Badger — Privacy Policy
Last updated: 14 July 2026
Effective date: 14 July 2026
This Privacy Policy explains how Foreverie Ltd (company number 17338477), registered office 128 City Road, London, EC1V 2NX, United Kingdom ("Foreverie", "we", "us", "our"), collects, uses, shares, and protects your personal data when you use the Badger app and related services (the "Service").
Foreverie is the data controller for the personal data described here. This Policy forms part of our Terms of Service. Terms defined there have the same meaning here.
Summary of the key points:
- We collect the data you give us (account details, Content), data generated by your use, and technical/device data.
- Some Content is end-to-end encrypted — we cannot read it and never use it for advertising or profiling.
- Personalised advertising is off by default. We only profile you for advertising if you are an adult and you turn personalised ads on yourself (see sections 4 and 9).
- We never use profiling-based or targeted advertising for users we know or reasonably believe to be under 18, whatever their settings say.
- Some data — such as your chat wallpaper and drafts — never leaves your device (see section 2.5).
- You have strong rights over your data (access, deletion, opt-out, and more).
1. Who this Policy applies to
This Policy applies to all users of the Service. If you are under the age of digital consent in your country (13–16 depending on where you live), a parent or guardian must review this Policy and consent on your behalf. Additional protections apply to minors — see section 10.
2. The personal data we collect
2.1 Data you provide:
- Account and profile data: username, phone number, email address, password (stored only as a secure hash), profile photo, status, and date of birth / age. We use your date of birth to derive whether you are an adult, which controls the advertising protections in sections 4 and 10.
- Content: messages, photos, videos, voice notes, documents, polls, and — when you choose to share them — your location and contact cards. If you edit a photo before sending it (cropping, drawing, or adding text), that editing happens on your device and we receive only the edited image you choose to send. Note that certain Content is end-to-end encrypted (see section 6).
- Content shared into Badger from other apps: if you use your device's share sheet to send a photo, video, file, link, or text into Badger, we receive that content in order to deliver it to the chat, group, or Hang you select. We do not receive anything you share into other apps.
- Hangs: the Hangs you create or join, their details (including title, description, cover image, time, and location), your attendance status, and — for public Hangs where the organiser enables ticketing — a QR ticket token issued to you and a record of your check-in.
- Contacts: if you choose to use contact-based features, information from your device's address book, used only to provide that feature.
- Communications with us: support requests, feedback, reports you submit about other users or Hangs (including the reason and any details you write), and diagnostics you choose to send us (see section 2.3).
2.2 Data generated by your use of the Service:
- Usage and activity data: features used, interactions, Hangs created, joined, or checked into, message metadata (such as sender, recipient, timing, and delivery status — but not the content of encrypted messages), and preferences.
- Product analytics: a lightweight record of in-app events (for example, "screen viewed" or "hang created") together with your user ID, app version, and platform. Analytics events never contain message content, contact details, or other personal Content — only event names and short, non-identifying parameters. You can turn this off in Settings → Diagnostics.
- Approximate and precise location: where you enable location features or Hang discovery.
- Inferences and profiles: where an adult user has turned personalised ads on, we may create inferences and audience/interest segments from the above (see section 4).
2.3 Technical, device, and diagnostic data (collected automatically):
- Device model, manufacturer, operating system, app version, language, time zone, identifiers (including advertising identifiers where permitted), IP address, and push notification tokens.
- Crash and error logs: when the app hits an error we record the error message, technical stack trace, app version, a short device description, and a "breadcrumb" trail of the last few in-app actions (event names and timestamps only — never message content). If you send us a diagnostics report from Settings → Diagnostics, that snapshot and any note you add are sent to our support team.
2.4 Data from third parties:
- Our infrastructure and advertising/analytics partners may provide us with technical, measurement, or audience data as described in section 7.
2.5 Data that stays on your device:
Some information is stored only in the app on your phone. We cannot see it, it is not uploaded to us, and it is removed when you delete the app. This includes your appearance and chat wallpaper choices, unsent message drafts, the cached results of matching your address book against Badger users, a tally of who you message most often (used to order the people suggested in invite and share pickers), and whether you have dismissed first-use tips.
3. Where the data comes from and cookies/SDKs
We collect data directly from you, automatically through your use of the app, and from our service providers and advertising/analytics partners. Our app and any websites use SDKs and similar technologies (for example, for analytics, crash reporting, push notifications, and advertising). Where required by law, we ask for your consent before using non-essential technologies, and you can manage these choices as described in section 9.
