Skip to content
AmidAmi
← Back to home

This is a translation of the French original for convenience. In case of any discrepancy, the French version of this policy prevails.

Privacy

Privacy policy

Version of 12 September 2026. It describes what the current version of the app and its server actually does.

In short

  • AmidAmi shows no advertising, sells no data, and measures app usage on its own servers, with no third-party tool. Crash reports, anonymous too, go to the same place — you can turn anonymous statistics and crash reports off in Settings → Anonymous statistics.
  • Your data is there to make the app work: organise a party, chat about it, keep the memory of it.
  • You can delete your account from the app, in two screens, without writing to us — see how.
  • There is a single cookie, and only if you answer an invitation without an account, from a browser. No advertising cookie.
  • AmidAmi is not meant for people under 16.

1. Who processes your data

The controller is the publisher of AmidAmi: Roméo Bernard, a natural person, on a non-professional basis. His address is not published — article 6-III-2 of the French Act on confidence in the digital economy allows this for a non-professional publisher who has given their details to their hosting provider. See the legal notice.

For any question about your data: support@amidami.app. No data protection officer has been appointed: none is required here — the processing is neither large-scale monitoring as a core activity, nor carried out by a public body.

2. What data, and what for

Nothing is collected “just in case”. Every line below matches a feature you use.

The data processed, its purpose and the matching legal basis.
Data Why Legal basis
Email, first name, last name, username, password (hashed one way) Create and keep your account, sign you in, send you a code if you forget it Performance of a contract
Apple identifier or verified Google address, if you go through “Sign in with” Recognise you from one time to the next. The profile photo of the Google account is never copied Performance of a contract
Profile photo, date of birth, phone, city, social accounts — all optional Make you recognisable to your friends. The city also serves to suggest friends near you Performance of a contract
Parties: title, description, date, free-text address, coordinates of the place, cover photo Show the party, place it on a map, add it to a calendar Performance of a contract
Answers to invitations, what each person brings, rides and seats in the car, kitty amounts, poll votes Hold the party together. A poll vote is by name: the other guests see who voted for what Performance of a contract
Messages, photos, voice messages, reactions — party chats and private ones alike The chat, before, during and after Performance of a contract
Your phone’s approximate location Show the parties around you. It is neither stored nor sent on: only your answer to the system permission triggers it Consent
A location you share in a message Tell the people in the chat where you are. It is an explicit gesture, never automatic Consent
Your device’s notification token, platform, language Send you the notifications you accepted, in your language and on the right device Consent (the permission given to the system)
Date of last activity Show “online” to your friends for the two minutes that follow Performance of a contract
Activity days, platform, OS version, app version Measure how many people come back and on which devices Legitimate interest
Anonymous telemetry: random installation identifier, usage events (screens, sign-up, coach marks, session length…) Understand where the app is difficult or unused Legitimate interest — you can object in Settings → Anonymous statistics
Anonymous crash reports: error type, cleaned message, call stack, screen, app and system version, device model, language, random installation identifier Fix the app’s defects Legitimate interest — you can object in Settings → Anonymous statistics
Support requests: subject, message, optional attachment, app version Answer your request Performance of a contract
Satisfaction: score, comment — anonymous if you choose Improve AmidAmi Legitimate interest
Sanctions and moderation decisions: reason, duration, statement of reasons sent User safety and legal obligations (DSA art. 16-17) Legitimate interest and legal obligation
Team audit log: who viewed what Protect your data from abusive access Legitimate interest
Reports and blocks: who reports, who is targeted, the reason, your comment Deal with illegal content or abusive behaviour Legitimate interest (user safety) and legal obligation to take down
Your account’s sign-in history: date, method (password, Apple, Google), app or browser type, truncated IP address Protect your account: spot a sign-in that is not yours, slow down password attempts Legitimate interest (account security)
Technical server logs: IP address, browser or device type, page requested, response code, language requested Diagnose an outage, spot abuse, limit the number of requests per address Legitimate interest (security and proper operation)
If you answer an invitation without an account: your first name, your email if you give it, a session cookie Recognise you from one visit to the next so that you find your answer and the chat again, and send you a code if you change browser Performance of a contract

What is still not collected

No advertising identifier, no bank details — the kitty only counts who paid what, and no payment goes through AmidAmi. No third-party analytics tool, and no third-party crash-reporting service: what is described below, crash reports included, goes to our own servers, and nowhere else. The app uses no font and no resource loaded from a third-party server, which would expose your IP address to that server before you had asked for anything.

