Last updated: 30 September 2026 · Version 2.5
1. Who we are
Piaar is operated by Saad Abdullah, PhD, trading as PiaarTech, based in Västerås, Sweden. PIAAR is a registered trademark of Saad Abdullah. For the purposes of GDPR, Saad Abdullah is the data controller for the personal data described in this policy. Contact details are at the bottom of this page.
If you're in the EU/EEA, your local data protection authority can hear complaints if you ever feel we've mishandled your data. In Sweden that's the Integritetsskyddsmyndigheten (IMY).
2. What we collect
Information you give us
- Account data — name, email, and a profile photo if you choose to add one. If you sign up with email, your password is stored only as a secure hash by our authentication provider (Firebase); we never see it.
- Sign-in through Google, Apple, or LinkedIn — if you choose to sign in with Google, Apple (on iOS), or LinkedIn, we receive your name and email address from that provider, plus a profile picture where the provider shares one. We never receive your password for those accounts, and we never post to them or read anything else from them. If you use Apple's "Hide My Email", we only ever see the private relay address Apple gives us.
- Profile data — bio, role, organization, workplace, the skills you offer and look for, custom skill proposals. Your workplace field is public, so it goes through the same automated content check as events and articles before it's shown to anyone else.
- Location — your coordinates, used to find matches near you. Precise location is off by default for accounts created from this release onward; if your account was created before this release, precise location may already be switched on for it, and you can turn it off any time in the app's privacy settings. Either way, other users only ever see an approximate area on your public profile — never your exact position.
- Location shared in chat — you can optionally share your live location with a connection inside a conversation, for example when you're meeting up. Each share is your explicit choice and applies only to that conversation. It's shown live for 30 minutes, after which the app stops displaying it as current — but the position stays in that conversation's history, visible to the person you shared it with, until you delete your account.
- Communications — messages you send through the app, connection requests, support emails.
- Blocks and reports — if you block someone, we store that block so we can enforce it: you and the blocked person disappear from each other's search, map, and matches, and any conversation between you is deactivated. The other person is never told they were blocked. If you report someone, the report reaches us by email and is handled under our terms of service.
- Preferences — discoverability settings, search radius, notification toggles.
- Event contact sharing — when you RSVP to an event, its organizer can already export your name, headline, and the skills you offer as part of their attendee list; that part isn't optional. What is optional, and off unless you switch it on, is including your email address (and phone number, if we hold one) in that same export. It's a separate choice for each event, and leaving the RSVP removes you from future exports. We record each decision in your consent log.
- Event check-in — if an event uses in-app check-in, we record that you checked in, visible to that event's organizer as part of their attendance record.
If you are a business customer
Separately from individual accounts, we hold records for organizations and individual customers who buy organizer plans, event promotion or event reporting:
- Organization details — organization name, the owner account, and any members invited to manage it.
- Billing contact — a name and email address, and a phone number if the customer chooses to give one. This is the only place a phone number is held anywhere in Piaar; the app never asks individual users for one.
- Commercial records — plan terms, entitlements, invoices and payment records.
Information we generate
- Match scores — computed from your skills against other users' skills; never stored as a permanent attribute, regenerated when inputs change.
- Activity signals — when you last opened the app, last updated your profile, accepted connections.
- Push notification token — a device token from Firebase Cloud Messaging, used only to deliver notifications about your messages, connection requests, and nearby-meet requests. You control which notifications you get in settings, and the token is removed when you delete your account.
- Nearby-meet proximity signals (Bluetooth) — the app's Meet feature can help you find someone you've agreed to meet in a crowded place. It activates only when both people accept a meet request, uses Bluetooth signal strength to show a coarse sense of closeness ("far", "warmer", "very close"), and stops when the session ends. It shows no direction and no map position, we never derive or store your location from Bluetooth, and there is no background scanning — if you never use Meet, Bluetooth is never used.
- Device data — device type and OS version, app version, and your IP address, used for security purposes.
- Usage data (only if you turn it on) — if you switch on "Help improve Piaar", we record which screens you open, whether a search returned matches, and whether a meet actually happened. These events carry a random app-instance identifier, never your name, email, or account id. This is off until you switch it on, and switching it off deletes the identifier and stops collection immediately.
