The short version. Everi-Circle is a private app for small groups planning real-life events together. We collect your name, email and the things you post inside your circles. We do not collect your phone number, your address, your date of birth, your contacts or your location. We do not sell your data, we do not share it with advertisers, and there is no advertising or analytics tracking in the mobile app.
Money in Everi-Circle is a record, not a transaction. When your group splits a cost, the money moves through your own bank or wallet app — OPay, PalmPay, a bank transfer, Cash App, Venmo. Everi-Circle never touches the funds and takes no fee.
You can delete your account and everything in it from inside the app, or from our deletion page.
1. Who we are and who this covers
This policy explains how Everi-Circle ("we", "us") handles personal data in the Everi-Circle mobile app and at loan-c68b9.web.app. Everi-Circle is the data controller for that data.
Everi-Circle serves users in two primary markets, and this policy is written to satisfy both:
- Nigeria — the Nigeria Data Protection Act 2023 (NDPA) and the General Application and Implementation Directive 2025 (GAID) made under it, supervised by the Nigeria Data Protection Commission (NDPC).
- United States — including the California Consumer Privacy Act as amended (CCPA/CPRA), and the Children's Online Privacy Protection Act (COPPA).
- If you use Everi-Circle from the European Economic Area or the United Kingdom, the GDPR / UK GDPR rights in section 8 apply to you as well.
Where a law gives you a stronger right than this policy describes, the law wins.
2. What we collect
Everything below is either given to us by you, or created by you using the app. We do not buy personal data from anyone and we do not enrich your profile from outside sources.
| Data | Collected | Where it comes from |
|---|---|---|
| Name, email address, account ID, profile photo (if you add one) | Yes | You, at sign-up — directly, or through Sign in with Google or Sign in with Apple |
| Photos and videos you post to a circle or share as a moment | Yes | Your device, only for the items you choose to upload |
| Posts, comments, reactions, lists, events and RSVPs | Yes | You, as you use the app. Stored unencrypted so your circle can read them |
| Direct messages | Yes | You. Messages are encrypted on your device before they are sent. In rare cases where encryption cannot complete, a message is stored unencrypted so it is not lost — so we count messages as data we hold |
| Payment handles — the last 4 digits of a bank account and the bank name, or an OPay / PalmPay / Cash App / Venmo handle | Yes | You, only if you add a way for your group to pay you back. Encrypted with AES-256-GCM on our servers. We never ask for and never store a BVN, a full account number, a card number or a card CVV |
| Device push token | Yes | Your device, if you allow notifications. It identifies the device, not you |
| Crash reports and diagnostics | Yes | Automatically, when the app misbehaves. Includes your account ID and a stack trace — not your email, your messages or your content |
| Basic technical logs (IP address, timestamp) from our hosting and database provider | Yes | Automatically, for security and abuse prevention |
What we deliberately do not collect
| Data | Collected | Note |
|---|---|---|
| Phone number, home address, date of birth | No | Not requested and not stored |
| Your phone's contacts or address book | No | The app does not ask for contacts access. You invite people with a share link |
| Precise or approximate location | No | No location permission is requested and no location library is in the app |
| Microphone / audio recording | No | No recording feature exists |
| Advertising identifier (IDFA / GAID), ad or tracking profiles | No | No advertising SDK. On iOS this is why you never see a tracking permission prompt |
| Behavioural analytics in the mobile app | No | No analytics SDK is active in the iOS or Android app |
| Biometrics, health data, religious or political data, or any other sensitive category | No | The app has no field for any of it |
3. Why we use your data, and our lawful basis
Under NDPA section 25 and GDPR Article 6 we must have a lawful reason to process your data. Here is each purpose and the reason it rests on.
| What we do | Data used | Lawful basis |
|---|---|---|
| Create and secure your account; sign you in | Name, email, account ID, credentials held by our auth provider | Performance of a contract — you asked us to run an account for you |
| Show your posts, photos, comments, lists and events to the circles you joined | Your content and profile name/photo | Performance of a contract — this is the product |
| Deliver direct messages | Message content, sender and recipient IDs | Performance of a contract |
| Record who has paid toward a shared cost and show a payout destination | Amounts, who paid, payment handle | Performance of a contract. Adding a payment handle is optional and is your choice each time |
| Send you push notifications about your circles | Device push token | Consent — the OS permission prompt. Withdraw it in your device settings or in the app at any time |
| Diagnose crashes and keep the app working | Crash report, account ID, device model, OS version | Legitimate interest in a functioning, secure product (NDPA s.25(1)(f)) |
| Investigate reports, abuse, fraud and safety issues | Reported content, account IDs, technical logs | Legitimate interest in protecting our users and the service |
| Keep records we are legally required to keep | Money records, acceptance of these terms | Legal obligation (tax and financial record-keeping) |
We do not use your data for automated decision-making that produces legal or similarly significant effects, and we do not profile you for advertising.
