N2U / PRIVACY
Privacy Policy
Effective and last updated: July 16, 2026
N2U is a location-aware social discovery service for people age 16 and older. We minimize precise-location exposure, do not sell personal information, and provide in-app controls for visibility, access, export and deletion. This policy describes the service as implemented; it does not claim that any online system is risk-free.
1. Who controls your data
N2U ("N2U", "we", "us") is responsible for the personal information described here. Privacy requests may be sent to privacy@n2u.app. Safety and support requests may be sent to support@n2u.app.
2. Information we process
| Category | Examples | Primary purpose |
|---|---|---|
| Account and eligibility | Apple/Google subject identifier, email when provided, birth date or age result, consent records, device-bound session data | Sign-in, 16+ eligibility, account security and legal records |
| Profile and claims | Name, photo, city, languages, interests, school-related claims, social handles, card appearance and verification status | Create your card, discovery and claim verification |
| Location and proximity | Device coordinates during authorized use; reduced/approximate discovery cells; venue, event and distance context | Radar, map, crossed paths, venue rooms, hangouts and safety features |
| Events and attendance | Hangouts, participant and request state, rotating QR check-in, attendance feedback, no-show history, ratings and reviews | Operate events, deter fraud and show evidence-based participation signals |
| Communications | Encrypted message payloads, public keys, nonce, sender/recipient, timestamps, delivery/read state and retention setting | Deliver encrypted chat, synchronize receipts and prevent abuse |
| Social and game activity | Intent handshakes, crews, drops, Arena lobbies, answers, votes and server-controlled game state | Provide requested social and game features |
| Safety and integrity | Reports, blocks, appeals, risk signals, Safety Capsule state, approximate meeting context, device/IP abuse indicators | Moderation, fraud prevention, rate limiting and user safety |
| Diagnostics and purchases | App version, platform, crash/diagnostic events, subscription entitlement and store transaction references | Reliability, support, entitlement validation and security |
3. How information is collected
We receive information directly from you, from device permissions you choose to grant, from your interactions with other users, from Apple or Google sign-in, from app-store purchase systems, and from service providers operating infrastructure on our behalf. Location permission can be changed in device settings. Some discovery features cannot work without location, but unrelated safety and account controls remain available.
4. Why we process information
Depending on your location, processing is based on performing the service you request, your consent, compliance with law, and legitimate interests such as security, moderation, service reliability and fraud prevention. We do not repurpose sensitive or location data for advertising. We do not sell or rent personal information.
5. Location protections
Other users are shown privacy-safe distance or venue context, not a raw coordinate. Discovery storage reduces location precision to an approximate cell. Private Radar levels include hidden and restricted visibility options. Searchable maps display aggregate density and public event context rather than a list of exact user positions. No location feature is an emergency-location service.
6. Messages and encryption
Supported cloud conversations use X25519 key agreement, HKDF-SHA256 and ChaCha20-Poly1305 authenticated encryption on participant devices. The server receives encrypted message content and routing metadata. Encryption protects content on supported clients, but it cannot prevent a recipient from saving or sharing content they receive. Account or device compromise and unsupported or obsolete clients remain risks. N2U does not use Bluetooth or peer-to-peer nearby messaging.
7. Sharing and service providers
We disclose only what is needed to infrastructure, database/storage, push notification, monitoring, content-moderation, payment/store and customer-support providers acting for N2U. Public profile fields, public hangouts and reviews are shared according to the visibility you select. We may disclose information to comply with valid legal process, investigate threats, protect rights and safety, or complete a corporate transaction subject to appropriate safeguards.
The interactive public website map uses Apple Maps, with MapLibre and map data delivered by OpenFreeMap as an availability fallback. When a map loads, its provider may receive standard connection information such as IP address, browser user agent and map requests. The website map does not send N2U account coordinates or expose exact user positions.
8. International transfers
Providers and users may be located outside your province or country. Where required, N2U uses contractual, consent-based or other legally recognized safeguards for cross-border processing. Data may be subject to lawful access in the jurisdiction where it is processed.
9. Retention
- Profile and account data: while the account is active, then deleted or de-identified after an authorized deletion request unless retention is required.
- Messages: according to the selected 12-hour, 24-hour or supported retention setting; delivery metadata may persist briefly for synchronization and abuse prevention.
- Approximate radar presence and short-lived game/session state: limited operational windows.
- Reports, blocks, appeals, fraud and legal records: only as long as reasonably needed for integrity, disputes, safety or law.
- Backups: removed through scheduled backup rotation and protected from ordinary product access.
10. Your choices and rights
Inside the app you can edit profile fields, change visibility, manage consent, block users, export data and delete your account. Depending on applicable law, you may also request access, correction, deletion, restriction, portability, withdrawal of consent or objection to certain processing. We may verify identity before acting. You may complain to your local privacy regulator, including the Office of the Privacy Commissioner of Canada, an EU/EEA supervisory authority, or Türkiye's Personal Data Protection Authority where applicable.
11. Account deletion
Deletion is available in the app and through the process on our account deletion page. It covers profile data and user-generated content associated with the account, subject only to narrow legal, fraud-prevention, safety or dispute-retention duties. Deleting N2U does not automatically cancel a subscription managed by Apple or Google.
12. Security
Controls include transport encryption, end-to-end message encryption, device-bound tokens, keychain storage, encrypted local caches, access controls, input validation, rate limits, audit logging and server-side authorization. No method of storage or transmission is guaranteed secure. Report a suspected vulnerability privately to security@n2u.app; do not access other users' data while testing.
13. Age eligibility
N2U is for people age 16 and older. Date-of-birth eligibility is independently enforced by the client and server. If we learn that a user is under 16 or otherwise ineligible to use the service where they live, we will restrict and delete the account as appropriate.
14. Changes
We will update the effective date and provide additional notice for material changes when required. Continued use after an effective change is governed by applicable consent and notice requirements.