Updated August 2026
Your data, your rights — here's how we handle it.
Who We Are (Data Controller)
Blizo is operated by Svurzhi Se, registered in Bulgaria ("we", "us", "our"). We are the data controller for all personal data processed through this app. Contact: [email protected].
What We Collect
We collect: (a) Account data — name, username, email address, profile photo, bio, and date of birth verification. (b) Content you create — posts, stories, event listings, photos, videos, and direct messages. (c) Usage data — events you view, save, or attend; profiles you follow; interactions with content. (d) Location data — precise or approximate GPS coordinates when you grant permission; or a manually entered home city. (e) Device data — device type, operating system version, and app version. (f) Authentication data — if you sign in with Google or Apple, we receive your name and email from that provider.
Lawful Basis for Processing (GDPR)
We process your data on the following legal bases under GDPR Art. 6: (a) Contract performance — to create and manage your account, deliver core app features (event discovery, messaging, profiles). (b) Legitimate interests — to prevent fraud, ensure platform security, and improve app functionality. (c) Consent — for optional features such as precise location tracking; you may withdraw consent at any time. (d) Legal obligation — where required by applicable law (e.g. responding to lawful legal requests).
How We Use Your Data
Your data is used to: operate and personalise your experience; show nearby and relevant events; enable social features (follows, messaging, stories); ensure platform safety and content moderation; send service notifications (not marketing, unless you opt in); and comply with legal obligations. We do not use your data for targeted advertising and we do not sell it.
Location Data
Precise location is only accessed with your explicit permission and used solely to show events near you and calculate distances. You can revoke permission at any time in your device Settings. If denied, you can manually set a home city in the app. We do not share your precise location with other users — only approximate city/area.
Direct Messages
Messages between users are transmitted securely over HTTPS and stored in our database, which is encrypted at rest by our hosting provider (Supabase). We do not apply any additional client-side encryption, and messages are not end-to-end encrypted. We do not read private messages except where legally required (e.g. a valid court order). Message content is not used for advertising or profiling.
Third-Party Processors
We share data only with trusted processors under strict data processing agreements: Supabase (database and authentication, EU-hosted); Google (sign-in via Google OAuth, governed by Google's privacy policy); Apple (Sign in with Apple, governed by Apple's privacy policy); OpenStreetMap Foundation / Nominatim (city and location search lookups, governed by their privacy policy); Expo / EAS (app build and update delivery). These processors may not use your data for any purpose other than providing their services to us. We do not share your data with advertisers or data brokers.
International Data Transfers
Our primary database is hosted by Supabase in the EU. Where data is processed outside the EU/EEA (e.g. by Google for OAuth), we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other lawful transfer mechanisms under GDPR Chapter V, to ensure your data receives equivalent protection.
Your Rights
Depending on where you live, you have rights over your data. EU/UK users (GDPR / UK GDPR): right to access, rectify, erase, restrict processing, data portability, and object to processing. California users (CCPA/CPRA): right to know, delete, correct, and opt out of sale/sharing. Australian users (Privacy Act 1988): right to access and correct your data. To exercise any right, go to Settings > Account > Delete Account or contact [email protected]. We respond within 30 days (or sooner as required by law).