Skip to the document
Back to ein1

Legal

Privacy Policy

What ein1 collects, what it does not, who it is shared with, and how to get it deleted, described as the service is actually built.

Effective date
7 September 2026
Last updated
11 September 2026

This policy describes what ein1 does with your information, as the service is built today.

1. Who we are#

ein1 ("we", "us") is an all-in-one local discovery platform: you find local businesses, read and write reviews, share photos and videos, save places into collections, follow businesses and people, and message businesses and other users.

Data controller
Tizita Abeje Dubale, operating ein1 as an individual (sole proprietor) in Ethiopia. On the App Store and Google Play we are listed as Tizita Dubale.
Privacy contact
privacy@mail.ein1.app
Postal address
Available on request. Email privacy@mail.ein1.app

ein1 is currently operated by an individual rather than a company. We intend to transfer operation to an Ethiopian company once one is incorporated. If that happens, the company becomes the controller, we will update this page, and we will give you notice as described in §17. Your data will not be used for any new purpose as a result of that change.

This policy covers the ein1 mobile app for iOS and Android (com.ein1.app), our API at api.ein1.app, and our internal administration tools. It does not cover businesses listed in ein1, or third-party sites and apps you reach through links we display.

2. At a glance#

The short version, before the detail:

We do not sell your personal data.
Ever, to anyone, for any price.
We show no advertising.
There are no ad networks and no ad SDKs in the app.
We do not track you across other apps or websites.
We do not use the iOS advertising identifier (IDFA), the Android advertising ID, or any cross-app tracking. The app never shows the "Allow tracking" prompt because it has nothing to ask for.
We run no third-party analytics or crash-reporting SDK.
No Google Analytics, Firebase Analytics, Crashlytics, Sentry, Facebook SDK, Amplitude, Mixpanel, PostHog or Segment is bundled in the app.
We host our own infrastructure.
Our database, file storage, image processing, map tiles and address search all run on servers we operate, not on a third-party cloud service that reads your data.
Location is only collected while you are using the app.
We never request or receive background location.
The most sensitive thing we store is your search location.
See §4.2. Please read it.
You can delete your account from inside the app.
See §12.

3. What we collect, in one table#

WhatExamplesDo we need it?
Account and identityName, email address, profile handle, profile photoRequired to have an account
LocationYour device's coordinates while you search, browse nearby places, or pin a businessOptional; you can decline the permission
Content you createReviews, photos, videos, collections, messages and attachmentsOptional; only what you choose to post or send
Business ownership claimsYour name, role, phone number, email, and the proof documents you uploadOnly if you claim a business
Device and technicalNotification token, device model label, app-generated device id, platform, IP address, browser/app identifierRequired for security and notifications
Activity in the appSearches, businesses you viewed, follows, reactions, blocks, onboarding progressRequired for core features
CommunicationsThe transactional emails we send you (verification and security codes, account notices)Required for account security

Everything in that table is explained in §4. What we do not collect is in §5.

4. Information we collect, in detail#

4.1 Account and identity information#

When you create an account with an email address and password, we collect your name, email address and password. We never store your password itself, only a cryptographic hash of it. We derive a public profile handle from your name so other people can find you; you can change it at any time.

If you sign in with Google, we receive your email address, name and profile picture URL from Google. We request only the basic openid, email and profile scopes, so we cannot see your Gmail, Drive, Contacts or Calendar. We store the tokens Google issues so the sign-in keeps working. If a Google account matches an email address that already has an ein1 account, we link the two so you do not end up with duplicate profiles.

If you have not uploaded your own profile photo, we may use the Google profile picture. In that case the photo is still hosted by Google, so your device fetches it from Google each time it is displayed. Uploading your own photo replaces this.

If you sign in with Apple, we receive your email address and, the first time you sign in only, your name. Apple sends no profile picture. We request nothing beyond name and email. We store the tokens Apple issues so the sign-in keeps working, and when you permanently delete your account we ask Apple to revoke them.

