Hang Privacy Policy
Version 1.0.4 · effective · English · wersja polska
1. Data controller
Conttinu is the controller of personal data processed through Hang. You can contact the controller through Hang Help or at support@conttinu.com.
2. Data we process
We process data needed to create and operate an account, including email address, username, secure password hash, Apple sign-in identifier, avatar, and profile settings. We also process session and notification tokens and basic technical and security logs.
Depending on the features you use, we process favourite places, private lists and travel plans, notification preferences, and reports. We do not require medical data; any diet or health information voluntarily included in content is processed as part of that content.
When you search for places, we send the raw text you entered to the backend so it can return matching results. If you use nearby or map search and share location, the App may send the device location or a bounding box calculated from that location or the current map area to find places in the requested area. Recent queries may be stored locally on the device. These are functional search data, not analytics-event parameters.
The notification channel operates independently of product-analytics consent. To register and deliver notifications, we process an APNs or FCM registration token, Firebase Installation ID, device model, language and locale setting, time zone, operating system, App version and build number, notification preferences, and delivery data. The token may be linked to an account after sign-in. Firebase Installation ID supports the operational installation of Firebase services and is distinct from the analytics App Instance ID.
The diagnostics channel also operates independently of product-analytics consent. Crashlytics or Sentry reports may contain a crash description, stack trace, device model and state, operating system, App version, technical logs and breadcrumbs, and — when a user is signed in — a diagnostic account identifier. We do not add Firebase App Instance ID or the local flag fallback identifier to them.
After voluntary consent to product analytics, we also process a pseudonymous Firebase App Instance ID and, on iOS, the non-advertising IDFV, product-usage events, and limited context: platform, App version and build number, environment, language and locale setting, which may include a region or script, consent state, and loggedIn, which is only a boolean indicating whether an account is signed in. The data and its flow are described further below.
3. Community content
Content published publicly — including reviews, comments, threads, replies, photos, an avatar, and shared travel plans — is visible to other people together with the author information shown by the App. Content may be processed for publication, search, reporting, moderation, abuse prevention, and community features.
Do not place data in public content that you do not want to disclose, or another person's data without an appropriate basis.
4. Document and consent-decision records
When you accept the Terms and Community Guidelines, we record the account identifier, document type and version, server time, platform, App version, and acceptance surface. We do not record an IP address, device identifier, or copy of the document text for this purpose.
For a signed-in user, we store an optional-consent decision as an immutable history of account identifier, purpose, exact document, grant or withdrawal, server time, platform, and App version. For an anonymous user, a decision containing the purpose, document, result, and time remains locally on the device and is not sent to an anonymous backend endpoint.
The Privacy Policy is presented as information and is not treated as consent to every processing purpose. Product-analytics consent is presented separately, off by default, and requires an explicit positive choice.
5. Purposes and legal bases
We process data to provide the service and perform our contract with you: creating an account, authenticating, synchronising data, publishing selected content, responding to requests, and delivering notifications according to your settings.
When you request text, nearby, or map search, we process the raw query and — depending on the selected feature and permission — device location or bounding box to perform the contract and return the requested results. We do not reuse this data as product-analytics parameters.
Under our legitimate interests, we protect the App's security and stability, prevent abuse, moderate reports, and diagnose failures using minimised Crashlytics and Sentry data. Notification and diagnostics channels are operational purposes independent of product-analytics consent.
On the basis of voluntary consent under Article 6(1)(a) of the GDPR, we measure feature use, run controlled experiments, and compare variations to identify issues in product journeys and make data-informed decisions about developing Hang. Refusal does not limit core features. We do not use data for this purpose for personalised advertising, sale of data, or decisions that produce legal or similarly significant effects.
Under Conttinu's legitimate interest, we deliver and configure ordinary feature flags safely. For this separate purpose, a staging or production build may fetch definitions from the GrowthBook CDN even without product-analytics consent. The scope of that request is described in the next section.
We may also process data to comply with a legal obligation or protect legal claims. Consent can be withdrawn at any time without affecting the lawfulness of prior processing.
