🛡️ Privacy Policy — Medueti

Last updated: November 25, 2025


Table of Contents

  1. Introduction
  2. Data Controller Identity
  3. Data We Collect
  4. How We Use Your Data
  5. Legal Basis for Processing (GDPR)
  6. Data Sharing and Third-Party Services
  7. Advertising and Personalization
  8. Device Permissions
  9. Cookies and Tracking Technologies
  10. Data Security
  11. Data Retention
  12. Your Rights
  13. International Data Transfers
  14. Children's Privacy
  15. User-Generated Content
  16. Account Verification
  17. Payment Processing
  18. California Privacy Rights (CCPA)
  19. Changes to This Policy
  20. Contact Us

1. Introduction

Welcome to Medueti, the super-app connecting the African diaspora worldwide through a rich social network featuring communities, marketplace (Afroshop), money transfers, events, local services, shipping logistics, and more.

The protection of your personal data is our priority. This Privacy Policy explains how we collect, use, store, share, and protect your information when you use the Medueti application ("the App") on mobile devices or web platforms.

By downloading, installing, or using Medueti, you acknowledge that you have read and understood this Privacy Policy and agree to the practices described herein.

If you do not agree with this policy, please do not use our services.


2. Data Controller Identity

Company NameMedueti
Contact Emailsupport@medueti.com
Privacy Contactprivacy@medueti.com
Administrative HeadquartersHamburg, Germany
Data ControllerMedueti Team
Websitehttps://medueti.com

For any privacy-related inquiries, including exercising your data protection rights, please contact us at privacy@medueti.com.


3. Data We Collect

Medueti collects data necessary to provide and improve our services. We collect information in the following categories:

3.1 Account Registration Data

When you create an account, we collect:

Data TypeRequiredPurpose
Email addressYesAccount identification, communications
Phone numberOptionalAccount verification, 2FA
Full nameYesProfile display, community features
PasswordYesAccount security (stored hashed)
Date of birthOptionalAge verification
GenderOptionalProfile personalization
ProfessionOptionalCommunity matching
Languages spokenOptionalContent localization

3.2 Profile Information

Data TypePurpose
Profile photoVisual identification
Username/handleUnique identifier
Bio/descriptionSelf-expression
Country of residenceLocalized content
City/townNearby services & events
AddressService delivery, shipping

3.3 User-Generated Content

Content TypeDescription
Social postsText, images, videos, location tags
MessagesText, images, videos, audio, files (end-to-end encrypted)
Comments & reviewsText, ratings
EventsTitle, description, venue, dates, images, tickets
Service listingsService descriptions, pricing, availability
Product listingsProduct descriptions, images, pricing
Shipping requestsOrigin/destination, package details, photos
Portfolio itemsArtwork, images, categories

3.4 Transaction & Financial Data

Data TypePurpose
Purchase historyOrder management
Booking historyService reservations
Subscription statusFeature access
Event credits balanceVirtual currency
Transaction metadataAmount, date, type

⚠️ Important: We do not store credit/debit card numbers. All payment card data is processed securely by our payment provider, Stripe.

3.5 Device & Technical Data

Data TypePurpose
Device model & OS versionApp optimization
App versionCompatibility, updates
Push notification tokens (FCM)Delivering notifications
Device advertising IDAd personalization (with consent)
IP addressSecurity, approximate location
Crash logs & error reportsApp stability
Biometric capabilityAuthentication options

3.6 Location Data

TypeCollection MethodPurpose
CountryUser-providedLocalized content
City/townUser-provided or GPSNearby services & events
Precise GPS coordinatesDevice sensors (with permission)Nearby discovery, event check-in

📍 Location data is collected only when you grant permission and can be disabled at any time in your device settings.

3.7 Usage & Analytics Data

Data TypePurpose
Screen viewsUnderstand feature usage
Button interactionsUX improvement
Search queriesSearch optimization
Content engagement (likes, shares)Content recommendations
Session durationPerformance metrics
Feature usage patternsProduct development

3.8 Communication Data

Data TypePurpose
Support ticketsCustomer service
In-app communicationsNotifications, updates
Email preferencesMarketing communications

4. How We Use Your Data

We use collected data for the following purposes:

4.1 Service Provision

4.2 Personalization

4.3 Transactions & Payments

4.4 Communications

4.5 Safety & Security

4.6 Analytics & Improvement

4.7 Advertising

4.8 Legal Compliance


For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we process personal data under the following legal bases:

Legal BasisExamples
Contract PerformanceAccount creation, service delivery, payments, messaging
Legitimate InterestsSecurity, fraud prevention, analytics, app improvement
ConsentMarketing communications, personalized advertising, location access
Legal ObligationTax records, responding to legal requests

You may withdraw consent at any time by adjusting your settings or contacting us.


