Privacy Policy
What we collect, why, how long we keep it and what you can demand from us. Written for the app and this website. If something here is unclear, ask — the address is at the bottom.
Effective from 2026-09-01
1. Who is the controller
The controller is the person or company named on the Contact page. That page also carries the registered address and company number.
Write to [email protected] with anything about your data. We have not appointed a data protection officer; we are not required to.
2. What we process
Grouped by why it exists, not by where it is stored.
- Account: e-mail address, username, display name, profile picture, language, and whether you have Frinity+ (including the customer identifier from the payment provider).
- Content: events you create or join — name, description, place name and coordinates, time — and the photos and videos you upload, together with their size, length, dimensions and the caption you write.
- Interactions: reactions to media, the record that you have seen a photo, friendships, crews, blocks and reports.
- Location: while the app is open and you have location sharing on, your current position, so friends can see you on the map. Separately, the territory an event took place in, which is what colours your map.
- Verification: when an event is verified, the fact that several people were in one place at one time, plus a device identifier used to stop two accounts verifying from the same phone.
- Device: the push notification token, so we can deliver notifications.
- Usage: anonymous-in-content but account-linked events such as “app opened” or “event created”, used to see which parts of the app people actually use.
3. Why we may process it
- To provide the service you signed up for — account, events, media, friends, notifications about them (Art. 6(1)(b) GDPR, performance of a contract).
- To keep the service safe and usable — moderation, blocking abuse, the shared-device check, rate limits and basic usage statistics (Art. 6(1)(f), legitimate interest). You may object to this; write to us.
- Location sharing with friends and push notifications happen only when you switch them on, and you can switch them off at any time (Art. 6(1)(a), consent).
- Where the law makes us — for example keeping accounting records for a payment, or reporting illegal content (Art. 6(1)(c), legal obligation).
4. How long we keep it
- Full-quality originals of your media: 30 days from upload. A nightly job deletes them; the smaller archive version stays.
- The archive version, the event and everything in it: as long as the event exists.
- Account data, interactions, notification history and usage statistics: until you delete your account.
- When you delete your account, your profile, the events you own and your media go with it, and it cannot be undone. Media that other people already downloaded to their devices are out of our reach.
- Records we must keep by law — typically accounting documents for a purchase — are kept for the period the law sets, even after the account is gone.
5. Who else sees it
People in an event see the media and names of the others in that event. That is the whole point of the app, and it is not something we can switch off for you — if you do not want to be in a gallery, do not join the event.
Beyond that, your data reaches only the suppliers who run the technical side for us. They act on our instructions and may not use the data for themselves:
- Supabase — database, sign-in and push notification history
- Cloudflare — web hosting, application server and media storage (R2)
- Expo (Expo Push) — delivery of push notifications to the device
- Google (FCM) / Apple (APNs) — platform delivery of push notifications
- Stripe — payment for Frinity+ (only if you buy it)
6. Transfers outside the EU
Some of these suppliers are based in the United States, so your data may be processed outside the European Union. For each of them we rely on the safeguards named on the Contact page — typically the EU–US Data Privacy Framework or standard contractual clauses.
Where the supplier lets us choose, we keep the data in an EU region.
7. Your rights
You may ask us for a copy of your data, for a correction, for deletion, for a restriction on processing, and you may object to processing based on our legitimate interest. Write to [email protected] and we will answer within one month.
You can take a copy of your data yourself at any time: in the app under Settings → Download your data.
Where processing is based on your consent, you may withdraw it at any time. That does not make the earlier processing unlawful.
If you think we handle your data badly, you may complain to the Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz).
8. Children
Frinity is not for children under 15. We do not knowingly process their data, and if we find such an account we close it and delete the data.
If you believe a child under 15 has an account here, write to [email protected].
9. Automated decisions
We do not make decisions about you purely by machine and we do not profile you. Verification of an event compares positions in time, but its outcome only decides whether the event gets a badge — nothing about you personally.
10. Security
Media are stored privately, not on a public address, and each file is opened only through a short-lived signed link. Access to data in the database is restricted per user at the database level, not just in the app.
If a breach happens that is likely to be a risk to you, we will tell you and report it to the supervisory authority within 72 hours as the law requires.
11. Changes
If we change how we handle your data, we will update this page and, where the change matters, tell you in the app or by e-mail.