Naxos Neighbors Privacy Policy

Effective Date: September 16, 2026

This website and the associated Naxos OD App connect people who need help ("Requesters") with partner-agency dispatch services, and the volunteers and staff who fulfill those requests ("Responders").

DATA WE COLLECT FROM EVERYONE

The following applies whether you're using the app as a Requester or a Responder — it's collected the moment the app opens, regardless of which role you're in.

Device information. We collect your phone's model, manufacturer, and operating system version and build, along with basic display information (screen size, pixel density). This is used to keep the app working correctly across different phones — we do not collect your carrier or a list of other apps installed on your device. (Your IP address is addressed separately, below.)

Push notifications. We use a token issued by our notification provider to deliver alerts to your device. The notification itself contains only a request ID and a short title — never a location or message content — so that if the notification is intercepted or visible on a lock screen, nothing sensitive is exposed.

REQUESTERS

We do not collect your name, phone number, or email address. Using the app does not create an account tied to your identity.

Location. To route your request, we collect an address you enter or confirm, which we convert to map coordinates for routing. You may enter any address, not necessarily where you are. This is captured once, at the time you submit the request — we do not monitor your location before or after that, and we hold no movement history.

Chat. If you exchange messages with a responder, that conversation exists only while your request is open, and any message older than 12 hours is deleted automatically, including from our own records.

Device identifier. We use an identifier your phone or the app assigns (not your name) to route your request back to your device and to tell whether you're a first-time or returning requester for our own reporting. We never store this identifier in raw form — it's run through a one-way cryptographic hash before it reaches our database, using a key that is rotated on a schedule and destroyed for prior periods, so that after enough time passes even we can no longer connect old records back to a device.

What happens when your request closes. When a request is completed, cancelled, or times out, we immediately and irreversibly: delete the chat history, delete the exact address and any geocoding details, replace your coordinates with a random point several hundred feet away, delete your device's push-notification token and phone model/OS details, and delete your form answers except for the small set an agency needs for service reporting (e.g., request category). What remains afterward is enough to know an agency helped someone, roughly where and when, and for what — not enough to identify you or find you again.

RESPONDERS

Responder accounts are set up by the partner agency you volunteer or work with. Your account record holds your email address, the agency you're affiliated with, and the permissions that account has been granted — nothing else.

ANALYTICS & THIRD-PARTY SERVICES

We rely on a small number of outside services to run the platform. None of them are given your name or contact information as a Requester, because we never collect it.

ServiceWhat it's used forWhat it can seeGoogle Cloud / FirebaseHosts the app, database, and all backend logicAll data the platform holds — this is our core infrastructure. For Responders, who sign in with email and password, Google's own sign-in logs (timestamp, IP) are kept under Google's retention policyFirebase Cloud MessagingDelivers push notificationsA request ID and short title onlyFirebase CrashlyticsReports app crashes so we can fix bugsPhone model and OS version at the time of a crash — no device identifierGoogle AnalyticsUnderstands which screens people use, to improve the appScreen views and taps. The entire help-request and dispatch flow is excluded — nothing about requesting or responding to help is ever sent to Analytics, and there is no way to connect Analytics data back to a specific requestCloud LoggingRecords backend activity for troubleshooting and security reviewFunction execution logs; your IP address is not retained — a filter excludes it before storage. Message content and form answers are never included

We do not use advertising services, do not sell data, and have no data-broker relationships.

YOUR RIGHTS & CONTACT

Because Requester use of the app doesn't create an identifiable account, there generally isn't a personal record for us to locate and delete beyond what's described above. Responders may contact us to ask what account information we hold or to request its correction or deletion, subject to what your affiliated agency needs to keep the platform functioning for their team.

Questions about this policy or your data: support@naxosneighbors.com

CHANGES TO THIS POLICY

We may update this policy as the platform changes. Material changes will be reflected here with an updated effective date.