Privacy Policy
Last updated: August 5, 2026
1. Who we are
IDarU ("we") is the friends-challenge app for iOS and Android, with a website at idaru.app. The data controller is ⚠️ controller identification not yet published — missing, required by Article 13 GDPR, reachable at privacy@idaru.app.
This policy explains what we collect, why, who we share it with and how long we keep it.
2. Data we collect
Account: email, password (securely hashed by our authentication provider) or Apple/Google sign-in identifier; username, display name and profile picture (the last two optional).
Challenges and progress: challenges you create or join, goals, progress logs, streaks and trophies.
Proof photos: the photo you take in the app to prove you hit a goal, with its date, the goal it belongs to and who confirmed it.
Messages: the text of chat messages in each challenge, the GIFs you choose to send, the time and the author.
Moderation: reports you file or that are filed about your content (content type, reason, date) and the list of accounts you blocked.
Preferences: language, timezone, notification settings and reminder time.
Device: push notification token (Expo) and platform (iOS/Android).
Advertising: with your consent, Google AdMob may process the device advertising identifier. Without consent, non-personalized ads are shown.
Diagnostics: crash reports (Sentry) with app version, device model and the technical trace of the error — never the content of your messages or photos.
GIF search: when you open the GIF picker, your device talks directly to GIPHY (see section 6).
Website waitlist: if you sign up at idaru.app, we store the email address and the language you signed up in.
We do NOT collect: contacts, location, health data or audio — the app never asks for microphone access. We do not track you across apps without consent.
3. Why we use it, and on what legal basis
To provide the service (contract performance, GDPR art. 6(1)(b)): syncing challenges, progress, proof photos and messages between you and the members of your challenges, awarding trophies and keeping streaks.
Notifications (consent, art. 6(1)(a)): daily reminders and friend-activity alerts, all configurable and switchable off in settings.
Advertising (consent, art. 6(1)(a)): personalized ads only if you accept in the consent form; without it, ads are non-personalized.
Safety and moderation (legitimate interest, art. 6(1)(f)): reviewing reports, enforcing blocks, filtering offensive language and suspending abusive accounts — without this we cannot keep the community safe or meet app store rules.
Stability (legitimate interest): understanding and fixing errors from diagnostic reports.
Waitlist (consent): telling you when the app opens to everyone.
4. The content you create: who sees it
Challenges are private: only members approved by the creator can see the challenge, each other's progress and profiles. The rule is enforced in the database (row-level security): no approval, no access.
Proof photos: stored in private storage and served only through short-lived signed URLs to members of the same challenge. They are never public, never go to the Feed and are never used for advertising.
Messages and GIFs: visible only to members of that challenge. If you block someone, you stop seeing their messages.
Our team only opens specific content when it has been reported, or where the law requires it.
5. Public Feed (optional)
IDarU has an optional public Feed. Nothing lands there on its own: only what you choose to share, post by post.
When you share, other users of the app can see: the challenge name, its goals, the result you shared (the day's progress or a completion), the comment you write and your public profile — username, name, picture and trophies.
Never visible: your proof photos, your other challenges, chat messages and who the members of your challenges are.
You can delete a post at any time; it stops being visible in the Feed.
6. Third parties and international transfers
Supabase (European Union, Frankfurt region): database hosting, authentication and storage of proof photos and avatars.
Expo (USA): push notification delivery, which then travels through Apple (APNs) and Google (FCM).
Google AdMob (USA/Ireland): in-app advertising, under whatever consent you gave.
GIPHY, Inc. (USA): provides GIF search and the GIFs themselves. Every search and every GIF shown is a request your device makes to GIPHY servers, which receive the search term, your IP address, the device user agent and the app language. We do not send them your account, your email or the content of your messages. GIPHY processes this data as its own controller, under its privacy policy. Because the request leaves your device and not our servers, we are not the exporter of this data: the legal basis for this transfer to the US rests with GIPHY, under its own policy. You can avoid it entirely by not opening the GIF picker — nothing is sent to GIPHY until you do.
Sentry (crash reports): receives the technical diagnostics described above. The project is hosted in Sentry’s EU region (Frankfurt, Germany) and the processing is governed by Sentry’s data processing agreement.
We do not sell data and we do not share it with anyone outside this list.
7. How long we keep each thing
Account and profile: for as long as the account exists.
Challenges, progress and trophies: for as long as the account exists; challenges you created are deleted with it, for every member.
Proof photos: until the challenge ends — they are deleted then — or until you delete your account, whichever comes first.
Messages and GIFs: for as long as the challenge exists; they go with the challenge or with the account.
Reports: up to 12 months after they are handled, so we can recognise repeat offenders.
Blocks: until you undo them in the app, under Settings → Legal → Blocked users.
Diagnostics: up to 90 days.
Website waitlist: until launch, or until you ask us to remove it.
8. Deleting your account
You can delete your account in the app (Profile → Account → Delete account). Deletion is immediate and irreversible: it takes the challenges you created, your progress, trophies, proof photos and messages with it.
You can also request deletion by email at privacy@idaru.app.
9. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability (GDPR arts. 15–21). Write to privacy@idaru.app.
Withdrawing consent is as easy as giving it: notifications switch off under Settings → Notifications, and personalized advertising under Settings → Legal → Privacy and ads, which reopens the consent form. Withdrawal does not affect processing carried out before it.
You may also lodge a complaint with your national supervisory authority.
10. Minimum age
IDarU is intended for people aged 16 and over.
11. Security
Everything travels encrypted (TLS). Access to data is decided in the database by row-level security, photos live in a private bucket behind short-lived signed URLs, and passwords are hashed by the authentication provider.
12. Cookies and the website
This website uses no tracking cookies and no cookie-based analytics. If you join the waitlist, we store the email address and language you gave us.
The app only uses local storage required for it to function (your session) and your advertising consent preferences.
13. Changes to this policy
If something material changes, we update the date at the top and tell you in the app. The version in force is always the one on this page.