Skip to the privacy policy
CirunaCiruna

Ciruna privacy policy

Privacy Policy & Data Protection

This policy explains what personal data we collect when you use Ciruna, why we use it, who we share it with, how long we keep it and the rights you have under the EU General Data Protection Regulation (GDPR).

Effective: 31 July 2026Version: 1.0Contact: privacy@cirunaapp.eu

1. Privacy at a glance

Ciruna exists to help parents and caregivers find genuine local friends. That only works if people feel safe sharing a little about their family. These are the promises behind every decision in this policy.

Minimum data, maximum trust.

We collect what is needed to match you with nearby families, keep the community safe and run memberships—nothing more.

You choose what is public.

Your interests, languages, life stage and kid age bands are shown to members so they can find people like you. Your exact address is never shown.

Children stay out of the spotlight.

We ask only for age bands, never names, photos, schools or birth dates of children.

We never sell personal data.

Curated partner recommendations are chosen by us and shown to everyone in a country; advertisers receive no personal data about you.

Safety data is handled carefully.

Reports and blocks are visible only to moderators and our safety team, and are kept confidential from the reported member where possible.

You can leave and take your data.

Export or delete your account at any time from your profile settings, or by writing to us.

This summary is for orientation only. The sections below are the binding description of our processing, and should be read together with our Terms, Community Standards & Safety Guidelines.

2. Who is responsible for your data

The data controller for personal data processed through Ciruna is Ciruna Community OÜ, Tallinn, Estonia (company number: Registration pending).

We have not appointed a statutory Data Protection Officer because our processing does not meet the thresholds in Article 37 GDPR. Privacy questions are handled directly by our team at privacy@cirunaapp.eu.

3. Data we collect

You give us

  • Account data: email address, password (stored only as a salted hash by our authentication provider), preferred language and, if you sign in with Google, the basic profile fields Google returns.
  • Profile data: display name, short bio, country, municipality or city, life stage, parenting style, kid age bands (0–1, 1–3, 3–6, 6–13, 13–18, 18+), up to three languages and up to three interests per category, including any free-text tags you type yourself.
  • Community activity: villages you follow, meetups you post or join, event RSVPs, meetup invites you send or receive, and messages exchanged with other members.
  • Feedback: problem reports, improvement ideas, general feedback and country suggestions you submit through the feedback form.
  • Safety data: reports and blocks you submit, including the free text you write.
  • Requests: municipality or area requests you send when your region is not yet listed.

We collect automatically

  • Technical data: IP address, device and browser type, operating system, language settings and timestamps of requests.
  • Usage data: pages and screens visited, features used, sign-in times (used to show whether an account was active in the last 30 days) and error diagnostics.
  • Push subscription data: the browser push endpoint and encryption keys, only if you enable notifications.

We receive from others

  • Payment status and limited transaction metadata from our payment provider (never full card numbers).
  • Verification outcomes from our identity verification provider, where such a check applies to your account.
  • Referral information when another member's referral or founding code is used at sign-up.
Please do not overshare.Free-text fields—bio, interests, meetup descriptions and messages—are yours to control. Avoid entering home addresses, children's full names, health details or anything you would not want another member to read.

4. Why we use your data and our legal bases

Under the GDPR we must have a legal basis for every purpose. Ours are set out below.

Contract (Art. 6(1)(b))

  • Creating and maintaining your account and profile.
  • Showing you nearby families, meetups, events and villages, and letting others find you.
  • Delivering messages, meetup invites and RSVPs.
  • Processing membership purchases, verification fees, discounts and referral credit.
  • Providing member support.

Legitimate interests (Art. 6(1)(f))

  • Keeping the community safe: moderation, report and block handling, fraud and abuse prevention, and enforcing our Terms.
  • Securing the service, debugging and preventing misuse of free founding slots and discount codes.
  • Improving the product using aggregated usage insight and the feedback you send us.
  • Showing curated partner recommendations selected by country, without profiling you individually.

Where we rely on legitimate interests we have balanced them against your rights, and you may object at any time (see Your rights).

Consent (Art. 6(1)(a))

  • Browser push notifications.
  • Optional non-essential cookies or analytics, where used.
  • Any special-category information you volunteer in free-text fields, such as religion, health or beliefs relevant to your parenting approach.

You can withdraw consent at any time; this does not affect processing already carried out.

Legal obligation (Art. 6(1)(c)) and vital interests (Art. 6(1)(d))

  • Accounting and tax records for payments.
  • Responding to lawful requests from authorities.
  • Acting where there is a risk of serious harm to a person, including a child.

