Privacy Policy

Indaba app and openindaba.org · Version 1 · Effective 10 October 2026

The short version

1. Who is responsible

The controller responsible for your personal data under the General Data Protection Regulation (GDPR) is:

Franz Mohr
[Postal address]
Email: franz.x.mohr@gmail.com

Write to this address with any question about your data or to exercise any of your rights.

This policy covers the Indaba app on Android, the Indaba web app, and the openindaba.org website.

2. What we process and why

Your account

What
  • Your email address and password. The password is stored only as a secure hash by Firebase Authentication.
  • The country or space you registered for.
  • The invite code you used.
  • When your account was created, and whether your email address has been verified.
Why
  • To create your account and let you sign in.
  • To send you a verification email and password-reset emails.
  • To make sure only invited people take part, and that each person takes part in their own country.
Legal basis
Performance of the contract with you, which is providing the service you signed up for (Art. 6(1)(b) GDPR).

For private spaces run for an organisation, we check the domain of your email address (the part after the @) to confirm you belong to that organisation.

Your contributions

What
  • The problems, causes, goals and measures you submit.
  • The entries you support.
  • The country and the time of each contribution.
Why
Civic participation: collecting and showing what people see as problems in their country, and how much support each one has.
Legal basis
Your explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR), which you give when you register. Contributions can reveal political opinions, which the GDPR treats as a special category of data, so we accept contributions only from accounts that have given this consent. We keep a record of when you consented and to which version of the consent text.

Feedback you send us

What
  • Your message.
  • If you are signed in, your account ID and email address.
  • The app version, platform (Android or web), language, the country you have selected, and whether you were signed in.
Why
To understand and fix problems and to improve the app.
Legal basis
Our legitimate interest in running and improving the service (Art. 6(1)(f) GDPR).

You can send feedback without being signed in. It is then not linked to any account.

Reports about content

What
  • When you report a contribution, we store your account ID, which contribution you reported, the reason, any note you add (at most 500 characters), and when you reported it.
  • When we act on a report, we record that the contribution was hidden.
Why
To find and remove unlawful or abusive content, and to stop the same person reporting the same item repeatedly.
Legal basis
Our legitimate interest in keeping the platform lawful and usable (Art. 6(1)(f) GDPR).

Only the operator can see reports. The author of the reported content is never told who reported it.

Usage statistics and crash reports (only if you switch them on)

This is off by default. You can switch it on or off at any time in Settings.

What, if you switch it on
  • Google Analytics for Firebase records anonymous usage events, for example "a problem was submitted" or "support was added", together with the country and the type of entry.
  • On Android, Firebase Crashlytics sends a crash report when the app crashes. The report contains technical details about the error and your device.
  • Both are tagged with your random account ID so that events from the same account can be grouped. They never contain the text of your contributions or your email address.
Why
To find bugs and to learn which parts of the app are used.
Legal basis
Your consent (Art. 6(1)(a) GDPR and § 165(3) of the Austrian Telecommunications Act 2021). Switching it off stops collection from that moment on.

Technical data when you use the service

What
Your IP address, browser or device type, and the time of each request. Our hosting and backend providers process these automatically and briefly log them.
Why
To deliver the app and website, and to keep them secure against abuse and attacks.
Legal basis
Our legitimate interest in running a secure service (Art. 6(1)(f) GDPR).

Data stored on your device

The app stores your settings on your device so it remembers them:

On Android it also keeps a local copy of your own contributions so they load quickly.

All of this is needed for the service you asked for (§ 165(3) of the Austrian Telecommunications Act 2021), and none of it is sent anywhere else. Neither the app nor this website sets advertising or tracking cookies.

To remove this data, uninstall the app or clear the site data in your browser.

No profiling, no automated decisions

We do not make decisions about you by automated means, we do not build advertising profiles, and we do not sell your data.

3. What other people can see

Indaba is a public forum, so contributions in a public country are visible to everyone, including people who are not signed in.

Please note: because each contribution carries your account ID, someone with technical skills can collect everything submitted or supported under the same ID. That ID is not your name, but your contributions can still identify you if you mention personal details in them. We recommend that you do not write your name or other identifying details into your contributions.

Contributions in a private space are visible only to members of that space.

4. AI features

The app is designed so that it could, in the future:

These features are currently switched off, and no text you write is sent to an AI service. Before switching them on, we will update this policy to name the provider, the location of processing and the safeguards that apply.

5. Who receives your data

We use the following service providers. They process data only on our instructions under a data processing agreement (Art. 28 GDPR):

If you install the app from Google Play, Google processes data about your download and your device as an independent controller under Google's own privacy policy.

Apart from that, we pass your data on only if the law requires us to, for example under a court order.

6. Where your data is stored

Our database and server functions run in Google's Frankfurt, Germany data centre (region europe-west3).

Some Firebase services operate globally and may process data in the United States. These include Authentication, Hosting and, if you switch them on, Analytics and Crashlytics. Google LLC is certified under the EU–U.S. Data Privacy Framework, which the European Commission has found to provide an adequate level of protection (Art. 45 GDPR). Google also applies the EU Standard Contractual Clauses (Art. 46 GDPR).

7. How long we keep it

8. Your rights

Under the GDPR you have the right to:

For anything the app does not let you do yourself, email franz.x.mohr@gmail.com. We will answer within one month.

You also have the right to lodge a complaint with a data protection supervisory authority. In Austria this is:

Österreichische Datenschutzbehörde
Barichgasse 40–42, 1030 Wien, Austria
www.dsb.gv.at · dsb@dsb.gv.at

You can also complain to the authority in the EU country where you live or work.

9. Children

Indaba is not intended for children under 14. If you are under 14, please do not register. If we learn that a child under 14 has registered, we will delete the account.

10. Security

We protect your data in these ways:

11. Changes to this policy

We will update this policy when the app or the law changes. The version and date at the top show which version applies. If a change affects what you consented to, the app will ask for your consent again before it processes your data in the new way.