Privacy Policy
Last updated: 2026-05-31
On this page
1. What we collect
When you use Taarifa, we collect:
Account data
- Name, email address, and password (hashed) when you register
- Profile information you choose to add (display name, avatar, bio)
- Phone number, if you provide one for account recovery
Content you create
- Reports, feeds, comments, and other posts you submit
- Photos and images you upload
- Tags and categories you apply to your reports
- Groups you join and messages you send in groups
Location data
- Approximate location (city/region) when you submit a report tagged with location
- Precise GPS coordinates only when you explicitly attach them to a report
- You can turn location sharing off at any time in your device settings
Device and usage data
- Device type, OS version, and app version
- Push notification token (so we can send you alerts)
- Crash reports and error logs (anonymous)
2. How we use it
- To operate the app โ show you feeds, deliver notifications, route messages
- To improve the app โ analyze usage patterns and fix bugs
- To moderate content โ review reports that other users flag
- To communicate with you โ send transactional emails (password resets, important account changes)
- To comply with legal obligations
We do not sell your personal data to third parties. We do not use your data for advertising.
3. Who we share with
Other users can see:
- Your public profile (display name, avatar, bio)
- Reports and feeds you post publicly
- Comments and likes you make on public posts
We share data with service providers who help us operate the app:
- Hosting โ our backend infrastructure provider (Hostinger)
- Push notifications โ Apple (APNs) and Google (FCM/Expo) for delivering notifications
- Email delivery โ for sending password resets and account emails
We may disclose data when legally required (e.g. lawful court orders), but we will challenge requests that are overly broad or improperly served.
4. Your rights
You can:
- Access โ request a copy of the data we hold about you
- Correct โ fix inaccuracies in your profile or content
- Delete โ request deletion of your account and associated data
- Export โ receive your data in a portable format (JSON)
- Withdraw consent โ turn off optional features (location, notifications) at any time
To exercise any of these rights, email privacy@toataarifa.com. We respond within 30 days.
5. Data retention
- Account data is kept while your account is active
- Posts and reports are kept until you delete them or your account
- Deleted accounts are purged from our active database within 30 days; backups are rotated out within 90 days
- Anonymous analytics logs are retained for up to 12 months
6. Security
We protect your data with:
- HTTPS encryption for all traffic between the app and our servers
- Encryption at rest for sensitive fields (passwords are hashed with bcrypt)
- Row-level security on our database, so users can only access their own data
- Restricted physical access to our hosting environment
No system is perfectly secure. If we discover a breach affecting your data, we will notify you within 72 hours.
7. Children
Taarifa is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe we have collected such data, please contact us and we will delete it.
8. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top. For material changes that affect your rights, we will notify you in-app or by email.
9. Contact us
Questions about this privacy policy or about how we handle your data?
Email privacy@toataarifa.com or write to the support team at support@toataarifa.com.