Privacy Policy
Last updated: 19.09.2026
The German version is the binding one. This English text is a convenience translation of the German privacy policy at zquady.com/datenschutz. It is provided to make the content easier to understand. In the event of any discrepancy between the two versions, the German wording prevails.
Zquady is an app that lets people aged 18 and over arrange things to do together in their area — we call these arrangements “Zquads”. Because people meet here in real life, we handle your data as sparingly as possible: in the app and in the browser version we use no analytics services, and we do not sell data. Ad measurement only happens if you expressly agree to it (2.15) — without your consent there is no tracking. We have used an external crash reporting service since 12 August 2026 — solely to notice and fix crashes (details under 2.7 and section 4). The only exception is a cookieless visitor count on this website, which does not recognise anyone — what it collects is set out under 2.10. This page sets out what we do need, why, and who gets to see it.
Scope: This policy applies to the Zquady app (iOS and Android), to the website zquady.com including the link preview pages at /z/… and /u/…, and to the browser version app.zquady.com. Where something applies to only one of these, it is stated expressly.
1. Data controller
The controller for the processing of personal data in the Zquady app, on the website zquady.com and in the browser version app.zquady.com is:
Zquady e.U. Linzer Straße 17 4100 Ottensheim Austria
Legal form: registered sole proprietorship (eingetragenes Einzelunternehmen), FN 687516 d, Regional Court Linz
Phone: +43 664 99216386
Email: privacy@zquady.com
Data protection officer: not appointed; we are not legally required to appoint one.
2. Which data we process
We only process data that you give us yourself or that arises technically when the app is operated. In detail:
2.1 Account and sign-in
- Your email address. To sign in, we send you a one-time code by email. A password is optional; if you set one, it is only ever stored as a cryptographic hash, never in plain text.
- If you sign in via another provider: the link to that account and the data the provider transmits to us in the process (as a rule the email address and a provider identifier; with Apple, on request, only a relay address). All three sign-in options are enabled: Apple, Google and Discord.
- If you create a passkey: its public key and an identifier. The private key never leaves your keychain or password manager.
- Your date of birth and the confirmation that you are of full age. Both are stored permanently with your account, not merely checked once.
- Your language selection, so that emails from us arrive in your language.
- If you switch on two-factor authentication: the associated security factor and your recovery codes. We store the codes exclusively as hashes — we cannot show them to you again.
- Your sign-in session is stored on your device in the protected system storage (iOS keychain or Android keystore) so that you stay signed in.
2.2 Profile
- Your username. You do not type it in freely but choose from generated suggestions — that keeps names clean and anonymous. We also store when you last changed it, because a change is only possible every 30 days.
- Your profile picture: either your initials (taken from your username, nothing extra is stored) or a photo you upload yourself. An uploaded photo is resized to 400 × 400 pixels and stored in our file storage.
- Your bio, if you write one.
- Your answers to conversation starters (up to three questions you choose yourself), if you answer any.
- If you like, your Instagram and/or Discord profile. What we store, who can see it and how confirmation works is set out under 2.12.
- Confirmations: whether and since when your phone (2.14) and your linked profiles are confirmed.
- Your badges. We calculate them from your confirmed activity — for example Zquads that took place, ratings received, places visited or how long you have been a member. You choose yourself which of them others see (at most three).
- Your privacy settings (who may see your profile picture, your bio and your linked profiles, and who may message you) and whether you have enabled “presence at the venue” (off by default).
- The total of thumbs up and thumbs down you have received as a host.
- Your gender (woman, man or diverse) — a required field at registration. What we need it for and who sees it is explained in 2.13.
2.3 Location
We only request your location if you grant the permission, and only while the app is in the foreground. We deliberately use a medium accuracy (roughly 100 metres) and prefer your device's last known position.
Your GPS coordinates are stored neither on your device nor in our database. They only exist in the app's working memory for the duration of the session. Distances to Zquads (“1.2 km away”) are calculated by your phone itself. It is different only if you set your place yourself (place selection in the header): the app remembers that place, including its coordinates, on your device until you switch back to your current location.
Nevertheless, your coordinates do leave the device in three places, and you should know about it:
- To display the place name in the header, we use them to query the Nominatim service of OpenStreetMap.
