1. Scope and controller
This Privacy Policy applies to the Inweit iOS application, the websites at inweit.app and links.inweit.app, and related services (together, the “Service”).
Ulysses Holding B.V., trading as Inweit, is the controller responsible for the personal data described here. Its address is Stadhouderskade 125 2, 1074 AV Amsterdam, Netherlands. You can contact us at privacy@inweit.app. “Inweit”, “we”, “us”, and “our” refer to Ulysses Holding B.V.
The short version: Inweit uses identity, profile, location, and social activity data to make a real-world social map work. We do not sell personal data, and we do not use it for third-party behavioural advertising.
2. Data we process
Account and identity data
When you register or sign in, we process account identifiers, authentication status, and information supplied by the sign-in method you choose, such as your name, Apple relay email address, email address, or phone number where available. Authentication credentials are handled by Apple and Firebase Authentication; Inweit does not receive your Apple ID password.
Profile and verification data
We process the name and profile photo you provide, profile settings, verification status and confidence results, and the timestamps needed to manage profile updates. To help ensure that profiles represent real people, onboarding and certain profile refreshes use a camera-based liveness and face-match check.
For that check, camera frames and a reference image are processed through AWS Rekognition. Your selected profile photo is also checked with Google Cloud Vision for a single face and clearly inappropriate content, then compared with the liveness reference. Inweit stores the successful profile photo and verification status. The temporary liveness reference held by Inweit is deleted after a successful check or automatically within approximately 24 hours if the flow is abandoned. Inweit does not build a face-recognition gallery or use this data for advertising.
Location and presence data
If you grant location permission, we process device location, accuracy, timestamps, and the sharing settings you select to show relevant nearby activities, places, weather, directions, and—only when you enable it—your presence to the audience you choose. Turning off sharing stops new publication. A last-known shared location may remain visible to an already-authorised person for up to 24 hours so the Service can display an honest “last here” state.
Social and user-generated content
We process the activities you host or join, invitations, friend and trust relationships, messages, polls, lists, checklists, place recommendations, reactions, availability signals, and other content you choose to share. The Service also processes the audience, time, and place attached to that content.
Safety and support data
We process reports, blocks, moderation decisions, abuse-prevention signals, support messages, and related records where necessary to keep the community safe, investigate complaints, enforce our Terms, or comply with law.
Device and operational data
We process device and app identifiers, push-notification tokens, app version, language, request timestamps, error and security logs, rate-limit records, and network information made available to our infrastructure. Some place, map, and interaction history is cached on your device to improve speed and offline use.
3. How we use data
- Provide accounts, profiles, authentication, invitations, friendships, messaging, activities, maps, discovery, and notifications.
- Show information to the audience you choose and apply privacy, trust, block, and visibility controls.
- Verify that profiles represent real people and review profile photos for safety.
- Rank and personalise nearby activities and places using context such as time, general weather, distance, your interactions, and privacy-safe social signals.
- Protect the Service through rate limits, device security, abuse prevention, reports, moderation, and enforcement.
- Maintain reliability, troubleshoot errors, understand aggregate performance, and improve features.
- Comply with legal obligations and respond to valid legal requests.
Inweit does not use an LLM or generative AI to infer your interests or decide what appears on your map. Contextual discovery is generated by rule-based product logic from the signals described above.
4. Legal bases
Where data-protection law requires a legal basis, we rely on the following:
- Contract: to create your account and provide the features you request.
- Consent: for device permissions and optional features such as precise location sharing, camera access, and notifications. Where face verification involves biometric data used to verify you, we rely on your explicit consent. You can withdraw device permissions in iOS Settings, change sharing inside Inweit, and contact us to withdraw biometric-processing consent. Withdrawal does not affect processing that was lawful before it.
- Legitimate interests: to secure, operate, improve, and protect the Service, prevent abuse, and provide relevant contextual discovery, balanced against your rights.
- Legal obligation: where processing is needed to comply with applicable law or a binding request.
- Protection of vital interests: only in exceptional safety emergencies where permitted by law.
5. Who sees what
Inweit is social, so some data is shared with other members as part of the feature you use. Your profile card and eligible activities may be visible according to the Service’s access rules. Precise shared location is limited to people and audiences allowed by your settings and the Service’s trust and block rules. Approval-gated activities use privacy-reduced previews until a viewer is allowed in.
