DE EN
← amidu

Privacy Policy

Effective date: 2026-05-03 · Last updated: 2026-10-05

amidu ("we", "us", "our") operates the amidu mobile application (the "App"). This policy explains what personal data we collect, why we collect it, how we use and share it, and the rights you have over it.

If you have questions, contact us at [email protected].

The data controller is Amidu UG (haftungsbeschränkt), Kolonnenstr. 8, 10827 Berlin, Germany.

1. What we collect

We only collect what we need to operate the App. We do not sell personal data and we do not share it with advertisers or data brokers.

Provided by you

If you apply to a shared plan without an account

A plan on amidu can be shared as a link (amidu.app/p/…). Anyone who opens that link can apply by email, without installing the App or creating an account. If you do, we collect:

We use this to pass your request to the host and to email you about that one plan: the confirmation, the host's decision, a changed date or place, and a cancellation. The host sees your first name and your note — never your email address. We do not use the address for anything else: no newsletter, no matching, no profile.

The legal basis is your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time using the link in every email we send you about the plan, or by emailing [email protected]; withdrawal does not affect processing that already took place.

Collected automatically

What we do not collect

2. Why we collect it

PurposeData usedLegal basis (GDPR)
Send you an invitation when you ask to join the waitlistemail, reason, phone platformConsent
Create and authenticate your accountemail, Apple user IDContract
Show you to potential matches and show matches to youprofile fields, interests, location, photosContract
Deliver in-app messages and push notificationsmessages, push tokenContract
Pass your request to the host of a shared plan and email you about that plan (no account needed)first name, email, noteConsent
Send you service and product emails (profile reminders, activity updates, news about amidu)email, profile and activity dataLegitimate interest (Art. 6(1)(f))
Keep the service safe and prevent abuselogs, IPLegitimate interest
Screen what you publish for other members to see, and review reportsprofile and plan photos and text, reports and the evidence attached to them, account age and activityLegitimate interest (Art. 6(1)(f))
Understand how the App is used, and find and fix crashesapp usage and diagnosticsLegitimate interest
Comply with law (e.g. lawful requests)any of the aboveLegal obligation

We process certain special category data (such as sexual orientation and gender identity) based on your explicit consent in accordance with Art. 9(2)(a) GDPR. You may withdraw your consent at any time by deleting your account or adjusting your profile information.

Where we rely on legitimate interests (e.g. to prevent abuse and ensure the security of the service), our interest is to maintain a safe and reliable platform for all users.

Every service and product email we send carries a link that unsubscribes you with one click, and you can switch these emails off at any time in the App under Settings. That switch does not cover sign-in codes and safety emails — you need those to use and to keep your account.

Matching

We use automated processing (including matching algorithms) to suggest potential connections based on your profile information, preferences, and activity within the App. This processing does not produce legal effects or similarly significant effects on you.

Content screening

What you publish for other members to see — profile photos and their captions, your About Me, your display name, and the title, description and photo of a plan — is screened automatically when you publish it. Photos are analysed by Amazon Rekognition's image-moderation service in Frankfurt. Text is checked against pattern rules and may additionally be assessed by an AI language model (Anthropic Claude); when we use that model, only the published text, the kind of field it is and your account's trust level (below) are sent — never your account identity, your photos or your messages.

A screening result never removes anything on its own. It can hide a photo or a text field from other members until a member of our team has looked at it; you keep it — a photo or your About Me is marked "Under review" in the App — and only a person decides whether it is removed. If something is removed, we tell you by push and email, with the reason. Your private messages are not screened.

To decide how closely new content is checked, each account carries a trust level derived from its age, its activity in the App, reports made about it and our moderation decisions, whether we have verified you as a host, and the trust level of the member who invited you. It is not shown to other members and is not used for matching. Because a person makes every removal decision, this processing does not produce legal or similarly significant effects on you (Art. 22 GDPR).

3. Who we share it with

We share data only with infrastructure providers that process it on our behalf, under contract, and only as needed to run the App.

ProviderWhat they processWhere
AppleSign in with Apple, push notificationsEU/US
Amazon Web ServicesHosting, database, photo storage, automated photo screening (Rekognition)eu-central-1 (Frankfurt)
CloudflareCDN and TLS terminationGlobal edge
ResendTransactional email deliveryEU/US
Google (Firebase)App usage analytics, crash and performance reportsEU/US
PostHog (EU Cloud)App usage analytics (product usage and funnels)eu-central-1 (Frankfurt)
AnthropicAutomated screening of published profile and plan text (see "Content screening")US

We do not sell your data, and we do not share it with advertisers or data brokers. The analytics providers we use are listed above; they process usage and crash data on our behalf and may not use it for their own purposes.

If we are ever required by law to disclose data (e.g. court order), we will do so only to the extent legally required and, where lawful, notify you first.

4. International transfers

Your data is primarily stored in the EU (AWS Frankfurt). Some processors (Apple, Cloudflare, Resend, Google, Anthropic) may process data in the United States. PostHog processes analytics data solely on its EU Cloud in Frankfurt; the company is US-based, so access from there cannot be entirely ruled out. Where applicable, we rely on Standard Contractual Clauses for transfers outside the EEA.

5. Retention

When you delete your account, it is immediately hidden from everyone, and we delete or irreversibly anonymize your personal data within 30 days, except where we are required to retain specific records by law.

To prevent banned users from returning and repeated create-and-delete abuse, we retain a keyed hash of the email address and sign-in identifier — not the address itself — after deletion. It is deleted automatically after at most 12 months, or 3 years for suspended accounts (legal basis: our legitimate interest in abuse prevention, Art. 6(1)(f) GDPR).

If your account remains inactive for an extended period, we may delete or anonymize your data after providing notice, in accordance with applicable law.

6. Your rights

If you are in the EU/EEA, UK, or California you have the right to:

Where we send you service and product email on the basis of legitimate interests, you can object to it at any time and we will stop — see the bullet above. Nothing else about your account changes when you do: you keep the App, your matches and your conversations, and you keep receiving sign-in codes and safety emails, which are not marketing and are not covered by that objection.

Most of our processing is necessary to provide the service you requested (legal basis: contract). For that processing, the equivalent of "withdrawing consent" is deleting your account, which removes your personal data as described in section 5.

To exercise any of the rights that aren't self-service, email [email protected]. We respond within 30 days.

7. Children

amidu is intended for adults aged 18 and older. We do not knowingly collect data from anyone under 18. If we learn that we have, we delete it. If you believe a minor has provided us data, contact [email protected].

8. Security

We follow industry-standard practices to protect your data, including TLS for traffic in transit and access controls on the systems that store it. Profile photos are stored on AWS S3 under randomly generated per-user paths; the URLs themselves are not authenticated, so anyone who obtains a photo URL while it exists can view that photo. While these URLs are difficult to guess, they are not access-controlled. This means that anyone who obtains a valid URL may be able to view the image while it exists. Photos are deleted from storage when you delete them in the App or delete your account.

No system is perfectly secure. If we ever experience a breach affecting your data, we will notify you and the relevant supervisory authority within the timeframes required by law.

9. Changes to this policy

We may update this policy as the App evolves. If we make a material change we will notify you in the App and update the "Effective date" above. Continued use after a change constitutes acceptance.

10. Contact

Email: [email protected]
Postal address: Amidu UG (haftungsbeschränkt), Kolonnenstr. 8, 10827 Berlin, Germany