- For the personalised “For you” feed we pass them to our own server function as a calculation input. There they are used only for the calculation and are not stored permanently.
- When you open the map, your device loads map sections from a map server; that server thereby learns which section you are viewing, and your IP address.
In addition: if you tap “use current location” when creating a Zquad, exactly that point becomes the address of the meeting place — it is stored permanently and is visible on the map to all signed-in users.
2.4 Content you create
- Zquads with title, description, tags, category, cost information, time and duration, number of places, and location including coordinates.
- Your memberships in Zquads and the time you joined.
- Messages in group chats and direct messages including read status, and reactions to messages.
- Join requests including the personal message you can write to the host, as well as invitations and waiting list entries.
- Your rating of a host after a meet-up (thumbs up or down). The host only sees the overall total, never your individual vote.
- Memory photos: after a zquad has taken place, you can upload one photo and replace it any time. They are resized to at most 1600 pixels wide, stored in our file storage, and are visible only to the members and the host of that zquad — never publicly. Only upload photos you have the rights to, and be considerate of the people shown. You can replace or delete your photos at any time; they are also deleted when your account or the zquad is deleted. Any photo can be reported by the other members directly in the photo viewer; we review reported photos and remove them if they violate our rules.
- Public questions to a Zquad and the answers to them. They are visible to all signed-in users.
- Polls in the group chat, including date polls, together with your vote. The vote is stored with your user identifier; in the app we only show the totals.
- Notices the app posts in a group chat when you trigger them — for example “is on the way” with your username.
2.5 Connections and personal lists
- Who you follow and which topics (tags) you follow. Both are visible to signed-in users and control what is shown to you.
- Saved and hidden Zquads, your block list, your chat settings (pinned, muted, cleared, hidden, marked as unread), your read states and saved searches. These lists are visible only to you.
2.6 Notifications
- If you allow push notifications, we store the device identifier for delivery (push token) and the platform (iOS, Android or web).
- Your settings on which kinds of notifications you want to receive and which sound is played.
- The notifications themselves, so that you can read them again in the app.
- The weekly summary: once a week you receive a notification about how many new Zquads there are near you and on the topics you follow — only if there are any. We determine “near you” without your location: our server takes the centre point (median) of the places of the Zquads you are a member of and counts new Zquads within 50 km. This centre point is only formed for the calculation and is not stored. You can switch off the weekly summary in the notification settings.
2.7 Technical data and error reports
When an error occurs in the app, we send an error report to our own database: the error message, the technical stack trace, the place in the program, your operating system, the app version and your user identifier. At most 25 such reports are possible per session, identical errors are only reported once, and nothing at all is sent by this route before sign-in.
Since 12 August 2026 we additionally use Sentry as a crash reporting service (see section 4). The reason: the route above needs an existing sign-in and runs in the JavaScript part of the app. Crashes before sign-in, and those in the native part, therefore never reach it — and those are precisely the worst ones. What goes to Sentry is the error message with its technical stack trace, details about device and app, and the most recent network requests before the error; the specifics are in section 4.
As with every internet service, technical connection data arises at our service providers when content is retrieved, in particular the IP address, the time, the address called up and the device/browser identifier. We do not evaluate these logs ourselves; the providers delete them again according to their own schedules.
In the app and in the browser version we use no analytics services. Events to Meta and your device's advertising ID only exist if you agree to ad measurement (2.15); without your consent there is no tracking. The cookieless visitor count described under 2.10 runs on the website zquady.com only.
2.8 Security
- Failed attempts to re-enter your password or to redeem a recovery code are counted (after five failed attempts within 15 minutes there is a short block).
- The time of your last email or password change, because both are only possible once every 24 hours.
2.9 Support and reports
- If you write to us via the support form, we transmit your username, your email address, your user identifier as well as the category, subject and text of your enquiry by email to our mailbox.
- If you report a person, a Zquad or a message, we store the type and target of the report, a label of the reported content (such as the username), your reason for reporting and your user identifier. We take your identifier from your valid sign-in so that reports cannot be forged.
- We count how many emails our system sends in order to monitor the quota of our sending service and to limit abuse.
