Privacy policy
This is the formal version. The plain-English version of what we do and don't do lives on Responsible AI.
Last updated: 2 August 2026 · Version 2.3
1. Who we are
Piaar is operated by Saad Abdullah, PhD, trading as PiaarTech, based in Västerås, Sweden. PIAAR is a registered trademark of Saad Abdullah. For the purposes of GDPR, Saad Abdullah is the data controller for the personal data described in this policy. Contact details are at the bottom of this page.
If you're in the EU/EEA, your local data protection authority can hear complaints if you ever feel we've mishandled your data. In Sweden that's the Integritetsskyddsmyndigheten (IMY).
2. What we collect
Information you give us
- Account data — name, email, and a profile photo if you choose to add one. If you sign up with email, your password is stored only as a secure hash by our authentication provider (Firebase); we never see it.
- Sign-in through Google, Apple, or LinkedIn — if you choose to sign in with Google, Apple (on iOS), or LinkedIn, we receive your name and email address from that provider, plus a profile picture where the provider shares one. We never receive your password for those accounts, and we never post to them or read anything else from them. If you use Apple's "Hide My Email", we only ever see the private relay address Apple gives us.
- Profile data — bio, role, organization, the skills you offer and look for, custom skill proposals.
- Location — your precise coordinates, used to find matches near you. In the app's privacy settings you can choose to hide your exact position, in which case other users only ever see an approximate area rather than where you actually are.
- Location shared in chat — you can optionally share your live location with a connection inside a conversation, for example when you're meeting up. Each share is your explicit choice, applies only to that conversation, and expires automatically after 30 minutes.
- Communications — messages you send through the app, connection requests, support emails.
- Blocks and reports — if you block someone, we store that block so we can enforce it: you and the blocked person disappear from each other's search, map, and matches, and any conversation between you is deactivated. The other person is never told they were blocked. If you report someone, the report reaches us by email and is handled under our terms of service.
- Preferences — discoverability settings, search radius, notification toggles.
Information we generate
- Match scores — computed from your skills against other users' skills; never stored as a permanent attribute, regenerated when inputs change.
- Activity signals — when you last opened the app, last updated your profile, accepted connections; used for sort order and freshness ranking.
- Push notification token — a device token from Firebase Cloud Messaging, used only to deliver notifications about your messages, connection requests, and nearby-meet requests. You control which notifications you get in settings, and the token is removed when you delete your account.
- Nearby-meet proximity signals (Bluetooth) — the app's Meet feature can help you find someone you've agreed to meet in a crowded place. It activates only when both people accept a meet request, uses Bluetooth signal strength to show a coarse sense of closeness ("far", "warmer", "very close"), and stops when the session ends. It shows no direction and no map position, we never derive or store your location from Bluetooth, and there is no background scanning — if you never use Meet, Bluetooth is never used.
- Device data — device type and OS version, app version, anonymized IP for security and rate limiting.
- Usage data (only if you turn it on) — if you switch on "Help improve Piaar", we record which screens you open, whether a search returned matches, and whether a meet actually happened. These events carry a random app-instance identifier, never your name, email, or account id. This is off until you switch it on, and switching it off deletes the identifier and stops collection immediately.
- Your Piaar code — a short random code (for example k3nf8a) that stands in for your account in a shareable link. It is deliberately not your account id. Anyone holding the link can open your public profile while your profile is discoverable. You can reset the code at any time, which immediately breaks every link you have already shared.
- Profile views — when you open someone's profile we record that you did, so they can see who visited. The same applies in reverse. Views are recorded once per person per day.
Information we do not collect
- We don't track you across other apps or websites
- We don't import your contacts
- We don't record audio or use your microphone
- We don't use motion sensors
- We don't scan for Bluetooth devices in the background — proximity is used only during a meet session both people accepted
- We don't scrape public profiles from LinkedIn, GitHub, or anywhere else
- We don't use third-party advertising trackers
- We don't take photos or video — the camera is used only to read a Piaar code, the image is processed on your device, and nothing is stored or uploaded
3. Why we collect it
Every piece of data has a specific purpose. If a use case isn't listed here, we don't have it.
- To match you with people — skills and location are the inputs to the matching engine
- To deliver the app — account data, device data, and activity signals are needed for the product to work
- To notify you — your push token lets us tell you about new messages, connection requests, and meet requests; every notification type can be turned off in settings
- To help you meet safely — chat location sharing and Bluetooth proximity exist only to help two people who chose to meet actually find each other
- To keep you safe — anonymized IP and security logs help us detect abuse and rate-limit attacks
- To respond to you — your support emails and in-app messages are stored so we can follow up
- To improve the product — if, and only if, you switch on "Help improve Piaar", anonymous usage events tell us which parts of Piaar work and which don't. Nothing here is used for advertising or sold
- To keep content safe — events and articles are checked automatically before they appear publicly, so that abusive or explicit content is caught early
- To meet legal obligations — limited retention for tax, fraud, and statutory compliance
4. Legal basis under GDPR
For each category of data, the legal basis is one of the following:
- Consent — for optional features: precise-location visibility, discoverability, sharing your location in a chat, Bluetooth proximity during a meet session, and usage analytics ("Help improve Piaar"). Each of these is off until you turn it on, and you can withdraw consent in Account settings (or simply end the share/session) at any time.
