Airpaw Airpaw
  • Features
  • How It Works
  • Get the App

Privacy Policy

Last updated: February 2025

1. Introduction

Welcome to Airpaw ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, store, and protect your data when you use our mobile application and services.

By creating an account or using Airpaw, you agree to the collection and use of information as described in this policy. If you do not agree with our practices, please do not use our services.

2. Information We Collect

2.1 Account Information

When you create an account, we collect:

  • Email Address: Used for authentication, account recovery, and important notifications. Your email is encrypted and stored securely.
  • Display Name: Your chosen name visible to other users.
  • Username: A unique identifier for your account. If you sign up via magic link, a temporary username is auto-generated until you set one.
  • Password: If you choose password-based authentication, your password is securely hashed and never stored in plain text. Passwords are optional if you use magic link authentication.
  • Profile Photo: Optional avatar image you upload, stored on our secure cloud storage.

2.2 Phone Number

You may optionally add a phone number to your account for:

  • Account verification and recovery
  • Friend matching (finding contacts who use Airpaw)

Your phone number is encrypted and stored securely. It may be used for account verification and friend discovery.

2.3 Contact Data

With your explicit permission, you may sync your device's contacts to find friends on Airpaw. When you sync contacts:

  • What We Collect: Contact names, phone numbers, and email addresses from your device's address book.
  • How We Store It: All contact data is encrypted with unique encryption keys to protect your privacy.
  • Friend Matching: To find mutual connections, contact information is securely processed using privacy-preserving techniques that prevent reverse-engineering of phone numbers or other contact details. We compare encrypted contact information to match you with friends who also use Airpaw, without exposing actual contact details in our systems.
  • Limit: You can sync up to 5,000 contacts per sync operation.
  • Deletion: You can delete all synced contacts at any time, which also removes all friend suggestions generated from those contacts.

Important: We never share your contacts with third parties or use them for marketing purposes. Contact data is used solely to help you find friends on Airpaw.

2.4 Recommendation Content

When you use Airpaw to ask for or provide recommendations:

  • Recommendation Requests: Title, description, visibility settings, and optional location coordinates.
  • Responses: Your recommendation text and any contact information you choose to share.
  • Visibility: You control who sees your requests—all contacts or selected individuals.

2.5 Location Data

Location information is optional and only collected when:

  • You choose to add a location to a recommendation request
  • You explicitly grant location permission in the app

Location data is stored as geographic coordinates and used to provide location-relevant recommendations. We do not track your location in the background or create location histories.

2.6 Device Information

For push notifications, we collect:

  • Device Type: iOS or Android
  • Push Notification Token: A unique token provided by Apple (APNS) or Google (FCM) to deliver notifications to your device. This token is securely stored.

We do not collect device identifiers such as IMEI, UDID, advertising IDs, or hardware serial numbers.

2.7 What We Do NOT Collect

Airpaw does not use third-party analytics services. We do not collect:

  • Browsing history or app usage analytics
  • IP addresses for tracking purposes
  • Advertising identifiers
  • Crash reports via third-party services
  • Behavioral data for profiling or advertising

3. How We Use Your Information

We use your information to:

  • Provide Our Services: Enable you to create and respond to recommendation requests, connect with friends, and manage your account.
  • Authentication: Verify your identity when you sign in via magic link, password, or two-factor authentication.
  • Friend Discovery: Match you with friends who also use Airpaw based on mutual contact information.
  • Notifications: Send push notifications about new recommendations, responses, and friend suggestions (you can disable these in app settings).
  • Account Security: Protect your account through verification codes, 2FA, and session management.
  • Service Improvement: Maintain and improve our infrastructure and security systems.

We do not use your data for advertising, profiling, or selling to third parties.

4. Data Security

We implement industry-standard security measures to protect your data:

4.1 Data at Rest

Sensitive information stored on our servers is protected using:

  • Encryption: Email addresses, phone numbers, contact data, and authentication tokens are encrypted using strong encryption standards.
  • Secure Hashing: Passwords and backup codes are never stored in plain text; they are securely hashed using one-way cryptographic functions.
  • Access Controls: Data is protected with account-specific encryption keys to ensure isolation between users.

4.2 Data in Transit

  • All communications between your device and our servers are encrypted using industry-standard TLS/SSL protocols.
  • API communications use HTTPS exclusively to prevent interception.

4.3 Privacy-Preserving Technologies

We use privacy-preserving techniques to protect your information:

  • Secure Lookups: Email and phone numbers are processed using cryptographic techniques that allow matching without exposing actual values.
  • Friend Matching: Contact information is securely processed to find mutual connections without revealing your contacts to our systems in readable form.

4.4 Access Controls

  • Authentication required for all access to personal data.
  • Ownership verification ensures you can only access your own data.
  • Rate limiting protects against unauthorized access attempts.
  • Regular security audits and monitoring to detect potential threats.

5. Authentication & Account Security

5.1 Magic Link Authentication

Our primary authentication method sends a one-time verification code to your email:

  • Verification codes are time-limited and expire after a short period.
  • Failed verification attempts are limited to prevent unauthorized access.
  • Codes are securely stored and automatically deleted after use.

5.2 Password Authentication

Optional password-based login:

  • Passwords are securely hashed and never stored in plain text.
  • Password reset available via email verification.

5.3 Two-Factor Authentication (2FA)

For enhanced security, you can enable two-factor authentication:

  • Compatible with standard authenticator apps (Google Authenticator, Authy, etc.).
  • Backup codes provided for account recovery in case you lose access to your authenticator.
  • Failed authentication attempts are limited to protect your account.
  • 2FA configuration data is encrypted for your protection.