2.10 Visits to our website and link previews
For the website zquady.com — including the page you are reading right now — you do not need an account and do not have to sign in. When the page is called up, the usual server logs arise at the web host: IP address, time, address called up, referring page and browser identifier. We use them to deliver the pages and to fend off attacks; the legal basis is our legitimate interest in a functioning, secure web presence (Art. 6(1)(f) GDPR).
If someone shares a Zquad or profile link, it leads to a preview page at zquady.com/z/… or zquady.com/u/…. If such a link is pasted into a messenger or a social network, that provider's server retrieves the page on its own in order to generate the preview card — the provider thereby learns the address called up, and thus that this link has been shared. The preview pages do not require a sign-in; anyone who has the link sees:
- for a Zquad: title, date, city, category and the number of members and places. We do not show Zquads that are restricted to one gender there.
- for a profile: username, month of registration, rating as a percentage (only from five ratings), whether the phone is confirmed, the number of Zquads that took place which the person hosted or attended, and up to three badges they chose themselves. Profile picture, bio, tags, conversation starters, linked profiles, gender and age never appear there.
If you share a Zquad as an image, for example in your Instagram story, our server creates that image with the title, description, date, city, category, tags, occupancy, short code, the host's username, for in-person meet-ups the weather forecast for the meeting place, and a QR code with the link. Where you share the image is up to you; from then on the terms of the platform in question apply.
The legal basis for the previews and images is our legitimate interest in shared links being understandable (Art. 6(1)(f) GDPR); you can object as set out in 6.1.
The website sets no cookies and embeds no advertising services. We serve the typeface and images from our own web space, and no request is made to Google or any other provider.
There is one exception: we count visits using Cloudflare Web Analytics. For this, every page loads a small counting script from static.cloudflareinsights.com; in doing so Cloudflare learns your IP address, the address called up, the referring page and your browser identifier. The service works without cookies and stores no identifier in your browser — it therefore does not recognise you on a later visit and builds no profile. We ourselves only ever see totals: how many page views there were, from which countries and via which referring pages. The legal basis is our legitimate interest in learning whether and how our site is found (Art. 6(1)(f) GDPR). Because nothing is stored on or read from your device in the process, we do not ask for consent and show no cookie banner.
The website stores your language and theme choice locally in your browser (localStorage); this information never leaves your device.
2.11 Storage on your device
Besides what is held on our servers, the app stores some things directly on your device — exclusively for functions you use yourself:
- Your sign-in session in the protected system storage (iOS keychain or Android keystore) so that you stay signed in — see 2.1.
- Your settings in ordinary app storage: appearance (system, light, dark), language, sort orders, radius, vibration and your choice on ad measurement.
- Markers, so that the app does not ask twice or repeat the same notices — for example whether you have already seen the introduction, which questions on a Zquad you have already read, which steps of setting up your profile you skipped, and which Zquads you have already sent a join request to.
- A place you chose yourself, including its coordinates, if you set your place in the header (see 2.3).
- A cache so that content appears faster, for example your own profile.
- For Sentry, a random installation identifier and, if the app crashes, the crash report until it is sent on the next launch (see 4).
Advertising identifiers and data of the Meta SDK only arise on your device if you agree to ad measurement (2.15). The app stores no analytics values.
You get rid of all of it by uninstalling the app.
The browser version at app.zquady.com places the same things in your browser's storage (localStorage) instead of in system storage: your sign-in token, your chosen appearance and — as soon as you set a place or share your location — the place you last used, including its coordinates, so that the map does not jump back to the start after a reload. This information stays in your browser; there it is read only by the application itself. The browser version embeds no analytics or advertising services — the visitor count described under 2.10 runs on the website zquady.com only, not in the application. You remove all of it by signing out or by deleting the website data for app.zquady.com.
2.12 Linked profiles on Instagram and Discord
You may voluntarily store your Instagram and/or Discord profile in your Zquady profile. Nothing depends on it — the app works fully without these details. Facebook and TikTok profiles cannot be linked.
We store the profile name and, for Discord, additionally the account identifier from which the app builds the profile address. We only show a link to others once you have confirmed it — while unconfirmed, nobody but you sees it. This is how confirmation works:
- Instagram: the app shows you a short code, which you send us as a direct message to our Instagram account. We compare the sender against the stored name and then set the check mark; this can take up to 48 hours. The message itself sits in your inbox and ours at Meta; their terms apply to it.