Apple lets you hide your real address. If you choose Hide My Email, what we receive is an address ending in privaterelay.appleid.com that forwards to your real inbox, and we never see the address behind it. Two things follow from that. Our email to you travels through Apple's relay, and you can switch the forwarding off at any time in your Apple settings, after which our messages will no longer reach you. And because a hidden address is unique to ein1, it cannot match an account you already have, so signing in this way creates a separate profile rather than linking to an existing one. Choosing to share your real address instead lets us link the two.

We also store your role (whether you are a standard user, moderator or administrator) and, if we have had to restrict your account, the fact that it is restricted and the reason.

You may optionally add a short bio and change your display name and handle at any time.

4.2 Location information#

Please read this section carefully. It is the most privacy-sensitive processing we do.

The app asks for location permission so it can show you what is nearby. We request foreground ("while using the app") location only. We do not request, and cannot receive, background location: there is no background location tracking, no geofencing and no location history built from your movements.

Location is used in four places:

  • Nearby feed and search: an approximate fix, or your device's last known position.
  • Pinning a business on the map when you add or edit a listing: a high-accuracy fix, because a listing pinned to the wrong side of the street is not useful.
  • Address lookup: turning coordinates into a readable address, and searching for a place by name. This is answered by a geocoder we run ourselves; we do not use Google Places or Mapbox.
  • The map compass: your device's magnetic heading, to draw the direction cone. This never leaves your device.

What we retain. When you run a business search, we record the search as an analytics event: the words you typed, the categories and filters you chose, how many results you got, when it happened, whether you were on mobile or web, and the exact coordinates your device sent, not a rounded or blurred version. If you were signed in, that record is linked to your account, and our administrators can see that a named user ran a particular search from a particular point at a particular time. If you were not signed in, the record has no user attached and we have no way to attribute it to you later.

These search records are deleted after 30 days, automatically, every day. They exist so we can see what people are looking for and cannot find, and improve the directory accordingly.

Coordinates are also held briefly in short-lived caches to keep the app fast. For example, feed results are cached for a minute or two against a coarse location of roughly 110 metres, and address lookups are cached against a location of roughly 11 kilometres.

On your device, your current location is held only in memory and is gone when you close the app. Your search history is saved locally in your device's secure storage and includes the coordinates of the places you searched for; it stays on your device and is not uploaded.

Your control. You can refuse or revoke location permission in your device settings at any time. The app still works; you will be asked to enter a location instead of having it detected.

4.3 Content you create#

We store what you choose to create and post:

  • Reviews: your rating, title and review text, including replies to other reviews.
  • Photos and videos: the files you upload to businesses and reviews, plus any captions.
  • Collections: the lists you build, their names and descriptions, and the businesses in them. A private collection is visible only to you, but it is stored on our servers and is not end-to-end encrypted.
  • Messages: the text of your direct messages and messages to businesses, and any image attachments. Messages are stored on our servers so they can be delivered and re-read on your other devices. They are not end-to-end encrypted, which means we are technically able to access them; we do so only where necessary, for example to investigate a report of abuse or where the law requires it. Business conversations are a shared team inbox: anyone the business has authorised as a manager can read them.
  • Suggested edits to business listings, and the note you attach.
  • Reports you file about content, including the free-text explanation.

Photo metadata. Photos you upload are re-encoded, once on your device and again on our servers, which removes embedded metadata including any GPS coordinates stored by your camera. Videos are stored exactly as you upload them and are not re-encoded, so any metadata they carry is preserved. Documents you upload to a business ownership claim are also stored unchanged.

4.4 Business ownership claims#

If you claim a business listing, we collect the information needed to verify that you are entitled to it: your name, your position at the business, a contact phone number, a contact email address, an optional note, and the proof documents you upload (for example a business licence or registration certificate).

These documents are held in separate, private storage. Unlike the photos on a business page, they are never publicly accessible; they can only be retrieved through an authenticated request by an administrator reviewing your claim. They are deleted when the claim is deleted, and when you delete your account.

The phone number you give here is the only phone number ein1 stores, and we use it solely to verify and process the claim.

