Privacy Policy
Version: 2026-07-20 · Date: 20 July 2026
Ripple is a hyperlocal news app: users post reports tied to a place and the nearby community confirms or disputes them. This policy describes what personal data we process, why, for how long and what rights you have.
1. Controller
The controller is Alessio Danna, whose contact address is Carrer Mas 40, 08903 L'Hospitalet de Llobregat (Barcelona), Spain.
To exercise your rights or for any question about this policy you can write to alessio.danna.94@gmail.com.
2. What data we process
2.1 Account data
- Email: used only for authentication (sign-up and sign-in with a password, plus a one-time confirmation code by email). It is never shown to other users.
- Password: stored in encrypted form (hashed), never in plain text; it is never accessible to staff nor displayed on any screen. If you choose to sign in with Apple, Google or Facebook, no password is set: authentication is handled by the provider you choose.
- Nickname: the public name under which you appear in the app. You choose it when you sign up (format: letters, numbers, dot, hyphen or underscore, from 3 to 40 characters) and it cannot be changed from the app afterwards; to have it corrected, see section 7 "Rectification".
- Preferred language and notification preferences (radius, categories, quiet hours).
- Any internal administrative role, if applicable to your account.
2.2 Location data
Location is processed for five distinct purposes. We never keep a history of your movements.
- News point: when you post a news item, its location is public. Before posting you can manually move the point by up to about 200 meters from the detected position.
- Location at the time of the vote: when you confirm or dispute a news item, your location is used to verify that you are within the radius within which a vote is valid. It is stored together with the vote and is not visible to other users.
- Last known location: used to decide whom to notify about nearby news. It is stored at reduced granularity (about 110 meters) and is overwritten at every update: there is always a single value, never a historical series.
- Last geolocated action: the location and time of the last action (for example a post), used to check the plausibility of movements for anti-abuse purposes. This data is also overwritten at every action and does not feed any history.
- Saved places: the addresses you choose to save as points of interest, with the name, the radius and the notification preference you assign to each of them. The coordinates are stored on our servers at reduced granularity (rounded to about 110 meters) and are used to center the feed on the chosen place and, if you have enabled notifications for that place, to send you alerts about nearby news. When you search for an address to save, the text of the search is forwarded to the Nominatim geocoding service of the OpenStreetMap Foundation (see section 4); the text of the search and the results are kept in a cache on our servers for 30 days. You can delete each place at any time from the app; all saved places are deleted together with the account.
2.3 Content
The news items you post (title, text, category, tags, photo if any), the comments, the votes, the reports you send and the list of users you have blocked.
2.4 Push notifications
Your device's push token (generated through the Expo service) and your notification preferences.
2.5 Consents
The record of the consents you have given (age declaration, acceptance of this policy), with version and date.
2.6 Account suspension status
Account suspension status (the outcome of moderation measures), kept for as long as the account exists. Legal basis: legitimate interests (community safety, art. 6(1)(f) GDPR).
2.7 Reputation events
Reputation events: a dated record of the events that change your score (news items verified/disputed, matching votes), kept for the life of the account.
2.8 Technical moderation and security data
- Moderation log: the outcome of the automated checks on content (verdict and any categories detected).
- Device attestation log (Android only): the outcome of the Android device integrity check via Google Play Integrity (for example "verified" or "failed"). We record only the outcomes, never the attestation tokens. On iOS devices no attestation is performed and no data of this kind is collected.
- Record of administrators' moderation actions (for example suspension/reactivation of an account): kept for audit purposes and survives the deletion of the account concerned.
3. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|
| Providing the service: account, posting, feed, votes, comments | Account, location, content, consents | Performance of a contract (art. 6(1)(b) GDPR) |
| Automated content moderation and abuse prevention | Content, last geolocated action, moderation log, reports | Legitimate interests: community safety (art. 6(1)(f) GDPR) |
| Push notifications about nearby news | Push token, last known location, saved places with notifications enabled, preferences | Consent, through the system permission and the in-app preferences (art. 6(1)(a) GDPR) |
| Feed centered on a saved place and address search | Saved places, search text | Performance of a contract (art. 6(1)(b) GDPR) |
| Android device attestation (anti-fraud; in beta, monitoring only, no blocking) | Attestation log | Legitimate interests: fraud prevention (art. 6(1)(f) GDPR) |
4. Recipients and processors
We rely on the following providers, which process data on our behalf:
- Supabase: database, storage and authentication hosting. The data is hosted in the European Union (Frankfurt region).
- OpenAI: automated content moderation. It receives the text and any photo of news items and the text of comments, for the sole purpose of assessing them.
- Expo: delivery of push notifications.
- Google (Play Integrity): device integrity verification, on Android devices only. We receive and keep only the outcomes of the verification.
- OpenStreetMap Foundation (Nominatim): address search when you save a point of interest. Our server forwards to it only the text of the search and the app language, never your identity or your location; the text of the search and the results are kept in a cache on our servers for 30 days.
5. Transfers outside the EU
The app's data resides in the European Union (Supabase, Frankfurt). Some providers — OpenAI for moderation, Expo for push notifications, Google for Android device attestation — may process data in the United States; these transfers are covered by appropriate contractual safeguards, including the European Commission's standard contractual clauses. The OpenStreetMap Foundation, which processes address searches, is based in the United Kingdom, a country covered by an adequacy decision of the European Commission.
6. Data retention
| Data | Retention |
|---|
| News items | They leave the feed after about 90 minutes of inactivity, but remain stored in the app's history |
| Last known location, last geolocated action | Overwritten at every update; never kept as a history |
| Technical queues (push delivery, moderation, internal events) | 7 days |
| Read notifications | 90 days |
| Device attestation log (Android only) | 90 days |
| Moderation log | 180 days; verdicts awaiting review by the administrators remain until they are reviewed |
| Reports | Indefinitely, as an anti-abuse record |
| Technical counters for rate limits (votes, exports) | About 2 hours |
| Saved places | Until you delete them from the app, and at most for the lifetime of the account |
| Address search cache (geocoding) | 30 days |
| Account, content, consents, push tokens, reputation events, suspension status | For the lifetime of the account (see section 7 for deletion) |
7. Your rights
- Access and portability: from Settings → Privacy section → Download your data you obtain a JSON file with all your data (profile, consents, news items, comments, votes, reports, blocks, notifications, saved places, reputation events, push tokens, record of device attestation checks). The export is available once per hour.
- Erasure: from Settings → Privacy section → Delete account. The content you have posted (news items, comments) and the reports remain visible in anonymous form, attributed to the nickname "utente-eliminato" (deleted user); photos are deleted together with the account. Everything else — profile, email, location, saved places, votes, notifications, push tokens, consents — is deleted. References to your nickname in alerts already delivered to other users are anonymized upon deletion.
- Rectification: the nickname is chosen when you sign up and cannot be changed from the app. To request its correction, write to the controller at the contact details given in section 1.
- Other rights (objection, restriction, etc.): contact the controller at the contact details given in section 1.
- Complaint: you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement (art. 77 GDPR). The controller is established in Spain, so its lead supervisory authority is the Agencia Española de Protección de Datos (www.aepd.es).
8. Minimum age
Ripple is reserved for people who are at least 16 years old. On first launch the app asks for an explicit age declaration, together with acceptance of this policy.
9. Changes to this policy
Each version of this policy is identified by a version date (at the top of the document). If it changes, the app asks you to accept the new version before you can continue using the service.
What changed in version 2026-07-20 (compared to 2026-07-06): the "saved places" feature has been introduced. We therefore also process the places you choose to save (name, location rounded to about 110 meters, radius and notification preference) and the address searches you carry out, which are forwarded to the OpenStreetMap Foundation (Nominatim service) and kept in a cache on our servers for 30 days. The details are in sections 2, 4, 5, 6 and 7.