- Discord: you briefly sign in with Discord and allow it there to confirm your username and your account identifier to us. We request nothing more: we receive no password, no messages and no contacts, and we use the access key only for this one request and do not store it.
For each confirmation we store the profile name, the status and the time, for Instagram additionally the code. If you later change or remove the profile name, the confirmation is deleted automatically. If someone taps a link, the platform in question opens — from that moment their privacy terms apply.
Who sees your linked profiles is additionally up to you in your privacy settings: everyone, nobody, people from shared Zquads and/or people you follow. The default is “everyone”. The decision is made on our server, not only when displaying on the device.
A profile name can only ever be linked to a single Zquady account. If you delete your account, the link and the confirmation go with it and the name is immediately free again.
2.13 Gender and single-gender Zquads
When you register you state your gender (woman, man or diverse). This is mandatory because a Zquad can be limited to one gender: whoever creates a Zquad can decide which genders can take part — their own is always included, for example “women only” or “women and diverse”. A Zquad restricted in this way is invisible to everyone else everywhere: not in the lists, not on the map, not via a link and not via an invitation. Our database enforces this, not just the app.
Your gender is never visible to other users — not in your profile, not in member lists and not in chats. It is evaluated exclusively on our server to decide which Zquads you see and whether you can send a request.
Join hint and asking together: if you request to join an open Zquad in which nobody of your gender has joined so far, the app tells you beforehand (“So far there are no women here”). This hint names no individual person, is shown only to you and is suppressed as soon as members have not stated a gender. You can then “ask together”: your request is held back until a second person of your gender asks, and is then sent to the host together with theirs. Until then the host learns nothing; for this we temporarily store your request together with your gender in a waiting list, which is deleted when the request is sent or when you withdraw it. The host then sees that the two requests were made together.
We do not (yet) verify this information. Gender is a self-declaration; no verification via ID document or other procedures currently takes place. False statements can be reported (2.9) and lead to measures under our Terms. If others can infer your gender from your username, your linked profiles, your photos, your chats or how you appear at meet-ups, that is beyond our control — what you reveal is your decision.
You can change this information at any time in your profile; it is deleted together with your account.
2.14 Verifying your phone number via WhatsApp
You can voluntarily confirm that there is a real person behind your profile by sending a code generated by the app to our number via WhatsApp. Meta transmits your phone number to us as the sender. We do not store the number in plain text, only an encrypted fingerprint (HMAC with a secret key) that lets us ensure one number verifies only a single Zquady account. Others see only that and since when your phone is verified, never the number. The message itself is not stored; our log keeps only the code and the outcome and is deleted after 60 days. WhatsApp’s terms (Meta Platforms Ireland Ltd.) apply to the transmission. You can remove the verification in your profile at any time; we then delete the fingerprint. If you delete your account, it is deleted as well. The legal basis is your consent (Art. 6(1)(a) GDPR).
2.15 Ad measurement with the Meta SDK
Zquady advertises on Instagram and Facebook. To learn whether an ad led to an install or sign-up, the Meta SDK is built into the app. Only with your consent does it send events to Meta Platforms Ireland Ltd.: app opened, sign-up completed, Zquad created, join requested, phone verified, each with device model, OS version, app version, language, time and your IP address and, if you additionally allow it on your device, your device’s advertising ID. No chat contents, no locations, no names. Meta uses the data to measure and deliver our ads; for this processing Meta and we are joint controllers (Art. 26 GDPR), see facebook.com/legal/terms/businesstools. We ask you once at first launch; you can change your consent at any time in the settings under Privacy › Tracking, on iOS also in the system settings under Tracking. Without consent the app reports no events to Meta and reads no advertising ID. Note on the current app version: the Meta SDK currently starts together with the app and may retrieve its basic settings from Meta in the process; your IP address and technical details such as the app and SDK version are sent to Meta. With the next app update, the SDK will only start after your consent. The legal basis is your consent (Art. 6(1)(a) GDPR).
