Last updated: 21 July 2026
Niar is designed to know as little about you as possible. We ask for no name, no email and no phone number, and your exact location never leaves your device. This policy explains exactly what we process and what you can do about it.
The controller of your personal data is Fernando Zamora Díez, developer of the Niar app.
Niar divides the world into fixed hexagonal cells of roughly 0.1 km² using the H3 system.
Your device reads your position, works out locally which cell you are in
and sends only that cell's identifier: a 15-character code such as
89390cb1bffffff. Your latitude and longitude are never transmitted or stored.
The chat you see combines your cell and the six surrounding it, which amounts to a radius of about 485 metres. That cell identifier is identical for everyone inside it, so it does not single you out: it points to a neighbourhood, not an address.
What this means in practice: neither we nor anyone else can reconstruct from our data where you were with any more precision than "somewhere in this cell". And because the account is anonymous, that cell is not tied to your identity.
| Data | Purpose | Who sees it |
|---|---|---|
| Anonymous identifier A UUID generated automatically the first time you open the app. |
Keeping your session and linking your messages to one account. | Only the system. It is never shown to other users. |
| Nickname Randomly generated (for example Zorro-482). You can change it. |
Identifying you in the chat without using personal data. | Anyone in your zone. |
| Zone (H3 cell) A 15-character code. Not your exact location. |
Knowing which chat you belong to and who should receive your messages. | The system. Other users only know you are "in the zone". |
| Messages Text up to 500 characters, and the time sent. |
Providing the chat service. | They are public to anyone in the zone. |
| Zone background images The photo you choose, compressed. |
Displaying it as the chat background for that cell. | They are public. They are hosted at a URL reachable without authentication. |
| Presence Your nickname and the moment you connected. |
Showing "N people nearby" and the list for the zone. | Anyone in your zone, while you are connected. |
| Reports Who reported, who was reported, the reason and a copy of the reported content. |
Moderating the service and being able to act even if the original content is gone. | Only us. The reported person never learns who reported them. |
| In-app purchases Transaction identifier and what you bought. Only if you make a purchase. |
Validating the payment, granting what you bought and handling refunds. | Us and the payment processor. |
Some information is kept in your device's local storage and never sent to our servers: your session, whether you have seen the welcome screen, your language, your light or dark theme and, notably, your list of blocked users. Blocking is local to your device: we do not know about it and neither does the blocked person. All of it disappears if you uninstall the app or clear its data.
We process your data under Regulation (EU) 2016/679 (GDPR):
This is the most important part and the easiest to forget: your messages and any background images you upload are public to anyone in that zone, and the images are hosted at a web address reachable without authentication. Do not post anything you would not want a stranger to see. Do not share personal data about yourself or others in the chat.
| Provider | Purpose | Where |
|---|---|---|
| Supabase | Database, anonymous authentication, realtime messaging and storage of background images. Acts as a data processor. | European Union — Ireland (EU West) |
| RevenueCat | Validating in-app purchases. Only involved if you make a purchase. | United States |
| Apple and Google | App distribution and payment processing. They handle the charge: we never see your banking details. | Per their own policies |
Where a provider processes data outside the European Economic Area, the transfer relies on the Standard Contractual Clauses approved by the European Commission.
We may also disclose data to competent authorities where there is a legal obligation or a valid judicial request.
| Data | Retention |
|---|---|
| Messages | A daily automated process keeps only the 50 most recent messages in each cell and deletes the rest. In a busy zone that is hours; in a quiet one it can be weeks. |
| Background images | Until someone uploads another one in its place or its author removes it. |
| Account, nickname and presence | For as long as you use the app. They disappear as soon as you delete your account. |
| Reports | Kept for as long as they are needed for moderation. If the account of the author or of the reporter is deleted, the report is anonymised but not erased: otherwise deleting an account would be enough to wipe a history of violations. |
| Purchases | For the periods required by tax and consumer law. |
You have the right to access your data, rectify it, erase it, restrict or object to its processing, and to data portability. In Niar you exercise most of them yourself, without asking us or waiting:
For any other right, or if you want a copy of your data, write to niar.support@gmail.com. Note that because the account is anonymous we may need you to provide your user identifier from within the app so we can locate your data: without it we cannot tell which data is yours.
If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es) or with the supervisory authority in your country.
Niar is an open chat with strangers and with user-generated content. It is not directed at minors and its store rating reflects that. We do not allow use by anyone under 14. If we identify an account belonging to someone under that age, we will delete it. If you are a parent or guardian and believe a minor in your care is using the app, write to us and we will remove the account.
All communication between the app and our servers is encrypted with TLS. Database access is restricted row by row: no user can read another user's profile, alter someone else's messages, or see anyone else's reports.
You should know that background images are held in public storage: anyone who knows or guesses the address can view them without being in the zone or having an account. That is a consequence of the design, not a flaw, which is why we state it here. Do not upload images containing sensitive information or that could identify you.
No system is infallible. If we detect a security breach affecting your data, we will notify it as required by the GDPR.
If we change this policy we will update the date at the top. Where the change is substantial we will also announce it inside the app before it takes effect.
We handle content reports in under 24 hours and all other enquiries within a maximum of 30 days, as required by the GDPR.