Skip to content

Privacy Policy

Last updated: 25 July 2026

This policy applies to the Friendity mobile app, web app and backend services (together, the “Service”). It describes what we do with your data and the data of the people you add as friends.

0. In short

Your friends' names, contact details and notes are stored on your device and are not transmitted to our servers or our AI provider; in the AI chat they are replaced with pseudonymous identifiers before anything is sent (§3). A phone number you choose to share with a friend you link with is the one exception: it rests on our servers until that person's app fetches it, 30 days at the most (§9, §16). To operate the Service we process the account data described in §2. What you share with other people leaves your device only when you use the relevant feature, such as sending an invitation or hosting an event, and only to the extent that feature requires (§16).

1. Data Controller

The data controller under Art. 4 No. 7 GDPR is:

Saskia Sofia Tontara
Jürgen-Töpfer-Straße 26
22763 Hamburg, Germany
Email: contact@friendity.app

For data-protection questions and to exercise your rights, please use: privacy@friendity.app.

We are not required to appoint a Data Protection Officer under Art. 37 GDPR or § 38 BDSG.

2. Where which data is stored

On your device only (in an encrypted database): your first and last name, your phone number (it leaves your device only if you choose to share it on a friend invitation; see §9 for how long we keep it), your exact birthday, your full home and work addresses, the photos you take, your profession, the children you list as part of your household, any free-text notes you save, the durable facts Friendi learns about you across chats (stored in pseudonymised form; you can view or delete each one under Privacy & data), and for each friend you add, the same kinds of detail you keep about them: their name, contact details, home address, birthday, photos and your private notes.

Optional profile details you can share with the people you invite (voluntary; empty by default): your profile photo and a display name. When set, your photo is stored with Microsoft Azure in Sweden Central (EU) and shown only on invitations you send and to friends you are linked with, that is, whenever an invitation has been accepted in either direction. Your display name is included on each outgoing invitation and visible to the recipient in their inbox and on the invitation review screen. You can delete either at any time from your profile; the data is removed and is then no longer visible to linked friends.

On our servers: your email address (for sign-in and transactional email; it is also shown to a friend you are linked with if you choose to share it, §16), your password (stored only as a salted one-way hash, never in plain text), your coarse location (city, country, postal code, neighbourhood; never a precise address), your chosen interests, activity preferences and dietary facts, your schedule preferences, your notification settings, and an opaque identifier for each friend you add together with their interests and dietary facts (used to match suggestions). If you connect a calendar, the calendar data described in §6 is added to this. We store no name, photo or address of any friend. The one contact detail that can sit here is a phone number you choose to share with a friend you link with: it rests on our servers until that person's app fetches it, 30 days at the most (§9, §16).

Your conversation with Friendi is stored in two places. The readable text you see in the chat lives in your encrypted on-device storage. A pseudonymised copy of the same conversation, in which every friend name is replaced by a pseudonymous identifier, is stored on our servers so that Friendi retains the context of the conversation. Retention is governed by §9 and the pseudonymisation by §3.

Data on our servers is encrypted in transit (TLS) and at rest (AES-256). Your friends' names, contact details and addresses are pseudonymised on your device (§3) and reach our servers in identifiable form only where §16 says so: the contact details two linked people deliberately exchange.

3. AI chat and pseudonymisation

Before a chat message leaves your device, your friends' names, their contact details and the details you keep about them are replaced on your device with pseudonymous identifiers; that data never leaves your device. The AI provider receives only the pseudonymised message together with non-identifying details such as the person's interests and dietary facts. Responses are matched back to the real names on your device. A name the app does not recognise as one of your friends may reach the AI as you typed it. The app shows you which details were replaced.

The pseudonymised conversation is stored on our servers so that Friendi retains context between your messages. This copy does not contain your friends' names. Other content you type in the chat (places, dates, preferences, free text, including a name not recognised as a friend) is stored as you typed it. Retention is governed by §9.

One exception applies: the availability field on a date poll. When a host is still finding a date and you write when you are free (“weekends are fine, after 6 on work days”) instead of selecting the offered dates, that sentence is sent to our AI provider (§8) exactly as you typed it, without pseudonymisation, because the field asks for times, not for people. The AI converts the sentence into recurring weekly time slots, and you confirm that result before anything is shared with the host. The host sees the time slots, not your sentence; only if automatic processing fails is your sentence shown to the host as written. Please do not enter names, phone numbers, addresses or other personal details in this field. This exception applies to that one field and to nothing else in the Service.