6. Product analytics, experiments, and minimisation
After a current consent, we enable Firebase Analytics. It may automatically record first_open and App start, session start and user_engagement, a screen view, an App or operating-system update, and — depending on the platform and delivery path — receipt, foreground display, opening, or dismissal of a Firebase Cloud Messaging notification.
Automatic notification events may contain technical message metadata: message identifier or name, topic, label, channel, type, and time. Campaign names, topics, and labels must not contain an email address, username, name, or other data that directly identifies a person. Firebase may also process device model, operating system, App version, language and locale setting, which may include a region or script, and approximate region.
Custom product events cover navigation and screens, search and filters, places and favourites, reviews and community features, registration and sign-in, legal documents and App updates, and experiments. They contain technical place, review, experiment, feature, variation, or rule identifiers only where needed, together with categorical values, source, outcome, and common App context. They contain no review, thread, report, photo, or document content. For analytics search measurement, we record only filter state and broad query-length and result-count buckets, never raw query text or location sent functionally to the backend.
Payments and automatic purchase analytics are not currently covered by this purpose. Before enabling them, we will publish a new notice and ask for a new choice.
Firebase App Instance ID is a pseudonymous installation identifier. After consent, GrowthBook uses it locally to assign the installation to a variation. On iOS, Firebase Analytics may also process IDFV, a non-advertising vendor identifier for apps on the device. IDFV is not IDFA. We do not request App Tracking Transparency permission and do not use IDFA or Android Advertising ID.
Flags are evaluated on the device and remote evaluation is disabled, so App Instance ID, loggedIn, and assignment attributes are not included in the request that fetches flag definitions. App Instance ID is not a custom event parameter, log, breadcrumb, or part of an error report.
Even without consent, a staging or production build may make a bodyless GET request to the GrowthBook CDN for ordinary flag definitions. The request contains no App Instance ID, local fallback identifier, or assignment attributes. GrowthBook and its CDN nevertheless receive ordinary network metadata such as the IP address and an access-log entry. This traffic emits no measured exposure or product event.
Firebase Analytics manages the corresponding identifier at the top level as user_pseudo_id. A daily export enters BigQuery in the EU region. Only experiment_viewed, place_searched, and place_viewed enter the minimised curated views, where the identifier is named anonymous_id. GrowthBook receives read-only access to those views so it can join a variation to an outcome, but cannot access the other events in the raw export tables.
Local GrowthBook context may contain platform, App version and build number, environment, language and locale setting, which may include a region or script, consent state, and loggedIn as a boolean, but not an account identifier, username, or email address. loggedIn is not a Firebase Analytics custom parameter, a curated-view column, or an attribute sent to the GrowthBook CDN. The App does not add a backend account identifier, raw search query, precise location, location history, or IP address as its own event parameter. Google nevertheless receives the IP address in transit and may derive an approximate region from it.
The ad_storage, ad_user_data, and ad_personalization settings remain denied regardless of product-analytics consent. We do not use advertising identifiers or the data for this purpose for advertising.
Notification delivery through Apple Push Notification service and Firebase Cloud Messaging remains a separate channel operating independently of this consent. The consent does not enable that channel; Firebase Analytics automatic notification measurements are collected only after a current consent.
Product breadcrumbs are sent to Sentry only after a current consent. Operational error reporting through Sentry or Crashlytics remains a separate, minimised channel; product-analytics consent does not enable it or permit App Instance ID or another assignment identifier to be added. A diagnostic account identifier used by that channel is separate from analytics identity and is not used for bucketing.
7. Recipients, providers, and transfers
Data may be entrusted to providers of hosting, file storage, email, notifications, and error monitoring, only as needed to provide their services and with appropriate safeguards. Data may be disclosed to a public authority where required by law.
For operational notification delivery, we use Apple Push Notification service and Google Firebase Cloud Messaging. For stability and error diagnostics, we use Google Firebase Crashlytics and Sentry. Providers receive only the data needed to register and deliver a message or to receive, secure, and analyse a technical report. These channels operate independently of product-analytics consent.
For product analytics, we use Firebase, Google Analytics, and Google Cloud BigQuery supplied by the applicable Google group entities, and GrowthBook Cloud supplied by GrowthBook, Inc. GrowthBook can access only the minimised BigQuery views. In the current service model, GrowthBook subprocessors may include Amazon Web Services in the United States, Fastly through global infrastructure, and MongoDB in the United States. We do not use GrowthBook Managed Warehouse.
