CooldleFrançais

Privacy policy

Updated: 14 September 2026 · iOS · Android · cooldle.app

1. About Cooldle and contact

Cooldle is an individually developed, non-profit project based in Belgium. For any questions about your personal data, contact: hello@cooldle.app.

This policy covers the iOS and Android app, cooldle.app and invitation links. Cooldle helps you keep intentions and arrange activities, alone or with others.

2. The data used

DataWhy Cooldle uses it
Account and authenticationPhone number, internal user ID, sender name when provided, session and verification information: identify your account, verify access and protect the service. A communications provider handles verification by SMS or fallback voice call.
Intentions and activitiesText you enter, duration, participants, roles, proposed dates and times, responses and invitation states: keep your intentions and arrange the activities you request.
Invited peopleEntered or selected phone numbers and names of participants actually added: identify recipients and deliver invitations, including to people who do not yet use Cooldle.
NotificationsCooldle user ID, iOS/Android platform and device push tokens: address notifications to devices. Transmitted content may include an invitation title and a date or time.
Operation and securityTimestamps, SMS delivery identifiers and states, anti-abuse counters, links and click information, IP addresses and HTTP metadata in logs: deliver invitations, recover their origin at registration, investigate errors and prevent abuse.
Preferences and supportInterface preferences stored on the device and, if you contact support, your email address and correspondence: adapt the interface and handle your request.

A phone number is required for authentication. Address-book access is optional: you can enter a number manually. The verification provider generates and checks verification codes; Cooldle does not retain those codes in its live verification flow.

3. Contacts and people who do not yet use Cooldle

Your entire address book is not uploaded. With your permission, it is read on your device. Only numbers you enter or select are sent to the server to check whether they belong to users and prepare the invitation. This check starts during entry or selection, before the invitation is sent. Names are transmitted for participants actually added. The list of previously added people is stored locally.

If you receive an invitation without using Cooldle, your number and, where applicable, name were supplied by the person inviting you, manually or from their contacts. They are used to deliver the invitation and retrieve it if you join Cooldle. Receiving an SMS does not create an account or constitute advertising consent.

An installation link contains a random identifier. Its server record includes the recipient’s phone number and the last store-button click. This application-level click record does not contain an IP address or browser identifier; hosting logs are separate and may contain the IP address and full link path.

For questions about the use of your data, the general contact is hello@cooldle.app. Revoking Contacts permission in your phone’s settings prevents future address-book access but does not erase invitations already recorded.

4. Purposes and legal bases

The purposes and legal bases for processing are set out below:

PurposeLegal basis
Account, intentions and requested arrangementsPerformance of the requested service, where processing is necessary to provide it.
Security, limits and abuse preventionLegitimate interests in protecting users and the service, while limiting data and retention.
Inviting non-users and retrieving invitations at registrationLegitimate interests in delivering the personal invitation requested by its initiator and allowing the recipient to retrieve it. The initiator does not consent on the recipient’s behalf.
Optional processing based on consentConsent where required, withdrawable for the future. An iOS/Android permission is not general consent to all processing.
Rights requests and legal dutiesCompliance with applicable legal obligations; handling requests and keeping the evidence needed to document their handling.

5. Who receives data?

Information needed for an invitation is shared with the people concerned according to their role: participant identity, content, proposals and responses. The sender name may appear in the SMS.

Cooldle uses technical providers for storage, hosting, phone verification, SMS delivery and notification delivery. They receive the data needed for these functions: account and invitation information, recipient numbers for telephone communications, or user IDs and device tokens for notifications.

Notification content may include an invitation title and a date or time. No phone-number field is sent to the notification relay, but free text may itself contain personal data.

The website also uses hosting and font providers; loading requests transmit technical information, including the IP address. Following a store link takes you to Apple’s or Google’s services.

6. Retention periods

Deleting active data and expiring recovery copies are separate steps. The scheduled periods below do not guarantee that all copies are erased at an exact instant.