6. Data Sharing and Third-Party Services

We do not sell your personal data. We share information only in the following circumstances:

6.1 Service Infrastructure Providers

ProviderServiceData SharedPrivacy Policy
Google FirebaseBackend infrastructure, database, file storage, authenticationAll app dataGoogle Privacy Policy
Google Cloud PlatformCloud functions, hostingProcessed dataGoogle Cloud Privacy

6.2 Analytics Providers

ProviderServiceData SharedPrivacy Policy
Firebase AnalyticsUsage analyticsAnonymized usage data, device infoFirebase Privacy
Firebase PerformancePerformance monitoringApp traces, network metricsFirebase Privacy
Firebase CrashlyticsCrash reportingCrash logs, device infoFirebase Privacy

6.3 Payment Processors

ProviderServiceData SharedPrivacy Policy
StripeCredit/debit card payments, subscriptionsBilling info, transaction dataStripe Privacy Policy
Google Play BillingAndroid in-app purchasesPurchase dataGoogle Privacy Policy
Apple App StoreiOS in-app purchasesPurchase dataApple Privacy Policy

6.4 Authentication Providers

ProviderServiceData ReceivedPrivacy Policy
Google Sign-InSocial loginEmail, name, profile photoGoogle Privacy Policy
Sign in with AppleSocial loginEmail (may be hidden), nameApple Privacy Policy

6.5 Advertising Partners

ProviderServiceData SharedPrivacy Policy
Google AdMobMobile advertisingDevice advertising ID, ad interactionsGoogle Ads Privacy
SKAdNetwork Partners (iOS)Ad attributionAttribution dataVarious (see Section 7)

6.6 Location Services

ProviderServiceData SharedPrivacy Policy
Nominatim (OpenStreetMap)Address autocompleteSearch queriesOSM Privacy
Photon (Komoot)City searchLocation queriesKomoot Privacy

6.7 Machine Learning Services

ProviderServiceData ProcessedPrivacy Policy
Google ML KitImage labeling for visual searchImages (processed on-device)Google ML Kit Privacy

⚠️ Note: ML Kit image processing occurs on-device and images are not sent to Google servers.

6.8 Other Sharing Circumstances


7. Advertising and Personalization

7.1 Google AdMob

Medueti displays advertisements through Google AdMob. AdMob may collect and use:

7.2 Ad Personalization

By default, you may see personalized ads based on your interests and activity. You can choose to receive non-personalized ads by:

  1. Adjusting your device advertising settings
  2. iOS: Settings → Privacy → Tracking → Disable "Allow Apps to Request to Track"
  3. Android: Settings → Google → Ads → Opt out of Ads Personalization

7.3 iOS App Tracking Transparency (ATT)

On iOS 14.5+, we will request your permission before tracking your activity across other apps and websites for advertising purposes. You can change this setting at any time in your device settings.

7.4 SKAdNetwork (iOS)

For iOS, we work with the following SKAdNetwork partners for ad attribution:

Click to see SKAdNetwork Partner List

These networks receive limited attribution data to measure ad campaign effectiveness.

7.5 Premium Users

Users with Premium, Pro, or Business subscriptions may enjoy an ad-free experience based on their subscription tier and our current policies.


8. Device Permissions

Medueti requests the following device permissions to enable specific features:

8.1 Android Permissions

PermissionPurposeRequired
INTERNETConnect to Medueti serversYes
ACCESS_NETWORK_STATECheck connectivity statusYes
CAMERATake photos/videos for posts and profileNo
READ_MEDIA_IMAGES (Android 13+)Select photos from galleryNo
READ_MEDIA_VIDEO (Android 13+)Select videos from galleryNo
READ_MEDIA_AUDIO (Android 13+)Select audio files for chatNo
READ_EXTERNAL_STORAGE (Android ≤12)Access media filesNo
WRITE_EXTERNAL_STORAGE (Android ≤12)Save downloaded filesNo
ACCESS_FINE_LOCATIONFind nearby services/eventsNo
ACCESS_COARSE_LOCATIONApproximate location for servicesNo
POST_NOTIFICATIONS (Android 13+)Display push notificationsNo
READ_CONTACTSFind friends from contactsNo
VIBRATENotification vibrationsNo
USE_BIOMETRICFingerprint/face authenticationNo
USE_FINGERPRINTFingerprint authentication (legacy)No
FOREGROUND_SERVICEBackground messaging/uploadsYes
com.android.vending.BILLINGIn-app purchasesYes

8.2 iOS Permissions

Permission KeyPurposeRequired
NSCameraUsageDescriptionTake photos for posts and profileNo
NSPhotoLibraryUsageDescriptionAccess photo libraryNo
NSPhotoLibraryAddUsageDescriptionSave images to libraryNo
NSLocationWhenInUseUsageDescriptionFind nearby servicesNo
NSContactsUsageDescriptionFind friends from contactsNo
NSFaceIDUsageDescriptionFace ID authenticationNo
NSUserTrackingUsageDescriptionAd tracking (ATT prompt)No

📱 All optional permissions can be denied without blocking basic access to the app. You can modify permissions at any time in your device settings.