The photos you send

Every image sent is re-encoded on our server: its orientation is applied, it is scaled down to 1600 pixels on its longest side, and all of its metadata is stripped along the way, including the GPS coordinates your device had written into it. The original is not kept. Two known exceptions: an animated GIF is not re-encoded (any metadata it carries remains), and a voice message is only checked for its shape, not cleaned of its tags.

How we measure usage

AmidAmi measures app usage itself, on its own servers, with no third party. Two levels, which never overlap — and, on the anonymous side, the reports sent when the app crashes.

With your account

On each day you use the app while signed in, the server records that your account was active that day, with the platform (iOS or Android), your system version and the app version — read from the X-AmidAmi-Client header the app sends on every authenticated request. This tells us how many people come back, not every gesture you make.

Without your account — anonymous telemetry

The app also sends anonymous events, tied to a random installation identifier drawn at first launch. That identifier is never linked to your account, your IP address (which is not kept), or your name. It follows the installation, not the person.

What is sent (exact list):

  • app open and return after a long absence;
  • screens you open — by a short name from a closed list (for example home, event_detail), never by a path that would contain a party or person identifier;
  • sign-up steps you reach (1 email, 2 identity, 3 password) and completed sign-up;
  • coach marks shown and the gestures they ask for;
  • that an invitation card was swiped — without saying which way;
  • end of a session, with time in the foreground;
  • your platform, system version, device family (not a hardware identifier), app version and device language.

What is never sent: your account, your parties, your friends, your messages, your location, what you write, or your IP address.

When the app crashes — anonymous crash reports

When the app closes on its own, it keeps a report of what happened on your phone and sends it at the next launch, to our servers. No third-party crash-reporting service is used. The report carries a random installation identifier, never linked to your account.

What is sent (exact list):

  • the error type and its message, cleaned on your phone before sending: email addresses, web addresses and digit sequences are removed from it;
  • the call stack, reduced to the lines of our code;
  • the screen where it happened — the same short name from a closed list as for the statistics, never a path that would contain an identifier;
  • the app version, your system version, your device model (not a hardware identifier) and the device language;
  • the installation identifier, drawn at random and not linked to your account.

What is never sent: your account, your parties, your friends, your messages, your photos, your location, what you write, or your IP address — it is not kept.

These reports serve one purpose only: fixing the app’s defects. The legal basis is legitimate interest, and you can object at any time with the same switch, Settings → Anonymous statistics. A report is kept 13 months at most; the counts drawn from it, with no identifier at all, 25 months at most.

The switch in Settings

Settings → Anonymous statistics stops sending — usage events and crash reports alike. Off: nothing more goes out, and whatever was waiting on your phone is erased. On again: a new identifier is drawn — the two periods do not join up.

The usage measurement described above falls under the CNIL consent exemption for first-party audience measurement (anonymous statistics, no cross-linking, with information and a right to object). Crash reports are not audience measurement: they rest on legitimate interest, with the same right to object. No consent banner is shown for this — and this website itself shows none either: it measures nothing.

3. Who else sees it

Four providers only, each for one precise task. No data is sold, traded or passed on to an advertiser.

Google — Firebase Cloud Messaging (notifications)

To put a notification on your phone screen, our server sends Google your device token and the text to display. That text contains the sender’s first name, the name of the party, and — for a message — its first 120 characters. This is a direct consequence of how notifications work: what appears on your lock screen has to travel through the platform’s notification service.

You can turn notifications off in your phone settings, or by type in the app: nothing is then sent. The service is provided by Google LLC (United States). The transfer outside the European Union relies on the European Commission’s standard contractual clauses and on Google’s certification under the EU–US Data Privacy Framework.

Google — Places (address search)

When you look for the address of a party, the text you type is sent to Google to offer you suggestions, then to find the coordinates of the place you picked. Nothing else leaves: not your identifier, not your location, not your IP address. The call is made by our server, precisely so that Google never sees your device. As with notifications, the service is provided by Google LLC (United States), under standard contractual clauses and the Data Privacy Framework.

OVH — hosting and email sending

The server, the database and the files you send are hosted at OVH SAS, in Europe. Transactional emails — reset code, approval of a request, new invitation link — leave from an OVH mail server, from no-reply@amidami.app. The servers are located in France, in the Hauts-de-France region: none of this data leaves the European Union.

