Privacy Compliance Notice: This privacy policy is designed to align with the EU General Data Protection Regulation (GDPR), UK GDPR, California Consumer Privacy Act (CCPA), and other applicable privacy laws.
1. Introduction
Welcome to Booji ("we", "our", "us", or "the App"). Booji is a private sensory and intimacy platform designed for couples and partners to share moments, expressions, and important dates. Your privacy is fundamental to us. This Privacy Policy explains how we collect, use, store, protect, and share your personal data when you use our mobile application and related services.
2. Data Controller and Contact Information
- Data Controller: Arman Ebrahimpour & Arezoo Nazerdeylami GbR (WhileTrue AI)
- Address: c/o POSTFLEX PFX-617-737, Emsdettener Straße 10, 48268 Greven, Germany
- Email: admin@whiletrue.ai
- Phone: +49 15678 336895
3. Data We Collect
3.1 Account and Profile Information
- Authentication Data: Email address, Google OAuth tokens, authentication session tokens.
- Profile Information: Name, birthdate, avatar selection, timezone.
- Relationship Data: Connection codes, partner email address.
- Status Information: Status title, expression selections, status timestamps.
3.2 Communication and Content Data
- Pulse Telemetry Data: When utilizing the Pulse feature, we collect and share device telemetry, including battery level, network connection type (Wi-Fi/Cellular), and local device mode (silent/ring).
- Moods & Expressions: Predefined emotion and expression selections shared between partners.
- Location & Weather Data: Precise location coordinates and local weather when you explicitly choose to trigger a Pulse or share location in messages.
- Anniversary and Event Data: Custom anniversary dates, event titles, and notification preferences.
- Messages: Private text messages exchanged between partners.
3.3 Device and Technical Information
- Device Information: Device model, operating system version, unique device identifiers.
- Authentication Tokens: Firebase Cloud Messaging (FCM) tokens for push notifications.
- Session Data: Login timestamps, session duration, IP addresses (temporarily stored in memory for rate limiting and security purposes).
- App Usage Data: Feature usage statistics, error reports, performance metrics.
3.4 Automatically Collected Data
- Log Data: Server logs, API access patterns, error logs.
- Crash and Diagnostic Reports: Technical diagnostic information, including non-fatal error reports and crash data, collected via Firebase Crashlytics to help us identify and fix problems.
4. How We Collect Your Data
- Direct Collection: When you create an account, complete your profile, or use app features.
- Google Sign-In: Via Google OAuth authentication service.
- Automatic Collection: Through your use of the app and interaction with features.
- Partner Sharing: When your partner shares your connection code or sends you messages.
5. Purpose and Legal Basis for Processing
5.1 Contract Performance (GDPR Art. 6(1)(b))
- User authentication and account management.
- Enabling presence sharing, expressions, and messaging between partners.
- Providing core app functionality (status sharing, anniversary reminders).
- Synchronizing data across your devices.
5.2 Consent (GDPR Art. 6(1)(a))
- Location sharing and telemetry transmission in Pulse messages (explicit consent required).
- Push notifications and marketing communications.
5.3 Legitimate Interest (GDPR Art. 6(1)(f))
- App security, fraud prevention, and abuse detection.
- Technical support and troubleshooting.
- Service optimization and performance improvement.
- Legal compliance and regulatory requirements.
7. Data Retention
7.1 Account Data
- Profile Information: Retained while account is active, deleted upon account deletion.
- Authentication Data: Sessions expire after a period of inactivity and are automatically deleted.
- Anniversary Data: Deleted when account is deleted.
7.2 Communication Data
- Messages: Each message is automatically deleted no later than 12 months after it is sent. When you delete your account, your messages are immediately made inaccessible to your partner and are then permanently erased within this 12-month window. We may retain specific records longer only where necessary to comply with a legal obligation or to establish, exercise, or defend a legal claim.
- Location Data: Deleted with associated messages.
7.3 Technical Data
- Log Data: Retained for a limited period for security and troubleshooting purposes.
- Crash and Diagnostic Reports: Retained until the underlying issue is resolved or no longer needed.
8. Your Privacy Rights
8.1 Rights for EU Residents (GDPR)
Right of Access (Art. 15)
Request a copy of all personal data we process about you, including processing purposes and recipients.
Right to Rectification (Art. 16)
Correct inaccurate or incomplete personal data directly in the app or by contacting us.
Right to Erasure (Art. 17)
Request deletion of your personal data when no longer necessary or when you withdraw consent.
Right to Restrict Processing (Art. 18)
Limit processing of your data under specific circumstances while maintaining data storage.
Right to Data Portability (Art. 20)
Request a copy of your data in a structured, machine-readable format (JSON). Contact us and we will provide your data within 30 days.
Right to Object (Art. 21)
Object to processing based on legitimate interests, including profiling and direct marketing.
Right to Withdraw Consent (Art. 7)
Withdraw previously given consent at any time without affecting the lawfulness of past processing.
8.2 Rights for UK Residents (UK GDPR)
UK residents have equivalent rights under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, including all rights listed above for EU residents.
UK Supervisory Authority: You may lodge complaints with the Information Commissioner's Office (ICO) at ico.org.uk or call 0303 123 1113.
8.3 Rights for California Residents (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of personal information collected, used, and shared about you.
- Right to Delete: Request deletion of your personal information.
- Right to Correct: Request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: See below.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
Do Not Sell or Share My Personal Information
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. Booji does not participate in data broker activities or sell user data to third parties for monetary or other valuable consideration.
8.4 Automated Decision-Making
We keep limited, pseudonymous analytics profiles (such as an age range and country) to understand how the app is used and to improve it. Booji does not use automated decision-making or profiling that produces legal or similarly significant effects on users.
9. Data Security
We implement comprehensive technical and organizational measures to protect your data:
9.1 Technical Safeguards
- Secure encryption for communications in transit and at rest.
- TLS/SSL encryption for all data transmission.
- Encrypted database storage with AWS encryption at rest.
- Secure authentication protocols and token management.
- Regular security updates and vulnerability assessments.
9.2 Organizational Measures
- Role-based access controls and need-to-know principles.
- Employee training on data protection and security.
- Regular security audits and compliance reviews.
- Incident response procedures and breach notification protocols.
10. Data Breach Notification
In case of a personal data breach:
- We will notify relevant supervisory authorities within 72 hours.
- Affected users will be informed without undue delay if the breach poses a high risk.
- We maintain detailed incident response procedures and documentation.
11. Children's Privacy
Booji is designed for users aged 16 and above. We ask for your date of birth during onboarding and do not knowingly create accounts for, or collect personal data from, children under 16. If you are under the age of legal majority where you live (typically 18), you should use Booji only with the involvement and agreement of a parent or legal guardian. If we become aware that we have collected data from a child under 16, we will delete it.
13. Changes to This Privacy Policy
We may update this privacy policy to reflect changes in our practices, legal requirements, or app features. We will:
- Notify you of material changes through the app or email.
- Provide at least 30 days' notice before changes take effect.
- Seek additional consent where required by law.
- Maintain previous versions for reference.
15. Contact Information
For privacy-related questions, exercising your rights, or data protection concerns:
Email: admin@whiletrue.ai
Response Time: Within 30 days (as required by GDPR)
When submitting a data subject rights request, please include your name, email address used in the app, and the specific right you wish to exercise. We may request additional information to verify your identity.
16. Effective Date
Version 1.0
This policy is designed to align with the GDPR, UK GDPR, CCPA/CPRA, and other applicable privacy regulations.