esadra EN IT ← Back to the page

Closed alpha

Terms & privacy

Alpha — v0.8 · August 2026

Esadra is in a closed alpha run by one person. This page says plainly what the app does with your data and what you agree to by using it — no boilerplate.

Privacy policy

Who runs Esadra

Esadra is run by its founder, who is the data controller during the alpha. For anything on this page — questions, access requests, deletion — write to esadraapp@gmail.com (the same mailbox as the Help center).

What we collect

Your account (email and name, handled through Firebase Authentication, our Google-run sign-in provider); your approximate home area as a neighbourhood-sized hex cell (~0.7 km²) — never your exact GPS position unless you explicitly pick Precise. What other people see is not that cell but a larger one containing it, the size of a district or a small town (~5.2 km²). While you're Free Now, that larger cell is visible to anyone within about 100 km of you, and only then; ending your slot stops sharing it. If you schedule availability for later, that cell becomes visible ahead of time to people searching that very window — but a search never looks past a short horizon of a few weeks, so a slot far out stays invisible until it draws closer. We also keep your availability slots and the vibes you choose; the messages, posts, and comments you write; the venues you tag; your connections — who you friend, block, and ping; and crash reports: when something breaks we receive a technical report with the error text and the page where it happened, which may be linked to your account if you're signed in. If you turn on push notifications, we also keep a technical identifier of your device — the notification token, with platform, app version, timezone, language, notification status and last contact — and the technical confirmation that a notification arrived.

Crossing paths

When crossing paths is on — and it is on by default — Esadra records that you and another Free Now person were in the same neighbourhood-sized cell (~0.7 km²) at the same time. It takes both of you: nothing is recorded unless the other person has it on too. A record is deleted 30 days after the last time you crossed paths — cross again and the clock starts over, so someone you pass every day stays in the list until you stop passing them. Only you see your own Nearby list. You can switch it off anytime in Settings → Privacy & safety: from that moment nothing new is recorded, and what is already there goes when it expires or when you delete your account.

What it's used for

To make the app work: discovery on Radar and Board, chat, suggestions, fixing what breaks and — if you turn them on — the notifications that tell you when someone reaches out: a ping, a message, an invite. That's it. No ads, no data sales, no profiling beyond the features you can see.

The legal bases

The GDPR asks us to name the legal basis for each kind of processing, so here they are. Everything needed to make the app work — your account, availability, approximate area, chat, Radar, and Board — rests on the contract between you and us: these are the features you signed up for (Art. 6(1)(b) GDPR). Two things happen only with your consent, which you can withdraw at any time from the settings: Precise location and push notifications (Art. 6(1)(a)). Crossing paths is different and we would rather say so than dress it up: it is on by default, and a pre-enabled setting is not the clear affirmative act consent requires, so it rests on our legitimate interest in making a discovery app work (Art. 6(1)(f)) — with the same switch to object, at any time, and the safeguard that it needs both people to have it on. Error reports rest on the same legitimate interest in fixing what breaks (Art. 6(1)(f)).

Services we rely on

Sign-in goes through Firebase Authentication, a Google service, so your email and name — and, if you sign in with Google, your Google profile name and picture — pass through Google's systems. Place search uses Photon, a public OpenStreetMap-based service — in this phase, the coordinates of your place searches are sent to that public service. Push notifications, if you enable them, go through Google's Firebase Cloud Messaging: its service receives your device token and a technical wake-up signal — never content, never names, never your location.

Transfers outside the EU

Firebase Authentication, our sign-in provider, is a Google service: your email and name may therefore be processed in the United States. The same goes for push notifications, if you enable them: the notification token and delivery timing pass through Google's systems. Both transfers are covered by a data processing agreement (DPA) with the European Commission's standard contractual clauses and by Google's certification under the EU-U.S. Data Privacy Framework. Everything else never leaves the European Union.

Where your data lives

On a server in the European Union: an Aruba VPS in Italy, run directly by us. The database, cache, real-time messaging, and even the maps run there, self-hosted. No US analytics service, no ad network — the only exceptions are the services listed above.

Cookies and local storage

Esadra keeps your sign-in session in your browser's local storage (through Firebase Authentication), not in tracking cookies. Preferences like theme and language are stored on your device and never leave it. No advertising cookies, no analytics cookies — which is why there is no banner to click through.

How long we keep it

While your account is active, your data stays: it's what makes the app work, nothing more. Crossing-paths records are the exception — each one is deleted 30 days after the last time you crossed that person. When you want to leave, everything happens in the app: Settings → Account → Delete account. Your profile is deactivated right away and you disappear from Esadra; you then have 30 days to change your mind — sign back in and choose Undo deletion. When the window ends, an automated process permanently erases everything private to you — your profile, availability, saved places, friendships, pings, crossing-paths records, notifications and device tokens — and your sign-in account at Firebase. What you left in shared places stays where it is, but without your name: your messages in other people's conversations, your posts and comments on the Board, and the huddles and events you created all show as "deleted user". One thing survives on purpose: a copy of your sign-in identifier, kept so that a leftover access token can never bring a deleted account back to life. It carries no name, no email and no location, but it has a practical consequence worth knowing before you press the button — the same Google or email account cannot sign up for Esadra again. A different one can. The notification token stays for as long as you keep push on: turning it off, or deleting your account, removes it from our systems too; the technical delivery confirmations delete themselves after 30 days.

Your rights

Under the GDPR you can ask at any time to access, correct, delete, or export your data, to restrict how it is processed, or to object to processing based on legitimate interest. One email to the contact mailbox is enough — no forms, no hoops.

The right to complain

If you think your data is being handled improperly, write to us first: almost everything can be sorted out with an email. You always keep the right, though, to lodge a complaint with the Italian supervisory authority — the Garante per la protezione dei dati personali (www.garanteprivacy.it) — or with the authority of the EU country where you live.

Events: what the venue sees when you say you're going

When you tap "I'm going" on an event, whoever runs that venue sees your name and your profile picture in the attendee list — for that one event, and only because you tapped the button. They see nothing else about you: not your email, not your area, not your availability, not the other events you're going to. Everyone else in the app sees only how many people are going; your name is visible to your friends alone. If you've blocked the person running the venue, or they've blocked you, your name doesn't appear in their list (you stay in the count only). The gesture itself is the consent: untap "I'm going" and you leave the list straight away. How long it lasts: your attendance at an event that took place stays like any other content of yours — the venue keeps seeing it in the history of their console for as long as your account exists, and it goes when you delete your account. If the event is cancelled instead, your attendance deletes itself when the event's window ends.

Changes

If this policy changes, the new version appears here with a new version number and date.

Terms of service

This is an alpha

Esadra is a test service. Things will break, features will change, and there is no guarantee of availability or support. It's offered as-is, free of charge, so you can try it and tell us what you think.

Your data may be wiped

Between alpha phases the database may be reset. That means your profile, messages, posts, and history can disappear entirely. Don't keep anything in Esadra you can't afford to lose.

Be kind

No harassment, no threats, no illegal content. Esadra is built for quiet, low-pressure meetups — content or behavior that breaks that gets removed, and the account banned. To report a piece of content or a person, write to esadraapp@gmail.com: every report gets a reply, normally within 72 hours.

Age

The alpha is for adults: you must be at least 18 to use it. An age attestation step will be added in the beta; by using the alpha you confirm you are 18 or older.

Liability

To the extent permitted by law, liability for damages arising from the use of this test service is excluded. Meetups happen between real people in the real world — use the same judgment you would anywhere else.

Changes to these terms

If these terms change, the new version appears here with a new version number and date.

This text will be reviewed by a lawyer before the public beta.