5. What other members can see

Signed-in members in your country can see your display name, bio, life stage, parenting style, kid age bands, languages, interests and municipality or city. Meetups and events you post, and your attendance in them, are visible to the members who can see that meetup or event.

Premium members can browse profiles in their area on the nearby page and send meetup invites. Whether you have a verified badge or premium membership is also visible.

  • Your email address is never shown to other members.
  • Your exact address and precise coordinates are never shown; distance is derived from your municipality or city.
  • Payment details, verification documents, reports and blocks are never shown to other members.
  • Blocked members cannot see your profile or contact you.

6. Identity verification data

Verification helps keep the community adult-only and accountable. Depending on the checks that apply to your account, verification may involve your email, phone number, age or an identity document reviewed by a specialist provider acting as our processor.

We aim to store only the outcome of a check—verified or not, the method used and the date—not the underlying document images, which are handled and deleted by the provider according to its own retention rules.

A verified badge confirms only the checks described in the app. As explained in our Terms, it is not a background, criminal-record or childcare-licensing check.

7. Children's data

Ciruna is for adults. Only people aged 18 or over may create an account, and children may not use the service or communicate through it.

To help match families we ask for kid age bands rather than personal details. We do not ask for and you should not enter children's full names, birth dates, schools, kindergartens, health information or identifiable photographs.

If a child's data appears anyway.Tell us at privacy@cirunaapp.eu or report the content in the app. We remove identifiable children's data promptly once we become aware of it.

8. Payments and membership

One-time payments—such as lifetime verification or lifetime premium—are processed by our payment provider, Stripe. Stripe collects your card or payment details directly; we never receive or store full card numbers.

We store the fact that a purchase was made, the product and amount, the currency, the time, any code or discount applied, and the resulting membership status on your account. Invoices and transaction records are kept for the statutory accounting period.

Founding slots, referral credit and discount links are tracked against your account so that free and reduced-price offers can be granted fairly per municipality.

9. Messages, meetups and events

Messages and meetup invites are stored in our database so they can be delivered and shown in your inbox. They are not end-to-end encrypted, which means our safety team can access specific conversations when investigating a report or a legal request.

We do not read private messages routinely and do not use them for advertising or profiling. Meetup and event details you publish, including the public place, time and description, are visible to the members eligible to see them.

10. Notifications and email

If you enable browser push notifications, we store the push endpoint and keys your browser generates so we can notify you about RSVPs, messages, follows, invites and events. You can revoke this at any time in the app or in your browser settings, and we delete the subscription.

Service emails necessary for the contract—such as sign-in, verification and purchase confirmations—are sent on the basis of our contract with you. Any optional community newsletter is sent only with your consent and always includes an unsubscribe link.

11. Location and neighbourhood data

We work at municipality, kommun or city level, not street level. You choose your area yourself from a searchable list; we do not track your device GPS in the background.

Distance filters on the nearby page are approximate and calculated from the centre of the areas concerned, so that browsing never reveals where anyone actually lives.

12. Reports, blocks and moderation

When you report a member or content, we process your report text, the account reported, related messages or posts, and the outcome. Reports are visible to our safety team and, where relevant, to the local moderators who help run your area.

We keep reports and blocks confidential from the reported member where we can, but we may have to describe the substance of a complaint in order to act on it fairly.

Records of serious violations, removals and bans may be retained after account deletion to prevent the same person from returning, on the basis of our legitimate interest in community safety.

13. Cookies and local storage

We keep cookie use to a minimum.

  • Strictly necessary: session and authentication tokens that keep you signed in, and security cookies that protect forms. These cannot be switched off without breaking the service.
  • Functional: your language choice and interface preferences, stored in your browser's local storage.
  • Payment: cookies set by Stripe during checkout to complete the transaction and prevent fraud.

We do not use advertising or cross-site tracking cookies. If we ever introduce non-essential analytics or advertising cookies, we will ask for your consent first.

14. Analytics and product improvement

We look at aggregated, non-identifying measures—such as how many members joined a municipality, how many meetups were created, or which screens produce errors—to decide what to build next.

Feedback you submit is stored with your account so we can follow up, and is visible to administrators in an internal admin view. Administrators can also see aggregate lists of members by country and neighbourhood, moderator status, recent activity and meetup participation, in order to run and support the community.

We do not build advertising profiles and do not use your data to train third-party AI models.

