IMPORTANT
This Privacy Policy describes how Alladro collects, uses, stores, and shares your personal information. By using the Service, you consent to the practices described in this Policy.
1. Introduction and Controller Information
1.1 Who We Are
Alladro ("we", "us", "our") is a community-based crime reporting mobile application. We are the data controller responsible for your personal information.
Contact Information:
Service Name: Alladro
Email: alladro@appjuice.it
1.2 Scope of This Policy
This Privacy Policy applies to all personal information collected through:
The Alladro mobile application (iOS)
Our website: https://alladro.appjuice.it
Any related services, features, or communications
1.3 Legal Basis
We process your personal data in compliance with:
EU General Data Protection Regulation (GDPR) - Regulation 2016/679
Italian Privacy Code (Legislative Decree 196/2003 as amended)
EU ePrivacy Directive (Directive 2002/58/EC)
Other applicable data protection laws
2. Personal Information We Collect
WARNING
When you post crime reports, your geolocation data, username, and report content become PUBLIC and are visible to all users.
2.1 Information You Provide Directly
Data Category
Specific Data
When Collected
Account Information
• Email address • Username • Full name (optional) • Password (hashed)
Account registration
Profile Information
• Avatar/profile picture (optional) • User preferences • Theme settings
Profile setup/updates
Crime Report Content
• Report title • Report description • Crime type/category • Event date and time • Images/photos (up to 1) • User-provided location notes
When creating crime reports
User Interactions
• Upvotes on events • Contact requests • Direct messages • Report submissions (flagging content) • Bug reports and suggestions
• Display crime events on map • Filter events by proximity • Associate reports with locations
Device Information
• Device type (iOS version) • Operating system version • App version • Device identifiers (IDFA if consented) • Screen resolution
• Technical support • App optimization • Crash reporting
Usage Data
• Login timestamps • Last active time • Features used • Reports created/viewed • Messages sent/received • Search queries
• Service improvement • Analytics • Security monitoring
Network Information
• IP address • Connection type (WiFi/Cellular) • Network provider
• Security • Fraud prevention • Service delivery
2.3 Information from Third-Party Services
We integrate with the following third-party services that may collect data:
Supabase (Database & Authentication)
Email authentication data
Session tokens
All user-generated content
Database queries and logs
Google Maps API
Map tile requests
Geocoding requests (coordinates to addresses)
Location data for map display
Google AdMob (Advertising)
Ad impressions and clicks
Device advertising ID
Ad performance metrics
3. How We Use Your Personal Information
3.1 Legal Bases for Processing
Purpose
Legal Basis (GDPR)
Account creation and authentication
Contract performance (Art. 6(1)(b))
Displaying crime reports on map
Contract performance + Legitimate interests
Geolocation processing
Consent (Art. 6(1)(a)) via iOS location permission
Direct messaging between users
Contract performance
Content moderation
Legitimate interests (safety, legal compliance)
Security and fraud prevention
Legitimate interests
Analytics and service improvement
Legitimate interests
Marketing communications (if any)
Consent (Art. 6(1)(a))
Legal obligations and law enforcement
Legal obligation (Art. 6(1)(c))
3.2 Specific Use Cases
We use your personal information to:
Provide the Service:
Create and manage your account
Authenticate your identity
Display crime events on interactive map
Filter events based on your location and preferences
Enable voting, messaging, and social features
Process contact requests between users
Content Moderation:
Review user-generated content for policy violations
Process user reports of inappropriate content
Use automated AI moderation tools (Claude/ChatGPT)
Remove violating content and suspend accounts
Security & Safety:
Prevent fraud, spam, and abuse
Detect and prevent security threats
Enforce our Terms of Service
Monitor for illegal activity
Communications:
Send account-related notifications
Respond to support inquiries
Send service updates and announcements
Facilitate messaging between users
Analytics & Improvement:
Analyze usage patterns and trends
Improve app performance and features
Conduct research and development
Generate aggregate statistics (anonymized)
Legal Compliance:
Comply with legal obligations
Respond to law enforcement requests
Protect our legal rights
Investigate potential violations
Advertising:
Display personalized advertisements (via Google AdMob)
Measure ad performance
Generate revenue to support the Service
4. How We Share Your Personal Information
PUBLIC INFORMATION
Crime reports you create (including title, description, location coordinates, images, username, and event date) are PUBLIC and visible to all app users and potentially the general public.
4.1 Public Disclosure
The following information is PUBLIC by default:
Crime report titles and descriptions
Precise GPS coordinates (latitude/longitude) of reported events
Geocoded addresses of events
Images/photos attached to reports
Your username associated with reports
Event date and time
Crime category/type
Number of upvotes on events
This public information may be:
Viewed by any app user or visitor
Indexed by search engines
Archived by third parties
Republished or redistributed
Persistent even after deletion (in caches/backups)
Direct Messages: Shared only with the specific recipient
Contact Requests: Shared with the event creator you're requesting to contact
Upvotes: Vote counts are public; individual voter identity may be visible
4.4 Legal and Safety Disclosures
We may disclose your information without consent when required or permitted by law:
Law Enforcement Requests: In response to valid legal process (subpoena, court order, search warrant)
Legal Compliance: To comply with applicable laws and regulations
Safety Emergencies: To prevent death or serious bodily harm
Rights Protection: To protect our rights, property, or safety
Fraud Prevention: To investigate and prevent fraud or illegal activity
Terms Enforcement: To enforce our Terms of Service
4.5 Business Transfers
If Alladro is involved in a merger, acquisition, sale of assets, or bankruptcy, your personal information may be transferred to the acquiring entity. We will notify you via email and/or prominent notice in the app before your data is transferred.
