Noxentry

Noxentry Privacy Policy

This Privacy Policy explains what data Noxentry collects, why, and the rights you have under the GDPR. It describes the app as it currently works and is updated when our processing changes.

Controller (Verantwortlicher)

The data controller for Noxentry is Majd Joukhadar, Karwendelstraße 2, 86356 Neusäß, Germany, email info@noxentry.de. Full provider details are in the in-app Imprint (Impressum).

Data We Collect

Noxentry collects account details you provide, such as name, nickname, email address, phone number, date of birth, country of birth, profile photo, and verification status. The app also stores safety alerts you create, including alert text, category, severity, location, photos, and videos.

Purposes and legal bases (GDPR Art. 6)

We process your data on the following legal bases: account creation and core service delivery (Art. 6(1)(b), contract); finding users near a new alert via short-lived location pings (Art. 6(1)(b), contract); push notifications and the background safety radar (Art. 6(1)(a), consent); content moderation (Art. 6(1)(f), legitimate interest in keeping the platform free of illegal content); compliance with deletion requests (Art. 6(1)(c), legal obligation); crash and error diagnostics to keep the service stable and secure (Art. 6(1)(f), legitimate interest). Optional identity-verification documents, which may reveal special categories of data, are processed only with your explicit consent (Art. 9(2)(a)).

Providing your data and minimum age

An email address, password and username are required to create an account, without them the Service cannot be provided. Your date of birth is required solely to confirm you meet our minimum age of 18; you cannot register without it. All other profile fields (phone number, profile photo, country of residence) are optional and you decide whether to provide them.

Location

Noxentry uses location to show nearby alerts, map navigation, and proximity warnings. When you create an alert, the alert location is saved with the alert. The app may also save recent location pings to help find users near a new safety alert. The optional background safety radar evaluates your location on your device only, that background location is not transmitted to our servers or any third party, and turning the radar off stops all background location use immediately.

Notifications

If you allow notifications, Noxentry stores your Expo push token and platform so it can send nearby-alert notifications. You can disable notifications in system settings.

Media and Verification

Photos, videos, and optional verification documents are uploaded only when you choose to submit them. Verification documents are used to review account verification status. Because such documents may reveal special categories of personal data, they are processed only with your explicit consent (Art. 9(2)(a) GDPR), stored in a restricted controller-only location, and deleted within 30 days of the verification decision.

Service Providers

Noxentry uses Supabase for authentication, database, storage, and Edge Functions; Expo for app services and push delivery; and Mapbox for maps, geocoding, and search. PostHog (EU-hosted, eu.i.posthog.com) processes crash and error diagnostics to keep the app stable and secure.

How Noxentry uses Google user data (Sign in with Google)

If you choose to sign in with Google, Noxentry receives only your basic Google profile through Google's sign-in service: your name, your email address, and your profile picture. We do not access, request, or store any other Google user data — no Gmail, Drive, Contacts, Calendar, or location data from your Google account.

Use: this data is used exclusively to create your Noxentry account, authenticate you when you sign in, pre-fill your profile (name and photo), and send you service messages at your email address. We do not use it for advertising, we do not build profiles with it, and we do not use it to train AI or machine-learning models.

Sharing: we never sell Google user data and never share it with third parties for their own purposes. It is processed only by the infrastructure providers listed under Service Providers (Supabase, acting as our authentication and database processor under GDPR Art. 28) in order to operate the service.

Storage and protection: the data is stored in our Supabase database, encrypted in transit (TLS) and at rest, with access restricted to authorized personnel.

Retention and deletion: we keep this data only while your account exists. You can delete your account in-app via Profile > Account > Delete account (this permanently and irreversibly erases your profile and data) or email us at info@noxentry.de; we respond within one month (Art. 12(3) GDPR). You can also revoke Noxentry's access to your Google account at any time at https://myaccount.google.com/permissions.

Noxentry's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

International transfers (Schrems II)

Some processors are located in the United States: Cloudflare (Workers AI moderation), Mapbox (maps and geocoding), and Expo (push delivery). Transfers rely on either the EU-US Data Privacy Framework or Standard Contractual Clauses (Commission Decision 2021/914). A Transfer Impact Assessment per processor is available on request from the controller.

Retention periods

Account profile: until account deletion. Alerts: until removed or account deleted. Density / zone pings: 30 days. Distress events: 90 days. Push tokens: until logout or token refresh. Alert reports and moderation appeals: 24 months as an audit trail. Verification documents: 30 days after the verification decision.

Your rights (GDPR Art. 15-22)

You have the right to access, rectification, erasure, restriction of processing, data portability, and to object to processing. You may exercise erasure in-app via Profile > Account > Delete account. For all other requests contact info@noxentry.de, we respond within one month (Art. 12(3) GDPR). You also have the right to withdraw any consent at any time without affecting the lawfulness of past processing.

Right to lodge a complaint

You have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU member state of your habitual residence. For German users this is typically the Landesdatenschutzbeauftragter of the controller's federal state, or the Bundesbeauftragter für den Datenschutz und die Informationsfreiheit (BfDI), Graurheindorfer Straße 153, 53117 Bonn, https://www.bfdi.bund.de.

Automated content moderation (GDPR Art. 22, DSA Art. 17)

When you submit an alert, the text is automatically checked by an automated content classifier before publication. Content classified as hate speech, sexual content involving minors, self-harm or weapons-related violence is blocked. You will be told the category that triggered the block, and you have the right to request a human review of the decision via the in-app appeal channel.

Tracking and Advertising

Noxentry does not sell personal data and does not use third-party advertising or cross-app tracking. We use PostHog (EU-hosted) only for crash and error diagnostics, not advertising, not cross-app tracking, and not for profiling or marketing.

Your Choices

You can control camera, photo library, microphone, location, and notification permissions in device settings. You can delete your account from Profile > Account > Delete account. For privacy requests, contact info@noxentry.de.