Privacy policy
Last updated 17 September 2026
This page explains which data Popaz uses, why it is needed, who it may be shared with, and how you can use your rights.
Who controls your data
Benedetto Pascucci and Arcangelo Massari are joint controllers and provide Popaz from Via San Felice 141, Bologna, Italy. They decide the purposes and means of processing together.
To use a right or request the main points of the joint-controller arrangement, write to them at info@popaz.eu.
Data we process
- Account and profile information: email address, password hash, handle, name, language, theme, settings, contact details you choose to add, and the version and time of your acceptance of the Terms.
- Content and activity: text, images, video, audio, other files, links and their previews, places with coordinates, and dates and times that you add. We also keep actions in the app, such as follows, comments, votes, reactions, content openings, searches, and personalised content.
- Technical data: network address, time, route, request event or error, and data needed to provide the features you choose. The popaz.eu website does not keep this data.
- Moderation data: the account that submits a report in the app or the name and email of a person who sends one to info@popaz.eu, reported content, its reason, explanation, a copy of the content and visible context, moderators' decisions, corrections, appeals, and outcomes.
- Emails: messages that you exchange with info@popaz.eu, including addresses, dates, and content.
Profiles and published content, such as boxes and capsules, are visible to other signed-in users. They are not published on the Web for people without an account.
We keep chalkboard openings to identify read messages and use Favorites, Buzz, and scouting to order them when Personalised content is enabled. We also remember whose chalkboards you hide until you change that choice or delete your account, even if you stop supporting them. To keep the order stable while you browse, we store the chalkboard sequence for twenty-four hours, while expired messages leave the list.
Why we use data and our legal basis
- Contract: we use account, profile, content, and activity information to create and manage your account, show content to signed-in users, and provide social features, live broadcasts, maps, search, and personalised content.
- Legal duty: we use emails and account, content, technical, and moderation data to respond to authority orders, handle reports, send moderation decisions by email, and meet valid personal-data requests.
- Legitimate interests: we use technical, activity, and moderation data to protect accounts and the service, prevent abuse, fix faults, recover the service after an incident, enforce rules, and rank content. We also use emails when we answer your other questions.
Device permissions
Camera, microphone, photos, and files are used only when you choose to create content or start a live broadcast. Sensors, breath, and movement stay on the device and serve only as opening gestures. Popaz adds an event to your device calendar only when you ask. Popaz does not collect your device location.
Recipients, systems, and providers
Other signed-in users receive profile data, content, and interactions that you choose to make visible in the app. The joint controllers and people authorised by Popaz receive only the data needed to run the service and moderation.
Hetzner hosts Popaz's main systems in the European Economic Area. The joint controllers store encrypted backups and emails in Italy. IONOS manages the popaz.eu domain in the European Economic Area. Popaz runs the database, backend, live broadcasts, and services for search and personalised content. Geoapify processes place searches for Popaz, as described in the next section.
App stores independently process data needed to distribute the app. When you request a link preview, the named website receives a request from the Popaz server and applies its own privacy policy.
Places and maps
When you pause after typing at least three characters in a map or event place field, the Popaz server sends the text and selected app language to Geoapify for suggestions. Geoapify receives the query, the Popaz server address, and request data, but not your account details or device address. Successful requests are normally kept for no more than 24 hours under Geoapify's policy. You can ignore every suggestion and save your own text. When you save a place, Popaz stores the place text and its coordinates. Static maps use OpenStreetMap data served by Popaz. The place reaches your chosen maps app only when you tap the preview.
How long data is kept
- Account, profile, content, and activity data remains until the account or content is deleted.
- When you delete data, it may remain in encrypted backups for up to 14 days. After that period, it is also deleted from those copies.
- Content with an expiry follows the date shown. Incomplete uploads disappear after one hour. Live chat and call requests disappear when the live broadcast ends.
- Emails that you exchange with info@popaz.eu are deleted 12 months after they arrive or are sent.
- Reports, decisions, appeals, and material in a moderation case remain for 12 calendar months after the most recent closure of the moderation case. A case involving a suspended account stays open until the account is restored or deleted. The content of a suspended account stays hidden from other users. If no appeal is accepted, the account is deleted 12 months after the decision.
Required data and minimum age
You need an email address, a password, a handle, a name, and acceptance of the Terms to open an account. You must be at least 18. Popaz does not collect a birth date, identity document, biometric data, or parent or guardian data. Popaz cannot provide the service without the required data. Other data depends on the features you choose.
Your rights
You can ask for access, a copy, correction, deletion, restriction, portability, or object to processing based on legitimate interests by writing to the joint controllers at info@popaz.eu. You can also delete your account in the app and lodge a complaint with the Italian Data Protection Authority.
Security, data protection officer, and transfers
Popaz limits access to personal data, uses encrypted connections, and stores passwords only as hashes. When you sign up, reset, or change your password, Popaz compares the SHA-1 hash of the password with the Pwned Passwords corpus of compromised password hashes, stored on a Popaz server. Popaz updates the corpus from the public source without sending passwords or account data.
Popaz has not appointed a data protection officer and does not transfer personal data outside the European Economic Area.
Contacts and sources
For rights, questions, or complaints, write to the joint controllers at info@popaz.eu. Include your account and request, but do not send your password. You can also read Geoapify's privacy policy and the Italian Data Protection Authority website.