At a glance
The short version, so you don't have to read everything:
We do not collect your location. No GPS, no coordinates. The city on your profile is text you typed yourself.
Nearby discovery doesn't reveal who you are. Your phone broadcasts a random, short-lived code over Bluetooth that changes regularly — not your name, not your user ID.
We don't sell your data. ceya has no ads, no ad networks, and no advertising trackers.
Analytics only if you say yes. Until you actively agree, not a single analytics event is collected.
You can delete your account yourself, at any time, from inside the app.
ceya is for adults only — 18 and over.
1. Who is responsible for your data
Aurora GmbH Geisenhausen 4 83250 Marquartstein Germany
Managing Director: Luca Kraus Privacy contact: privacy@aurora-creation.com
Aurora GmbH is the "controller" of your personal data under the General Data Protection Regulation (GDPR).
Data Protection Officer: We have not appointed a Data Protection Officer, as the conditions under Article 37 GDPR and § 38 of the German Federal Data Protection Act (BDSG) do not currently apply to us. For any privacy matter, contact us at the address above.
This policy covers the ceya mobile app (iOS and Android) and the servers behind it. Our website has its own separate privacy policy, which you'll find there.
2. Minimum age: ceya is 18+
ceya is for people aged 18 and over.
When you register, you must enter your date of birth. If it shows you are under 18, registration stops and no account is created. We store your date of birth so we can carry out and evidence this check.
If we learn that someone under 18 has circumvented the age check, we will suspend the account and delete the data. If you are a parent who believes your child has an account, write to privacy@aurora-creation.com and we will handle it.
Because ceya is adults-only, we do not knowingly process children's data. Rules such as COPPA (United States) or Article 8 GDPR on children's consent therefore do not apply.
3. What data we process
3.1 Data you give us
| Data | Where it comes from |
|---|---|
| Email address, display name | Registration |
| Date of birth and age | Registration (age check) |
| Profile photo (avatar) | Profile — optional |
| Short bio | Profile — optional |
| Home city, as free text you type yourself (e.g. "Barcelona") | Profile — optional |
| Workplace, university | Profile — optional |
| Interests, languages | Profile — optional |
| Posts, photos, videos, comments, likes | Using the app |
| Reports about other users (reason + free text) | Reporting function |
| Your invite code and who invited you | Invite system |
Email address, display name
- Where it comes from
- Registration
Date of birth and age
- Where it comes from
- Registration (age check)
Profile photo (avatar)
- Where it comes from
- Profile — optional
Short bio
- Where it comes from
- Profile — optional
Home city, as free text you type yourself (e.g. "Barcelona")
- Where it comes from
- Profile — optional
Workplace, university
- Where it comes from
- Profile — optional
Interests, languages
- Where it comes from
- Profile — optional
Posts, photos, videos, comments, likes
- Where it comes from
- Using the app
Reports about other users (reason + free text)
- Where it comes from
- Reporting function
Your invite code and who invited you
- Where it comes from
- Invite system
3.2 Data created automatically as you use ceya
| Data | Purpose |
|---|---|
| Authentication identifiers and session data | Keeping you signed in |
| IP address | Technically unavoidable for any server request; held in server logs |
| Device and operating system information | Troubleshooting and analytics |
| Your device's push token | Delivering notifications |
| Notification history | Showing it to you in the app |
| Short-lived Bluetooth tokens | Nearby discovery (see section 4) |
| Your visibility and radar settings | So the app behaves the way you want |
Authentication identifiers and session data
- Purpose
- Keeping you signed in
IP address
- Purpose
- Technically unavoidable for any server request; held in server logs
Device and operating system information
- Purpose
- Troubleshooting and analytics
Your device's push token
- Purpose
- Delivering notifications
Notification history
- Purpose
- Showing it to you in the app
Short-lived Bluetooth tokens
- Purpose
- Nearby discovery (see section 4)
Your visibility and radar settings
- Purpose
- So the app behaves the way you want
3.3 Your connections
We store your friendships and connections. This social graph is the core of the app — without it, ceya cannot work.
3.4 What we do not collect
Stated plainly, so there's no ambiguity:
No GPS or location coordinates. Anywhere.
No phone number.
No payment data — ceya currently has no paid features.
No advertising IDs, no ad tracking, no ad networks.
No access to your contacts or address book.
4. How nearby discovery ("radar") works
This is the feature people quite reasonably look at most closely, so here is the detail.
