Skip to content
Privacy Policy

Privacy Policy

Introduction

Effective 28 September 2026 Frendis is operated from Barcelona, Spain. This Privacy Policy explains what personal data we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR) and Spanish data protection law (LOPDGDD).

DATA CONTROLLER

Frendis · Barcelona, Spain · hello@frendis.app

1. DATA WE COLLECT

Account data — your name, email address and profile photo, received from Google when you sign in with Google, or the name and email address Apple returns when you sign in with Apple on iOS (which may be a private relay address). Date of birth — asked once at sign-up to confirm you are 18 or older. It is visible only to you, never to other users. Profile data — display name, bio, interests, languages, goals, your profile photo and up to 10 more photos in your profile gallery, all of which you add yourself. Location — the city you select (currently Barcelona) and, if you fill it in, the neighbourhood on your profile. The mobile app may also ask your permission to use the device's location; it is used for one thing only — centring the map on you — the coordinate stays in the app's memory on your device, and it is never sent to our servers, never stored and never shared with anyone. Refusing the permission leaves everything else working. Activity venues: the host chooses what others see before joining — the exact address (for example, a café), only the neighbourhood, or nothing until approval. Approved participants always see the exact address. Activity data — activities you create or join, the photos you attach to activities you host, RSVP and attendance records, chat messages, and reviews you write. Device data — if you allow notifications in the mobile app, the push-notification token of your device, so we can deliver them. It is deleted when you sign out on that device or delete your account. Technical logs — server logs including IP addresses, request identifiers, and timestamps, retained for up to 90 days for security and debugging purposes. Error reports — when the app or the website hits an unexpected error, it sends us the error's own message, its technical stack, the screen it happened on and the app version, device model and language. Never anything you typed. Reports are stored on our own servers in the EU for up to 90 days and are linked to your account only if you were signed in.

2. HOW WE USE YOUR DATA

To operate the Service — matching you with activities and people nearby in Barcelona. To send notifications — in-app, by email, and optionally via Telegram. To keep the platform safe — moderating content and investigating reports of abuse. To comply with legal obligations — under Spanish and EU law. We do not sell your data, share it with advertisers, or use it for profiling beyond operating the Service.

3. DATA SHARING

Other Frendis users see your public profile (display name, photo, interests, rating, and year of joining). Exact venue addresses are shown to approved participants, and to everyone else only when the host chose to show the exact address. We engage the following processors: — Supabase — database, authentication and file storage (EU-based servers) — Hostinger — the servers that run our API, the website and our own translation model (EU) — Resend — transactional email delivery — Google — sign-in with Google (your Google account's name, email address and photo); address autocomplete in the create-activity form (the text you type into the address field, sent from our server, not from your device); the map on the website (Google Maps); and delivery of push notifications to Android devices (Firebase Cloud Messaging) — OpenFreeMap — map tiles in the mobile app: your device's IP address and the area of the map you are looking at reach them. Nothing that identifies your account is sent — Apple — Sign in with Apple on iOS (the name and email address your Apple account returns, which may be a private relay address) and delivery of push notifications to iOS devices (APNs) — Expo — over-the-air updates of the mobile app and the relay that carries push notifications to your device — Anthropic and Google (Gemini) — automated moderation and category suggestions for the PUBLIC text of activities (title and description). Private chat messages are never sent to them. See section 9 — Telegram — only if you link the Telegram bot yourself No other third parties receive your personal data except where required by law. We do not sell your data, share it with advertisers, or use it for profiling beyond operating the Service.

4. YOUR RIGHTS

Under GDPR you have the right to: — Access the personal data we hold about you — Correct inaccurate or incomplete data — Delete your account (app: Profile → Settings → Account deletion → Delete account; web: Profile → Settings → Account deletion → Delete account) — deletion takes effect immediately and the identifying data on the deleted records is anonymised within 30 days; section 5 lists what is kept after that — Receive a copy of your data in a portable format — Object to or restrict certain processing — Withdraw consent at any time (where processing is based on consent) — Lodge a complaint with the Spanish Data Protection Agency (AEPD) at www.aepd.es To exercise any right, contact us at hello@frendis.app. We will respond within 30 days.

