Blijdorp
Privacy Policy
Blijdorp is a neighbourhood app that helps new and expecting mothers in Blijdorp, Rotterdam find each other for walks, coffees and friendship. We built it privacy-first: we collect the minimum needed to connect you with neighbours, we never sell your data, and we never show anyone your exact location. This policy explains what we process, why, and your rights under the EU General Data Protection Regulation (GDPR).
1. Who is responsible (controller)
Svetlana Zigalkina de Boer, Rotterdam, the Netherlands, is the data
controller for the Blijdorp app.
Contact: via the in-app support form (Me → Contact support).
2. What we collect and why
| Data | Why (purpose) | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Name, profile photo, life stage (expecting / has children) | Your profile, shown to verified neighbours so you can find each other | Contract (providing the service) |
| Phone number | Sign-in by SMS code; keeps throwaway accounts out | Contract; legitimate interest (community safety) |
| Recovery email (optional) | Getting back into your account if you lose your phone; only used after you confirm it via a link | Contract |
| Approximate location | Showing you on the neighbourhood map and finding mums near you. We store only a point snapped to a ~200 m grid — your exact address or GPS position is never stored and never shown | Contract; consent (you grant location access) |
| Children's age band and optionally gender | Matching you with mums in a similar phase. We deliberately never ask a child's name or exact birth date | Contract |
| Messages, invites, RSVPs, availability | The core service: chatting and planning meetups. Messages are visible only to their participants | Contract |
| Invitation link (who invited you) | Blijdorp is invite-only; we record which member's code you used | Legitimate interest (community trust) |
| Push token | Sending notifications (new message, RSVP) to your device | Contract; you can disable notifications in iOS settings |
| Blocks and reports | Safety: keeping the community respectful; reports go to the founder for moderation | Legitimate interest (safety); legal obligation where applicable |
| Journal entries: voice notes, typed notes, photos and the dates you give them | Your private journal. Entries are visible only to you — never to other members, never on the map, never in chat. Each voice or typed note is sent once to our AI provider to be transcribed and written up; nothing is used to train anyone's models | Contract (providing the service); consent (you grant microphone access) |
| Album share links (only if you make one) | Letting family read one of your albums in a browser, without an app or an account. A link exists only when you create it: it carries an unguessable token, shows that album's dates, written records and photos and nothing else, and stops working the moment you turn it off. Photo links inside the page expire after an hour. We count how many times a link was opened, so you can see it is being read — never who opened it | Consent (you choose to share); contract |
| Exports you make yourself | The album PDF is created on your phone and handed to whatever you choose — Files, mail, a print service. Once it leaves the app it is yours to look after; we keep no copy | Contract |
| Usage analytics (screens viewed, features used) | Improving the app: seeing which parts are actually used and where people get stuck. Two contentless records — a pseudonymous event stream (PostHog, EU) and a small table in our own EU database holding an action name, a count and your member id (for example “album exported, 11 pages”). Never your name, phone, message or journal contents, photos, or location | Legitimate interest (product improvement) |
A note on profile photos: your photo is stored at an unlisted web address so the app can display it. It is not indexed or listed anywhere, but anyone with the exact link could view it. Choose a photo you are comfortable with.
3. What we never do
- We never sell or rent your personal data.
- We never show ads based on your data.
- We never store or show your precise location or address.
- We never collect your child's name or full date of birth.
- We never make your journal public, and we never share an album with anyone unless you create a link yourself.
- No automated decision-making or profiling with legal effects (Art. 22 GDPR).
4. Who processes data for us
We use a small number of service providers (processors), bound by data processing agreements:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, sign-in, file storage | EU (Frankfurt, Germany) |
| Twilio | Sending the SMS sign-in code | USA* |
| Optional "Continue with Google" sign-in | EU/USA* | |
| Expo & Apple | Delivering push notifications | USA* |
| Resend | Account and support emails | EU (Ireland) |
| Mapbox | Map display and place search | USA* |
| Google (Gemini API) | Transcribing and writing up your journal notes — one call per note. Your notes are not used to train models | EU/USA* |
| PostHog | Pseudonymous usage analytics | EU (Frankfurt, Germany) |
| GitHub Pages | Hosting this policy and the page family opens an album link on. The page holds no data itself — it asks our EU database for the album each time it is opened | USA* |
*Transfers to US providers are protected by the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses (Art. 46 GDPR), and are limited to what each service strictly needs (e.g. Twilio only receives your phone number to deliver the code).
5. How long we keep data
- While your account is active: we keep your profile and content so the service works.
- When you delete your account (Edit profile → Delete account): your profile, photos, messages, invites, RSVPs, groups you created and push tokens are permanently deleted immediately. Residual copies in encrypted backups are purged within 30 days.
- Journal entries can be deleted one by one, or with the whole journal; the recording, the photos and the written record all go together. Deleting your account removes every journal, entry, voice note and photo with it.
- Album share links stop working the moment you turn them off, and are removed with the album or the account. A PDF you already exported is outside the app and cannot be recalled.
- Unused invite codes are deleted 30 days after they expire.
- Support emails are kept as long as needed to help you.
6. Your rights
Under the GDPR you can, at any time:
- Access the data we hold about you (Art. 15);
- Correct it (Art. 16) — most of it directly in Edit profile;
- Delete it (Art. 17) — instantly, in-app, via Delete account;
- Restrict or object to processing based on legitimate interest (Art. 18, 21), including analytics;
- Receive a copy of your data in a portable format (Art. 20);
- Withdraw consent (e.g. location access) at any time via iOS settings, without affecting past processing.
Use the in-app support form (Me → Contact support) for any of these; we respond within one month. You also have the right to complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.
7. Security
Data is encrypted in transit and at rest, stored in the EU, and protected by strict database access rules (each member can only read what the app intends her to see). Sign-in uses one-time codes — there are no passwords to steal. The community itself is protected by invitation-only membership, phone verification and active human moderation.
8. Children
Blijdorp is for adults (18+). We process only minimal information about members' children — an age range and optionally gender, provided by the parent — to match families in a similar phase. We never knowingly collect data from children themselves.
9. Changes
If we change this policy in a meaningful way we will tell you in the app before the change takes effect. The current version always lives at this address.