Privacy Policy - Alladro

Last Updated: October 21, 2025 | Version 2.0

IMPORTANT: This Privacy Policy describes how Alladro collects, uses, stores, and shares your personal information. By using the Service, you consent to the practices described in this Policy.

1. Introduction and Controller Information

1.1 Who We Are

Alladro ("we", "us", "our") is a community-based crime reporting mobile application. We are the data controller responsible for your personal information.

Contact Information:

1.2 Scope of This Policy

This Privacy Policy applies to all personal information collected through:

1.3 Legal Basis

We process your personal data in compliance with:

2. Personal Information We Collect

WARNING: When you post crime reports, your geolocation data, username, and report content become PUBLIC and are visible to all users.

2.1 Information You Provide Directly

Data Category Specific Data When Collected
Account Information • Email address
• Username
• Full name (optional)
• Password (hashed)
Account registration
Profile Information • Avatar/profile picture (optional)
• User preferences
• Theme settings
Profile setup/updates
Crime Report Content • Report title
• Report description
• Crime type/category
• Event date and time
• Images/photos (up to 1)
• User-provided location notes
When creating crime reports
User Interactions • Upvotes on events
• Contact requests
• Direct messages
• Report submissions (flagging content)
• Bug reports and suggestions
When using platform features

2.2 Information Collected Automatically

Data Category Specific Data Purpose
Geolocation Data • Precise GPS coordinates (latitude/longitude)
• Reverse-geocoded addresses
• Distance calculations
• Location radius filters (3-20km)
• Display crime events on map
• Filter events by proximity
• Associate reports with locations
Device Information • Device type (iOS version)
• Operating system version
• App version
• Device identifiers (IDFA if consented)
• Screen resolution
• Technical support
• App optimization
• Crash reporting
Usage Data • Login timestamps
• Last active time
• Features used
• Reports created/viewed
• Messages sent/received
• Search queries
• Service improvement
• Analytics
• Security monitoring
Network Information • IP address
• Connection type (WiFi/Cellular)
• Network provider
• Security
• Fraud prevention
• Service delivery

2.3 Information from Third-Party Services

We integrate with the following third-party services that may collect data:

3. How We Use Your Personal Information

3.1 Legal Bases for Processing

Purpose Legal Basis (GDPR)
Account creation and authentication Contract performance (Art. 6(1)(b))
Displaying crime reports on map Contract performance + Legitimate interests
Geolocation processing Consent (Art. 6(1)(a)) via iOS location permission
Direct messaging between users Contract performance
Content moderation Legitimate interests (safety, legal compliance)
Security and fraud prevention Legitimate interests
Analytics and service improvement Legitimate interests
Marketing communications (if any) Consent (Art. 6(1)(a))
Legal obligations and law enforcement Legal obligation (Art. 6(1)(c))

3.2 Specific Use Cases

We use your personal information to:

4. How We Share Your Personal Information

PUBLIC INFORMATION: Crime reports you create (including title, description, location coordinates, images, username, and event date) are PUBLIC and visible to all app users and potentially the general public.

4.1 Public Disclosure

The following information is PUBLIC by default:

This public information may be:

4.2 Sharing with Third-Party Service Providers

Service Provider Data Shared Purpose Location
Supabase
(Database & Auth)
All user data, content, messages, location data Backend infrastructure, database storage, authentication Various (check Supabase DPA)
Google Maps Location coordinates, geocoding requests Map display, address conversion United States, Global
Google AdMob Device ID, ad interactions, app usage Advertising and monetization United States, Global
AI Moderation Services
(Claude/OpenAI)
Crime report content, images (for moderation only) Automated content moderation United States

4.3 Sharing with Other Users

4.4 Legal and Safety Disclosures

We may disclose your information without consent when required or permitted by law:

4.5 Business Transfers

If Alladro is involved in a merger, acquisition, sale of assets, or bankruptcy, your personal information may be transferred to the acquiring entity. We will notify you via email and/or prominent notice in the app before your data is transferred.