4. Who we share it with
We do not sell your personal data, and we have never sold or shared it for cross-context behavioural advertising. We do not share your data with advertisers, data brokers or marketing networks.
Other members of a circle you join can see your display name, your profile photo and whatever you post in that circle. That is the point of a circle — but it also means you should only post there what you are happy for those people to see.
We use a small number of service providers ("data processors" under NDPA and GDPR) who handle data strictly on our instructions, under contract:
| Provider | What it does for us | What it receives |
|---|---|---|
| Google Firebase (Google LLC / Google Cloud) | Authentication, database, file storage, server functions, push delivery on Android, web hosting | Effectively all account and content data, encrypted in transit (TLS) and at rest |
| Sentry (Functional Software, Inc.) | Crash and error reporting so we can fix bugs | Your account ID and username only, plus the technical stack trace and device details. Sentry does not receive your email address, your messages, your photos or your payment handles — sending personal data by default is switched off |
| Expo push notification service (Expo, Inc.) | Relays push notifications to Apple's and Google's push networks | Your device push token and the notification text |
| Apple and Google | Sign in with Apple / Sign in with Google, app distribution, push transport | Only what is needed to authenticate you or deliver a notification. If you use Sign in with Apple's private relay, we never see your real email address |
We may also disclose data where the law requires it — a valid court order, a lawful request from the NDPC or another regulator, or where disclosure is necessary to protect someone's life or safety, or to defend a legal claim. If we are ever compelled to hand over your data we will tell you unless we are legally forbidden from doing so.
If Everi-Circle is ever acquired or merged, your data may transfer to the new owner. You will be told before that happens and this policy will continue to apply until you are given a new one.
5. Where your data is stored, and transfers out of Nigeria
Our database, file storage and server functions run on Google Cloud infrastructure, and our current data location is in the United States. Sentry and Expo also process data in the United States. This means that if you are in Nigeria, your personal data is transferred outside Nigeria; if you are in the EEA or the UK, it is transferred outside those areas.
We rely on the following safeguards for those transfers:
- NDPA sections 41–43: transfers are made to recipients bound by contract to protect your data to a standard materially similar to the NDPA, and are necessary for the performance of the contract we have with you (that is, running the app you asked us to run).
- GDPR Chapter V: our providers' data processing terms incorporate the European Commission's Standard Contractual Clauses, and Google Cloud additionally participates in the EU–US Data Privacy Framework.
You can ask us for details of the safeguards that apply to your data by writing to the contact in section 12.
6. How long we keep it
| Data | Kept for |
|---|---|
| Your profile, content, messages, memberships and settings | For as long as your account is open. Deleted when you delete your account |
| Photos and videos in storage | Same as above. Moments also expire on their own schedule inside the app |
| Payment handles (encrypted) | Until you remove them or delete your account |
| Device push token | Until you turn notifications off, sign out, or delete your account |
| Crash reports in Sentry | Up to 90 days, then automatically discarded |
| Technical logs (IP address, request logs) | Up to 30 days |
| Money records — the record that a payment toward a shared cost was made, and by whom | 7 years after the record is created, because financial and tax record-keeping law requires it. This is the one category we cannot delete on request; NDPA s.34(1)(c) and GDPR Art. 17(3)(b) both allow retention where a legal obligation applies |
| Your acceptance of these terms and this policy (date, version) | 7 years, as proof of consent and agreement |
| Backups | Deleted data can persist in encrypted backups for up to 30 days after deletion, then rolls off automatically |
7. Children
You must be at least 13 years old to use Everi-Circle. We check your age at sign-up and we do not knowingly create accounts for anyone under 13.
- Nigeria: the NDPA treats anyone under 18 as a child. If you are under 18 and in Nigeria, a parent or guardian must consent to your use of Everi-Circle before you sign up, and may contact us at any time to see, correct or delete your data.
- United States: the app is not directed to children under 13 and we do not knowingly collect their data (COPPA).
- Money features are for adults. You must be 18 or older to add a payment handle or take part in a shared-cost record.
If you believe a child has an account they should not have, write to privacy@evericircle.com and we will remove the account and its data.
