Privacy Policy
Last updated 17 May 2026
Taluvo is a family event coordination app. We're built around the principle that people coordinating with each other — getting home, meeting up, picking each other up — should not have to give up their privacy to do it.
This policy explains what we collect, why, where it goes, and how you can see, export, or delete it.
1. What we collect
We collect only what's needed to make the app work.
- Phone number — required to sign in and to receive event invites from people who know your number. Verified by SMS at sign-up via Firebase Auth.
- Display name — what other people see when you accept an event invite or appear in their connections list. You choose it; you can change it any time in Settings.
- Connections you accept — the list of people you have explicitly agreed to share event invites with. Always opt-in; the other side cannot see you as a "connection" until you tap Accept on their request.
- Events you create or are invited to — title, optional time, optional address you typed, optional meeting link, and the people invited.
- Live ETA during an active journey — when you tap "I'm leaving now" we ask for one fresh location reading. The reading is sent to our server once, used to compute an estimated arrival time, and then immediately discarded — it is never written to any database, log, or storage system. Only the resulting ETA in minutes (not your location) is then shared with the event creator. You can also choose to send "on the way" without an ETA — in that case we don't even take the location reading. The journey ends the moment you tap "I've arrived"; if you forget, the system automatically marks it arrived after a configurable window (default 8 hours past your stated ETA — adjustable from 1 hour up to 4 days in Settings). There is no live or background location tracking at any point.
- Device push token (FCM) — required to deliver notifications. Anonymous to us; meaningful only to Google's push infrastructure.
- Crash reports and basic analytics — anonymized events (screen-views, action counts) and crash stack traces via Firebase Crashlytics + Firebase Analytics. No personally identifying fields are attached.
We do not collect: your contacts list, your full location history, your messages, your call log, your photos, biometrics, or anything from other apps on your device.
2. What we do NOT do
- No selling of data. We never sell your data to anyone.
- No tracking across other apps or websites. No third-party trackers are loaded by the app. The only third-party SDKs in the app are Google (Firebase + AdMob), all under the privacy posture described below.
- No background location. Location is requested only at the moment you tap "I'm leaving now" and is dropped on arrival.
- No address-book scraping. When you invite someone by phone number, we hold that number until they sign up (so the invite can be redeemed) — we do not read your phone book.
3. Who can see what
The app is built so that data flows are limited to the relationship you have explicitly opted into.
- Your own profile data — only you and our backend can read it.
- Your event invites — only people invited to a specific event can see that event and who's been invited (the event creator can also choose to hide the invitee list).
- Your live journey ETA — only the creator of the event you're on the way to can see it. Other invitees see "X is on the way" without your ETA. This is enforced on the server, not just in the app.
- Your connections — appear on your "People" tab and only there. Other users cannot enumerate your connections.
4. Ads (AdMob)
Taluvo shows ads via Google AdMob to keep the app free. We've configured AdMob with the strictest privacy posture available:
- No personalized advertising. We tag every ad request with "treat as user under age of consent," which suppresses behavioral targeting, IDFA/AAID collection, and cross-app tracking.
- EEA/UK consent is handled by Google's User Messaging Platform (UMP). You'll see a consent form on first launch in those regions and can revisit it via Settings → Manage privacy options.
- Withdrawal. You can withdraw advertising consent at any time via that same Settings screen. After withdrawal the app continues to function; ads may still appear non-personalized as Google's fallback.
See also:
5. Where your data is stored
All data lives in Google's cloud (Firebase / Google Cloud Platform).
Storage region: europe-west1 (Belgium). Encryption in transit (TLS)
and at rest (Google-managed keys).
6. How long we keep it
You control retention. Settings → Privacy → Data retention lets you set a window (e.g. 90 days) after which old events, journeys, and notifications are automatically deleted server-side. The default is to keep your data until you delete your account.
Crash logs and analytics summaries: retained per Firebase defaults (currently 30 / 60 days respectively).
7. Your rights — see, export, delete
- See your data: every screen in the app shows you the data we hold about you. Nothing is hidden.
- Export a copy: Settings → Privacy → Export my data runs a server-side job that returns a JSON dump of everything tied to your account. You can share it with another app or save it.
- Delete your account: Settings → Account → Delete account schedules a permanent deletion. All your events, member rows, journeys, connections, and notifications are reaped. The phone number is freed so it can sign up again as a brand-new user. We may retain audit-log entries for up to 90 days for fraud and security investigation; these contain no profile data, only the fact that an action occurred.
For requests we can't fulfill in-app (e.g. you can't sign in), email hello@threeandapaw.com and we'll respond within 30 days.
8. Children
Taluvo is not directed to children under 13 (under 16 in the EEA). Sign-up requires a working phone number. If we learn that we've collected data from a child, we'll delete it.
9. Changes to this policy
We'll update the date at the top when this policy changes. For material changes (new categories of data collected, new third-party processors), we'll prompt you in-app on the next launch before the change takes effect.
10. Contact
- Email: hello@threeandapaw.com
- Data Protection inquiries (EEA): hello@threeandapaw.com
The data controller responsible for personal data processed by Taluvo is Shehan Fernando, an individual developer based in Linköping, Sweden, publishing under the indie label Three & a Paw. The data controller can be reached at the email addresses above.
This policy is written in plain language because we want it to be understandable. If anything is unclear, email us and we'll explain.