- Your Piaar code — a short random code (for example k3nf8a72) that stands in for your account in a shareable link. It is deliberately not your account id. Any signed-in Piaar user holding the link can open your public profile while your profile is discoverable. You can reset the code at any time, which immediately breaks every link you have already shared.
- Profile views — when you open someone's profile we record that you did, so they can see who visited. The same applies in reverse. If the visitor is not discoverable, they're shown to you as an anonymous visit rather than by name. Views are recorded once per person per day.
- Search history — which skills you searched for and which profiles were shown to you as a result. We use this to run the matching service, and we also keep it for our own internal analytics and reporting on how people search and what the network surfaces for them. It isn't shared outside the company, sold, or used to advertise to you. See Retention, below, for how long it's kept.
Information we do not collect
- We don't track you across other apps or websites
- We don't import your contacts
- We don't record audio or use your microphone
- We don't use motion sensors
- We don't scan for Bluetooth devices in the background — proximity is used only during a meet session both people accepted
- We don't scrape public profiles from LinkedIn, GitHub, or anywhere else
- We don't use third-party advertising trackers
- We don't take photos or video — the camera is used only to read a Piaar code, the image is processed on your device, and nothing is stored or uploaded
3. Why we collect it
Every piece of data has a specific purpose. If a use case isn't listed here, we don't have it.
- To match you with people — skills and location are the inputs to the matching engine
- To deliver the app — account data, device data, and activity signals are needed for the product to work
- To notify you — your push token lets us tell you about new messages, connection requests, meet requests, event reminders, organizer announcements, moderation decisions about your own content, important account or service notices, and (if you've opted in per the Recruiters section below) job alerts; every notification type can be turned off in settings
- To help you meet safely — chat location sharing and Bluetooth proximity exist only to help two people who chose to meet actually find each other
- To keep you safe — your IP address and security logs help us detect abuse and respond to attacks
- To respond to you — your support emails and in-app messages are stored so we can follow up
- To improve the product — if, and only if, you switch on "Help improve Piaar", pseudonymous usage events tell us which parts of Piaar work and which don't. Nothing here is used for advertising or sold
- To understand how the network is used — your search history (see "What we collect," above) feeds our own internal analytics and reporting on how people search and what Piaar surfaces for them. This runs regardless of the "Help improve Piaar" toggle, and is never used for advertising or sold
- To keep content safe — events, articles, event announcements, job posts, job-alert messages, and the "workplace" field on your profile are checked automatically before they're shown to anyone else, so that abusive or explicit content is caught early
- To show organizers what their event produced — attendance, connections made and the skills present in the room, so an organizer can see whether the networking actually worked. Your contact details are part of this only if you switched on event contact sharing for that event
- To meet legal obligations — limited retention for tax, fraud, and statutory compliance
4. Legal basis under GDPR
For each category of data, the legal basis is one of the following:
- Consent — for optional features: discoverability, sharing your location in a chat, Bluetooth proximity during a meet session, sharing your contact details with an event organizer, and usage analytics ("Help improve Piaar"). Each of these is off until you turn it on, and you can withdraw consent in Account settings (or simply end the share/session, or leave the RSVP) at any time. Precise location is on the same consent basis and is off by default for accounts created from this release onward; if your account predates this release, precise location may already be on for it, and you can turn it off in Account settings at any time.
- Contract — for processing necessary to provide the service you signed up for (matching, messaging, account, notifications).
- Legitimate interest — for security, fraud prevention, keeping published content safe, keeping a record of who searched for what (see Retention, below), and showing you who viewed your profile, used only to the extent it doesn't override your own rights and interests. Product improvement through usage analytics is not covered here — that runs on consent only, and nothing is collected until you switch it on.
- Legal obligation — for retention periods imposed by Swedish or EU law, including the seven-year retention of invoices and accounting records under bokföringslagen.
