Legal

Privacy Policy

Last updated: 1 October 2026

This policy explains what data Quino uses, why, how long we keep it, who we share it with and what your rights are. It covers the Quino app and the website joinquino.com.

In short

  • Quino is free. We show no ads and we do not sell your data.
  • We only use what is needed to choose a time and a place together.
  • We do not use your location, your contacts or your camera.
  • We do not use advertising or analytics trackers. The website sets no cookies.
  • Our database is in the European Union (Frankfurt, Germany).
  • Dietary choices (halal, vegetarian, vegan) are optional and used only to pick a suitable place.
  • You can delete your account yourself in the app at any time.
  • Quino is for people aged 16 and over.

1. Who is responsible?

Quino is a private project based in the Netherlands. The "controller", the person who decides why and how your data is used, is named in section 15. In this text "we" or "Quino" means that person.

Questions about your data: hello@joinquino.com.

2. What data we use, why, on what legal ground and for how long

"Contract" means we need the data to make Quino work the way you use it. "Legitimate interest" means we have a good reason that does not override your interests (we have weighed this).

Your account

  • What: email address and password (stored encrypted; we cannot read it). If you sign in with Apple or Google: an account ID, your email (with Apple this can be an anonymous relay address) and sometimes your name. To keep you signed in we store a session with the IP address and device type of that moment. We also store the date and time at which you confirmed you are 16 or older and accept the terms and this policy.
  • Why: signing in, securing your account, being able to show that you agreed and are old enough.
  • Legal ground: contract. Recording your confirmation: legitimate interest.
  • How long: until you delete your account. A session ends when you sign out.

Your profile

  • What: your name, your friend code, a profile photo if you choose one, an avatar colour and your settings (notifications, light/dark, usual visit length). The app reads only the photo you pick, nothing else in your photo library.
  • Why: so friends and people in your plans know who you are.
  • Legal ground: contract.
  • How long: until you delete your account. An old photo is deleted when you pick a new one.

Friends, requests and blocks

  • What: who your friends are, friend requests you send and receive (including declined ones, so nobody keeps pestering you), and who you blocked.
  • Why: adding and inviting friends, and protecting you.
  • Legal ground: contract; for blocks also legitimate interest (a safe app).
  • How long: until you or the other person deletes their account. Blocking removes the friendship and open requests at once.
  • People can find you only by your friend code, not by name or email.

Plans and matches

  • What: what you choose when planning (city, food or drinks, budget, optional dietary choice, date and time or the days and times you are free, an optional title), who takes part and who has answered, the place picked, whether you booked, places already shown, optional feedback ("did you go?"), and how many plans you start per day (daily limit).
  • Why: pick a place that fits and is open, find a time that works, show your plans.
  • Legal ground: contract. Dietary choices: see section 3.
  • How long: a match you made only for yourself and did not mark as booked is deleted automatically 30 days after its date. Other plans stay until the organiser deletes or cancels them or the organiser's account is deleted. Times, chosen places and feedback belong to the plan and go with it. The daily counter stays until you delete your account.

Invitations and guests

  • What: each plan has an invitation link. Whoever opens it sees the organiser's first name, the first names of those who answered and the plan details (city, kind of place, date and time, the chosen place). If you answer as a guest without an account we store the name you enter and your answer or availability. Your browser keeps a key for that one invitation so you can edit your answer later.
  • Why: inviting people who do not have Quino yet.
  • Legal ground: contract; legitimate interest.
  • How long: guest names and answers are deleted automatically 30 days after the day of the plan. The key in your browser stays until you clear your browser data.

Notifications and push messages

  • What: in-app notifications (for example an invitation, a reply or a reminder). If you allow push messages on your iPhone we store a push token, a code that lets us send a message to your phone. A push message can contain a friend's name and a plan title.
  • Why: telling you what happens in your plans.
  • Legal ground: contract. You only get push messages if you allow them in iOS; you can switch them off any time.
  • How long: in-app notifications are deleted after 90 days. The push token is deleted when you sign out or delete your account.

Email

  • What: we send email from noreply@joinquino.com: sign-in codes, confirmations (for example when you change your email address) and confirmations of website forms. If you write to hello@joinquino.com your message arrives in our mailbox.
  • Why: signing in, security, answering your questions.
  • Legal ground: contract; for questions legitimate interest (helping you).
  • How long: we delete support email 12 months after the last contact.

