← Nalgo Legal

Privacy Policy

Last updated: 13 September 2026

Nalgo (“we”, “us”) is operated by Ethan Toushek and Thomas Gaudet. This policy explains what personal information the app collects, why, how it is stored, who can see it, and the choices you have. Questions: nalgosupport@gmail.com.

You need an account

Nalgo requires an account to use. Signed out, the app shows only the sign-in and sign-up screens — there is nothing to browse, no feed, no search, and we do not collect profile information about you before you register.

There is one exception. Any Nalgo user can create a web link for a public community post and send it to someone who does not have Nalgo. Opening that link shows that single post, read-only, and nothing else — no feed, no profile, no comments, no way to move to another post. Visiting a shared link does not create an account and we do not build a profile of you for doing it. See Shared links below.

What we collect

When you create an account and use Nalgo, we collect:

We do not use third-party advertising, and we do not use analytics or tracking SDKs for profiling.

Stored on your device only

Some things are stored locally on your device and are not sent to our servers: your tab layout and visibility choices, your personal community colour customisations, your appearance/theme preference, and locally cached engagement such as which posts you have liked and your message read markers.

Permissions the app asks for

PermissionWhy
Photo library So you can attach photos and videos to a post. We only receive the files you pick.
Camera So you can take a photo or video for a post.
Microphone So videos you record have sound.
Notifications So we can tell you about a direct message or a friend request while the app is closed. Only asked for when you turn notifications on in Settings.

You can decline any of these and keep using the rest of the app. We do not access your location, contacts, or microphone outside of recording a video.

Who can see your information

These visibility rules are enforced on the server with row-level security, not only in the app.

How your information is stored and protected

Your data is stored using Supabase (PostgreSQL database, authentication, and file storage). Access is protected by row-level security policies, connections use HTTPS/TLS, and passwords are hashed by the authentication provider. No method of transmission or storage is completely secure, but we take reasonable measures to protect your information.

Our Supabase project is hosted in the United States — AWS region us-east-2 (Ohio) — and your data is stored and processed there. If you use Nalgo from outside the United States, including from the European Economic Area or the United Kingdom, your information is transferred to the United States, where data protection law differs from that of your own country. Where such a transfer is subject to UK or EU law, it is covered by the Standard Contractual Clauses in Supabase’s data processing agreement.

Third parties

That is the complete list. Nalgo contains no analytics, advertising, or crash-reporting SDKs, and no third-party trackers. Account confirmation and password reset emails are sent through Resend on our behalf, to the address you signed up with.

We do not sell your personal information.

You can create a web link for a public community post, so you can send it to someone who does not use Nalgo. The link contains a long random token; it is not guessable and the links cannot be listed or enumerated. We do not ask search engines to index them.

A link is nonetheless a bearer key: anyone who has it can open the post, and anyone your recipient forwards it to can open it as well. Do not create one for something you would not be comfortable being passed on.

What a visitor sees is that one post — its text, its images or video, its tags, and the display name, @handle and avatar of the author. They do not get your account id, your other posts, your profile page, comments, likes, or any way to navigate anywhere else in Nalgo.

Any signed-in Nalgo user can create a link for a public community post — their own or someone else's. This is possible because a community post is already readable by every signed-in Nalgo user; a link does not widen who may read it inside Nalgo, it lets one specific person read it without signing up.

If someone links your post and you would rather they had not, you can revoke that link. A link also stops working as soon as the post is deleted, switched out of the public feed, or the account is suspended or deleted. Inner Circle posts, Niche posts and direct messages cannot be linked at all.

Notifications

Push notifications are off until you turn them on. When they are on, we send you a notification when someone sends you a direct message or adds you.

A notification carries the sender’s name and the first part of their message, so that content passes through Expo and then through Apple’s or Google’s push service on its way to your device, and it can appear on your lock screen. If that matters to you, you can turn off the message type you do not want in Settings, turn notifications off altogether, or hide notification previews in your device settings.

Turning notifications off in Settings deletes that device’s push token from our servers. Signing out or deleting your account does the same.

Your choices and rights

If you are in Canada

Nalgo is operated from Ontario, Canada, and handles personal information in line with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). Our Privacy Officer, Ethan Toushek, is accountable for how Nalgo handles personal information. You can reach him at nalgosupport@gmail.com (put “Privacy” in the subject line).

Legal bases for processing

If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR:

Data retention

We keep your information for as long as your account exists. When you delete your account, the data above is removed. Backups, if any, are retained for up to 30 days before being overwritten.

Moderation records — reports, suspensions, and the content they concern — are kept for two years after an account is deleted, so that a banned user cannot erase the record by deleting their account. When something is reported, a private copy of it is kept for that period even if it is later removed or deleted. Only our moderators can access it.

Where the law requires us to preserve information for longer — for example, after reporting child sexual abuse material to the police — we keep it for as long as that requires.

Age

Nalgo is for people aged 17 and over. It is not directed to children or to younger teenagers, and we do not knowingly collect personal information from anyone under 17. If you believe someone under 17 has created an account or given us information, contact nalgosupport@gmail.com and we will delete it.

Changes to this policy

We may update this policy from time to time. We will update the “Last updated” date above and, for material changes, provide a more prominent notice in the app.

Contact

Questions or requests: nalgosupport@gmail.com