#Privacy Policy

Effective date: 7 May 2026 Last updated: 29 July 2026

Note on the data controller. The 1fifty mobile application is operated by 1fifty BV (Belgium, VAT BE1038210695), the incorporated legal entity that acts as the data controller for the processing described in this Privacy Policy. References to “we”, “us”, and “our” in this Privacy Policy refer to 1fifty BV. Any future change of the controlling legal entity will be reflected here and notified to you through the Service.


#1. Introduction

This Privacy Policy describes how 1fifty BV (“we,” “us,” or “our”) collects, uses, shares, retains, and protects information when you use the 1fifty mobile application and any related services (collectively, the “Service”). It is provided so you can understand our processing activities and exercise your data-protection rights; it does not replace any consent that we must separately request from you.

We may update this Privacy Policy from time to time. When we make material changes we will notify you through the Service or by other means (e.g., email) and update the “Last updated” date above. Where a change requires your consent, we will request it before relying on that consent.


#2. Information We Collect

#2.1 Information You Provide Directly

CategoryExamples
Account informationEmail address; first and last name (optional at sign-up); profile photo.
Authentication credentialsPasswords (managed and hashed by Supabase Auth); one-time passcodes (OTP) delivered by email; multi-factor authentication (MFA) tokens and factor names (TOTP).
Third-party sign-inWhen you sign in with Google, Apple, or LinkedIn, we receive the identifier, email address, display name, and profile image made available by the provider.
Workspace dataEvery account is provisioned with a personal workspace at sign-up. Workspace name, region, and member metadata are stored alongside your account.
ContactsNames, email addresses, phone numbers, physical addresses, websites, social-media handles, industry tags, labels, free-text notes, and any other information you enter about your contacts.
CompaniesCompany name, legal form, registration number, headquarters address (including geographic coordinates), email addresses, phone numbers, websites, social-media handles, free-text notes, and company logos.
Business-card scans and imagesPhotos of business cards, avatars, and other images you upload or capture. When you use the scanner, we may also store geographic coordinates (latitude and longitude) of the location where the card was scanned, if location permission is granted. Embedded image metadata (EXIF, including GPS coordinates) is re-encoded out before business-card images are persisted to private storage; uploads that cannot be re-encoded are rejected rather than stored with metadata intact.
Tasks and eventsTask titles, descriptions, due dates, reminders; event names, descriptions, locations (including coordinates), dates, and associated URLs.
Templates and labelsReusable message templates (title, subject, body) and custom labels you create.
Free-text “context” fieldsFree-text instructions or context you may enter to guide AI features (e.g., enrichment hints).
AI chat conversationsMessages you send to the in-app AI chat assistant, the assistant’s responses, and any images you attach to a chat message — including the contact, company, note, task, and event data the assistant reads from your workspace in order to answer you. Conversations are stored as chat history in your account until you delete them, until your chat-retention setting removes them, or until your account is deleted (see Section 5).
Voice-dictation audioShort voice-dictation audio (up to 90 seconds), captured only while you are actively dictating into a freeform text field. The audio is transcribed to text by our speech-recognition sub-processor and is not retained after transcription (see Groq in Section 4.1).
FeedbackMessages, optional screenshots, and your name and email (pre-filled from your account) when you use the in-app feedback feature.
Status-page subscriptionsIf you subscribe to incident notifications on our public status page (status.1fifty.ai), the email address you provide is stored by our status-page provider (BetterStack — see Section 4.1) and used solely to send incident and maintenance notifications. You may unsubscribe at any time from any notification email.

#2.2 Information Collected Automatically

CategoryExamples
Product-analytics eventsPseudonymous user identifier; app lifecycle events (open, foreground, background); screen views; feature-interaction events from the catalog defined in apps/mobile/lib/analytics/events.ts (e.g., contact_created, event_list_sorted). Events do not include names, email addresses, phone numbers, notes, or other free-text user content.
Session replaysWhen session replay is enabled in production builds, the Service captures screen recordings and user-interaction events for diagnostic and product-improvement purposes. All text inputs are masked by default. Screens, modals, and overlays that surface freeform user content (notes, AI output, scanned-card OCR, share-extension payloads, OTP echoes, payment card numbers) are masked at the view-tree level — including any text and images they contain — so their content is not captured. Rendered content on other screens, including decorative app imagery and your own profile imagery, may appear in captured replay frames.
Usage recordsFeature-level usage counts (e.g., card extractions, contact cleanups, company enrichments, employee searches) used to enforce plan limits and bill on-demand consumption.
Technical and diagnostic dataWhen crash and error reporting is enabled: crash reports, stack traces, performance metrics, breadcrumbs, and device/app identifiers.
Audit logsFor security purposes we log: user identifier, email address, IP address, user-agent string, request identifier, action type (e.g., sign-in, sign-up, OTP verification, account deletion), affected resource type and identifier, and success/failure status.
Server logsStructured request logs (HTTP method, path, response status, response time, request identifier) used for operational monitoring, rate-limiting, and security investigations. IP addresses appear in transient rate-limit counters and short-lived logs and are not retained beyond the periods set out in Section 5.

#2.3 Information from Device Permissions

The Service may request the following device permissions. You can grant or revoke any permission at any time in your device settings.

PermissionData accessedPurpose
CameraStill images captured by your device camera.Scanning business cards, capturing QR codes, and taking profile photos.
Photo library (read)Images you select from your device’s photo library.Choosing avatars, uploading business-card images, attaching screenshots to feedback.
Photo library (write)Permission to save images you’ve created with the Service.Saving scanned business-card images and downloaded contact photos to your library.
Contacts (read and write)Names, phone numbers, email addresses, physical addresses, URLs, social profiles, photos, company names, and job titles from your device’s contact book.Importing your device contacts into the Service, and — when you enable two-way contact sync — writing changes you make in 1fifty back to your device contact book. The Service does not write to your device contacts unless you explicitly enable contact sync.
Location (foreground only)Approximate or precise geographic coordinates while the app is in use.Geo-tagging scanned business cards; suggesting nearby places when you add a meeting location. The Service does not use background location.
NotificationsPermission to display notifications.Event-prep reminders, follow-up reminders, and task alerts, and — through the in-app support chat — remote support and operator messages delivered via Apple Push Notification service (iOS) or Google Firebase Cloud Messaging (Android). See Section 4.1.
Microphone (foreground only)Short voice recordings captured only while you are actively dictating (up to 90 seconds).Voice-to-text dictation for freeform text fields (notes, context, descriptions). Recording occurs only during an active dictation; the Service does not use the microphone in the background.

