Privacy Policy
Effective 4 August 2026Last updated 4 August 2026
1. Who we are
Been is operated by Emmanuel Phiri (ABN 81 224 437 424), a sole trader based in Perth, Western Australia (“Been”, “we”, “us”).
Been is a map-based app for sharing places you have genuinely visited with friends and people you choose to follow. This policy explains what personal information we collect, why, who we share it with, and your rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
We are committed to complying with the Australian Privacy Principles. If you have any questions or concerns, contact us at privacy@trybeen.app.
2. The short version
- We collect what the product needs to work: your phone number, the places you post, your photos and takes, and your friends and follows.
- We never track your live location in the background. Been is about places you choose to post, not where you are right now.
- If you choose to find friends from your contacts, we match phone numbers against existing users and then discard them — we don’t keep your address book.
- We don’t sell your personal information, and we don’t show ads.
- Your data is processed by a small set of infrastructure providers located overseas — mainly in South Korea, the United States, and Europe. They act on our instructions.
- You can access, correct, or delete your data at any time, including full account deletion in the app.
3. What we collect
Account information. Your phone number, which you verify with a one-time SMS code when you sign up and each time you sign in. You may optionally add a recovery email address; it is not used to log in. We also collect your chosen display name.
Profile information. Your username, profile photo, and bio if you choose to add them.
Content you post. Places you mark as visited or want to visit, photos you upload, your written one-liner takes, and the time you posted them. A place post includes the venue’s location — this is the location of the venue, selected by you from venue search, not a recording of your movements or your device’s GPS position. Photos are re-encoded before upload, which removes embedded metadata — including any GPS location and device details — from the image file.
Contacts (only if you allow it, matched then discarded). During onboarding you can choose to find friends from your contacts. If you grant contacts permission, the phone numbers in your address book are sent to our server over an encrypted connection, matched against the phone numbers of existing Been users to show you who’s already here, and then discarded. Your contact list is never stored or logged, we do not build shadow profiles of non-users, and contact data is not used for any other purpose. You can skip this entirely and find friends by username instead.
Device location (only when you allow it). If you grant location permission, we use your device’s location while you’re using the app to centre the map, show nearby places your friends have visited, help you find the venue you’re posting about, and show distances to places in your feed and saved lists — including taking proximity into account when ordering them. We do not collect location in the background, and we do not maintain a history of your device’s movements. You can use Been without granting location permission by searching for venues manually.
Social graph. Your friends (mutual, accepted connections) and the creators you follow. Been has no likes, comments, direct messages, follower counts, or leaderboards.
Photos and camera roll access. If you grant photo library or camera access, we access only the single photo you select to attach to a post. We do not scan or upload your camera roll.
Usage and analytics data. How you use the app (screens viewed, features used, session length), collected via PostHog to help us improve the product. These events are linked to your Been user ID and include standard device metadata (device model, OS version, app version). They are not anonymous, but they contain no ad identifiers or cross-app tracking, and are never sold or shared for advertising.
Device and diagnostic data. Device model, OS version, app version, crash reports and error logs (via Sentry, configured not to capture personal information), and a push notification token if you enable notifications.
Support communications. Anything you send us when you contact support.
4. What we do NOT collect
- Background or continuous location tracking, or any history of your device’s movements
- GPS coordinates or device details embedded in your photos — photo metadata is stripped on upload
- A stored copy of your contacts or address book (contact matching, if you opt in, is match-and-discard as described above)
- Private messages (Been has none)
- Advertising identifiers, or data from data brokers or advertisers
- Sensitive information as defined by the Privacy Act (health, religion, political opinions, biometrics), unless you choose to include it in content you post
5. Why we collect it (purposes)
We collect and use personal information to: create and operate your account and verify sign-in by SMS code; display your posts and map to the people allowed to see them; help you find friends already on Been (if you opt in to contact matching); power venue search and the map, including showing nearby places from your friends when you allow location (Mapbox); show distances to places in your feed and saved lists and order them by proximity, while you’re using the app with location allowed; send push notifications you have enabled — you control these in settings; moderate photos for safety; understand aggregate product usage and fix crashes; comply with legal obligations; and communicate with you about the service.
We do not use your personal information for purposes unrelated to these without your consent.
6. Who can see your content
Two things control who sees your posts: your account’s privacy setting, and each post’s shared/private flag.
Your account is Private by default. Posts by Private accounts are visible only to your friends (connections you have both accepted) — on every surface, including venue pages. They never appear to strangers anywhere, and they cannot be shared as links.
If you switch to a Public profile (an explicit setting you choose), your shared posts also appear on the venue’s own page in the app, where any signed-in Been user viewing that venue can see them.
Each post is additionally either shared or private:
- Private posts are visible only to you, whatever your account setting.
- Shared posts are visible to your friends on their map and feed — and, if your profile is Public, on venue pages as described above.
Share links. You can share one of your posts as a link (trybeen.app/p/…). That page is viewable by anyone on the web — no Been account needed — and shows the post’s photo, one-liner, venue, and your display name, username, and profile photo. Only shared posts by Public-profile accounts can be shared this way; this is enforced on our servers, so a Private account’s posts cannot be exposed by a link even accidentally.
Friendships on Been are mutual — both people must accept. There is no public feed of strangers’ activity, no reshare mechanic that pushes your content beyond where you posted it, and no public engagement counts. If you don’t want a post visible on a venue page or shareable as a link, keep your account Private or make the post private.