4.6 Aggregate/Anonymized Data
We may share aggregate, anonymized, or de-identified information that cannot reasonably be used to identify you, including:
Crime statistics by neighborhood or city
Aggregate usage metrics
Trend analysis and research
5. Data Retention
5.1 Retention Periods
Data Type
Retention Period
Reason
Account Information
Until account deletion + 30 days
Account management, legal obligations
Crime Reports (Published)
Indefinitely (public record)
Public safety information, platform purpose
Crime Reports (Rejected/Unverified)
90 days after rejection
Appeal process, moderation review
Direct Messages
Until deletion by user or account closure
User communication history
Contact Requests
7 days after expiration or until accepted/rejected
Operational necessity
Usage Logs
90 days
Security, analytics
IP Address Logs
30 days
Security, fraud prevention
Moderation Records
2 years
Legal defense, pattern detection
Backup Data
90 days (rolling backups)
Disaster recovery
5.2 Account Deletion
When you delete your account:
Your account credentials and profile are deleted within 30 days
Your private messages are deleted
Your public crime reports MAY REMAIN VISIBLE as they constitute public safety information
Your username may be anonymized on existing reports (e.g., "Deleted User")
Backups may retain data for up to 90 days
Legal holds or law enforcement requests may prevent deletion
IMPORTANT
Deleting your account does NOT guarantee removal of public crime reports you created. These may remain visible for public safety purposes.
6. Your Rights Under GDPR
If you are located in the European Economic Area (EEA), UK, or Switzerland, you have the following rights:
6.1 Right of Access (Art. 15 GDPR)
Request a copy of all personal data we hold about you
Receive information about how we process your data
How to exercise: Email alladro@appjuice.it with subject "Data Access Request"
6.2 Right to Rectification (Art. 16 GDPR)
Correct inaccurate or incomplete personal data
Update your profile information directly in the app
How to exercise: Edit your profile or contact alladro@appjuice.it
6.3 Right to Erasure / "Right to be Forgotten" (Art. 17 GDPR)
Request deletion of your personal data
Limitations: We may retain data if required by law or for legitimate interests (e.g., public crime reports)
How to exercise: Delete account in-app or email alladro@appjuice.it
6.4 Right to Restriction of Processing (Art. 18 GDPR)
Request temporary suspension of data processing
How to exercise: Email alladro@appjuice.it
6.5 Right to Data Portability (Art. 20 GDPR)
Receive your data in machine-readable format (JSON)
Transfer your data to another service
How to exercise: Email alladro@appjuice.it with subject "Data Portability Request"
6.6 Right to Object (Art. 21 GDPR)
Object to processing based on legitimate interests
Object to direct marketing
How to exercise: Email alladro@appjuice.it
6.7 Right to Withdraw Consent (Art. 7(3) GDPR)
Withdraw consent for location tracking (disable in iOS Settings)
Withdraw marketing consent
Note: Withdrawal does not affect lawfulness of processing before withdrawal
6.8 Right to Lodge a Complaint
File a complaint with your local data protection authority
Italy (Garante): https://www.garanteprivacy.it
EU Data Protection Authorities: https://edpb.europa.eu/about-edpb/board/members_en
6.9 Exercising Your Rights
To exercise any of these rights:
Email us at: alladro@appjuice.it
Include subject line: "GDPR Rights Request"
Specify which right(s) you wish to exercise
Provide identity verification (to prevent fraud)
Response Time: We will respond within 30 days (may be extended to 60 days for complex requests).
Cost: Free of charge, unless requests are manifestly unfounded or excessive.
7. International Data Transfers
NOTE
Your data may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States.
7.1 Transfer Mechanisms
When we transfer data outside the EEA, we use the following safeguards:
Standard Contractual Clauses (SCCs): EU-approved contracts with third-party processors (Supabase, Google)
Adequacy Decisions: Transfers to countries deemed adequate by the EU Commission (if applicable)
Privacy Shield successor frameworks: If applicable for US transfers
Binding Corporate Rules: For transfers within multinational corporate groups (if applicable)
7.2 Third-Party Data Locations
Supabase: Data may be stored in various regions (check Supabase's data processing agreement)
Google Services (Maps, AdMob): United States and global data centers
AI Moderation (Claude/OpenAI): United States
For more information about international transfers, contact alladro@appjuice.it.
8. Security Measures
8.1 Technical and Organizational Measures
We implement appropriate security measures to protect your data:
Encryption:
HTTPS/TLS encryption for data in transit
Password hashing (not stored in plain text)
Encrypted database connections
Access Controls:
Role-based access to backend systems
Authentication required for all actions
Limited employee access to personal data
Monitoring & Logging:
Security event logging
Intrusion detection systems
Regular security audits
Data Minimization:
Collect only necessary data
Delete data when no longer needed
Anonymize data where possible
8.2 Limitations
NO SECURITY IS PERFECT
Despite our efforts, no system is 100% secure. We cannot guarantee absolute security of your data. You use the Service at your own risk.
8.3 Data Breach Notification
In the event of a data breach affecting your personal information:
We will notify affected users within 72 hours (as required by GDPR Art. 33-34)
We will notify relevant supervisory authorities
Notification will include nature of breach, affected data, and remedial actions
9. Children's Privacy
9.1 Age Restrictions
Minimum Age: 13 years old
Under 18: Parental or guardian consent required
We do NOT knowingly collect data from children under 13
9.2 Parental Rights
Parents/guardians have the right to:
Review their child's personal information
Request deletion of their child's data
Refuse further collection of their child's data
If you believe we have inadvertently collected data from a child under 13, contact us immediately at alladro@appjuice.it.