5. Sharing
We share your data with a short list of service providers ("processors") that we use to run Piaar:
- Google Firebase / Google Cloud — authentication, database (Cloud Firestore), file storage, push notifications (Cloud Messaging), server functions, the matching service, App Check (which uses Play Integrity on Android and App Attest on iOS to confirm a request comes from our real app), and Remote Config. Our database runs in Google Cloud's eur3 multi-region and our server functions and matching service run in europe-west1 (Belgium) — both inside the EU. Push notifications, authentication infrastructure, App Check, and Remote Config are global Google services by design and aren't pinned to the EU. On iOS, notifications are delivered through Apple's Push Notification service (APNs).
- Google Cloud AI — text and images you publish are checked automatically by Cloud Natural Language and Cloud Vision before they appear publicly: events, articles, event announcements, job posts, job-alert messages, and the "workplace" field on your profile. As currently configured, this moderation runs on Google's global default infrastructure rather than an EU-restricted endpoint. It runs only on that public content — never on your private one-to-one messages or your location.
- Google Analytics for Firebase — only if you switch on "Help improve Piaar". Receives usage events tied to a random app-instance identifier. Not linked to your account, and never used for advertising. This identifier is pseudonymous, not anonymous — it can persist across a sign-out and sign-in with a different account on the same device, so we don't call it anonymous.
- Sign-in providers — if you sign in with Google, Apple, or LinkedIn, that provider knows you use it to sign in to Piaar. Their own privacy policies govern what they do with that fact. We receive only your name, email, and (where offered) profile picture from them. If you sign in with LinkedIn and it shares a profile photo, that photo is loaded directly from LinkedIn's own servers rather than copied to ours, so opening your profile picture also sends a request to LinkedIn's content delivery network.
- OpenStreetMap — the map in the app loads tiles from OpenStreetMap's servers, and city lookups use its Nominatim service. Like any web request, those requests expose your device's IP address and the map area being viewed to OpenStreetMap. We never send them your name, account, or profile data.
- Email infrastructure — for transactional emails: password reset and verification, event and connection invitations, workspace and organization management invites, and plan and billing notices. Provider details available on request.
Event organizers
An event organizer is not one of our processors — they are a separate controller of whatever they receive from us, and their own privacy policy governs what they do with it afterwards. Two things can reach them:
- Your attendee details. An organizer can export the name, headline, and offered skills of everyone who RSVP'd to their event — that part happens whether or not you turn anything on. Your email address (and phone number, if we hold one) is included in that export only if you switched on contact sharing for that specific event. Withdrawing consent, or leaving the RSVP, stops you appearing in future exports — but we cannot recall an export the organizer has already downloaded.
- Event outcome reporting. Organizers see how their event performed: how many people attended, how many connections and skill-matches it produced, invitations sent, and the most common skills in the room. This is reporting about the event, and is separate from the contact export above.
Recruiters
If you're Discoverable and switch on "Open to opportunities," you can see jobs a workspace posts and choose to act on them. Just being shown a job, or eligible for a job alert, does not share anything about you with the recruiter — our server checks eligibility against your coordinates and a recruiter composing an alert only ever sees a rounded count of how many people it reached, never who they are.
Tapping "I'm interested" on a job is different: it requires a separate standing consent, "Share details with recruiters" in Account settings, because it's what lets a recruiter see more of you. Once given, it covers every future job until you turn it off. From that point, the workspace owner can see your public profile (name, headline, category, city, photo, bio, and the skills you offer) and the match score you held at the moment you applied, and can download that alongside your email address in a spreadsheet export — but only while your standing consent is currently switched on. Your exact coordinates and phone number are never part of this. Turning off that consent, or withdrawing from a specific job, stops future sharing; it can't recall a profile or an export a recruiter has already seen or downloaded.
We do not sell your data. Not to advertisers, not to data brokers, and not for money to recruiters either — but if you apply to a job, a recruiter does legitimately receive some of your data with your consent, exactly as described above. We'd rather be precise about that than imply recruiters never see anything about you. If Piaar is ever acquired, we intend that your data would only transfer to the buyer after you re-consent — that's a commitment about how we'd handle an acquisition, not something our systems can enforce on their own.
6. Retention
We keep data only as long as we need it for the purpose we collected it.
