- Samely detects nearby users via local Bluetooth signals, without using maps, without tracking exact GPS coordinates, and without showing distance measurements to other users.
- Messaging between two individuals opens only after both users accept a friend request.
- We do not sell personal data, and we do not use third-party cross-context behavioral advertising networks.
- Location data processed for the Area feature is coarsened on the server to protect your exact location.
- You have the right to access, rectify, download, and permanently delete your account and personal data at any time.
- If the English and Vietnamese versions differ, the English version prevails.
Note: This summary provides a convenient overview. The full text below governs in all instances of interpretation and application.
Table of contents
- 1. About this policy and glossary of terms
- 2. Data we process
- 3. Purposes and legal bases for processing
- 4. What other users see
- 5. Device permissions
- 6. Bluetooth and location
- 7. Data sharing
- 8. International data transfers
- 9. Data retention
- 10. Security measures
- 11. Your privacy rights
- 12. Regional privacy notices
- 13. Individuals under 18
- 14. This website
- 15. Changes to this policy
- 16. Contact information
1. About this policy and glossary of terms
This Privacy Policy explains how ZEENII STUDIO (Individual Developer / Independent Studio), located at Online service operated by ZEENII STUDIO, Hanoi, Vietnam, privacy contact email: contact@samely.app (referred to as "Samely", "we", or "us"), processes personal data when you download, install, and use the Samely mobile application.
If the English and Vietnamese versions differ, the English version prevails.
Glossary of terms
Throughout this policy, capitalized and recurring terms have the following meanings:
- Services: The technical platform, mobile application, and related features provided by Samely.
- App: The Samely mobile application distributed on Google Play.
- Account: The personalized user profile created by signing in through Google to use the App.
- Content: Text, photos, messages, comments, and other material you upload, publish, or transmit through the Services.
- Personal Data: Any information relating to an identified or identifiable natural person.
- Processing: Any operation performed on personal data, such as collection, recording, storage, adaptation, disclosure, or deletion.
- Other Users: Other individuals who have registered an Account and access the App.
2. Data we process
We process only data necessary to deliver proximity discovery, communication, and account functionality. The table below outlines personal data by collection source:
| Source | Data categories | Requirement status |
|---|---|---|
| Data you provide directly |
- Display name and birth year. - Profile photos uploaded by you. - Text posts, attached photos, and comments published to the Feed. - Direct and group chat messages exchanged with mutual friends. - Recipient name, phone number, and physical shipping address submitted when redeeming physical gifts in Rewards. |
- Display name and age/birth year: Required to register and confirm eligibility (18+). - Photos, feed posts, chat messages: Optional, based on your participation. - Delivery address: Optional, required only when redeeming physical goods. |
| Data collected automatically |
- Ephemeral randomized Bluetooth signal identifiers broadcasted and received between nearby devices. - Encounter count indicating how many times two devices have crossed paths, and rough proximity levels. - Coarsened geographic location data when you open Area. - Reward points, rank status, and mission milestones. - Push notification tokens. |
- Bluetooth signals: Required to activate nearby presence cards on Home. - Area location: Optional, processed only when accessing the Area tab. |
| Data from Google Sign-In and Google Play |
- Google Account ID, Google account email address, and account display name. - Purchase verification receipts from Google Play Billing for VIP upgrades. We do not receive, store, or process your credit card numbers. |
- Google account credentials: Required for authentication. - VIP receipt tokens: Processed only if you purchase paid upgrades. |
| Data from other users |
- Friend requests sent to your account. - Reports or safety notifications submitted by other users concerning your content or conduct. |
Generated through community interaction on the platform. |
3. Purposes and legal bases for processing
Under international data protection baselines, we process personal data only when a recognized legal basis applies:
| Processing purpose | Data categories involved | Recognized legal basis |
|---|---|---|
| Creating and administering your user account | Google ID, email address, display name, birth year | Performance of a contract (Terms of Use) |
| Detecting nearby users via local Bluetooth presence | Randomized Bluetooth device identifiers | Consent (granted through device Bluetooth permissions) |
| Showing broad locality members in the Area feature | Coarsened geographic location data | Consent (granted through location permissions) |
| Facilitating mutual friend messaging and community posts | Chat messages, feed posts, comments, photos | Performance of a contract |
| Managing rewards, missions, rankings, and gift fulfillment | Points history, rank level, delivery address details | Performance of a contract and user consent for delivery |
| Safety moderation, abuse prevention, and platform security | User reports, block logs, moderation review records | Legitimate interests (securing the community) and legal compliance |
| Statutory accounting and tax records for VIP purchases | Google Play transaction receipt tokens | Compliance with legal obligations |
4. What other users see
Transparency regarding profile visibility is fundamental to our service design:
Information other users can see
- Nearby cards and Area: Your profile photo, display name, encounter count, rough closeness level, and rank badge (if rank Gold or higher).