2.16 Our profiles on Instagram and Facebook; contact via WhatsApp
Zquady has its own profiles on Instagram and Facebook (Meta Platforms Ireland Ltd.), and the website and the app link to them. These are plain links: as long as you don’t click, nothing is loaded from these providers and nothing is sent to them.
If you visit one of our profiles, the respective provider processes your data under its own terms, even if you don’t have an account there or aren’t logged in. From these visits, the platforms create aggregated statistics for us, for example on reach and interactions; we cannot identify individual people from them. Meta and we are joint controllers for the statistics on our Instagram and Facebook profiles (Art. 26 GDPR). Meta takes primary responsibility, including for handling your rights (facebook.com/legal/terms/page_controller_addendum). If you write to us or comment on one of our profiles, we see your profile name and your message and use them only to reply to you. The legal basis is our legitimate interest in making Zquady known and answering questions where the people Zquady is made for spend their time (Art. 6(1)(f) GDPR).
You can message us directly via the WhatsApp link. The message is sent through WhatsApp (Meta Platforms Ireland Ltd.); we see your phone number, your WhatsApp name and your message and use them only to handle your request. The legal basis is answering your request (Art. 6(1)(b) or (f) GDPR). If you’d rather not use WhatsApp for this, you can reach us just the same at support@zquady.com.
3. Purposes and legal bases
Performance of a contract, Art. 6(1)(b) GDPR — everything that is necessary for the app to do what you installed it for: your account and your sign-in, your profile, creating and finding Zquads, joining and requests, group and direct chats, ratings, the weather forecast for meeting places and the associated notices in the app.
Consent, Art. 6(1)(a) GDPR — processing that only takes place with your express permission and that you can withdraw at any time: access to your location, push notifications, access to your photos when uploading a profile picture, adding an appointment to your calendar, the voluntary presence indicator “I'm already there”, and linking your Instagram or Discord profile including its confirmation (2.12), verifying your phone number via WhatsApp (2.14) and ad measurement with the Meta SDK (2.15). You can withdraw these permissions in your device's system settings and in part directly in the app; the withdrawal takes effect for the future.
Legitimate interests, Art. 6(1)(f) GDPR — security and abuse prevention: limiting sign-in and change attempts, the blocking and reporting functions, handling reports, error reports for the stability of the app, and the restriction on username changes. Our interest is a safe service on which strangers can actually meet each other without danger. We also base the link previews and the visitor count on the website (2.10) and the weekly summary (2.6) on legitimate interests. You can object as set out in 6.1.
Legal obligations, Art. 6(1)(c) GDPR — for example, information provided to authorities on the basis of statutory duties, and compliance with statutory retention obligations where they apply to us.
We process the age information because Zquady is intended exclusively for adults. The legal basis for this is performance of the contract (Art. 6(1)(b) GDPR): being of age is a prerequisite of the user agreement.
We process your gender in order to show Zquads that are limited to one gender only to the matching people, for the join hint and for asking together (2.13). The legal basis is performance of the contract (Art. 6(1)(b) GDPR); restricting a Zquad to one gender also serves our legitimate interest and that of our users in safe meet-ups between strangers (Art. 6(1)(f) GDPR).
4. Recipients and services used
We do not sell data. For advertising purposes, something only goes to Meta with your consent (2.15). We do, however, use service providers without which the app would not work. Where a service processes data on our behalf, it does so under a data processing agreement pursuant to Art. 28 GDPR. For each service we state where it is based and whether data goes to a country outside the EU or the EEA in the process. We base transfers to the USA on the European Commission's adequacy decision on the EU-US Data Privacy Framework where the provider is certified under it, and otherwise on the European Commission's standard contractual clauses (Art. 45, 46 GDPR). You can obtain a copy of the standard contractual clauses on request at privacy@zquady.com.
- Supabase (Supabase, Inc., USA) — our backend: accounts and sign-in, database, file storage for photos, realtime connection for chats, and server functions. Practically all of the data listed under point 2 is held here. Our project runs in the Ireland region; the database, authentication and file storage are therefore located in the EU. Access by the provider from third countries, for example for operations and support, cannot be ruled out.
