This Privacy Policy explains how Kang Fahrdienst (Jugmeet Singh Kang) ("INOU", "we", "us", "our") collects, uses, and protects your personal data when you use the INOU mobile application (the "App") and this website. We built INOU for sharing with people you already know, and we've tried to keep the data we collect as limited as the app's actual features require. This policy is written to comply with the EU General Data Protection Regulation (GDPR) and applicable German data protection law (BDSG).
The data controller responsible for your personal data is:
Kang Fahrdienst (Jugmeet Singh Kang)
Westendorf 6, 38315 Schladen-Werla, Germany
Email: info@inouapp.com
We have not appointed a formal Data Protection Officer, as one is not required for a business of this size and processing scope under GDPR Art. 37. All privacy inquiries can be sent to the email address above and will be handled personally by the controller.
INOU uses your mobile phone number as your identity — there is no email address and no password. To create and operate an INOU account, we collect, via Firebase Authentication:
Because we never ask for a password, there is no password for us to lose. Signing in always requires access to your phone number.
INOU's core function is letting you share photos, videos, and short text notes with people you choose — a private "bubble," an event, or a circle. Nothing you post is public: every piece of content is limited to people you have accepted, or to the members of an event or circle you belong to. When you post, we store:
This content is stored in Cloud Firestore (structured data) and Firebase Cloud Storage (photos/videos), both Google services. See Section 5 for how sharing/visibility works.
To power connections, bubbles, circles, and events, we store who you're connected to, which bubbles/circles/events you've created or joined, and the membership of those spaces.
Like virtually all cloud-connected apps, the underlying infrastructure (Firebase/Google Cloud) automatically logs limited technical data as part of operating and securing the service — such as IP address, approximate connection region, device/OS type, and app version, at the point of each request. We do not use this for advertising, and we do not operate any separate analytics, advertising, or tracking SDKs in the App.
INOU has no search, no suggestions, and no public directory. The only way to find someone is if you already have their phone number saved on your phone, and they already have an INOU account. To make that possible, the App can — with your permission — check your address book against the accounts that exist on INOU.
We have designed this so that we never receive your address book. The matching works like this:
So that your own contacts can find you in the same way, we store a hash of your own phone number, linked to your account. This hash is generated on our server from the number you already verified by SMS, and it is not readable by any other user of the App.
An honest note about hashing. We want to be straightforward about the limits of this technique rather than overstate it. A hash is not the same as anonymous data: because the total number of possible phone numbers is finite, someone with the hash and enough computing power could work backwards to the number. We therefore treat these hashes as personal data under GDPR, protect them accordingly, keep them inaccessible to other users and to the App itself, and do not claim that hashing makes them anonymous. It means your contacts' numbers never travel to us or get stored by us — which is a real and meaningful protection — but it is not the same as us being unable to identify anyone.
Your control. The App asks for contacts permission before any of this happens, and explains why at the point of asking. You can decline. If you decline, INOU still works — you simply add people another way, such as by being invited into an event or a circle by someone you know. You can grant or revoke contacts permission at any time in your device's system settings.
The legal basis for this processing is your explicit consent (GDPR Art. 6(1)(a)), given via your device's contacts permission prompt.
We do not use your location. Earlier versions of this policy described a "Shake-to-Connect" feature that used GPS to find people physically nearby. That feature has been removed from INOU, and the App no longer requests or uses location data of any kind.
| Purpose | Data Used | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Creating and securing your account | Verified phone number, device/session data | 6(1)(b) — necessary to perform our contract with you |
| Operating core app features (bubbles, circles, events, chat) | Content you post, connections, memberships | 6(1)(b) — necessary to perform our contract with you |
| Finding which of your existing contacts already use INOU | Hashes of your contacts' phone numbers, generated on your device | 6(1)(a) — your consent |
| Letting your contacts find you in the same way | A hash of your own verified phone number | 6(1)(b) — necessary to perform our contract with you |
| Displaying your profile to other users per the app's sharing model | Name, profile photo, status | 6(1)(b) — necessary to perform our contract with you |
| Responding to support requests | Email and message content you send us | 6(1)(f) — our legitimate interest in supporting our users |
| Securing the service against abuse | Technical/diagnostic data, account activity | 6(1)(f) — our legitimate interest in keeping the service safe and functional |
| Complying with legal obligations | As required by applicable law | 6(1)(c) — legal obligation |
We do not use your data for advertising, we do not sell or rent your personal data to third parties, and we do not use third-party advertising or tracking SDKs.
