locations | Delivering your messages to the person you're chatting with | Art. 6(1)(b) GDPR |
| Device push token (Firebase Cloud Messaging) | Notifying you about new messages and expiring statuses | Art. 6(1)(a) GDPR (notification permission) |
| Crash and stability reports (Firebase Crashlytics), technical performance data (Firebase Performance Monitoring) | Finding bugs and keeping the app stable | Art. 6(1)(f) GDPR (legitimate interest in a working service) |
| App usage events (screens viewed, features used) and automatically-collected technical identifiers: an app-instance identifier, device and OS model, app version, and an approximate, city-level location derived from your IP address — coarser than, and separate from, the precise location in the row above (Firebase Analytics) | Understanding which features are used, so we can improve the app | Art. 6(1)(f) GDPR (legitimate interest in improving the service) |
| Device integrity attestation (Google Play Integrity on Android, Apple App Attest on iOS): a signal that a request comes from a genuine, unmodified copy of the app, not a message about you personally | Blocking bots, scripted abuse and tampered clients from calling our backend | Art. 6(1)(f) GDPR (legitimate interest in preventing abuse) |
| If someone reports you: the reason and any details they gave, a copy of your recent messages in that conversation, and a copy of your profile photo at that moment | Reviewing the report — see section 5 for how long this is kept | Art. 6(1)(f) GDPR (legitimate interest in community safety) |
We currently process no payment data (Frenby Plus is not yet purchasable) and run no advertising; because of that, we've turned off Advertising ID collection in Firebase Analytics; it never sees that identifier. We never sell your data. If either of that changes, we will update this policy before it does.
We use Google Firebase under a data processing agreement (Google Cloud Data Processing Addendum).
| Service | Purpose | Location |
|---|---|---|
| Cloud Firestore | Profiles, statuses, chat messages | EU multi-region eur3 (Belgium and the Netherlands) |
| Cloud Storage | Profile photos, voice messages | Germany (europe-west10, Berlin) |
| Cloud Functions | Sending chat notifications | Netherlands (europe-west4) |
| Cloud Functions | Erasing your data when an account is deleted | Belgium (europe-west1) |
| Firebase Authentication | Accounts and sign-in | Google global infrastructure; third-country transfer possible |
| Firebase Cloud Messaging | Push notifications | Google global infrastructure; third-country transfer possible |
| Crashlytics, Performance Monitoring | Crash and performance diagnostics | Google global infrastructure; third-country transfer possible |
| Firebase Analytics | App usage analytics | Google global infrastructure; third-country transfer possible |
| Firebase App Check (Play Integrity / App Attest) | Verifying requests come from a genuine copy of the app | Google global infrastructure; third-country transfer possible |
Your profile, chat and media data therefore stay in the EU. For the account-related and diagnostic services, transfer to the USA cannot be ruled out; Google relies on the EU–US Data Privacy Framework and on Standard Contractual Clauses (Art. 45, 46 GDPR).
Apple is not in this table because Apple is not our processor. If you sign in with Apple, Apple processes that authentication under its own responsibility and on its own legal bases, in the USA. When you delete an account created with Apple, the iOS app additionally sends Apple a revocation request so that Frenby's access to your Apple Account ends; on Android that revocation is not yet possible, so you can remove Frenby yourself under Settings > Apple Account > Sign in with Apple.
You can withdraw any permission at any time in your device settings.
Please send requests to privacy@frenby.com. You may also complain to a supervisory authority. For Berlin, the Berlin Commissioner for Data Protection and Freedom of Information. If you are outside Germany, see section 10 for the equivalent rights and the regulator where you live.
In the app: You → Settings → Delete account, then confirm. If you can't get into the app, email privacy@frenby.com from the address your account is registered with and include your display name so we can find the right one; we may ask for a little extra proof that the account is really yours before we act on the request. Frenby will never ask you for your password, by this route or any other.
Deletion removes your authentication record, profile and profile photo, statuses, device push tokens, the messages and media you sent, and your First frenby badge claim (section 5 has the full retention picture). Messages someone else sent to you stay with them, since those are their data, not yours. The one exception: if a conversation was reported before you deleted your account, the copy of its recent messages already attached to that report (section 5) stays on the same 12-month schedule as any other report, since it exists to preserve evidence, not to keep your profile around. Your public profile still comes down immediately.
Frenby is for people aged 18 and over only. We check age at sign-up from the date of birth you provide. If we learn of an account belonging to a minor, we delete it. Please report concerns to report@frenby.com.
