Privacy Policy

Last updated: September 6, 2026

Introduction

This Privacy Policy explains how we collect, use, disclose, and protect your personal data when you use the FOMO mobile application ("App" or "Service"). It also outlines your privacy rights and how Portuguese and European laws safeguard them.

By using the Service, you consent to the collection and use of your data in accordance with this Privacy Policy.

Note: FOMO is owned by Expansive Verity, LDA, a company registered in Portugal.

Interpretation and Definitions

Account: A unique profile created by you to access our Service.
Application: "FOMO," the software program owned and provided by Expansive Verity, LDA.
Company: Referred to as "We," "Us," or "Our," meaning Expansive Verity, LDA.
Country: Portugal.
Device: Any electronic device that can access our Service.
Personal Data: Any information relating to an identified or identifiable individual.
Demographic Data: Information (university, relationship status, gender, and age range) used to filter poll results. Filtering is aggregated and never identifies an individual.
Poll: A community vote, held on Thursday, Friday and Saturday nights at 9PM, where users select which venue they plan to visit.
Partner: A venue or business that offers a promotion to FOMO users.
Promotion: An offer made by a Partner, shown to you in the App and claimed in person at that Partner's venue.
Service Provider: A third-party company that processes data on our behalf and on our instructions, listed in the "Third-Party Services We Use" section below.
Usage Data: Information collected automatically when using the App (e.g., user interactions, device and app version, and diagnostic data).
User Content: Any text, images, or other data that you voluntarily submit through the Service.
You: The individual accessing or using our Service.

Types of Data Collected

Account & Profile Data

When creating and maintaining your account, we collect:

  • Name;
  • Email address;
  • Phone number (optional);
  • Profile photo;
  • Date of birth (to verify minimum age of 18);
  • Instagram handle (optional);
  • Any additional details you voluntarily provide.

Demographic Data (Optional & Anonymous)

You may optionally provide:

  • University or educational institution;
  • Relationship status;
  • Gender.

Together with your age range (derived from your date of birth), this information is used to enable demographic filtering of poll results (e.g., "see results for students only"). Filtering is always aggregated and never identifies an individual. This data is never used for advertising or profiling, and you can update or remove it at any time from your profile settings.

Visibility: Your university, relationship status and gender are visible to users you are friends with. They are not shown to anyone else.

Poll & Voting Data

When you participate in a weekly poll, we record:

  • The venue you voted for;
  • The poll date;
  • Your user ID (to associate the vote with your account and display it on your profile).

Promotions and Claims

When you claim a promotion at a partner venue, we record:

  • Your user ID;
  • The partner whose offer you claimed;
  • The date and time of the claim, in the partner's local time.

This record is what enforces the one-claim-per-partner-per-night limit and lets a partner reconcile what was handed out. Be aware that it says more than a vote does: a vote is where you said you were going, a claim is a venue you were actually at, on a given night.

Instagram Handle (Optional)

You may add your Instagram handle to your profile, or state that you do not have one. If you add it, users you are friends with can see it and open your Instagram profile. Users who are not your friends are only shown whether you have added a handle, not the handle itself. Opening a handle leaves the App for Instagram, which is operated by Meta under its own terms and privacy policy - we do not share any of your data with Meta.

User Content

When you create posts within the App, we collect:

  • Text and captions;
  • Images or photos you choose to upload;
  • The location you select for the post.

Location Data

Location During a Poll: While a poll is open, we access your device's GPS coordinates to connect you to the poll for your area. Your precise coordinates are not stored. We do store the wide geographic area they fall in - a cell of roughly 22 km across - alongside your vote, because poll results are grouped by area. That area is retained for as long as the vote is.

Post Location Data: When you manually tag a location in a post, that place is stored and linked to your post.

Location for Promotions: Promotions are listed nearest first, so we send your coordinates to find the ones around you. Claiming one sends them again, to check that you are at the venue rather than at home - that check is the only thing standing between the offer and someone claiming it from their sofa. In both cases the coordinates are used to answer the request and then discarded. They are not written to your account, to the record of your claim, or to our logs.

Contacts (Optional)

If you choose to look for friends from your address book, the App asks for contacts permission and reads the names and phone numbers stored on your device. Only the phone numbers are sent to our servers, over an encrypted connection, so that we can check which of them belong to FOMO accounts. On arrival they are converted into irreversible cryptographic hashes in memory and compared against the equally hashed numbers of existing accounts.

We never write your address book to our database or to our logs, the names never leave your device, and we do not use your contacts to build a social graph, to send invitations, or for any purpose other than showing you the FOMO users among them at that moment. The permission is optional, you can revoke it at any time in your device settings, and every other part of the App works without it.

Usage Data

We may automatically collect certain technical and interaction data:

  • User interactions within the App (e.g., features used, actions performed);
  • Device ID (managed by AWS Cognito for authentication);
  • Device model, operating system version and app version;
  • Your IP address, from which an approximate country or city may be derived.