4.5 Device and technical information#

  • Notification token: if you enable notifications, a token that lets us deliver a notification to that specific device, plus the platform (iOS or Android) and the time we last saw the device.
  • Device label: your device's model name, for example "iPhone 15 Pro", so you can recognise your devices in the notification settings list. It is used for display only, never for routing or identification.
  • Device identifier: a random identifier the app generates on first launch and stores locally, so that replacing a notification token on the same device does not create a duplicate. This is not your device's hardware serial number, IDFA, Android ID or any advertising identifier, and it changes if you reinstall the app.
  • IP address and app/browser identifier: when you sign in, we record the IP address and the user-agent string of the request against your session. We use these to secure your account, to let you and us recognise unfamiliar sessions, and to detect abuse. Because a session can stay valid for up to a year while you keep using the app, this information can be retained for that long. Our web servers also write standard access logs containing IP addresses and user-agent strings; these rotate and are retained only briefly.
  • Client and platform headers: every request tells us whether it came from the mobile app or the web, and from iOS or Android.
  • Time zone offset: sent once when you sign up, so scheduled emails and times display sensibly.

We also use your IP address, in a hashed and truncated form held for 30 seconds only, to avoid counting the same search twice when you refresh. That value is never written to our database.

4.6 Your activity in the app#

To make the product work, we record:

  • Businesses you recently viewed: kept as a rolling list of your 20 most recent.
  • Searches you ran: see §4.2; deleted after 30 days.
  • Who and what you follow: users, businesses and collections.
  • Category preferences you choose during onboarding.
  • Reactions you leave on reviews.
  • Users you have blocked from messaging you, and people you have dismissed from your "people you may know" suggestions.
  • Onboarding progress: which help guides you have seen, finished or skipped.
  • Contribution counters: how many reviews, photos and listings you have added. These are derived from your content, shown on your profile, and used to rank suggestions.

Our "people you may know" suggestions are calculated fresh each time you ask for them, from your follows, shared interests and mutual connections, and cached for about ten minutes. We do not build or store a persistent behavioural or advertising profile of you.

4.7 Communications#

We send you transactional email only: your email verification code, sign-in and password-reset codes, the code that confirms an account deletion, and notices about your account's deletion status. These emails contain a code or an account notice, not your name, handle or profile data.

If you signed in with Apple and chose to hide your address, these emails reach you through Apple's relay. Turning the forwarding off in your Apple settings means they stop arriving, which also means you would not receive the codes needed to confirm or reverse an account deletion.

We do not send marketing email, and there is no mailing list to unsubscribe from.

5. What we do not collect#

We want to be specific, because "we may collect" lists are unhelpful. The app has no code that collects any of the following:

  • Contacts, address book or calendar.
  • Microphone, audio or voice recordings. (The Android build currently declares an unused microphone permission inherited from a library; nothing in the app records audio.)
  • Health, fitness, or biometric data. If you use Sign in with Apple, Face ID or Touch ID may unlock the Apple sheet on your device, but that check happens entirely on your device and no biometric information is ever sent to us or stored by us.
  • Payment or financial information. ein1 has no purchases, subscriptions or in-app payments.
  • Your date of birth, age, gender, race, ethnicity, religion, political opinions or sexual orientation.
  • Your web browsing history outside the app, or a list of the other apps installed on your device.
  • Advertising identifiers. No IDFA, no Android advertising ID, no fingerprinting.
  • IP address, user-agent, or any anonymous visitor identifier in our search analytics. The search records described in §4.2 contain none of these, which is precisely why an unsigned-in search is unattributable and stays that way.

6. How we use your information#

PurposeWhat this means in practice
Providing the appShowing nearby businesses, running searches, publishing your reviews and photos, delivering your messages, maintaining your collections and follows
Managing your accountCreating and authenticating your account, verifying your email, resetting your password, letting you change your name, handle and photo, and deleting your account
PersonalisationOrdering your feed by location and interests, suggesting people to follow, and showing your recently viewed businesses
NotificationsSending a push notification for a new message when you do not have the app open
Security and abuse preventionDetecting suspicious sign-ins, rate-limiting, investigating reports, enforcing blocks, and acting on content that breaks our rules
Understanding and improving the serviceAggregate search analytics (what people look for, where, and what returns no results) so we can fill gaps in the directory
Legal complianceMeeting our obligations and responding to lawful requests

We do not use your data for advertising, ad measurement, or automated decisions that have a legal or similarly significant effect on you.

