Privacy Policy
Last Updated: 20 July 2026
Effective date: 20 July 2026
1. Who we are
Flatable helps people find flatmates and shared flats in Switzerland and Europe. This policy explains what personal data we collect when you use the Flatable app (iOS and Android), the Flatable web app (app.flatable.ch), and our website (flatable.ch), why we collect it, and what rights you have.
The data controller is:
Flatable GmbH
Eichstrasse 19A, 6330 Cham, Switzerland
Email: support@flatable.ch
We process personal data under the Swiss Federal Act on Data Protection (revFADP) and, for users in the EU/EEA, the EU General Data Protection Regulation (GDPR). Data protection contact: support@flatable.ch.
2. The short version
- We collect the data you give us to run a flatmate-matching service: your account, your profile, your listings, your photos and optional application videos, and your chats.
- We use PostHog (hosted in the EU) for first-party product analytics. In the EU/EEA it is off until you say yes. In Switzerland and elsewhere it is on by default and you can switch it off anytime in Settings.
- We do not sell your data. We do not share it with third parties for cross-app advertising. We never use your device's advertising identifier.
- You can delete your account in the app at any time.
3. What data we collect
3.1 Account data
When you create an account we collect your email address, your name, and a password (stored only as a secure hash). If you sign in with Google, Facebook, or Apple, we receive your email address and basic account details from that provider instead of a password. We also store your language, your chosen role (flatmate seeker or flat), and account status timestamps.
3.2 Profile data
To match you with flats or flatmates, you build a profile. Depending on your answers this can include your birth year (to confirm you are at least 16 and show your age), gender, occupation, a short bio, lifestyle preferences, and profile photos. If you apply to a flat with a video application, we store the short video (and any voice recording) you choose to record. Photos, videos, and voice recordings are always optional and always uploaded by you.
3.3 Listing data
If you list a room or flat, we collect the listing details: address and map location, rent, size, photos, description, move-in dates, and your preferences for future flatmates. The address and location are shown to other users as part of the listing.
3.4 Messages
When you chat with other users, we store the messages you send and receive, including any photos and video applications shared in chat, so we can deliver them and show your conversation history.
3.5 Device and technical data
We collect a push notification token for your device (via Firebase Cloud Messaging) so we can send you notifications, plus basic technical information such as app version, platform (iOS, Android, web), device model, language, and theme setting. Our servers also keep standard technical logs (such as request logs) for security and troubleshooting.
3.6 Location data
If you allow location access, we use your device location to center the map and to power location-based search (for example, searching for flats within an area). Listing locations come from the address the lister enters. You can use Flatable without granting location access; location features then rely on addresses you type.
3.7 Usage and analytics data (PostHog)
With analytics enabled (see section 5), we collect product analytics events (for example: screen views, taps on core actions, signup and matching funnel steps) and masked session replays. Event data is stripped of personal content before it leaves your device: no message text, names, addresses, phone numbers, or bios are included in analytics events. The only personal identifiers attached to your analytics profile are your email address and your internal user ID, so we can debug issues affecting your account. Session replays mask all text and all images on the screen.
3.8 Purchases
If you buy video credits, the purchase runs entirely through Apple's In-App Purchase system (and Google Play billing on Android, once available there). We never see or store your card details. We store a transaction record (product, price, store receipt reference) to credit your account and for bookkeeping.
3.9 Support and contact data
If you contact us (support requests, contact forms, email), we keep the correspondence so we can respond and improve support.
3.10 Safety data
If you block or report another user, we store the block or report, including the reason you give, to protect our community.
4. Why we use your data, and on what legal basis
Under the GDPR, every use of personal data needs a legal basis. Under Swiss law (revFADP) the same principles of transparency and proportionality apply:
- Create and run your account, log you in — account data. Basis: contract (Art. 6(1)(b)).
- Matching: show your profile to relevant flats, show you relevant flats and flatmates — profile data, listing data, location and search filters. Basis: contract (Art. 6(1)(b)).
