Legal
Privacy Policy
Effective date: July 26, 2026
This Privacy Policy explains how Friebly ("we", "us", or "our") collects, uses, and protects information about you when you use our mobile application ("App") or website ("Site"). We are committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable Swedish data protection law.
By using Friebly you agree to the collection and use of information as described in this policy.
1. Data Controller
Friebly is the data controller responsible for your personal data. For the purposes of GDPR, our processing activities are based in Sweden.
2. Information We Collect
We collect the following categories of personal data when you use Friebly:
Phone Number
We collect your phone number to verify your identity during registration using a one-time passcode (OTP). Your phone number is hashed before storage and is not shared with other users in its raw form.
Profile Information
You may optionally provide a display name and profile photo. This information is visible to your friends on the platform.
Contact List
With your permission, we access your device's contact list to identify which of your existing contacts have also registered with Friebly. We hash the phone numbers from your contacts before sending them to our servers for matching. Raw contact data is never stored on our servers beyond the duration of the matching request.
Location Data
When you choose to drop a meet-up pin within the App, we collect your approximate location at that point in time. We do not continuously track your location. Location data associated with a signal is deleted when the signal expires.
Signals and Messages
We store the content of the signals you post (activity type, duration, and optional note) and the ephemeral chat messages exchanged within a signal group. Chat messages are encrypted server-side and are automatically deleted when the signal closes.
Device and Usage Data
We may collect technical data including your device type, operating system version, App version, push notification token, and anonymised usage events (e.g. feature interactions). This data is used solely to operate and improve the App.
3. Legal Basis for Processing
Under the GDPR, we process your personal data on the following legal bases:
- Performance of a contract— processing your phone number for authentication and storing your profile and signals is necessary to provide the Service you signed up for.
- Consent— accessing your contact list and location are based on your explicit consent, which you may withdraw at any time.
- Legitimate interests— collecting anonymised usage data and operating security measures to protect the platform.
4. How We Use Your Information
We use the information we collect to:
- Create and manage your account.
- Authenticate you securely via phone number verification.
- Display your profile to your friends.
- Enable you to post signals and join friends' signals.
- Facilitate friend discovery by matching hashed phone numbers from your contact list.
- Deliver push notifications for friend signals and chat messages.
- Show meet-up map pins within active signal groups.
- Monitor and improve the performance and security of the App.
- Comply with our legal obligations.
We do not use your data for targeted advertising, and we do not sell your personal data to any third party.
5. Data Sharing
We do not sell or rent your personal data. We may share data with the following categories of third parties solely to operate the Service:
- Cloud infrastructure— we use Amazon Web Services (AWS) to host the App backend in the EU (Stockholm region). AWS is certified under the EU–US Data Privacy Framework.
- Push notifications— we use Apple Push Notification Service (APNs) and Google Firebase Cloud Messaging (FCM) to deliver notifications. These services receive only an anonymised device token and the notification payload.
- Identity verification— we use Amazon Cognito for secure user authentication. Cognito processes your phone number in accordance with AWS's privacy commitments.
All third-party processors are subject to data processing agreements (DPAs) and are obligated to process your data only on our behalf and in accordance with our instructions.
We may also disclose your data when required to do so by law, court order, or to protect the rights, property, or safety of Friebly, our users, or the public.
6. Data Retention
We retain your data for the following periods:
- Account data(profile, hashed phone number): retained while your account is active and deleted within 30 days of account deletion.
- Signals: deleted automatically at signal expiry, with a maximum retention period of 2 hours.
- Chat messages: deleted from our servers when the signal closes.
- Location data(meet-up pins): deleted together with the associated signal.
- Anonymised usage data: retained for up to 24 months for analytics purposes.
7. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), you have the following rights in relation to your personal data:
- Right of access— you may request a copy of the personal data we hold about you.
- Right to rectification— you may ask us to correct inaccurate or incomplete data.
- Right to erasure— you may ask us to delete your personal data ("right to be forgotten"). You can do this directly by deleting your account in the App settings.
- Right to restrict processing— you may ask us to pause processing of your data under certain circumstances.
- Right to data portability— you may request your data in a structured, machine-readable format.
- Right to object— you may object to processing based on legitimate interests.
- Right to withdraw consent— where processing is based on consent (e.g. contact list access, location), you may withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please use the account settings in the App. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at imy.se.
8. International Data Transfers
Your data is primarily stored and processed within the EU (AWS eu-north-1, Stockholm). Where transfers to third parties outside the EEA occur (e.g. APNs, FCM), we rely on Standard Contractual Clauses (SCCs) or adequacy decisions by the European Commission to ensure an appropriate level of protection.
9. Security
We implement technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:
- TLS encryption for all data in transit.
- AES-256-GCM encryption for chat messages at rest.
- Hashing of phone numbers using HMAC-SHA256 with a secret pepper.
- Role-based access controls and least-privilege infrastructure.
- Regular security reviews and dependency audits.
While we strive to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.
10. Children's Privacy
Friebly is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has provided us with personal data, please contact us so we can promptly remove that information.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice in the App or by other appropriate means before the change takes effect. Your continued use of the App after the updated policy takes effect constitutes your acceptance of the revised policy.
We recommend reviewing this policy periodically. The "Effective date" at the top of this page indicates when the latest version was published.