7. Why we are allowed to use your data#

We only use your personal data where we have a proper reason to:

BasisApplies to
Performance of a contractYour account, your content, messaging, business listings and claims: the things you asked us to provide
ConsentLocation, camera and photo-library access, and push notifications. Each is requested by your device's own permission prompt, and each can be withdrawn in device settings at any time
Legitimate interestsKeeping the service secure, preventing fraud and abuse, and aggregate analytics to improve the directory, balanced against your rights, which is why our search analytics deliberately stores no IP address or device identifier
Legal obligationRetaining or disclosing data where the law requires it

8. Who we share your information with#

We do not sell personal data, and we do not share it with data brokers or advertising networks.

We use a small number of service providers who process data on our behalf:

RecipientWhat they receiveWhy
Resend (email delivery)Your email address, and the code or account notice being sentDelivering verification, sign-in, password-reset and account-deletion emails. No marketing email
Expo push service, then Apple Push Notification service / Firebase Cloud MessagingYour device's notification token, and the notification content, which for a new message is the sender's display name and roughly the first 140 characters of the messageDelivering a notification when you do not have a live connection to the app. If you do, the notification is skipped entirely
Google (Sign in with Google)The sign-in exchange itself. If your profile photo is a Google-hosted one, your device requests it from Google when displaying itSocial sign-in
Apple (Sign in with Apple)The sign-in exchange itself, and a request to revoke your sign-in when you delete your account. If you use Hide My Email, Apple also relays our email to youSocial sign-in
Expo UpdatesA request from your app checking for an updateShipping fixes without a full store release
MapLibre demo server (demotiles.maplibre.org)Your IP address, when the map renders its text labelsMap label fonts. We intend to host these ourselves; until then, this request is disclosed here
YouTube / GoogleStandard YouTube cookies and your IP address, if you play an embedded videoPlaying business videos hosted on YouTube

Everything else runs on infrastructure we operate ourselves: our database, our file storage, our image processing, our address-search geocoder and our map tiles. We do not use Google Places, Mapbox or any third-party geocoding or analytics service, so your searches and locations are not passed to one.

We may also disclose information:

  • To other users, as described in §9.
  • To a business you contact or claim: a business's authorised managers can read the messages you send it, and an administrator reviewing your claim can see the details and documents you submitted.
  • Where the law requires it: to comply with a valid legal obligation, court order or lawful request, or to protect our rights, safety, or the safety of others.
  • In a business transfer: if ein1 is acquired or merged, your data may transfer to the acquirer, who will remain bound by this policy or give you notice before changing it.

9. What other people can see#

Public: visible to anyone using ein1Private: not shown to other users
Your name, handle and profile photoYour email address
Reviews, ratings and replies you postYour direct messages and their attachments
Photos and videos you uploadYour private collections
Public collections you createWho you have blocked, and who you have dismissed from suggestions
Who you follow, and your follower countsYour search history and recently viewed businesses
Your contribution countsYour business claim details and proof documents
Businesses you have addedYour notification settings and devices

Reviews and photos you post are public by design; that is the point of a review platform. Assume anything in the left column can be seen, copied and shared by anyone.

Blocking someone stops the two of you from messaging each other. It deliberately does not hide your public profile, reviews or photos from them, and it does not affect follows or business conversations. We also do not tell someone that you have blocked them.

10. Where your data is stored, and international transfers#

Our servers are located in Europe, so your personal data is stored there. The service providers listed in §8, namely Resend, Expo, Apple and Google, may also process data in other countries in order to deliver email and notifications to you.

Wherever your data is processed, we require each provider to be bound by data-protection terms and to protect it to a standard consistent with this policy.

