Your privacy at Ekiro
Ekiro helps you find and create local events. Doing that means we hold some information about you - your profile, the events you join, the messages you send. This page explains, in plain terms, what we collect, why, how we protect it, how long we keep it, and how you can take it with you or delete it at any time.
Who we are
Ekiro is operated by Nexlify OÜ (Estonian registry code 17216661), Narva mnt 5, 10117 Tallinn, Estonia (“Ekiro”, “we”, “us”). We are the controller of the personal data described here, and because we are established in Estonia the GDPR governs how we handle it. For any privacy question, or to reach the people responsible for data protection, write to privacy@getekiro.com.
What we collect
We collect only what the service needs. Every field below has a purpose you can see in the app.
- Profile
- Your name, handle, an optional short bio, an optional avatar, and your date of birth. The date of birth is used only to check that you meet the age threshold for your region. We do not display it.
- City and area
- The city you pick and a coarse geo tile (a rounded area, not a point) used to sort nearby events. We do not store your precise coordinates - see the next section.
- Interests
- The categories you choose, used to order your feed.
- Events and activity
- Events you host or attend, join requests, invitations, and friends. If you host an event, the details you enter about it.
- Pictures you upload
- Your avatar, the photos of an event you host, and the short video an event can carry. We do not read anything out of them beyond checking the file is the kind of file it says it is.
- Messages
- The content of messages you send to other people through Ekiro, and unread counts.
- Reports
- If you report a person, an event or a message, the report and what you tell us about it, so our moderators can act on it.
- Your devices
- An identifier for each device you sign in on, so a session can be ended on one without ending it on the others, and - if you turn push notifications on - the registration token Google issues for that install. Both are deleted when you delete your account, and the token is deleted when you turn push off.
- Technical logs
- Limited logs needed to keep the service secure and working, including some that carry an IP address. These are kept only briefly (see retention).
Your location stays on your device
This is the part people care about most, so it gets its own section. When you set up your area, your device may read your position to help you pick a city - but your precise coordinates never leave your device. Before anything is sent to us, your position is folded into a coarse geo tile (a rounded area covering many streets) together with your chosen city. We store only that tile and city. We never store, and cannot recover, your exact location.
This is separate from an event’s own venue. When a host creates an event, the address they enter is the meeting place, and it is shown to the people who can see that event - publicly, for a public event - because finding events near you and building a route to them depends on it. An event’s venue is location data about a place, not private location data about you. It is not encrypted, and it is not the same as your own position, which never leaves your device.
How we use your data
- To run the core service: your feed, search, events, requests, invitations, friends and messages.
- To sort events by time, distance from your area and your interests.
- To keep you signed in and to send the notifications you have turned on (in the app, by push, or by email).
- To operate safety features you choose to use, such as the route message you compose before you leave for an event.
- To handle reports, moderate content, and keep Ekiro safe.
- To meet legal obligations and confirm you meet the age threshold for your region.
We do not sell your data, and we do not run third-party advertising or cross-site tracking on Ekiro.
How we store and protect it
- In transit: all traffic between your device and Ekiro is encrypted with TLS.
- By not collecting it: the most sensitive location data - your own precise coordinates - is never collected or stored, so there is nothing there to expose.
- Sessions: we keep you signed in with a secure refresh cookie rather than storing long-lived credentials in the page.
How long we keep it
These windows are configured per region and may differ where local law requires it. As a baseline:
- Messages
- Kept for 24 months, then removed.
- Precise coordinates
- Never stored, so there is nothing to retain.
- Logs that carry an IP
- Kept for 90 days.
- A deleted account
- Held for a 30-day soft-delete window (so you can change your mind), then irreversibly anonymised.
- Backups
- A deletion propagates into backups on their rotation schedule, at most 35 days.
Your rights and choices
You can exercise the main rights yourself, without asking us, from Profile → Your data in the app:
- Export: download a single archive of your profile, interests, events, requests, friends, the messages you sent, your notifications and your recorded consents.
