Privacy Policy — Frola

PRIVACY POLICY

Last updated: May 24, 2026

1. Introduction

jsouce ("jsouce," "we," "us," or "our") operates the Frola social events platform on mobile and web (the "Service"). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and your choices.

By using the Service, you acknowledge this Policy. If you do not agree, do not use the Service.

The Service is currently free with advertising when we enable it. We may add optional paid features later; we will update this Policy before collecting payment data.

2. Who is responsible

The data controller for the Service is jsouce (Frola). Contact: jsouceorg+privacy@gmail.com (privacy requests and questions).

We make the Service available in multiple countries (including the EU, US, Türkiye, and parts of Asia). If you are in the EEA, UK, or another region with local privacy laws, you may have additional rights described below.

3. Data we collect

3.1 You provide

- Account and profile: name, username (profilename), email, phone number, date of birth, gender, password (stored hashed), bio, profile photo, and preferences you set in the app
- Events: titles, descriptions, times, locations, images, attendance settings, and related metadata
- Social: follow relationships, attendance requests, and notifications you send or receive
- Messages: chat content you send (including text, images, voice, and shared locations) and related metadata (timestamps, read state where supported)
- Reports: report category, optional description, and identifiers needed to investigate
- Support correspondence you send us
- Photos, camera, and microphone: when you choose to set a profile photo, attach images, record voice messages, or use similar features, we process the content you capture or upload

3.2 Collected automatically

- Device and app: device type, operating system, app version, language, and identifiers needed for security, push delivery, and (when ads are on) advertising
- Usage: features used, interactions, and diagnostic logs
- Network: IP address and approximate location derived from IP
- Location: when you use location-based features, we request device location permission (when-in-use on mobile; not continuous background tracking). We may receive precise coordinates to show nearby events, place events on a map, or share location in chat. If permission is denied, we may use approximate location from your profile or IP-based estimates
- Push notifications: if you turn on push notifications in our consent screen, we may request OS notification permission and store a device messaging token (for example Firebase Cloud Messaging) to deliver alerts about events, messages, and attendance
- Cookies and similar technologies on the web (see /cookies)
- Crash diagnostics: only if you turn on crash reporting in the consent screen — technical crash data (stack traces, app version, device model) sent to Sentry; we minimize personal data, but logs can occasionally include incidental identifiers
- Advertising: when our servers enable ads, we show advertising (for example Google AdMob). Partners may receive device identifiers and ad interaction data. On iOS we may request App Tracking Transparency; where required we show Google's consent tools (UMP). Ads are not controlled by the analytics/crash toggles in the consent screen

3.3 From third parties

- Authentication providers (for example Google) if you choose to sign in with them: we receive information they share according to your settings with that provider
- Service providers that help us operate the Service, as described below

We do not knowingly collect data from anyone under 18.

We do not collect payment card or bank account data in the current app version.

4. In-app privacy choices (what the app actually does)

When you first use the Service (after sign-in), we show a privacy choices screen:

| Choice | Default if you tap "Reject optional" | Behavior |
|--------|--------------------------------------|----------|
| Essential storage / cookies | On | Required to sign in and run the Service |
| Analytics | Off | Firebase Analytics runs only if you enable this |
| Crash reporting | Off | Sentry runs only if you enable this |
| Location | On (required in screen) | Records your choice; device permission is requested when a feature needs GPS |
| Push notifications | Off | We register a push token only if you enable this; OS permission is requested when we set up push |
| Ads | Shown when enabled server-side | Separate from that screen; ATT/UMP may apply on iOS |

You can change analytics and crash preferences when the app exposes those controls. Location and push also depend on device permissions you grant or revoke in system settings.

