Official Legal DocumentTerms & Conditions
Privacy Policy & Zero-Trust Framework

Privacy Policy

Last updated: 20 August 2026

Compliant with GDPR (EU 2016/679), CCPA & Google API Services User Data Policy

Our Core Privacy Commitments (Summary)

  • ✓Zero-Trust: no public textual profiles or free-form reviews.
  • ✓Spatial Cloaking: your precise location is never made public.
  • ✓TTL Policy: expired events and chat logs are auto-deleted.
  • ✓No data selling and no usage for AI/ML training models.

1Data Controller & Contact Information

The Data Controller for personal data processed through the Halo application and platform ("Halo", "we", "us", "our") is Halo App. For any questions regarding the processing of your personal data or to exercise your rights under the General Data Protection Regulation (GDPR - EU Regulation 2016/679) and applicable privacy laws, you may contact our Data Protection Officer (DPO) at:

Email DPO & Privacy: privacy@joinhalo.it

2Zero-Trust Philosophy & Privacy by Design

Halo is designed specifically for solo travelers around the Zero-Trust paradigm. Unlike conventional social networks, we have removed the root causes of social anxiety and invasive tracking: there are no public feeds, open indexed profiles, follower counts, or free-text review systems prone to retaliation or abuse. We process only the minimum technical data necessary to enable safe spontaneous meetups and safeguard the community from malicious or fraudulent behavior.

3Categories of Data Collected & Purposes

We process only the following categories of data strictly for purposes related to providing the service:

a. Authentication and Profile Data (Google Sign-In / OAuth)

Unique user identifier (UID), email address, display name, and profile picture URL provided via secure Google OAuth. This data is processed to create your account, prevent impersonation, and allow confirmed event members to identify each other.

b. Geolocation and Position Data (GPS)

Real-time location retrieved from your device ONLY and EXCLUSIVELY in the foreground (while the app is open and actively in use), subject to your explicit consent. We perform no background location tracking. Location is used solely to discover and create nearby meetups.

c. Event Content and Internal Communications

Event title, activity category, scheduled meet time, optional destination link (screened via Google Web Risk API to prevent malware/phishing), introduction message for join requests, and ephemeral chat messages exchanged within the approved event room.

d. Reputation and Trust Engine Data (MMR)

Confidential binary feedback signals (positive, no-show/ghost, flag) submitted asynchronously by verified participants after an event concludes, reliability multipliers, and interaction ledgers used to prevent vote manipulation and fake accounts (Anti-Sybil mechanism).

e. Diagnostic Telemetry, Error Logs and Technical Cookies

Pseudonymized crash reports and error monitoring (Sentry), performance telemetry (Firebase Performance), and anonymized usage analytics (Google Analytics for Firebase, activated only upon prior user consent via cookie banner).

4Legal Bases for Processing (GDPR Art. 6)

  • Performance of a Contract (Art. 6.1.b GDPR): Processing profile data, event creation, join requests, and chat messaging is necessary to deliver the services requested pursuant to our Terms and Conditions.
  • User Consent (Art. 6.1.a GDPR): Access to real-time device GPS coordinates and the activation of non-essential analytical cookies occur strictly upon your explicit consent, withdrawable at any time.
  • Legitimate Interests (Art. 6.1.f GDPR): Trust Score calculations (MMR), abuse prevention, Sybil attack mitigation, and malicious link screening serve our legitimate interest in maintaining a safe and dependable environment for solo travelers.
  • Compliance with Legal Obligations (Art. 6.1.c GDPR): To comply with applicable legal obligations or mandatory requests from judicial or public safety authorities.

5Spatial & Temporal Cloaking: How We Protect Your Location

Halo implements strict geospatial and algorithmic obfuscation mechanisms by design:

Spatial Cloaking (Location)

In public map discovery, event markers never expose exact GPS coordinates. The system encodes location into a 5-character Geohash (coarse area of ~±2.4 km) with randomized jitter. Exact coordinates reside in an isolated subcollection accessible ONLY to the host and approved participants.

