Marilo Privacy Policy
This Privacy Policy explains how Marilo (“Marilo,” “we,” “us,” or “our”) collects, uses, stores, and shares information when you use the Marilo mobile application on Android or iOS.
1. Information We Collect
Account and profile information
When you create or use a Marilo account, we may process information such as your user identifier, email address, username, profile name, biography, profile image, authentication status, group memberships, roles, and account settings.
Signing in with Google or Apple
You can create an account and sign in with an email address and a password, with Google, or, on iOS, with Apple. When you choose Google or Apple, that provider confirms your identity and shares with Marilo your email address, a provider account identifier and, if you allow it, your name. Marilo uses the name only to suggest your profile name and username, which you can change before your account is created. If you use Apple's “Hide My Email”, Marilo receives the relay address Apple creates instead of your real one. Marilo does not receive your Google or Apple password.
An account created with Google or Apple can optionally be given a password later, from the Profile tab, so that you can also sign in with your email address. Before a password is added, and before such an account is deleted, Marilo asks for your phone's own screen lock (fingerprint, face or PIN) and for your Google or Apple account again. The screen-lock check happens entirely on your device: Marilo never receives your fingerprint, face data or PIN, only whether the check succeeded.
Precise location information
Marilo processes precise geographic location information, including latitude, longitude, direction of travel, update time, sharing status, and whether the application is active, in the background, or offline.
Motion and activity information
To help manage battery usage while you are sharing your location, Marilo may process on-device motion and activity information, such as whether you appear to be stationary, walking, cycling, or travelling in a vehicle. Only the resulting activity state is processed for this purpose — Marilo does not process or store raw accelerometer, gyroscope, or other raw sensor data.
User-generated content
We process content that you create or submit through Marilo, including group messages, map targets, action pings, responses, live-location trails left by a shared destination, saved routes, group details, profile images, and group images.
Reports and blocking
If you report a member or a message, we process the report: your user identifier, the reported member and message, a copy of the reported content, the reason you selected, any note you add, and the time. If you block a member, we process the fact that you blocked them, so that their content and notifications can be withheld from you. See section 7.
Presence information
So that group members can tell who is reachable, Marilo processes whether your app currently holds a connection, whether it is on screen, and the last time you were using it. Your online status and the time you were last using the app may be visible to other Marilo users who know your account, for example your group members and friends.
Device and notification information
Marilo may process device notification tokens and related technical identifiers to deliver push notifications and maintain application functionality. On iOS these tokens are issued by Apple Push Notification service; on Android, by Firebase Cloud Messaging.
Diagnostics and usage measurement
Marilo uses Firebase Crashlytics and Firebase Analytics. If the application crashes, a crash report may be sent containing the error, a stack trace, the device model, the operating-system version, and an installation identifier. Analytics processes aggregated usage events and a pseudonymous application-instance identifier, and may derive a general location, such as your country or city, from your device's IP address. Neither of these is used to collect the content of your messages, and neither receives the precise location Marilo collects for its group features.
Language preference
Marilo stores the display language you select so that notifications sent from our backend can be delivered in that language.
Purchase and subscription information
If you purchase an optional subscription, we process a subscription status linked to your user identifier, together with related purchase events. Payment details are handled by Google Play or the Apple App Store, depending on where you installed Marilo, and are not collected by Marilo.
Local application data
Marilo may store application preferences, session-related settings, selected map settings, and cached images locally on your device.
2. Live Location Sharing
Marilo's primary function is to allow users in the same group to view one another's live locations on a map.
When live location sharing is active, Marilo may send your precise location to Firebase Realtime Database. Your live location may then be displayed to authorized members of the group in which you are participating.
Live location records may include:
- your Marilo user identifier;
- latitude and longitude;
- direction or heading;
- the time of the latest update;
- your location-sharing status;
- the current application state; and
- your current motion or activity status (for example, stationary, walking, or in a vehicle).