CategoryPeriod or criterion
Active account and contentKept to provide the service until the content or account is deleted, depending on the content type. Shared invitations are addressed below.
Installation linksValid for 30 days; scheduled for deletion 37 days after creation. This deadline may be brought forward after attribution is acknowledged, but never extended by that acknowledgement.
Invitation SMS dispatch records at CooldleScheduled for deletion 30 days after creation.
Anti-abuse countersDepending on the counter: scheduled for deletion 24 hours or 7 days after the last consumption; preflight counters after 24 hours. Some counters linked to a hashed phone number survive account deletion so limits are not reset. Hashing is pseudonymisation, not anonymisation.
Automatic Firestore deletionExpiry triggers asynchronous TTL deletion. A technical delay may occur between the deadline and physical deletion.
Firestore recoveryA 7-day recovery history. Daily backups are kept for 98 days from creation; a copy made before deletion may remain until its expiry. These periods are not added together.
Push relay registrations and tokensAccording to the provider: retained while the project remains active, unless individually deleted on request. Deleting a Cooldle account does not automatically erase them.
Notification content and historyAccording to the provider: 90 days in active systems, followed by up to 30 additional days in backups.
Backend and proxy logsAccording to the provider: 90 days, followed by 30 additional days in archives/backups.
SMS provider — invitationsThe reported account setting is 30 days of data access, with optional backup storage disabled. This access period does not guarantee simultaneous erasure of all internal copies or records the SMS provider must retain.
Verification provider — authenticationVerification has separate retention rules from invitation SMS delivery. Documentation specifies a minimum 30-day retention for some personal fields; the maximum time to erase all data has not been confirmed for Cooldle.
Support and rights requestsKept while handling the request, then as needed to document its handling or resolve a dispute, within applicable legal limits.

Netlify’s site-specific log retention and the communications provider’s full retention limits have not been confirmed here. The periods stated for backend logs do not apply to Netlify logs.

7. Delete your account

In the app: use the account-deletion option in Cooldle’s settings. Uninstalling the app does not delete your server account.

A proportionate identity check may be needed to prevent deletion of someone else’s account. Never email an SMS login code or password.

The audited deletion mechanism removes the account and its sessions, invitations it initiated, relevant installation links and SMS dispatch records, and notification tokens stored by Cooldle. It removes the account’s identity from invitations initiated by other people. Necessary anti-abuse counters and recovery copies follow the periods above.

Current limitation: deleting your account erases the relevant data in Cooldle’s systems, but does not automatically erase registrations and tokens already sent to the notification relay. That data remains subject to the provider’s retention and deletion arrangements described above. Disabling notifications does not erase it either.

8. Hosting, transfers and security

The Firestore database is European, but processing is not exclusively European. According to Emergent support, the backend and application logs are hosted in the United States; platform logs and push relay data are processed in the United States and India.

Emergent states that it uses Standard Contractual Clauses for international transfers. Other providers apply their data-processing agreements and transfer mechanisms. For information about applicable safeguards and a copy of safeguards that can be disclosed, contact hello@cooldle.app.

Communications use encrypted connections. Phone numbers are masked in application logs and invitation paths are redacted there. This does not cover all infrastructure logs: proxies may record IP addresses, full paths, query parameters and HTTP metadata. According to Emergent, sensitive authentication headers are masked before storage and request/response bodies are not logged by default. Cooldle does not claim end-to-end encryption.

9. Website and permissions

This privacy page loads no third-party resources and sets no cookies. The homepage loads fonts from Google Fonts. TestFlight and Google Play buttons lead to Apple’s and Google’s services.

The /l/… invitation page has no cookies or third-party analytics; it records the chosen store to retrieve the invitation at registration. This does not prove that an installation took place. Hosting providers’ technical processing is separate.

You can change Contacts and Notifications permissions in iOS/Android settings. Disabling notifications prevents their presentation according to your device settings; it does not itself delete tokens or history already held by providers.

10. Your rights

Subject to applicable legal conditions, you can request access, correction, erasure, restriction and portability of your data, or object to processing based on legitimate interests. Where processing relies on consent, you can withdraw it for the future.

General contact: hello@cooldle.app. A response is generally required within one month; a reasoned extension may apply under the GDPR. You may complain to the Belgian Data Protection Authority or the competent authority in your country.

11. Children and teenagers

Cooldle does not currently verify users’ ages or provide a parental-consent mechanism. No minimum age for using the service has been defined. A store’s age rating concerns the app’s content.

For questions about a minor’s data, the general contact is hello@cooldle.app.

12. Changes to this policy

This policy will be updated when data use, providers or processing arrangements change. The update date is shown at the top of this page. Material changes will be communicated appropriately.

Contact: Cooldle — Belgium — hello@cooldle.app.