Huddle.
Privacy Pricing FAQ
// PRIVACY

Privacy Policy

1. An overview of data protection

We built Huddle to be the anti-social network. That means we have zero interest in your data. We use End-to-End Encryption (E2EE) to ensure your content remains strictly yours. The following policy provides a simple overview of what happens to your personal information when you visit our website or use our app, in accordance with the General Data Protection Regulation (GDPR / DSGVO).

2. Data Controller

The data processing on this website and within the app is carried out by the website operator. The responsible party (Controller) is the same entity listed in our Impressum.

Because of the nature and size of our operation, we are not legally required to appoint a dedicated Data Protection Officer (Datenschutzbeauftragter).

3. Hosting and Content Delivery

Website Hosting: Our website is hosted by ZAP-Hosting GmbH, based in Frankfurt, Germany. When you visit our website, standard server log files are collected (e.g., IP address, browser type, time of access). These are kept for a maximum of 7 days for security and debugging purposes before being automatically deleted. The legal basis for this is Art. 6(1)(f) GDPR.

App Database: The backend infrastructure for the Huddle app is powered by Supabase, hosted on Amazon Web Services (AWS) in the Frankfurt, Germany region (eu-central-1) — so your data physically stays within the European Union. We have concluded an appropriate Data Processing Agreement (DPA/AVV) with our providers to ensure your data is processed strictly according to European privacy standards.

External Fonts & Icons: For the visual design of our landing page, we use Google Fonts and Bootstrap Icons loaded via a Content Delivery Network (CDN). This means your browser establishes a connection to their servers, exposing your IP address. This is based on our legitimate interest in presenting a uniform and appealing website (Art. 6(1)(f) GDPR).

4. The Huddle App: Encryption & Metadata

The core philosophy of Huddle is privacy. We utilize the Signal Protocol to End-to-End Encrypt (E2EE) your messages, photos, notes, and lists. We physically cannot read your content.

Metadata: To route messages and make the app function, our server must process certain metadata in plaintext. Specifically, the server knows which User ID belongs to which Huddle (group), to deliver the encrypted blobs to the correct devices. This processing is strictly necessary for the fulfillment of our contract with you (Art. 6(1)(b) GDPR).

Analytics & Crash Reports: We do not use any telemetry, behavioral tracking, or crash reporting tools (like Firebase Crashlytics or Sentry) inside the app. Zero tracking means zero tracking.

5. Registration and Authentication

To use Huddle, you must create an account. You can do this via:

  • Email & Password: We store your email address securely to facilitate login and password recovery.
  • Apple / Google Sign-In: You can use third-party OAuth providers. If you do, we receive basic profile information (like your email address) to create your account.

The processing of this data is necessary to provide you with a user account (Art. 6(1)(b) GDPR).

6. In-App Purchases (Huddle+)

If you choose to upgrade to Huddle+ for more storage, the payment is processed entirely through Apple (App Store) or Google (Play Store) In-App Purchases. We do not collect, process, or store any of your financial data (like credit card numbers). We only receive a secure token confirming your purchase so we can unlock the additional storage. The processing of this status is necessary for the performance of a contract (Art. 6(1)(b) GDPR).

7. Third-Party APIs & Services

To power certain in-app features, Huddle connects to a small number of external service providers. Only the minimum data required for a given feature is transmitted, and — because your content is End-to-End Encrypted — none of these providers ever receive the content of your memories, messages, notes, or journal entries.

Weather (Open-Meteo): When you add a memory, the app can automatically attach the local weather. To do this, the approximate coordinates of the memory are sent to Open-Meteo (open-meteo.com), a European open-source weather service, which returns the weather for that location. Open-Meteo does not require an account and states that it does not track users or store personal request data.

Place names (Nominatim / OpenStreetMap): To turn GPS coordinates into a readable place name (e.g. "Munich, Germany"), the app sends those coordinates to the Nominatim geocoding service operated by the OpenStreetMap Foundation. Only the coordinates you attach to a memory are transmitted for this lookup.

Address search (Photon / komoot): When you search for a place to attach to a memory, the words you type and an approximate position (to rank nearby results first) are sent to Photon (photon.komoot.io), an open-source search service based on OpenStreetMap data and operated by komoot GmbH in Berlin. This only happens while you search.

Maps (OpenFreeMap): When the app shows a map, the map tiles for the visible area are loaded from OpenFreeMap (openfreemap.org), a free, open-source map service without accounts or tracking. Your device transmits its IP address and the requested map area to do so.

Sunrise, sunset and moon phase: These are calculated directly on your device from the memory's place and date. No data is sent anywhere for this.