11. How long we keep your information#

DataRetention
Your account and profileUntil you delete your account, then as described in §12
Your reviews, photos and collectionsUntil you delete them, or delete your account
Message textKept indefinitely while the conversation exists, so both people can re-read it
Message image attachmentsThe files are deleted after 90 days to free storage; the message and a placeholder remain
Search analytics records30 days, then permanently deleted by a daily job
Recently viewed businessesYour 20 most recent only; older entries are dropped
Sign-in sessions (including the IP address and user-agent recorded against them)Up to 365 days, extended while you keep using the app; expired sessions are purged in batches
Verification, sign-in, password-reset and deletion codes5 minutes, single-use
Hashed IP used to de-duplicate searches30 seconds, in memory only
Business claim documentsUntil the claim is deleted, or you delete your account
Short-lived performance caches1 to 2 minutes for feed and search; up to 24 hours for address lookups; up to 30 days for resized images
Server access logsRotated continuously and retained only briefly
Database backupsTaken daily by an automated job, retained 30 days, then deleted

Two further points:

  • After your account is deleted, an anonymised placeholder record remains indefinitely. It holds no personal data (the name reads "Deleted user" and the email address is replaced with an undeliverable one), but the record itself is not removed. This is explained in §12.
  • Backups are kept for 30 days. An automated job on our server backs up the database once a day, and deletes any backup older than 30 days, so that we can recover from a failure or a mistake. This means that for up to 30 days after data is deleted, a copy of it may still exist in a backup. Backups are only ever used to restore the service, never to look up an individual, and they are removed automatically once they pass 30 days.

12. Deleting your account#

You can delete your account from inside the ein1 app, in your profile settings. You can also find instructions at www.ein1.app/account-deletion, or email privacy@mail.ein1.app if you have already uninstalled the app.

How it works.

  1. You request deletion and choose what happens to your content: delete my content or keep my content.
  2. We email you a six-digit code and you confirm. This step exists so that someone with brief access to your unlocked phone cannot delete your account.
  3. Your account is deactivated immediately: you are signed out of every device, and your reviews, photos and collections are hidden from everyone.
  4. You have 30 days to change your mind. Signing back in during that window, using a code we email you, restores your account and un-hides exactly what was hidden. The deadline is fixed at the moment you request deletion and never moves.
  5. After 30 days, the deletion is carried out permanently.

What is deleted permanently, either way: your sessions and sign-in credentials, your Google and Apple connections and their tokens, your notification tokens and devices, your profile photos, your follows, your blocks, your category preferences, your reactions, your recently viewed list, your onboarding progress, your search analytics records, and your business claims and their proof documents.

If you signed in with Apple, we also ask Apple to revoke the connection at their end, so ein1 no longer appears in the list of apps you have used Sign in with Apple for.

What happens to the content you posted depends on the choice you made:

Your content"Delete my content""Keep my content"
ReviewsPermanently deletedKept, shown as by "Deleted user"
Photos and videosPermanently deleted, files removed from storageKept, shown as by "Deleted user"
CollectionsPermanently deletedKept, shown as by "Deleted user"
Message textBlanked; the text is removed, the conversation remainsKept
Message attachmentsPermanently deletedKept

Please note, because it surprises people: if you choose keep my content, your reviews and photos are hidden during the 30-day window and then become visible again when the deletion completes, attributed to "Deleted user". If you want them gone, choose delete my content.

What we retain, and why:

  • Your profile record becomes an anonymised placeholder rather than being removed. Reviews, collections and conversations are permanently linked to their author in our database, so deleting the record outright would make "keep my content" impossible and would leave conversations with one side missing. The placeholder holds no personal data: the name becomes "Deleted user", the email address is replaced with an undeliverable one, and every counter is reset. Your real email address is freed, so you can sign up again with it.
  • Message text is blanked, not deleted, under "delete my content." A conversation is a record shared with another person; we remove your words but do not erase the fact that the exchange happened.
  • Reports you filed about other people's content are kept as moderation evidence. Once your account is a placeholder, they no longer identify you.
  • Businesses you added to the directory are not deleted. They are public directory entries that other people review, follow and save. If you were the sole owner of a claimed business, the business reverts to unclaimed rather than being handed to someone else.
  • We may retain the minimum necessary to comply with a legal obligation or to resolve a dispute.

