Request deletion of your data — Hazely

Effective 14 August 2026 | Version 1.1

This page explains how to ask us to delete data relating to your use of Hazely: Find Coffeeshops (nl.hazely.app), and what is deleted, kept, or already removed automatically.

Language. This page is published in English only. No other language version of it exists, so none can prevail over this one. The only Hazely document currently published in Dutch is the Privacy Policy, at hazely.nl/privacybeleid. You are welcome to write your request in Dutch and we will answer in Dutch.

How to request deletion

Hazely has no user accounts. There is no profile to close and no login, so there is nothing for us to look up by name or email address.

1. Delete everything stored on your device — you can do this yourself, immediately. Open Hazely → Settings → Reset all my privacy choices. This clears your consent choices, your saved favourites, and every other setting Hazely has stored locally. Uninstalling the app removes the same data.

2. Ask us to delete data held by our processors. Email privacy@hazely.nl with the subject "Data deletion request".

Because we cannot identify you from the data we hold, please include whatever you can:

The app instance ID is the only identifier that links analytics records together, and we hold nothing that connects it to a person. Without it we genuinely cannot find "your" analytics data among everyone else's — Article 11(2) GDPR covers exactly this situation. We will not use that as a way to refuse you: we honour whatever is technically possible, and we will tell you plainly what was possible and what was not, and why.

We answer within one month, as required by Article 12(3) GDPR.

What gets deleted

DataWhere it livesOn request
Analytics events (screen views, feature use)Google Analytics for FirebaseDeleted — finding them requires the app instance ID described above
Crash reports and performance tracesFirebase Crashlytics / PerformanceDeleted
Firebase installation identifierGoogleDeleted (Google removes within 180 days)
Menu scan resultsFirestoreDeleted
Consent choices, favourites, settingsYour device onlyYou delete these yourself, in Settings

What is already deleted automatically — you do not need to ask

DataRetention
Menu photographsNot retained after text extraction
Menu scan results30 minutes
Map search textNever transmitted. What you type into the map search bar stays on your device; if Analytics is on, only the number of characters typed and the number of results are recorded — never the text
Strain-catalogue search textThis one is transmitted. A lookup for a strain we do not already have goes to our server and on to Google's Gemini API, and the text appears in our server request logs, which are kept for 30 days and then deleted. The Privacy Policy §3.1 describes the two searches side by side
Precise locationHeld in memory while the App is open; never sent to our servers

What we keep, and why

Strain reference entries. When a menu scan finds a strain name that is not yet in our catalogue, we add a description of that strain to our public reference catalogue. These entries contain only the strain name and its description — no identifier, no location, no link to you or your device. They are ordinary catalogue content, not personal data, and are kept indefinitely.

Aggregate figures. Counts and statistics that cannot be traced back to any individual are kept.

Records we are legally required to retain. Where the law requires us to keep something (for example, a record of a rights request and how we handled it), we keep it for as long as the law requires and no longer.

Your other rights

Deletion is one of several rights you have. You can also request access, correction, restriction, portability, or object to processing. See the Privacy Policy for the full list and how to exercise them.

If you are not satisfied with our response, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens (<https://autoriteitpersoonsgegevens.nl>).

Contact

Changelog

Version 1.1 — 14 August 2026 (replaces version 1.0 of 3 August 2026)

1. The app-instance-ID instructions were wrong and are corrected. Version 1.0 directed you to a Settings screen to read the ID; no current version of the App can display it. This version says so, and names the releases — Android 1.0.7 and the next iOS build — that add an "App instance ID" entry with a copy button to Settings. The underlying limitation was and remains true: without that ID, analytics records cannot be linked to you (Art. 11(2) GDPR). But directions to a screen that did not exist made that limitation look engineered, and they are gone. 2. "Search terms — never transmitted" was half wrong and is now split in two. It is true for the map search bar, whose text never leaves your device. It is not true for strain-catalogue lookups, which are sent to our server and on to Google's Gemini API and appear in server request logs for 30 days. The split now mirrors the Privacy Policy §3.1 exactly. 3. A language note was added, and this changelog begins with this version.