4. Account recovery

Your friend data exists only on your phone; we cannot restore it if you lose the device. We recommend your platform's encrypted backup (iCloud Backup with Advanced Data Protection on iOS, Android's encrypted device backup). We do not operate a backup of our own and cannot guarantee an automatic restore onto a new device. Without an operating-system backup, the data on a lost device cannot be recovered; we hold no copy.

5. The provisional account before sign-up

When you first open the app, we create a provisional account on our servers so onboarding works before you register. It contains no email address. If you complete sign-up, it becomes your regular account. Otherwise, the provisional account and all its server-side data are deleted automatically after about two weeks of inactivity.

6. Calendar

Friendity can work with two kinds of calendar. Both are optional. In both cases you pick a level when you connect. In the app they are called Basic, Smart and Full sync, and internally they carry the values freebusy, read_only and full. For Outlook, the app offers only Basic and Full sync.

Your device calendar. Friendity asks for full read access to your device calendar; a narrower permission, such as adding events only, is not enough for it. The app reads the calendar on the device to suggest times for meeting a friend, and it can add a plan you create or confirm to your device calendar. The level decides what the phone transmits to our server. At Basic, that is only the start and end of your busy times, as blocks with no content: no title, location, description or attendees. At Smart, event titles and locations are added, but no descriptions and no attendees. At Full sync, we transmit and store every field, including descriptions and attendee email addresses. From Smart upwards the app also reads your calendar entries on the device to suggest interests and people to you; those suggestions leave your phone only once you confirm them. What the phone transmits is replaced at every sync and only ever covers about one week back and three months ahead. You can change the level in the app or revoke calendar permission at any time in your phone's settings.

An external calendar (Google Calendar, Microsoft Outlook). Connecting one is optional, and you choose the level. At Basic we receive only busy periods and store them as blocks with no content; titles and details stay with your provider. With Google, the permission you grant allows nothing more than that. Microsoft offers no free/busy-only permission. We therefore ask for the narrowest permission Microsoft provides for an availability query: read access to the basic details of your own calendars. We do not ask for access to calendars other people have shared with you. Even with that permission we could technically read events; we ask Microsoft only for the times when you are busy, and we store only those times. The permission stays in force for as long as the connection exists, including at Basic; only you can narrow or revoke it, in your Microsoft account. If you connected Outlook at an earlier time, a broader read permission may still be recorded there, one that also covered calendars shared with you; you remove that in your Microsoft account as well. At Smart, we additionally read and store the title, location and description of your events. At Full sync, we store the same content and may also create events in your calendar, update them and remove ones we created; if you invite people to such an event, we pass their email addresses to your provider, and your provider notifies them of the invitation and of any cancellation. Your provider's responses also contain the attendees of an event; we do not store those from an external calendar. Events from a connected calendar are kept until you lower the level, disconnect it, or delete your account. You can change the level or disconnect at any time: dropping to Basic deletes the titles, locations and descriptions we stored from that calendar and keeps only your busy times; disconnecting deletes the access tokens we hold and every event imported from that calendar. Either way we delete only our own copy: we remove nothing from your calendar at Google or Microsoft. If you raise the level again later, we fetch the details from your provider at the next sync. For Google, disconnecting also revokes our access; for Microsoft/Outlook, please also remove access in your Microsoft account.

Sensitive entries. Some calendar entries can reveal sensitive information, for example a medical or religious appointment. You decide how much of your calendar we receive: at Basic, we receive only busy times and no event details at all. If you share event details at a higher level, you do so on the basis of your explicit consent, which you can withdraw at any time: lowering the level deletes the details the new level no longer covers. At Basic only your busy times remain; the titles, locations, descriptions and attendee lists we stored from that calendar are removed. Disconnecting deletes everything we stored from that calendar. We always delete only our own copy: nothing is removed or changed in your own calendar, on your device or at Google or Microsoft. If you raise the level again later, the details are picked up again at the next sync, so nothing is permanently lost. We use what you share only to suggest and schedule activities.

7. Lawful basis

  • Account creation, login, password reset, transactional email: Art. 6(1)(b) GDPR (performance of the contract you enter into by signing up).
  • Activity suggestions, AI chat, meetup planning: Art. 6(1)(b) GDPR over your pseudonymised data; the underlying friend data is your own processing on your device.
  • Sending an invitation to a friend by email: Art. 6(1)(f) GDPR (the legitimate interest in delivering an invitation you explicitly asked us to send); the recipient's email is used to deliver the invitation and kept with your invitation records (see §9).
  • Sharing your contact details with a friend you link with: Art. 6(1)(a) GDPR, given per detail when you send or accept the invitation and withdrawable at any time in the app. Your email address is then shown to that friend; a phone number you share rests on our servers only until their app fetches it (see §9).
  • Calendar access: explicit consent when you connect the calendar (Art. 6(1)(a) GDPR), which you can withdraw at any time by disconnecting in the app.
  • Error monitoring and security: Art. 6(1)(f) GDPR, the legitimate interest in keeping the Service working and secure; error reports are minimised and personal data is redacted from them where technically possible.
  • Web analytics: Art. 6(1)(f) GDPR, the legitimate interest in understanding aggregate site usage. Our web analytics provider (Vercel) does not set cookies, does not store identifiers on your device, and does not profile individual users.