Live location information is used to provide Marilo's group map, navigation, coordination, safety, target, and location-sharing functions. Precise location collected for these features is not used to target advertising and is not shared with advertising partners.
3. Background Location
If you start or participate in an active group map session, Marilo may continue processing your location after the application is minimized or is no longer visible on the screen.
On Android
Marilo uses a foreground location service for this purpose. An ongoing system notification is displayed while that service is active.
On iOS
Background location requires the location permission you grant to Marilo in iOS Settings. With “While Using the App”, iOS shows a blue indicator in the status bar while Marilo is using your location in the background; with “Always”, sharing can also resume after the system has stopped the app. Turning off Background App Refresh, or switching on Low Power Mode, may reduce or stop background updates. Marilo shows the state of these settings under Profile → Battery and background; it cannot change them for you.
Marilo may reduce the frequency at which location updates are sent or stored while the application is in the background. However, location processing may continue so that members of your active group can still view your current position.
Marilo may use the motion and activity information described in section 1 to help determine how frequently location updates are sent while the application is in the background — for example, sending updates less often while you appear to be stationary, and more often while you appear to be moving or approaching a shared destination.
Under normal operating conditions, location sharing is intended to stop when the active tracking session ends, the relevant map session is closed, the required permissions are withdrawn, or the operating system terminates the tracking process. Device and operating-system behavior may affect exactly when a background process stops.
4. Optional Location History and Trails
Location history
Location history is disabled by default. A user may voluntarily enable it from the relevant Group Info settings.
When location history is enabled, Marilo stores selected precise location points so that the user can review recent movement history on the map.
Stored location-history records may contain latitude, longitude, and timestamps. Marilo is designed to retain these records for up to seven days. A scheduled backend process is used to remove records older than the retention period.
Turning off location history prevents new historical points from being recorded. It may not immediately remove location-history records that were already stored.
Marilo does not currently provide a separate in-app control for manually deleting individual location-history records before the automatic retention period ends. Deleting your account removes location-history records associated with it.
Live-location trails
When you share a live destination with a group (a “follow me” target), Marilo records the path you take while that target is active, so the group can see where you went. The trail belongs to that target: it is removed when the target expires, when it is completed, or when it is deleted. A target lasts at most 24 hours.
Saved routes
A route you save from your own history is stored until you delete it, and is visible to the members you shared it with.
5. Groups and Social Features
Marilo processes information about groups, group administrators, supervisors, members, friendships, invitations, and participation status to operate its group-based features.
Information displayed inside a group may include usernames, profile images, online status and the time you were last using the app, live location, targets, action pings, and messages.
You should join groups only with people you trust. Group members may be able to view information that you share within that group.
6. Chats, Targets, and Action Pings
Marilo allows users to communicate while using the group map. Messages and related metadata may be stored in Firebase Realtime Database.
Users may also create targets or action pings on the map. These records may include the creator's user identifier, geographic coordinates, assigned users, responders, completion status, timestamps, and related instructions.
This information is processed to coordinate group activity, provide navigation, and show group members relevant map events.
Messages and map events are not end-to-end encrypted. They are transmitted over encrypted connections and are processed by our backend services in order to deliver them and to generate the related notifications.
7. Reporting, Blocking, and Moderation
Marilo has zero tolerance for objectionable content or abusive members. Reporting and blocking are available inside the application, and both involve processing personal information.
Reporting
You can report a member from their profile, and a single message by pressing and holding it in the chat. A report contains your user identifier, the reported member, the reported message and a copy of its content at the time you reported it, the group it came from, the reason you selected, any note you wrote, and the time of the report.
Reports are stored so that they can be reviewed by us. They cannot be read, edited, or withdrawn from inside the application by anyone, including the member who filed them — that restriction exists so that a report can never be traced back to its author by another user. We review reports as soon as possible, remove content that breaks our rules, and may suspend or remove the accounts responsible.
