Privacy Policy
Your data, your rights — here's how we handle it
Who We Are (Data Controller)
Blizo is operated by Svurzhi Se, registered in Bulgaria ("we", "us", "our"). We are the data controller for all personal data processed through this app. Contact: svurzhise@gmail.com.
What We Collect
We collect: (a) Account data — name, username, email address, profile photo, bio, and date of birth verification. (b) Content you create — posts, stories, event listings, photos, videos, and direct messages. (c) Usage data — events you view, save, or attend; profiles you follow; interactions with content. (d) Location data — precise or approximate GPS coordinates when you grant permission; or a manually entered home city. (e) Device data — device type, operating system version, app version, and crash reports. (f) Authentication data — if you sign in with Google, we receive your name and email from that provider.
Lawful Basis for Processing (GDPR)
We process your data on the following legal bases under GDPR Art. 6: (a) Contract performance — to create and manage your account, deliver core app features (event discovery, messaging, profiles). (b) Legitimate interests — to prevent fraud, ensure platform security, and improve app functionality. (c) Consent — for optional features such as precise location tracking and push notifications; you may withdraw consent at any time. (d) Legal obligation — where required by applicable law (e.g. responding to lawful legal requests).
How We Use Your Data
Your data is used to: operate and personalise your experience; show nearby and relevant events; enable social features (follows, messaging, stories); ensure platform safety and content moderation; send service notifications (not marketing, unless you opt in); comply with legal obligations; and improve app performance through anonymised analytics. We do not use your data for targeted advertising and we do not sell it.
Location Data
Precise location is only accessed with your explicit permission and used solely to show events near you and calculate distances. You can revoke permission at any time in your device Settings. If denied, you can manually set a home city in the app. We do not share your precise location with other users — only approximate city/area.
Direct Messages
Messages between users are transmitted securely over HTTPS and stored in our database, which is encrypted at rest by our hosting provider (Supabase). We do not apply any additional client-side encryption, and messages are not end-to-end encrypted. We do not read private messages except where legally required (e.g. a valid court order) or where a message is reported by a recipient for safety review. Message content is not used for advertising or profiling.
Third-Party Processors
We share data only with trusted processors under strict data processing agreements: Supabase (database and authentication, EU-hosted); Google (sign-in via Google OAuth, governed by Google's privacy policy); Expo / EAS (app build and update delivery). These processors may not use your data for any purpose other than providing their services to us. We do not share your data with advertisers or data brokers.
International Data Transfers
Our primary database is hosted by Supabase in the EU. Where data is processed outside the EU/EEA (e.g. by Google for OAuth), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms under GDPR Chapter V, to ensure your data receives equivalent protection.
Your Rights
Depending on where you live, you have rights over your data. EU/UK users (GDPR / UK GDPR): right to access, rectify, erase, restrict processing, data portability, and object to processing. California users (CCPA/CPRA): right to know, delete, correct, and opt out of sale/sharing. Australian users (Privacy Act 1988): right to access and correct your data. To exercise any right, go to Settings > Account > Delete Account or contact svurzhise@gmail.com. We respond within 30 days (or sooner as required by law).
Data Retention
We retain your data for as long as your account is active. When you delete your account, personal data is removed within 30 days. Some data may be retained for up to 90 days for fraud prevention, legal compliance, or dispute resolution, after which it is permanently deleted. Anonymised, non-identifiable analytics data may be retained indefinitely.
Security
We use industry-standard measures including HTTPS for all data in transit, encryption at rest provided by our database host (Supabase), Row Level Security on our database, and hashed credentials. No system is 100% secure. If you become aware of a security issue, please notify us immediately at svurzhise@gmail.com.
Minors
Blizo is strictly for users aged 18 and over. We do not knowingly collect personal data from anyone under 18. If we discover that we have collected data from a minor, we will delete it immediately. If you believe a minor has registered, contact us at svurzhise@gmail.com.
Cookies & Device Identifiers
We do not use advertising cookies or cross-app tracking. We use session tokens stored securely on your device (via Expo SecureStore) solely to keep you logged in. We do not use your advertising identifier (IDFA/GAID) for any purpose.
Changes to This Policy
We may update this Privacy Policy as the app evolves. We will notify you of material changes via the app or by email at least 14 days before they take effect. The date at the top of this screen always reflects the current version.
Supervisory Authority & Complaints
If you are in the EU/EEA, you have the right to lodge a complaint with your local data protection authority. In Bulgaria, this is the Commission for Personal Data Protection (CPDP) at www.cpdp.bg. UK users may contact the ICO at ico.org.uk. We encourage you to contact us first at svurzhise@gmail.com — we aim to resolve all privacy concerns directly.
Your privacy matters to us. This policy may be updated as the app evolves — we'll always be transparent about changes.
Questions about this document? svurzhise@gmail.com