Data may be processed outside the European Economic Area, including in the United States. Where required by law, we rely on an appropriate transfer mechanism, such as an adequacy decision or standard contractual clauses, together with data minimisation, access controls, and encrypted transmission.
8. Retention
Active-account data is kept while you use the App. After a confirmed request, the account and associated data in active systems are usually deleted within minutes and no later than 30 days, subject to exceptions required by law or the protection of claims.
Backups rotate as follows: daily copies for up to 7 days, weekly copies for up to 28 days, and monthly copies for up to 180 days. They are not used for ordinary operations; confirmed deletions are reapplied after a restore.
A technical record of a completed deletion request — a non-reversible hash and dates without an email address or account identifier — is retained for up to 180 days for audit, idempotency, and restore handling. Legal acceptance and consent-decision history is deleted with the account.
Raw query text, device location, and bounding box are processed to handle a specific search. They may appear in technical cache or operational and security logs if those are created while handling the request. We retain them only as long as needed to return or retry the result, protect the service, diagnose abuse, or protect legal claims, and then delete or anonymise them under the applicable system lifecycle. Recent queries stored locally remain until you remove them or remove the App data.
We retain APNs and FCM tokens and their account association for as long as needed to deliver notifications according to settings; we remove or invalidate them when the relevant feature is disabled, on sign-out, account deletion, or token rotation, subject to safe retries needed to complete invalidation. Firebase Installation ID, delivery metadata, and Crashlytics or Sentry diagnostics follow periods determined by their operational purpose, service configuration, and provider policies; we delete or anonymise them when no longer needed for delivery, security, failure diagnosis, or the protection of claims.
The Google Analytics 4 retention setting for unaggregated event and user data used in features such as Explorations is 14 months, and the option that restarts this period after new activity is disabled. Standard aggregated Google Analytics reports are not governed by the same setting and may remain available longer as aggregates. Tables, views, and partitions for the current BigQuery Sandbox pilot in the EU region expire automatically after 60 days.
GrowthBook cannot access the raw Google Analytics tables. Through access to the minimised source and operation of the service, it may process configuration, query metadata and results, cache data, and security and access logs. Their retention periods depend on the data category, configuration, applicable agreement, and provider policies. Conttinu deletes or anonymises this data when it is no longer needed for the described purposes, subject to legal obligations and the protection of claims.
The anonymous decision record remains on the device until App data is removed or it is replaced by a newer decision. Withdrawal stops new collection but does not automatically erase data transmitted earlier, which remains subject to the periods above or a separate erasure request.
9. Your rights
You may request access, correction, erasure, restriction, and portability of your data, and object where processing is based on legitimate interests. You can withdraw consent at any time in Profile settings. You also have the right to complain to the competent supervisory authority.
Because analytics data is pseudonymous, we may ask for information needed to locate the relevant installation securely and verify the request. Contact about a request does not re-enable analytics.
10. Account, content, and analytics-data deletion
An account can be deleted in the App or through the public Hang account and data deletion page. For security, we send a one-time link to the verified address and do not reveal in the form whether an account exists.
Deletion covers the account, sessions, lists, plans, community content, reviews, notification tokens, legal acceptances, consent decisions, and user-linked files. Aggregated data that can no longer be linked to a person is not covered by deletion.
Withdrawing analytics consent stores a local refusal, disables new events and measured experiments, disables Firebase Analytics, and resets its local data and App Instance ID. It is not the same as a request to erase data already transmitted. That request can be made separately through Hang Help or email, without re-enabling analytics.
11. Security and automated decisions
We apply organisational and technical measures appropriate to the risk, including access controls, encrypted connections, data minimisation, and separate permissions for curated views. Automated signals may help protect against spam and harmful content, but we do not use them alone to make decisions that produce legal effects for a user without an appropriate basis and opportunity for intervention.
12. Versions and changes
The document number and effective date appear above. We communicate material changes in a manner appropriate to their significance. A material change to the analytics purpose, data scope, providers, or use of the pseudonymous identifier requires a new notice and a new consent choice. The Polish and English texts are intended to express the same rules.