CARTO — map tiles

The map background shown in the app comes from CARTO, based on OpenStreetMap data. Since September 2026 the app no longer asks CARTO for it directly: it asks our servers, which relay the request. CARTO therefore only sees our server’s address, in France — never yours. No data about your party is passed to it, and it has no way of knowing who is looking at what. Tiles already requested are kept on our server for thirty days: they are pictures of the world, and contain nothing about you.

Apple and Google — “Sign in with”

If you use these buttons, it is you who authorise Apple or Google to pass us your identifier and your verified email address. We send them nothing but the check on the token they handed you. If you hide your address with Apple, it is Apple’s relay address that we keep. The contracting entity is Apple Distribution International Ltd (Ireland) for Sign in with Apple, and Google LLC (United States) for Google sign-in, the latter under standard contractual clauses and the Data Privacy Framework.

Authorities

Data may be disclosed to a judicial or administrative authority on a lawful order, within the limits of what the law requires.

What the AmidAmi team sees

A small team may access some of your data to run the service, handle a report or answer support. Every named access is logged: who opened which record, who revealed an email address or phone number. The content of a private message is never read, even on a report — only moderation of content published in front of a group may require it.

4. What other people see of you

This is not hidden processing, but it is what surprises people most, so it is worth writing down.

  • Other AmidAmi members can find you by your name or your username, and see your photo and your city if you filled it in — that is what makes it possible to add you as a friend. Your contact details (email, phone, social accounts, date of birth) are never visible, except to your friends. Turn on Private account in Settings → Privacy to keep your full profile for your friends.
  • Your friends also see your contact details and when you were last active.
  • The guests of a party see your first name, your answer, what you are bringing, what you put into the kitty, your poll votes and your messages.
  • Anyone who has the share link for a party sees the title, the date, the city, the cover photo and the guests’ first names — with no account. Photos, on the other hand, only appear there if the person who took them marked them as shareable. The host can switch that link off or change it at any time.
  • A party the host has made “public” shows up in the “Discover” tab of other signed-in members, who can sign up for it. Its address is then shown only approximately. A party is private by default: that setting is the host’s choice, party by party.
  • Nobody else. There is no profile open to the web, no public directory, no indexed page: AmidAmi’s public pages carry a no-indexing instruction, and search engines are kept away from them.

Moderation and reports

You can report content or a person from the app, or write to support@amidami.app (contact point under Article 12 of the Digital Services Act).

For a party, the host receives reports about them first and can decide. Those sent to us directly, or forwarded by the host, are handled by the AmidAmi team.

Every takedown or sanction decision is made by a person, never automatically, and explained by email: the facts, the rule breached, the measure and its duration, and how to appeal ( support@amidami.app).

5. How long we keep it

Retention periods, as the server applies them.
Data Period
Your account and everything you created Until you delete your account. There is no automatic deletion for an inactive account: a forgotten account stays, and you have to delete it yourself
Photo sent as view once The file is erased 30 days after it was sent, whether it was opened or not
Data of a guest who came without an account (email, secret of their link) Erased 30 days after the party. A guest who was never approved is deleted entirely
Trace of a deleted party (name of the party, host’s first name, the account that organised it) 30 days, so that we can say “this party was cancelled” rather than “invalid link”, and so that the team can see on your record the parties you deleted
Share link of a party Stops working 30 days after the party
Session (the token that keeps you signed in) 90 days, pushed back with every use
Your account’s sign-in history 12 months, then erased. The IP address is truncated as it is written: it points to a network neighbourhood, not to your line
Password reset code 15 minutes, and 5 attempts
Technical server logs 30 days at most. They contain the IP address of the request and the type of your browser or app
Database backups 30 days at most. They are kept in France, with the same hosting provider, and only serve to bring the service back after a failure
Reports 12 months after they are handled, then erased
Installation identifier and raw anonymous telemetry events 13 months at most, then erased
Anonymous telemetry aggregates 25 months at most
Anonymous crash reports 13 months at most, then erased. The counts drawn from them, with no identifier: 25 months at most
Activity days tied to your account Erased with your account. Anonymous retention aggregates (with no identifier) may be kept
Closed support requests 24 months after the ticket is closed
Satisfaction survey responses 25 months
Sanction record on your account While your account exists — erased with it if you delete it
Team audit log 24 months

What happens when you delete your account

Deletion is immediate and final: your account, your parties and their chats, your photos, your friends, your groups, your private messages, your trophies and your recaps are erased — files included: profile photo, cover photos, images and voice messages leave the server storage at the same time. The database is changed in a single block: there is no in-between state where half your account would have gone. The details are on the Delete my account page.

