Privacy Policy
Effective Date: August 26, 2026 | Last Updated: August 27, 2026
Welcome to Nezoola. This Privacy Policy explains how we collect, use, and protect your personal information, and the choices you have concerning it. By using the Nezoola app (the "Service"), you entrust us with your information, and we take that responsibility seriously. Please read this policy carefully; we want you to understand, in plain language, what data we handle and why.
Throughout this policy, "we," "us," and "our" refer to Nezoola, the operator of the Service. "You" and "your" refer to you as a user.
1. Information We Collect
1.1 Information You Provide Directly
When you use Nezoola, you share some information with us directly. This includes:
- Account details: your name, email address, and password (which we store in a securely hashed form using bcrypt), and optionally your phone number and profile picture.
- Profile information: your date of birth, gender, city, and place preferences such as favorite categories, preferred vibe, and budget range. You can update or remove any of these at any time in the app settings.
- Google account data (if you sign in with Google): your name, email address, and profile photo, exactly as Google shares them with us.
- Reviews and ratings: the written reviews and star ratings you submit for places.
- Saved places: the places you choose to bookmark for later.
- Contact form submissions: your name, email address, subject, and the content of your message.
1.2 Information We Collect Automatically
As you use the app, we automatically collect a limited amount of technical information to keep the Service working and to improve it:
- App usage analytics: screen views, search queries, feature interactions, and session data collected through Firebase Analytics, a service provided by Google. Analytics collection is opt-in and can be switched off at any time in the app settings.
- Crash and performance data: error logs, along with your device model, operating system version, and app version, collected through Firebase Crashlytics (a Google service) so we can diagnose and fix issues. This collection is opt-in alongside analytics and can also be disabled at any time in the app settings.
- Device identifiers: a Firebase Installation ID and App Instance ID (pseudonymous identifiers used by Firebase for analytics and crash reporting). These are resettable identifiers used only by Firebase (Google) for the purposes described in Section 3 of this Policy, and they are never shared with any other party, advertiser, or data broker.
- Push notification token: a device token issued by Firebase Cloud Messaging (a Google service) that lets us deliver notifications to your device about your account and content.
- Authentication metadata: login timestamps and session tokens, used to keep you signed in across your device.
- Server request logs: IP addresses, browser or app details, and request URLs, logged for security and debugging purposes.
1.3 Information We Do NOT Collect
We have designed Nezoola with privacy in mind, and there are certain things we deliberately do not collect:
- Device location. We never request location access from your device. Coordinates may be sent to Google Maps only when you explicitly type in an address for geocoding.
- Camera or photo gallery access. We never request these permissions, and the app does not currently support photo uploads. The Service may receive images through other means, such as administrative or future client-side functionality.
- Contacts or call logs.
- Advertising identifiers.
2. How We Use Your Information
We use the information we collect to provide, operate, and improve the Service. Concretely, we use it to:
- Set up and manage your account, including verifying your sign-in and keeping your session secure.
- Show, process, and display the reviews and ratings you submit.
- Respond to your inquiries and messages through the contact form.
- Send you notifications about your account and the content you interact with (you can manage these in your device settings).
- Detect, prevent, and fix technical issues so the app runs smoothly.
- Understand broadly how people use the app so we can make it better.
- Enforce our Terms of Service and keep the community safe.
3. Third-Party Services and Data Sharing
To run the Service, we rely on a small number of trusted third-party providers. Some of them may process limited information on our behalf:
- Firebase Authentication: we use your name, email address, and authentication identifiers to let you sign in and manage your account.
- Firebase Analytics: we use usage events, search queries, and feature interactions for analytics.
- Firebase Crashlytics: we use crash logs, device model, OS version, and app version for crash diagnostics.
- Google Analytics 4 Data API: we use aggregated, anonymized analytics queries for server-side reporting.
- Cloudflare R2: we use it to store and deliver images provided to the Service.
- Google Maps Platform: we use place addresses and coordinates for geocoding, which means turning an address you enter into map coordinates.
- Firebase Cloud Messaging: we use your device push token to deliver notifications about your account and content.
- Heroku (Salesforce): we use cloud application hosting, where our servers process and serve the Service.
- MongoDB Atlas: we store all user data in cloud database hosting.
- Gmail / Google SMTP: we use it to send contact-form emails and account verification emails.
You can review each provider's own privacy policy at Firebase Privacy, Cloudflare Privacy, Google Privacy, MongoDB Terms, and Salesforce Privacy.
A note on cross-border processing: some of the providers above process data outside Egypt (for example, in the United States, including our hosting provider Heroku), where data protection laws may differ from Egypt's. To respect your rights, when you create an account we present you with a dedicated consent checkbox through which you can give your express consent to this transfer. We do not transfer your data outside Egypt without that express consent. You may withdraw your consent at any time by emailing nezoola.help@gmail.com. We encourage you to review the privacy policies of these third-party services.
We do NOT sell your personal information to any third party, share it with advertisers, use it for personalized advertising, or share it with data brokers.
4. Do Not Sell My Personal Information
Nezoola never sells, trades, or otherwise transfers your personal information to outside parties for money or any other benefit, and we do not use your data for targeted advertising. If this ever changes in the future, we will update this policy and give you clear ways to opt out.