The Service explicitly disables and does not request: background location, calendar, reminders, SMS, call-log, or always-on biometric permissions.

#2.4 Information from Third-Party Data Sources

SourceData receivedPurpose
CoreSignalProfessional profiles (names, job titles, employment history, education, skills, professional email addresses, LinkedIn URLs) and company profiles (name, industry, workforce data, financials, addresses, social URLs).Employee and company search, enrichment, and data-collection features.
Google PlacesAddress predictions and place details (formatted address, coordinates).Address autocomplete when entering company headquarters or event locations.
Google Programmable/Custom SearchPublic-web image-search results matching a contact’s or company’s name: candidate image URLs, thumbnail URLs, page titles, and source-page URLs. An image you select is saved to the record as its avatar or logo.Suggesting contact avatars and company logos. Enabled by default; can be turned off in the app.
MediastackNews articles (headline, source, URL, date, summary, optional image URL) matching a company name.Displaying relevant company news on company detail pages.
Open Exchange RatesCurrency exchange-rate quotes (no personal data is sent or received).Converting billing amounts between native currency, USD, and EUR.

#2.5 Information about people you enrich (obtained from a data provider, not from them)

Some 1fifty features let a user retrieve professional information about a person or company from our enrichment provider (CoreSignal — see the tables in Sections 2.4 and 4.1). Where that information identifies an individual — for example a professional’s name, job title, employment history, education, skills, professional email address, or public professional/LinkedIn URL — that individual is a data subject even though they are not a user of the Service, and we did not obtain the information from them directly. This section is the notice required by Article 14 GDPR for that data.

  • Who processes it, and why. 1fifty BV caches and surfaces this provider-sourced professional data so that a user can enrich the records they keep about their own business contacts and the companies they track. We do not use it for advertising, we do not sell it, and we do not use it to take automated decisions that produce legal or similarly significant effects concerning the individual.
  • Legal basis. Legitimate interest (Article 6(1)(f)) — our users’ interest in maintaining accurate professional contact records, balanced against the interests and fundamental rights of the individual, and limited to professional rather than private-life information.
  • Source. A third-party data-aggregation provider (CoreSignal), which compiles professional and corporate profiles from publicly available sources.
  • Categories. The professional-profile and company-profile fields listed in the CoreSignal rows of Sections 2.4 and 4.1.
  • Retention. Cached for up to 365 days and refreshed on demand — see the “Third-party enrichment caches” row in Section 5.
  • Your rights. You may object to this processing at any time, and you may request access to, correction of, or erasure of the data we hold about you, by contacting us at privacy@1fifty.ai. On a valid objection or erasure request we will remove the data we hold about you. You may also lodge a complaint with a supervisory authority (see Section 12).

#3. How We Use Your Information

We process your information for the following purposes:

PurposeLegal basis (where applicable)
Providing the Service — storing your contacts, companies, tasks, events, templates, labels, and images; powering search, scanning, enrichment, and synchronisation features.Storing your data and providing search, scanning, and synchronisation is performance of our contract with you (Art. 6(1)(b)). Optional enrichment of your records with publicly available information rests on our and our users’ legitimate interest in maintaining richer, more useful contact records (Art. 6(1)(f)); you can object to it (see Section 8).
Authentication and account management — signing you in, verifying your identity (OTP, MFA), managing your profile and email.Performance of a contract.
AI-powered features — extracting contact data from business-card images; cleaning and normalising contact data; enriching contact and company records with publicly available information; and answering your questions about your contacts, companies, tasks, and events through the in-app AI chat assistant (which reads the relevant records to answer you and proposes record changes that are applied only after you confirm them).Extracting card data, cleaning your records, and the AI chat assistant operate on data you provide to deliver a feature you invoke — performance of our contract with you (Art. 6(1)(b)). Enriching records with publicly available third-party information rests on the legitimate interest described in the “Providing the Service” row and in Section 2.5 (Art. 6(1)(f)).
Voice-to-text dictation — transcribing short voice-dictation audio you record into text for freeform fields (notes, context, descriptions) via our speech-recognition sub-processor.Performance of a contract (Art. 6(1)(b)) — you invoke dictation to transcribe your own audio into your own field; the audio is not retained after transcription.
Billing and subscriptions — tracking feature usage against plan limits; processing in-app purchases via Apple App Store and Google Play (with RevenueCat orchestrating entitlement state); managing future web subscriptions via Stripe.Performance of a contract.
Security and fraud prevention — audit logging; rate-limiting; webhook-signature verification; CSRF protection; input validation; account-deletion handling.Our legitimate interest in protecting the Service, our users, and ourselves from abuse, fraud, and security threats (Art. 6(1)(f)); and compliance with our legal obligations where applicable (Art. 6(1)(c)).
Product analytics and improvement — understanding feature usage in aggregate, identifying friction points, prioritising improvements (PostHog product analytics).Our legitimate interest in understanding aggregate, pseudonymous feature usage and friction points in order to improve the Service (Art. 6(1)(f)).
Diagnostics and session replay — diagnosing UX issues and bugs through screen-replay capture with strict PII masking (PostHog session replay); collecting crash reports and performance data (Sentry).Our legitimate interest in diagnosing and fixing bugs and usability issues and keeping the Service stable and performant (Art. 6(1)(f)).
Operational logging — centralised structured logging for incident response, performance monitoring, and capacity planning.Our legitimate interest in operating, monitoring, and securing the Service and responding to incidents (Art. 6(1)(f)).
External uptime, heartbeat, and status-page services — out-of-band probes against our public endpoints, scheduled-job heartbeats, and a public incident-status page so you can subscribe to outage notifications (BetterStack).Our legitimate interest in monitoring availability and operating a public status page (Art. 6(1)(f)); and, for the incident-notification subscriber list only, your consent (Art. 6(1)(a)).
Transactional communications — sending OTP codes, magic-link emails, security notifications, and account-related messages.Performance of a contract.
Engagement and lifecycle communications — sending optional onboarding tips, re-engagement reminders, milestone messages, and occasional product announcements by email; and maintaining an address-level do-not-contact (suppression) list so opt-outs and undeliverable addresses are respected.Segmented for the message itself: for existing paying customers, the ePrivacy “soft opt-in” (ePrivacy Directive Art. 13(2), transposed as Belgian Code of Economic Law Art. XII.13 §2), with an opt-out in every message; for all other recipients, consent (Art. 6(1)(a)). Suppressing hard-bounced addresses for deliverability hygiene: legitimate interest (Art. 6(1)(f)). Honouring opt-outs and complaints: compliance with the Art. 21 objection right and the ePrivacy opt-out (Art. 17(3)(b)).
Feedback and support — receiving and responding to your in-app feedback.Our legitimate interest in receiving, understanding, and responding to your feedback and providing support (Art. 6(1)(f)).
Legal compliance — responding to lawful requests and complying with applicable law (including tax-record retention for billing).Legal obligation.