Blocking
You can block a member from their profile. Blocking is recorded in two places: in your own account data, which is what the app reads to hide that member's messages and pings from you, and in a server-side record attached to the blocked member, which is what our notification service reads so that their messages no longer reach your phone. That server-side record cannot be read by any user, so a blocked member is not told who blocked them.
Blocking hides content. It does not hide a member's location on the map: Marilo is used for safety and coordination in the field, and a group that cannot see where somebody is has a more serious problem than an unwanted message. You can see and undo your blocks under Profile → Blocked users, and you can leave a group at any time.
8. Third-Party Services
Marilo uses service providers that process information on our behalf or provide essential application functionality.
Google Firebase
Marilo may use Firebase Authentication, Cloud Firestore, Firebase Realtime Database, Cloud Storage for Firebase, Firebase Cloud Messaging, Firebase Remote Config, Firebase App Check, Firebase Crashlytics, Firebase Analytics, and Cloud Functions for Firebase.
These services may process account information, user identifiers, precise location, messages, group data, notification tokens, uploaded images, crash diagnostics, and related technical data.
Google Maps Platform
Marilo uses Google Maps services to display maps, locations, targets, routes, and group activity. Google may process technical or map-related information in accordance with its own privacy terms.
When you search for a place, the text you type, your language and region, and your most recent position, if your device already has one, are sent to Google Places so that nearby results are listed first. Marilo does not store your searches, whether for places or for other users by username.
Google AdMob
Marilo includes the Google AdMob advertising framework. When advertising is enabled, AdMob may process advertising identifiers, your IP address (from which a general location can be estimated), your interactions with the app and its ads, and diagnostic information about the app's performance, in order to deliver and measure ads and to prevent fraud, in accordance with Google's own privacy terms. See section 16 for details.
RevenueCat
Subscription status is managed using RevenueCat. RevenueCat processes your user identifier and purchase events in order to determine whether a subscription is active. Payment details are handled by the app store you purchased through and are not passed to RevenueCat by Marilo.
Google Sign-In and Sign in with Apple
If you sign in with Google or Apple, Google or Apple authenticates you and passes the result to Firebase Authentication, which Marilo uses to manage accounts. Google and Apple process your sign-in under their own privacy policies. When you delete a Marilo account created with Apple, Marilo also asks Apple to revoke the authorization you gave it.
Apple and Google app-store services
On iOS, Marilo relies on Apple Push Notification service to deliver notifications, and on Apple's App Store and StoreKit for subscriptions. On Android, notifications are delivered through Firebase Cloud Messaging and subscriptions are sold and billed by Google Play. Apple and Google process this information under their own privacy policies.
Device operating-system services
Marilo relies on Android and iOS location, notification, networking, and background-processing services. Your device settings and permissions determine whether these services are available.
9. How We Use Information
We use information to:
- create and manage Marilo accounts;
- provide live and background group location sharing;
- manage battery usage while location sharing is active;
- display optional location history, trails, and saved routes;
- operate group chat, target, ping, and navigation features;
- deliver service and activity notifications in your chosen language;
- maintain account, group, and membership functionality;
- review reports, enforce our rules, and honour the blocks you set;
- determine whether an optional subscription is active and apply the corresponding feature limits;
- display advertising where it is enabled;
- diagnose crashes and understand which features are used;
- protect the reliability and security of the service;
- detect and resolve technical issues; and
- comply with legal obligations.
11. Data Retention
Different categories of data may have different retention periods depending on operational, legal, security, and service requirements.
- Location-history records are designed to be retained for up to seven days.
- A live-location trail is removed with the shared destination it belongs to, which lasts at most 24 hours.
- Live location records may remain stored as the latest known location until they are overwritten or removed.
- Action pings are removed about 24 hours after they expire.
- In-app notifications are removed after about 30 days.
- Account information, group records, messages, targets, saved routes, and uploaded images may be retained while the account or related service data remains active.