The last two categories are collected by our analytics and error-reporting providers, described in the next section, and are not stored in our own database. We do not track how long you spend on individual screens, and none of this data is used for advertising, ad targeting or profiling.

Diagnostic Data

When the App hits an error we send a diagnostic report containing the technical details of the failure, the sequence of actions that led to it, and your user ID, so that we can reproduce and fix it. These reports can incidentally contain personal data that was on screen at the time.

How We Use Your Data

We process your personal data for the following purposes:

  • Running the Service - operating polls, displaying results, and enabling social features;
  • Managing your account - authentication and account features;
  • Poll filtering - using demographic data to let users filter poll results by university, relationship status, gender or age range, always in aggregate and without identifying individuals;
  • Displaying your voting history - showing the venues you voted for on your profile;
  • Social features - showing friends' votes, showing you the other people who voted for the same venue as you, calculating friends in common, and enabling connections;
  • Processing user content - storing and displaying posts;
  • Providing location-based features - connecting you to your local poll during the voting window, and listing the promotions near you;
  • Running promotions - showing you a partner's offer, checking you are at the venue when you claim it, and keeping the claim so the limits hold;
  • Asking friends to vote - letting you prompt friends who have not voted yet, and letting them receive that prompt;
  • Communicating with you - sending push notifications about polls and updates, and delivering the prompts other users send you;
  • Improving the Service - analysing usage trends to enhance functionality;
  • Security and fraud prevention - detecting and preventing unauthorised access;
  • Legal compliance - fulfilling legal and regulatory requirements.

Friends and Social Visibility

Friends' Votes: When you vote in a poll, your friends may see which venue you voted for, shown as part of the poll results (e.g., "3 friends voted here").

Others at the Same Venue: Users who voted for the same venue as you in the same poll can see your name and profile photo, and can open your profile, even if they are not your friends. You can see theirs on the same basis. Within a poll this is limited to the venue you picked: nobody is shown the people who voted for a venue they did not vote for themselves, and it applies only to the poll you both voted in. Outside a poll, one person may be shown to you on the basis of where you both go - see "People Who Go Where You Go" below. Users you are not friends with are shown your name, profile photo, friend count and any friends you have in common - not your university, relationship status, gender or Instagram handle.

People Who Go Where You Go: On your home screen we may show you one person who has voted for the same venues as you over the last two weeks, with their name, profile photo and the venue the two of you overlap on most. You may be shown to them on the same basis. This is deliberately somebody you are not already friends with, and it is the one place in the App where a venue you voted for is named to someone who did not vote for it themselves. It is bounded by the same controls as everything else: it never shows a friend, both of you must have "Show me to others at my place" switched on, and it never shows anyone you have blocked or who has blocked you. Turning that setting off takes you out of it entirely.

Asking Friends to Vote: While a poll is open you can ask your friends to vote. That sends a push notification carrying your name to the friends who have not yet voted or opted out in that poll. You can send it once per poll, and each friend can receive it once per poll however many people ask. It only ever goes to your friends, never to anyone you have blocked or who has blocked you, and it does not tell you who had not voted: you are told how many people were reached, not which ones.

Hiding Yourself from Others at Your Venue: In your visibility settings you can turn off "Show me to others at my place". While it is off, users who are not your friends do not see you among the people at the venue you voted for, and in return you do not see them. This is reciprocal and applies only to users you are not friends with: your friends stay visible to each other and can still see each other's votes at all times.

Friends in Common: When another user's profile or name is shown to you, we calculate and display how many friends you have in common.

Blocking: If you block someone, or they block you, neither of you appears to the other anywhere in the App - including the list of people at the same venue, search, friend suggestions and contact sync.

Profile Visibility: Your name and profile photo are visible to other users. Your university, relationship status and gender are visible only to users you are friends with.

Voting History: Your past votes are visible on your profile to users who are your friends.

Posts: Content you post is visible to other users of the App. There is no per-post audience setting, so treat anything you post as visible to the whole community.

Third-Party Services We Use

We rely on the following providers to run the Service. Each of them processes data on our behalf, under a data processing agreement, and none of them is permitted to use your data for their own purposes.

  • Amazon Web Services (AWS) - our databases, file storage, servers and authentication (AWS Cognito). Your account data, posts, photos and votes are stored here, in the Ireland (eu-west-1) region.
  • Google (Firebase Analytics) - product analytics. Receives your user ID, the in-app events you trigger, your device and app version, and your IP address, from which an approximate location is derived.
  • Sentry - crash and error reporting. Receives the diagnostic data described above, including your user ID and IP address.
  • Algolia - user search inside the App. Receives only your user ID, name, profile photo address and timezone. It never receives your email, phone number, date of birth, university, relationship status, gender or votes.
  • Expo - delivery of push notifications. Receives your device's push token and the content of the notification.
  • Google Maps and Google Places - venue search and map display. Receives the searches you type and the approximate area you are searching in.
  • Apple and Google - only if you choose to sign in with them, in which case we receive your name and email address from your existing account with them.