- Contract — for processing necessary to provide the service you signed up for (matching, messaging, account, notifications).
- Legitimate interest — for security, fraud prevention, and keeping published content safe. We've conducted balancing tests and limit processing accordingly. Product improvement through usage analytics is not covered here — that runs on consent only, and nothing is collected until you switch it on.
- Legal obligation — for retention periods imposed by Swedish or EU law.
5. Sharing
We share your data with a short list of service providers ("processors") that we use to run Piaar:
- Google Firebase / Google Cloud (EU regions) — authentication, database (Cloud Firestore), file storage, push notifications (Cloud Messaging), server functions, and the matching service. This is where all app data lives.
- Google Cloud AI (EU regions) — text and images you publish in events and articles are checked automatically by Cloud Natural Language and Cloud Vision before they appear publicly. This runs only on content you publish. It never runs on your private messages, your profile, or your location.
- Google Analytics for Firebase — only if you switch on "Help improve Piaar". Receives anonymous usage events tied to a random app-instance identifier. Not linked to your account, and never used for advertising.
- Sign-in providers — if you sign in with Google, Apple, or LinkedIn, that provider knows you use it to sign in to Piaar. Their own privacy policies govern what they do with that fact. We receive only your name, email, and (where offered) profile picture from them.
- OpenStreetMap — the map in the app loads tiles from OpenStreetMap's servers, and city lookups use its Nominatim service. Like any web request, those requests expose your device's IP address and the map area being viewed to OpenStreetMap. We never send them your name, account, or profile data.
- Email infrastructure — for transactional emails (password reset, verification). Provider details available on request.
We do not sell your data. Not to advertisers, not to recruiters, not to data brokers. If Piaar is ever acquired, your data only transfers to the buyer after you re-consent.
6. Retention
We keep data only as long as we need it for the purpose we collected it.
- Profile data — until you delete your account
- Message history — until you delete the thread or your account
- Block records — until you unblock the person or delete your account
- Shared locations in chat — each share expires after 30 minutes
- Meet (Bluetooth) sessions — session records are deleted when the session ends
- Push notification tokens — until you sign out on that device or delete your account
- Activity logs — 90 days for product improvement, then aggregated or deleted
- Usage analytics — up to 14 months, and only if you switched "Help improve Piaar" on. Switching it off deletes the app-instance identifier on your device and stops collection immediately
- Security logs — 12 months for incident investigation
- Deletion request handling — deleting in-app removes your profile from search and matches immediately (email requests: within 24 hours of verification); downstream caches and matches clear within 7 days; backups roll over within 35 days
7. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you (data export)
- Correct inaccurate or incomplete data
- Delete your account and the data attached to it — see how deletion works
- Restrict processing for specific purposes
- Object to processing based on legitimate interest
- Portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time, without affecting prior lawful processing
- Lodge a complaint with your local data protection authority
To exercise any of these, email privacy@piaartech.com. We respond within statutory windows (typically 30 days, extendable to 60 days for complex requests).
8. Security
All app data lives in Google Firebase, which encrypts data in transit (TLS) and at rest. On top of that we use Firebase App Check to block unauthorized clients from talking to our backend, database security rules that restrict every read and write to the signed-in user's own permissions, password hashing handled by Firebase Authentication (we never store or see passwords), and access to production data limited to the operator. No system is 100% secure — if a breach affecting you ever happens, you'll hear from us within 72 hours per the GDPR breach notification rule.
9. International transfers
Your data is stored in EU data centers (Google Cloud europe-north1 and europe-west1 regions). If any processor we use is outside the EU/EEA, we ensure transfers are protected by Standard Contractual Clauses or equivalent safeguards in line with the Schrems II ruling. If you sign in with Google, Apple, or LinkedIn, those providers process your sign-in under their own EU transfer safeguards.
10. Children
Piaar is not intended for users under 18. We don't knowingly collect data from anyone under that age. If you believe a child is using the service, contact privacy@piaartech.com and we will delete the account promptly.
11. Changes to this policy
If we change this policy meaningfully, we'll notify you in-app and by email at least 30 days before the change takes effect. The version number and "last updated" date at the top of this page change with every revision; older versions are archived and available on request.
All privacy and general questions: privacy@piaartech.com
Postal: We're a small team operating from Sweden — for formal correspondence requiring a physical address, email privacy@piaartech.com and we'll provide one.