The mechanism
Your device broadcasts a randomly generated, short-lived code over Bluetooth Low Energy (BLE) and simultaneously scans for codes broadcast by other ceya devices.
The important part: this code is not your user ID, your name, or any lasting identifier. It is random, it expires, and it is regularly replaced with a new one. Another device near you sees only a meaningless string.
For that code to become a person, the app has to ask our server — and the server checks whether your visibility settings allow the two of you to see each other at all. Without that check, nothing happens.
What this means for you
Someone intercepting Bluetooth traffic cannot use these codes to recognise you over time.
No movement profile is created. We don't store where you've been. We don't know.
No coordinates are transmitted or derived at any point.
The location permission on Android
Android itself requires apps to hold the "location" permission before they may scan for Bluetooth devices. That is Google's rule, not our choice.
We use this permission exclusively for Bluetooth scanning. Your position is never read, never stored, and never transmitted to us. There is no code in the app that requests location data.
On iOS no location permission is needed; nearby discovery there runs on the Bluetooth background modes.
Staying in control
You can switch nearby discovery off in the app at any time, and revoke the Bluetooth permission in your device settings. Radar then stops working — the rest of the app carries on.
5. Our legal bases
Article 6 GDPR requires a lawful basis for every processing activity. Here are ours:
| What we do | Legal basis |
|---|---|
| Creating and managing your account, signing you in | Art. 6(1)(b) — performance of our terms of use |
| Profile, posts, comments, likes, friendships | Art. 6(1)(b) |
| Bluetooth nearby discovery | Art. 6(1)(b) — core function of the app, backed additionally by the Bluetooth permission you grant at OS level |
| Push notifications | Art. 6(1)(a) — your consent, given through your device's system prompt |
| Product analytics (PostHog) | Art. 6(1)(a) GDPR and § 25(1) TDDDG — only with your explicit consent |
| Age verification | Art. 6(1)(c) — legal obligation |
| Reports and moderation | Art. 6(1)(f) — our legitimate interest, and that of other users, in a safe platform |
| Server logs, abuse prevention, IT security | Art. 6(1)(f) — legitimate interest in secure operation |
| Invite system | Art. 6(1)(b) |
Creating and managing your account, signing you in
- Legal basis
- Art. 6(1)(b) — performance of our terms of use
Profile, posts, comments, likes, friendships
- Legal basis
- Art. 6(1)(b)
Bluetooth nearby discovery
- Legal basis
- Art. 6(1)(b) — core function of the app, backed additionally by the Bluetooth permission you grant at OS level
Push notifications
- Legal basis
- Art. 6(1)(a) — your consent, given through your device's system prompt
Product analytics (PostHog)
- Legal basis
- Art. 6(1)(a) GDPR and § 25(1) TDDDG — only with your explicit consent
Age verification
- Legal basis
- Art. 6(1)(c) — legal obligation
Reports and moderation
- Legal basis
- Art. 6(1)(f) — our legitimate interest, and that of other users, in a safe platform
Server logs, abuse prevention, IT security
- Legal basis
- Art. 6(1)(f) — legitimate interest in secure operation
Invite system
- Legal basis
- Art. 6(1)(b)
Where we rely on legitimate interests, we have weighed them against your rights and freedoms. We're happy to explain that assessment on request.
A note on analytics specifically
The first time you open the app, we ask whether we may collect usage data to improve ceya. Until you agree, no analytics event is collected and nothing is sent to our analytics provider. You can change your decision at any time in the app under profile - settings - analytics.
6. Special categories of data — please think before you type
Some information is given extra protection under Article 9 GDPR: health, religion, political opinions, trade union membership, racial or ethnic origin, sexual orientation, and biometric data.
We do not ask for any of it and we do not want it.
But free text fields — your bio, your interests, the notes box on a report — will accept whatever you write. If you choose to put such information there, you are making it public yourself, and our processing then rests on Article 9(2)(e) GDPR.
Our advice: think carefully about what goes into a public profile. And when filing a report, please don't include sensitive information about other people unless it's genuinely relevant.
