Legal
Privacy Policy
Effective date: June 8, 2026
This privacy policy explains how SideMissions handles personal data when people create, join, and play private challenge journeys.
Controller and contact
The controller responsible for personal data in SideMissions is Stefan Sousa (sole proprietor), Windeckstr. 48, 68163 Mannheim, Germany.
General contact: support@sidemissions.app. Privacy requests and data-subject rights: privacy@sidemissions.app. We aim to respond to privacy requests within one month.
Data we process
SideMissions processes the name or alias you enter, journey names and settings, participant lists, invite codes, challenge text, proof descriptions, uploaded or selected proof media, journey pictures, progress, phase status, language and appearance settings, device session identifiers, install identifiers, request metadata, and operational logs.
The app does not require precise location data. If you include locations, faces, names, or other personal information in journey text, pictures, videos, or proof descriptions, that content may become personal data shared with the journey members.
Why we use data
We use data to create and manage journeys, let invited members join, show challenges and recap material to journey members, protect host and participant permissions, operate the backend, prevent misuse, debug problems, and improve reliability.
SideMissions does not sell personal data and does not use third-party advertising tracking.
Legal basis
Where GDPR applies, the main legal bases are performance of a contract or requested service for the core app flow, legitimate interests for security, fraud prevention, operations, and service improvement, and consent or device permission where you choose to access photos, videos, camera, or notifications.
Sharing and hosting
Journey content is shared with the host and members of the same journey. We do not sell personal data and do not use third-party advertising tracking.
We use the following service providers (processors) to operate SideMissions, each only to provide its service:
DigitalOcean — backend hosting and private media storage, stored in the Frankfurt, Germany region (FRA1). DigitalOcean is a US company; any access from outside the EU/EEA is governed by Standard Contractual Clauses.
Google Firebase Authentication (Google) — account sign-in and identity. Processing may occur on Google infrastructure outside the EU/EEA; such transfers are covered by Standard Contractual Clauses and the EU-US Data Privacy Framework.
Google Play Billing (Google) — in-app purchases and Premium entitlement status. The same transfer safeguards apply.
Proton Mail (Proton AG, Switzerland) — email you send to our support or privacy addresses. Switzerland is recognised by the EU as providing an adequate level of data protection.
Media
Pictures and videos can contain sensitive information about you or other people. Upload or share media only when you have the right to do so and when the people shown are comfortable with that use.
Production media uses private storage with backend-issued short-lived upload and read URLs. Development builds may use local signed storage for emulator testing.
Retention and deletion
You can delete your account and journeys at any time. Hosts can delete journeys, and participants can leave journeys from the app. We keep your account and journey data while your account is active and do not automatically delete inactive accounts.
When you delete an account or journey, we remove it (and its proof media and journey pictures) from our live systems within 30 days. Residual copies in encrypted backups are overwritten on the normal backup rotation, which keeps backups for 14 days.
Server and security logs, including IP-derived request metadata, are kept for up to 30 days and then deleted. Session tokens expire after 30 days, and expired sessions are removed.
Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to processing, receive a portable copy of your data, withdraw consent where processing is based on consent, and lodge a complaint with a data protection authority.
Requests will be handled through the configured privacy contact. GDPR requests should generally receive a response within one month.
Security
Production traffic should use HTTPS. The backend enforces membership and host permissions, media uploads use signed URLs, and the app stores session material using device secure storage where available.
No system is perfectly secure. Please avoid uploading content that would create serious harm if seen by the wrong person until retention controls, monitoring, and incident-response procedures are complete.
Children
You must be at least 16 to use SideMissions. The app is not directed at children under 16, and we do not knowingly process their personal data. If you believe a child under 16 has used the app, contact privacy@sidemissions.app and we will delete the account. Parents or guardians should supervise any use by minors.
Automated decisions and AI
SideMissions does not make legally significant automated decisions about users. Current challenge suggestions are template-based. If AI suggestions are added later, the privacy policy and product documentation must explain the provider, data use, and safeguards.
Changes
We may update this policy when the product, backend, hosting, media storage, notifications, or legal requirements change. The app should show the latest effective date.