Privacy Policy

Effective 18 August 2026. How FreeMan collects, uses, and protects information, in plain language.

The short version

  • You can use FreeMan without ever giving us your name or email.
  • Your check-ins and notes are tied to an anonymous device identity, not to you personally, unless you choose to add an email.
  • We never sell your data, and we don't run ads or trackers.
  • You can permanently delete everything, instantly, from Settings — no form, no wait.

Who we are

FreeMan is a project of the Anti-Social Social Vices Club (ASVC), ROYAL Ambassadors, Lagos East Baptist Conference (RALEBC). ASVC RALEBC is the data controller for the information described in this policy.

Information we collect

Anonymous identity. The first time you visit, we set a signed cookie holding a random device identifier — no name, email, or device fingerprint. This is what lets your check-ins show up again on your next visit.

Check-ins and habits. Your daily mood, an optional private note, and your habit-tracking history, tied to that identifier (or your account, if you've linked one).

Email address — only if you choose to add one. Linking an email (Settings → Account) lets your history follow you across devices via a sign-in link. It's used only for signing you in — we don't email you for any other reason.

Admin accounts. Volunteers and staff who manage content have a separate login with an email and a securely hashed password. This is entirely separate from public user data and is never used to identify or look up an individual check-in.

Anonymous usage counts. We log when features are used — a helpline number tapped, a guide opened — as a bare (what, when) pair with no identifier of any kind attached, ever. There is no record anywhere that connects one of these events to a person or a device.

What we don't collect: your real name, your location or GPS position, your IP address in any stored record, device fingerprints, or any advertising identifier. We don't use Google Analytics, Meta Pixel, or any similar tracking service.

How we use it

To run the check-in and habit tracker, show you your own history, send a sign-in link if you've linked an email, keep the service secure (rate limiting, abuse prevention), and understand — only in aggregate, never per person — which features are actually helping, so we can improve the ones that aren't.

We process your check-in data because it's necessary to provide the feature you're actively using; your email, only because you chose to give it to us for sign-in.

Who we share it with

We don't sell data, and we don't share it for marketing. A small number of infrastructure providers process data on our behalf, strictly to run the service. They see only what they need to do their job, and are contractually bound to keep it secure and not use it for any other purpose.

The WhatsApp emergency button opens a chat directly in your own WhatsApp app — we don't see or store that conversation, only an anonymous, identifier-free click count. The hospital/rehab/NGO directory shows contact details for third-party organisations, not personal information about you.

How long we keep it

Check-ins and habit logs are kept until you delete them — which you can do instantly and completely from Settings — or your account is otherwise removed. Anonymous usage counts, which never carried an identifier to begin with, are kept in aggregate to help us improve the service over time.

Your rights

Under the Nigeria Data Protection Act 2023, you have the right to know what we hold about you, correct it, restrict or object to how it's used, take a copy of it, and delete it — plus withdraw any consent you've given, at any time.

Delete everything, right now: Settings → “Delete all my data”. No form, no waiting period.

Access, correction, or a copy of your data: self-serve export is on the way; until it ships, email us at ralebcasvc@gmail.com and we'll help directly.

You can also lodge a complaint with the Nigeria Data Protection Commission (NDPC) if you believe your rights haven't been respected.

Younger members of our community

FreeMan is offered as a resource within a church youth ministry context, and we recognise some visitors may be under 18. We don't ask for a name, email, or any identifying detail by default, and the check-in note field is always optional — but we can't verify age, and we encourage parents, guardians, and pastoral leaders supporting younger members to be aware of how the app is used.

Security

Staff passwords are hashed, never stored in plain text. Traffic is encrypted in transit. Session cookies are signed so they can't be forged or replayed. Login and submission endpoints are rate-limited against abuse. Every admin action that changes data is logged with who, what, and when — end users are never subject to that logging. Our database provider encrypts data at rest and restricts network access to our application only, and we monitor our dependencies for known vulnerabilities.

International data transfers

Our hosting, database, and email providers operate global infrastructure and may process data on servers outside Nigeria as part of that. Where this happens, we rely on those providers' standard security and contractual safeguards for cross-border transfer.

Changes to this policy

If this policy changes in a way that meaningfully affects how we handle your data, we'll update the effective date above and, where the change is significant, make that clear on the site.

Contact

Questions about this policy or your data: ralebcasvc@gmail.com.