Privacy
Frenbar is for organising gatherings with people you already know. Several parts of it are deliberately visible to other people — that is what an invitation is — so this page is mostly about which parts, and to whom.
The short version
- There are no ads, no analytics, no tracking and no crash reporting in this app. Nothing about your use of it is sold or measured.
- Frenbar never reads your device's location. It declares no location permission. Towns are picked from a list.
- Frenbar never reads your phone's contacts. It declares no contacts permission. Everyone on your list is someone you added.
- There is no birth year anywhere — not in the app, not in storage, not in the picker.
- You cannot be searched for by name. But three features publish things on purpose, and each has its own section below: your public card, the ranking, and the links you send.
Who runs this
Frenbar is an independent app. For anything on this page — a copy of your data, a correction, or deletion — write to privacy@frenbar.app.
What Frenbar stores about you
Your account
Signing in with Google, or with an email address and a password, creates an account held by Firebase Authentication (Google), storing your email address and a user id. Signing in with Google gives us your email address, name and profile picture — not your password, and nothing else from your Google account.
Your profile
All optional: a display name, a photo, a birthday (day and month only), a country you are from, the towns you live in, up to three social handles, a free-text note of where you usually are, and your app settings.
Most of these are copied to a published profile: your name, photo, birthday, handles, country and first town. Your email address is not in it. It is readable by any signed-in Frenbar user who has your account id — which normally means someone who looked you up by your exact email address, but an account id also travels with an invitation you accept and with a ranking row, so treat the published profile as visible to people you have interacted with. Emptying a field stops publishing it.
The people you add
You may record someone's name, email address, phone number, a note, where they live, where they are from, a birthday, and your own private labels for them ("best friend", "work"). This is your address book, stored under your account, and no other Frenbar user can read it. Labels never leave it.
Please record only what you have reason to hold. Deleting someone deletes what you wrote — though their name stays on the guest list of events they were already invited to, because those are records of who was asked.
Your events
An event holds its title, place, street address and map coordinates if you add them, time, notes and guest list. Creating one publishes a copy that the invitation link opens.
That copy carries the event details and guest names — never guest email addresses, because a link can be forwarded. Each guest's answer also carries their Frenbar account id, which is how the app finds your own row. Anyone holding the link can read all of it; the link carries a long random token and is not indexed.
Deleting an event deletes everything underneath it — the public page, every answer on it, and every request left through its ask-to-come link, including the email addresses in them.
Your public card
The card is a page at frenbar.app/c/… that you can hand out
as a link or a QR code. It is readable by anyone who has that code,
with no account and no sign-in — that is its purpose.
It can carry your name, photo, one line about you, your three handles, and — only if you switch them on — your email address and phone number. It is off until you create it, and turning it off blanks the published page. Only put on it what you would put on a business card.
The ranking, only if you switch it on
Off by default. Switching it on publishes one row — how many different countries your friends come from, and up to twenty country flags — visible to any signed-in Frenbar user, beside your published name and photo. It never names your friends, but the flags do reveal the set of countries they come from. Switching it off deletes the row.
This is the only part of Frenbar that can be browsed by someone who does not already know your email address.
Links you send to other people
| Link | Who can read it | What it collects |
|---|---|---|
| Invitation | Anyone holding it | The guest's yes/no and date choices, stored against the name you already had for them. No account needed. |
| Ask to come | Anyone holding it — shows the event without the guest list | The asker confirms their email address first (through Google, or by clicking a verification email — which creates a Firebase account for them). The address is stored on the request and only you can read it. Accepting them puts them on the guest list by name, not by address. |
| Add me | Anyone holding it — shows your name so they know who they are giving details to | They type their own name, email address and optionally a birthday, verify the address the same way, and it lands in a queue only you can see. Accepting it adds them to your address book. |
Verification for the last two works by creating an account for that address so the system can send it a one-time email. If the person never finishes, that account is left behind with nothing attached to it.
The launch waitlist
The public pages offer a "tell me when it launches" box. Submitting it stores your email address, plus which link you arrived through, so we can email you once when Frenbar opens up. It is not a newsletter and it is not shared.
Nobody can read the list back — not other users, and not you through the app. To be removed, write to privacy@frenbar.app.
Notifications and reminders
The app checks periodically — roughly every fifteen minutes, and only while your phone allows it — whether anyone has answered your events, and reminds you the day before and a few hours ahead. These are produced on your phone. There is no push server, and no notification content leaves your device.
Invitation emails
When you send invitations, the app asks our server for them to be sent. The server reads the guest list from your own event and passes each guest's name and email address, the event details, your name and your address as the reply-to, to Resend, the email provider that delivers them. One message per guest — never a single message addressed to everyone, which would show the guest list to all of them. We keep a per-day count of how many recipients you have mailed, to stop the endpoint being abused.
Some builds instead hand the invitation to your own mail app for you to send. If yours does, nothing goes through our server or Resend.
Who else your data reaches
| Who | What they get | Why |
|---|---|---|
| Google (Firebase) | Everything described above | Authentication, database and hosting, on our instructions |
| Resend | Guest names and email addresses, event details, your name and reply-to address | Delivering invitation emails you chose to send |
| OpenStreetMap | The coordinates of an event's pin, and the requesting device's IP address | Drawing the small map preview. Only when an event has a pin. |
| Other Frenbar users | Only as described above | Invitations, your published profile, your card, your ranking row |
Nothing is sold. There are no advertising or analytics recipients.
Choosing a town uses a list that ships with the app and is also served from our own site; the towns themselves come from GeoNames under CC BY 4.0. If you type an address for an event, your phone's own geocoder (part of Android) turns it into coordinates.
Backups
Android may back the app up to your Google account, as it does for most apps. That backup includes the app's local data — on a phone signed out of Frenbar, that is your whole address book. Your signed-in session is excluded, so a restored backup does not carry your account with it. You can turn app backup off in Android's own settings.
Keeping and deleting
Your data is kept while your account exists. You can delete individual pieces from inside the app — a person, an event, a photo, a field, your card, your ranking row.
To delete the whole account and everything stored under it, use Delete account on the You tab — in the app, or at frenbar.app/app in a browser with nothing installed. What that removes is spelled out in full. If you cannot sign in, write to privacy@frenbar.app from the address you signed in with. You can also ask for a copy of what is stored, for a correction, or for us to stop — under the GDPR these are your rights to access, rectification, erasure, restriction, portability and objection, and you may complain to your national data protection authority.
Children
Frenbar is not intended for children under 16 and is not directed at them. If you believe a child has an account, write to us and we will remove it.
Changes
If this policy changes in a way that affects what is collected or who can see it, the date at the top changes and the app will say so before the change takes effect.