NoGo
Support

Privacy Policy

Last updated: 18 August 2026

NoGo is built so that as little as possible accumulates about you: there is no user account, no email address, no free-text fields and no photos. This policy describes which data is nevertheless processed when you use the “NoGo” app, why, for how long — and what rights you have.

1. Controller

ESBM-Solutions UG (haftungsbeschränkt) i. Gr.
Ditfurthstraße 48
33611 Bielefeld, Germany
Email: support@esbm-solutions.com

2. Hosting

The app’s API (api.nogo.esbm-solutions.com) runs on servers operated by Hetzner Online GmbH (Germany), managed via Coolify; the server location is Frankfurt am Main. The PostgreSQL database holding the report data is operated by Supabase, Inc. — also in a data centre in Frankfurt am Main (AWS region eu-central-1). Data processing agreements are in place with both providers. Report data and location queries are processed exclusively in Germany.

3. Use without an account

NoGo has no registration and no sign-in. We collect neither an email address nor a name, phone number or password, and the app is not linked to any social login.

So that reporting limits, confirmation limits and abuse protection can work at all, the app creates a random device identifier the first time you use it. That identifier is stored in your device’s encrypted system storage and is kept on our server only as a cryptographic hash (SHA-256). It contains no information about you, your device or your connection and is not linked to any advertising identifier. If you delete the app you lose access to that identifier; reinstalling creates a new one.

4. Which data we process

5. Location data in detail

In the foreground (while you are using the app) we use your location to centre the map on you, to place and verify your report and to find help nearby.

In the background we use your location only if you explicitly enable warnings and grant the “always allow” permission. In that case the app loads the current areas within your chosen radius (500 m to 5 km) and monitors up to 18 zones of 200 metres radius each on your device. If you enter such a zone, the app creates the notification itself. We do not keep a server-side movement profile, and your location is not continuously transmitted for this purpose. You can switch warnings off at any time in the app settings or in your device’s system settings.

6. Notifications

Warnings are local notifications triggered by your own device. We do not send push messages through a push service, we store no push token, and we are technically unable to message you individually.

7. Reports and other people’s data

A report describes a situation at a place, not a person. That is exactly why the app has no input fields for names, descriptions or photos: no identifying information about third parties should be created in the first place. Please do not use NoGo to follow, observe or tag individual people — our terms of use prohibit this.

8. Purposes and legal bases

PurposeLegal basis (Art. 6(1) GDPR)
Providing the map, reports, confirmations and nearby help(b) — performance of the contract of use
Abuse protection: reporting and confirmation limits, plausibility check, trust score, IP counter during registration(f) — legitimate interest in a reliable map with little abuse
Warnings (background location and notifications)(a) — your consent, revocable at any time
Non-personalised advertising to finance free use(f) — legitimate interest in financing the service
Personalised advertising (only after consent in the consent dialog)(a) — your consent, revocable at any time
Crash reports to keep the app stable(f) — legitimate interest in a working app
Measuring the success of our ad campaigns (only after consent)(a) — your consent, revocable at any time
Handling and managing subscriptions(b) — performance of the subscription contract

9. Recipients and processors

ServicePurposeLocation
Hetzner Online GmbHHosting of the APIGermany
Supabase, Inc.Hosting of the database (data centre in Frankfurt am Main)USA (data stored in Germany)
Google AdMob (Google Ireland Ltd.)Ad banner on the map screen (only without a subscription)Ireland / USA
Functional Software, Inc. (Sentry)Crash and error reports (EU servers, data stored in Frankfurt am Main)USA (data stored in Germany)
TikTok Technology Ltd.Measuring the success of our ad campaigns — only with your consentIreland / USA and others
RevenueCat, Inc.Technical management of subscriptionsUSA
Apple / Google PlayDistribution of the app, processing of purchasesIreland / USA

Beyond that we use no further analytics or AI services; in particular, NoGo uses no OpenAI or comparable AI providers.

10. Advertising

Without a subscription we show an ad banner — exclusively on the map screen. No advertising appears in the reporting, help, onboarding or settings areas.