We do not sell your personal data. We do not use your data for cross-app tracking, behavioural advertising, or model training. For AI features, we configure AI routing to enforce zero-data-retention and no-training settings: requests that cannot be processed under those settings are rejected rather than routed to a provider that would log or train on your prompts or outputs (see Section 4.1 below and the DPA, §6.2).


#4. How We Share Your Information

We share data only as described below. We do not share data with data brokers or for advertising purposes.

#4.1 Service Providers and Third-Party Recipients

The table below lists the service providers and third-party recipients that receive data from us or directly from you in connection with the Service. Where a provider processes personal data on our behalf, it is treated as a processor or sub-processor and must be covered by an Article 28 GDPR data-processing agreement and transfer safeguards where applicable. Some recipients, such as app stores, payment providers, and sign-in providers, may act as independent controllers for parts of their processing under their own terms and privacy notices.

For personal data you upload about third parties (such as your contacts) — for which you act as the controller (or processor) and we act as your processor (or sub-processor) — the data-processing terms required by Article 28 GDPR are set out in our Data Processing Addendum (“DPA”), which is incorporated into our Terms of Service by reference. The canonical Sub-processor list lives at Annex 3 of the DPA; the table below is a public-facing mirror and Annex 3 governs in case of conflict.

ProviderData sharedPurpose
Supabase (Supabase Inc.; project hosted in EU North — Stockholm, Sweden on AWS eu-north-1)Account data, all app content (contacts, companies, tasks, events, templates, images), audit logs, billing records.Cloud database (PostgreSQL), authentication, file storage, and Realtime infrastructure.
PostHog (PostHog Inc.; processed on the EU cluster in Frankfurt)Pseudonymous user identifier; app interaction events; session replay frames with all text inputs masked by default and screens surfacing freeform or sensitive content masked at the view-tree level; rendered content on other screens may appear in frames.Product analytics and session-replay-based diagnostics.
Sentry (Functional Software Inc.; project configured for the European Union data-storage region)User identifier, email address, display name; crash reports, stack traces, performance data; feedback messages and optional screenshots.Error and crash monitoring; in-app feedback collection. Active when the Sentry DSN is configured.
Resend (Resend, Inc.; emails may be routed from the Ireland sending region where configured; account data, email metadata, logs, and API records are stored in the United States)Recipient email address, your name (where applicable), OTP codes, magic-link tokens, security-notification content, and — for the engagement-email programme described in Section 8 — engagement-email content (onboarding tips, re-engagement reminders, milestone messages, and product announcements) with a per-message unsubscribe link.Transactional-email delivery and engagement/lifecycle-email delivery (Section 8). Resend is our existing email sub-processor; the engagement-email programme adds no new sub-processor.
Axiom (Axiom, Inc.; logs hosted in EU Central — Frankfurt, Germany on AWS eu-central-1)Structured server logs (request method, path, response status, response time, request identifier, hashed/transient IP addresses, audit-event metadata). PII is filtered from logs at the source.Centralised structured logging for incident response and operational monitoring.
BetterStack (Better Stack, Inc. / applicable Better Stack contracting entity; EU data storage where configured, with distributed edge probes and lawful transfers under Better Stack’s DPA)(a) Probe metadata for our public endpoints (target URL, response status, response time — no user data); (b) opaque per-job heartbeat tokens for scheduled background jobs (no user data); (c) only when you opt in to status-page incident notifications: the email address you provide on status.1fifty.ai. Probes originate from BetterStack’s distributed edge and may transit non-EU regions before being stored in the configured workspace region.External uptime monitoring, scheduled-job heartbeats, and the public incident-status page at status.1fifty.ai.
Crisp (Crisp IM SAS; data processed in the European Union — Nantes, France)Email address, display name (first + last name), pseudonymous user identifier, plan tier, device fingerprint (model, OS, brand, app version, build), runtime environment, language preference, the device’s push-notification token (APNs on iOS / FCM on Android), and the content of any messages you exchange with us through the in-app chat (including any text or files you attach). When you submit the landing-page waitlist form at 1fifty.ai: email address, language preferences (from your browser), timezone (from your browser), approximate location (country, region, city, postal code, and approximate IP-derived latitude/longitude) inferred from your IP address by Cloudflare, the page that referred you to the waitlist (where your browser provides one), any UTM marketing-attribution query parameters in the URL, your browser’s User-Agent string, and metadata about the Cloudflare edge that handled your request (datacenter code, ASN, network organisation).Customer-support chat (“Open live chat” in the app and on the website), operator-initiated proactive support, and profile-timeline events for support-ops context (sign-in, sign-out, subscription changes, account deletion, data-export requests, email/name updates). On the landing site: capture of the waitlist signup itself, plus enough context to localise and time-zone subsequent follow-up communications and to measure which marketing channels drive signups.
Apple App Store (Apple Inc., USA)Payment-card data and billing details that you provide directly to Apple. We do not receive your payment card numbers.Merchant-of-record processing for in-app purchases on iOS.
Google Play (Google LLC, USA)Payment-card data and billing details that you provide directly to Google. We do not receive your payment card numbers.Merchant-of-record processing for in-app purchases on Android.
