π Ξλληνικά Β· English Β· EspaΓ±ol
π Privacy Policy
Last updated: 13 July 2026
Version: 2.1
This Privacy Policy explains how ShareIt ("we", "the app") collects, uses, stores and protects your personal data, in compliance with the General Data Protection Regulation (GDPR β EU Regulation 2016/679) and Greek law.
1. Data Controller
Name: Christos Katsios
Email: Christos.katsios1@gmail.com
Location: Greece
Status: Individual developer (natural person)
For any matter relating to your personal data, please contact us at the email address above.
2. Data we collect
2.1 Account details (required)
- Email
- First & last name
- Password hash (encrypted β no plain-text password is stored)
- Phone number β optional. It is used to verify your account (SMS OTP). Without a verified phone number you can still use the app normally, but you appear to others as an "unverified user".
Your email and phone number are NOT visible to other users. They are stored separately from your public profile and are accessible only by you.
2.2 Profile details (optional)
- Profile photo
- Bio
- Additional photos
2.3 Location data
- GPS coordinates β only with your consent
- Use: displaying listings near you, map
- You may decline access and enter a location manually
2.4 Activity data
- Listings you create (photos, title, description, location)
- Chat messages
- Comments & likes on posts
- Reactions to messages
- Deals & reviews
- Friends & blocked users
- Saved listings
- Record of acceptance of the Terms and of age (consent timestamp)
2.5 Technical data
- FCM token (for push notifications)
- Last login (lastSeen timestamp)
- IP address (via Firebase, for security)
3. Legal basis for processing (GDPR Article 6)
| Type of data | Legal basis |
| Account details | Contract (Article 6(1)(b)) |
| Location | Consent (Article 6(1)(a)) |
| Push notifications | Consent (Article 6(1)(a)) |
| Reports & blocks | Legitimate interest (Article 6(1)(f)) |
| Security logs | Legitimate interest (Article 6(1)(f)) |
| Acceptance of the Terms | Contract (Article 6(1)(b)) |
4. Purpose of processing
- Providing the app's services (listings, chat, deals)
- Communication between users
- Security (block, report, fraud prevention)
- Improving the user experience (anonymous analytics)
- Compliance with legal obligations
5. Where the data is stored β Data Processors
Data is stored on Google Firebase servers:
- Region: europe-west1 (Belgium, EU)
- Provider: Google Cloud Platform (GCP)
- Legal relationship: Google acts as a Data Processor under GDPR Article 28, on the basis of the Google Cloud Data Processing Addendum
- GDPR-compliant: β
Yes
- Encryption: AES-256 in transit & at rest
Further information: Google Cloud DPA
6. Retention period (Data Retention)
| Data | Retention |
| Active account | Until deleted by the user |
| Listings | Deleted automatically 30 days after posting (or earlier, if you set an expiry date). You can renew them before they expire to keep them active. |
| Chat messages | Until account deletion |
| Reports | 2 years, anonymised (legal obligation) |
| Deleted account | Immediate deletion of all data (at the same moment) |
| Security logs | 90 days |
7. User rights (GDPR Articles 15-22)
7.1 Right of access
View all your data from the app's profile section. For a full copy in a structured format, send us an email.
7.2 Right to rectification
Settings β Edit Profile. For details you cannot change within the app, send us an email.
7.3 Right to erasure ("right to be forgotten")
Settings β Delete Account. Full deletion of all data (listings, chats, deals, posts, friends, photos, auth) immediately, at the same moment. Reports are retained in anonymised form for 2 years on the basis of a legal obligation.
7.4 Right to data portability
Send an email to Christos.katsios1@gmail.com requesting a written export of all your data in JSON format. Response within 30 days (GDPR Article 12).
7.5 Right to object
At any time, by email.
7.6 Right to withdraw consent
Settings β Permissions (for location, notifications). You may also withdraw your consent by email.
7.7 Right to lodge a complaint
Hellenic Data Protection Authority:
π www.dpa.gr β 1-3 Kifissias Ave., 11523 Athens
8. Sharing with third parties
We do not sell your data. We share data only:
- With other users of the app: Name, profile photo, listings, comments β whatever you make public
- With Google (Firebase) as a Data Processor: Authentication, Firestore database, Cloud Messaging, Storage, Cloud Functions β all GDPR-compliant under Article 28
- With Google (Firebase Crashlytics): Crash reports. These include technical diagnostics: device type, operating system version, error stack trace and an anonymous installation identifier. They do not include the content of your messages.
- With Google Maps: When you use the map, location data is processed by the Google Maps SDK in order to display the map.
- With Google Sign-In: If you choose to sign in with a Google account, we receive your name, email and profile photo from Google.
- With authorities: Only where required by law (e.g. a court order)
9. Data breach procedure
In the event of a security breach affecting your personal data:
- You will be notified within 72 hours by email & push notification (GDPR Article 33)
- The Data Protection Authority will be notified within 72 hours
- You will receive detailed guidance on protective measures to take
- An internal investigation and remediation will be launched in parallel
10. Cookies, tracking & diagnostics
The app does NOT use tracking cookies, advertising SDKs, an advertising identifier (Advertising ID), or usage analytics (Firebase Analytics is not used).
The app uses Firebase Crashlytics (Google) for crash and stability reporting. When the app crashes or encounters an error, technical diagnostic data is sent:
- Device model, Android version, app version
- Technical description of the error (stack trace) and the time it occurred
- An anonymous installation identifier (installation ID) β this is not your name, email or phone number
Purpose: exclusively to fix bugs and ensure the stability of the app (legitimate interest, Article 6(1)(f) GDPR). This data is not used for advertising, user profiling or behavioural tracking, and does not include the content of your messages, listings or photos.
If you do not wish crash reports to be sent, email us and we will disable collection for your account.
11. Age limit
The app is permitted only for users aged 18 and over.
- Explicit confirmation of age is required at registration (checkbox)
- We do not knowingly collect data from minors
- If we identify a minor's account, it is deleted immediately
- Parents who believe that a minor has created an account: email us for immediate deletion
12. International data transfers
Data remains within the EU (Firebase europe-west1). In the event of a transfer outside the EU:
- It is carried out under Standard Contractual Clauses (SCCs)
- In compliance with GDPR Articles 44-49
13. Security measures
- AES-256 encryption on all data
- HTTPS/TLS across all communications
- Firestore Security Rules for access control
- Password hashing via Firebase Authentication
- SMS OTP verification for phone numbers
- Security logs to monitor breaches
- Automatic detection and hiding of listings after multiple reports
14. Changes to this policy
In the event of significant changes:
- You will be notified by email and push notification
- You will have 30 days to accept the new changes
- If you do not accept them, you may request deletion of your account
15. Contact
For any GDPR matter or questions: