Privacy

Fradar Privacy Policy

Last updated: 14 July 2026

Fradar helps people find each other during temporary events, festivals, beaches, venues, and similar shared contexts. Fradar is designed around short-lived groups: location and proximity data are used only while a radar is active and are automatically removed shortly after it expires or is revoked.

Who Controls Your Data

The data controller for Fradar is Niccolò Busetti (applicazi.one), Castello 3593, 30122 Venice, Italy. For privacy questions or rights requests, contact privacy@applicazi.one.

Data We Collect

Fradar may collect a temporary display name or nickname, color choice, group membership, invite-token metadata, meeting-point/RSVP data, visual-beacon state, and precise or approximate location, accuracy, heading, and speed while you actively share in a radar.

To improve proximity accuracy while a radar is active, Fradar may also process barometric pressure and relative altitude, and short-range cooperative signals exchanged between nearby members over Bluetooth Low Energy and Ultra Wideband, including estimated distance, relative angle, signal strength, and temporary precision tokens.

When notifications are enabled, Fradar stores APNs device and Live Activity tokens on iOS. On Android it stores a Firebase Installation ID (FID) for push delivery; an older FCM registration token may remain temporarily for previously installed builds.

Fradar uses Supabase Auth identifiers, including anonymous user IDs. If you link Apple or Google sign-in, the authentication provider and Supabase may process your verified account email and provider identifier. If you later delete that linked account, Fradar may retain a keyed HMAC proof of the provider identity for protected purchase reconciliation; that recovery record does not contain the raw provider subject or email.

If you make an in-app purchase, Fradar receives purchase-history information from Apple or Google, including the selected 1,000, 5,000, or 10,000-credit package, store, status, transaction or order identifiers, credited and spent units, refund/reversal state, and a protected purchase-token reference. Subscription expiry is processed only for historical annual products kept for recovery, not as a new checkout offer. Fradar does not receive or store your card number, bank account, or store password. Where store lifecycle notifications are configured, Fradar also processes signed Apple notifications and authenticated Google Play Real-time Developer Notifications. Google Play notification audit records retain the Pub/Sub message ID, event type, purchase-token hash, and minimal processing outcome, but not the raw purchase, refund, or OIDC token.

Referral participation may associate your referral code, referring account, referred account, reward status, and qualifying purchase. Fradar does not collect contacts, photos, health data, advertising identifiers, browsing history, or search history. Camera frames used to scan invite QR codes are processed on the device and are not uploaded or retained by Fradar.

How We Use Data

We use data to create and join temporary radars, show participant position, distance, direction, and meeting-point information to members of the same radar, synchronize state, deliver notifications, verify the three consumable credit packages, spend credits when a radar is created or its capacity increases, recover eligible historical rights, prevent fraud and abuse, provide support, and comply with legal obligations.

We do not sell personal data, serve behavioral advertising, or use Fradar data to track users across apps or websites.

Location and Nearby Sharing

When you join a radar, other active invited members can see your display name, color, latest shared location, location accuracy, and presence/freshness state. Cooperative proximity and vertical hints may improve distance or direction estimates but are not guaranteed indoor positioning.

On Android, a user-started location foreground service may continue sharing while the app is minimized or the device is locked. Android displays an ongoing notification with a Stop sharing action. On iOS, active-radar sharing may continue in the background when the user has granted the required system permission. Leaving, stopping, group expiry or revocation, or removal ends the active sharing session.

Invite links should be shared only with people you want to admit to the radar. A web guest who joins an invite uses a temporary anonymous session and browser location permission.

Retention

Native-app radars last no more than 7 hours and web guest sessions no more than 3 hours. Expired or revoked radars and related location, ranging, membership, meeting, and beacon data are deleted after a 15-minute reliability grace by a five-minute cleanup job, normally within about 20 minutes.

Authentication records remain while your account is active. APNs tokens and Firebase Installation IDs, including transitional legacy FCM registration tokens, remain until replaced, invalidated, or the account is deleted. Purchase, entitlement, immutable credit-ledger, refund/dispute, referral, fraud-prevention, keyed identity-recovery, and support records may be retained or restricted for the minimum period needed to honor purchases, prevent repeated abuse, and meet accounting or legal obligations.

Account and Data Deletion

The authenticated in-app deletion operation revokes active radars you created, removes your memberships and active location/proximity data through radar lifecycle cleanup, removes push identifiers and your referral code, rejects pending referral rewards, sets the remaining in-app credit balance to zero with an immutable ledger record, and deletes the Supabase Auth user. Only minimum restricted purchase, legal, fraud-prevention, and keyed recovery records may remain where needed for the purposes described above.

Deletion does not delete your Apple or Google account and does not itself cancel a historical store subscription, if one exists. Manage or cancel that legacy subscription through the applicable Apple or Google account. Store refunds and applicable legal rights remain governed by the store and law. Use the in-app Delete Account command or follow the account deletion instructions.

Security

Fradar uses encrypted transport, Supabase Auth, row-level security, JWT-protected Edge Functions, server-side validation, rate limits, and automatic cleanup. Sessions and credentials are stored using platform-protected storage in the native apps. No system is perfectly secure, so share invite links only with people you trust.

Service Providers

Fradar relies on Supabase for authentication, database, realtime synchronization, and Edge Functions; Vercel for the guest and legal website; Apple for Sign in with Apple, StoreKit, App Store Server Notifications, APNs, and Live Activities; and Google for Google identity, Play Billing, Android Publisher API, and Firebase Cloud Messaging. These providers process data under their own contractual and privacy terms.

Your Choices

Children

Fradar is not directed to children below the minimum digital-consent age in their country. Do not create an account or share a child's location without the authorization required by local law.

International Processing and Your Rights

Service providers may process data outside your country using legally recognized safeguards. Depending on where you live, you may request access, correction, deletion, restriction, portability, or objection, and may complain to your local data-protection authority.

Changes

We may update this policy when the product, providers, or legal requirements change. The revision date above identifies the current version. Material changes will be communicated in the app or on this page when appropriate.

Contact

For privacy requests, contact privacy@applicazi.one, or write to Niccolò Busetti (applicazi.one), Castello 3593, 30122 Venice, Italy.

Terms of Use · Fradar home