Messages and activity content are visible to their intended participants. Reports and blocks are not announced to the reported or blocked person, although we may need to disclose limited information if required by law or necessary to resolve an appeal safely.
Think carefully before sharing content. People who can see content may capture or re-share it outside Inweit, which we cannot fully control.
6. Service providers and disclosures
We use carefully selected providers to operate the Service. They process data for the purposes described here and under their own contractual and legal obligations.
| Provider | Purpose | Typical data |
|---|---|---|
| Google Firebase / Google Cloud | Authentication, database, hosting, server functions, push delivery, maps, places, weather, and profile-photo safety checks | Account identifiers, Service content, device tokens, location queries, profile photo during review, logs |
| Amazon Web Services (AWS Rekognition) | Face liveness and comparison for real-person verification | Camera challenge data, temporary face reference, selected profile photo for comparison, confidence results |
| Apple | Sign in with Apple, App Store distribution, device permissions, maps handoff, and push-notification transport | Apple-provided account details, device/app identifiers, push token and notification payload |
We may also disclose data to professional advisers, a successor in a merger or asset transfer subject to appropriate protections, law-enforcement or public authorities responding to a valid legal demand, or another person when necessary to protect rights, safety, and the integrity of the Service. We do not sell personal data.
7. Retention and deletion
We keep personal data only for as long as needed for the Service, the purposes above, and applicable legal obligations. Different records have different lifetimes:
- Temporary face-verification request data is removed when consumed or swept if abandoned; Inweit’s temporary liveness reference is removed after success or within approximately 24 hours.
- Published location is short-lived. New publishing stops when sharing stops; authorised last-known visibility is capped at approximately 24 hours.
- Operational request records and short-lived caches are routinely removed or overwritten. Some security, moderation, and rate-limit records are kept longer where reasonably necessary.
- Your account, profile, relationships, messages, activities, and history are generally kept while your account is active or inactive so the Service can work across devices and preserve conversations.
You can permanently delete your account in Profile → Account → Delete account. This removes your profile, hosted activities, friendships, invitations, messages and conversation records, live location, verification artefacts, encrypted backups, and other data linked to your account from Inweit’s active systems. Limited records may be retained where required by law, necessary to establish or defend legal claims, or held temporarily in provider backups until their normal overwrite cycle completes.
8. Security
We use technical and organisational safeguards designed for the sensitivity of the data, including authenticated access, server-enforced access rules, least-privilege service credentials, encryption in transit, restricted administrative writes, expiring location records, and deletion workflows. Direct-message backup content is stored as encrypted ciphertext. No system is perfectly secure, and we cannot promise that unauthorised access will never occur.
If you believe your account or data is at risk, contact security@inweit.app promptly.
9. Your choices and rights
Inside Inweit, you can update profile information, control location sharing and its audience, manage notifications, block people, remove content where the product allows, sign out, and delete your account. iOS Settings lets you revoke camera, precise location, photo-library, local-network, and notification permissions.
Under the GDPR and other applicable law, you may have rights to be informed, access personal data, correct inaccurate data, request erasure, restrict processing, object to processing, receive certain data in a portable format, and withdraw consent without affecting earlier processing. You also have rights concerning decisions based solely on automated processing that produce legal or similarly significant effects. Inweit does not currently make those kinds of automated decisions.
You may lodge a complaint with your local data-protection authority. In the Netherlands, the supervisory authority is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority).
To exercise a right, email privacy@inweit.app. We may need to verify your identity before acting. We will respond without undue delay and, where the GDPR applies, normally within one month.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal data from them. If you believe a child under 16 has provided data, contact us so we can investigate and delete it.
11. International processing
Inweit is operated from the Netherlands. Our providers may process data in the European Economic Area, the United States, and other countries where they maintain infrastructure or support teams. When personal data is transferred outside the EEA, we rely as applicable on European Commission adequacy decisions, Standard Contractual Clauses, and supplementary technical and organisational measures. You may contact us for information about the safeguard relevant to a particular transfer.
12. Changes to this policy
We may update this policy when the Service or law changes. We will post the revised version here and change the “last updated” date. If a change materially affects your rights or how we use sensitive data, we will provide additional notice in the Service where reasonably possible.
13. Contact
Ulysses Holding B.V.
Stadhouderskade 125 2
1074 AV Amsterdam
Netherlands
privacy@inweit.app
General support: support@inweit.app
Security reports: security@inweit.app