Other users, per your own choices. INOU is a social app — content you post is visible to whoever you chose as the audience: a specific bubble's members, everyone you're connected to, or the members of a circle or event. It is never public and never visible to people outside the audience you picked. Your name and profile photo are visible to people you're connected with, and to members of circles and events you join, consistent with the App's normal social functionality.
Our infrastructure provider. We use Firebase, a platform operated by Google (Google Ireland Limited and/or Google LLC), to host our backend: Firebase Authentication (accounts), Cloud Firestore (structured data), and Cloud Storage (photos/videos). Google processes this data on our behalf, under Google's Data Processing Addendum for Google Cloud/Firebase, and does not use it for its own purposes such as advertising.
Nobody else. We do not share your personal data with advertisers, data brokers, or any other third party, and we do not sell your data. We will only disclose data beyond the above if required by law (e.g. a valid legal request from German or EU authorities) or to protect the rights, safety, or property of INOU, our users, or the public.
Firebase/Google Cloud may process and store data on servers located outside the European Economic Area (EEA), including in the United States. Where this happens, the transfer is safeguarded by the European Commission's Standard Contractual Clauses (SCCs), which Google incorporates into its Cloud Data Processing Addendum, as a legally recognized mechanism for transferring personal data outside the EEA under GDPR Chapter V.
We retain your account and content data for as long as your account remains active. If you delete a specific piece of content (a photo, note, or message), it is removed from our active systems, subject to a short operational delay for cache/backup propagation. If you delete your account, see Section 8. We may retain minimal data longer where required to comply with a legal obligation, resolve disputes, or enforce our agreements.
You can delete your INOU account at any time from within the App (Profile → Settings → Delete Account). Because your account is tied to your phone number, deletion from inside the App requires confirming a one-time SMS code first, so that nobody else can delete your account. You can also write to info@inouapp.com, in which case we will need to verify that you control the phone number on the account before acting on the request. When you delete your account:
We aim to complete account deletion requests within 30 days, and any residual copies in backups are purged on our routine backup rotation schedule thereafter.
If you are located in the EEA, UK, or Switzerland, you have the following rights regarding your personal data, which you can exercise by contacting us at info@inouapp.com:
Die Landesbeauftragte für den Datenschutz Niedersachsen
Prinzenstraße 5, 30159 Hannover, Germany
Website: lfd.niedersachsen.de
You may also lodge a complaint with the supervisory authority in your own EU member state of residence.
We will respond to verified requests within one month, as required by GDPR Art. 12(3).
We rely on Firebase's security infrastructure, including encryption of data in transit (TLS) and at rest, and Firestore/Storage security rules that restrict read and write access to data based on your identity and the app's sharing model — for example, only members of a bubble can read what's shared to it, and only you can edit your own profile. Authentication is managed entirely by Firebase Authentication and is based on proving control of your phone number by SMS; INOU has no passwords at all, so there is no password database to be stolen. Phone number hashes used for contact matching are stored where no user of the App can read them, and are only ever accessed by our server. No system is 100% secure, and we cannot guarantee absolute security, but we take reasonable, industry-standard measures to protect your data.
INOU is not directed at, and may not be used by, children under 16 years old. Consistent with GDPR Art. 8 as implemented in Germany, we require users to be at least 16 to create an account. If we become aware that we have collected personal data from a child under 16 without appropriate consent, we will delete it promptly. If you believe a child under 16 is using INOU, please contact us at info@inouapp.com.
We do not use your personal data for automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, within the meaning of GDPR Art. 22.
We may update this Privacy Policy from time to time, for example as the App's features change. If we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the App. Continued use of INOU after a change takes effect constitutes acceptance of the updated policy.
For any question about this Privacy Policy or how we handle your data:
Kang Fahrdienst (Jugmeet Singh Kang)
Westendorf 6, 38315 Schladen-Werla, Germany
Email: info@inouapp.com