Last updated: 13 September 2026
Nalgo (“we”, “us”) is operated by Ethan Toushek and Thomas Gaudet. This policy explains what personal information the app collects, why, how it is stored, who can see it, and the choices you have. Questions: nalgosupport@gmail.com.
You need an account
Nalgo requires an account to use. Signed out, the app shows only the sign-in and sign-up screens — there is nothing to browse, no feed, no search, and we do not collect profile information about you before you register.
There is one exception. Any Nalgo user can create a web link for a public community post and send it to someone who does not have Nalgo. Opening that link shows that single post, read-only, and nothing else — no feed, no profile, no comments, no way to move to another post. Visiting a shared link does not create an account and we do not build a profile of you for doing it. See Shared links below.
What we collect
When you create an account and use Nalgo, we collect:
- Account credentials — your email address and a password, handled by our authentication provider (Supabase). Your password is stored only as a secure hash; we never see it in plain text. Your email is used for sign-in and account confirmation and is never shown to other users.
- Date of birth — collected at sign-up to confirm you are at least 17. It is stored against your login, not on your public profile, and is never shown to other users.
- Agreement record — the version of our Terms you agreed to and the date you agreed.
- Profile information — a @handle (auto-generated at sign-up, which you can change), and any optional display name, bio, location, and profile picture you add.
- Interests — the communities and topics you pick, which power discovery of people with shared interests.
- Content you create — posts, comments, community chat messages, and any images or videos you attach, stored in Supabase Storage.
- Connections — your friend and Inner Circle relationships.
- Direct messages — the private messages you send and receive.
- Device push token — only if you turn on push notifications. This is an identifier issued by Expo for the app on that particular device, which Expo maps to the underlying Apple or Google token when it delivers, and it is what lets us send a notification to it. It is not linked to anything else about your device, and it is deleted when you turn notifications off, sign out, or delete your account.
- Moderation records — users you block, reports you submit, and reports submitted about you. A report about an account is kept even if that account is deleted, so that the record of it survives.
We do not use third-party advertising, and we do not use analytics or tracking SDKs for profiling.
Stored on your device only
Some things are stored locally on your device and are not sent to our servers: your tab layout and visibility choices, your personal community colour customisations, your appearance/theme preference, and locally cached engagement such as which posts you have liked and your message read markers.
Permissions the app asks for
| Permission | Why |
|---|---|
| Photo library | So you can attach photos and videos to a post. We only receive the files you pick. |
| Camera | So you can take a photo or video for a post. |
| Microphone | So videos you record have sound. |
| Notifications | So we can tell you about a direct message or a friend request while the app is closed. Only asked for when you turn notifications on in Settings. |
You can decline any of these and keep using the rest of the app. We do not access your location, contacts, or microphone outside of recording a video.
Who can see your information
- Email and date of birth — only you. Never shown to other users.
- Profile fields (@handle, display name, bio, location, avatar) — visible to any signed-in user, since they power people discovery.
- Likes — the interests you add are visible to any signed-in user, since they are how Nalgo matches people with shared interests.
- Public community posts and chat — visible to anyone signed in. A post is not visible to signed-out visitors unless someone creates a share link for it, which any signed-in user can do for any public community post. You can revoke a link to your own post.
- Niches — a Niche’s name and the likes it is about are visible to any signed-in user, and any signed-in user can join a Niche. Once they join, they can read its posts and chat. Treat what you share in a Niche as visible to anyone who shares those likes, not as private.
- Inner Circle posts — visible only to the people you place in your Inner Circle.
- Direct messages — visible only to you and the person you are messaging.
- Photos and videos added to Inner Circle posts, Niches, and direct messages from 13 September 2026 onward are stored privately and can only be opened by people who can see the post or message they belong to, through links that expire after two hours. Ones added before that date are stored at an unlisted web address that anyone who has the exact link can open.
- Blocks and reports — not shown to the people they concern.
- Moderators — our moderators can see content that has been reported, in order to review it.
These visibility rules are enforced on the server with row-level security, not only in the app.
How your information is stored and protected
Your data is stored using Supabase (PostgreSQL database, authentication, and file storage). Access is protected by row-level security policies, connections use HTTPS/TLS, and passwords are hashed by the authentication provider. No method of transmission or storage is completely secure, but we take reasonable measures to protect your information.
Our Supabase project is hosted in the United States — AWS region
us-east-2 (Ohio) — and your data is stored and processed there.
If you use Nalgo from outside the United States, including from the European
Economic Area or the United Kingdom, your information is transferred to the
United States, where data protection law differs from that of your own
country. Where such a transfer is subject to UK or EU law, it is covered by
the Standard Contractual Clauses in Supabase’s data processing agreement.
Third parties
- Supabase — database, authentication, and file storage.
- Vercel — hosts the Nalgo website (nalgo.ca), including shared-post links and the password reset page. Like any web host, it receives your IP address and basic request details when you visit.