- Cloudflare (Cloudflare, Inc., USA) — placed in front of our programming interface; it also hosts the browser version at app.zquady.com. In doing so, Cloudflare processes the technical connection data of all requests, including in the USA. In addition, Cloudflare Web Analytics counts visits to the website zquady.com — cookieless and without recognition; details under 2.10.
- Expo (650 Industries, Inc., USA) — sending push notifications. Important and easily overlooked: the notification text is transmitted in plain text. For a direct message that is the sender's name and roughly the first 120 characters of the message; in a group chat additionally the Zquad title; for join requests an excerpt of your personal message. From Expo, delivery continues to Apple (APNs) on iOS or Google (FCM) on Android. On Android, Google’s Firebase Cloud Messaging is built into the app for this: on launch it creates a delivery identifier for your device (push token) and sends it to Google Ireland Ltd. together with technical details such as device model, operating system version and IP address — even before you have allowed notifications. Google Analytics for Firebase is not included. If you do not want that, switch off the relevant notifications in the app or in your system settings.
- Expo/EAS Updates (650 Industries, Inc., USA) — on launch the app checks whether a new program version is available. Technical details such as the IP address, platform and app version are transmitted in the process; no account data.
- Apple and Google (Apple Distribution International Ltd. and Google Ireland Ltd., both Ireland) — delivery of push notifications (see Expo), sign-in with Apple or Google if you choose it, and distribution of the app through their stores. Transfers to the parent companies in the USA are possible.
- Resend (Resend, Inc., USA) — email delivery: sign-in, confirmation and recovery codes, the welcome email and security notices to you (for example for a new passkey or a changed email address), support enquiries and abuse reports to our mailbox, and an internal daily report containing purely aggregate figures to an internal mailbox of the operator. The images in our emails (logo and icons) are hosted on zquady.com and are only loaded once your mail program displays images; our webspace provider then sees your IP address and the time. These addresses contain nothing that identifies you — every email loads the same image. We additionally publish our logo via the BIMI method in our domain's directory so that some mail programs show it next to the sender; the image file is held in our own storage.
- EasyDMARC (EasyDMARC Inc., USA) — evaluation of the reports other mail providers send us about messages dispatched in our name (DMARC). The aggregate reports contain IP addresses of sending servers and counts; individual failure reports may additionally contain header lines of an affected message, such as sender, recipient and subject. We use this solely to detect misuse of our sender address. The legal basis is our legitimate interest in secure email delivery (Art. 6(1)(f) GDPR).
- Apple iCloud Mail (Apple Distribution International Ltd., Ireland) — our mailboxes support@, privacy@ and info@zquady.com are hosted on iCloud. Emails to us and enquiries from the support form arrive there; transfers to Apple Inc. in the USA are possible.
- Nominatim (OpenStreetMap Foundation, United Kingdom; adequacy decision of the European Commission) — converting coordinates into place names, and place search. Your coordinates or your search term and your IP address are transmitted.
- OpenFreeMap (Hyperknot Software Kft., Hungary) and map data by OpenStreetMap contributors — map background in the app. The requested map section and your IP address are transmitted.
- Open-Meteo (OpenMeteo GmbH, Switzerland; adequacy decision of the European Commission) — weather forecast for the meeting place of a Zquad. Your device queries Open-Meteo directly; the coordinates of the meeting place, the date and your IP address are transmitted — not your own location. For images to share (2.10), our server makes the request, without your IP address.
- Sentry (Functional Software, Inc., USA) — crash and error reports, so that we notice crashes without anyone having to report them to us. Transmitted are: the error message with its technical stack trace, device model and operating system version, app and build version, language setting, battery level and free memory, a random installation identifier for your device, and the app's most recent network requests before the error. Those requests include query parameters that may contain your user identifier and identifiers of Zquads — no names, no email addresses, no message contents, no passwords. From the IP address Sentry derives a coarse location on receipt (country, region and city); the IP address itself is not stored. Our Sentry project runs in the EU region with servers in Germany; access by the provider from the USA, for example for operations and support, cannot be ruled out. Performance and usage measurement is switched off.
