Legal

Privacy Policy

Effective date: August 27, 2026

Auf Deutsch lesen

This privacy policy explains how SideMissions processes personal data in the app, on the website at sidemissions.app, and when you contact us.

Controller and contact

The controller is Stefan Henrique Dos Santos Sousa (sole proprietor), Windeckstr. 46, 68163 Mannheim, Germany, trading as AventuraApps.

General contact: support@sidemissions.app. Privacy requests and data-subject rights: privacy@sidemissions.app.

Account, profile, and sign-in data

We process your email address, email-verification status, username, optional profile picture, internal user id, authentication provider and provider subject id, as well as the time and version of your Terms and Acceptable Use acceptance.

Firebase Authentication handles email/password sign-in. Where offered, Google or Apple first authenticates you and Firebase then provides the identity used by SideMissions. We do not receive your Google or Apple password.

Journey, content, and media data

We process journey names, occasion and settings, city-pack selections, participant names and roles, invite codes, challenges, assignments, proof descriptions, completion and phase information, City Discovery badges, and recap-video status and metadata.

Selected or captured profile pictures, journey pictures, proof photos and proof videos are uploaded only when you choose the relevant action. They may contain faces, voices, locations, names, or other personal information. Journey content is available to the host and members of that journey.

Content reports can contain the reported object, reason, optional note, reporter reference, status, and moderation decision. Removed media can remain in private storage while needed to review a report or protect users and legal claims.

Device, local storage, notifications, and logs

The app stores language, appearance, active-journey and participant references locally. The backend session token and install identifier use secure device storage where available; Firebase keeps its authentication state in app-local storage.

The app temporarily caches journey media and generated video thumbnails for performance. User-specific disk caches are cleared when you sign out or delete your account; public City Discovery artwork can remain available offline.

If you enable notifications, we store an Expo push token with platform and app language. Notification delivery processes the token, notification text, and a journey reference through Expo and the device platform service (Google FCM or Apple APNs).

The app and website process request time, path, status, IP-derived network data, request identifiers, and operational or security logs. Error reports can include app environment, error type, message, code, affected path, and a shortened technical stack trace. We do not intentionally include journey text or media in error reports.

Purchases

For Google Play purchases we process the product, entitlement and subscription status, expiry and acknowledgement information, an obfuscated account reference, and encrypted short-lived or hashed durable purchase-token references. Google processes payment and transaction data under its own terms; we do not receive your full payment-card details.

Purposes and legal bases

We process account, profile, journey, membership, challenge, media, recap, and entitlement data to provide the service you request (Article 6(1)(b) GDPR). Required data cannot be omitted if the corresponding account or feature is to work.

We process limited request, error, security, report, moderation, and audit data for our legitimate interests in secure and reliable operations, abuse prevention, troubleshooting, enforcing journey access, documenting operator actions, and defending legal claims (Article 6(1)(f) GDPR). We balance these interests against users' rights and limit access and retention.

Transactional push notifications are optional and are processed to deliver the notification feature you request (Article 6(1)(b) GDPR). You can disable them in device settings. Camera, microphone, photo-library, media-library, and notification permissions are operating-system controls; they do not by themselves replace the legal basis for the related processing.

Where law requires transaction or correspondence records, processing is based on the relevant legal obligation (Article 6(1)(c) GDPR).

Recipients, hosting, and international transfers

DigitalOcean, LLC (USA) hosts the backend, PostgreSQL database, and private live media in Frankfurt (FRA1), and encrypted database, media, and Firebase-authentication backups in Amsterdam (AMS3). Remote access outside the EEA is covered by DigitalOcean's EU-US Data Privacy Framework certification and, as a fallback, Standard Contractual Clauses.

Google Firebase Authentication provides account authentication; Google Sign-In can be used as an identity provider; Google Play Billing processes Android purchases; FCM delivers Android notifications. Transfers are covered by Google's applicable Data Processing Terms, Data Privacy Framework certification, and Standard Contractual Clauses.

Apple acts as an optional sign-in and APNs notification provider where those features are offered. Apple processes data under its applicable developer and privacy terms.

Expo (650 Industries, Inc., USA) routes push notifications and forwards them to FCM or APNs. Applicable transfers are covered by Expo's contractual Standard Contractual Clauses.

Proton AG (Switzerland) processes support and privacy emails sent to us. Switzerland has an EU adequacy decision.

You may request information about or a copy of applicable transfer safeguards from privacy@sidemissions.app. We do not sell personal data and do not use third-party advertising or advertising tracking.

Media and security

Production traffic uses HTTPS. Live media is stored in private object storage and is accessed with backend-issued short-lived upload and read URLs. The backend checks account, journey-membership, host, and media permissions. Administrative access is restricted and production backups are encrypted before leaving the production host.

Only upload or share media when you have the right to do so and the people shown can reasonably expect that use. No system is perfectly secure, so avoid content whose disclosure would create disproportionate harm.

Retention and deletion

Account and journey data is kept while the account or journey remains active. Hosts can delete journeys and participants can leave journeys. After 23 months without relevant account activity, we warn the account holder. After 24 months, we schedule account deletion unless the account has an active paid entitlement or a hosted journey has had relevant activity during that period. Relevant activity includes a successful sign-in or a meaningful account, journey, challenge, or media action.

An account-deletion request immediately blocks sign-in, revokes sessions, and removes push tokens. During the 30-day recovery period, you can withdraw the request by emailing privacy@sidemissions.app from the address linked to the account. After that period, a scheduled process permanently deletes the account, its Firebase identity, hosted journeys, memberships, authored or assigned content, and associated stored media.

Administrative security-audit events are kept for up to 24 months. When the target account is permanently deleted, its email and authentication identifiers are removed and its user id is replaced with an unrelated reference. A documented legal hold can extend retention only for a specific security incident, legal claim, or official proceeding.

Deleted live data can remain in encrypted backups for up to 35 days. Database backups, deleted-media recovery copies, and Firebase-authentication exports follow that same maximum backup window. After a restore, deletion requests must be reapplied before normal service resumes.

Server, website, security, and error logs are retained for up to 30 days. Backend sessions expire after 30 days and expired rows are regularly removed. Push tokens are removed on sign-out, account deletion, or an invalid-token response.

Open content reports and related moderation data are kept until the case is closed. Report and decision metadata is then kept for up to 12 months; reported media retained as evidence is removed within 90 days after closure. A documented legal hold can apply where the material is required for a specific legal claim or official proceeding.

Technical Google Play billing and entitlement events are kept while the entitlement is active and for up to 24 months afterward. Invoices, booking records, and other records that are legally relevant for tax or accounting purposes are kept for 8 years from the end of the calendar year in which they arose.

Your rights

Subject to the applicable conditions, you have rights to access, correction, deletion, restriction, objection, data portability, and withdrawal of consent without affecting earlier lawful processing. You may also complain to a data protection authority, including the State Commissioner for Data Protection and Freedom of Information Baden-Württemberg.

Send requests to privacy@sidemissions.app. We normally respond within one month; legally permitted extensions or identity verification can apply.

Children

You must be at least 16 to use SideMissions. We do not knowingly create accounts for younger children. Contact privacy@sidemissions.app if you believe a child below that age has used the service.

Automated decisions and changes

SideMissions does not make decisions with legal or similarly significant effects through automated processing. Current challenge suggestions are selected from curated templates, not generated from user data by an AI provider.

We update this policy before materially changing purposes, data categories, recipients, transfers, or retention, and show the current effective date in the app and on the website.