feelya

App privacy policy

This is an English translation of the Italian original. If the two differ, the Italian version prevails.

Version 1 · 4 October 2026

This policy covers the feelya app. For the waiting list on the website, the website privacy policy applies.

In short

feelya. is for a closed group of friends to think together about a question. To do this, we process your email address, the name and photo you choose, what you write and the positions you take on topics.

Positions on topics may reveal political opinions or religious or philosophical beliefs: under the law, these are special categories of personal data (Art. 9 GDPR). We process them only with your explicit consent, which you give the first time you sign in.

We do not sell your data, we do not show advertising, we do not profile you and we do not use what you write to train artificial intelligence.

1. Who the data controller is

The data controller is the feelya team.

For any question about your data, and to exercise your rights, write to hello@feelya.it. We have assessed whether Art. 37 GDPR requires us to appoint a data protection officer (DPO): at present we believe it does not, and we will repeat the assessment if the service grows. The contact point for data protection is hello@feelya.it.

2. What data we process

What is required and what is not. Email, name and consent to the processing of your positions are required: without them, you cannot create an account or use the app. Content and positions are provided by you when you take part in a session. Profile photo, notifications and usage statistics are optional: if you do not provide them, the app works the same way (without notifications, we do not alert you when a session opens). Technical data and logs are generated by the use of the app and the server itself.

We do not collect your geographic location, your contacts, the microphone, advertising identifiers or browsing data outside the app.

3. Who sees what, inside the app

The pseudonym protects you from other people, not from us: on the server there is a table that links your pseudonym to you. It is needed for the reveal to work and for any legal obligations, and it is not consulted for anything else.

People who know you may recognise you from the way you write, even under a pseudonym. Keep this in mind when you write.

4. Why we process it and on what legal basis

We do not make decisions based solely on automated processing that produce legal effects concerning you (Art. 22 GDPR). The only automated mechanism is the filter that stops a message containing hate words before it is sent: you can rewrite it, and if you think the filter got it wrong you can write to us.

5. Who receives the data

We use certain providers that process data on our behalf, as data processors (Art. 28 GDPR), under a contract that requires them to use it only for the service they provide to us. The table shows, for each one, what it receives, where the data are stored and, if they leave the European Union, under which safeguard. For emails we use three providers in sequence: if the first has reached its sending limit or does not respond, the email is sent through the next one. Each email goes through only one of them.

ProviderWhat it does and what it receivesWhereSafeguard outside the EU
Amazon Web Services EMEA SARL, Luxembourg (Amazon group). Processor. Servers, database and job queues: all the app’s data. European Union, Stockholm (Sweden). The data stay in the EU. For any access from the United States by the Amazon group: Data Privacy Framework, and the standard contractual clauses in the AWS contract.
Register.it S.p.A., Italy. Processor. Sending emails: the access code, report confirmations and your data when you request them. It receives your address and the text of the email. European Union. No transfer.
Sendinblue SAS, “Brevo”, France. Processor. Sending emails, like Register.it: the same emails and the same data. European Union. No transfer.
Resend Inc., United States. Processor. Sending emails, like Register.it: the same emails and the same data. United States. Data Privacy Framework (Resend participates), and the standard contractual clauses in its contract.
Functional Software Inc., “Sentry”, United States. Processor. Error reports from the app and the server: device, system, app version, point in the code. Neither messages nor emails. United States. Data Privacy Framework (Sentry participates).
650 Industries Inc., “Expo”, United States. Processor. Delivery of notifications (device token, circle name, topic title) and distribution of app updates. United States. Data Privacy Framework (Expo participates), and the standard contractual clauses in its contract.
PostHog Inc., United States. Processor. Usage statistics, only if you accept them, tied to a random code on your phone. European Union (Germany). The data stay in the EU. For any access from the United States: Data Privacy Framework (PostHog participates).
Google LLC, United States. Processor for notifications, independent controller for sign-in. Delivery of notifications to Android phones (Firebase Cloud Messaging). If you sign in with Google, it knows you used it to sign in to feelya. United States. Data Privacy Framework (Google participates).
Apple Inc., United States. Independent controller. Delivery of notifications to iPhones (Apple Push Notification service). If you sign in with Apple, it knows you used it to sign in to feelya. United States. Data Privacy Framework (Apple participates).

Google and Apple have two different roles. For notifications, Google delivers the messages on our behalf, under the Firebase data processing terms: it is our processor. Apple, on the other hand, delivers them with the service built into the iPhone’s system, on its own terms: there it is an independent controller. For sign-in with Google or with Apple, both are independent controllers, with their own privacy policies.

We may disclose data to authorities when required by law (for example, by order of a court). We do not disclose data to anyone else.

6. Transfers outside the European Union

When a provider receives data in the United States, the transfer is based on the European Commission’s adequacy decision of 10 July 2023 on the EU-U.S. Data Privacy Framework (Art. 45 GDPR), in which all the providers in the table based in the United States participate. Where the provider’s contract provides for them, the standard contractual clauses approved by the Commission in 2021 (Art. 46 GDPR) also apply, and they remain valid even if participation in the Data Privacy Framework were to lapse.

You can request a copy of the safeguards applied by writing to hello@feelya.it.

7. How long we keep it

feelya. is in beta. If the beta closes without a follow-up, we will tell you at least 30 days in advance and erase all data within 90 days of closure.

8. Your rights

At any time you can:

For everything else, write to hello@feelya.it. We reply within one month, free of charge. We may ask you to write to us from the account’s address, to make sure it is you.

If you believe we are processing your data in a way that does not comply with the law, you can lodge a complaint with the Garante per la protezione dei dati personali (Italian Data Protection Authority) (garanteprivacy.it) or with the authority of the EU country where you live or work.

9. Minimum age

feelya. is for people aged at least 16: when you sign up, we ask you to declare this. In Italy the law allows you to give consent on your own from the age of 14 (Art. 2-quinquies of the Italian Privacy Code). We have chosen a higher limit, because the app involves discussing topics that may touch on political and religious opinions. If we find out that an account belongs to a younger person, we delete it.

10. Security

Communications between the app and the server are encrypted. Sign-in uses a one-time code, with no password to steal. The link between pseudonyms and people is kept in a single table, which the app’s code can read from only one place, and every time a pseudonym is linked back to a name a trace remains. Photos are re-encoded on the server and stripped of location data.

If a data breach occurs that puts your rights at risk, we notify the Garante within 72 hours and, if the risk is high, you as well.

11. On your phone

The app stores on your phone only what it needs to work: the access key (in the system’s protected keychain, if you choose «resta connesso» (stay signed in)), a copy of the last screens you viewed so it can be used without a network connection, and drafts of what you are writing. We do not use cookies or tracking tools. When you sign out of your account, the key and the copies are erased.

12. Changes

If we change this policy substantially, we will ask you again in the app before the changes apply to you. Last updated: 4 October 2026.