Aavaaa

aavaaa pe aava — social plan-sharing app

Privacy Policy

Effective date: June 2026

1. Who we are

Aavaaa (“we”, “us”) is operated by an individual data controller based in Copenhagen, Denmark. You can reach us at admin@aavaaa.com.

2. What we collect

3. Why we collect it

To run the service: authenticate you, deliver invites + notifications, render the feed, render Memories, and let friends find you.

4. Third-party processors

We use the following sub-processors. Each receives only the data needed for its narrow purpose.

What are Standard Contractual Clauses (SCCs)? SCCs are contract terms pre-approved by the European Commission that legally bind a data recipient outside the EU to provide the same level of data protection required under GDPR. When we use a US-based processor, we have signed SCCs with them, giving you the same enforceable rights and giving EU regulators legal recourse if those commitments aren't met.

5. Data Access and Security

Aavaaa encrypts data at rest and in transit. We implement strict technical controls (Row Level Security) to ensure other users cannot access your private data, photos, or conversations without your permission.

As the data controller, Aavaaa's operator retains the technical ability to access stored data — including messages, photos, and account information — for the purposes of:

We do not access user content for any other purpose, and all administrative access is logged. We do not sell, share, or use your personal data for advertising or any purpose beyond operating Aavaaa.

If you require communications with guaranteed end-to-end encryption that even Aavaaa cannot access, we recommend using a dedicated secure messaging app for sensitive conversations.

6. Law Enforcement Requests

We may disclose your information if required to do so by law, a valid court order, or other legal process, or if we believe in good faith that disclosure is necessary to comply with a legal obligation, protect the rights, safety, or property of Aavaaa, our users, or the public, or investigate fraud or security issues.

We will only respond to legally valid requests from law enforcement or government authorities, and we carefully review each request before responding. Where legally permitted, we will make reasonable efforts to notify affected users of such requests.

7. Your rights (GDPR)

You can exercise the following rights directly inside the app at Settings → Privacy or by emailing us:

8. Deleting Your Account

To delete your Aavaaa account and all associated data, open the app and go to Settings → Data & privacy → Delete account. This permanently removes your profile, hosted plans, photos, messages, and friendships. This action cannot be undone.

If you no longer have access to the app, email admin@aavaaa.com from your registered contact with your username, and we will process your deletion request within a reasonable timeframe.

9. Data retention

Active-account data is kept until you ask us to delete it. Audit / abuse logs are kept for up to 90 days. Backups roll off Supabase's retention window (typically 7 days).

10. Security

All traffic uses HTTPS. Database access is gated by Postgres Row-Level Security policies — each row is filtered by auth.uid() at the database engine, not just the application layer. App-lock + biometric unlock is available locally.

11. Children and Age Requirements

Aavaaa requires users to be at least 13 years old globally. If you are located in the European Union, the minimum age is 16 years, in accordance with GDPR Article 8's default digital consent age. We apply the 16-year minimum EU-wide for consistency, even in EU member states (such as Denmark) that have exercised GDPR's permitted floor to lower the national minimum to 13.

We do not operate a parental consent flow. If you do not meet the minimum age for your jurisdiction, you must not create an account.

Photos and content within event Memories may incidentally include images of minors as part of family or friend gatherings. This content belongs to the uploader and is governed by this Privacy Policy. The presence of minor images in event content does not imply the app permits account creation below the minimum ages stated above.

12. Child Safety Standards

Aavaaa has zero tolerance for child sexual abuse and exploitation (CSAE) content or behavior of any kind. We are committed to protecting minors from harm.

13. Changes to this policy

We will note the new effective date at the top of this page when we make material changes. Continued use after that date constitutes acceptance.

14. Contact

Email admin@aavaaa.com for any data-protection question.


© Aavaaa, Copenhagen — Denmark. Terms of Service