EUTOOBack to home

Privacy Policy

1Introduction

This Privacy Policy explains how Youtoo.Social SL (“EUTOO,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects personal data when you use the EUTOO mobile application (the “App”). EUTOO is a social networking app. By creating an account and using the App, you acknowledge and accept that your personal data will be processed as described in this Policy. EUTOO is subject to an age limit of 18 years and therefore, no content is intended for or directed at children.

2Who Is Responsible For Your Data (the Data Controller)

The entity that decides why and how your personal data is processed — the “data controller” under GDPR — is: Youtoo.Social SL
NIF: B88863477
Registered address: Olleries no. 5, 07142 Santa Eugenia, Spain
Contact email: privacy@eutoo.eu

3What Personal Data We Collect

We collect and process the following categories of personal data, generally directly from you as you use the App:

3.1Account and profile data

Email address and password (your password is never stored in readable form — only a one-way

cryptographically hashed version is stored, which we ourselves cannot read), or an identifier from Sign in with Apple / Sign in with Google if you use those options.

Username.

Nationality and country of residence.

Date of birth

Interests you select from a preset list (some of these are ideologically or politically flavored, e.g. “Democracy,”

“Social Justice,” “European Identity” — see Section 3.6 on special category data).

Optional: full name, short biography, profile photo, and a personal website link.

3.2Content you post

“V oices” — public posts visible to everyone on the App.

“Moments” — governed by a per-user visibility setting. The options are: Everyone, Friends only, or Friends

from your country. The default setting is “Everyone” — a user who never opens this setting is posting Moments publicly, not to friends only.

A separate setting controls whose Moments appear in your own feed: Everyone, Friends only, or Your country

only. Because of this, your nationality is used by the App to decide who can see your Moments and whose Moments you are shown, not only displayed on your profile.

Text, photos and/or videos attached to posts, including posts you mark to automatically expire after a period of

time.

The group or topic category a post is filed under, where applicable.

3.3Interactions and social graph

Likes, comments (and likes on comments), reposts, and private post shares to a specific friend — each

recorded together with who performed the action and on what content.

Friend requests sent, accepted, declined, or blocked, which together form your network of connections.

Group memberships and your role within each group.

3.4Private messages

The content of one-to-one and group chats: text, photos, videos, and voice (audio) recordings.

Message metadata: delivered/read receipts (recording, for each message and each participant, when it was

delivered and when it was seen), emoji reactions to individual messages, and per-conversation records of when you last read a chat, how many messages are unread, whether you have muted, pinned, or archived it, and when you joined or left.

A "delete for me" record when you remove a message from your own view — this hides the message from you

only; it remains stored and visible to the other participant(s), and is not deleted from our systems (see Section 7).

3.5Notifications and device data

A push notification token for each device you use, so we can deliver alerts (likes, comments, messages, friend

requests, etc.).

Your notification preferences (on/off, globally or per notification type).

Stored notification records hold templated text describing an action (e.g. "[username] reacted to your

message") and do not contain private message content, and no notification record is created for new-message pushes at all. Separately, the push notification itself — sent via Expo to Apple or Google (see Section 6) — carries a content preview of up to the first 50 characters of a new message, or a placeholder such as "Photo" or "Audio message" where there is no text. This preview is not stored by us; it is generated at send time and only exists in the transfer described in Section 6.

Local storage and session identifiers on your device (see Section 11 — Cookies, Local Storage and Similar

Technologies), including a cache of your most recent conversations, and a session/login token to keep you signed in.

3.6Content moderation / reports

If you report a post, photo, video or any other content (e.g. for spam, harassment, hate speech, nudity, violence,

or misinformation), we record who made the report, which content it concerns, the category selected, and any optional written explanation. Currently, posts can be reported within the App whereas other content can be reported via e-mail to support@eutoo.eu.

3.7Special category and sensitive data

The following special categories of personal data may be processed; however, such data will only be provided from you or other users and will not be required to use the App:

Some self-selected interests may reveal political opinions or philosophical beliefs.

Post and private messages may, by their nature, contain any category of data a user chooses to share, including

special category data. We do not proactively read or analyse message content. If any personal data about you is disclosed by another user, we do not separately notify you that we hold this data as this would be a disproportionate effort, as individually notifying every user referenced in another user's message, comment, or report is not feasible at the App's scale.

3.8A note on public media links

Three categories of files are stored in a public file area, reachable directly by anyone who has the file's web address without signing in, regardless of the visibility setting on the post it belongs to: photos and videos attached to posts, and your profile photo. Three categories are stored in an access-controlled (private) area, reachable only via a signed link issued to conversation participants, which expires: photos, videos and voice notes sent in chats.