8. Processors

We use the following service providers to operate the Service. Unless noted below, they act on our instructions as processors under Art. 28 GDPR.

ProviderPurposeHosting regionTransfer basis
Neon, Inc.Postgres database hostingFrankfurt, Germany (EU)No transfer (EU)
Microsoft AzureBackend hosting and photo storageSweden Central (EU)No transfer (EU)
Anthropic, PBCAI chat processing; receives data about your friends only in pseudonymised form; a name the app does not recognise as a friend may arrive as typed (§3). Also reads a date-poll availability reply, which is sent as written (§3)USAStandard Contractual Clauses
OpenAI, L.L.C.AI chat processing; receives data about your friends only in pseudonymised form; a name the app does not recognise as a friend may arrive as typed (§3). Also reads a date-poll availability reply, which is sent as written (§3)USAStandard Contractual Clauses
Google LLCSign-in, calendar sync, maps and location services, link-safety checks, push deliveryUSAEU-US Data Privacy Framework + Standard Contractual Clauses
Microsoft CorporationExternal calendar sync (Outlook), only if you connect oneUSAEU-US Data Privacy Framework + Standard Contractual Clauses
Plus Five Five, Inc. (operating as Resend)Transactional email (verification, password reset, invitations)USAEU-US Data Privacy Framework + Standard Contractual Clauses
Expo (650 Industries, Inc.)Push notifications (relayed through Apple APNs / Google FCM)USAEU-US Data Privacy Framework + Standard Contractual Clauses
Exa Labs, Inc.Web search for activity suggestions; receives search queries onlyUSAStandard Contractual Clauses
Functional Software, Inc. (Sentry)Error monitoring; error reports are minimised and personal data is redacted from them where technically possibleUSAEU-US Data Privacy Framework + Standard Contractual Clauses
Vercel, Inc.Web app hosting + cookie-less web analyticsUSA / EU edgeEU-US Data Privacy Framework + Standard Contractual Clauses
Apple Inc.Sign in with Apple (ID-token verification)USAEU-US Data Privacy Framework + Standard Contractual Clauses

Where you sign in with Google or Apple, Google and Apple also process your data as independent controllers under their own privacy policies. We additionally use technical services that receive no personal data (for example weather and stock-photo look-ups for city-level catalogue data); as they do not process your data, they are not listed here.

This list is current as of the “Last updated” date above. We will update it when providers change. Copies of the relevant safeguards (Standard Contractual Clauses, DPF certifications) are available on request from privacy@friendity.app.

9. Retention

  • Provisional (un-signed-up) accounts and their server-side data: deleted ~2 weeks after inactivity.
  • Signed-up accounts: kept until you delete your account or request erasure.
  • Server-side conversation context (pseudonymised copies of the conversation, see §3): 30 days of inactivity, then automatically deleted. If you keep chatting in the same thread, that thread's 30-day clock resets each time.
  • On-device chat history (the conversation you see in the app): kept on your phone until you delete it manually or wipe the app.
  • Behavioural signals used for personalisation: pruned on a rolling 90-day window.
  • Sent invitation records (recipient email + status): retained as long as your account exists; deleted with your account.
  • A phone number shared on an invitation: it rests on our servers only until the other person's app fetches it, and is deleted automatically after 30 days at the latest.
  • Event chat messages: stored while the event exists and deleted when the event is over or deleted (see §16).
  • Calendar data (§6): what your phone transmits is replaced at every sync and only ever covers about one week back and three months ahead. Lowering the level to Basic deletes the event details we stored from that calendar and keeps only your busy times. Events from a connected Google or Outlook calendar are deleted in full as soon as you disconnect that calendar, and at the latest with your account. Both delete only our copy; nothing is removed from your calendar at the provider.
  • Error logs (Sentry): retained per Sentry's default, currently 30 days.

10. Your rights under the GDPR

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20) and objection (Art. 21); the right to withdraw consent at any time (Art. 7(3)); and the right to lodge a complaint with a supervisory authority (Art. 77).

