MiaB.social privacy policy

Version of September 28, 2026 · Law No. 09-08 on the protection of individuals with regard to the processing of personal data

Who is responsible for your data

MiaB.social is operated by Abdelaziz Hana, an individual domiciled in Morocco (20 rue Ohoud Bettana, 11040 Salé). For any question about your data: contact@miab.social.

This processing has been declared to the National Commission for the Control of Personal Data Protection (CNDP) under No. [receipt number], and the transfer of data abroad has been the subject of request No. [number].

What your data is used for

MiaB.social connects people who need help with people who can help, on a map. Your data is used only to:

  • create and manage your account;
  • publish your help requests and comments, and show them on the map;
  • allow private exchanges between two people who have agreed to them;
  • notify volunteers who have asked for it of requests near them;
  • handle reports and protect the community against abuse.

It is never sold, passed on to others, or used for advertising.

What we collect

DataVisible to
Username, display name, photo (optional except the username)Everyone
Email addressOnly us; never displayed
Help request: text, category and exact point on the mapEveryone, even without an account
Public commentsEveryone
Private messagesThe two participants
A volunteer’s location (if you turn on alerts)Only you; the map shows no one
ReportsOnly us; the reported person does not know who reported them

We never ask for: phone number, date of birth, nationality, immigration or residence status, identity document, bank details.

Before you post

A help request is public and precise: its text and location are visible to everyone. Choose a neutral username, post from a nearby public place rather than from home, and do not write health data, opinions or personal documents in your messages. Private messages are not end-to-end encrypted.

When you create an account, you tick a box to accept this policy, including the transfer of your data to the providers listed below. Location and notifications are only turned on if you allow them in your browser; you can withdraw that permission at any time.

Who receives your data, and in which countries

ProviderCountryRole
Supabase Pte. Ltd.Singapore (data hosted in Ireland, AWS eu-west-1)Database, authentication, profile photo storage
Vercel Inc.United StatesWeb app hosting, server functions, anonymous audience measurement (Vercel Analytics)
Mapbox, Inc.United StatesInteractive base map
OpenStreetMap Foundation (Nominatim)United KingdomConverting a location into a place name
Google LLC (Firebase Cloud Messaging), Apple Inc., Mozilla CorporationUnited StatesDelivering notifications to the user’s browser
GitHub, Inc. (Microsoft)United StatesStorage of the daily database backups
Google LLC (sign-in)United StatesSigning in with a Google account, if the user chooses to

These providers act on our instructions, under data processing agreements.

How long we keep it

DataRetention
Account: username, display name, email, photoUntil the account is deleted. Deletion on request within 7 days; it also erases all the data below.
Help request (text, category, location)Visible for 24 h (emergency), 7 days (help, information), 14 days (lost / found item) or 30 days (event), then hidden; kept until its author’s account is deleted, for handling reports.
Public commentsUntil their author’s account is deleted.
Private messagesThe conversation closes 30 days after the request expires; messages are kept until the account of either participant is deleted.
A volunteer’s locationUpdated each time the app is opened; ignored after 90 days without an update; deleted with the account.
Alerts for a visitor without an account (location, subscription)Deleted after 60 days without a visit.
Notifications waiting to be sent7 days after sending; 30 days if sending fails.
ReportsUntil the reporter’s account is deleted.
Encrypted database backups7 days; deleted data disappears from the backups no later than 7 days afterwards.
Hosting providers’ technical logsAccording to Supabase’s and Vercel’s retention periods (a few days).

Security

The database is backed up every night; each backup is encrypted before it is stored, and kept for 7 days. All communications go through HTTPS. Access rules are enforced by the database itself: a user cannot read another user’s messages or location. The content of notifications is encrypted all the way to your device. We will inform you as soon as possible of any incident affecting your data.

Your rights

Under Law No. 09-08, you may at any time access your data, have it corrected, and object, on legitimate grounds, to its processing. You can edit your profile in the app and request the deletion of your account by email to contact@miab.social: it is carried out within 7 days and erases your requests, comments, messages and locations.

If you believe your rights are not being respected, you can refer the matter to the CNDP (www.cndp.ma).

Minimum age

MiaB.social is reserved for people aged 18 or over. Every user confirms this when signing up; an account found to belong to a minor is deleted.

Changes

We will inform you in the app of any significant change to this policy.