RevenueCat (RevenueCat, Inc., USA)Pseudonymous user identifier (UUID), purchase events, product identifiers, entitlement identifiers, store environment (App Store / Google Play).Mobile in-app purchase orchestration and subscription state management.
Stripe (Stripe, Inc., USA)User identifier, email address, subscription and invoice metadata. We do not receive or store full payment-card numbers — Stripe handles card data directly.Payment processing for future web checkout and current backend integration. The user-facing Stripe checkout flow is not active in the current release.
OpenRouter (OpenRouter, Inc., USA)Images of business cards (base64-encoded); contact and company text data (names, addresses, positions, email domains, phone numbers) sent as prompts; voice-dictation transcripts (the text produced by Groq speech recognition), sent for formatting and cleanup; and — for the AI chat assistant — your chat messages, any images you attach, the conversation history of the active chat, and the contact, company, note, task, and event data the assistant reads from your workspace to answer you.AI-powered extraction, cleanup, and enrichment; the in-app AI chat assistant; and formatting and cleanup of voice-dictation transcripts — via large-language-model APIs. OpenRouter routes each request to an underlying model provider under zero-data-retention and no-training routing enforced on our account.
Groq (Groq, Inc., USA)Short voice-dictation audio recordings (up to 90 seconds) and the resulting transcript. Not logged or retained (Groq zero-data-retention setting enabled); discarded immediately after transcription.Voice-to-text transcription (speech recognition) for freeform text fields (notes, context, descriptions).
Microsoft Azure AI Speech (Microsoft — the applicable Microsoft contracting entity for our Azure subscription; Microsoft Ireland Operations Limited is Microsoft’s designated data-protection representative for the EEA and Switzerland. Processed in the European Union — West Europe, Netherlands)Only the text of the AI assistant’s spoken reply in voice mode, sent one sentence at a time to be turned into audio. That text can quote information the assistant used to answer you (for example a contact or company name, or part of a note). Your voice recording is never sent to Microsoft — speech recognition is handled by Groq (see the row above), and Microsoft receives text only. Microsoft states that it does not retain the text you send or store the audio it returns for real-time synthesis with its prebuilt neural voices, and does not use them to train its voice models.Text to speech — speaking the AI assistant’s answers aloud in voice mode.
CoreSignal (CoreSignal UAB, Lithuania, EU)Search queries (names, LinkedIn URLs, company names, website domains); employee and company identifiers.Professional employee and company data search and collection.
Mediastack / apilayer (apilayer GmbH, Austria, EU)Company names as search keywords.News-article retrieval.
Google Places (Google LLC, USA)Partial address text input; place identifiers.Address autocomplete and place details.
Open Exchange Rates (Open Exchange Rates Ltd., USA)No personal data — only currency codes.Currency exchange rates for cross-currency billing display.
Railway (Railway Corp.; Redis service hosted in EU West — Amsterdam, Netherlands)Hashed cache keys; rate-limit counters keyed by IP address; cached API responses; distributed-lock state. Connections are encrypted via TLS (rediss://).Server-side caching, rate-limiting, request de-duplication, and distributed locks. Railway also hosts the backend application service.
Cloudflare (Cloudflare, Inc., USA; global edge network)Website and admin-page request metadata such as IP address, URL, TLS/security metadata, and cached static assets. No app database content is hosted on Cloudflare Pages. The Cloudflare edge also produces approximate geolocation (country, region, city, postal code, continent, and approximate latitude/longitude) and network metadata (ASN, network organisation) from your IP address for landing-site requests; when you submit the waitlist form, this derived data is forwarded to Crisp (see the Crisp row above) — your raw IP address itself is not.DNS, CDN, security, and static hosting for the public landing site and admin frontend.
Expo Application Services (EAS) (Expo, Inc., USA)Application binaries and over-the-air update bundles. When your device checks for an update, Expo’s update service receives technical request metadata (app version, runtime version, platform, and the requesting IP address). No user-account data is shared.Mobile build, submission, and OTA-update infrastructure.
Twilio (Twilio, Inc., United States; EU processing region, with US control-plane access)Caller and called phone numbers, IVR key-press (menu) digits, and the content of inbound SMS messages sent to 1fifty’s published business lines. Twilio does not receive the contact or company data you upload to the Service.Business telephony (inbound voice IVR + SMS) for 1fifty’s published business lines.
Google Programmable/Custom Search (Google LLC, United States)A contact’s or company’s name sent as a search query.Searching the public web for a contact avatar or company-logo image. This feature is enabled by default and can be turned off in the app.
Google Firebase Cloud Messaging (Google LLC, United States)The device’s Android push-notification token, and — for operator/support pushes routed through the in-app chat — the notification payload.Delivering push notifications to Android devices, including support messages sent through the Crisp channel.
Apple Push Notification service (Apple Inc., United States)The device’s iOS push-notification token, and — for operator/support pushes routed through the in-app chat — the notification payload.Delivering push notifications to iOS devices, including support messages sent through the Crisp channel.

#4.2 Legal and Safety Disclosures

We may disclose your information if we believe in good faith that disclosure is necessary to:

  • comply with applicable law, regulation, or legal process;
  • protect the rights, property, or safety of us, our users, or the public;
  • detect, prevent, or address fraud, security, or technical issues;
  • enforce our Terms of Service.

#4.3 Business Transfers

If we are involved in a merger, acquisition, reorganisation, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy. Any future change of the controlling legal entity will be communicated to you in advance.