- Profile data — until you delete your account
- Message history — kept until you or the other person deletes their account; "clearing" a chat in the app only hides it on your device, it doesn't delete it
- Block records — until you unblock the person or delete your account
- Shared locations in chat — shown live for 30 minutes, then stays in that conversation's history until you delete your account
- Meet (Bluetooth) sessions — deleted automatically shortly after the session expires
- Push notification tokens — until you sign out on that device or delete your account
- Search history — which skills you searched and which profiles were shown to you, kept under a 90-day automatic-deletion policy
- Profile-view log — who viewed your profile and when; we haven't yet set a fixed retention period for this one
- Usage analytics — only if you switched "Help improve Piaar" on, kept for Google Analytics for Firebase's standard retention window. Switching it off deletes the app-instance identifier on your device and stops collection immediately
- Security logs — kept for a limited period for incident investigation, on our cloud provider's standard retention setting
- Event contact sharing — your consent decision is kept while you hold the RSVP; contact details an organizer has already exported are held by that organizer under their own retention rules, not ours
- Business customer records — invoices and related accounting records are kept for seven years, as Swedish accounting law (bokföringslagen) requires; organization and plan records are kept while the customer relationship is active; a job report PDF is kept for 24 months and then deleted automatically
- Deletion request handling — deleting your account in the app takes effect immediately: your profile is removed from search and matches right away. We don't currently run scheduled backups of this database, so there's no backup-rollover period behind it. A few things intentionally continue to exist after deletion because they're someone else's record or a legal record: messages you sent remain in the other person's copy of a conversation (shown as from a deleted account), events belonging to an organization stay with that organization, and paid invoices are kept for seven years as described above. Email deletion requests are handled as described under "Your rights," below.
7. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you (data export)
- Correct inaccurate or incomplete data
- Delete your account and the data attached to it — see how deletion works
- Restrict processing for specific purposes
- Object to processing based on legitimate interest
- Portability — on request by email, we'll send you your data in a structured, machine-readable format
- Withdraw consent at any time, without affecting prior lawful processing
- Lodge a complaint with your local data protection authority
To exercise any of these, email privacy@piaartech.com. We respond within statutory windows: one month, extendable by up to two further months for complex requests.
8. Security
All app data lives in Google Firebase, which encrypts data in transit (TLS) and at rest. On top of that we use Firebase App Check to block unauthorized clients from talking to our backend, database security rules that are designed to restrict reads and writes to what a signed-in user should be allowed, password hashing handled by Firebase Authentication (we never store or see passwords), and access to production data limited to the operator. No system is 100% secure. If a breach happens, GDPR requires us to notify our supervisory authority (IMY) within 72 hours of becoming aware of it; if the breach is likely to put you at risk, we will also tell you directly — the law doesn't set a fixed deadline for that part, only "without undue delay."
9. International transfers
Your core data — account, profile, and messages — is processed within the EU: our database (Cloud Firestore) runs in Google Cloud's eur3 multi-region, and our server functions and matching service run in europe-west1 (Belgium). Some processing is not confined to the EU by default: our content-moderation calls to Google Cloud Natural Language and Vision currently run on Google's global endpoints rather than an EU-restricted one (see Sharing, above), and services like push notifications, authentication, and Remote Config are global Google infrastructure by design, not something we can pin to the EU ourselves. If any processor we use is outside the EU/EEA, we rely on Standard Contractual Clauses or an equivalent safeguard in line with the Schrems II ruling. If you sign in with Google, Apple, or LinkedIn, those providers process your sign-in under their own infrastructure and transfer safeguards.
10. Children
Piaar is not intended for users under 18. We don't knowingly collect data from anyone under that age. If you believe a child is using the service, contact privacy@piaartech.com and we will delete the account promptly.
11. Changes to this policy
If we change this policy meaningfully, we'll notify you in-app and by email at least 30 days before the change takes effect. The version number and "last updated" date at the top of this page change with every revision.
All privacy and general questions: privacy@piaartech.com
Postal: Fiholmsgatan, Västerås, Sweden — see Trader details on our contact page.