- Host and show your listings — listing data including address. Basis: contract (Art. 6(1)(b)).
- Deliver chat and video applications — messages, videos. Basis: contract (Art. 6(1)(b)).
- Transactional push notifications (new match, new message, viewing reminders) — push token, account data. Basis: contract (Art. 6(1)(b)); you control categories in Settings.
- Marketing or offer notifications — push token. Basis: consent (Art. 6(1)(a)); off by default, opt-in in Settings.
- Transactional emails (verification, password reset) — email address. Basis: contract (Art. 6(1)(b)).
- Product analytics and session replay (PostHog) — usage data, email, user ID. Basis: EU/EEA consent (Art. 6(1)(a)); Switzerland and elsewhere legitimate interest with an always-available opt-out in Settings.
- Measuring app installs from our ads (TikTok, Meta) — aggregate install and signup events, no advertising ID. Basis: legitimate interest (Art. 6(1)(f)): measuring our marketing without identifying you.
- Crash and error diagnostics — diagnostic events. Basis: legitimate interest (Art. 6(1)(f)): keeping the app working.
- Processing purchases of video credits — purchase records. Basis: contract (Art. 6(1)(b)); bookkeeping retention: legal obligation (Art. 6(1)(c)).
- Blocks, reports, and abuse prevention — safety data. Basis: legitimate interest (Art. 6(1)(f)): keeping users safe; legal obligation where applicable.
- Responding to support requests — support data. Basis: contract and legitimate interest.
5. Analytics with PostHog (EU)
We use PostHog, hosted on PostHog's EU cloud (data stored in the EU), as our only product analytics tool. What this looks like in practice:
- First-party only. Analytics data is used by us, for our product. It is never shared with or linked to third parties for cross-app advertising.
- EU/EEA users: opt-in. If your device region is in the EU/EEA, analytics is off by default. The analytics software does not even start until you actively allow it in the consent prompt. You can change your mind anytime in Settings.
- Switzerland and everywhere else: opt-out. Analytics is on by default and you can turn it off anytime under Settings, Analytics. The change takes effect immediately.
- Minimal identity. Your analytics profile carries your email address and internal user ID and nothing else personal. Analytics events are automatically stripped of personal content (names, message text, addresses, phone numbers, bios) before leaving your device.
- Masked session replay. To find and fix usability problems we record a small sample of app sessions (about 1 in 10). All text and all images in these recordings are masked, so we see where users tap and get stuck, not what they read or write. Replays only happen when analytics is enabled for you.
- Error tracking. App crashes and errors are reported so we can fix them.
To opt out at any time: open the app, go to Settings, and switch off Analytics.
6. Install attribution (TikTok and Meta)
We advertise Flatable on TikTok and Meta platforms. To know whether those ads work, the app includes the TikTok Business SDK and the Meta SDK, configured in the most privacy-preserving mode the platforms offer:
- Attribution runs through Apple's SKAdNetwork and comparable aggregate mechanisms. These report campaign-level results (for example "campaign X led to Y installs") without identifying you.
- We never read or share your device's advertising identifier (IDFA on iOS, advertising ID on Android). On Android, the advertising ID permission is actively removed from the app. On iOS, we never show the App Tracking Transparency prompt because we do not track.
- We do not send your name, email, phone number, or any profile content to TikTok or Meta for attribution. The events sent are limited to aggregate app milestones such as "app installed", "registration completed", "login", and purchase events with an amount and currency, without your identity attached.
- The Meta SDK also logs basic app-launch events automatically for the same aggregate measurement purpose.
This is measurement of our own advertising, not tracking of you across other companies' apps.
7. Who receives your data (processors and recipients)
We use a small number of service providers to run Flatable. They process data on our behalf under data processing agreements:
- DigitalOcean LLC — servers hosting our application and database, and object storage for photos, videos, and voice recordings. Hosted in Frankfurt, Germany (DigitalOcean is a US company; see section 8).
