onefifty Privacy Policy

Version 1.1 — effective 15 May 2026

onefifty ("we," "us," or "our") operates the onefifty mobile application (the "App"). This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and what rights you have over it.

We take your privacy seriously. onefifty is designed around data minimisation — we collect only what's needed to run the App, we delete content automatically after around 90 days, and we never sell your data or show you ads.

This policy applies to users in the European Union, the United Kingdom, and the United States. If you're in the EU or UK, the General Data Protection Regulation (GDPR / UK GDPR) applies. If you're in California, the California Consumer Privacy Act (CCPA/CPRA) applies. We've written this policy to satisfy both.

1. Who is responsible for your data?

The data controller is:

onefifty
privacy@onefifty.world

2. What data we collect and why

Data you provide directly

Data Why we collect it Legal basis (GDPR) Retention
Phone number Account creation and authentication via SMS one-time passcode. Your phone number is also stored as a one-way salted hash for contact matching (so your friends can find you without us seeing their raw contact list). Contract (account creation) Until you delete your account.
Display name Shown on your profile. Contract Until you delete your account.
Photos and videos The core purpose of the App — sharing moments with the people you choose. Stored in encrypted cloud storage (AWS S3) and delivered via a content delivery network. Contract 30 days after viewed by a recipient, or 90 days if never viewed — whichever comes first. Then permanently deleted from our servers and CDN.
Comments Text responses on shared photos, visible only to you and the person who posted the photo. Contract Deleted when the parent photo expires (30 or 90 days as above).
Reactions Emoji reactions on shared photos, visible only to you and the poster. Contract Deleted when the parent photo expires.
Groups You can organise contacts into groups for easier sharing. Group names and membership are stored on our servers. Contract Until you delete the group or your account.

Data we collect automatically

Data Why we collect it Legal basis (GDPR) Retention
Device push token To send you lock-screen notifications when someone comments on or reacts to your photo. We use Apple Push Notification Service (APNs) for iOS and Firebase Cloud Messaging (FCM) for Android. Consent (you choose whether to allow push notifications) Until you disable push notifications or delete your account.
Location (latitude and longitude) If you grant permission, your location is used to sort your feed by proximity — closest photos appear first. Location is also optionally attached to photos you share so recipients see where the photo was taken. Consent (you choose whether to share location) Your last-known location is stored on your account until updated or your account is deleted. Location on photos is deleted when the photo expires.
App preferences Your chosen theme (light or dark mode). Contract Until you delete your account.

Data we process but do not store

Data What happens Legal basis (GDPR)
Contact list phone number hashes When you use the "find friends" feature, the App hashes your contacts' phone numbers on your device using a one-way salted hash, then sends only the hashes to our server for matching. We never see, transmit, or store your contacts' raw phone numbers. Hashes are compared in memory and discarded — they are not written to our database. Legitimate interest (enabling friend discovery while protecting contact privacy)

Data we do not collect

We do not collect your name (beyond the display name you set), email address, date of birth, browsing history, advertising identifiers, or any data for advertising or profiling purposes. We do not use analytics SDKs, tracking pixels, or third-party analytics services.

3. How we use your data

We use your personal data only to operate the App. Specifically:

We do not use your data for advertising, profiling, automated decision-making, or any purpose beyond operating the App.

4. Who we share your data with

Other users

When you share a photo, the recipients you select can see your display name, the photo/video, its location (if you attached one), and any comments or reactions in your private thread. No other users can see your content. Comments and reactions are private between you and the poster — other recipients cannot see them.

Service providers

We use the following third-party services to operate the App. Each processes data only on our instructions and under a data processing agreement:

Provider Purpose Data shared Location
Amazon Web Services (AWS) Cloud hosting, database, file storage, content delivery, push notification routing All data listed above EU (London, eu-west-2)
Twilio SMS delivery for one-time passcodes during login Your phone number (to send the SMS) US (Twilio's global SMS infrastructure)
Apple (APNs) iOS push notifications Device token + notification content US
Google (FCM) Android push notifications Device token + notification content US
Mapbox Map rendering in the App No personal data is sent to Mapbox from our servers. The mobile app loads map tiles directly. US

Law enforcement

We will disclose personal data to law enforcement only when legally compelled to do so (e.g., by a valid court order or subpoena). We will notify you of such requests unless prohibited by law.

No sale of data

We do not sell, rent, or trade your personal data to anyone. We do not share data with advertisers. We have no advertising business.

5. International data transfers

Our servers are in the European Union (AWS eu-west-2, London). If you are in the EU or UK, your data is stored within the EU/UK.

However, some processing involves transfers outside the EU/UK:

For US users, all data is processed in the EU (London). No special transfer mechanism is needed for data flowing from the US to the EU.

6. Data retention and deletion

onefifty is designed to be ephemeral. Most data is automatically deleted:

Account-level data (phone number, display name, preferences, groups) is retained until you delete your account.

How to delete your account and data

You can delete your onefifty account and all associated data at any time, directly from the app:

  1. Open the onefifty app.
  2. Tap the Settings icon (top left of the global view).
  3. Scroll to the Account section and tap Delete my account.
  4. Confirm the deletion on the screen that follows.

If you no longer have access to the app, email privacy@onefifty.world from the phone number registered to your account and we will process the deletion within 30 days.

What is deleted: your profile, phone number, display name, photos and videos you've posted, comments and reactions you've sent or received on your posts, groups you created, notification history, and your push notification registration. The deletion cascades automatically through our database and CDN and is irreversible.

What is retained: nothing in our application database that can be linked back to you. Our cloud-hosting provider (AWS) may retain low-level infrastructure logs (e.g. request IP addresses, timestamps) for a short period as part of its standard service-operation and security obligations, but these are not used by us to identify former users and contain no app-level personal information.

7. Your rights

If you are in the EU or UK (GDPR)

You have the right to:

To exercise these rights, contact us at privacy@onefifty.world. We will respond within 30 days.

If you are in California (CCPA/CPRA)

You have the right to:

To exercise these rights, contact us at privacy@onefifty.world.

If you are in another US state

Several US states (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and others) have enacted consumer privacy laws similar to the CCPA. If you reside in one of these states, you generally have the right to access, delete, and correct your data, and to opt out of data sales (which we do not engage in). Contact us to exercise these rights.

8. Children's privacy

onefifty is not intended for users under 16. At signup, every user explicitly confirms they are 16 or over. We do not knowingly collect personal data from anyone under that age. If we become aware that we have collected data from a child, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at privacy@onefifty.world.

9. Security

We protect your data with:

No system is 100% secure. If we become aware of a data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours (as required by GDPR) and notify affected users without undue delay.

10. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify you through the App or by other means before the changes take effect. The "Last updated" date at the top of this policy indicates when it was last revised.

11. Contact us

If you have questions about this privacy policy or your personal data, contact us at:

privacy@onefifty.world

If you are in the EU and are unsatisfied with our response, you have the right to lodge a complaint with your local data protection authority.