5. User-Generated Content
The reviews, ratings, and other content you submit to Nezoola are shown publicly within the app. They reflect your own opinion and are not endorsed by Nezoola, and we are not responsible for what you choose to publish. By submitting content, you grant Nezoola a non-exclusive, worldwide, perpetual, royalty-free license to display, distribute, and promote that content within the Service.
6. Data Security
We take reasonable and industry-standard measures to protect your information:
- Passwords are hashed with bcrypt (a one-way hashing method) before they are stored.
- All communication between your device and our servers is encrypted with HTTPS/TLS, enforced by our hosting provider.
- Authentication relies on short-lived JWT access tokens with secure refresh-token rotation.
- Images provided to the Service, including any review photos handled on our behalf, have their EXIF metadata (including GPS coordinates) stripped before storage.
- API access is rate-limited and restricted by origin.
- Security headers are applied to all server responses.
Even with these safeguards, no method of transmission over the Internet or electronic storage is 100% secure, so we cannot guarantee absolute security.
If we experience a data breach, we will notify Egypt's Personal Data Protection Center within 72 hours of becoming aware of it. Where required, we will also notify affected individuals no later than three working days after notifying the Center, and we will inform affected users as promptly as we can.
7. Data Retention
We keep your data only as long as needed for the purposes described in this policy:
- Account data: kept until you request deletion.
- Reviews: kept with your account; they are anonymized (attributed to "Deleted User") when you delete your account, so place ratings remain accurate for everyone.
- Refresh tokens: automatically expire after 30 days or upon logout, whichever comes first.
- Analytics data: retained by Firebase for up to 14 months.
- Crash reports: retained by Firebase for up to 90 days.
- Images provided to the Service: retained on cloud storage until you delete your account or an admin removes them.
- Server request logs: IP addresses and related request data are logged for security and debugging. These logs are written to our hosting platform's standard output and retained for a limited period managed by our hosting provider; we do not use them for any other purpose.
8. Your Rights
You have control over your personal information. You may:
- Access the personal data we hold about you.
- Correct any inaccurate personal data.
- Delete your account and all associated data.
- Request a copy of your personal data in a structured, machine-readable format (data portability).
- Opt out of analytics collection at any time in the app settings.
- Lodge a complaint with Egypt's Personal Data Protection Center.
To exercise these rights, use "Delete My Account" in the app settings, email nezoola.help@gmail.com, or submit a request at https://nezoola-deletion.pages.dev. We will respond to data requests within 30 days.
9. Account Deletion
You can delete your account at any time:
- Open the Nezoola app
- Navigate to Profile > Settings
- Tap "Delete My Account" and confirm
Deletion permanently removes your profile, preferences, saved places, authentication credentials, and images provided to the Service. Your reviews are kept but anonymized as "Deleted User" so that place ratings remain accurate for other users. Deletion is processed immediately, though some data may remain in backup systems for up to 90 days; backup copies are never restored into active use.
You may also request deletion without installing the app at https://nezoola-deletion.pages.dev, or by emailing nezoola.help@gmail.com.
10. Children's Privacy
Nezoola is not intended for children under the age of 13, and we do not knowingly collect personal information from anyone under 13. If we learn that we have collected personal data from a child under 13, we will delete it promptly. If you believe a child under 13 has provided us with personal data, please contact us at nezoola.help@gmail.com.
During account creation, we ask for your date of birth to verify that you meet our minimum age of 13. Accounts created with a date of birth indicating an age under 13 are rejected and cannot be created.
If you are 13 or 14 years old, we require the consent of a parent or legal guardian before you can use the Service. At account creation, users aged 13 to 14 must provide their guardian's name and email address and confirm that their guardian has reviewed this Privacy Policy and our Terms of Service and consents to their use of the Service. We record this guardian consent with the account. If a guardian believes their child has provided data without proper consent, they may contact us at nezoola.help@gmail.com to request deletion.
11. Child Sexual Abuse and Exploitation (CSAE)
Nezoola has zero tolerance for child sexual abuse and exploitation material (CSAM) or any content that endangers children. We do not knowingly host, display, or distribute CSAM. Our moderation process relies on user reporting and manual review. If we become aware of such content, we will:
- Remove it immediately
- Report it to the National Center for Missing & Exploited Children (NCMEC) and the relevant Egyptian authorities
- Preserve evidence and account information for law enforcement
- Permanently terminate the account of the uploader
To report suspected child safety issues, email nezoola.help@gmail.com with the subject line "Child Safety Report."
12. User-Generated Content Moderation
We moderate user-generated content to keep the Service safe and to enforce our Terms of Service. Content may be reviewed and removed if it violates our policies, including (but not limited to) spam, harassment, hate speech, false or misleading information, and intellectual property infringement. Accounts that repeatedly violate our policies may be suspended or terminated.
You can also block other users; reviews submitted by people you have blocked are hidden from your view.
If your content is removed, we will make reasonable efforts to let you know. You may appeal a moderation decision by emailing nezoola.help@gmail.com within 30 days of the removal.
13. Changes to This Policy
From time to time, we may update this Privacy Policy to reflect changes in our Service or in the law. We will notify you of any material changes by posting the updated policy in the app and updating the "Last Updated" date above. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.
14. Governing Law
This Privacy Policy is governed by and construed in accordance with the laws of Egypt. Any disputes will be subject to the exclusive jurisdiction of the courts of Egypt.
15. Contact Us