7.1 Processors acting on our behalf
These providers process personal data on our instructions. We have a data processing agreement in place with each of them under Article 28 GDPR.
| Provider | What it does | Data it receives | Where processed |
|---|---|---|---|
| Clerk (Clerk, Inc., USA) | Sign-in, account management, Google and Apple sign-in, account emails | Email, name, profile image, authentication identifiers, session and device metadata | United States |
| Neon (Neon Inc.) | Our application database | Everything stored under section 3 | AWS eu-central-1, Frankfurt |
| Cloudflare R2 (Cloudflare, Inc.) | Storage for photos and video | Profile avatars, post media | Western Europe |
| Fly.io | Running our servers | All API traffic, IP addresses | Frankfurt (fra) |
| PostHog Cloud EU | Product analytics and error reporting — only with your consent | User ID, email, app events, device and OS metadata | EU (eu.i.posthog.com) |
| Expo Push Notification Service (650 Industries, Inc., USA) | Delivering push notifications | Push tokens, notification content | United States |
Clerk (Clerk, Inc., USA)
- What it does
- Sign-in, account management, Google and Apple sign-in, account emails
- Data it receives
- Email, name, profile image, authentication identifiers, session and device metadata
- Where processed
- United States
Neon (Neon Inc.)
- What it does
- Our application database
- Data it receives
- Everything stored under section 3
- Where processed
- AWS eu-central-1, Frankfurt
Cloudflare R2 (Cloudflare, Inc.)
- What it does
- Storage for photos and video
- Data it receives
- Profile avatars, post media
- Where processed
- Western Europe
Fly.io
- What it does
- Running our servers
- Data it receives
- All API traffic, IP addresses
- Where processed
- Frankfurt (fra)
PostHog Cloud EU
- What it does
- Product analytics and error reporting — only with your consent
- Data it receives
- User ID, email, app events, device and OS metadata
- Where processed
- EU (eu.i.posthog.com)
Expo Push Notification Service (650 Industries, Inc., USA)
- What it does
- Delivering push notifications
- Data it receives
- Push tokens, notification content
- Where processed
- United States
7.2 Independent controllers
These companies decide for themselves how they handle the data, under their own privacy policies. They are not acting on our instructions:
| Provider | Context | Data involved |
|---|---|---|
| Apple (Apple Distribution International Ltd., Ireland, for users in the EEA) | App Store and TestFlight distribution, Sign in with Apple, Apple Push Notification service | Apple ID (if you use Sign in with Apple), device push tokens |
| Google (Google LLC, USA) | Google Sign-In, offered through Clerk | Your Google account identity |
Apple (Apple Distribution International Ltd., Ireland, for users in the EEA)
- Context
- App Store and TestFlight distribution, Sign in with Apple, Apple Push Notification service
- Data involved
- Apple ID (if you use Sign in with Apple), device push tokens
Google (Google LLC, USA)
- Context
- Google Sign-In, offered through Clerk
- Data involved
- Your Google account identity
Provider privacy notices: clerk.com/legal/privacy · neon.tech/privacy-policy · cloudflare.com/privacypolicy/ · fly.io/legal/privacy-policy · posthog.com/privacy · expo.dev/privacy · apple.com/legal/privacy · policies.google.com/privacy
We may also disclose data where the law requires it — for example under a court order or a lawful request from law enforcement.
8. Transfers to the United States
Some of the providers above process data in the United States. The US does not automatically offer a level of data protection equivalent to Europe's, and US authorities have access powers that EU residents can only challenge to a limited extent. We'd rather say that plainly than bury it.
We rely on two recognised transfer mechanisms:
Adequacy decision (Art. 45 GDPR) — EU-US Data Privacy Framework
These providers are certified with the US Department of Commerce under the EU-US Data Privacy Framework, for which the European Commission has found an adequate level of protection:
Clerk, Inc. — certified under the EU-US DPF, the UK Extension, and the Swiss-US DPF
Google LLC — certified under the EU-US DPF, the UK Extension, and the Swiss-US DPF
Standard Contractual Clauses (Art. 46(2)(c) GDPR)
For these providers, the European Commission's Standard Contractual Clauses apply:
650 Industries, Inc. (Expo) — Standard Contractual Clauses, Module Two (controller to processor)
Apple — for users in the EEA the controller is Apple Distribution International Limited in Ireland; Apple's onward transfers to the United States are governed by Standard Contractual Clauses
We will provide copies of the Standard Contractual Clauses on request at privacy@aurora-creation.com.