5. How we use data

We use personal data to:

- Provide and maintain the Service (accounts, events, chat, notifications)
- Show content you request (for example nearby events, profiles, messages)
- Enforce Terms, including automated and manual review of reported content
- Run automated safety checks on certain user-submitted content (for example event text and images) using moderation services
- Deliver and measure advertising when the Service shows ads
- Communicate with you (verification codes, service messages, optional marketing where permitted and where you have not opted out)
- Improve reliability, security, and product design (including optional analytics and crash reporting you control in the app)
- Comply with law and respond to lawful requests

6. Legal bases (EEA/UK users)

Where GDPR or UK GDPR applies, we rely on: performance of a contract (providing the Service); legitimate interests (security, abuse prevention, improvement, and limited advertising measurement where applicable) balanced against your rights; consent where required (for example optional analytics, crash reporting, non-essential cookies on web, and advertising identifiers where required); and legal obligation.

7. How we share data

7.1 Other users. Profile information, events, and messages are visible to others according to your privacy settings and how the feature works (for example event hosts see attendance requests; chat participants see messages).

7.2 Service providers. We use trusted processors, including:

- Google Firebase / Google Cloud (hosting, authentication, push notifications, analytics when you enable it)
- Google AdMob (advertising when ads are enabled in the Service)
- Sentry (crash and error reporting when you enable crash reporting)
- SMS or phone verification providers (for example Twilio) when phone verification is enabled
- Mapping providers for location features
- OpenAI or similar providers for automated content moderation of certain submissions (we send content needed for that check; do not include unnecessary personal data in public event fields)

Processors are bound by contract to use data only on our instructions where required by law.

7.3 Legal and safety. We may disclose data if we believe it is necessary to comply with law, protect users and the public, investigate abuse, or enforce our Terms.

7.4 Business transfers. If we are involved in a merger or acquisition, data may transfer subject to this Policy, with notice where required.

We do not sell your personal information for money. When ads are shown, advertising partners may use data for ad delivery and measurement under their policies and your consent choices.

8. Your advertising and tracking choices

- iOS: you may be prompted to allow or deny tracking for personalized ads (App Tracking Transparency); you can change this later in iOS Settings
- In-app / partner tools: where required, we show Google's consent tools for ads (UMP) before personalized advertising
- Optional analytics and crash reporting: managed in the Service's privacy consent screen; you can change preferences where the app provides controls

9. International transfers

We may process data in countries other than yours (including the United States and the European Union, where some providers host services). Where required, we use appropriate safeguards (such as Standard Contractual Clauses) for transfers from the EEA/UK.

10. Retention

We keep data only as long as needed for the purposes above:

- Account data: while your account is active
- After account deletion: we delete or anonymize profile data within a reasonable period (typically within 30 days), except where we must retain data for legal, security, or dispute purposes
- Messages and events: may remain visible to other participants in truncated or anonymized form after deletion, as described in the app
- Logs and security records: typically up to 90 days unless a longer period is required
- Reports: retained as needed to investigate and prevent repeat abuse
- Crash logs: typically up to 90 days unless needed longer for a specific incident

11. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, object, or port your data, and to withdraw consent.

- In-app: edit profile and privacy settings; delete your account under Profile → Settings → Account
- Email: jsouceorg+privacy@gmail.com (we aim to respond within 30 days)

You may lodge a complaint with your local supervisory authority if you are in the EEA/UK.

California residents: we do not sell personal information for money. You may request access or deletion via jsouceorg+privacy@gmail.com with "California Privacy Rights" in the subject line. If we use advertising identifiers, you may also limit certain tracking through device settings and in-app choices.

12. Security

We use technical and organizational measures such as encryption in transit, access controls, and monitoring. No system is completely secure; use a strong password and protect your device.

13. Children

The Service is not for users under 18. If you believe a minor provided data, contact jsouceorg+privacy@gmail.com and we will take appropriate steps to delete it.

14. Changes

We may update this Policy. We will post the new version at /privacy and update the "Last updated" date. Material changes may be communicated in-app or by email where required.

15. Contact

jsouce (Frola)
jsouceorg+privacy@gmail.com — privacy requests and questions
jsouceorg+legal@gmail.com — legal notices
jsouceorg+support@gmail.com — general support

Postal or registered business address: available on request to jsouceorg+privacy@gmail.com for verified legal or regulatory correspondence.