3.9Links (Third-Party Disclosure)

When you open a web link that has been added into a post, chat message or elsewhere, your device contacts that third- party website directly and this discloses your device's IP address to the operator of that website. We do not control what the destination website does with that information. This is a disclosure to a third party, not a transfer to one of our service providers.

4How and Why We Use Your Data (Purposes and Legal Bases)

Under GDPR, every use of personal data needs a legal basis. The table below sets out our intended purposes and bases.

PurposeWhat data is involvedLegal basis (GDPR Art. 6)
Creating and maintaining your account; authenticationEmail/password (hashed) or Apple/Google sign-in identifier, date of birthPerformance of a contract (Art. 6(1)(b))
Operating your profile and letting other users view itUsername, nationality, country, interests, name, bio, photo, websitePerformance of a contract (Art. 6(1)(b))
Letting you post, comment, like, repost, and share contentPosts, comments, reactions, mediaPerformance of a contract (Art. 6(1)(b)); manifestly made public by the data subject (Art. 9(2)(e))
Building and managing your friend network and groupsFriend requests/connections, group membershipsPerformance of a contract (Art. 6(1)(b)); manifestly made public by the data subject (Art. 9(2)(e))
Delivering private messagesChat text, photos, videos, voice notes, read receiptsPerformance of a contract (Art. 6(1)(b))
Keeping you signed in and making messaging responsiveSession/login token, local conversation cachePerformance of a contract (Art. 6(1)(b))
Sending push notifications (can be turned off by the user at any time)Push token, notification textLegitimate interest in core app functionality (Art. 6(1)(f))
Content moderation and trust & safetyReports, reported content, report reasonLegitimate interest in a safe platform (Art. 6(1)(f)); legal obligation (Art. 6(1)(c))
Diagnosing crashes and technical errorsTechnical logs, device/OS details (pseudonymised, no name/email linkage)Legitimate interest in a reliable, secure service (Art. 6(1)(f))
Understanding product usage (analytics)In-app usage events (not for advertising)Legitimate interest in developing the app (Art. 6(1)(f))
Complying with legal obligationsAs required (e.g. responding to lawful requests)Legal obligation (Art. 6(1)(c))
Processing personal data about other users that you or another user discloses (messages, comments, reports)Content referencing a third party; report explanationLegitimate interest in operating the App's core social and safety functionality (Art. 6(1)(f))

We do not use your data for advertising, behavioral profiling for third-party marketing, or automated decision-making with legal or similarly significant effects. We do not sell personal data, and at this point in time, we do not use advertising trackers, analytics-for-advertising tools, or data broker relationships of any kind. If this changes, we will inform you and secure any required consents.

5Who We Share Data With

We share personal data only with the service providers strictly necessary to run the App, and never with advertisers or data brokers. Each provider acts under contract, only on our instructions, and only for the purposes below.

5.1Current sub-processors and recipients

Hostinger International Limited (“Hostinger”) — provides our database, authentication system, file storage,

and current notification pipeline. This is where account, profile, post, message, and media data is stored, hosted in Frankfurt, Germany (EU).

650 Industries, Inc. (Expo) — the software toolkit the App is built with. Its push-notification relay service

passes the push token and notification text onward to Apple and Google.

Apple Distribution International Limited and Apple Inc. — Apple Distribution International Limited delivers

push notifications to iPhones (Apple Push Notification service), and distributes the App via TestFlight and the App Store, and Apple Inc. provides processing and storage for Apple-affiliated companies.

Google LLC — delivers push notifications to Android phones via its equivalent notification service, and will

distribute the App via Google Play. Google Sign-In is also used for identity services.

Functional Softward Inc. d/b/a Sentry — performance evaluation, crash and error reporting. Configured to use

Sentry's EU (Germany) data region. Performance data may include screen and network timings on a sample of sessions. Technical logs may include what failed, the code path, and device/OS details; we avoid linking names, emails, or profile identities to these logs. 650 Industries, Inc. (Expo), Apple Inc. and Google LLC are US companies. Please see Section 6 on international transfers.

5.2Hosting

Our database, authentication, storage, and related infrastructure currently run on Hostinger managed cloud in Frankfurt, Germany.

5.3Legal disclosures

We may disclose personal data where required to comply with a legal obligation, enforce our Terms, protect the rights, property, or safety of Youtoo.Social SL, EUTOO, our users, or the public, or in connection with a merger, acquisition, or sale of assets.

6International Data Transfers

Your personal data is stored and processed within the European Union: currently in Frankfurt, Germany in Hostinger’s data centre. The one routine exception is “push” notifications. To deliver a notification to your phone, your device's push token and a content preview pass through Expo's notification relay on their way to Apple's or Google's notification services, which then deliver the alert to your device. The alert contains up to the first 50 characters of the message text itself, or a placeholder such as "Photo" or "Audio message" where there is no text. This means a fragment of a private conversation, not merely a signal that something happened, is what delivered to Expo, Apple and Google. You can turn off the push notification at any time. For transfers to Google LLC (US-based) and 650 Industries, Inc. (Expo) (US-based), we rely on the EU-U.S. Data Privacy Framework (DPF). For transfers to Apple Inc. (US-based), we rely on the European Commission's Standard Contractual Clauses (SCCs).

