Privacy Policy
The short version
- To take part you need an email address, a password and an invite code. We do not ask for your name, address, phone number or date of birth.
- What you contribute (problems, causes, goals, measures and your support for them) can reveal your political opinions. We process it only with your explicit consent.
- Contributions are public and linked to a random account ID, not to your name or email. Someone who looks closely can group together everything submitted under the same account ID.
- Usage statistics and crash reports are off unless you switch them on.
- You can export all your data and delete your account in the app's Settings at any time. Deleting your account removes your contributions.
- Your data is stored in Frankfurt, Germany, by Google Firebase. We do not sell it, use it for advertising, or share it with anyone else.
1. Who is responsible
The controller responsible for your personal data under the General Data Protection Regulation (GDPR) is:
Franz Mohr[Postal address]
Email: franz.x.mohr@gmail.com
Write to this address with any question about your data or to exercise any of your rights.
This policy covers the Indaba app on Android, the Indaba web app, and the openindaba.org website.
2. What we process and why
Your account
- What
-
- Your email address and password. The password is stored only as a secure hash by Firebase Authentication.
- The country or space you registered for.
- The invite code you used.
- When your account was created, and whether your email address has been verified.
- Why
-
- To create your account and let you sign in.
- To send you a verification email and password-reset emails.
- To make sure only invited people take part, and that each person takes part in their own country.
- Legal basis
- Performance of the contract with you, which is providing the service you signed up for (Art. 6(1)(b) GDPR).
For private spaces run for an organisation, we check the domain of your email address (the part after the @) to confirm you belong to that organisation.
Your contributions
- What
-
- The problems, causes, goals and measures you submit.
- The entries you support.
- The country and the time of each contribution.
- Why
- Civic participation: collecting and showing what people see as problems in their country, and how much support each one has.
- Legal basis
- Your explicit consent (Art. 9(2)(a) and Art. 6(1)(a) GDPR), which you give when you register. Contributions can reveal political opinions, which the GDPR treats as a special category of data, so we accept contributions only from accounts that have given this consent. We keep a record of when you consented and to which version of the consent text.
Feedback you send us
- What
-
- Your message.
- If you are signed in, your account ID and email address.
- The app version, platform (Android or web), language, the country you have selected, and whether you were signed in.
- Why
- To understand and fix problems and to improve the app.
- Legal basis
- Our legitimate interest in running and improving the service (Art. 6(1)(f) GDPR).
You can send feedback without being signed in. It is then not linked to any account.
Reports about content
- What
-
- When you report a contribution, we store your account ID, which contribution you reported, the reason, any note you add (at most 500 characters), and when you reported it.
- When we act on a report, we record that the contribution was hidden.
- Why
- To find and remove unlawful or abusive content, and to stop the same person reporting the same item repeatedly.
- Legal basis
- Our legitimate interest in keeping the platform lawful and usable (Art. 6(1)(f) GDPR).
Only the operator can see reports. The author of the reported content is never told who reported it.
Usage statistics and crash reports (only if you switch them on)
This is off by default. You can switch it on or off at any time in Settings.
- What, if you switch it on
-
- Google Analytics for Firebase records anonymous usage events, for example "a problem was submitted" or "support was added", together with the country and the type of entry.
- On Android, Firebase Crashlytics sends a crash report when the app crashes. The report contains technical details about the error and your device.
- Both are tagged with your random account ID so that events from the same account can be grouped. They never contain the text of your contributions or your email address.
- Why
- To find bugs and to learn which parts of the app are used.
- Legal basis
- Your consent (Art. 6(1)(a) GDPR and § 165(3) of the Austrian Telecommunications Act 2021). Switching it off stops collection from that moment on.
Technical data when you use the service
- What
- Your IP address, browser or device type, and the time of each request. Our hosting and backend providers process these automatically and briefly log them.
- Why
- To deliver the app and website, and to keep them secure against abuse and attacks.
- Legal basis
- Our legitimate interest in running a secure service (Art. 6(1)(f) GDPR).
Data stored on your device
The app stores your settings on your device so it remembers them:
- the selected country, language and colour theme
- whether you have seen the tutorial
- whether statistics are switched on
- your sign-in session
On Android it also keeps a local copy of your own contributions so they load quickly.
All of this is needed for the service you asked for (§ 165(3) of the Austrian Telecommunications Act 2021), and none of it is sent anywhere else. Neither the app nor this website sets advertising or tracking cookies.