If you join the waitlist on our website, we store the email address you enter and, if you give one, your postcode, together with the time you signed up and the city your browser's time zone suggests. The postcode is optional and is there for one purpose: it tells us which neighbourhood has enough people waiting to be worth opening first.
Why we may do this: your consent, given by submitting the form (Art. 6(1)(a) GDPR). What we use it for: writing to you once, when Frenby opens in your area, and nothing else. We do not sell or share these addresses, and they are not merged with any app account. How long: until we have written to you about the launch, or until you ask us to remove you, whichever comes first, and in any case no longer than 24 months. Withdrawing: every email we send carries an unsubscribe link, and you can write to privacy@frenby.com at any time to be deleted from the list. Withdrawing consent does not affect anything we did before you withdrew it.
The entry is stored in the same EU Firestore database as the rest of our data (see sections 4 and 10). The website writes it directly; nobody can read the list back from a browser.
We update this policy when the app or the law changes. The current version is always at this address; the date above shows when it last changed.
Frenby is operated from Germany and built to the GDPR standard. We apply that standard to everyone, wherever you are: what we collect (section 2), who can see it (3), where it is stored (4), how long we keep it (5) and the rights in section 7 are the same for every user. This section adds what your local law gives you on top of that, and names the regulator you can complain to.
The GDPR applies in full and this policy is written to it, so nothing here is additional. Our lead supervisory authority is the Berlin Commissioner for Data Protection and Freedom of Information, and you may complain there or to the supervisory authority in your own country of residence, whichever you prefer.
The UK GDPR and the Data Protection Act 2018 apply. Your rights are the same ones listed in section 7, under the same names. Complaints go to the Information Commissioner's Office (ICO), or to us first at privacy@frenby.com. Your profile, chat and media data are stored in the EU (section 4), which is a transfer out of the UK; the UK recognises the EU as providing an adequate level of protection, so no additional safeguard is needed for it.
The Personal Information Protection and Electronic Documents Act (PIPEDA) applies. You can ask for access to the personal information we hold about you, ask us to correct it, and withdraw your consent at any time, which for the location-based features means the app can no longer show you people nearby. Complaints go to the Office of the Privacy Commissioner of Canada (OPC).
Quebec. Law 25 adds rights, including data portability and the right to be informed about decisions made solely by automated processing. We make no decisions about you by automated means that produce legal or similarly significant effects: reports are reviewed by a person (section 7 of the Terms of Use), and matching is only distance-based.
There is no single federal privacy law. Several states give their residents rights over personal information, most prominently California under the CCPA as amended by the CPRA, with comparable laws in states including Virginia, Colorado, Connecticut, Utah and Texas. Where one of those laws applies to you, you have the right to know what we hold and access it, to have it deleted, to have it corrected, to receive a portable copy, to opt out of targeted advertising, sale and profiling, and not to be treated worse for exercising any of these. To exercise them, write to privacy@frenby.com. You may use an authorised agent; we will ask for proof of their authority and enough information to confirm your identity before we act.
Sale and sharing. We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those two terms are defined in the CCPA. Frenby runs no advertising at all today (section 2). If that ever changes, we will update this policy before it does and provide the opt-out mechanism the law requires at that point.
Sensitive personal information. Several of these laws treat precise geolocation as sensitive. Your profile location is rounded to roughly 70–111 m before it is stored and is only ever shown to others as a calculated distance; a location you actively share inside a chat is exact, and is deleted removed an hour after you send it (sections 2, 3 and 5). We do not use location to infer characteristics about you, and we do not use it for advertising.
The Privacy Act 1988 and the Australian Privacy Principles apply. Under APP 8 we have to tell you which countries our overseas recipients are in: your profile, chat and media data sit in Belgium, the Netherlands and Germany, and the account, push-notification and diagnostic services may involve the United States. Section 4 sets out which service is where.
Complaints should come to us first at privacy@frenby.com so we have a chance to fix the problem; if you are not satisfied with how we handle it, you can take the complaint to the Office of the Australian Information Commissioner (OAIC). Where a data breach is likely to result in serious harm, the Notifiable Data Breaches scheme requires us to notify both you and the OAIC, and we will.
Separately from privacy law, the eSafety Commissioner regulates online safety under the Online Safety Act 2021 and can order the removal of material such as image-based abuse. Our Safety Guide explains how to reach them.