Two current limitations, stated honestly:

  • If you request deletion in a web browser, there is a window of up to five minutes during which that browser session may still appear signed in. Mobile app sessions end immediately.
  • If you are the last remaining administrator, or you own a business that needs its ownership transferred first, we will tell you at the point of request and cannot complete the deletion until that is resolved. Contact privacy@mail.ein1.app and we will help.

13. Your rights#

You have the right to:

  • Access the personal data we hold about you.
  • Correct it if it is wrong.
  • Delete it.
  • Restrict or object to our processing of it.
  • Withdraw consent you previously gave, at any time.
  • Receive a copy of your data in a portable format.
  • Complain to the data protection authority in your country if you believe we have mishandled your data. We would prefer you tell us first so we can put it right.

What you can do yourself, right now, in the app:

RightHow
Change your name, handle or bioProfile, then Edit profile
Replace or remove your profile photoProfile, then Edit profile
Delete a review, photo or collectionOpen it and delete it
Turn notifications off for one device, or for your whole accountSettings, then Notifications
Stop someone messaging youTheir profile, then Block
Remove someone from your suggestionsDismiss them in "People you may know"
Turn off locationYour device's system settings
Delete your accountProfile settings, then Delete account, or www.ein1.app/account-deletion

To exercise any other right, email privacy@mail.ein1.app. We will verify that the request comes from you (we may ask you to confirm from your account's email address) and respond within 30 days.

A self-service "download your data" export does not exist yet. Until it does, email privacy@mail.ein1.app and we will compile and send you a copy of your data. Building this into the app is on our roadmap.

14. Notifications and your choices#

Push notifications have three independent switches, all of which must be on for a notification to reach you:

  1. Your device's notification permission, in system settings.
  2. This device, in the app's notification settings; useful for muting a tablet but not a phone.
  3. Your whole account, in the app's notification settings.

Muting a device survives reinstalling the app and rotating its notification token. If Apple or Google tells us a token is dead, we stop using it.

Remember that notification content, the sender's name and a short message preview, passes through Expo and then Apple or Google in order to reach your lock screen. If you do not want message previews visible, turn off notification previews in your device settings.

15. Security#

We protect your data with:

  • Encryption in transit: all traffic between the app and our servers uses HTTPS/TLS.
  • Hashed passwords: we cannot read your password and could not tell you what it is.
  • Session revocation: resetting your password signs out every session everywhere.
  • Private storage for verification documents: business claim documents are held in separate, non-public storage, reachable only through an authenticated administrator request.
  • Signed image URLs, so image links cannot be tampered with to reach other content.
  • Role-based access control, so administrative functions are limited to the accounts that need them.
  • Rate limiting on our public API.
  • A machine-to-machine interface that fails closed and is not reachable from the internet.

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you, and the relevant authorities where the law requires it, without undue delay.

16. Children#

ein1 is not intended for children under 13, and we do not knowingly collect personal data from them. We do not ask for your date of birth, so we rely on the minimum-age term in our Terms of Service.

If you believe a child under 13 has created an account, email privacy@mail.ein1.app and we will delete the account and its data. If you are between 13 and the age of majority where you live, you should review this policy with a parent or guardian.

17. Changes to this policy#

If we change how we handle your personal data, we will update this page and change the "Last updated" date. For changes that materially affect your rights, we will give you notice in the app or by email before they take effect, and where the law requires it we will ask for your consent.

18. Contact us#

Privacy and data requests
privacy@mail.ein1.app
Controller
Tizita Abeje Dubale (listed on the App Store and Google Play as Tizita Dubale), operating ein1 as an individual (sole proprietor) in Ethiopia
Postal address
Available on request. Email privacy@mail.ein1.app