A few things do not go with it, and it has to be said:

  • What other people wrote stays with them. A message a friend sent you in their own party, a photo they took, an amount they noted down: that is their data.
  • Anonymous statistics and crash reports are not tied to your account: nothing links them to you, so they cannot be deleted with it. They follow their own periods (13 months for raw events and reports, 25 months for aggregates).
  • A satisfaction comment left anonymously stays anonymous — it is not erased with your account.
  • Your support requests go with your account, attachments included.
  • A report about you, if there is one, is kept so that moderation can be dealt with, then erased 12 months after it is handled.
  • The trace of a party you had deleted (its name, your first name) runs out its 30 days, then disappears: it is what lets us tell a guest who still has the link that the party was cancelled. It is no longer tied to any account.

6. Cookies

The mobile app uses no cookie, and this site sets none.

There is a single cookie in the whole of AmidAmi, and only in one case: you open the link of a party in a browser and you answer it without an account. It is then called __Host-amidami_invite. It holds a random value — no information about you, no profile — and it serves only to recognise you from one visit to the next so that you find your answer, the chat and your photos again. It cannot be read by the page’s JavaScript, it is sent only to our server, and it lasts 90 days, pushed back with every visit.

It is a cookie strictly necessary for the service you have just asked for: it therefore needs no consent banner, and that is also why there is none. Deleting it from your browser signs you out of the party, and nothing else.

No other cookie, no pixel, no tracker, on any of our pages.

Search engines show us, in their own tools, the searches that lead to this site. That is not a measurement placed on our pages: nothing is added to our HTML, no cookie is set, and those figures are the ones Google and Bing keep about their own clicks.

7. Your rights

The GDPR gives you the right to access your data, to have it corrected, to have it erased, to object to a processing operation, to ask for its restriction, to receive it in a reusable format, and to withdraw a consent you had given.

What you can do yourself, right now

  • Correct your profile: Profile → Edit. First name, last name, username, photo, city, social accounts, all of it can be changed.
  • Change your password: Settings → Password. The other devices are signed out.
  • Turn notifications off, by type: Settings → Notifications.
  • Turn anonymous statistics off: Settings → Anonymous statistics.
  • Block someone: from their profile, or the menu on a message.
  • Delete your account: Settings → Delete my account. The details.

What goes through us

For full access, portability, an objection or a restriction, write to support@amidami.app, from the address on your account: that is what lets us check the request really comes from you, without asking you for an identity document. We answer within one month, as the GDPR provides.

To date there is no automatic export button: a portability request is handled by hand. It is slower, and it is still your right.

If our answer does not satisfy you, you can refer the matter to the Commission nationale de l’informatique et des libertés (the CNIL, the French data protection authority), 3 place de Fontenoy, 75334 Paris Cedex 07, or at cnil.fr.

8. Under-16s

AmidAmi is not meant for people under 16, and the terms of use make it a condition of access. We do not seek to collect data from minors of that age and we publish no content aimed at them.

There is no automatic age check in place: the minimum age is a self-declared condition of access. If you are the legal guardian of a child under 16 who has created an account, write to support@amidami.app: the account will be deleted.

9. Security

  • Everything travels over HTTPS. The app flatly refuses to start if its server is configured on an unencrypted address.
  • Your password is never stored: the server keeps only a hash computed with bcrypt, from which the password cannot be recovered.
  • Session tokens too are stored only as a hash. Changing your password invalidates every session open elsewhere.
  • The database is not reachable from the Internet: only the web server reaches it, over a private network.
  • Files sent in are checked on their content, not only on their name, and served in a way that no browser will ever execute them.
  • The logs mask tokens, passwords, cookies, email addresses and first names sent in a form.
  • Access to the server is restricted to a key: there is no password login. Data, on the other hand, is not encrypted at rest on its disk — better written down than claimed as a protection that does not exist.

No system is invulnerable. If you find a flaw, write to us at support@amidami.app before publishing it: we will get back to you.

10. Changes

This page changes along with the app. Its version date is at the top. If a change alters what is done with your data, it will be announced in the app before it takes effect — not slipped quietly into an update.