Temporal Cloaking (Timing)

Unapproved users see only an approximate time window (e.g., "This afternoon", "Tonight"). The exact meeting timestamp (meetAt) remains encrypted/restricted and is revealed only after the host explicitly accepts the join request.

6Trust Engine, MMR Scoring & Automated Decision-Making (GDPR Art. 22)

Halo utilizes a deterministic reputation algorithm (Trust Gravity) to safeguard community members:

• Calculation Logic: Following each event, confirmed attendees may submit a confidential signal (positive, no-show/ghost, or conduct flag). The impact is weighted by the voter's trust tier and filtered through Anti-Sybil rules (repeated positive trades between identical pairs yield zero artificial score boost).

• Effects and Measures: The algorithm determines trust badge states ("Reliable", "Calibration phase", or "Suspended"). Accounts falling below safety thresholds due to chronic ghosting or misconduct flags are placed into automated Shadow Ban (events become invisible to others and join requests are suppressed).

• Right to Contest & Human Review: Under GDPR Art. 22, you have the right to request human review, state your viewpoint, and contest automated trust sanctions or restrictions by contacting privacy@joinhalo.it.

7Data Retention and TTL (Time-To-Live) Policies

We enforce strict automatic data pruning using Cloud Firestore Time-To-Live (TTL) indices:

  • Events, Chat Messages & Exact Coordinates: Permanently and automatically purged from our servers 2 hours after scheduled meeting time (meetAt + 2 hours). We do not store persistent logs of your past movements or historical chat transcripts.
  • Reputation and Account Credentials: Core profile credentials and aggregated trust score metrics are retained until you delete your account to preserve ongoing community safety.

8Account Deletion and Right to Erasure (GDPR Art. 17)

You may exercise your right to erasure (right to be forgotten) and permanently delete your account at any time. Account deletion can be triggered instantly from the profile settings inside the app or by emailing privacy@joinhalo.it. This permanently purges your user document from Firestore and your authentication record from Firebase Auth.

9Google API Services User Data Policy & Limited Use Disclosure

Halo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • We never sell, lease, or monetize user data obtained through Google OAuth.
  • We do not use Google account data for targeted advertising, retargeting, or third-party marketing.
  • We do not use or transfer user data to train, fine-tune, or improve generalized or personalized AI/ML models.
  • Human access to user data is prohibited except upon explicit user consent for technical troubleshooting or under legal mandate.

10Cookies, Third-Party Infrastructure & Security

We use only strictly necessary technical storage (session auth tokens, language preferences) and aggregated analytical cookies (Google Analytics for Firebase) with anonymized IP collection, active solely upon user consent via our Cookie Banner. Data is secured via end-to-end transport encryption (HTTPS/TLS 1.3) and encryption at rest (AES-256) hosted on Google Cloud / Firebase infrastructure.

11International Data Transfers (GDPR Art. 44+)

Our primary database and server infrastructure are hosted within the European Union (Google Cloud region europe-west1). Whenever auxiliary technical transfers occur outside the European Economic Area (EEA), they are safeguarded under the EU-U.S. Data Privacy Framework and European Commission Standard Contractual Clauses (SCCs).

12Your Rights (GDPR & CCPA) & Supervisory Complaints

As a data subject, you hold comprehensive rights under GDPR and international privacy legislation:

  • Right of Access (Art. 15): Obtain confirmation and copy of your personal data.
  • Right to Rectification (Art. 16): Correct or update inaccurate or incomplete data.
  • Right to Erasure (Art. 17): Request permanent deletion of your data.
  • Right to Restriction & Object (Arts. 18-21): Restrict or object to specific processing on legitimate grounds.
  • Right to Data Portability (Art. 20): Receive personal data in a structured, machine-readable format.
  • Right to Lodge a Complaint: You have the right to lodge a formal complaint with a competent supervisory authority (such as the Italian Garante per la Protezione dei Dati Personali at www.garanteprivacy.it or your local EU Data Protection Authority).

To exercise any of these rights, contact us at: privacy@joinhalo.it