In short: the FAYA app processes the data it needs to work – your account, profile, event RSVPs and chats. Your content is stored with providers in the EU. We show no ads in the app and never sell data. Chats are protected in transit and at rest but are not end-to-end encrypted. You can delete your account at any time inside the app.
Faya UG (haftungsbeschränkt), c/o Axel Dieterle, Solinger Str. 5, 40227 Düsseldorf, Germany · Managing director: Axel Dieterle · Commercial register: Amtsgericht Düsseldorf, HRB 100928 · E-mail: info@getfaya.app · Legal notice. This address is also our point of contact under Art. 11 and 12 of the Digital Services Act (German or English).
This policy covers the FAYA app for iPhone (iOS), including remaining Android installations of version 2. Two generations exist and differ technically. Where processing differs, it is marked Version 2 (the app available on the App Store since 2024, versions 2.x) or Version 3 (the newly built app from version 3.0). Unmarked sections apply to both. Your version is shown in the app settings or on the App Store.
Permissions are requested only when you use the related feature and can be changed in iOS Settings at any time: Photos (profile, groups, chat photos in version 3), Camera (version 3, chat photos), Microphone (voice messages), Location (distance to events, stays on the device), Notifications (device token), Tracking (version 2, ATT prompt – no advertising). Stored locally on your device: your session (encrypted keychain), settings such as language and city, a cache of recent messages and voice messages (version 3, cleared on sign-out), seen events and goodie proofs. The app does not read your contacts, calendar or other apps.
We only share data with the service providers we need to run the app, under data processing agreements (Art. 28 GDPR). Transfers outside the EU rely on the EU-US Data Privacy Framework (DPF), the EU Standard Contractual Clauses (SCC) or, for features you trigger yourself, Art. 49(1)(b) GDPR.
| Provider | Purpose | App | Location · basis |
|---|---|---|---|
| schnaq GmbH | Backend operation and maintenance, support mailbox for reports | Version 2 | Germany · processor |
| Scaleway SAS, Paris | Servers (Amsterdam), object storage (Paris/Amsterdam), system e-mails | Version 2 | EU · processor |
| Google Ireland Ltd. / Google LLC | Firebase (SMS sign-in, push, analytics, crash reports), Maps SDK, Tenor, YouTube | Version 2 | EU / USA · processor, DPF, SCC |
| Apple Inc. / Apple Distribution International Ltd. | Push delivery (APNs), Sign in with Apple (v2), MapKit (v3), App Store | both | Ireland / USA · DPF |
| Supabase, Inc. | Database, authentication, storage, server functions | Version 3 | Frankfurt (EU) · processor, SCC for support access |
| Twilio Inc. | SMS verification codes | Version 3 | USA · processor, DPF, SCC |
| PostHog Inc. | Usage analytics | Version 3 | Frankfurt (EU) · processor, SCC for support access |
| Functional Software, Inc. (Sentry) | Crash reports | Version 3 (backend also v2) | Frankfurt (EU) · processor, DPF |
| Giphy, Inc. (Shutterstock, Inc.) | GIF search and delivery | Version 3 | USA · Art. 49(1)(b), only on your action |
| Ticket i/O GmbH, Cologne | Ticket shop (browser), order data sent to us | both | Germany · independent controller |
Instagram, TikTok, Facebook, Spotify, SoundCloud, YouTube, WhatsApp, Telegram or a maps app only receive data when you tap a link or share content yourself. Authorities receive data only where the law obliges us (Art. 6(1)(c)).
| Data | Retention |
|---|---|
| Account, profile, photos, settings | until you delete your account |
| RSVPs, likes, connections, follows | until withdrawn, at the latest until account deletion |
| Chat messages and media | until the message, connection or account is deleted (version 2: also on block or report) |
| Push device token | until you withdraw permission, sign out (version 3) or delete your account |
| Reports and blocks | blocks until lifted; reports until reviewed, at most 12 months |
| Ban for serious violations (hashed phone number) | up to 3 years |
| Usage analytics | at most 12 months; Firebase Analytics at most 14 months |
| Crash reports | 90 days |
| Goodies, sweepstakes, Secret Link applications | up to 12 months after the event |
| Ticket order data | statutory retention periods (see website policy) |
| Server logs | at most 30 days |
Delete your account any time in the app: Profile → Settings → "Delete account", or e-mail info@getfaya.app (ideally from or with the phone number of your account). This deletes your account, profile, photos, RSVPs, likes, connections, chats and chat media, push tokens, group memberships, reports and blocks (version 2: also your Firebase sign-in account). Group messages you wrote may remain visible to other members without your name. Secret Link applications, goodie redemptions and analytics are detached from your account and deleted when the periods above expire. Data we must keep by law is retained only for that purpose. Accounts unused for more than 24 months may be deleted after prior notice.
FAYA is for adults aged 18 and over only. We check your date of birth at sign-up and do not knowingly process data of minors; such accounts are deleted.
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), to withdraw consent at any time with future effect (Art. 7(3)) and to object to processing based on legitimate interests (Art. 21), for example analytics or crash reports. Send requests to info@getfaya.app; we reply within one month.
Complaints: you may lodge a complaint with a supervisory authority. The authority responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany, www.ldi.nrw.de – or the authority of your place of residence.
We protect your data with technical and organisational measures under Art. 32 GDPR: TLS encryption in transit, encrypted session storage on your device, database access rules limiting each account to its own data and what features require (version 3), at-rest encryption of 1:1 chat text (version 2), short-lived signed links for chat media (version 3), and need-to-know access for staff and providers. We update this policy when the app or the law changes and inform you in the app about material changes. The current German version at faya.events/app/datenschutz prevails.