#5. Data Retention

Data categoryRetention period
Account and profile dataRetained while your account is active; cascade-deleted upon account deletion.
Workspace metadataRetained while the workspace exists; cascade-deleted on workspace removal or account deletion.
Contacts, companies, tasks, events, templates, labels, imagesRetained while your account is active; cascade-deleted when your account is removed.
Pending scans (incomplete)Retained until you complete or discard the scan, or your account is deleted.
Scan historyAutomatically purged after 90 days.
AI chat conversations and attachmentsRetained until you delete the conversation (or all conversations) in the app, until your configurable chat-retention setting auto-deletes inactive conversations (off by default; optional 90, 180, or 365 days), or until your account is deleted — whichever comes first. Attachments are stored in the chat-attachments bucket and are removed with their conversation; files the assistant renders for you (for example CSV or PDF exports) are stored in the chat-artifacts bucket, are pruned by a scheduled age-based cleanup, and are removed when you delete your account.
Audit logsAutomatically purged after 90 days — except entries that evidence an exercised data-subject right (data export, in-app data deletion, account deletion), which are retained beyond 90 days as part of our compliance record (see the deletion-cascade exceptions below).
Webhook deduplication recordsAutomatically purged after 7 days.
Sync tombstonesMarkers recording that a contact, company, task, or event was deleted (identifier and deletion timestamp only, no content), kept so your other devices learn of the deletion. Purged after 90 days.
Engagement-email send ledgerRetained while your account is active to enforce frequency caps and to avoid sending you the same lifecycle email twice. It records which engagement email was sent to you, when, and in which language; it does not store the message body. Cascade-deleted when your account is deleted.
Email suppression list (do-not-contact)An address-level do-not-contact list, keyed on a pseudonymised hash of your email address rather than your account identifier. Retention is differentiated by reason. An entry created by a spam complaint is retained indefinitely and gives effect to a lasting objection: we will not resume sending you engagement email even if you later re-enable the in-app setting. An entry created by an unsubscribe — whether through the one-click link in a message or by turning the in-app setting off — is retained while it is in force, but you can lift it yourself at any time by turning engagement emails back on in the app, which resumes delivery. (Basis for retaining these entries: giving effect to your Art. 21 objection and the ePrivacy opt-out; Art. 17(3)(b) exempts the record from the erasure right.) Entries created by a hard bounce (an address we could not deliver to) stop suppressing after 3 months, so the address becomes contactable again (basis: legitimate interest in deliverability hygiene — a bounce is a technical signal, not an objection). The expired row itself is retained as a deliverability record. Because this list is keyed on a hash, a suppression entry survives account deletion — a deliberate exception described in the paragraph below.
Billing and subscription recordsRetained for the longest period required by Belgian accounting and tax law. Belgian accounting law generally requires books and supporting documents to be kept for at least seven (7) years; Belgian tax and VAT rules may require tax-relevant accounting records, invoices, books, and VAT documents to be kept for ten (10) years, with longer periods of fifteen (15) years or longer where Belgian law specifically requires it for that document type. When you delete your account, the link between billing rows and your user identifier is severed (set to NULL) so that the records can no longer be associated with your identity through our systems, but the underlying accounting entries are preserved as required by law.
Usage recordsRetained while your account is active for billing accountability, and thereafter as part of our billing records for the periods required by Belgian accounting and tax law (see Billing and subscription records above). When you delete your account, the link between usage records and your user identifier is severed (set to NULL) so the records can no longer be associated with your identity through our systems.
CSRF tokensExpire after 15 minutes.
Server-side request-deduplication cachesExpire after 5 minutes.
Server-side response caches (Redis)Short-lived (5 minutes to 24 hours, depending on data type); automatically evicted.
Third-party enrichment caches (CoreSignal company and employee data)Refreshed when older than 365 days or when you explicitly request a refresh. Cached provider records are retained (and re-refreshed) for as long as the workspace retains access to them, rather than deleted on a fixed schedule. Enrichment caches store third-party professional and corporate data sourced from our enrichment provider; they are workspace-scoped and access-gated, and they are not commingled with your contact data. The cache is refreshed when stale or when you explicitly request a refresh.
Signed storage URLs (private buckets)Expire after 1 hour.
Data-export filesAuto-deleted approximately 1 hour 5 minutes after generation.
Rate-limit countersWindow-dependent (15 minutes to 24 hours).
Stale background jobsMarked failed after 15 minutes of inactivity by a scheduled cleanup job.
Client-side session tokensStored in the device secure store (Keychain / Keystore); removed on sign-out.
Client-side caches (AsyncStorage, SQLite local database 1fifty_local.db)Cleared on sign-out; SQLite data for the user is deleted.
Encrypted infrastructure backupsDeleted data may persist temporarily in our infrastructure providers’ encrypted backups until those backups are overwritten in the ordinary rotation cycle, after which it is permanently deleted. During that residual window the data remains encrypted, is not used for any other purpose, and is not restored to the live system except where strictly necessary to remedy a data-loss incident (see §13.2 of our Data Processing Addendum).
PostHog session replays and analytics events30 days for session replays (configured in our PostHog dashboard). Analytics events are retained for as long as the PostHog project exists and are deleted when we delete them or close the project; when you delete your account, the pseudonymous identifier linking those events to you is no longer associated with an existing account.
Sentry error and feedback dataRetained for the event-retention window applicable to our current Sentry plan, after which error events, performance data, and feedback are automatically deleted by Sentry.
BetterStack probe and monitoring dataProbe response logs, monitor incident history, and heartbeat history contain no user personal data (see Section 4.1) and are retained for the log-retention window applicable to our current BetterStack plan, after which they are automatically deleted.
BetterStack status-page subscriber emailsRetained until you unsubscribe (one-click via any incident notification email) or we close the status page. No additional profile information is associated with the subscription.
Crisp People profile and chat transcriptsRetained while your account is active. On account deletion, the People profile and every linked conversation transcript and timeline event are deleted from Crisp via API request as part of the deletion cascade (see paragraph below). If a Crisp-side deletion request fails, our operations team is alerted so that the deletion can be completed. Inactive Crisp conversations may additionally be auto-pruned per the retention policy configured in our Crisp workspace.
Crisp People profile and chat history on a waitlist signupIf you joined the public waitlist on 1fifty.ai, your email address is stored on a Crisp People profile tagged waitlist. It is retained until you ask us to remove it at privacy@1fifty.ai or until the waitlist programme is closed and the segment is purged.

When you delete your account through Profile → Delete Account, all user-owned database records are cascade-deleted (contacts, companies, tasks, events, templates, labels, scans, notes, touchpoints, AI chat conversations and messages, preferences, and per-user Redis state). Storage objects (images, files) under your user identifier are removed from each bucket (avatars, contact-avatars, company-logos, company-cards, chat-attachments, chat-artifacts, admin-avatars, data-exports). Your Crisp People profile (email, display name, identifier, device fingerprint, all timeline events, and every linked chat conversation) is deleted server-side via the Crisp REST API as part of the deletion cascade. Audit-log entries containing your user identifier are purged per the 90-day retention schedule, except the entries that record the deletion request itself and any prior data-export or in-app data-deletion request, which we retain as evidence that your request was received and honoured (see the exceptions below). Third-party enrichment records sourced from CoreSignal are not user-owned and are not deleted with your account, but the link between you and those records is removed.