- PostHog (EU Cloud) — product analytics, session replay, error tracking (see section 5). EU (Frankfurt region).
- Google (Firebase) — push notifications (Firebase Cloud Messaging) and sign in with Google. EU/US.
- Google Maps — maps display and address geocoding. EU/US.
- Apple — sign in with Apple, In-App Purchases, push delivery (APNs). EU/US.
- Meta Platforms — sign in with Facebook; aggregate install attribution (see section 6). US.
- TikTok — aggregate install attribution (see section 6).
- Amazon Web Services (SES) — sending transactional emails (verification, password reset). EU/US.
Other users see what you publish: your profile as shown in matching, your listings, and the messages you send in chats. We may also disclose data if the law requires it, or to protect our users (for example when investigating abuse reports).
We do not sell personal data. We do not share personal data with data brokers.
8. International transfers
Our primary data storage is with providers in Europe. Some of our providers (DigitalOcean, Google, Apple, Meta, TikTok, Amazon) are headquartered in the United States or may process limited data outside Switzerland and the EU/EEA. Where that happens, we rely on recognized transfer safeguards: the Swiss-US and EU-US Data Privacy Frameworks where the provider is certified, and Standard Contractual Clauses otherwise.
9. How long we keep your data
- Account, profile, listings, messages: as long as your account exists.
- Account deletion: you can delete your account anytime in the app (Settings, Delete account) or by emailing support@flatable.ch. Your account is deactivated immediately and is no longer visible to other users. We then erase your personal data upon request within 30 days.
- Analytics data (PostHog): analytics events are retained for up to 12 months; masked session replays are automatically deleted after 30 days.
- Purchase records: kept for 10 years to meet Swiss bookkeeping obligations.
- Support correspondence: up to 24 months after the case closes.
- Server logs: around 30 days.
- Blocks and reports: kept while relevant for the safety of our community, where necessary also after account deletion.
10. Your rights
You have the right to:
- Access the personal data we hold about you and get a copy.
- Rectify data that is wrong (most profile data you can edit directly in the app).
- Erase your data (delete your account in the app, or ask us).
- Receive your data in a portable, machine-readable format (data portability).
- Object to processing based on legitimate interest, including analytics (use the Settings toggle) and attribution measurement.
- Withdraw consent at any time where processing is based on consent (for example EU/EEA analytics), without affecting past processing.
- Restrict processing in the situations GDPR Art. 18 provides.
To exercise any right, email support@flatable.ch. We answer within 30 days. We may ask you to verify your identity first.
You can also complain to a supervisory authority: in Switzerland, the Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch); in the EU/EEA, your national data protection authority.
11. Children
Flatable is for users aged 16 and older. We ask for your birth year during profile creation and do not accept profiles of users under 16. We do not knowingly collect data from children under 16; if you believe a child is using Flatable, contact us at support@flatable.ch and we will remove the account.
12. Security
We protect your data with technical and organizational measures, including access controls, secured infrastructure, password hashing, secure credential storage on your device, and masking of analytics recordings. Payment details never touch our servers. We continuously improve our security measures.
If a data breach affects you, we will notify you and the competent authority as the law requires.
13. Cookies and local storage on our websites
- flatable.ch (our marketing website) is hosted on Webflow and uses only the cookies needed to serve the site.
- app.flatable.ch (the Flatable web app) uses browser local storage to keep you signed in and to remember preferences such as language and theme. This storage is necessary for the app to work and stays on your device. Analytics in the web app follows the same consent rules as in the mobile app (section 5).
14. Changes to this policy
We will update this policy when our data practices change. We will post the new version here with a new date and, for significant changes, inform you in the app or by email.
15. Contact
Flatable GmbH
Eichstrasse 19A, 6330 Cham, Switzerland
support@flatable.ch
Find your new home on Flatable.

