Privacy Policy
Effective date: 30 July 2026
Applies to: the Middle Ground iOS app
Middle Ground helps two people make shared decisions together. This policy describes exactly what the app collects, why, where it goes, and how to delete it. It describes what the software actually does — every item below corresponds to real behaviour in the app.
The short version
- We collect the minimum needed to show your requests to the person you paired with.
- We record how the app is used — that you created or answered a request, and when — so we
can understand and improve the product. We do not sell your data, run advertising, or use third-party trackers or ad SDKs.
- Your requests are visible to you, the person you paired with, **and to authorised Middle
Ground staff** who may access accounts for support, safety and debugging. Every such access is recorded in a tamper-evident log.
- We collect crash diagnostics so we can fix crashes. They contain no request content.
- You can report abusive content and leave a group at any time, from inside the app.
- You can delete your account, and everything tied to it, from inside the app.
What we collect, and why
| Data | Where it is stored | Why |
|---|---|---|
| Display name | users/{your-id} in Firebase Firestore | So the person you pair with sees a name instead of an ID |
| Account identifier | Attached to every document you create | Determines what you are allowed to read and write |
| Email address | Firebase Authentication | Only if you sign in with a method that provides one. With Sign in with Apple, you may choose Apple's private relay address and we never see your real one |
| Requests you create — title, optional note, optional proposed time, and the responses exchanged | requests/{id} in Firebase Firestore | This is the product: it is the content you and your partner are deciding on |
| Group membership — who you are paired with, and your invite code | relationships/{id} and invites/{code} | Connects two people so they can send each other requests |
| Notification token | user_tokens/{your-id} | Lets us send a push notification when your partner sends or answers a request. Only if you grant notification permission |
| Progress data — XP, streak, achievements | On your device, and mirrored to gamification/{your-id} | Powers the Activities tab, and means your progress survives changing phone |
| Usage events — that you signed up, paired, created a request, or responded, with a timestamp | events | Lets us understand how the product is actually used and where people get stuck. Records the action, not the words you wrote |
| Reports you file — which request you reported, who sent it, the reason, and your optional note | reports/{id} | So we can act on harassment and abuse. Readable only by staff |
| Crash diagnostics — stack trace, device model, OS version, and the app version at the time of a crash | Firebase Crashlytics | So we can find and fix crashes. Contains no request content and no message text |
We do not collect: contacts, photos, location, calendars, health data, advertising identifiers, or device fingerprints.
You can read the usage events recorded about you at any time — they are readable by your own account and by nobody else's.
Who can see your content
- You and the person you paired with. Requests are readable only by their participants, and
this is enforced on the server, not just in the app.
- Authorised Middle Ground staff. A small number of accounts hold an administrator
permission that allows access to account records and request content. It exists so we can provide support, investigate abuse or safety reports, and diagnose faults.
- The permission is granted server-side and cannot be obtained by modifying the app.
- **Every administrator access to an individual's data is written to an append-only audit
log** that administrators cannot edit or delete.
- We use it only for the reasons above — not for browsing, marketing, or curiosity.
- No other app user. Invite codes cannot be listed or enumerated — a code only works if
someone tells it to you. Notification tokens are not readable by any app user, including you.
- We do not sell, rent, or share your data with third parties for their own purposes.
If you would like to know whether your account has been accessed by staff, email us and we will tell you what the audit log shows.
Service providers
Middle Ground uses Google Firebase (Google LLC) for authentication, database storage, and push notification delivery. Firebase processes data on our behalf under Google's terms, and data is stored on Google's infrastructure, which may be located in the United States. Google's privacy information is at https://firebase.google.com/support/privacy.
Push notifications are delivered through Apple Push Notification service. If you sign in with Apple, Apple handles that authentication; see https://www.apple.com/legal/privacy/.
Crash diagnostics are collected by Firebase Crashlytics, also part of Google Firebase. It reports crashes only — stack traces and device/OS/app-version details. It does not see request titles, notes, or messages.
These are the only third parties involved. Usage events are recorded in our own Firestore database — there are no advertising, attribution, or third-party marketing-analytics SDKs in the app, and no usage data is shared with anyone else.
Reporting abuse, and leaving a group
If someone sends you something abusive, you can act on it from inside the app without contacting us first:
- Report it. Open the request, tap the menu, and choose Report this. We review every
report within 24 hours.
- Leave the group. Open Profile → Your groups → Leave. You immediately stop seeing each
other's requests and they can no longer send you any. If the invite code was yours, it is revoked at the same time so nobody can use it to reach you again.
Reports are kept even if you later delete your account, because a report is a record about somebody else's conduct and erasing it would remove the evidence of what you reported.
Sign in with Apple
If you sign in with Apple, we receive an account identifier and — only if you choose to share it — your name and an email address. Apple's Hide My Email option gives us a relay address instead of your real one, and the app works normally either way. When you delete your account we also revoke the Apple token issued to us, so the connection between your Apple ID and Middle Ground is severed.
Notifications
Notifications are optional. The app asks only when it is relevant, and declining does not limit any other feature. If you allow them, a device token is stored so notifications can be routed to your phone; you can turn them off at any time in Profile → Push Notifications, or in iOS Settings. Turning them off removes the token from your account.
Deleting your account and data
Open Profile → Delete Account. After you confirm:
- Your authentication account is deleted and, for Sign in with Apple, the token we hold is
revoked.
- The progress data stored on your device is removed with the app's data.
- Your profile, notification token, invite codes, group membership, progress data, usage
events, and requests that involved only you are erased from our database. Requests shared with your partner have your participation removed so they keep their own history.
The erasure happens while you are still signed in, as part of the deletion itself — not on a delay and not in a queue. An automated server-side job runs the same cleanup afterwards to catch anything the app could not reach (for example if your phone lost connectivity mid-way).
Deletion is permanent and cannot be undone. There is no waiting period and you do not need to contact us to do it.
The one thing not erased is any report you filed about someone else, for the reason given above.
Retention
Your content is kept until you delete it or delete your account, and is erased when you do. Usage events are additionally deleted automatically 90 days after they are recorded, whether or not you delete your account. We do not keep backups of deleted accounts for our own purposes.
Children
Middle Ground is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will remove it.
Your rights
Depending on where you live, you may have the right to access, correct, export, or erase your data, and to object to processing. The app's delete function satisfies erasure directly. For anything else, contact us and we will respond within 30 days.
Security
Access is enforced by server-side security rules, not just by the app: every read and write is checked against who you are and which conversations you belong to. Data is encrypted in transit, and at rest by our provider. No system is perfectly secure, but we do not store passwords ourselves and we collect as little as we can.
Changes
If this policy changes materially we will update the effective date above and note the change in the app's release notes.