Your engagement-email consent state (stored alongside your preferences) and your engagement-email send ledger are cascade-deleted with your account. One deliberate exception applies to the deletion cascade. If you have unsubscribed from — or filed a spam complaint about — an engagement email, the corresponding entry on our email suppression list is retained even after your account is deleted, so that we can continue to honour your opt-out and never contact you again. That entry is a pseudonymised, keyed hash of your email address (an HMAC computed with a secret key), not your account identifier and not your address in readable form. It remains personal data under the GDPR — membership can be tested by hashing a candidate address, so the value is pseudonymised, not anonymised — but its retention rests specifically on the Article 17(3)(b) exemption and the Article 21 objection right, not on any claim that the hash falls outside the scope of the GDPR.


#6. Security

We implement industry-standard technical and organisational measures to protect your information. The canonical technical and organisational measures (TOMs), at the level of control objective and as required by Article 32 GDPR, live at Annex 2 of our Data Processing Addendum; the table below is a public-facing summary and Annex 2 governs in case of conflict.

LayerMeasure
Encryption in transitAll network traffic between the app, our backend, and third-party services uses TLS/HTTPS. Redis connections use TLS (rediss://). HTTP Strict Transport Security (HSTS) is enforced in production with a two-year max-age.
Encryption at restData at rest is encrypted by our infrastructure providers (Supabase / AWS). Storage buckets and database volumes are encrypted by default.
On-device credential storageAuthentication tokens (access and refresh) are stored in the operating system’s secure enclave / Keychain / Keystore via Expo SecureStore.
Row-Level Security (RLS)Every database table enforcing user-scoped access uses Supabase RLS policies (over 70 policies in place across the schema). Each user can access only their own data. Service-role access is restricted to trusted server-side operations (audit logging, system-level writes, webhook handlers).
AuthenticationSupabase Auth with JWT and refresh tokens; OTP (magic-link and code) via Resend; OAuth (Google, Apple, LinkedIn); optional TOTP-based multi-factor authentication.
CSRF protectionDouble-submit pattern: X-CSRF-Token header (mobile) or header + csrf-token cookie (web). Tokens are timing-safely compared, expire after 15 minutes, and are revoked on sign-out.
Custom-header checkMutation requests require X-Requested-With: xmlhttprequest to mitigate cross-origin attacks.
Rate limitingRedis-backed rate limiting with per-IP and per-user quotas. Separate limits for authentication, AI, external API, billing, and bulk operations. Authentication, billing, AI, and external paths fail closed when Redis is unavailable. Database-level triggers further limit scan history per user.
Webhook verificationStripe webhooks are verified using stripe.webhooks.constructEvent (HMAC-SHA256 signature). RevenueCat webhooks are verified with a timing-safe comparison of Bearer tokens. Duplicate webhook events are detected via an INSERT-first deduplication table.
Security headersX-Content-Type-Options: nosniff, X-Frame-Options: DENY, X-XSS-Protection: 1; mode=block, Referrer-Policy: strict-origin-when-cross-origin, Content-Security-Policy, and Permissions-Policy (which restricts geolocation, microphone, camera, accelerometer, gyroscope, magnetometer, payment, USB, and other browser APIs at the web layer).
Input validationAll API inputs are validated with Zod schemas. Utility functions enforce email, URL, phone, and UUID format checks. HTML tags are stripped from text inputs. Request-body size limits are enforced per route.
SQL injection defensesParameterised queries via the Supabase client SDK; user input is never concatenated into SQL.
Audit loggingEvery authentication and account-lifecycle action is recorded with user identifier, email, IP address, user-agent, request identifier, resource type, resource identifier, and outcome.
Account-deletion cascadeDatabase records cascade-delete via foreign-key constraints; storage objects are explicitly purged from every bucket; per-user Redis state is exact-key-deleted and SCAN-pattern-deleted; CSRF tokens are revoked.
Session-replay PII maskingAll text inputs are masked by default. Screens that surface freeform user content (notes, AI output, OCR, share-extension payloads, OTP echoes, payment card numbers) are masked at the view-tree level via accessibilityLabel="ph-no-capture" — including any images they contain — so their content is not captured by the replay SDK.
Secrets managementAll API keys and credentials are managed through Doppler and are never committed to source control.

No system is 100% secure. If you discover a vulnerability, please contact us at security@1fifty.ai.


#7. Cookies and Local Storage

  • Cookies (web only): The Service uses a single optional first-party cookie (csrf-token) for CSRF protection on the web platform. We do not use advertising, analytics, or third-party tracking cookies.
  • Website chat widget (1fifty.ai): Our public website loads the Crisp customer-support chat widget (Crisp IM SAS — see Section 4.1). Crisp stores functional identifiers in your browser (cookies and/or local storage) so that a chat conversation stays continuous across pages and visits. These identifiers are used solely for chat functionality — not for advertising, analytics, or cross-site tracking.
  • Website preferences: The website stores your light/dark theme choice in your browser’s local storage. This value never leaves your device.
  • Mobile local storage: Authentication tokens are stored in the device secure store (Keychain on iOS, Keystore on Android via Expo SecureStore). Non-sensitive preferences (theme, locale, date/time format, font) and offline-queue metadata are stored in AsyncStorage. A local SQLite database (1fifty_local.db) caches contacts, companies, tasks, events, and enrichment data so the app works offline. All client-side data is cleared on sign-out and the SQLite database is deleted.