Sharing Your Personal Data

We do not sell or rent your personal data. We may share your data under the following circumstances:

  • With Service Providers - the providers listed in "Third-Party Services We Use" above, each limited to the data described there;
  • With partner venues - when you claim a promotion, the confirmation screen you hold up at the counter shows your name and profile photo, so staff can see the claim is yours. That is all they are shown, we send them nothing about you separately, and a partner receives nothing at all about you unless you claim their offer;
  • For legal reasons - when required to comply with Portuguese or EU laws;
  • In case of business transfers - if our company undergoes a merger, acquisition, or sale of assets;
  • With your consent - when you explicitly authorise sharing for a specific purpose.

Demographic Data: University, relationship status and gender are never shared with third parties or advertisers, in any form - aggregated or otherwise. Within the App they are visible only to users you are friends with.

Retention and Transfer of Your Data

Data Retention

We store your personal data only for as long as necessary:

  • Account data: retained until you delete your account or request removal;
  • Voting history: retained as long as your account is active or until you request deletion;
  • Promotion claims: retained as long as your account is active or until you request deletion;
  • User content: retained until you manually delete it or close your account;
  • Demographic data and Instagram handle: retained until you remove them from your profile or delete your account;
  • Usage data: retained for shorter periods unless required for security or service improvements;
  • Analytics events: retained by our analytics provider for up to 14 months from your last activity;
  • Diagnostic and error reports: retained for up to 90 days;
  • Server logs: retained for 14 days;
  • Encrypted database backups: retained for 7 days, after which deleted data is also gone from the backups.

International Data Transfers

Your account data, posts, photos and votes are stored in the European Union, in AWS's Ireland (eu-west-1) region.

Some of the providers listed above are established in the United States, namely Google, Sentry and Expo. Transfers to them rely on the EU-US Data Privacy Framework where the provider is certified under it, and on Standard Contractual Clauses (SCCs) together with supplementary technical measures otherwise.

Your Rights Over Your Data

Under the GDPR you may ask us to:

  • Access - give you a copy of the personal data we hold about you;
  • Port - provide that copy in a structured, commonly used, machine-readable format;
  • Correct - fix data that is inaccurate or incomplete;
  • Delete - erase your data, as described below;
  • Object or restrict - object to, or ask us to limit, how we process it.

Email [email protected] and we will respond within one month. You also have the right to complain to the Portuguese data protection authority (CNPD).

Deleting Your Data

You may request the deletion of your personal data at any time by:

What we erase. Deleting your account removes your profile and all the details on it, your profile photo and post photos, your posts and comments, your friendships and pending friend requests, your notifications, your blocks and reports, your entry in our search index, and your login credentials with our authentication provider.

What we keep, and in what form. A small number of records outlive the account:

  • Poll votes and feedback you sent us - kept for statistics and product research. They carry no name, email, phone number, photo or demographic detail, but they do keep the internal account identifier they were written with, which no longer resolves to any account;
  • Partner offer redemptions - kept as a count with the link to you removed;
  • Aggregated poll results - the totals per venue per night, which never identified anyone individually;
  • Analytics, diagnostic reports, server logs and backups - these expire on the schedules set out in the Retention section above, the longest being 14 months for analytics.

If you want the retained vote and feedback records erased outright rather than kept in this form, email us at [email protected] and we will do it.

Note: Some data may also be retained where the law requires it, or where it is needed for security or fraud prevention.

Security of Your Personal Data

We implement strong security measures to protect your data, including:

  • Encryption in transit and at rest;
  • Access controls to restrict unauthorised access;
  • Monitoring systems to detect and prevent security breaches.

How photos are stored and served

Profile pictures and post images are held in encrypted cloud storage and delivered over HTTPS. Each image sits at an address built from two random identifiers, which makes the address impractical to guess, but the image itself is served without a sign-in check: anyone holding the address can open it. Treat an image address the way you would treat a shared link.

When you delete a photo or your account, the file is deleted from our storage and the address stops working. Copies already downloaded or cached by someone else are outside our control.

⚠ However, no system is 100% secure, and we cannot guarantee absolute protection against cyber threats.

Age Restrictions

Our Service is only intended for users aged 18 and above. We do not knowingly collect personal data from individuals under 18. If you believe an underage person has provided us with data, please contact [email protected].

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Any significant changes will be communicated via notifications in the App or email. The "Last updated" date at the top reflects the most recent changes.

Contact Us

If you have any questions, concerns, or complaints regarding this Privacy Policy, please contact us at:

[email protected]

Thank you for trusting FOMO! 🚀