Privacy Policy
Effective September 13, 2026 · version privacy-v8
The short version
The short version: we collect what we need to run a private social app — your profile, the content you share with your connections, and, if you use the Map, a one-time identity verification handled by Stripe. Your device location is read only in the moment, to show events near you or to place the pin on an event you create; we never store where you are, and no other user ever sees your position. Direct messages are end-to-end encrypted, so we can’t read them. Your data lives primarily in Canada and we don’t sell it. You can download everything we hold about you from Settings, deactivate whenever you like, and delete your account for good — deletion takes effect after 30 days, and you can cancel any time before then. We text you only to send a sign-in code you asked for — never marketing — and we never share mobile numbers with anyone for their own marketing. Message and data rates may apply. Questions or requests: privacy@ensosocial.app.
1. What This Policy Covers
This policy explains what personal information Enso ("we", "us") collects, why, who we share it with, and the choices you have. It applies to the Enso app and related services. We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and other applicable Canadian privacy laws.
2. What We Collect
- Account & profile: name, username, date of birth, phone number or email, bio, interests, avatar, and profile details you add.
- Location: read from your device only while you use the Map, to show events near you or to place the pin on an event you create. It is used in the moment and never stored (see section 3).
- Content: Stories, Moments, Memories, comments, event details, and other content you create (see section 8 for how long each kind lasts).
- Messages: your direct and group messages, stored end-to-end encrypted (see section 4).
- Connections & activity: who you connect with, events you host or join, and reports and blocks you make.
- Verification data: handled by our verification provider under a separate consent (see section 5).
- Device & diagnostics: device type, OS, app version, crash and freeze reports (encrypted, and sent to Sentry — see section 7), and analytics about how the app is used, recorded against a pseudonymous identifier that rotates every 30 days.
- Legal records: the versions of the Terms, policies, and consents you accepted, and when.
3. Location: Never Stored
Enso is not a location-based app. The only location we store is an event’s, placed by its organizer. Your own position is read from your device only while the Map is open — to show events near you, or to put the pin on an event you are creating — and it is never written to our servers, never kept as a history, and never shown to any other user, masked or otherwise.
Event pins are protected too: before you join an event you see the neighbourhood, not the address. The exact address opens only to people who have joined, and for events that are not open to everyone, only once the event’s safety minimum has been met.
The app asks for location permission only when you open the Map, and you can withdraw it in your device settings at any time; the rest of Enso works without it. Separately, your Active Sessions list shows an approximate city for each sign-in so you can spot a sign-in that was not you — that city comes from your network address, not from your device’s location (see section 7).
4. Messages: End-to-End Encrypted
Direct messages and group chats on Enso are end-to-end encrypted. The encryption keys live on your device — we store only ciphertext and cannot read your message content. Your encryption key is backed up under your PIN with help from a secret we hold, and under your recovery phrase, which never leaves your device. If you lose both, we cannot recover your message history. Message metadata needed to deliver messages (who, when) is processed by our servers.
5. Identity Verification
To use the Map, Enso requires a one-time government-ID verification, performed by Stripe Identity. It happens only under an explicit consent presented at the time, which describes exactly what is collected, where it is processed (Stripe processes ID images in the United States), what we keep, and for how long. We do not store your ID images, and we do not store the details on your ID either — not your document number, and not the name or date of birth printed on it. Stripe holds the verification record; we keep only whether you passed, the date, Stripe’s reference number, and two one-way fingerprints that let us stop the same person opening a second account without telling us who that person is. If we need to see your identity details for a safety review or a lawful request, they are fetched from Stripe at that moment, never from our own records, and every access is logged with the reason. Enso does not run criminal-record or background checks.
6. How We Use Your Information
We use personal information to:
- Provide the Service: profiles, connections, events, messaging, the Map.
- Keep people safe: verification, moderation, investigating reports, enforcing our Terms, and preventing banned users from returning.
- Fix and improve the app: diagnostics, crash reports, usage analytics.
- Communicate with you: service messages, and push notifications you can turn off.
- Meet legal obligations: responding to lawful requests and keeping required records.
We do not sell your personal information, and we do not use the content of your encrypted messages for anything — we can’t read it.
7. Who We Share It With
We share personal information only with:
- Service providers who help us run Enso: Supabase (our database and backend, hosted in Canada — ca-central-1); DigitalOcean (storage for photos, videos and voice notes, hosted in Toronto, Canada); Stripe Identity (identity verification, processed in the United States); push-notification delivery via Expo, Apple and Google; Sentry (crash reports, hosted in the EU, with your identity and message content stripped before sending); and ipapi.co, with ipinfo.io as a fallback, which the app asks at sign-in for the approximate city behind your network address so that your Active Sessions list can show where each sign-in came from. Those two services see your IP address for that one request; we store only the city, never the address.
- Other users: only what the app is designed to show them (your profile, the content you share with them, and the events you join).
- Authorities: where the law requires it, or where necessary to address a serious safety risk — under our consents and policies, and with access logged.
- A buyer or successor: if Enso is ever acquired or merged, under the same protections.
When your information is processed outside Canada (for example by Stripe in the US), it is subject to the laws of that jurisdiction. We use contractual and technical safeguards with all providers.
Mobile numbers and SMS consent are never shared, sold, or rented to third parties or affiliates for their own marketing or promotional purposes. Your number reaches our messaging provider and your own carrier for the sole purpose of delivering a code you requested.
8. How Long We Keep It
- Account data: while your account is active.
- Deactivating: hides your profile, content and messages from everyone else. Nothing is deleted, there is no time limit, and you can reactivate whenever you like.
