Privacy Policy
Last Updated: July 26, 2026
1. About This Policy
This Privacy Policy describes how Hoppura ("we," "us," or "our") collects, uses, stores, and shares information when you use the Hoppura mobile application (the "App"). By using Hoppura, you agree to the practices described in this policy.
2. Information We Collect
2.1 Information You Provide Directly
- Account & Profile: Display name, avatar, cover photo, bio, pronoun, gender, birthdate — identity, profile display, social features
- Social Links: Facebook, X, TikTok, Instagram URLs (optional) — social presence linking
- Content: Post text (subject + body), file attachments (images), marketplace listings (price, currency) — content sharing, community interactions
- Comments & Replies: Comment/reply text, optional file attachments — threaded discussions
- Engagement: Likes/hearts on posts/comments/replies, follow/unfollow actions — social graph, engagement metrics
- Calendar Events: Event title, description, category, date/time, venue, metadata; RSVP status — event management
- Reports: Report reason, optional description — safety and moderation
- Country Preference: Preferred country code for event filtering — localized content display
2.2 Information Collected Automatically
- Device Identifiers: FCM push notification token — push notifications
- Authentication Data: Google Sign-In ID token (name, email) — account creation and login
- Usage Analytics: Screen views, login events, session data — analytics and improvement
- Crash Diagnostics: Crash stack traces, device model, OS version, app version — crash reporting
- Content Metadata: Post view counts, post/like counts, follower/following counts — engagement metrics
2.3 Information Stored Locally on Your Device
- Onboarding completion status
- Preferred country code
- Personal calendar events (stored in local SQLite database)
- Cached images for faster loading
3. How We Use Your Information
| Purpose | Legal Basis (GDPR) | Data Used |
|---|---|---|
| Providing the App and its features | Contract performance | Account, profile, content, social graph |
| Sending push notifications | Consent / Legitimate interest | FCM token, notification preferences |
| Analytics and app improvement | Legitimate interest | Usage data, screen views, login events |
| Crash reporting and bug fixes | Legitimate interest | Crash diagnostics, device info |
| Safety and moderation | Legitimate interest / Legal obligation | Reports, blocks, content flagged |
| Points system and avatar frame shop | Contract performance | Points balance, purchase history |
4. Third-Party Services
We use the following third-party services to operate the App. Each service receives only the data necessary for its function.
4.1 Firebase Services (Google LLC)
- Firebase Cloud Messaging (FCM): Receives your device push notification token to deliver notifications.
- Firebase Crashlytics: Receives crash stack traces, device model, OS version, and app version for crash reporting.
- Firebase Analytics: Receives screen view events, login events, and your user ID for aggregated analytics. Analytics is disabled in development builds and enabled only in staging/production.
Firebase Privacy Policy: https://firebase.google.com/support/privacy
Data Processing Terms: https://firebase.google.com/terms/data-processing-terms
4.2 Supabase
- Authentication: Receives your Google ID token for secure sign-in.
- Database & Storage: Stores all your profile data, content, social graph, engagement data, notifications, points, and uploaded files. Our Supabase project is hosted at
supabase.hoppura.com.
Supabase Privacy Policy: https://supabase.com/privacy
4.3 Google Sign-In
Receives your Google account name and email to create and authenticate your Hoppura account. We do not access your Google contacts, calendar, or other Google services.
Google Privacy Policy: https://policies.google.com/privacy
5. Data Sharing and Disclosure
We do not sell your personal data to third parties. We share data only:
- With the third-party service providers listed in Section 4, as necessary to operate the App
- When required by law or to respond to valid legal process
- To protect the rights, property, or safety of Hoppura, our users, or the public
- In connection with a merger, acquisition, or sale of assets (users will be notified)
6. Data Retention
| Data Type | Retention Period |
|---|---|
| Account and profile data | Retained while your account is active. Deleted 30 days after account deletion. |
| Posts, comments, replies | Retained while your account is active. Deleted upon account deletion or manual post deletion. |
| Reactions, follows, blocks | Deleted upon triggering action reversal (unfollow, unblock) or account deletion. |
| Reports | Retained for up to 6 months after resolution for audit purposes. |
| Notifications | Retained while your account is active. Cleared upon read or account deletion. |
| FCM push notification token | Retained while your account is active. Removed upon logout or token refresh. |
| Crash logs (Crashlytics) | Retained by Firebase for up to 90 days. |
| Points transaction history | Retained indefinitely for audit integrity while your account exists. |
| Local calendar events | Stored on your device only. Deleted when you delete the event or uninstall the App. |
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the data we hold about you.
- Rectification: Correct inaccurate or incomplete data.
- Erasure: Request deletion of your account and associated data.
- Portability: Receive your data in a structured, machine-readable format.
- Restriction: Limit how we process your data in certain circumstances.
- Objection: Object to processing based on legitimate interest.
- Withdraw Consent: Withdraw consent for push notifications at any time (via App settings or device settings).
- Complaint: Lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at the email address in Section 11. We will respond within 30 days.
You can manage your data directly in the App by:
- Editing your profile (Settings > Edit Profile)
- Deleting your posts and comments
- Unfollowing users
- Unsubscribing from push notification categories (Home > Bell icon)
- Blocking users (from their profile)
- Managing notification preferences (device system settings)
8. Data Security
We implement appropriate technical and organizational measures to protect your data:
- All data transmission uses HTTPS/TLS encryption
- Authentication uses OAuth 2.0 via Google Sign-In
- Supabase provides encryption at rest for all stored data
- Row-Level Security (RLS) policies ensure you can only access data you are authorized to see
- Database views and access controls prevent unauthorized data exposure between users
Despite these measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
9. Children's Privacy
Hoppura is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has provided us with personal data, please contact us immediately so we can delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Post the updated policy in the App
- Notify you via in-app notice or push notification
- Update the "Last Updated" date at the top of this policy
Your continued use of Hoppura after changes take effect constitutes your acceptance of the updated policy.
11. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
- Email: adminhoppura@gmail.com
- Response Time: We aim to respond within 30 days