Privacy
CheersFeed collects as little as the app needs to work. This policy says what that is in concrete terms — not in categories, but in fields.
Last updated: 27 August 20261. Controller
⟨Legal name of the provider⟩, ⟨Street No.⟩, ⟨Postcode City⟩, Switzerland.
Contact for all privacy matters: support@cheersfeed.app.
2. What is processed
| Data | Source | Purpose |
|---|---|---|
| Email address, Firebase user ID | On sign-up, via Firebase Authentication (email, Google or Apple) | Signing in and identifying your account |
| @handle, display name, profile picture, join date | From you when setting up your profile | So your friends can find and recognise you |
| Moments: two photos, timestamp, drink name, optional text | When you take one in the app | The core of the app — delivery to your friends |
| Resolved venue (name and point from Google Places) | Resolved server-side from your coordinate | Place label on the moment, map, „your places“, heatmap |
| Location coordinate at the time of capture | From the device, only if you grant access | Resolved into a venue once and then discarded — it is not stored |
| Reactions, seen markers, chaining of moments | From your use of the app | Counters on a moment, the „joined in“ list, the recap |
| Friendships and requests, rounds and memberships | From your use of the app | Visibility: who is allowed to see which moment |
| Pinned moments and pinned recaps | Chosen by you | Your profile |
| Push token and platform (iOS/Android) | From the device, if you allow notifications | Push messages via Firebase Cloud Messaging |
| Invite code and expiry | When you open QR Connect | Adding friends; the code expires after 15 minutes |
| Reports: reported moment, reason, optional note, reporter, timestamp | When you report something | Moderation and accountability |
| Operational logs: IP address, timestamp, endpoint, status code | Automatically when the backend is called | Operation, debugging, abuse prevention |
3. Legal bases
For users in the EU and EEA the GDPR applies, in Switzerland the revised Data Protection Act (revFADP). We rely on:
- Performance of a contract (Art. 6(1)(b) GDPR) — account, moments, friendships, delivery to your friends. Without this data there is no app.
- Consent (Art. 6(1)(a) GDPR) — camera, location and notifications. You give it through your device's system prompt and can withdraw it there at any time.
- Legitimate interests (Art. 6(1)(f) GDPR) — operational logs, rate limiting and handling reports. Our interest: an app that works and in which nobody is harassed.
4. Who else processes the data
CheersFeed runs on Google Cloud. We pass on no data for advertising purposes and sell none.
| Service | Purpose | Where |
|---|---|---|
| Google Cloud Run, Cloud SQL | Backend and database | europe-west6 (Zurich) |
| Google Cloud Storage | The photos | Google data centre, access only via short-lived signed links |
| Firebase Authentication | Sign-in, management of the login account | Google, partly USA |
| Firebase Cloud Messaging | Push messages, on iOS via Apple APNs | Google / Apple |
| Google Places API | Resolving your coordinate into a venue | |
| Google Sign-In / Sign in with Apple | Optional sign-in methods | Google / Apple |
For transfers to the USA we rely on the European Commission's standard contractual clauses and the corresponding addenda with Google and Apple.
5. How long
- Moments in the feed
- Visible for 24 hours. After that only in your own history and for those who were out with you that night.
- Photos
- Until you delete the moment or your account. There is no automatic purge — visibility and storage are two different things.
- Places, map, heatmap
- 365 days. The map looks back exactly as far as we store.
- Signed image links
- Valid for 1 hour, worthless afterwards.
- Invite codes
- 15 minutes.
- Reports
- Until handled, then for as long as needed to trace repeat offences.
- Operational logs
- According to Google Cloud's retention defaults, usually 30 days.
- Account
- Until you delete it.
6. Who sees what
- Moments go to accepted friends and nobody else. There is no public view, no web profile and no shareable link.
- Numbers and pinned moments on a profile are visible to friends only. Someone arriving from search sees the name, the @handle and the picture — nothing more.
- The social score stays with you. It is delivered to nobody, not even to friends.
- Blocked people disappear from the feed, search and lists in both directions.
7. Security
All traffic runs over TLS. Every endpoint except the health check requires a valid Firebase ID token. The photos sit in Google Cloud Storage, which encrypts them at rest; access runs exclusively through signed links valid for one hour. There is no additional end-to-end encryption of the pictures — whoever controls the bucket could read them. That is a deliberate decision rather than an oversight, and it is written here so that you know it.
8. No tracking, no advertising
The app contains no analytics SDK, no ad network and no cross-device identifier for advertising. We build no usage profiles and no audiences. What goes to Google goes there because sign-in, push, the map or storage need it.
9. Your rights
You have the right to access, rectification, erasure, restriction of processing, data portability and objection. Consent you have given can be withdrawn at any time with future effect — for camera, location and notifications in your device settings.
Write to support@cheersfeed.app for any of it. We answer within 30 days. You can also delete your account yourself — here is how.
You may lodge a complaint with a supervisory authority: in Switzerland the FDPIC, in the EU the authority of your country of residence.
10. Changes
If what the app processes changes, this policy changes with it. The date above says when it last did. We announce material changes in the app.