- Meta (Meta Platforms Ireland Ltd., Ireland) — only if you use the function in question: ad measurement with the Meta SDK (2.15, joint controllership), phone verification via WhatsApp (2.14), confirmation of your Instagram profile by direct message (2.12), and contact via WhatsApp or our profiles (2.16). Meta also transfers data to Meta Platforms, Inc. in the USA.
- Discord (Discord Inc., USA) — sign-in with Discord if you choose it, and confirmation of your Discord profile (2.12). Discord thereby learns that you are signing in to Zquady or confirming a profile.
- united-domains GmbH, Germany (united-domains.de) — hosting of the website zquady.com with the legal texts and the link previews. Address: Gautinger Straße 10, 82319 Starnberg, Germany.
- CARTO — map background in the browser version at app.zquady.com. When the map loads, map tiles are fetched directly from
basemaps.cartocdn.com; CARTO thereby receives your IP address, your browser identifier and — from the map section requested — the area you are currently looking at.
Two particularities that are not classic service providers:
- If someone inserts a link to an image or GIF into a chat, your app loads that image directly from the third-party server. That server thereby learns your IP address. We have no influence over this.
- If you tap “open in maps”, your device passes the address of the meeting place to your maps app (Apple Maps or Google Maps). If you add a Zquad to your calendar, the entry initially stays on your device — if your calendar syncs with an online service, it ends up there as well.
5. Storage period and deletion
The principle: we store your messages, your Zquads and your profile for as long as your account exists. Fixed retention periods apply to the remaining categories; once they expire, we delete the data:
- Notifications
- 90 days.
- Error reports
- 90 days.
- Counter of our email dispatch
- 90 days.
- Reports about users
- 12 months after the report has been dealt with.
- Counted failed sign-in attempts
- 2 days.
- Support enquiries and emails to us
- for as long as needed to handle them and for possible follow-up questions, at most three years after completion (general limitation period).
- Log of confirmations by direct message
- 60 days.
- Messages, Zquads and profile
- for as long as your account exists — what happens on deletion is set out in point 5.1.
5.1 What happens when you delete your account
You can delete your account yourself at any time in the app under Profile › Settings. Deletion takes effect immediately and cannot be undone — there is no waiting period and no recycle bin. Deleted in the process are your sign-in data including linked sign-in providers, your profile including an uploaded profile photo, your memory photos from past Zquads, your messages (including those in other people's group chats and both sides of your direct chats), your memberships, requests, lists, settings and push tokens. Your email address is immediately available again for a new registration afterwards.
Important for others: Zquads you created disappear entirely — together with the group chat, the memberships and the memory photos of the other participants.
5.2 What survives deletion
Not everything disappears with the account. What remains is listed here in full — and for each item it is stated whether it still has a link to you.
- Abuse reports are retained so that deleting an account does not become a tool for covering tracks. If you filed the report yourself, your identifier is removed from it. The label of the reported content — a username, for instance — remains stored in plain text; so if you were reported, the report can continue to name you. Legal basis: legitimate interest in investigating breaches (Art. 6(1)(f) GDPR). Reports are deleted automatically 12 months after they have been dealt with.
- Error reports are retained; the user identifier is removed from them. The text of an error report is technical in nature but may in individual cases contain remnants of a program run. Error reports are deleted automatically after 90 days.
- The counter of our email dispatch is retained as a bare tally line; the user identifier is removed from it when the account is deleted. What remains is only a timestamp and an occasion — with no link to you. These entries are also deleted automatically after 90 days.
Backups: our backend provider creates technical backups daily and keeps them for up to 7 days. Deleted data can persist in them until the backups are overwritten.
6. Your rights
Under the GDPR you have the right of access (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18) and to data portability (Art. 20). You can withdraw consent you have given at any time with effect for the future (Art. 7(3)). Your right to object is set out separately under 6.1.
You can exercise much of this directly in the app: change your profile, bio and avatar, adjust visibility settings, switch off individual notification types, review and withdraw permissions, block people, clear chats, delete your account.
For data portability there is a file export in the settings under “My data”. It contains your account key details, your profile, the Zquads you created, your memberships and the topics you follow. Not included are, among other things, messages, notifications, blocks, saved searches and reports — for those, please write to us at privacy@zquady.com and we will compile the remaining data for you.
