Privacy Policy
Last updated: 13 August 2026
Fenzly is built on a simple promise: the people you share your location with should be the only ones who can see it. This policy explains what little data we process, what we deliberately cannot see, and the rights you have.
1. Who is responsible
The data controller for Fenzly is Logil Sàrl (“we”, “us”), [registered address], Switzerland (company no. CHE-435.741.642).
For any privacy question, contact us at privacy@fenzly.app.
2. Our core principle: end-to-end encryption and a “blind” server
Fenzly encrypts your locations, places, and messages on your device using the Signal protocol, individually for each recipient. Our servers only ever relay opaque encrypted data. As a result, we cannot read:
- your GPS coordinates or movements;
- the names, coordinates, or radius of your places (“zones”);
- the content of your messages;
- who is in your circles, or your address book.
This is by design, not by policy: even if compelled, we cannot produce data we are not technically able to read.
3. Data we process
Account data. To create an account you provide either an email address or a phone number (one is sufficient). Fenzly does not use passwords: every sign-in is verified with a one-time code sent by email or SMS — so there is no password for us to store, and none to lose. We also store a display name and your language preference (used to localize the emails and SMS we send you). Phone numbers are stored in international format and verified by a one-time code. For optional contact discovery, we store one-way SHA-256 hashes of email/phone numbers — never the values in clear.
Device data. A push notification token (Firebase Cloud Messaging) and basic device information, used solely to deliver notifications. If you enable arrival/departure notifications for a shared place, we additionally store a coarse notification preference (which place, and whether you want arrivals or departures) so we can wake your device — never which member you follow; that filter stays on your device.
Cryptographic material. Your public Signal keys (identity key, signed pre-keys, one-time pre-keys), needed so others can start an encrypted session with you. These are public by design and reveal nothing about your activity.
Encrypted content we relay (but cannot read). Encrypted location updates, place definitions, zone-crossing events, and messages transit our servers temporarily (e.g. via short-lived queues) so they can be delivered when a recipient comes online. They are stored encrypted and expire automatically (see Retention). Profile pictures (for users, groups, and places) are stored as opaque encrypted blobs: the decryption key travels end-to-end encrypted between your devices and your contacts, so we cannot view the images.
Backups. If you enable backups, your data is encrypted on your device. In automatic mode we use a split-key scheme: we hold only a random key share and an encrypted blob, and your cloud (Google Drive or Apple iCloud) holds the other share — neither part alone can decrypt anything.
Licensing data. If you subscribe to a plan, we keep minimal receipts: the plan, its status and validity period, and whom you assigned licenses to (technical identifiers). For a child account we keep a parental-consent receipt (guardian and child identifiers, method, date) — the legal proof of consent, nothing more.
SOS alerts. So that an SOS alert keeps ringing until someone takes charge, the server holds, for the duration of the alert (30 minutes at most), minimal metadata: emitter and recipient identifiers and timestamps — never the location, which travels end-to-end encrypted.
Diagnostic data. Crash reports and technical logs (via Firebase Crashlytics) to detect and fix bugs. These do not contain your location or message content.
4. Data we do not have
We never receive your address book, your social graph, your coordinates, or your place names — these stay on your device or are encrypted end-to-end.
5. Legal bases
Where the GDPR applies, we rely on: performance of a contract (Art. 6(1)(b)) to provide the service; your consent (Art. 6(1)(a)) for optional features such as contact discovery or phone-based discoverability; and our legitimate interests (Art. 6(1)(f)) in keeping the service secure and functioning. Where Swiss law applies, processing is carried out in accordance with the Federal Act on Data Protection (FADP/nLPD).
6. Service providers (sub-processors)
We rely on a small number of providers, chosen with privacy in mind:
- Infomaniak (Switzerland) — hosting of our servers, databases, and encrypted media storage, and outbound email. Data hosted in Switzerland.
- ASPSMS (Switzerland) — sending SMS one-time codes, if you sign in or verify a number by phone. For certain destination countries we use Twilio instead.
- Google Firebase (Cloud Messaging and Crashlytics) — push notifications and crash reporting.
- MapTiler — map tiles and address search. Address searches are proxied through our servers, so your IP address and search query are not exposed to MapTiler.
- Google Drive / Apple iCloud — only if you enable backups; your encrypted backup is stored in your own cloud account.
7. International transfers
Our core infrastructure is hosted in Switzerland. Some providers (e.g. Google Firebase) may process limited data outside Switzerland/the EU; such transfers are governed by appropriate safeguards (e.g. EU Standard Contractual Clauses).
8. Retention
- Encrypted messages queued for offline delivery: up to 30 days, then deleted automatically. Encrypted zone-crossing events and delivery/read receipts: up to 7 days.
- Encrypted location updates: kept only for the duration of the share, then expire.
- Address-search queries proxied for you: cached (server-side, not tied to your account) for 7 days.
- Encrypted profile pictures: kept until you replace or remove them, or delete your account.
- Backups: the most recent versions are retained; older versions are pruned automatically.
- Account data: kept until you delete your account — deletion is immediate and permanent. We then keep, for 12 months, a minimal deletion record (technical identifier + date, nothing else): it lets your devices detect the deletion and clean themselves, and is then purged in turn.
9. Your rights
You have the right to access, rectify, delete, restrict, or object to the processing of your personal data, and to data portability. These rights are exercised directly in the app, with no human in the loop and immediate effect:
- Export your data (Settings → Personal data → Download my data): a readable copy of your local data (profile, places, trips, history, settings — your data only, never your circle members’) plus the server side, near-empty by design — the demonstration of our architecture.
- Delete your account (Settings → Personal data): deletion is verified with a one-time code and immediately, permanently erases your data from our servers and from your device; your other devices clean themselves the next time Fenzly opens. You can also delete your account without the app, at fenzly.app/delete-account. Deleting a child account requires a guardian’s approval (the code goes to their verified channel).
Note: data you already shared with your contacts (e.g. your past positions in their app) lives on their devices, beyond our reach — inherent to end-to-end encryption, like a message already delivered. You may withdraw consent for optional features at any time. You also have the right to lodge a complaint with a supervisory authority — in Switzerland, the [Federal Data Protection and Information Commissioner (FDPIC)]; in the EU, your national data protection authority.
To exercise your rights, contact privacy@fenzly.app.
10. Security
We protect your data with end-to-end encryption (Signal protocol), device-bound key storage (Keychain/Keystore), TLS in transit, and Swiss hosting. No system is perfectly secure, but our architecture is designed so that the most sensitive data is never readable by us in the first place. Our encryption is implemented with a pure-Dart port of the Signal protocol; it has not undergone an independent third-party cryptographic audit, and we describe it accurately rather than claiming certifications we do not hold.
11. Children
Fenzly is not directed to children under 13 outside the family mode. Where required by law — under the GDPR for users below the age of digital consent in their country (which varies between 13 and 16), and under the U.S. COPPA for children under 13 — processing a minor’s personal data requires verifiable parental consent. Fenzly provides a guardian-managed family mode: a member can only be designated as a child after verifiable parental consent (a code sent by SMS to the guardian’s verified number), of which we keep a minimal receipt (identifiers, method, date). Guardians can review and withdraw this consent at any time in the app, and deleting a child account requires their approval. If you believe a child has provided us personal data without the required consent, contact us at privacy@fenzly.app and we will delete it.
12. Changes to this policy
We may update this policy from time to time. Material changes will be announced in the app or by email. The “last updated” date above always reflects the current version.
13. Contact
Logil Sàrl — Switzerland — privacy@fenzly.app