- Delete: close your account. This starts the 30-day clock described above. Until it runs out you can cancel and nothing is lost. If you cannot reach that screen - a lost phone, an uninstalled app, a sign-in you can no longer complete - deleting your account says how to ask us instead.
- See what you agreed to: the same screen lists the versioned consents you gave at sign-up, with dates.
Self-service requests are completed within 30 days. Depending on your region you may also have rights to correct your data, object to or restrict certain processing, and to complain to a supervisory authority. Ours is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, info@aki.ee; if you live in another EU country you may complain to the authority there instead. To make any request we cannot yet handle in the app, contact privacy@getekiro.com. Where our legal basis is your consent, you can withdraw it at any time without affecting what came before.
Companies that help us run Ekiro
We use a small number of service providers, who process data only on our instructions and only to run the service:
- Google and Facebook - only if you choose to sign in with them. We talk to each of them directly, with our own credentials. There is no third party sitting between you and them (see the next section).
- Google (Firebase Cloud Messaging) - the only way Android has of waking an app that is not running, so it carries our push notifications to your phone. What travels through Google is deliberately empty of content: the kind of event and the identifiers the app needs to fetch the text from us, and not one word of the notification itself.
- S3-compatible object storage - for the pictures you upload.
- An email provider - to send verification codes and the notifications you have turned on.
Each processes data only on our instructions and only to run the service. None of them is paid in data, and none of them is given anything for advertising. Ekiro carries no advertising, no analytics and no crash reporting - there is no Firebase Analytics, no Crashlytics and no measurement library in the app. For the countries these systems sit in, and the data-processing agreements behind them, write to privacy@getekiro.com.
Regions, age and legal basis
Ekiro is built to the strictest common standard and then set per region, so the same product can meet the GDPR (EU), the DPDP Act (India) and the CCPA/CPRA (United States) without a separate policy for each. Your region determines which of these rules and which retention windows apply to you. Ekiro is launching in Pakistan.
You must be 18 or older to use Ekiro, wherever you are. We check your age at sign-up using the date of birth you provide, and record your age confirmation as a versioned consent.
Ekiro is operated from Estonia, so the GDPR applies to what we do with your data wherever you live. Where the rules of your own region give you more, those apply on top. Our legal basis under Article 6 depends on the activity:
- Our agreement with you (Art. 6(1)(b)): your account, profile, city and interests, the feed, events, requests, invitations, friends, messages, and the service notifications that go with them.
- Your consent (Art. 6(1)(a)): the optional push and email notifications you switch on.
- Our legitimate interests (Art. 6(1)(f)): keeping Ekiro safe and working - moderation, acting on reports, preventing abuse and fraud, and the limited security logging described above.
- A legal obligation (Art. 6(1)(c)): confirming you meet the age threshold, keeping records we are required to keep, and answering lawful requests from authorities.
Changes to this policy
When this policy changes in a way that matters, we update the document version and the effective date at the top, and - where the change is material - ask you to accept the new version, recording it against your account. Older versions of what you agreed to remain on record so you can always see what applied when.
How to reach us
For any privacy question or request, write to privacy@getekiro.com. The controller is Nexlify OÜ (Estonian registry code 17216661), Narva mnt 5, 10117 Tallinn, Estonia. This policy is governed by Estonian law and by the GDPR (Regulation (EU) 2016/679), as supplemented by the Estonian Personal Data Protection Act (isikuandmete kaitse seadus). It is effective 4 September 2026.
Signing in with Google or Facebook
If you sign in with Google or Facebook, the sign-in happens between you and them directly - your browser goes to Google or to Facebook, and what comes back reaches us over our own connection to them. We receive a provider account identifier, your name, and your email address, so we can create or match your Ekiro account. We do not receive your social password, and we do not post anything on your behalf. An email address that Facebook has not marked as verified is not treated by us as a confirmed address.
If you connected Facebook, you can ask for the data obtained through Facebook to be deleted - either from within Facebook, which sends us a data-deletion request we honour, or by deleting your account in the app. A Facebook data-deletion request is put through exactly the same 30-day deletion machinery as deleting your own account.