8. Your rights
These rights apply to everyone who uses Everi-Circle, regardless of where you live. The column tells you which law grants each right in your market.
| Right | What it means | Granted by |
|---|---|---|
| Be told | To know what we hold and why — this policy is how we do that | NDPA s.27 · GDPR Arts. 13–14 · CCPA §1798.100 |
| Access | To get a copy of your personal data | NDPA s.34(1)(a) · GDPR Art. 15 · CCPA §1798.110 |
| Correct | To fix data that is wrong. Most of it you can edit yourself in the app | NDPA s.34(1)(b) · GDPR Art. 16 · CCPA §1798.106 |
| Delete | To have your data erased, except records under a legal hold (section 6) | NDPA s.34(1)(c) · GDPR Art. 17 · CCPA §1798.105 |
| Restrict | To have us pause processing while a dispute is resolved | NDPA s.37 · GDPR Art. 18 |
| Object | To object to processing based on legitimate interest | NDPA s.36 · GDPR Art. 21 |
| Portability | To receive your data in a structured, machine-readable format | NDPA s.38 · GDPR Art. 20 |
| Withdraw consent | To turn off anything based on consent (such as notifications) without affecting what came before | NDPA s.26(3) · GDPR Art. 7(3) |
| No sale, no discrimination | We do not sell or share your data for advertising, so there is nothing to opt out of. You will never get a worse service for exercising a right | CCPA §§1798.120, 1798.125 |
| Complain | To take the matter to a regulator if we get it wrong | NDPA s.46 · GDPR Art. 77 |
How to use a right
- Delete your account: in the app, go to Settings → Delete account. If you cannot open the app, use the deletion request page.
- Correct your data: most of it is editable in Settings → Profile.
- Anything else — access, a copy of your data, restriction, objection, or a question: email privacy@evericircle.com from the address on your account, and say which right you are using.
We answer within 30 days. If a request is unusually complex we may take up to 30 days more, and we will tell you why before the first 30 days are up. We do not charge for this. We may ask you to confirm your identity — normally by replying from your account email — so that we do not hand your data to someone else. In California, an authorised agent may act for you with written permission.
If you are not satisfied
Nigeria. You may complain to the Nigeria Data Protection Commission (NDPC) — ndpc.gov.ng, No. 5 Ajayi Crowther Street, Asokoro, Abuja. You can complain to the NDPC whether or not you have contacted us first, but we would rather have the chance to fix it.
EEA / UK. You may complain to your national supervisory authority, or to the UK Information Commissioner's Office (ico.org.uk).
California. You may contact the California Privacy Protection Agency or the California Attorney General.
9. Security
- All traffic between the app and our servers uses TLS. The iOS app additionally refuses unencrypted connections at the operating-system level.
- Data at rest in our database and file storage is encrypted by the platform (AES-256).
- Payment handles get a second layer: they are encrypted with AES-256-GCM on our servers with a key held in server configuration, and each encrypted record is cryptographically bound to the specific payment request it belongs to, so it cannot be lifted and reused elsewhere. Only the last 4 digits and the bank name are ever stored readable.
- Direct messages are encrypted on your device using NaCl public-key cryptography before they leave it. Where encryption cannot complete, the message is stored unencrypted rather than lost — so please do not treat DMs as a channel for secrets.
- Access to your data is enforced by server-side security rules: content in a circle is readable only by members of that circle, and money records only by the people involved.
- Staff access to production data is limited to what is needed to run the service and to answer your requests.
No system is perfectly secure. If a personal data breach occurs, we will notify the NDPC within 72 hours of becoming aware of it as NDPA section 40 requires (and the relevant EEA/UK authority under GDPR Art. 33), and we will notify you directly and without undue delay where the breach is likely to result in a high risk to you.
10. Payments — an important clarification
Everi-Circle does not process payments, does not hold funds, does not operate a wallet, and does not charge a fee. When your circle splits a cost, one member records the request and the others pay through their own bank or wallet app — OPay, PalmPay, a bank transfer, Cash App, Venmo — outside Everi-Circle. What we store is the record: who owes what, who says they have paid, and who confirmed it.
That means we never see or store card numbers, CVVs, full bank account numbers, BVNs or wallet passwords. Your relationship with your bank or wallet provider is governed by their terms and their privacy policy, not ours.
11. Changes to this policy
If we change this policy we will update the effective date at the top. For any change that materially affects your rights or how we use your data, we will tell you in the app or by email before it takes effect, and where the law requires consent we will ask for it again rather than assume it.
12. Contact us
Data protection and privacy requests: privacy@evericircle.com
General support: support@evericircle.com
Nigerian users may use the same address for any NDPA request — access, correction, erasure, portability, objection, or a complaint. Write "NDPA request" in the subject line and we will route it to our data protection contact. Nigerian requests are handled under Nigerian law and you keep your right to escalate to the NDPC.
We reply to every data protection request within 30 days.