Reporting and safety

  • What: if you report a person we store the reason, the text you write, who you report and the name that person had at that time, the plan if the report is about a plan, and who made the report. If you report a place we store the place, the reason and your text. Every report sends us an email so we can look within 24 hours. The person you report is not told that you reported them.
  • Why: keeping Quino safe, tackling abuse, fixing wrong place data.
  • Legal ground: legitimate interest (a safe app with correct information); a legal obligation where content is illegal.
  • How long: 12 months after we have handled the report. When an account is deleted, the link with that account is removed; a report about a person keeps the name they had, for those 12 months, so we can keep dealing with abuse.

Website forms

  • Waitlist: email address, city and your consent. We first email you a link to confirm. Ground: consent (withdraw any time by emailing us). If you do not confirm we delete your address after 7 days; if you confirm we keep it until we have emailed you that Quino is live, then delete it.
  • Suggest a place: the place you suggest (name, city, location, kind, dietary labels, budget, why) and, if you want, your name. Your email only if you tick that we may tell you what we did. Ground: legitimate interest (improving Quino); consent for the email. We keep it until we have reviewed it and, if you asked, replied.
  • Delete account: the email address you enter. We email you first to check the request is yours. Ground: legal obligation (carry out your request and show that we did). We keep the record for 12 months.
  • Each form uses Cloudflare Turnstile to check you are not a robot. Cloudflare uses technical data from your browser and your IP address for that.

Technology and security

  • What: to limit abuse (for example very many requests in a row) we count how often an account or IP address does something. Our hosting providers Supabase and Cloudflare keep short technical logs with your IP address, the time, the page requested and errors. Cloudflare also gives us aggregate traffic statistics from its servers (no script on your device, no cookies). An automatic check tests that the website and forms work; it uses no data about you.
  • Why: protecting Quino against abuse, finding and fixing outages.
  • Legal ground: legitimate interest (a secure and working service).
  • How long: most counters are deleted after one day. The weekly limit for form abuse stores only a scrambled version (hash) of an IP address or email, deleted after eight days. Technical logs are deleted automatically: after 1 day at Supabase and after 7 days at Cloudflare. Resend keeps email delivery logs for 30 days.

Error reports

  • What: if the app crashes or hits an error, it sends a report to Sentry: app version, phone model, iOS version, how long things took and what happened just before. Before sending, we strip email addresses, invitation links, friend codes and push tokens. We do not send your name or your IP address.
  • Why: finding and fixing errors.
  • Legal ground: legitimate interest (an app that works).
  • How long: at most 90 days.

Sharing a place

  • What: on the match screen you can share a place, for example via WhatsApp. The message contains the place's name and address and a link to joinquino.com/p/…. That page shows the place and sends you on to Google Maps. The link contains nothing about you, your plan or who you go with. We do not see who you share with.
  • Legal ground: contract. How long: the link points only to the place.

Booking, directions and calling

If you book, ask for directions or call a place, Quino sends you to the restaurant's website or booking partner, to Apple Maps or Google Maps, or to your phone. We pass nothing about you. What you enter there falls under that party's privacy policy.

Backups

We make a copy of the database every week and keep it encrypted for at most 4 weeks. When you delete your account, your data disappears from backups within 4 weeks. Legitimate interest (recovering from errors).

3. Dietary choices (halal, vegetarian, vegan)

A plan can require a place to be halal, vegetarian or vegan. Such a choice can say something about your faith or health. That is extra sensitive data (article 9 GDPR). This is how we handle it:

  • It is optional. Quino works without it.
  • A dietary choice belongs to the plan, not to you as a person. Often the organiser chooses it for the whole group.
  • We do not look at dietary choices per person, build no profile and never use them for statistics, advertising or error reports.
  • People in the same plan see which dietary choice belongs to the plan.
  • Dietary choices are deleted with the plan (see section 2).
  • You can remove a dietary choice at any time by changing or deleting the plan.