7Data Retention

We intend to retain personal data for as long as your account remains active, and for a limited period afterward as needed to comply with legal obligations, resolve disputes, and enforce agreements. Specific retention periods, are:

Account and profile data: retained while your account is active. You may delete your account permanently and

thereby immediately erase your profile, posts, comments, messages, friendships, group memberships, notifications, push tokens, and stored media files.

Posts, comments, reactions, and messages: retained while your account is active. Deleting an individual post,

comment, or message (including "delete for me" in chat) only hides it from display — the record and any attached media currently remain in storage indefinitely. Content of this kind is only genuinely erased if the account itself is deleted.

Content that you set to expire is automatically removed from normal display at the set time. Any expired

content is NOT deleted from storage, and it remains in full in our database indefinitely. Content of this kind is only genuinely erased if the account itself is deleted.

Reports of content violations: retained for 24 months to support moderation consistency and, where relevant,

legal defense.

Crash/error logs (Sentry): retained per Sentry's standard retention window, currently 30 days, and not linked to

your identity.

Local storage and session data (see Section 11): the recent-chat cache and session/login token are cleared

automatically when you sign out, or when you clear the App's data.

8How We Protect Your Data

All data in transit between the App and our servers is encrypted.

Passwords are never stored in plain text; only a one-way cryptographic hash is stored, which cannot be

reversed even by us.

Our database enforces per-user, row-level access rules, so a user's request can only read the data they are

permitted to see.

Private message media (photos, videos, voice notes) is stored in access-controlled storage reachable only by

conversation participants.

We do not integrate advertising SDKs, third-party trackers, or analytics-for-advertising tools that could

otherwise widen access to your data.

The local on-device cache of recent chats (Section 3.5/11) is currently stored in an ordinary, unencrypted

database file on the device, relying on the device's own security. No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a data breach affecting your personal data, we will notify the relevant supervisory authority and affected users as required by GDPR Articles 33–34.

9Your Rights Under GDPR

If you are located in the EEA (or another jurisdiction granting similar rights), you have the right to:

Access — request a copy of the personal data we hold about you.

Rectification — ask us to correct inaccurate or incomplete data.

Erasure (“right to be forgotten”) — ask us to delete your personal data, subject to certain legal exceptions.

Restriction — ask us to limit how we use your data in certain circumstances.

Data portability — receive your data in a structured, commonly used, machine-readable format, or have it

transferred to another provider where technically feasible.

Objection — object to processing of your data.

Withdraw consent — where processing is based on consent, withdraw it at any time without affecting prior

lawful processing.

Lodge a complaint with a supervisory authority.

To exercise any of these rights, please contact us at privacy@eutoo.eu. We aim to respond within one month as required by Article 12(3) GDPR.

10Children and Minimum Age

EUTOO is only available to users who are 18 years of age or older. When setting up an account users must fill in their date of birth and it is not possible to create an account if the user is below the age of 18 years. We do not knowingly allow anyone under 18 to create an account or use the App.

11Cookies, Local Storage and Similar Technologies

The App uses local storage and session identifiers on your device, which function similarly to cookies. These are:

A session / login token, stored on your device, which keeps you signed in between app openings so you are not

asked to re-enter your credentials every time.

A local cache of your most recent conversations (roughly the last 30 messages per recent chat), stored on your

device so messages load instantly rather than being re-fetched from our servers each time. We consider these technologies strictly necessary to provide the App as requested by the user (i.e. to keep you logged in and to make messaging responsive). Both the session token and the local conversation cache are removed automatically when you sign out, and can also be cleared manually at any time by clearing the App's data through your Android device settings. We use these technologies for product analytics to understand how the App is being used, however, we do not use these technologies for advertising or cross-app tracking.

12Automated Decision-Making

We do not currently use your personal data for any automated decision-making or profiling that produces legal effects or similarly significantly affects you. If this changes (for example, automated content-moderation decisions with account consequences), we will update this Policy and provide you with information accordingly.

13Changes to This Policy

We may update this Privacy Policy from time to time, for example as new features are enabled or as legal requirements change. We will post the updated Policy in the App with a new effective date, and where changes are material, we will seek your renewed acceptance or provide advance notice as required by law.

14Contact Us

For any question about this Policy or how your data is handled, or to exercise your rights under Section 9, please contact us at privacy@eutoo.eu.

Telephone: +34 670 400 016 / Email: support@eutoo.eu / Palma de Mallorca / Spain NIE: B88863477