#8. Your Rights and Choices

Depending on your jurisdiction, you may have some or all of the following rights:

RightHow to exercise
AccessRequest a copy of the personal data we hold about you, or download a machine-readable copy directly via Profile → Download My Data in the app. The ZIP includes your account database (contacts and companies — including the labels applied to them — plus your notes and touchpoints), your AI chat conversations and messages (as a chats.json file), AND a crisp.json file with the customer-support data held by our Sub-processor Crisp (People profile, custom data, profile-timeline events, and complete chat transcripts of every conversation you have had with our support team). Each Crisp section is marked with a fetchStatus so any partial-failure is transparently disclosed in the export itself rather than silently omitted. Categories not yet covered by the self-service ZIP (events, tasks, message templates, label definitions, and preferences) are provided on request at privacy@1fifty.ai.
CorrectionUpdate inaccurate or incomplete data directly in the app, or contact us.
DeletionDelete your account and associated data at any time from Profile → Delete Account in the app, or by contacting us at privacy@1fifty.ai. When your account is deleted, all user-owned data is permanently removed (see Section 5).
Restriction / ObjectionRequest that we restrict or stop certain processing of your data (for example, object to AI-based processing or session replay). Contact us at privacy@1fifty.ai to exercise this right.
Analytics opt-outDisable product-analytics capture (PostHog) at any time from Profile → Privacy Settings → Analytics. The toggle takes effect immediately and is persisted on the device. Disabling analytics does not affect security audit logging, transactional logging, or error monitoring (which run under separate legal bases).
Engagement-email opt-outTurn engagement emails on or off at any time from Profile → Privacy Settings → Engagement emails in the app, or use the one-click unsubscribe in any engagement email. Turning them off — by either method — stops delivery immediately; turning them back on in the app resumes it. Reporting an engagement email as spam is treated as a lasting objection that the in-app setting does not override. This does not affect transactional or security emails (OTP codes, magic links, security notifications), which are essential to the Service and cannot be opted out of.
Data portabilityDownload a machine-readable copy of your data from Profile → Download My Data in the app (covers both Supabase-held account data and Crisp-held customer-support data — see the Access row), or request a copy by contacting us.
Withdraw consentWhere processing is based on consent, you may withdraw it at any time (for example, by revoking device permissions in your device settings, or by turning off engagement emails). Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
Lodge a complaintFile a complaint with your local data-protection authority. In Belgium this is the Gegevensbeschermingsautoriteit / Autorité de protection des données (APD/GBA).

To exercise any of these rights, use the in-app options above or contact us at privacy@1fifty.ai. We will respond within the timeframe required by applicable law (typically 30 days under the GDPR).

#Is providing your data mandatory?

Providing your email address is a contractual requirement — it is the credential your account is created with, and without it we cannot create or maintain your account or deliver the Service. You are not under any statutory obligation to provide it; the only consequence of not providing it is that you cannot use the Service. All other information you provide (name, profile photo, contacts, companies, notes, images, and any content you add) is optional — not providing it only limits the related features (see also the device-permissions note below).

#Device permissions

You may grant or revoke camera, microphone, contacts, photo-library, location, and notification permissions at any time through your device settings (Settings → Privacy on iOS; Settings → Apps on Android). Revoking a permission may limit certain features. The in-app Profile → Privacy Settings screen surfaces the current state of each permission and provides a shortcut to your device’s permission settings.

#Push notifications

With notification permission granted, the Service sends local and scheduled notifications related to event-prep, follow-up, and task reminders. It can also deliver remote push notifications — in particular, support and operator messages sent through the in-app chat — routed through Apple Push Notification service (on iOS) and Google Firebase Cloud Messaging (on Android). You can control notifications at any time through your device settings.

#Engagement and marketing emails

Beyond the transactional and security messages described above, we operate an engagement-email programme: occasional onboarding tips, re-engagement reminders when your account has been dormant, milestone messages, and infrequent product announcements — all intended to help you get more value from 1fifty. Every engagement email identifies the sender, includes a valid postal address, and offers both a one-click unsubscribe (through the list-unsubscribe control your mail client exposes) and an unsubscribe link in the message body.

The legal basis is segmented according to who you are. Sending an unsolicited commercial email is governed first by the ePrivacy Directive (2002/58/EC) Article 13(2), transposed in Belgium as Article XII.13 §2 of the Code of Economic Law. This is the rule that specifically governs email marketing (lex specialis), and it takes precedence over the general provisions of the GDPR for the act of transmission:

  • If you are an existing paying customer, we may send you engagement emails about our own similar products and features under the ePrivacy “soft opt-in” exception, because you provided your email address in the context of a purchase. You may opt out at any time, including at the moment your email address is collected and in every message we send.
  • If you are not a paying customer (for example, on the free tier), we send engagement emails only with your prior, explicit consent (opt-in). This consent is off by default; it is turned on only by an affirmative action that you take.

We do not treat “legitimate interest” (GDPR Article 6(1)(f)) as a substitute for the consent that ePrivacy requires for the act of transmission: consistent with EDPB Opinion 5/2019, legitimate interest cannot displace the ePrivacy consent rule for sending marketing email. (Legitimate interest does support a narrow, non-marketing, deliverability-hygiene activity — suppressing an address that has hard-bounced — as described in Sections 3 and 5.)

How to control engagement emails. You can turn engagement emails on or off at any time from Profile → Privacy Settings → Engagement emails in the app, or by using the one-click unsubscribe in any engagement email. Turning them off — by either method — stops delivery immediately; turning them back on in the app resumes it (see the suppression-list entry in Section 5). If you instead report an engagement email as spam, we treat that as a lasting objection and will not resume sending even if you re-enable the setting. Delivery is handled by our existing email sub-processor, Resend (see Section 4.1) — this programme introduces no new sub-processor. Resend is a US-based provider that processes on our behalf under Standard Contractual Clauses.

Measuring engagement. We measure whether the links inside engagement emails are clicked, through a redirect on our own domain, so we can tell which messages are useful and improve the programme. Each click event is recorded against your pseudonymous user identifier together with internal campaign and step identifiers; it does not capture the message content or your email address. Click events are recorded through our analytics sub-processor, PostHog (already listed in Section 4.1; not a new recipient). We do not use open-tracking pixels; if we introduce open measurement, we will update this Privacy Policy before doing so. This measurement stops when you unsubscribe.

Transactional and security emails are separate and non-optional. OTP codes, magic-link sign-in emails, security notifications, and other account-related messages are essential to providing the Service, are sent on the basis of contract performance, and are not part of the engagement-email programme. Turning off engagement emails, unsubscribing from them, or marking one as spam never affects these messages, and never blocks a security or sign-in email.

Sender identity. The controller named in this Privacy Policy, the sender identity and postal address shown in the footer of each engagement email, and the “From” domain used to send it will all name the same legal entity — 1fifty BV. Confirming that alignment is a prerequisite before the first engagement email is sent.