4. How and why we use your data (purposes)
We use personal data to:
(a) Provide the Service — create and manage your account, deliver messages and media, run Hangs (including issuing and validating QR tickets and recording attendance), deliver content you share into Badger from other apps, and enable the features you use.
(b) Secure the Service — authenticate you, prevent fraud, abuse, and spam, enforce our Terms, and keep the Service safe (including rate-limiting and detecting misuse).
(c) Communicate with you — send service messages, notifications, and respond to support requests.
(d) Improve and develop the Service — product analytics, crash and error diagnostics, testing, research, and troubleshooting.
(e) Personalise your experience — tailor content, suggestions, and features.
(f) Advertising and profiling (adult users who opt in only) — select, deliver, measure, and improve advertising, including profiling and targeting based on your Content (excluding encrypted Content), activity, inferred interests, and device/technical data.
Personalised advertising is off by default for everyone, everywhere. We only do this where all of the following are true: you are an adult; you have turned personalised ads on in Settings → Privacy & ads; you have not exercised "Do Not Sell or Share" or sent an opt-out signal such as Global Privacy Control; and, on iOS, you have allowed app tracking. If any of those is missing, you may still see ads, but they will be non-personalised and will not be based on profiling you. We never do this for users we know or reasonably believe to be under 18, and where we cannot establish that a user is an adult we treat them as a minor.
(g) Comply with law — meet legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims.
5. Legal bases (UK/EU users)
Where the UK GDPR or EU GDPR applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service and your account | Performance of a contract (Art. 6(1)(b)) |
| Security, fraud/abuse prevention, moderation and reporting | Our legitimate interests (Art. 6(1)(f)) in running a safe service, and compliance with our legal obligations |
| Product analytics, crash and error diagnostics | Our legitimate interests (Art. 6(1)(f)) in a reliable, working app — you can opt out in Settings → Diagnostics |
| Advertising, profiling, and targeted/personalised ads | Your consent (Art. 6(1)(a)), which you give by turning personalised ads on and can withdraw at any time |
| Service communications | Contract / legitimate interests |
| Marketing communications from us | Consent (which you can withdraw at any time) |
| Legal compliance | Compliance with a legal obligation (Art. 6(1)(c)) |
Where we rely on consent, you can withdraw it at any time without affecting prior processing. Where we rely on legitimate interests, you can object (section 9). We do not use special-category data for profiling or advertising.
6. End-to-end encryption
Certain Content is end-to-end encrypted, meaning it is encrypted on your device and readable only by the intended recipients. We cannot access, read, or use end-to-end encrypted Content, and it is never used for advertising, profiling, personalisation, or analytics. Related metadata (such as who sent a message and when) is not encrypted and may be processed as described in this Policy. If you lose access to your keys or device, encrypted Content may be unrecoverable.
7. When and with whom we share data
We share personal data only as described here. We do not share the content of end-to-end encrypted Content with anyone.
- Other users: Content and profile information you choose to share is visible to the users and groups you share it with. If you attend a ticketed Hang, the organiser can see that you have checked in.
- Service providers (processors) acting on our behalf under contract, including: Google Firebase (hosting, database, storage, authentication), Expo (push notifications), our email provider (used to deliver reports and support correspondence to our support inbox), and providers of analytics, crash reporting, and customer support.
- Advertising and analytics partners (opted-in adult users only): where an adult user has turned personalised ads on, we may share limited data — such as advertising identifiers, device/technical data, and inferred interest segments — with advertising and measurement partners to deliver and measure ads. We do not share encrypted Content, and we do not share minors' data for these purposes. Depending on how this sharing works and on applicable law, it may be considered a "sale" or "sharing" of personal information (see section 11) — you can opt out.
- Legal and safety: authorities, regulators, or third parties where we believe in good faith it is necessary to comply with law, enforce our Terms, or protect the rights, safety, or property of users, the public, or us.
- Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
We do not sell or share the content of your private messages for advertising.
8. International data transfers
We and our providers may process personal data outside the UK/EEA, including in the United States. Where we transfer data internationally, we use appropriate safeguards required by law — such as the UK International Data Transfer Agreement / Addendum and the EU Standard Contractual Clauses, together with additional measures where needed. You can request details of these safeguards using the contact details in section 14.
9. Your privacy rights and choices
Subject to applicable law, you have the right to:
- Access the personal data we hold about you and receive a copy.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), including by deleting your account in-app.
- Restrict or object to processing, including objecting to profiling and direct marketing at any time.
- Data portability — receive certain data in a portable format.