7. Who we share it with (service providers)
We use a small number of service providers (“processors”) who handle data on our instructions to run Been. We do not sell personal information, and no provider is permitted to use your data for its own advertising.
| Provider | What they do for Been | Data involved | Location |
|---|---|---|---|
| Supabase | Database, authentication (SMS sign-in), photo storage, contact matching | Phone number, account, profile, posts, photos, social graph; contact phone numbers transiently during matching | South Korea |
| Netlify | Website hosting and shared-post pages | Visitor IP addresses, shared-post content it serves | United States |
| Twilio (Twilio Verify) | Delivery of sign-in verification codes | Phone number, verification message | United States |
| Mapbox | Maps and venue search | Map interactions, coarse location while using the map | United States |
| Sightengine | Automated photo moderation | Photos you upload (transiently, for safety screening) | European Union (France) |
| Expo | App builds and push notification delivery | Push tokens, device info | United States |
| Sentry | Crash and error reporting | Device/diagnostic data, error context | United States |
| PostHog | Product analytics | Usage events tied to your user ID, device metadata | United States / EU |
| Resend | Service email (e.g. recovery email verification); no marketing | Email address (if you add one), email content | United States |
| Apple | App distribution (App Store / TestFlight) | Per Apple’s own privacy policy | United States |
We may also disclose personal information where required by law (e.g. to law enforcement under a valid legal process), or in connection with a restructure of the business (e.g. incorporation as a company or a sale), in which case this policy will continue to apply to your data.
8. Overseas disclosure (APP 8)
The providers above store and process data outside Australia, primarily in South Korea (our database and photo storage), the United States, and the European Union. Before disclosing personal information overseas, we take reasonable steps to ensure recipients handle it consistently with the APPs, including entering data processing agreements with each provider. By using Been you acknowledge your data will be processed in these locations.
9. Automated decision-making
Been uses automated systems in two ways: (1) your feed and map surface places based on your social graph — your friends and who you follow — rather than engagement-based ranking; and (2) photos you upload are automatically screened for unsafe content before publication (via Sightengine). If screening is temporarily unavailable, your post is not published — we never allow unscreened photos through — and you can simply try again. If a photo is blocked and you believe that’s wrong, you can contact us for human review. We do not use automated decision-making that produces legal or similarly significant effects about you.
10. Data retention
We keep your personal information while your account is active. If you delete a post, it is immediately hidden from everyone in the app. The underlying post data and photos are permanently deleted when you delete your account. If you delete your account, your profile, posts, photos, and social graph are deleted (backup copies expire within 7 days), except reports made about content or accounts (kept for safety and moderation integrity, with your account’s identifiers removed) and records we must retain by law. Crash and diagnostic data is retained for 90 days. Product analytics data is retained for 12 months, then deleted.
11. Security
We take reasonable steps to protect your information, including encryption in transit (TLS) and at rest, row-level security on our database, access controls, and using established infrastructure providers. No system is perfectly secure; if a data breach occurs that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.
12. Your rights: access, correction, deletion
You can: view and edit your profile and posts in the app at any time; delete your account entirely from within the app (Settings → Danger zone → Delete account), which permanently removes your account, profile, posts, photos, and social connections from our systems — except reports made about content or accounts (kept for safety and moderation integrity, with the deleted account’s identifiers removed) and records we must retain by law; and contact us to request a copy of the personal information we hold about you, ask us to correct it, or ask questions about this policy. We will respond within 30 days. We do not charge for reasonable requests.
13. Anonymity and pseudonymity (APP 2)
You may use a pseudonymous display name and username on Been — you are not required to use your legal name in your profile. We do require a working phone number to create and secure your account, because it is how you sign in.
14. Marketing and communications (APP 7)
We send service messages (sign-in codes, security, account notices) as part of operating Been. We do not currently send marketing email. If we introduce it, it will be strictly opt-in — never a pre-ticked box — and every marketing email will include an unsubscribe link. Push notifications are controlled by you in your device settings and in-app notification preferences.
15. Children
Been is not directed at children, and you must be at least 16 to create an account. We do not knowingly collect personal information from anyone under this age; if you believe someone under 16 has created an account, contact us and we will delete it.
16. Cookies and website
Our website, trybeen.app, is hosted by Netlify (see §7). If you join the waitlist, we collect your email address, stored alongside a hashed IP address used only for rate-limiting. We use your email solely to tell you when Been is available — nothing else — and will delete it on request. The website uses privacy-respecting analytics (PostHog) configured to be anonymous: we record only explicit events, with no autocapture, no session recording, and no cookie-based tracking of individuals.
17. Changes to this policy
We may update this policy from time to time — including as we add planned infrastructure (e.g. new photo storage, subscriptions, venue billing), at which point the relevant sections will be updated before the change goes live. Material changes will be notified in the app or by email before they take effect. The current version will always be available at trybeen.app/privacy.
18. Complaints and contact
If you have a privacy question or complaint, contact us first and we’ll do our best to resolve it within 30 days:
Emmanuel Phiri, operator of Been
ABN 81 224 437 424
Perth, Western Australia
Email: privacy@trybeen.app
If you’re not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC): www.oaic.gov.au | 1300 363 992 | GPO Box 5288, Sydney NSW 2001.
This policy was prepared with reference to the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles. It is provided for transparency and is not legal advice.