9. Cookies and Tracking Technologies

9.1 Mobile App

The Medueti mobile app uses:

9.2 Web Platform

Our website may use:

9.3 Managing Cookies


10. Data Security

We implement comprehensive security measures to protect your data:

10.1 Technical Measures

MeasureDescription
Encryption in TransitAll data transmitted using HTTPS/TLS encryption
Encryption at RestData stored encrypted on Google Cloud servers
End-to-End EncryptionPrivate messages encrypted with AES-256
Password HashingPasswords stored using secure one-way hashing
Firebase App CheckDevice attestation to prevent unauthorized API access
Rate LimitingProtection against brute-force attacks

10.2 Access Controls

10.3 Biometric Authentication

Medueti supports biometric authentication (Face ID, Touch ID, fingerprint) as an optional security feature. Biometric data is:

10.4 Data Breach Response

In the event of a data breach affecting your personal data, we will:


11. Data Retention

We retain personal data only as long as necessary for the purposes described:

Data CategoryRetention Period
Account dataUntil account deletion + 30 days grace period
User contentUntil deleted by user or account deletion
Chat messagesUntil deleted by user or account deletion
Transaction records7 years (legal/tax requirements)
Analytics data26 months (anonymized)
Security logs12 months
Push notification tokensAutomatically cleaned when invalid
Support tickets3 years after resolution

11.1 Automatic Data Cleanup


12. Your Rights

12.1 Rights Under GDPR (EEA/UK/Switzerland)

RightDescription
Right of AccessRequest a copy of your personal data
Right to RectificationCorrect inaccurate or incomplete data
Right to ErasureRequest deletion of your data ("right to be forgotten")
Right to Restrict ProcessingLimit how we use your data
Right to Data PortabilityReceive your data in a machine-readable format
Right to ObjectObject to processing based on legitimate interests
Right to Withdraw ConsentWithdraw previously given consent
Right to Lodge a ComplaintFile a complaint with a supervisory authority

12.2 How to Exercise Your Rights

In-App Options:

  1. Data Export: Settings → Privacy → Export My Data
  2. Account Deletion: Settings → Account → Delete Account
  3. Notification Preferences: Settings → Notifications
  4. Ad Personalization: Settings → Privacy → Ad Settings

Contact Us:

12.3 Account Deletion

When you delete your account:

  1. Your data enters a 30-day grace period (account recovery possible)
  2. After 30 days, all personal data is permanently deleted or anonymized
  3. Certain data may be retained for legal compliance (e.g., transaction records)

13. International Data Transfers

Your data may be processed in countries outside your residence:

ProviderLocationSafeguards
Google Cloud/FirebaseUSA, EUStandard Contractual Clauses (SCCs)
StripeUSAStandard Contractual Clauses, Privacy Shield (legacy)

We ensure all international transfers comply with GDPR through:


14. Children's Privacy

Medueti is intended for users aged 18 and over.


15. User-Generated Content

15.1 Content Moderation

Users may publish text, photos, videos, comments, and listings. Medueti reserves the right to remove content that is:

15.2 Reporting System

15.3 Public vs. Private Content


16. Account Verification

16.1 Business Verification

Business accounts may submit verification documents:

Document TypePurpose
Government IDIdentity verification
Proof of addressLocation verification
Business registrationBusiness legitimacy
Professional certificationsService provider verification

16.2 Document Handling


17. Payment Processing

17.1 Stripe Payments

Credit/debit card payments are processed by Stripe:

17.2 In-App Purchases

PlatformPurchasesBilling
Google PlaySubscriptions, creditsGoogle Play Billing
Apple App StoreSubscriptions, creditsApple In-App Purchase

17.3 Subscription Types

Manage subscriptions through your device's app store settings.


18. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

18.1 Your CCPA Rights

RightDescription
Right to KnowRequest what personal information we collect, use, disclose, and sell
Right to DeleteRequest deletion of your personal information
Right to Opt-OutOpt out of the "sale" of personal information
Right to Non-DiscriminationWe will not discriminate against you for exercising your rights

18.2 Categories of Personal Information Collected

(Under CCPA categories)

18.3 "Sale" of Personal Information

We do not sell your personal information in the traditional sense. However, sharing data with advertising partners may constitute a "sale" under CCPA. You can opt out of this by:

18.4 Exercising Your CCPA Rights

Contact us at privacy@medueti.com with subject line "CCPA Request"

We will verify your identity before processing requests.


19. Changes to This Policy

We recommend reviewing this policy periodically.


20. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data:

General Supportsupport@medueti.com
Privacy Inquiriesprivacy@medueti.com
Data Protection Officerdpo@medueti.com
Websitehttps://medueti.com
Mailing AddressMedueti, Hamburg, Germany

Summary of Key Points

We collect registration data, profile info, content you create, usage analytics, and technical data
We use your data to provide services, personalize experience, process payments, and display ads
We share data with service providers (Firebase, Stripe, AdMob) but never sell your data
You control your data through privacy settings, data export, and account deletion
We protect your data with encryption, secure infrastructure, and strict access controls
Your rights include access, deletion, portability, and objection (GDPR/CCPA)
Messages are encrypted end-to-end for your privacy
Ads can be personalized or not — your choice


This Privacy Policy was last updated on November 25, 2025.

🌍 Medueti — Connecting the African Diaspora Worldwide