If you believe that we are processing your data incorrectly, you can lodge a complaint with a supervisory authority. The competent authority is the Austrian Data Protection Authority (Österreichische Datenschutzbehörde), Barichgasse 40–42, 1030 Vienna, dsb.gv.at.
6.1 Your right to object
Where we base processing on our legitimate interests (Art. 6(1)(f) GDPR), you can object at any time on grounds relating to your particular situation (Art. 21(1) GDPR). This concerns security and abuse prevention including the handling of reports, error reports including Sentry, the link previews, the visitor count on the website and the weekly summary. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, or the processing serves the establishment, exercise or defence of legal claims.
You can object to the weekly summary at any time without giving reasons — fastest with the switch in the notification settings. For any other objection, an informal sentence to privacy@zquady.com is enough.
7. Specifics of Zquady
The following points appear in no standard template, but they are the most important ones for you.
7.1 What others see of your location
Other users do not see your location. What they see is the meeting place of a Zquad — that is, the place the host entered when creating it. That place is stored with coordinates and is visible on the map to everyone who is signed in, whether or not they are taking part.
Hence this note for hosts: if you choose “use current location”, you make the place you were at that moment public. Better to give a meeting place you would also name publicly.
The presence indicator is voluntary and off by default. If it is switched on, your phone itself decides whether it is close to the meeting place and transmits only a yes or a no. Your coordinates do not leave the device in the process, and the other members only see a number — never who is there, and never exactly where.
7.2 Who sees your profile
Your username is visible to everyone who is signed in; it deliberately contains no real name. Anyone who has a link to your profile also sees it without an account — together with the few key details listed under 2.10. For your profile picture, bio and direct messages you can set individually who may see them: everyone, only people from shared Zquads, only people you follow, or nobody. Your initials always remain visible. The setting for direct messages is enforced directly in the database: someone who is not allowed cannot even create a message to you.
Nobody sees your gender — it appears nowhere in your profile and in no list (2.13).
Who is taking part in a Zquad is visible to all signed-in users via the Zquad’s member list – also before joining.
Who you follow and which topics you follow is visible to signed-in users. The same applies to your answers to conversation starters, the badges you chose and your confirmation check marks.
Uploaded profile photos are held in file storage whose addresses are not publicly listed. The “Who can see my profile picture?” setting is reliably enforced within the app; someone who knows a file address can, however, retrieve the photo regardless of it. Only upload photos whose visibility you are comfortable with.
7.3 Chats, blocking and deleting
Group chats can only be read by the members of the respective Zquad and by the host; direct messages only by the two people involved. If you block someone, their messages disappear for you and they can no longer reach you; this too is enforced in the database, not merely in the display.
“Clear history” only hides the history for you — the messages remain for the other people involved. If you delete your account, by contrast, your messages are removed everywhere.
Messages are not end-to-end encrypted. They are encrypted in transit and are held in our database; technically they can be viewed in the course of troubleshooting and when handling reports. Access to the administrative interface of the database is limited to the operator.
And once more, because it is easily overlooked: if push notifications are switched on, an excerpt of the message text is transmitted to the delivery service and to Apple or Google respectively (see point 4).
7.4 Being of full age, and your date of birth
Zquady is exclusively for people aged 18 and over, because strangers meet here in real life. Before an account is created we ask for your date of birth; if it is under 18, the account is not created, or a sign-up already in progress is ended immediately.
This is a self-declaration. We do not check identity documents and do not use any age verification service. Your date of birth remains stored with your account so that the confirmation is traceable and does not have to be requested again at every sign-in.
8. Minors
The app is not directed at people under 18, and we do not knowingly process data of minors. If you notice that a minor has created an account, please report it to us via the reporting function in the app or to privacy@zquady.com. We will delete such an account together with the associated data.
9. Changes to this policy
As we keep developing the app, this policy may change as well. The version published here is the one that applies in each case; the date at the top shows you when it was last changed. In the case of changes that materially affect you, we will inform you in the app or by email.
10. Contact
For questions about data protection or to exercise your rights, you can reach us at privacy@zquady.com or by phone at +43 664 99216386. In the app you will also find a support form under Profile › Settings › Support.
Postal address:
Zquady e.U. Linzer Straße 17 4100 Ottensheim Austria