← Back to Family49

Privacy Policy

Last updated 9 July 2026

Family49 is a community for internationals building a life in Germany, run by 0049 (“we”, “us”). This policy explains what personal data we collect, why, and the rights you have under the EU GDPR. We are the data controller. For any privacy question or request, contact srijith@zerozerofournine.com.

1. Data we collect

  • Account: your email (held in our authentication system, shared with the 0049/Deck49 app) and a display name.
  • Profile & onboarding: username, city, country of origin, current status, time in Germany, and — for communities you join — German level and goal, university and field of study, and job-search details.
  • Content: posts, comments, reactions, poll votes, and direct messages you create.
  • Social graph & activity: who you follow, spaces you join, bookmarks, points/level, and a “last active” timestamp for online status.
  • Technical: data your browser sends (e.g. IP address), processed by our infrastructure provider to run and secure the service.

2. How and why we use your data (legal basis)

  • To provide the community — profile, feeds, messages, memberships. Basis: our agreement with you (Art. 6(1)(b)).
  • To keep it safe — moderation, preventing abuse. Basis: legitimate interests (Art. 6(1)(f)).
  • To send community emails — only if you opt in. Basis: consent (Art. 6(1)(a)), withdrawable any time in Settings → Privacy.

3. Who we share it with

We do not sell your data or share it for advertising. We use trusted processors, each under a data-processing agreement:

  • Google Firebase — app hosting, database, authentication and image storage, in the europe-west3 (Frankfurt, EU) region.
  • Hetzner (Germany, EU) — hosts the system that manages and sends our community emails.
  • Amazon SES (AWS) — delivers those emails. We pass your email, name and city here only if you opt in to community emails.
  • Expo (Expo push notifications) — if you turn on notifications, your device push token and notification content are relayed through Expo’s servers to deliver push notifications; these servers may be located outside the EU.
  • Google Firebase Cloud Messaging — delivers push notifications to your browser or device.
  • OpenAI — to keep the community safe, the text of public posts and comments is screened by OpenAI’s content-moderation service to detect harmful or illegal content (e.g. hate speech, threats, sexual content, scams, spam). We do not send private direct messages or group chats. OpenAI returns only a safety rating and, under its API terms, does not use this content to train its models.

Content you post (e.g. in public spaces) is visible to other members by design.

4. Cookies & tracking

We use only the essential storage needed to keep you signed in. We do not run Google Analytics or any third-party advertising/tracking cookies, so there is no tracking-cookie banner. If we ever add analytics, we will ask for your consent first.

5. Special-category data

Some information you may choose to share — such as your country of origin, or details in direct messages — can reveal or imply sensitive characteristics. Providing these fields is entirely optional; we ask for them only to run the relevant community, we do not use them for profiling or automated decisions, and we rely on your explicit consent (Art. 9(2)(a)) where such data is processed. You can remove them any time in Settings, or delete your account.

6. Automated decisions & profiling

We do not make decisions with legal or similarly significant effects about you by automated means. We tag your interests (e.g. “student”) from your onboarding choices only to route you to relevant communities and, with your consent, relevant emails.

To keep the community safe, we use automated tools (including OpenAI’s moderation service) to screen public posts and comments for content that may break our rules. This can temporarily hide a post or comment pending review, but a human moderator makes the final decision — if your content is hidden or removed you will be told and you can appeal.

7. International transfers

Your data is stored and processed in the EU — Firebase (Frankfurt) and Hetzner (Germany), with Amazon SES set to an EU region. Some services — such as Expo’s push-notification relay and OpenAI’s content-moderation service — may process limited data (e.g. a device push token, notification content, or the text of public posts and comments) outside the EU. Where a provider is a non-EU company that may process data outside the EU, it is protected by appropriate safeguards such as the EU Standard Contractual Clauses (for example, under the AWS Data Processing Addendum).

8. How long we keep it

We keep your data while your account is active. Deactivating hides your profile but retains data so you can return. Deleting your account (Settings → Security → “Delete my account & data”) permanently erases your Family49 profile, posts, comments, messages and memberships. Your shared 0049 login is kept so the Deck49 app keeps working.

9. Your rights

  • Access & portability — Settings → Security → “Download my data”.
  • Rectification — edit your profile in Settings.
  • Erasure — Settings → Security → delete your data.
  • Withdraw consent — turn off community emails in Settings → Privacy.
  • Object / restrict processing, and complain to a supervisory authority (in Germany, your state Data Protection Authority).

To exercise any right, use the in-app tools above or email srijith@zerozerofournine.com.

10. Security

Access to your data is protected by authentication and server-side security rules. Uploaded images are stored privately and scoped to your account.

11. Children

Family49 is not intended for anyone under 16, and we do not knowingly collect their data.

12. Changes

We may update this policy; we’ll note the date above and flag material changes in the app.

13. Contact

Questions or requests: srijith@zerozerofournine.com.