Controller: legal name / owner: to be filled in, address: to be filled in. Contact: [email protected].
1. What Nookly is
Nookly is a map app that helps couples find calmer, publicly accessible places. Nookly estimates how quiet a place may be from community feedback and, for some public venues, from third-party crowd estimates. These are relative estimates: Nookly never guarantees that a place is empty, quiet or safe.
2. Data we process
| Data | When | Why | Who can see it |
|---|---|---|---|
| Sign-in identity: e-mail address and an account identifier from Apple or Google; the first name your provider shares | When you sign in | Create and secure your account | Nobody else. Your e-mail is never shown to other people. |
| Profile: display name, optional photo, optional short bio, privacy choice (public / limited), optional interests and contribution counts | When you set them | Show who wrote a review or photo; let your partner see you | Public profile: people who see your reviews or photos see your photo, name and bio. Limited: others see only your name. Your partner always sees your full profile. |
| Precise location while the app is open | When you allow location | Show nearby places, distances and directions | Not shared with other people. To find nearby places the server receives a position rounded to about 500 m; to accept "We're here", feedback or a new place, a coarse position is checked and not stored. |
| Partner live location (only if you turn it on) | While "Share my live location with my partner" is on; if you choose "also in the background", also when the app is closed | Let your current partner see where you are | Only your current partner. One current position (rounded to about 11 m) is kept and overwritten; no history or route is kept. It expires after 2 hours without updates and is deleted at once when you stop sharing, unpair, block or delete your account. Never used for ads. |
| Pairing / couple data: pairing invites, couple membership, shared saves, plans, couple preferences, private couple places, couple-only photos and notes | When you pair and use couple features | Couple features | Only you and your partner. Private places never appear to anyone else. Deleted when you unpair (shared saves, plans, private places and couple-only photos). |
| Places you add | When you add a public place | Build the community map | Public places are visible to everyone without your name. |
| Visits ("We're here / We've left") | When you use them | Avoid two couples arriving at the same spot at once, history for the two of you, better suggestions | Other people only see an availability state (e.g. "possibly in use"), never who. Your partner sees visits made while you are paired. Kept 90 days or until you clear them in Settings. |
| Community feedback (calm / crowded / no access / did not feel safe) | When you give it | Improve quietness estimates and hide unsafe places | Shown only as aggregates from at least 3 different people. |
| Photos | When you add one | Show what a place looks like | "Everyone" or "Only me and my partner", as you choose. Location metadata is removed on your phone before upload. |
| Reviews and ratings | When you write one | Help others | Public places: everyone (with your display name); private places: only your partner. |
| Reports and blocks | When you report or block | Safety and moderation | Never shown to the person you report or block. |
| Push notification token and preferences (if notifications are enabled) | When you turn on notifications | Partner invites, pairing, plans, reminders | Nobody else |
| Ad interaction data (only in builds with ads) | When an ad is shown | Show ads, measure them, prevent fraud | Google (see section 4) |
| Sponsored-place counters | When a sponsored place is shown, opened or its button tapped | Count totals for sponsors | Sponsors get daily totals only, never who you are, where you are, your couple or preferences. |
We do not sell personal data. We do not keep a location history.
3. Legal bases (where GDPR/KVKK apply)
Contract (providing the app you signed up for), consent (location permission, background live location, notifications, personalised ads where applicable), and legitimate interests (security, abuse prevention, product improvement with aggregated data). You can withdraw consent at any time in the app or your phone settings.
4. Service providers
- Supabase (database, authentication, file storage, server functions): stores the data above. Hosting region: AWS ap-northeast-1 (Tokyo, Japan).
- Google Maps SDK (Android map): Google receives device metadata, IP address, a Maps-specific identifier, crash data and map interaction events. Apple Maps is used on iOS.
- Google Mobile Ads / AdMob (only in builds with ads enabled): Google collects IP address, ad interactions, diagnostics and device/advertising identifiers. Nookly requests non-personalised ads, never sends your location or profile to the ad SDK, and asks for consent where the law requires it (Google's consent form). Nookly does not ask iOS for tracking permission.
- BestTime (crowd estimates for some public venues): our server sends the venue name/address only; never your identity or location.
- Apple / Google sign-in: authenticate you.
- Expo push service, Apple Push Notification service, Firebase Cloud Messaging (only if notifications are enabled): deliver notifications.
5. Retention
- Account data: until you delete your account.
- Live location: one point, overwritten; hidden after 2 hours without updates; deleted on stop / unpair / block / account deletion.
- Visits: 90 days, or until you clear them.
- Pending photo uploads: 1 day; photos hidden by reports: 90 days; deleted photos and replaced avatars are removed from storage by an hourly job.
- Couple data: deleted when the couple ends.
- Reports: kept while open; closed reports are deleted after 180 days. When an account is deleted, its reports stay only without any link to the account.
- Sponsored counters: daily totals; per-person de-duplication records are deleted after 2 days.
- Notification records: 14 days.
6. Your choices and rights
- Location: allow/deny in your phone settings; background location is requested only if you turn on background partner sharing, and you can stop sharing at any time in the Together screen or from the banner on the map.
- Profile: choose public or limited; remove your photo; edit or delete reviews and photos; clear visit history.
- Block and report people, reviews, photos and places.
- Delete your account: Settings → Account → Delete account (immediate and permanent), or via the account deletion page.
- Access, correction, portability, objection and complaints to your data protection authority: contact [email protected].
7. Children
Nookly is not intended for children under 18.
8. Security
Data is encrypted in transit (HTTPS). Server access rules ensure people only read what they are allowed to; private photos are served through short-lived signed links.
9. Changes
We will update this page and the "Last updated" date; significant changes will be announced in the app.