4.6 Aggregate/Anonymized Data

We may share aggregate, anonymized, or de-identified information that cannot reasonably be used to identify you, including:

5. Data Retention

5.1 Retention Periods

Data Type Retention Period Reason
Account Information Until account deletion + 30 days Account management, legal obligations
Crime Reports (Published) Indefinitely (public record) Public safety information, platform purpose
Crime Reports (Rejected/Unverified) 90 days after rejection Appeal process, moderation review
Direct Messages Until deletion by user or account closure User communication history
Contact Requests 7 days after expiration or until accepted/rejected Operational necessity
Usage Logs 90 days Security, analytics
IP Address Logs 30 days Security, fraud prevention
Moderation Records 2 years Legal defense, pattern detection
Backup Data 90 days (rolling backups) Disaster recovery

5.2 Account Deletion

When you delete your account:

IMPORTANT: Deleting your account does NOT guarantee removal of public crime reports you created. These may remain visible for public safety purposes.

6. Your Rights Under GDPR

If you are located in the European Economic Area (EEA), UK, or Switzerland, you have the following rights:

6.1 Right of Access (Art. 15 GDPR)

6.2 Right to Rectification (Art. 16 GDPR)

6.3 Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR)

6.4 Right to Restriction of Processing (Art. 18 GDPR)

6.5 Right to Data Portability (Art. 20 GDPR)

6.6 Right to Object (Art. 21 GDPR)

6.7 Right to Withdraw Consent (Art. 7(3) GDPR)

6.8 Right to Lodge a Complaint

6.9 Exercising Your Rights

To exercise any of these rights:

  1. Email us at: [YOUR_EMAIL]
  2. Include subject line: "GDPR Rights Request"
  3. Specify which right(s) you wish to exercise
  4. Provide identity verification (to prevent fraud)

Response Time: We will respond within 30 days (may be extended to 60 days for complex requests).

Cost: Free of charge, unless requests are manifestly unfounded or excessive.

7. International Data Transfers

Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States.

7.1 Transfer Mechanisms

When we transfer data outside the EEA, we use the following safeguards:

7.2 Third-Party Data Locations

For more information about international transfers, contact [YOUR_EMAIL].

8. Security Measures

8.1 Technical and Organizational Measures

We implement appropriate security measures to protect your data:

8.2 Limitations

NO SECURITY IS PERFECT: Despite our efforts, no system is 100% secure. We cannot guarantee absolute security of your data. You use the Service at your own risk.

8.3 Data Breach Notification

In the event of a data breach affecting your personal information:

9. Children's Privacy

9.1 Age Restrictions

9.2 Parental Rights

Parents/guardians have the right to:

If you believe we have inadvertently collected data from a child under 13, contact us immediately at [YOUR_EMAIL].

10. Cookies and Tracking Technologies

10.1 Types of Technologies Used

10.2 Third-Party Tracking

10.3 Your Choices

11. Location Data

CRITICAL PRIVACY NOTICE: Location data you submit with crime reports is PUBLIC and includes precise GPS coordinates visible to all users.

11.1 Types of Location Data

11.2 How We Use Location Data

11.3 Location Permissions

11.4 Location Privacy Risks

PRIVACY RISK WARNING:

Recommendation: Only post crime reports if you are comfortable with your precise location being public.

12. AI and Automated Decision-Making

12.1 AI Moderation System

We use artificial intelligence (Claude/ChatGPT) to moderate user-generated content:

12.2 Your Right to Human Review (GDPR Art. 22)

13. Changes to This Privacy Policy

Version History:

14. Contact Us

For privacy-related questions, concerns, or requests:

Response Time: We aim to respond to all inquiries within 30 days.

15. Additional Rights for California Residents (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

15.1 Right to Know

15.2 Right to Delete

15.3 Right to Opt-Out of Sale

15.4 Right to Non-Discrimination

To exercise CCPA rights, email [YOUR_EMAIL] with subject "CCPA Request".

16. Data Processing Records (GDPR Art. 30)

Summary of our data processing activities:

Processing Activity Legal Basis Data Categories Recipients
User Account Management Contract Email, username, password Supabase
Crime Report Publishing Contract + Consent Location, report content, images Public, Supabase
Geolocation Processing Consent GPS coordinates Google Maps, Supabase
Content Moderation Legitimate Interest Report content, images AI services (Claude/OpenAI)
Advertising Legitimate Interest Device ID, usage data Google AdMob