4. Who can see what?

  • Your friends see your name, profile photo and friend code.
  • People in the same plan see your name and photo, whether you come, the chosen place and the plan details. Only the organiser sees the times you enter. Everyone invited sees the organiser's times.
  • Anyone with an invitation link sees what is described under "Invitations and guests". Share a link only with people you want to invite.
  • Anyone who opens your friend link (joinquino.com/u/…) sees your name and profile photo.
  • Someone you blocked can no longer see your profile, except in a plan you already share.

5. Who we share data with

We do not sell your data and do not share it for advertising. A few companies provide services to us and may use your data only for Quino:

  • Supabase: database, sign-in and photo storage. Servers in Frankfurt (Germany).
  • Cloudflare: the website (hosting and technical logs), the Turnstile robot check, forwarding of email sent to hello@joinquino.com, and aggregate traffic statistics.
  • Resend: sending email.
  • Expo: passing push messages on to Apple.
  • Apple: Sign in with Apple, delivering push messages, the App Store.
  • Google: Sign in with Google, and the mailbox where email to hello@joinquino.com and report alerts arrive, and storage of our encrypted backups. We get place information (address, opening hours, photos) from Google Places; we send nothing about you.
  • Sentry: error reports from the app.

If you sign in with Apple or Google, their own privacy policy also applies to what they process. We only give data to others, such as the police, if the law requires us to.

6. Data outside the European Union

Our database is in the EU. Some companies above are based in the United States (Cloudflare, Expo, Apple, Google, Sentry, and the parent companies of Supabase and Resend) or may process data on servers outside the EU. Data goes to a country outside the EU only with the protection the GDPR requires: the company is covered by the EU-US Data Privacy Framework or we use the European Commission's standard contractual clauses. Want to know which protection applies to which company? Email hello@joinquino.com.

7. Delete your account

Delete your account yourself in the app: Settings → Delete account. Without the app, use the form at joinquino.com/delete-account. We email you first to check the request is yours and delete your account within 30 days.

When your account is deleted:

  • your profile, photo, friends, requests, blocks, notifications and push token disappear;
  • plans you organise are deleted for everyone; for plans still to come, the others get the same message as for a cancellation;
  • in other people's plans you stay as "Deleted user", without name and without the times you entered;
  • reports you made or that were about you remain, without the link to your account, for the retention period in section 2. A report about you keeps the name you had.
  • Backups: see section 2.

8. Age

Quino is for people aged 16 and over. When you create an account you confirm with one tick: "I am 16 or older and agree to the terms and the privacy policy." We keep the date and time of that confirmation. If we find an account of someone under 16 we delete it.

9. Security

We protect your data as well as we can. All connections are encrypted (https). Strict rules in the database mean you only see what belongs to you and your plans. Your sign-in details are kept in the secure iOS Keychain on your iPhone. Limits make abuse harder. Only the owner has administrator access.

10. Storage on your device and cookies

The app keeps your session in the iOS Keychain and a few settings on your phone. If you reinstall the app, an old session is cleared on first launch. The website sets no cookies for statistics or advertising. If you answer an invitation as a guest, your browser stores only the key for that invitation (strictly necessary for the function you asked for, so no consent banner is needed).

11. Automated choices

Quino picks a place by chance within the filters you or the organiser choose. We build no profile of you and take no automated decisions that significantly affect you.

12. Your rights

  • Access: ask which data we hold and get a copy.
  • Correction: change your name, photo, email and settings in the app. If anything else is wrong, tell us.
  • Deletion: delete your account in the app or via the website form (section 7).
  • Objection: to use of your data based on our legitimate interest.
  • Restriction: ask us to stop using your data for a while, for example while we look into a question.
  • Portability: get your data in a common file format.
  • Withdraw consent: for example for the waitlist or a dietary choice. What we did before remains valid.

Email your request to hello@joinquino.com. We answer within one month. We may first ask you to confirm the request comes from you (for example by writing from the email address of your account), so nobody else can ask for your data.

13. Complaints

Not happy with how we handle your data? Tell us first at hello@joinquino.com. You can always lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.

14. Changes

If Quino changes, we change this policy. The date at the top shows the last change. We tell you about important changes in the app.

15. Controller and contact

The controller is Nasr El Karkouri, a private person based in the Netherlands. Email: hello@joinquino.com.