- Deleting: your account is hidden immediately and permanently deleted 30 days later. During those 30 days you can cancel by signing in — nothing is lost. We email you when you request it, again about 5 days before, and again 24 hours before; if we have no email address for you we send the same notices as push notifications and show a countdown in the app.
- What deletion destroys: your profile, posts, comments, stories, photos and videos, connections, circles, messages and your encryption keys. Once the 30 days are up this cannot be undone by anyone, including us.
- Stories: automatically deleted — both the story and its photo or video file — about 24 hours after you post them. We do not keep an archive of your expired stories.
- Moments: fade from other people’s view after 7 days, and stay available to you on your own profile until you delete or hide them.
- Memories: a Moment you share with a tagged connection becomes a Memory. Memories do not fade — they stay on your profile and visible to your connections until you delete them or remove the tag.
- Reported content: if content is reported, we keep a copy — including its photo or video — until our moderation review is finished, even if it would otherwise have expired or you deleted it. This is how we investigate safety reports fairly. An open report about you also pauses deletion of your account until the review is finished.
- Legal preservation: if we receive a valid legal or law-enforcement preservation request, we place the relevant data on hold and pause our automatic deletion for it, for as long as the law requires.
What we keep after your account is deleted, and why:
- A record that you accepted our Terms and this policy, and which version — kept for 6 years, to show consent was given and to defend legal claims.
- Safety and moderation records (reports, enforcement actions, an internal note of your account’s standing, and a one-way scrambled fingerprint of your phone number or email) — kept for 2 years, so a banned account cannot simply be recreated and so we can respond to a safety investigation. These hold no profile data and cannot be turned back into your identity.
- Your verification record, if you completed identity verification — that you passed, when, Stripe’s reference number, and the one-way fingerprints described in section 5. Kept for up to 2 years after deletion for safety and lawful-request purposes, then permanently destroyed. This holds none of your identity details, because we no longer store them.
- Anything under a legal hold — until the hold is lifted.
- Backup copies — our routine backups roll over within 35 days, so a deleted account may persist in an unrestored backup until then. Profile photos, cover photos, Moment and Memory photos and videos, and group photos are also kept in a recovery copy for up to 7 days after they are deleted or replaced, so a mistaken deletion can be undone; Stories, chat photos and voice notes have no recovery copy.
Outside of those cases, deleted and expired data is gone and cannot be recovered — including by us.
9. Your Rights & Choices
You can:
- Access and correct your information — much of it directly in the app; the rest via a request.
- Download a copy of everything we hold about you, as a machine-readable JSON file, from Settings → Privacy → Download my data. It includes your profile, posts, comments, connections, circles, feedback, support history and consent records, plus links to your photos and videos. Your messages are end-to-end encrypted, so the app adds their text from your own device — our servers cannot read them. This is free, and you can do it a few times a month without asking us.
- Deactivate your account at any time in Settings — a pause, not a deletion.
- Delete your account at any time in Settings → Account. See section 8 for exactly what happens and when.
- Withdraw consents, subject to legal and contractual limits — though some features (like the Map) require verification or location to function.
- Control device permissions (location, notifications, camera) in your device settings.
- Object to, or ask us to restrict, particular processing. Deactivating your account is the fastest way to restrict everything at once.
- Complain: contact our privacy officer first (section 13); you also have the right to complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca). If you are in the EU or UK, you may also complain to your local supervisory authority.
If you ask us for something we cannot do in the app, we will respond within 30 days.
10. How We Protect It
Safeguards include encryption in transit and at rest, end-to-end encryption for messages, not storing identity details at all — with any access to them fetched from our verification provider and logged with a reason, row-level security in our database, secure credential storage on your device, and access to your information limited to the people who need it, with every access logged. No system is perfectly secure, but security decisions in Enso default to the protective option.
Content review: a person may view content you post — your posts, stories, profile information and connection activity — when reviewing a report, enforcing our Community Guidelines, investigating suspected abuse, or complying with law. Every such access requires a documented reason and is logged and auditable. Nobody can browse content casually or without a record. Your end-to-end encrypted messages are never accessible to us — the only way message content reaches moderation is if someone in the conversation reports it, which shares recent messages from that conversation from their device (see section 4).
11. Adults Only
Enso is for adults 18 and older. We do not knowingly collect information from anyone under 18; date-of-birth checks and identity verification enforce this. If you believe a minor is using Enso, please report it immediately in the app.
12. Text Messages (SMS)
Enso sends text messages for one reason: a one-time code to sign you in, or to confirm a sensitive change to your account. You request each message yourself by entering your number and tapping Send code. We never text you unprompted.
- Message frequency: one message per sign-in or verification request you make. Nothing is recurring or scheduled.
- Message and data rates may apply, depending on your mobile plan and carrier.
- We do not send marketing or promotional texts, and there is no way to be enrolled in any.
- We do not share, sell, or rent mobile phone numbers or SMS consent to third parties or affiliates for their own marketing or promotional purposes. Your number is disclosed only to the provider that delivers the message and to your own carrier, solely to deliver the code you asked for.
- To stop these messages, reply STOP, or stop requesting codes. Because the code is how you sign in, stopping them means you can no longer sign in by phone — add an email address in Settings first if you would like another way in.
- For help with these messages: privacy@ensosocial.app, or Settings → Support.
13. Changes & Contact
If we make material changes to this policy, we will notify you in the app and ask you to review the new version before continuing. Each version is numbered and dated, and the version you accepted is recorded.
Privacy questions and requests: privacy@ensosocial.app, or Settings → Support in the app.
Enso is operated by Ashish, an individual carrying on business as a sole proprietor in Ontario, Canada, who is the privacy officer accountable for this policy under PIPEDA. Reach the privacy officer at privacy@ensosocial.app; a postal address is available on request.