- Reports are retained after review, and after the reported account is removed, so that repeated abuse can be recognised and so that we can answer questions about an enforcement decision.
- Notification tokens may be retained until replaced, invalidated, or removed.
- Local preferences and cached files may remain on the device until the application data is cleared or the application is uninstalled.
You can delete your account and its associated data at any time — see section 14.
12. Security
We use technical and organizational safeguards intended to protect information against unauthorized access, loss, misuse, or alteration. Information transmitted between Marilo and our backend services is protected using encrypted network connections, and access to stored data is restricted by server-side security rules.
No application, network, database, or storage system can be guaranteed to be completely secure. Users should protect their account credentials and should not share sensitive information with groups they do not trust.
13. Your Choices and Controls
You may:
- grant or deny device location permissions;
- disable location permissions from device settings;
- grant or deny the optional motion and activity permission, from within the app or from device settings — declining it does not prevent you from using Marilo, and location sharing continues without it;
- enable or disable optional location history;
- leave groups or stop participating in map sessions;
- report content or a member from inside the app;
- block a member, and undo that from Profile → Blocked users;
- change permitted profile information;
- change the application display language;
- control notification permissions through device settings;
- delete your account from within the application; and
- contact us regarding access, correction, or deletion requests.
Disabling a permission may prevent related Marilo features from functioning correctly.
14. Account Deletion
You can delete your Marilo account yourself, from inside the application: open your Profile tab, choose Delete Account, confirm, and verify that you are the account owner — with your password, or, for an account without one, with your phone's screen lock and your Google or Apple account.
Deleting your account removes or anonymizes account-related data under our control, including profile information, notification tokens, group membership records, live-location records, trails, stored location-history records, saved routes you own, friendship records, your block list, and the record of who had blocked you. Some information may be retained where required for security, legal compliance, moderation records (section 11), or the integrity of shared group activity.
If you cannot sign in, see the account deletion request page for the email-based alternative.
15. Children's Privacy
Marilo is not directed to children under the minimum age required to consent to data processing in their jurisdiction. We do not knowingly seek to collect personal information from children in violation of applicable law.
A parent or guardian who believes that a child has provided personal information without appropriate authorization may contact us. Our approach to child safety, including how to report it, is described on the child safety standards page.
16. Advertising and In-App Purchases
Optional subscription
Marilo is free to use. An optional subscription raises the limits that apply to groups, members, destinations, and daily action pings. Subscriptions are sold and billed by Google Play or the Apple App Store, depending on where you installed Marilo. Subscription status is managed through RevenueCat, which receives your user identifier and purchase events. Marilo does not receive or store your payment details.
Advertising
Marilo includes the Google AdMob framework so that advertising can be shown to users who do not have an active subscription. Where advertising is enabled, AdMob may process advertising identifiers, your IP address (from which a general location can be estimated), your interactions with the app and its ads, and diagnostic information to deliver and measure ads and to prevent fraud, in accordance with Google's privacy terms.
On iOS, personalized advertising requires your permission through Apple's App Tracking Transparency prompt. If that permission is not given, or is not requested, advertising is non-personalized. In the European Economic Area, the United Kingdom, and Switzerland, your advertising choices are collected through a consent form; you can reopen it from Profile → Privacy options.
The precise location that Marilo collects for its group features is not used to target advertising and is not shared with advertising partners.
Advertising and subscription availability may be enabled or disabled remotely and may not be active in every version or region.
17. Changes to This Privacy Policy
We may update this Privacy Policy when Marilo's features, service providers, legal obligations, or information-handling practices change.
The updated version will be published on this page with a revised “Last updated” date. Material changes may also be communicated within the application where appropriate.
18. Contact
For questions, privacy requests, or concerns regarding Marilo, contact:
Application: Marilo
Developer: Mehmet Kayaaslan
Email:
mehmetkayaaslan@outlook.com