To remove this data, uninstall the app or clear the site data in your browser.
No profiling, no automated decisions
We do not make decisions about you by automated means, we do not build advertising profiles, and we do not sell your data.
3. What other people can see
Indaba is a public forum, so contributions in a public country are visible to everyone, including people who are not signed in.
- Public:
- the title and text of each problem, cause, goal and measure
- its country and when it was created
- how many people support it
- the random account ID it was submitted or supported under
- Not public:
- your email address
- your consent record
- the space you registered for
- your feedback and reports
Please note: because each contribution carries your account ID, someone with technical skills can collect everything submitted or supported under the same ID. That ID is not your name, but your contributions can still identify you if you mention personal details in them. We recommend that you do not write your name or other identifying details into your contributions.
Contributions in a private space are visible only to members of that space.
4. AI features
The app is designed so that it could, in the future:
- summarise new problems with an AI language model
- detect problems that may already have been submitted
These features are currently switched off, and no text you write is sent to an AI service. Before switching them on, we will update this policy to name the provider, the location of processing and the safeguards that apply.
5. Who receives your data
We use the following service providers. They process data only on our instructions under a data processing agreement (Art. 28 GDPR):
- Google (Firebase): Firebase Authentication, Cloud Firestore (database), Cloud Functions (server logic), Firebase Hosting, and, only if you switch them on, Google Analytics for Firebase and Firebase Crashlytics.
If you install the app from Google Play, Google processes data about your download and your device as an independent controller under Google's own privacy policy.
Apart from that, we pass your data on only if the law requires us to, for example under a court order.
6. Where your data is stored
Our database and server functions run in Google's Frankfurt, Germany data centre (region europe-west3).
Some Firebase services operate globally and may process data in the United States. These include Authentication, Hosting and, if you switch them on, Analytics and Crashlytics. Google LLC is certified under the EU–U.S. Data Privacy Framework, which the European Commission has found to provide an adequate level of protection (Art. 45 GDPR). Google also applies the EU Standard Contractual Clauses (Art. 46 GDPR).
7. How long we keep it
- Account, consent record and contributions: until you delete your account. Deletion removes your contributions and your support from all counts, and erases the link between you and the invite code you used.
- Feedback and reports you sent while signed in: deleted together with your account at the latest.
- Feedback sent while signed out: cannot be linked to you. It is kept only as long as we need it to act on it.
- Crash reports: deleted by Firebase Crashlytics after 90 days.
- Usage statistics: event-level data is deleted after the retention period set in Google Analytics, which is 2 months. Deleting your account does not remove statistics already collected, but they are linked only to your random account ID and expire on this schedule.
- Technical logs: kept only for the short periods our providers use for security and operations.
8. Your rights
Under the GDPR you have the right to:
- access your data (Art. 15). Settings → Export my data shows everything we hold about you.
- data portability (Art. 20). The same export is in a machine-readable format (JSON).
- erasure (Art. 17). Settings → Delete account permanently removes your account and data.
- withdraw your consent at any time (Art. 7(3)).
- Your consent to processing your contributions is the basis of your participation, so you withdraw it by deleting your account.
- You withdraw consent to statistics with the switch in Settings.
- Withdrawal does not affect processing that took place before it.
- rectification (Art. 16) and restriction of processing (Art. 18).
- object to processing based on our legitimate interests (Art. 21).
For anything the app does not let you do yourself, email franz.x.mohr@gmail.com. We will answer within one month.
You also have the right to lodge a complaint with a data protection supervisory authority. In Austria this is:
Österreichische DatenschutzbehördeBarichgasse 40–42, 1030 Wien, Austria
www.dsb.gv.at · dsb@dsb.gv.at
You can also complain to the authority in the EU country where you live or work.
9. Children
Indaba is not intended for children under 14. If you are under 14, please do not register. If we learn that a child under 14 has registered, we will delete the account.
10. Security
We protect your data in these ways:
- All connections are encrypted (HTTPS/TLS), and data is encrypted at rest by Google.
- Access rules in the database make sure that nobody but you can read your private records.
- Writes go through server-side checks, including a check that you have given consent.
- Text you write is never written to server logs.
11. Changes to this policy
We will update this policy when the app or the law changes. The version and date at the top show which version applies. If a change affects what you consented to, the app will ask for your consent again before it processes your data in the new way.