#9. International Data Transfers

Your information may be processed and stored in countries other than your country of residence. When personal data is transferred outside the European Economic Area (EEA), United Kingdom, or Switzerland, we rely on:

  • the European Commission’s adequacy decisions;
  • Standard Contractual Clauses (SCCs) approved by the European Commission; or
  • other lawful transfer mechanisms as appropriate.

Our key providers and third-party recipients, and their primary processing or transfer locations:

The majority of core application data is stored in the European Union. Some providers are US-based or operate global edge/control-plane services; where personal data is transferred outside the EEA, we rely on the transfer safeguards listed above. You can obtain a copy of the Standard Contractual Clauses we rely on (redacted where necessary to protect commercial or security-sensitive terms) by contacting us at privacy@1fifty.ai. The European Commission also publishes the template clauses on its website.

Provider / recipientPrimary processing / transfer location
SupabaseEuropean Union (Stockholm, Sweden — AWS eu-north-1)
PostHogEuropean Union (Frankfurt, Germany)
SentryEuropean Union data-storage region
AxiomEuropean Union (Frankfurt, Germany — AWS eu-central-1) for log-event storage; Axiom, Inc. is US-based
ResendIreland sending region where configured; United States for account data, email metadata, logs, and API records
Railway (Redis + backend service)European Union (Amsterdam, Netherlands)
BetterStackEU data storage where configured; distributed probe locations and possible US/other processing under Better Stack’s DPA
CrispEuropean Union (Nantes, France)
Microsoft Azure AI SpeechEuropean Union (West Europe — Netherlands)
CloudflareGlobal edge network / United States
CoreSignalLithuania (EU)
apilayer / MediastackAustria (EU)
Apple App StoreUnited States
Google PlayUnited States
RevenueCatUnited States
StripeUnited States
OpenRouterUnited States
GroqUnited States
Google PlacesUnited States
Open Exchange RatesUnited States
Expo Application Services (EAS)United States
TwilioUnited States (EU processing region, with US control-plane access) — SCCs (Module 2) / DPF
Google Programmable/Custom SearchUnited States (SCCs / DPF)
Google Firebase Cloud MessagingUnited States (SCCs Module 2 / DPF)
Apple Push Notification serviceUnited States (SCCs Module 2 / DPF)

#10. Children’s Privacy

The Service is not directed at individuals under the age of 16 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children. If you believe that a child has provided us with personal data, please contact us at privacy@1fifty.ai and we will take steps to delete it.


#11. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) provides you with additional rights:

  • Right to know: You may request the categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties with whom we share it.
  • Right to delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to correct: You may request correction of inaccurate personal information.
  • Right to opt out of sale/sharing: We do not sell or share your personal information for cross-context behavioural advertising.
  • Non-discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise these rights, contact us at privacy@1fifty.ai.


#12. European Privacy Rights (GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland:

  • Data controller (for our processing): 1fifty BV, Oude Antwerpsebaan 109 bus 102, 2800 Mechelen, Belgium (VAT BE1038210695), is the incorporated data controller. Any future change of the controlling legal entity will be notified to you.
  • Data protection officer: We have not appointed a data protection officer, as we have assessed the criteria of Article 37 GDPR and concluded that a designation is not currently mandatory (this assessment is reviewed periodically). For all data-protection matters, contact us at privacy@1fifty.ai.
  • Data Processing Addendum (when you upload personal data of third parties): for personal data you upload about your contacts and other third parties, you act as the controller and we act as your processor. The Article 28 GDPR data-processing terms are set out in our Data Processing Addendum, which is incorporated by reference into our Terms of Service.
  • Legal bases: We process personal data under the legal bases described in Section 3 (contract performance, legitimate interest, legal obligation, consent).
  • Right to erasure: You can delete your account and data at any time via Profile → Delete Account in the app (Art. 17).
  • Right to data portability: You can download your data in a machine-readable format via Profile → Download My Data (Art. 20).
  • Right to object: You may object to processing based on legitimate interest; contact us to exercise this right (Art. 21).
  • Automated decision-making and profiling (Art. 22): We do not use your personal data to make decisions that produce legal effects concerning you or significantly affect you in a similar manner solely on the basis of automated processing. Our AI features (business-card extraction, contact and company cleanup, contact and company enrichment, and the in-app AI chat assistant) generate content and suggestions, but any AI-suggested change to your records is applied only after you review and accept it; an AI output never alone produces a legal or similarly significant effect.
  • Supervisory authority: You have the right to lodge a complaint with your local supervisory authority. In Belgium this is the Gegevensbeschermingsautoriteit / Autorité de protection des données (“APD/GBA”), Drukpersstraat 35, 1000 Brussels, Belgium — https://www.dataprotectionauthority.be.

#13. Third-Party Links

The Service may contain links to third-party websites or services (e.g., LinkedIn profiles, company websites, news articles). We are not responsible for the privacy practices of those third parties. We encourage you to read their privacy policies.


#14. Open-Source Components and Third-Party SDKs

The Service incorporates open-source libraries and third-party SDKs, including Expo and React Native (application framework), the PostHog SDK (product analytics and session replay), the Sentry SDK (error monitoring and feedback), the RevenueCat SDK (in-app purchases), the Crisp SDK (in-app customer-support chat), the Supabase JS client (database, authentication, storage, Realtime), and Google Sign-In / Apple Authentication SDKs (third-party sign-in). These components may collect technical and interaction data as described in their respective privacy policies and as configured by us. We do not use advertising SDKs, cross-app trackers, or behavioural-advertising networks.


#15. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices:

Controller1fifty BV
Data-protection contactprivacy@1fifty.ai
Email (legal)legal@1fifty.ai
Websitehttps://1fifty.ai
Mailing address1fifty BV, Oude Antwerpsebaan 109 bus 102, 2800 Mechelen, Belgium
VAT numberBE1038210695

We have not appointed a data protection officer (see Section 12); all data-protection enquiries go to privacy@1fifty.ai.


This Privacy Policy applies to the 1fifty mobile application (iOS and Android) and any related web companion. It does not apply to third-party services linked from the app.

FONT LAB1,234