WhosThere
Privacy notice
Last updated 28 August 2026
This notice describes how this WhosThere instance handles personal data under the EU/EEA GDPR, UK GDPR, Canada’s PIPEDA, US state laws including California CPRA, Australia’s Privacy Act (APPs), and similar regimes. It is product documentation, not legal advice.
Who is responsible
The operator of this deployed app is the controller of account and profile data. Processing runs on the app host and its database provider. Those processors may store data outside your country, including the United States. Where a transfer tool is required (GDPR Chapter V), standard contractual clauses or an adequacy decision are the intended mechanism.
What we collect
- Account: verified email, name, and sign-in identifiers.
- A server-minted 64-bit ID, unique to you.
- Profile you type: photo, bio, social handles, sharing preference.
- Security: email verification and password-reset codes. Codes expire in minutes and are stored hashed.
We do not collect GPS, address books, payment data, or advertising IDs. Your watch list and alarms stay on the device.
Why we process it
- Contract: creating your account and issuing your ID.
- Consent: making your profile visible to nearby users (sharing). Off by default. You can withdraw it any time.
- Legitimate interests: looking up IDs that are already public-by-consent, running security, and stretching the sync period under load so the service stays available.
Sharing and sale
We do not sell personal information (CPRA). We do not share it for cross-context behavioural advertising. Other users see your profile only while sharing is on, and only if their phone heard your ID. Hosting and database providers process data on our instructions.
Retention
Account and profile data are kept until you delete the account. Nearby lookups are answered and discarded. Sessions expire.
Your rights
Depending on where you live you can access, correct, export, delete, restrict, or object to processing, withdraw consent, and appeal a denial. In-app: Me → Download my data (portability) and Me → Delete my account (erasure). You may complain to a supervisory authority (for example your EU DPA, the ICO in the UK, the OPC in Canada, a US state AG or the CPPA, or the OAIC in Australia).
Children
WhosThere is for people 16 or older (the stricter EU digital-consent age). We do not knowingly collect data from children.
Security
Lookups are authenticated, scoped, and capped at 100 IDs per synchronisation period (default 8 seconds). Hidden profiles are never returned. Email is confirmed with a code or link before the account is usable. Passwords can be reset with a code sent to the verified email. Passwords are stored hashed by the auth service, not in profile rows. No system is perfect; delete the account if you believe it was misused.
Contact
Privacy and data requests: [email protected]. Safety and abuse: [email protected]. Reports of illegal or harmful content are reviewed; repeat reports hide a profile from nearby lookup.