Privacy & Your Data
Your privacy is fundamental to how we build denizen. We operate under the EU General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
Last updated: 31 August 2026
Our Privacy Principles
Privacy by Design
Privacy is built into every feature from day one — not bolted on as an afterthought. We collect only what we need and nothing more.
Transparency
We tell you exactly what data we collect, why we collect it, how we use it, and who can see it. No dark patterns. No tricks.
Your Data, Your Control
You can access, export, correct, or delete your data at any time. You're always in control. We never sell your data.
What Data We Collect
Account & Identity
- •Name (first name only, or full name if you provide it)
- •Email address
- •Whether you identify as a local leader/elected official
Legal basis: Legitimate interest (Art. 6(1)(f)) — providing the service
Location Data
- •Country, county/region, and town/neighbourhood
- •We use Nominatim (OpenStreetMap) for geocoding — IP-based geolocation is used only for initial country detection
Legal basis: Consent (Art. 6(1)(a)) — you choose your location during onboarding
Wellbeing Data
- •Self-assessed wellbeing scores across 14 life dimensions (1-10 scale)
- •Priority ratings for each dimension
- •Year-on-year comparison selections
- •Optional personal notes (you choose whether to add these)
Legal basis: Explicit consent (Art. 9(2)(a)) — this may include health-related data
Civic Engagement
- •Selected civic issues and sentiment responses
- •Votes and polling responses
- •Issue flags and local relevance markers
- •Actions taken or willing to take
Legal basis: Explicit consent (Art. 9(2)(a)) — you are asked outright before any issue question; withdraw at any time by request
Technical Data
- •Anonymous session ID (stored in localStorage — not a tracking cookie)
- •Browser timezone (for country detection only)
- •No IP addresses are stored. No third-party analytics. No advertising trackers.
Legal basis: Legitimate interest (Art. 6(1)(f)) — maintaining service functionality
How We Use Your Data
Personalisation
Your name and location personalise your experience. Wellbeing scores shape the tools and resources we recommend.
Aggregate Community Intelligence
Wellbeing scores and civic sentiment are aggregated (anonymised) to show community-level trends. Individual data is never publicly displayed.
Leader Dashboards
If you opt into leader tools, constituent data is shown only in aggregate form — leaders never see individual records.
Email Communications
If you subscribe, we send monthly wellbeing check-in reminders and platform updates via Resend (our email provider). You can unsubscribe at any time.
What We Never Do
We never sell your data. We never share individual records with third parties. We never use your data for advertising. We never profile you for commercial purposes.
Data Storage & Security
Infrastructure: Your data is stored on Supabase (built on PostgreSQL), hosted in the EU. Supabase provides encryption at rest and in transit (TLS 1.2+).
Data Residency: Everything Denizen itself stores resides within the European Union, compliant with GDPR data residency requirements. There is one named exception: our email provider, Resend, holds its account data in the United States — see “Email Service” below and “Messages Between Neighbours” further down.
Access Control: Admin access requires authentication. Public endpoints use API gateway authorisation. All server communication uses HTTPS.
Session Identifiers: We use a randomly-generated session ID stored in your browser's localStorage. This is not a cookie and is not shared with any third party. It persists only so we can link your onboarding progress and allow you to return to your data.
Email Service: We use Resend to send transactional emails, and to receive your replies to messages that reached you by email. Resend processes your email address, and the content of those emails, solely for delivery purposes under a data processing agreement. Resend holds its data in the United States and uses 22 sub-processors, all US-based, two of which are AI vendors.
No Third-Party Analytics: We do not use Google Analytics, Facebook Pixel, or any third-party tracking service. We do not use advertising cookies.
Messages Between Neighbours
What we store: the messages you send and receive, who they are between, and when each was sent. Messages are private to the two people in the conversation. We do not read them to build a profile of you, and we never use them for advertising.
Read receipts: the other person can see when you have read their message, and you can see when they have read yours. We record the time you last opened each conversation in order to do that.
Typing and “online”: while you both have a conversation open, each of you can see that the other is there or typing. This is the one thing on Denizen that is never stored — it exists only for as long as the conversation is open on your screen, is kept in no table, and leaves no history. Close the page and it is gone.
What email tells us — and what it does not: a message can reach you by email. We record where a message reached — that it was sent to your email address — so the sender can see it arrived. We do not record, and cannot tell anyone, whether you opened that email. There are no tracking pixels in Denizen email.
Who else can see a message: nobody, unless somebody reports it. A report copies a short window of the conversation for a moderator to review, and that copy is kept as evidence. Messages are automatically screened for known scam patterns before they are delivered; that check runs on our own servers and its result is not shared with anyone outside Denizen.
Nobody sees anyone's address: email is relayed through Denizen, so your email address is never shown to the person you are talking to, and theirs is never shown to you.
Who carries a message on its way to you: Email is sent by Resend (data held in the US). WhatsApp nudges go through Meta — Meta reads the nudge, never your neighbour's words. Texts go through a mobile carrier.
In more detail, because these three are the only companies outside Denizen that carry a message to you (Supabase, which stores it, is covered under Data Storage & Security above):
- Resend sends every Denizen email and receives your replies to them. Resend stores its account data in the United States, and uses 22 sub-processors, all US-based, two of which are AI vendors. A data processing agreement is in place. This is the one part of messaging where your data leaves the EU.
- Meta Platforms Ireland Limited delivers WhatsApp nudges. A nudge is Denizen's own sentence about what happened — “Sinéad has replied about your listing” — plus a link. Meta decrypts and reads that nudge in order to deliver it. It never receives your neighbour's own words, because we never send them there.
- The SMS carrier would deliver text nudges. We have not chosen one yet, so no carrier is named here. Neither WhatsApp nudges nor texts are switched on — both channels read “Coming soon” in your settings today. This paragraph will name the carrier before the first text is ever sent. (Placeholder held open for sign-off — the vendor is an unmade decision, not an omission.)
A fuller plain-English explanation lives on the How messaging works page inside Denizen.
Your Rights Under GDPR
As an EU/EEA data subject, you have the following rights:
Right of Access (Art. 15)
You can request a copy of all personal data we hold about you. We will respond within 30 days.
Right to Rectification (Art. 16)
You can ask us to correct any inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
You can request deletion of your personal data ("Right to be Forgotten").
Right to Restrict Processing (Art. 18)
You can ask us to limit how we process your data while a concern is being resolved.
Right to Data Portability (Art. 20)
You can receive your data in a structured, machine-readable format (JSON).
Right to Object (Art. 21)
You can object to processing based on legitimate interest at any time.
Submit a Data Request
Email privacy@denizen.one naming the request type below, and we'll acknowledge your request by email and process it within 30 days as required by GDPR.
Get a copy of all personal data we hold about you (Art. 15 GDPR)
Request erasure of your personal data (Art. 17 — "Right to be Forgotten")
Receive your data in a portable, machine-readable format (Art. 20)
Request rectification of inaccurate personal data (Art. 16)
Request restriction of processing while a concern is addressed (Art. 18)
Object to processing of your personal data (Art. 21)
We will acknowledge your request by email and process it within 30 days.
Privacy FAQ
Questions?
If you have any questions about this privacy policy or how we handle your data, please don't hesitate to get in touch.
Data Controller: denizen.one
Email: privacy@denizen.one
Supervisory Authority: Data Protection Commission, Ireland