- On the Feed: Display name, profile photo, public text posts, attached images, and comments you share.
- In Chat: When two people have mutually agreed to become friends, your friend can read your messages in one-to-one chats or shared group conversations.
Information other users CAN NEVER see
- Your Google account email address.
- Your exact GPS coordinates, home address, or map location.
- A numeric distance measurement in meters, kilometers, feet, or miles between you and another user.
- Your identity when you submit a confidential report against another user.
- Physical delivery addresses provided for gift redemptions.
- Your VIP payment transaction history.
5. Device permissions
To function as intended on Android, the App requests specific system permissions:
| Android permission | Intended purpose | Consequence if denied |
|---|---|---|
| Bluetooth permissions (Scan, connect, advertise) |
Enables scanning of nearby devices to detect other Samely users in physical proximity. | The app cannot discover or display nearby user cards on Home. Other features remain accessible. |
| Location permission (Approximate coarse location) |
Supports Bluetooth hardware scanning on certain Android releases and determines broad locality for Area. | You cannot browse members in the Area tab. Bluetooth presence may be limited depending on Android version. |
| Media / Photos permission (Read media images) |
Allows selecting photos from your gallery to set as a profile picture or attach to Feed posts. | You cannot upload pictures from device storage. You can still read posts and send text messages. |
| Notification permission (Post notifications) |
Delivers timely alerts for new messages, friend requests, and system announcements. | No background pop-up alerts. New messages appear when you open the application. |
6. Bluetooth and location
Our proximity architecture minimizes location data exposure:
- Bluetooth proximity: Devices broadcast and listen for temporary, randomized signal identifiers over short-range Bluetooth waves. This allows phones to recognize presence in physical proximity without logging GPS coordinates on our servers.
- Relative closeness: The app registers how many times two users have crossed paths and an approximate closeness tier. We do not store travel routes, timestamps of specific meetings, or numeric distance calculations.
- Area feature: When you browse the Area section, location coordinates are generalized on our backend into broad locality boundaries. Other users only see that you are within that general region, and coarsened data is not retained permanently on the server.
7. Data sharing
Samely does not sell, rent, or lease your personal data. We do not share personal information with third parties for cross-context behavioral advertising. Personal data is shared only in the following limited circumstances:
- Infrastructure service providers: We engage cloud infrastructure providers including Railway (backend application hosting) and Supabase Inc. (managed Postgres database hosting). These providers process data under our instructions and maintain strict security safeguards.
- Google services: Google LLC provides authentication via Google Sign-In and payment processing through Google Play Billing. When you buy VIP upgrades, Google handles your payment card details directly; Samely receives only a transaction verification receipt.
- Partner offers in Rewards: Special offers and vouchers from third-party shops or venues are displayed as informational listings. Samely does not share personal user data with these partners.
- Legal obligations: We disclose personal data only when required to comply with a valid legal process, court order, or mandatory statutory request issued by a competent public authority.
8. International data transfers
Because our backend infrastructure relies on cloud facilities operated by Railway and Supabase, your personal data may be transferred to and processed in countries outside the jurisdiction in which you reside.
Where personal data is transferred internationally, we ensure that appropriate technical and organizational safeguards are implemented to protect your information in accordance with applicable data protection requirements.
↑ Back to top9. Data retention
Personal data is retained only for the duration necessary to fulfill the purposes described in this policy, unless a longer retention period is mandated by law:
| Data category | Retention duration | Action upon expiry or account deletion |
|---|---|---|
| Profile details, photos, friend lists | Active for the lifespan of your user account | Permanently erased from active systems upon account deletion |
| Area generalized location data | Retained temporarily during active session | Automatically overwritten or cleared when feature is closed |
| Feed posts and comments | Active for the lifespan of your user account | Permanently removed or anonymized |
| In-app chat messages | Retained to maintain conversation history for participants | Associated user link removed upon account deletion |
| Physical gift delivery information | Retained until fulfillment confirmation and dispute window closure | Deleted after delivery confirmation and dispute window closure |
| Google Play VIP transaction tokens | Retained as required by applicable tax and accounting laws | Stored in isolated financial archives for statutory accounting periods |
| Safety reports involving child safety or severe abuse | Retained as required by law to support competent authorities | Preserved securely in isolated compliance records |
10. Security measures
We deploy technical and operational security controls designed to safeguard personal data against unauthorized access, loss, or alteration:
- Encryption in transit: All communication between the mobile app and server infrastructure is encrypted using industry-standard TLS/HTTPS protocols.