- Withdraw consent where we rely on it — including by turning personalised ads back off.
- Opt out of targeted/profiling-based advertising and, where applicable, the "sale" or "sharing" of your data (see section 11).
- Not be subject to solely automated decisions with legal or similarly significant effects (our advertising profiling does not produce such effects).
The controls in the app:
- Settings → Privacy & ads — turn personalised ads on or off (they are off until you turn them on) and exercise "Do Not Sell or Share My Personal Information".
- Settings → Diagnostics — opt out of product analytics, and choose whether to send us a diagnostics report.
- Your device settings — grant or revoke camera, microphone, photo library, location, contacts, and notification permissions, and control app tracking and your advertising identifier.
How to exercise your rights: use the in-app controls above, or contact us at support@badgerapp.co.uk. We will respond within the timeframes required by law and will not discriminate against you for exercising your rights. You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, your local Data Protection Authority.
10. Children and minors
10.1 The Service is available to users aged 13 and over. Where a user is under the local age of digital consent (13–16), we require parental or guardian consent.
10.2 We do not knowingly use the personal data of any user we know or reasonably believe to be under 18 for profiling-based or targeted advertising, and we do not "sell" or "share" minors' data for advertising. This exclusion is enforced in the app itself and cannot be overridden by a setting; where a user's age is unknown, we treat them as a minor. This reflects the EU Digital Services Act, the UK Age Appropriate Design Code (Children's Code), the GDPR, and US state-law protections for minors.
10.3 We apply heightened privacy protections for minors, including privacy-protective defaults and data minimisation for those accounts.
10.4 If you believe a child has provided us with personal data without appropriate consent, contact support@badgerapp.co.uk and we will take appropriate steps, including deletion where required.
11. US state privacy rights (California and others)
11.1 If you are a resident of California or another US state with applicable privacy law, you have rights including to know, access, correct, and delete your personal information, to opt out of targeted advertising and the "sale" or "sharing" of personal information, and to limit certain uses — and not to be discriminated against for exercising them.
11.2 Do Not Sell or Share My Personal Information / Opt out of targeted advertising: you can exercise this in Settings → Privacy & ads, by using a recognised opt-out preference signal (such as Global Privacy Control) where supported, or by contacting support@badgerapp.co.uk. Note that personalised advertising is off unless you have turned it on.
11.3 We do not knowingly sell or share the personal information of consumers under 16 without the opt-in consent required by law (and, for under-13s, we do not knowingly collect such information for these purposes at all).
11.4 To the extent we "sell" or "share" personal information (as those terms are defined by applicable law) for advertising, the categories involved are identifiers, device/technical data, and inferred characteristics of adult users who have opted in. We do not sell or share sensitive personal information for these purposes without the required consent.
12. Data retention
We keep personal data only for as long as necessary for the purposes described here, then delete or anonymise it. Retention depends on the type of data and the reason we hold it — for example:
- Account and profile data is kept while your account is active.
- Content may remain in the copies held by users you shared it with, even after you delete it or your account.
- Hang QR ticket tokens are revoked as soon as you are no longer attending the Hang.
- Analytics events, crash and error logs, and diagnostics reports are kept for a limited period for reliability and security purposes, then deleted.
- Reports of abuse are kept for as long as needed to investigate and act on them, and to handle any appeal or repeat-offender pattern.
- We may retain limited data longer where required for legal, security, fraud-prevention, or dispute-resolution reasons.
When you delete your account, we delete or anonymise your data in line with this Policy and our Terms, subject to those limited exceptions.
13. How we protect your data
We use technical and organisational measures appropriate to the risk, including end-to-end encryption for eligible Content, encryption in transit, access controls, authentication, and abuse and rate-limiting protections. No system is completely secure; we cannot guarantee absolute security, and you are responsible for keeping your device and credentials safe. We will notify you and the relevant authorities of a personal data breach where required by law.
14. Changes to this Policy and how to contact us
14.1 We may update this Policy from time to time. If we make material changes, we will provide reasonable notice (for example, in-app or by email) and, where required, obtain your consent. Changes take effect on the stated effective date. The current version is always available in the app and at www.badgerapp.co.uk/privacy.
14.2 Contact us:
Foreverie Ltd
Company number: 17338477
Registered office: 128 City Road, London, EC1V 2NX, United Kingdom
Privacy enquiries / Data Protection contact: support@badgerapp.co.uk
General support: support@badgerapp.co.uk
You have the right to lodge a complaint with your data protection authority (in the UK, the ICO at ico.org.uk).