2. What data we collect
Findly collects only the data that is strictly necessary for the operation of the app:
| Data category | Description | Legal basis |
|---|---|---|
| Google account data | Name, email address, profile picture (Google login) | Art. 6(1)(b) GDPR |
| Location data | GPS coordinates, only during active connection – transmitted with end-to-end encryption | Art. 6(1)(a) GDPR (consent) |
| Nickname | Self-chosen display name within the app | Art. 6(1)(b) GDPR |
| FCM-Token | Device-specific token for push notifications | Art. 6(1)(a) GDPR (consent) |
| Pairing data | Anonymous connection ID for assignment to a partner | Art. 6(1)(b) GDPR |
| Background location | GPS coordinates with screen locked, exclusively during active connection | Art. 6(1)(a) GDPR (consent) |
Findly does not collect payment data. Premium features are processed as a one-time in-app purchase via Google Play, subject exclusively to Google's privacy policy.
3. Location data in detail
- Location data is only collected when an active partner connection exists.
- Location data is transmitted with end-to-end encryption – comparable to the encryption used in modern messaging apps. Neither we nor Firebase can read the raw data.
- The connected partner is never shown the exact location – only distance and (in festival mode) direction.
- Collection is motion-based (not continuously periodic) to minimise battery usage.
- Location data is overwritten on the server, not stored – no location history.
- After the connection ends, location data is automatically deleted.
- Findly also processes location data in the background (locked screen / minimised app) while an active connection exists.
Background location processing: Findly uses an Android Foreground Service with a permanently visible notification ("Findly is running in the background") while an active partner connection exists. The service is automatically terminated when the connection is disconnected. Processing is carried out exclusively for distance calculation between connected partners – never for profiling or passing on to third parties.
4. Data processing and storage
- Google Firebase Firestore – User data, pairing data and real-time location transfer. Firebase Privacy ↗
- Firebase Cloud Messaging – Exclusively for push notifications.
- Google Sign-In – Sign-in with Google account. Google Privacy ↗
Note on IP addresses: We ourselves do not store IP addresses. However, when using Firebase (Firestore, FCM), IP addresses are technically transmitted to Google servers and processed for the purpose of establishing connections. This processing is carried out by Google as a data processor pursuant to Art. 28 GDPR and is subject exclusively to Google's privacy policy. We have no influence over this processing and no access to the data involved.
5. Disclosure to third parties
We do not sell or rent your data. Disclosure occurs exclusively:
- To your connected partner – but exclusively as calculated distance and direction, never as exact GPS coordinates. This is the core purpose of the app.
- To Google via Firebase Cloud Messaging and Google Sign-In (technically necessary).
- When we are legally obliged to do so.
6. Storage duration
- Location data: Continuously overwritten, no history. Deleted immediately after connection ends.
- User data (name, email, nickname): As long as the account is active.
- FCM-Token: Updated on every app start and deleted on logout.
- Pairing data: Automatically cleaned up after expiry or termination of connection.
7. Your rights
- Access (Art. 15 DSGVO)
- Rectification (Art. 16 DSGVO)
- Erasure (Art. 17 DSGVO)
- Restriction (Art. 18 DSGVO)
- Data portability (Art. 20 DSGVO)
- Withdrawal of consent – Location and notification consents can be withdrawn at any time.
Contact: treichellabs.app@gmail.com
Supervisory authority
The State Commissioner for Data Protection of Lower SaxonyPrinzenstraße 5 · 30159 Hannover
www.lfd.niedersachsen.de ↗
8. Data security
End-to-end encryption: Location data is encrypted on the device before it leaves the device – and only decrypted again on the connected partner's device. Neither we as the operator nor Firebase as the infrastructure provider can view the transmitted location data in plain text. The principle is comparable to the end-to-end encryption used in modern messaging apps.
- Encrypted transmission of all data via HTTPS/TLS.
- Location data on the device is protected by the Android security model.
- Access to location data only for authenticated users with an active connection.
- Server-side access control via Firebase Security Rules.
- Foreground Service is always visible through the persistent system notification and can be terminated immediately by disconnecting.
9. Children
Findly is not directed at children under 16. We do not knowingly collect personal data from minors. Parents or guardians can contact us if a child has used the app.
10. Changes
We reserve the right to update this privacy policy. The current version is always available at /datenschutz/findly. Users will be informed of material changes via the app.