- Access controls: Strict role-based authorization restricting production database access to designated operational personnel.
- Security reviews: Routine vulnerability assessments, software patches, and automated backup routines.
- Incident response: Procedures to assess, mitigate, and notify relevant authorities and affected individuals in the event of a verified personal data breach in accordance with applicable legal requirements.
While we implement rigorous safeguards, no electronic transmission or digital storage method is guaranteed against all unforeseen security vulnerabilities.
↑ Back to top11. Your privacy rights
Under global data protection standards, you have the following rights regarding your personal data:
- Right of access: You can request confirmation of whether we process your personal data and obtain a copy of your records.
- Right to rectification: You can correct inaccurate or incomplete profile details directly in the app or by contacting us.
- Right to erasure (deletion): You can request the permanent deletion of your account and personal information.
- Right to data portability: You can request an export of your provided personal data in a structured, machine-readable format.
- Right to restrict or object to processing: You can object to or request restrictions on certain processing activities where applicable by law.
- Right to withdraw consent: Where processing is based on consent, you may withdraw your consent at any time without affecting past lawful processing.
- Right to lodge a complaint: You have the right to submit a complaint to your local data protection supervisory authority.
Exercising your rights
To exercise any of these rights, use the settings available inside the app or email our dedicated privacy team at contact@samely.app using the Google email address registered to your Samely account.
We acknowledge receipt of verified requests promptly and provide substantive responses within statutory deadlines, generally within 30 days (or shorter statutory periods where local law applies).
↑ Back to top12. Regional privacy notices
European Economic Area (EEA) and United Kingdom
For individuals residing in the EEA or the UK, the General Data Protection Regulation (GDPR) and UK GDPR apply. The legal bases for processing your data are set forth in Section 3 of this policy. You have the right to lodge a complaint with your national supervisory authority (e.g., the ICO in the UK or the relevant Data Protection Authority in your EU Member State).
Article 27 EU/UK Representative: For data protection inquiries originating from the European Union or the United Kingdom, individuals may contact our designated privacy team directly at contact@samely.app.
United States State Privacy Notices (e.g., California CCPA/CPRA)
Under California and other applicable US state privacy laws, residents have specific statutory rights:
- Categories collected: Identifiers (name, email, user ID), Internet activity (app interactions), coarsened location data, and visual information (photos).
- No sale or sharing: We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
- Statutory rights: You have the right to know what personal information is collected, the right to request deletion, the right to request correction of inaccurate data, and the right not to receive discriminatory treatment for exercising your privacy rights.
Other global jurisdictions
If you reside in another country, we honor the data protection and privacy rights granted to you under your local legislation. Please contact us at contact@samely.app to submit a request under your local laws.
↑ Back to top13. Individuals under 18
Samely is designed and operated exclusively for individuals aged 18 and older. We do not knowingly permit minors under 18 to create accounts or collect their personal data.
If we become aware that an account belongs to an individual under 18, we will immediately terminate the account and erase all associated personal data from our systems.
↑ Back to top14. This website
This policy website is a standalone, cookie-free informational resource. It does not track your online browsing behavior, uses no web analytics tools, sets no tracking cookies, and does not interface directly with the mobile application database.
↑ Back to top15. Changes to this policy
We may update this Privacy Policy from time to time. When significant updates occur, we will post an in-app notice at least 7 days before the revised policy takes effect, except for urgent modifications required for legal compliance or critical security reasons.
If you do not agree with the updated terms, you may discontinue using the app and delete your account before the effective date.
↑ Back to top16. Contact information
For questions, data access requests, or privacy concerns, contact our dedicated privacy team:
- Data Controller: ZEENII STUDIO (Individual Developer / Independent Studio)
- Address: Online service operated by ZEENII STUDIO, Hanoi, Vietnam
- Business / Tax Registration: N/A (Individual Developer)
- Privacy Officer Email: contact@samely.app
- General Support Email: contact@samely.app