On first launch in the European Economic Area, Google’s consent dialog (User Messaging Platform, following the TCF standard) asks whether you agree to personalised advertising; on iOS, Apple’s App Tracking Transparency (ATT) additionally applies. Only with your consent does Google AdMob serve personalised ads and use your device’s advertising ID for that purpose. Without consent, advertising remains non-personalised; if your consent state does not permit any ads, the advertising SDK is not started at all.

In both cases Google AdMob processes technical information about the device and the ad request as well as a coarse location (region) derived from the IP address, in order to deliver ads, cap their frequency and prevent fraud. We do not pass any reports, NoGo device identifiers or precise locations to AdMob.

You can change or withdraw your advertising consent at any time in the app under Settings → Privacy settings for advertising. With a subscription, no advertising is loaded at all.

11. Crash reports (Sentry)

If the app crashes or a technical error occurs, it sends an error report to Sentry (Functional Software, Inc.). A report contains the technical error message with its execution trace, the app version, operating-system version and device model, and the time. We have deliberately restricted Sentry to the minimum: no session replay, no performance tracing, no transmission of personal details (send-PII is disabled); your NoGo device identifier, your reports and your location are never part of an error report. Processing takes place on Sentry’s EU servers in Frankfurt am Main; reports are automatically deleted there after 90 days at the latest. The legal basis is our legitimate interest in a stable app (Art. 6(1)(f) GDPR).

12. Measuring the success of ad campaigns (TikTok)

To measure whether our ads on TikTok work, we use the TikTok Business SDK — exclusively if you explicitly agree in the dialog on first launch (Art. 6(1)(a) GDPR). If you decline, the SDK is never started and no data whatsoever flows to TikTok. If you agree, the app transmits individual events to TikTok: completion of onboarding, the start of a subscription purchase and a completed purchase (with price, currency and product ID) — together with technical device information and, if you have allowed it on iOS via ATT, your device’s advertising ID. Your reports, your location and your NoGo device identifier are not transmitted to TikTok. The provider is TikTok Technology Ltd. (Ireland); data may also be transferred to third countries, in particular the USA. You can withdraw your consent at any time with effect for the future — directly in the app via the toggle Settings → Legal → Ad campaign measurement. After withdrawal, no further events are transmitted to TikTok.

13. Subscriptions

The “Ad-free” and “Supporter” subscriptions are purchased through the Apple App Store or Google Play; your contractual partner for the purchase is Apple or Google. The technical management (checking which subscription is active) is handled by RevenueCat. This creates an anonymous app identifier, the store’s purchase and transaction identifiers and the subscription status. We receive no payment data such as credit card numbers or billing addresses. The privacy policies of Apple and Google apply in addition. The subscription status is stored on your device and is not linked to your reports.

14. Retention

15. Transfers to third countries

Google AdMob, RevenueCat and — only with your consent — TikTok process data (also) in the USA. Sentry and Supabase are US companies but store the data described here on servers in Frankfurt am Main; access from the USA is contractually safeguarded. Transfers are based on the EU standard contractual clauses or an adequacy decision (EU-US Data Privacy Framework), where applicable. Your reports and location queries do not leave Germany.

16. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection. Consent you have given — for instance to warnings — can be withdrawn at any time with effect for the future by switching them off in the app. You also have the right to lodge a complaint with a data protection supervisory authority.

You can exercise your right to erasure (Art. 17 GDPR) without going through us at all: in the app under Settings → My data, “Delete my data” removes your device identifier and its trust score from our servers immediately and irreversibly. In the same step your reports and confirmations are anonymised — the link to your identifier is permanently removed, so that afterwards neither we nor any third party can establish which device a report came from. The anonymised reports stay on the map as a warning for others and are permanently deleted no later than 90 days after they arrive. Because they carry no personal reference once the link is gone, they are no longer personal data within the meaning of Art. 4(1) GDPR and are therefore no longer covered by the right to erasure. The same screen also shows you your device identifier.

A practical note for every other kind of request: because we deliberately store no contact details, we can only match a request to your data if you tell us your device identifier. Without that link we cannot provide information or carry out a targeted deletion — this is not a refusal but a consequence of data minimisation (Art. 11 GDPR).

17. Contact for privacy matters

For questions or to exercise your rights, contact: support@esbm-solutions.com.

Note: This text is a carefully prepared draft and does not constitute legal advice. We recommend having it reviewed by a lawyer before the official app launch.