9. How long we keep data
| Data | Retention |
|---|---|
| Account and profile data | Until you delete your account |
| Posts, photos, videos, comments, likes | Until you delete them, or delete your account |
| Bluetooth tokens | Very briefly — they expire automatically and are replaced |
| Push tokens | Until account deletion, or until the token becomes invalid |
| Notification history | Until account deletion |
| Reports about users | 12 months after the report is resolved, then anonymised |
| Server logs (Fly.io) | 7 days |
| Database backups (Neon) | Deleted data remains technically restorable for 6 hours, after which it is gone |
Account and profile data
- Retention
- Until you delete your account
Posts, photos, videos, comments, likes
- Retention
- Until you delete them, or delete your account
Bluetooth tokens
- Retention
- Very briefly — they expire automatically and are replaced
Push tokens
- Retention
- Until account deletion, or until the token becomes invalid
Notification history
- Retention
- Until account deletion
Reports about users
- Retention
- 12 months after the report is resolved, then anonymised
Server logs (Fly.io)
- Retention
- 7 days
Database backups (Neon)
- Retention
- Deleted data remains technically restorable for 6 hours, after which it is gone
We deliberately keep reports longer than other data, including beyond account deletion. Otherwise someone could escape a ban simply by deleting their account and signing up again. This protects other users, and rests on our legitimate interest in a safe platform (Art. 6(1)(f) GDPR).
10. Your rights
Under the GDPR you have the following rights. Exercising them is free, and we respond within one month.
Access (Art. 15) — what data we hold about you
Rectification (Art. 16) — correcting inaccurate data
Erasure (Art. 17) — the "right to be forgotten"
Restriction of processing (Art. 18)
Data portability (Art. 20) — your data in a machine-readable format
Objection (Art. 21) — to processing based on legitimate interests
Withdrawal of consent (Art. 7(3)) — at any time, with effect for the future. What happened lawfully before your withdrawal is unaffected.
In practice:
Delete your account: in the app under Profile → Settings → Delete account, then confirm
Withdraw analytics consent: in the app under Profile → Settings → Analytics, then confirm turning them off
Turn off push notifications: in your device's system settings
Anything else: email privacy@aurora-creation.com
Right to complain
You can lodge a complaint with a data protection supervisory authority at any time. Ours is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 18, 91522 Ansbach, Germany poststelle@lda.bayern.de
You may also complain to the authority where you live or work.
11. What happens when you delete your account
You can delete your account yourself at any time, under Profile → Settings → Delete account. You'll be asked to confirm once more.
Deletion is immediate and permanent. There is no recovery period. If you sign up again later, you start with an empty account.
Deleted:
- your profile and everything on it,
- your posts, comments and likes,
- your uploaded photos and videos, including the underlying files in our object storage,
- your friendships and connections,
- your push tokens and notification history,
your sign-in account at Clerk.
Retained:
Reports you were involved in, for the 12 months set out in section 9.
Database backups still contain deleted data for up to 6 hours. After that it is gone from there too.
12. Security
We protect your data with measures including:
Encrypted transport (TLS) between the app and our servers
Encrypted credential storage on your device — via the iOS Keychain and the Android Keystore
Cryptographically secure random values for Bluetooth tokens
Access controls — only people who need data for their work can reach it
EU server locations for our database, object storage and application servers
Nobody can promise absolute security. If a breach occurs that poses a risk to you, we will notify you and the supervisory authority as required by Articles 33 and 34 GDPR.
13. Where ceya is available, and what that means for you
ceya is offered in the European Economic Area, the United States and Canada. Wherever you live, we apply the standard described in this policy to everyone.
United States. The California Consumer Privacy Act (CCPA/CPRA) applies to businesses above certain size thresholds, which Aurora GmbH does not currently meet. Regardless: we do not sell your personal information, we do not share it for cross-context behavioural advertising, and we receive no consideration for passing it on. Send access and deletion requests to privacy@aurora-creation.com and we will handle them exactly as described in section 10.
Canada. Under PIPEDA you have the right to know what data we hold about you and how we use it, and to have inaccurate data corrected. Complaints go to the Office of the Privacy Commissioner of Canada. Residents of Québec have additional rights under Law 25, including data portability; the person accountable for privacy at Aurora GmbH is the Managing Director, reachable at privacy@aurora-creation.com.
14. Changes to this policy
As ceya develops, this policy may change. We will tell you about significant changes in the app or by email before they take effect. The date at the top always shows the current version.
15. Contact
Questions, concerns, complaints — get in touch:
Aurora GmbH Geisenhausen 4, 83250 Marquartstein, Germany privacy@aurora-creation.com