5. DATA RETENTION

Personal data is kept for as long as your account is active. When you delete your account, deactivation is immediate: your profile, the activities you created and your participation in other people’s activities stop being visible to anyone in Frendis, the push-notification tokens of your devices are deleted outright, and you are signed out. Within 30 days an automated job anonymises the identifying data on those records: your name is replaced with “Deleted user”; your bio, profile-photo link, neighbourhood and approximate location are cleared; the email address, phone number and sign-in identifier on our account record are replaced with anonymous placeholders; and the link between your account and product-analytics events is removed. Account deletion does not erase everything. We keep: messages you already sent, which stay visible to the other participants of those chats (shown as written by “Deleted user” after the 30-day step); reviews you left for other people, your reactions, saved activities and block list; the activities you created (hidden from everyone, but not physically erased); the photo files you uploaded; your date of birth, languages, goals and interests, your public profile handle and, if you linked the Telegram bot, your Telegram chat ID; and the sign-in identity held by our authentication provider (Supabase). Reports and moderation records are kept for up to 90 days from when they were created, and server logs for up to 90 days, for security and to comply with the law. Analytics events are kept without any link to your account (see section 12). If you want any of the retained data erased, email hello@frendis.app — we will consider the request under the GDPR and reply within 30 days. The step-by-step description of deletion is on the account-deletion page.

6. COOKIES

We use only strictly necessary cookies, which do not require your consent: the session cookie that keeps you signed in, a cookie that remembers the language you chose, and a short-lived cookie that returns you to the page you were on after signing in. We do not use advertising, tracking or analytics cookies.

7. CHILDREN

Frendis is not directed at anyone under 18. We do not knowingly collect personal data from people under 18. If you believe someone under 18 has registered, contact us at hello@frendis.app and we will delete their account.

8. SECURITY

We use industry-standard measures to protect your data, including encrypted connections (HTTPS), access controls, and row-level security on our database. No method of transmission is 100% secure; we cannot guarantee absolute security.

9. MAPS, AUTOMATED TRANSLATION AND MODERATION

Maps. The mobile app draws maps from OpenFreeMap tiles; the website uses Google Maps. Loading a map tells that provider your IP address and which area you are looking at. It does not tell them who you are. Automated translation. Activities are translated into the languages Frendis supports by a translation model we run on our own server in Europe — that text does not leave our infrastructure. Chat messages are translated only when you ask for a translation, by the same self-hosted model; the result is cached on our server so the same message is not translated twice. Translations are machine-made and may be inaccurate; the original text is always available. Automated moderation. Before an activity becomes visible, its title and description go through an automated check: our own rules first and, where the rules are not conclusive, a language model operated by Anthropic or Google (Gemini) acting as our processor. Text the check cannot clear is not published and waits for a human moderator. No account is restricted, blocked or deleted by an automated decision alone, and you can contest any moderation outcome at hello@frendis.app.

10. CHANGES TO THIS POLICY

We will notify you of material changes to this Policy by email or in-app notice at least 14 days before they take effect.

11. CONTACT

Privacy questions: hello@frendis.app Data protection supervisory authority: Agencia Española de Protección de Datos (AEPD) · www.aepd.es

Language

In case of any discrepancy between this translation and the Spanish original, the Spanish version prevails.

12. ANALYTICS

When you consent to analytics, we collect: pages you view, features you interact with, your device and browser type, and your city (derived from your IP address — the IP address itself is not stored). Analytics runs on our own self-hosted server — data is never shared with third-party analytics companies. Before you sign in, we identify visits using a hash that rotates daily; we do not use cookies for analytics. After you sign in, analytics events are linked to your internal account ID (a UUID) — never your name or email. Tracking only starts if you agree. You can withdraw your consent at any time using the controls on this page. If you delete your account, the link between these events and your account is removed within 30 days; the events themselves are kept, with no link to you, and are used only for aggregate statistics. Separately from the above, our server records operational events — an account created, an activity published, a join request sent — which we need to run the Service, enforce limits and investigate abuse. They carry your internal account ID, never your name or email, and they are recorded under our legitimate interest rather than your consent, so the control on this page does not switch them off. They are covered by the same retention and deletion rules as the rest of section 12.

CITY EXPANSION WAITLIST

If you join our city-expansion waitlist from the landing page, we collect your email address and the city you name. We use this only to email you once when that city opens on Frendis — nothing else. This is the only personal data we collect before you create an account. We keep waitlist entries for up to 24 months, after which they are automatically and permanently deleted. To have your entry removed sooner, email us at hello@frendis.app.