Music (Apple iTunes Search): If you enable the optional music integration and search for a song, your search words are sent to Apple's public iTunes Search API (itunes.apple.com). No Apple account is involved. The cover art and the optional 30-second preview of a song are loaded from Apple's servers when you or a member of your Huddle view the memory, which transmits the viewing device's IP address to Apple.

Films, series & books (Wikidata, Wikipedia, Open Library): If you enable the optional films, series & books integration and search for a title, your search words are sent to Wikidata and Wikipedia (operated by the Wikimedia Foundation) and to Open Library (operated by the Internet Archive). Both are non-profit, open projects without accounts or advertising. Posters and book covers are loaded from their servers when you or a member of your Huddle view the memory, which transmits the viewing device's IP address.

On this day (Wikipedia): If a memory's author switches on "On this day" (an optional integration), the memory only stores that switch. When the memory is viewed, the viewing device asks Wikipedia (operated by the non-profit Wikimedia Foundation) what happened on that calendar date in history, and loads the pictures for these events from Wikimedia's servers. Only the month and day are sent, never the year, the place or any content of the memory. Wikimedia receives the viewing device's IP address.

Push Notifications (Firebase Cloud Messaging & Apple Push Notification service): To notify you about new activity in your Huddle, we use Google's Firebase Cloud Messaging (Android) and Apple's Push Notification service (iOS). These services process a device-specific push token and your IP address in order to deliver the notification. The notification payload is kept minimal and never exposes the encrypted content of your messages.

This processing is necessary to provide the features you use (Art. 6(1)(b) GDPR) or is based on our legitimate interest in a functional, reliable app (Art. 6(1)(f) GDPR).

8. Device Permissions (Access)

Huddle only asks for a permission at the moment you use the feature that needs it. Every permission is optional: if you decline, only that feature is unavailable. You can revoke any permission at any time in your device settings. Whatever the app reads through these permissions is End-to-End Encrypted before it leaves your device.

  • Location: to attach a place to a memory (optionally automatically for new memories), to look up the weather there, and to share your position with your Huddle.
  • Camera: to take photos and videos for your memories and updates.
  • Photos & media: to choose existing photos, videos and audio files, and to save media to your gallery when you ask for it. Only the items you pick are read.
  • Microphone: to record voice messages. Recording only happens while you actively record.
  • Calendar (read only): to pick a calendar event and attach it to a memory. Huddle never changes or creates calendar entries.
  • Health & fitness (read only): to attach a workout to a memory. See Section 9.
  • Journaling Suggestions (iOS): Apple's system picker suggests moments from your device. Huddle only receives the one suggestion you choose.
  • Notifications: to tell you about new activity in your Huddle (see Section 7).
  • Face ID / fingerprint: to unlock your encrypted data. The check happens entirely in your device's operating system. Huddle never receives any biometric data.
  • Technical permissions (Android): network state (to detect whether you are online), vibration (for haptic feedback), and starting after a reboot (to keep scheduled reminders).

The legal basis is your consent, given through the permission prompt of your device (Art. 6(1)(a) GDPR), and the provision of the feature you use (Art. 6(1)(b) GDPR).

9. Health & Fitness Data

Huddle includes an optional feature that lets you bring your workouts into your shared timeline — for example a run, walk, ride, or other activity — so you and the members of your Huddle can see what you did and how far you went (the distance you walked, drove, or otherwise travelled).

What we access: With your explicit permission, and only after you enable this feature, Huddle reads two types of data from your device's health & fitness platform (such as Apple Health on iOS or Health Connect / Google Fit on Android): (1) your workout / exercise records (e.g. activity type, duration, distance) and (2) the location / route data associated with those workouts. We do not access any other health data (such as heart rate, sleep, nutrition, or medical information).

How we use it: This data is used solely to display your workouts and their routes inside the app, for you and the members of your Huddle. Like all your other content, it is protected with End-to-End Encryption before it leaves your device, so we cannot read it.

What we never do: We never sell your health or fitness data, never use it for advertising or profiling, and never share it with third parties. You can revoke the health permission at any time in your device settings, and deleting the data (or your account) removes it in line with your rights under Section 10. The legal basis for processing this data is your explicit consent (Art. 6(1)(a) and Art. 9(2)(a) GDPR), which you may withdraw at any time.

10. Your Rights (DSGVO)

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access (Art. 15): Request information about your stored data.
  • Right to rectification (Art. 16): Request correction of inaccurate data.
  • Right to erasure (Art. 17): Request the deletion of your data (The "No Hostage" guarantee).
  • Right to data portability (Art. 20): Receive your data in a machine-readable format.

To exercise these rights, simply contact us via the email address provided in our Impressum. You also have the right to lodge a complaint with the competent supervisory authority.

Huddle.
Impressum Privacy

Made in Germany