Short version: NowHere stores only what is necessary to run the service. Your real-time GPS coordinates are never uploaded — geofencing happens entirely on your device. We do not sell your data or use it for advertising.
1. Who we are
NowHere ("we", "our", "us") is a location-based reminder application available for iOS and Android. The service is operated by NowHere (nowheretasks.app). Questions can be directed to privacy@nowheretasks.app.
2. What data we collect
2.1 Account data
- Email address — used for authentication, email verification, password reset, and group invitations.
- Display name — optional, shown to group members.
- Password — stored as a one-way hash (bcrypt); we cannot recover it.
- Account preferences — preferred language, time zone, and notification settings.
2.2 Places and tasks
When you save a place, we store its name, category, coordinates (latitude and longitude), and radius. Tasks linked to a place include a title, completion status, and trigger type (on arrival, on departure, or both).
Your real-time location is never sent to our servers. Geofence events (entering or leaving a zone) are detected entirely by the operating system on your device.
2.3 Device and push tokens
To deliver push notifications (group events, invitations), we store a Firebase Cloud Messaging (FCM) token for each device you use, along with the platform (iOS/Android), app version, and the date the device was last active. We do not collect device identifiers such as IMEI, IDFA, or advertising IDs.
2.4 Group and collaboration data
If you use groups, we store the group name, membership list, role assignments, invitation history, shared list contents, and an immutable audit log of group actions (who invited whom, who was removed, etc.).
2.5 Cloud backups
When you create a backup via the app, we store a snapshot of your places, tasks, and metadata on our servers. Backups are associated with your account only and are deleted when you delete your account.
2.6 Error reports (Bugsink)
Crash reports and errors are sent to our self-hosted Bugsink instance. Reports contain a stack trace, app version, OS version, and anonymous device class. They are sanitised before transmission: email addresses, tokens, passwords, place names and task contents are stripped from every report.
2.7 Server logs
Our backend records each HTTP request: method, endpoint path, response code, latency, and an anonymous user identifier. Email addresses and request or response bodies are never written to logs. Logs are retained for 30 days.
3. How we use your data
- Provide and maintain the service (authentication, sync, backups, notifications).
- Send transactional emails you explicitly request (verification code, password reset, group invitation).
- Diagnose and fix software defects via anonymised crash reports.
- Enforce quotas associated with your subscription plan.
- Comply with legal obligations.
We do not use your data for behavioural advertising, profiling, or sale to third parties.
4. Legal basis for processing (GDPR)
If you are located in the European Economic Area, we rely on the following legal bases:
- Contract performance (Art. 6(1)(b)) — processing necessary to provide the service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — server logs and error reporting for security and reliability.
- Legal obligation (Art. 6(1)(c)) — when required by applicable law.
5. Data retention
- Account and user data — retained until you delete your account.
- Revoked device tokens — deleted within 30 days of logout or token invalidation.
- Expired invitations — purged after 7 days of expiry.
- Server access logs — 30 days.
- Backups — the 10 most recent are kept; older ones are automatically deleted. All backups are deleted when you delete your account.
- Anonymised crash reports — 90 days on our Bugsink instance.
6. Data sharing and third parties
We share personal data only with the following sub-processors, each bound by data protection agreements:
- Firebase Cloud Messaging (Google LLC) — delivery of push notifications. Only FCM tokens and notification payloads (which contain only internal identifiers, never personal content) are shared.
- SMTP provider — delivery of transactional email (verification codes, password resets, group invitations). Your email address and email content are passed to the provider solely for transmission.
- Hosting provider — our servers run on infrastructure that may be located in the EU or other jurisdictions with adequate data protection standards.
We do not share data with analytics platforms, advertisers, data brokers, or social networks.
7. International transfers
If personal data is transferred outside the European Economic Area, we ensure an adequate level of protection via Standard Contractual Clauses or equivalent safeguards as permitted by applicable law.
8. Security
We apply industry-standard security measures:
- All data in transit is encrypted via TLS 1.2 or higher.
- Passwords are stored as bcrypt hashes; we cannot retrieve them in plaintext.
- Session tokens are short-lived access tokens paired with rotating refresh tokens stored in the device's secure storage.
- The backend, database, and supporting services run in isolated Docker containers with no direct public access to the database.
9. Your rights
Depending on your location, you may have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — correct inaccurate or incomplete data.
- Erasure — request deletion of your account and all associated data.
- Portability — export your places and tasks (use the Export function in-app or email us).
- Restriction — request that we limit processing under certain conditions.
- Object — object to processing based on legitimate interests.
- Withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any right, contact us at privacy@nowheretasks.app. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
10. Account and data deletion
You may delete your account at any time:
- In-app: Settings → Privacy → Delete Account.
- By email: send a request to privacy@nowheretasks.app.
- Web form: Delete Account.
Deletion permanently removes your email, name, places, tasks, backups, group memberships, and all related data. The operation is irreversible. Residual data in anonymised logs may persist for up to 30 days.
11. Children's privacy
NowHere is not directed at children under 13 years of age (or under 16 in the EU/UK). We do not knowingly collect personal data from children. If we become aware that we have collected such data, we will delete it promptly. Contact privacy@nowheretasks.app if you believe a child's data has been collected.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated via an in-app notification or email at least 14 days before they take effect. Continued use of the service after the effective date constitutes acceptance of the revised policy.
13. Contact
Privacy enquiries: privacy@nowheretasks.app
General support: support@nowheretasks.app
Legal: legal@nowheretasks.app