- Resend — sends account emails, such as sign-up confirmation and password reset, from no-reply@nalgo.ca. It receives the email address a message is sent to and the message itself.
- Expo — app builds, over-the-air updates, and the push notification service that forwards our notifications to Apple and Google.
- Apple and Google — the push notification services built into iOS and Android. A notification we send passes through them to reach your device. This only applies if you turn notifications on.
That is the complete list. Nalgo contains no analytics, advertising, or crash-reporting SDKs, and no third-party trackers. Account confirmation and password reset emails are sent through Resend on our behalf, to the address you signed up with.
We do not sell your personal information.
Shared links
You can create a web link for a public community post, so you can send it to someone who does not use Nalgo. The link contains a long random token; it is not guessable and the links cannot be listed or enumerated. We do not ask search engines to index them.
A link is nonetheless a bearer key: anyone who has it can open the post, and anyone your recipient forwards it to can open it as well. Do not create one for something you would not be comfortable being passed on.
What a visitor sees is that one post — its text, its images or video, its tags, and the display name, @handle and avatar of the author. They do not get your account id, your other posts, your profile page, comments, likes, or any way to navigate anywhere else in Nalgo.
Any signed-in Nalgo user can create a link for a public community post — their own or someone else's. This is possible because a community post is already readable by every signed-in Nalgo user; a link does not widen who may read it inside Nalgo, it lets one specific person read it without signing up.
If someone links your post and you would rather they had not, you can revoke that link. A link also stops working as soon as the post is deleted, switched out of the public feed, or the account is suspended or deleted. Inner Circle posts, Niche posts and direct messages cannot be linked at all.
Notifications
Push notifications are off until you turn them on. When they are on, we send you a notification when someone sends you a direct message or adds you.
A notification carries the sender’s name and the first part of their message, so that content passes through Expo and then through Apple’s or Google’s push service on its way to your device, and it can appear on your lock screen. If that matters to you, you can turn off the message type you do not want in Settings, turn notifications off altogether, or hide notification previews in your device settings.
Turning notifications off in Settings deletes that device’s push token from our servers. Signing out or deleting your account does the same.
Your choices and rights
- Edit your profile at any time in the app.
- Delete your account — Profile → Account Settings → Delete account. This permanently removes your profile, posts, comments, attachments, interests, friendships, and direct messages (both sent and received) from our servers. See Delete Your Account for the full steps, including how to request deletion without the app.
- Depending on where you live, you may have additional rights to access, correct, export, restrict, or object to the processing of your personal data, and to lodge a complaint with your data protection authority. To exercise any of these, contact nalgosupport@gmail.com. We respond within 30 days.
If you are in Canada
Nalgo is operated from Ontario, Canada, and handles personal information in line with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA). Our Privacy Officer, Ethan Toushek, is accountable for how Nalgo handles personal information. You can reach him at nalgosupport@gmail.com (put “Privacy” in the subject line).
- You can ask to see the personal information we hold about you, and to have it corrected if it is wrong. We respond within 30 days.
- You can withdraw your consent at any time, subject to legal or contractual restrictions — for example, by turning off notifications or deleting your account.
- If you are not satisfied with how we handle a privacy concern, you can complain to the Office of the Privacy Commissioner of Canada.
Legal bases for processing
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR:
- Performance of a contract. Creating and running your account, showing your profile and posts to other people, and delivering your messages — the service you signed up for.
- Legitimate interests. Keeping Nalgo safe and usable: handling reports, moderating content, enforcing the Terms, preventing abuse and spam, and keeping the service secure and working.
- Consent. Anything optional you explicitly opt into, such as access to your photos and camera roll when you upload an image or video. You can withdraw that consent at any time in your device settings.
- Legal obligation. Where we have to keep or disclose information to comply with the law — for example, reporting child sexual abuse material to the authorities and preserving the related data.
Data retention
We keep your information for as long as your account exists. When you delete your account, the data above is removed. Backups, if any, are retained for up to 30 days before being overwritten.
Moderation records — reports, suspensions, and the content they concern — are kept for two years after an account is deleted, so that a banned user cannot erase the record by deleting their account. When something is reported, a private copy of it is kept for that period even if it is later removed or deleted. Only our moderators can access it.
Where the law requires us to preserve information for longer — for example, after reporting child sexual abuse material to the police — we keep it for as long as that requires.
Age
Nalgo is for people aged 17 and over. It is not directed to children or to younger teenagers, and we do not knowingly collect personal information from anyone under 17. If you believe someone under 17 has created an account or given us information, contact nalgosupport@gmail.com and we will delete it.
Changes to this policy
We may update this policy from time to time. We will update the “Last updated” date above and, for material changes, provide a more prominent notice in the app.
Contact
Questions or requests: nalgosupport@gmail.com