5.4 Phone Verification

SMS verification for phone numbers:

  • Verification codes sent via SMS.
  • Codes expire after a short time period.
  • Rate limiting in place to prevent abuse.
  • Failed verification attempts are limited for security.

5.5 Session Management

  • Active sessions remain valid for a limited time and automatically extend with use.
  • You can log out at any time to immediately end your session.
  • Inactive or partial sessions expire automatically.

6. Third-Party Services

We use the following third-party services to operate Airpaw:

6.1 Twilio (SMS Verification)

  • Purpose: Sending SMS verification codes for phone number verification.
  • Data Shared: Phone number, verification code.
  • Privacy Policy: twilio.com/legal/privacy

6.2 Email Service Provider (SMTP)

  • Purpose: Sending magic link codes and email verification codes.
  • Data Shared: Email address, verification codes, your display name.

6.3 Cloud Storage (Avatar Images)

  • Purpose: Storing profile photos.
  • Data Shared: Profile photo images.
  • Access: Avatar images are publicly accessible via URL to display in the app.
  • Retention: Previous avatars are deleted when you upload a new one.

6.4 Firebase Cloud Messaging (Android Push Notifications)

  • Purpose: Delivering push notifications to Android devices.
  • Data Shared: Push notification tokens, notification content.
  • Privacy Policy: firebase.google.com/support/privacy

6.5 Apple Push Notification Service (iOS Push Notifications)

  • Purpose: Delivering push notifications to iOS devices.
  • Data Shared: Push notification tokens, notification content.
  • Privacy Policy: apple.com/legal/privacy

We do not use analytics services (Google Analytics, Mixpanel, etc.) or advertising networks.

7. Data Retention

We retain your data as follows:

7.1 Automatic Deletion

Data Type Retention Period
Magic Link Codes 15 minutes or until used
Email Verification Codes 24 hours or until used
Phone Verification Codes 10 minutes or until used
2FA Attempt Records 15 minutes
Session Tokens 7 days (auto-extend on use)
Invalid Push Tokens Deactivated immediately

7.2 User-Controlled Deletion

  • Contacts: You can delete all synced contacts at any time via Settings. Deletion is immediate and also removes associated friend suggestions.
  • Recommendation Requests: You can delete your requests, which removes them from visibility (soft delete).
  • Profile Photo: You can remove or replace your avatar at any time.
  • Push Tokens: Automatically removed when you unregister or when tokens become invalid.

7.3 Long-Term Storage

The following data is retained while your account is active:

  • Account information (email, name, username)
  • Phone number (if added)
  • Recommendation history (unless deleted)
  • 2FA configuration (if enabled)

8. Your Rights & Controls

You have control over your data:

8.1 Access & Export

  • View your profile information in the app settings.
  • Request a copy of your data by contacting us at privacy@airpaw.0iop.be.

8.2 Correction

  • Update your name, username, and profile photo in app settings.
  • Change your email or phone number with verification.
  • Update your password at any time.

8.3 Deletion

  • Contacts: Delete all synced contacts via Settings → Contacts → Delete All.
  • Recommendations: Delete individual requests or all requests.
  • Account: Request full account deletion by contacting privacy@airpaw.0iop.be.

8.4 Security Controls

  • Enable or disable two-factor authentication.
  • Regenerate 2FA backup codes.
  • Log out to invalidate current sessions.
  • Manage push notification preferences.

8.5 Communication Preferences

  • Enable or disable push notifications in app settings or device settings.

9. Information Sharing

We do not sell your personal information. We share data only in these circumstances:

9.1 With Other Users

  • Public Profile: Your name, username, and avatar are visible to other users.
  • Recommendations: Your requests are visible to contacts you select; your responses are visible to the requester and other responders.
  • Friend Suggestions: Mutual contacts may see you as a suggested friend.

9.2 Service Providers

As described in Section 6, we share limited data with service providers who help operate our services. These providers are contractually obligated to protect your data.

9.3 Legal Requirements

We may disclose information if required by law, court order, or to:

  • Comply with legal obligations
  • Protect our rights and safety
  • Prevent fraud or security threats
  • Respond to lawful government requests

9.4 Business Transfers

If Airpaw is acquired or merged, your data may be transferred. We will notify you of any change in ownership or use of your personal information.

10. Children's Privacy

Airpaw is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent and believe your child has provided us with personal information, please contact us at privacy@airpaw.0iop.be, and we will delete that information.

11. International Data Transfers

Your information may be processed on servers located outside your country of residence. We ensure appropriate safeguards are in place, including:

  • Encryption of sensitive data during transfer and at rest
  • Compliance with applicable data protection regulations
  • Contractual protections with service providers

12. Changes to This Policy

We may update this Privacy Policy periodically. When we make significant changes:

  • We will update the "Last updated" date at the top of this page.
  • For material changes, we may notify you via email or in-app notification.
  • Continued use of Airpaw after changes constitutes acceptance of the updated policy.

We encourage you to review this policy periodically.

13. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

  • Email: privacy@airpaw.0iop.be
  • Support: Visit our Support page

We aim to respond to all privacy inquiries within 30 days.

14. Summary

In plain language:

  • We collect only what's necessary to provide our service.
  • Your email, phone, and contacts are protected with industry-standard encryption.
  • We don't use analytics or advertising services.
  • We don't sell your data to anyone.
  • You can delete your contacts and data at any time.
  • Friend matching uses privacy-preserving techniques that protect your contact information.
  • We use trusted third parties only for essential services: SMS delivery (Twilio), email delivery, push notifications (Firebase/Apple), and secure file storage.
Airpaw Airpaw

Trusted recommendations from your network.

Product

  • Features
  • How It Works
  • Download

Legal

  • Privacy Policy
  • Terms of Service

Connect

  • Contact Us
  • Support

© 2025 Airpaw. All rights reserved.