ReverseGram · Deutsch · English
Privacy Policy
1. General information
The protection of your personal data is very important to us. This privacy policy informs you about which data is processed in the ReverseGram app, for what purpose, and what rights you have.
Personal data is any data with which you can be personally identified.
2. Controller
Responsible for data processing within the meaning of the GDPR:
Emran Sawaied, Hedwigstraße 10, 34117 Kassel, Germany
Email: info@reversegram.com
3. Nature of the app
ReverseGram is a social networking app where users can create, view, comment on and share content.
4. Processed data
Depending on use of the app, the following personal data is processed:
4.1 User-provided data
- Account data: email, password, username, display name, profile picture, date of birth (not public)
- Profile: bio, website, optional email/phone
- Content: posts (text, photos, videos), comments, reposts, stories
- Messages: texts and voice messages in chats
- Location: GPS coordinates, place name, address (optional, when tagging posts/profile)
- Optional phone discovery: your own E.164 number; hashed contact-book numbers for matching
4.2 Automatically collected data
- Device info (type, OS, app version)
- IP address (shortened/anonymised)
- Approximate region: city, country and coordinates rounded to a grid of roughly 5 km (not shown on your public profile; can be switched off at any time — see section 15)
- Timestamps of activity
- Usage and interaction data
- Error and crash reports (Firebase Crashlytics)
- FCM/APNs token for push notifications
- Session data
4.3 Local storage on your device
- iOS: UserDefaults, Keychain (saved accounts, Firebase sessions), video cache
- Android: EncryptedSharedPreferences, Room chat database
- Web: localStorage, sessionStorage, IndexedDB (Firestore offline cache)
5. Purpose of processing
- Provision and operation of the app
- User account management
- Display and distribution of content
- Personalising content and friend suggestions by approximate region (can be switched off)
- Improvement of app functionality
- Error analysis and stability
- Sending push notifications (optional)
- Security and abuse prevention
6. Legal basis (GDPR)
- Art. 6(1)(a) GDPR (consent)
- Art. 6(1)(b) GDPR (contract)
- Art. 6(1)(f) GDPR (legitimate interest)
7. Firebase (Google)
ReverseGram uses Firebase services provided by Google Ireland Limited.
- Firebase Authentication
- Firebase Firestore
- Firebase Storage (media uploads)
- Firebase Crashlytics
- Firebase Cloud Messaging
- Firebase Realtime Database (presence)
- LiveKit (calls)
Provider: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. A transfer to the USA is possible on the basis of EU standard contractual clauses (Art. 46 GDPR).
8. Push notifications
ReverseGram may send push notifications about activity or new content. Consent is given on the device. You can turn them off in the device settings at any time.
9. Analytics and statistics
Firebase Analytics collection is disabled. Crash reports may be processed via Firebase Crashlytics to keep the app stable (Art. 6(1)(f) GDPR).
10. Retention
Personal data is stored only as long as needed for the purpose or legal duties. After account deletion, data is deleted unless legal retention periods apply.
11. Disclosure
Personal data is shared only:
- with technical service providers (e.g. Firebase)
- under a legal obligation
- with your explicit consent
We do not sell personal data.
12. Security
We use technical and organisational measures to protect your data against loss, manipulation or unauthorised access.
13. Your rights (GDPR)
You have the right to information (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20 — in-app “Download my data”), objection (Art. 21) and withdrawal of consent (Art. 7(3)). You may lodge a complaint with the Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Wiesbaden, or your local authority (Art. 77 GDPR).
To exercise your rights: info@reversegram.com
14. Device permissions
ReverseGram may request camera (photos/videos), microphone (video sound and voice messages), photo library (media for posts/stories) and location (optional tagging). If you have granted location access, we additionally use it to determine your approximate region (section 15); the coordinates are rounded on the device before they are sent. We do not request background location access. Each permission is used only for that purpose. You can revoke access in the device settings.
15. Location data
If you use location features, we process GPS coordinates and place names via the Google Places API and reverse geocoding. This data is stored in Firestore. Legal basis: Art. 6(1)(a) GDPR (consent).
Separately, the app determines your approximate region automatically in order to rank content and friend suggestions by proximity. This is based on the IP address of your request or — only if you have already granted location access — on a coarse GPS reading. We store the city, the country and coordinates rounded to a grid of roughly 5 km; we do not store a precise position. To resolve the IP address we transmit it to IPinfo (section 17); we do not store the IP address itself, only a salted hash used as the key for a cache that expires after seven days. No location history and no movement profile is created: the value is overwritten on each update, at most every six hours and only while the app is in the foreground. The region is not shown on your public profile.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in regionally relevant content and suggestions). You may object to this processing at any time (Art. 21 GDPR) by turning off “Location for suggestions” in Privacy settings; we then delete the stored region and do not determine it again.
16. Automated decisions
ReverseGram does not use AI for automated decisions about you. Moderation is handled manually based on user reports and our community guidelines.
17. Additional third-party services
- Google Sign-In / Sign in with Apple: login; email, name, profile picture
- Google Places API: location search; search terms, coordinates
- IPinfo: determining the approximate region from the IP address; data: IP address (IPinfo Inc., 300 Lenora Street #516, Seattle, WA 98121, USA; processed under a data processing agreement with EU standard contractual clauses)
- Google Translate API: translation of posts, comments, messages
- Klipy: GIFs and stickers; search queries
- Jamendo: story music; search terms
- Microlink: link previews; URLs
- Vercel: web hosting; IP, user-agent, requested URLs
- Google Cloud Run (OG proxy): share-link previews
Transfers to the USA use EU standard contractual clauses where applicable.
18. Storage on your device (TDDDG § 25)
The app stores data locally (UserDefaults, Keychain, EncryptedSharedPreferences, Room, localStorage, sessionStorage, IndexedDB) for authentication, preferences, caching and push tokens. This is necessary to provide the service (TDDDG § 25(2) No. 2) or based on consent.
19. Contacts and phone discovery
If you opt in, we store your own number (E.164) so friends can find you. Contact-book numbers are hashed on your device before matching; we do not keep the address book. Legal basis: Art. 6(1)(a) GDPR. You can turn this off anytime.
20. Profile visits and feed ranking
Visits to public profiles may be counted for the profile owner (visitor ID, day). You can opt out in Settings. Feed ranking uses interaction signals stored locally and in Firestore. This is not automated decision-making under Art. 22 GDPR.
21. Audio calls (LiveKit)
Audio calls use LiveKit (WebRTC). Signalling metadata is processed to connect the call. Call media is transport-encrypted (DTLS-SRTP); end-to-end encryption is currently not active. We do not record calls and we do not sell call data.
22. Analytics and crash reports
Firebase Analytics is disabled. Firebase Crashlytics may process crash data to keep the app stable (Art. 6(1)(f) GDPR). You can object by e-mail.
23. Supervisory authority
You may lodge a complaint with the Hessian Commissioner for Data Protection and Freedom of Information (HBDI), Gustav-Stresemann-Ring 1, 65189 Wiesbaden, or your local authority. The German Federal Commissioner (BfDI) is not the competent authority for this private provider.
Contact: info@reversegram.com · Terms · Legal notice
The German text is legally binding if translations differ.