Privacy Policy
Last updated: 27 May 2026This Privacy Policy explains how Xibarri ("we", "us") collects, uses and protects your personal data when you use the Xibarri app and website. We only collect what we need to route your reports to the right public bodies and keep the community working.
Who we are
Xibarri is the data controller for the personal data processed through the app and this website. If you have any questions about this policy or how we handle your data, contact us at privacy@xibarri.com.
Information we collect
We collect the following information when you use Xibarri:
- Account details: your name or handle, email address, and — if you sign in with Google — your basic Google profile.
- Reports you create: the title, description, photos, category and the location you attach to each report.
- Activity: the votes, comments and follows you make, and the towns you choose to follow.
- Technical data: device type, app version, language, and a push-notification token if you enable notifications.
How we use your information
We use your data to:
- Create and manage your account.
- Publish your reports and route them to the public body responsible for the area.
- Show rankings, votes and comments to other neighbours.
- Send you notifications about your reports and activity, if you opt in.
- Keep Xibarri secure, prevent abuse and improve the service.
Legal basis
We process your personal data under the EU General Data Protection Regulation (GDPR) on the following bases: performance of our contract with you (to provide the service), your consent (for notifications and optional features), and our legitimate interest in keeping the platform safe and useful.
What is public
Reports, votes and comments are public by design — that's how neighbours and public bodies see what needs fixing. Your handle and the content you post may be visible to other users and to the public authorities a report is sent to. Your email address is never shown publicly.
Sharing your information
We share data with public authorities so they can act on your reports, and with service providers that host and operate the app (for example our hosting and database provider). These providers act on our instructions and are bound by confidentiality. We may also disclose data where required by law.
Data retention
We keep your account data for as long as your account is active. Reports remain published as part of the public record of an area. If you delete your account, we remove or anonymise your personal data, except where we must keep it to comply with legal obligations.
Your rights
Under the GDPR you can request access to your data, correct it, delete it, restrict or object to its processing, and ask for a copy in a portable format. To exercise any of these rights, email privacy@xibarri.com. You also have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD).
Security
We use industry-standard measures to protect your data, including encryption in transit and access controls. No system is completely secure, but we work to keep your information safe.
Age requirement
Xibarri is not intended for children under 14. If you are under 14, please do not use the app. If we learn that we have collected data from a child under 14 without parental consent, we will delete it.
Changes to this policy
We may update this policy from time to time. When we make significant changes, we will let you know in the app or by updating the date at the top of this page.
Contact
Questions about your privacy? Email us at privacy@xibarri.com.