FriendBase ("we", "us", "our") is a personal app for remembering friends' birthdays, anniversaries, and preferences. This policy explains what data we collect, how we use it, who can see it, and how you can delete it.
If you have any questions, email us at hello@friendbase.app.
1. Information we collect
1a. Information you provide directly
- Account info from Sign in with Apple: your name (if you choose to share it) and a private relay or real email address. We do not see your Apple ID password.
- Profile info: display name, username, optional birthday, optional profile photo, and any "favorites" fields you fill in.
- Friends data: names, birthdays, important dates, gift ideas, optional photos, and any field values you save for each friend.
- Gift ideas: title, optional URL, optional auto-fetched image, optional price, and notes.
1b. Information collected automatically
- Device push token (FCM): used solely to send you notifications about upcoming dates. Not shared with anyone.
- Crash and performance data (via Firebase Crashlytics): non-identifying diagnostic information used to fix bugs.
- Approximate region (inferred from your IP by Firebase): used to route requests to the nearest Google data center.
1c. What we do NOT collect
We do not access your contacts, calendar, location, microphone, camera (you can pick photos via the system photo picker, but the app cannot read your library without your explicit action per pick), or any third-party social accounts.
2. How we use your information
- To run the app's core features: show your friends, surface upcoming dates, suggest gift ideas, send local notifications.
- To enable friend search: if you opt in via the "Searchable profile" toggle, other authenticated users can find your profile by username or display name. You can turn this off at any time.
- To improve reliability: crash reports help us fix bugs.
We do not sell or rent your data, ever.
3. Who can see your data
| Audience | What they can see |
|---|---|
| You | Everything you've saved. |
| Other FriendBase users | Only your profile fields if you've enabled "Searchable profile". Other users cannot see your friends list, gift ideas, or private fields. |
| Google / Firebase | We use Firebase Authentication, Firestore, Cloud Messaging, and (optionally) Crashlytics and App Check, provided by Google. Their privacy policy. |
| Apple | When you sign in with Apple, Apple sees standard auth metadata. Their policy. |
| Anyone else | Nobody. We never share your data with marketers, brokers, or advertisers. |
4. Data retention and deletion
- Your data is retained as long as your account is active.
- You can delete your account at any time from Settings → "Delete my account". This permanently removes your profile, all friends, all gift ideas, settings, your username reservation, and your authentication record. Deletion is immediate and irreversible.
- We may retain anonymized crash logs for up to 90 days.
5. Security
- All data is encrypted in transit (TLS 1.3) and at rest (AES-256) by Firebase.
- Authentication uses Sign in with Apple (no password ever stored).
- We use Firebase App Check (DeviceCheck / App Attest) to ensure only legitimate copies of FriendBase can talk to our backend.
- Firestore security rules prevent any user from reading another user's friends or settings.
- We never log auth tokens, emails, or personally identifying field contents.
No system is perfectly secure. If you become aware of a security issue, please email security@friendbase.app.
6. Children's privacy
FriendBase is not directed to children under 13 and we do not knowingly collect data from them. If you believe we have, please contact us and we will remove it.
7. Your rights (GDPR / CCPA / state privacy laws)
You have the right to:
- Access the data we hold about you (it's all visible in the app under your profile).
- Correct any incorrect information (edit your profile).
- Delete your account and all associated data (Settings → Delete my account).
- Export your data — contact us at hello@friendbase.app and we'll provide a JSON file within 30 days.
- Opt out of being findable in search (Profile → toggle off "Searchable profile").
- File a complaint with your local data protection authority.
8. International transfers
Firebase processes data in Google's global infrastructure. By using the app you consent to your data being stored in servers that may be outside your country, subject to standard contractual clauses where required.
9. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top will change. Material changes will be notified in-app before they take effect.