  • Access / export: the in-app “Export your data” option returns a machine-readable JSON file containing everything we hold about you on our servers plus everything held locally on your device.
  • Deletion: the in-app “Delete account” option permanently erases all server-side records of your account (including Friendi's stored conversation context) and all data stored locally on the device: your friends, profile, notes, photos and on-device chat history. The local encryption key is deleted as part of this, so any copy that remains in an operating-system backup (iCloud, Google) can no longer be read. You may also use the public deletion URL /account/delete.
  • To exercise any other right: email privacy@friendity.app. We respond within one month of receiving your request, as required by Art. 12(3) GDPR.
  • To complain: in Germany, your competent supervisory authority is the Datenschutzbehörde of your federal state, or the Hamburg authority if you reach out to us: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI), https://datenschutz-hamburg.de/.

11. International transfers

Our database, backend and photo storage are hosted within the European Union (see the processor table above).

Some providers operate from outside the EEA, primarily the USA. For each such transfer we rely on the EU-US Data Privacy Framework, where the provider is certified, or on Standard Contractual Clauses adopted by the European Commission. Where additional safeguards are needed, we apply technical measures such as the on-device pseudonymisation described in §3 to minimise the data that stays identifiable to the recipient.

12. AI Act transparency (Art. 50)

Friendi is an AI assistant. Every chat is clearly framed in the app as a conversation with an AI; AI-generated suggestions are flagged as such. The system is subject to the transparency obligations of Art. 50 of the EU AI Act; no automated decision-making with legal effect on you is performed by the Service (Art. 22 GDPR).

13. Children

The Service is not directed at people under 18 years of age. By signing up you confirm that you are 18 or older. We do not knowingly collect or process data from anyone under 18; if we learn that an account belongs to a minor, we will delete it.

14. Cookies and similar technologies

The Friendity web app uses only the cookies and local storage strictly necessary to deliver the Service you requested: your chosen theme, your language, your authenticated session, and functional friendity_guest_id / friendity_guest_name entries on public event links that keep your RSVP (and the display name you typed for it) standing across reloads. Under § 25 (2) TDDDG no consent is required for these; the site therefore does not show a cookie banner.

The browser event planner temporarily stores, in the functional friendity_event_draft_v1 entry, the event title, the selected place and address, the proposed dates and their time zone, the description, the cover and the page language on this device; once publishing begins, also the host first name used on the invite and the signed-in account ID. This keeps your draft in place while you sign in. An unpublished form draft expires after 24 hours; once a publish request has been sent, the record is kept until the created event opens or you start a new plan. Invalid or expired drafts are removed automatically.

We do not use advertising cookies, marketing trackers, cross-site tracking pixels, or third-party analytics that identify you. Our web analytics provider (Vercel) operates without cookies and without storing any identifier on your device.

15. Changes to this policy

We will update this policy as the Service changes. For material changes that affect your rights, we will notify you in-app and by email and give you a reasonable chance to object before the change takes effect. The “Last updated” date at the top of this page always reflects the current version.

16. What you share, and data about other people

When you invite someone, host an event, or message a participant, you share the details that feature requires with the people involved; they see only what the feature needs.

  • Invitations: if you have set a profile photo and display name, they appear on the invitations you send and to friends you are linked with, that is, once an invitation has been accepted in either direction. Your display name and an optional note are included on each outgoing invitation.
  • Event chat: the host and the confirmed participants of an event can read and post messages in that event's chat. Messages you send are stored on our servers and are visible to those participants. They are encrypted in transit and at rest, but not end-to-end encrypted. They are deleted when the event is over or deleted; you can delete your own messages, the host can remove any message, and any participant can report one.
  • Contact details with a linked friend: for each detail you tick when you invite someone or accept an invitation (email address, phone number), we pass it to that one person. Your email address is served from your account each time they open your profile, so untick it and they stop seeing it. A phone number is not kept with your account: it waits in a temporary slot until their app fetches it and is removed after 30 days at the latest (§9).

For you, the legal basis of these features is Art. 6(1)(b) GDPR (performing the service you asked for); for the invited person's email address it is Art. 6(1)(f) GDPR, and for the contact details linked people exchange it is your consent, Art. 6(1)(a) GDPR (see §7).

Where this data comes from. Some data we hold is about people other than you: the email address of someone you invite by email, the interests and dietary facts you record for a friend (kept under an opaque identifier, with no name or contact details), and a phone number a friend chose to share with you, while it waits for your app to fetch it. That data is provided by you, or by the friend who chose to share it. Those people may object to the processing or request deletion at any time via privacy@friendity.app.

An email address is required to create a full account; without it you can use onboarding but cannot save an account.