15. Who we share data with

We never sell personal data. We share it only with service providers acting on our instructions under a data processing agreement, and with others where the law requires it.

  • Hosting, database, authentication and storage provider — runs the application and stores account, profile and community data.
  • Payment provider (Stripe) — processes payments and prevents payment fraud.
  • Identity verification provider — performs verification checks where they apply.
  • Email and push delivery providers — deliver service notifications you have asked for.
  • Error and performance monitoring — helps us find and fix faults.
  • Professional advisers, accountants and authorities — where legally required or to establish or defend legal claims.

Local moderators are members who help run their area. They act under our instructions, accept confidentiality obligations, and can see only what is needed for moderation and local event management.

16. International transfers

We aim to keep personal data within the European Economic Area. Some providers may process data outside the EEA, for example in the United States.

Where that happens, we rely on an adequacy decision of the European Commission or on the Commission's Standard Contractual Clauses together with additional safeguards. You can request details of the safeguards used by writing to privacy@cirunaapp.eu.

17. How long we keep data

  • Account and profile data: for as long as your account exists, then deleted or anonymised within 30 days of deletion.
  • Messages and meetup invites: for as long as your account exists; after deletion, your side is removed and remaining copies are anonymised.
  • Meetups and events: kept while relevant to the community; the organiser's name is anonymised after account deletion.
  • Feedback: up to 24 months, or longer in anonymised form for product statistics.
  • Reports, blocks and moderation records: up to 3 years after the case is closed, and longer for serious safety cases.
  • Payment and accounting records: 7 years, as required by Estonian accounting law.
  • Verification outcomes: for as long as the badge is valid, then as needed to prevent re-registration abuse.
  • Technical logs: normally 30–90 days.
  • Push subscriptions: until you disable notifications or the browser endpoint expires.

18. How we protect data

  • Encryption in transit (HTTPS/TLS) and encryption at rest for the database.
  • Row-level security policies so members can only reach the records they are entitled to.
  • Hashed passwords and tokenised sessions; we never store passwords in readable form.
  • Least-privilege access for staff and moderators, with administrative views restricted to administrators.
  • Regular dependency and security reviews, and prompt patching of issues we find.

No online service can be completely secure. If a personal data breach is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours and inform affected members where required.

19. Your rights

Under the GDPR you have the right to:

  • Access — obtain a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data, most of which you can edit yourself in your profile.
  • Erasure — have your data deleted where there is no overriding legal or safety reason to keep it.
  • Restriction — ask us to pause processing while a dispute is resolved.
  • Portability — receive the data you provided in a structured, machine-readable format.
  • Objection — object to processing based on our legitimate interests, including profiling.
  • Withdraw consent — at any time, for anything based on consent such as push notifications.
  • Complain — to a supervisory authority (see below).

Write to privacy@cirunaapp.eu to exercise any right. We respond within one month and may extend by two further months for complex requests, telling you why. We may ask you to confirm your identity before acting, and we will not charge a fee unless a request is manifestly unfounded or excessive.

20. Deleting your account

You can delete your account from your profile settings, or by emailing support@cirunaapp.eu from the address on your account.

Deletion removes your profile, follows, interests, RSVPs and push subscriptions, and anonymises the content you leave behind—for example a meetup you organised will no longer show your name. Some records survive deletion where the law or community safety requires it: accounting records, and moderation records relating to serious violations.

One-time lifetime purchases are tied to your account. Deleting the account ends access to those benefits and does not create a right to a refund beyond your statutory withdrawal rights described in our Terms.

21. Changes to this policy

We update this policy when the service or the law changes. The version number and effective date at the top always tell you which version applies.

For material changes we give reasonable advance notice in the app or by email. Continuing to use Ciruna after a change takes effect means the updated policy applies to you.

22. Contact and complaints

We would always like the chance to resolve a concern first. Please contact us before escalating—most issues are answered within a few days.

Controller:
Ciruna Community OÜ
Address:
Tallinn, Estonia
Privacy and data requests:
privacy@cirunaapp.eu
Safety concerns:
safety@cirunaapp.eu
General support:
support@cirunaapp.eu
Legal notices:
legal@cirunaapp.eu
Supervisory authority:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, Tallinn

You may also lodge a complaint with the data protection authority in the EU country where you live or work.

Our privacy commitment

We collect the least we can, show only what helps you find your people, protect children by keeping them out of the data, never sell anything about you, and make it easy to take your data and leave.