Privacy Policy
Handsly is a private, invitation-only network for professional introductions. This page explains, in plain language, what data we process, why, and the choices you keep at every step.
Last updated: 10 June 2026
In one sentence
We never sell your data, your address book is never shown to other members, and an intermediary stays hidden until they consent.
The rest of this page breaks down those principles, point by point, so you know exactly what happens with your information.
Who is the data controller
The data controller is the company Fibroweb (https://fibroweb.fr), which publishes and operates the Handsly app. For any question about your personal data, you can write to app@handsly.io.
Data we collect
We only collect what is needed to run the service. Specifically:
Your account
- Your name and email address.
- Your password, stored only as a bcrypt hash (never in clear text).
- An optional profile: job title, company, city, phone, profile photo, spoken languages, LinkedIn URL.
- Your intentions and topics of interest, along with your privacy settings.
Your relationships and introductions
- Your imported contacts, if you consent: names are kept to enable private matching, while emails and phone numbers are transformed into irreversible SHA-256 hashes and are never stored in clear text.
- The connections you declare.
- Introduction requests and the messages attached to them.
- Your notifications.
Technical data
- A push notification token and a device identifier.
- Minimal server logs (including your IP address).
- Optional, pseudonymized product-analytics events, only if analytics is enabled.
How we use it
Your data is used solely to run and secure Handsly:
- Create and manage your account, and authenticate you.
- Compute introduction paths and surface relevant introductions.
- Route introduction requests and their messages.
- Send you notifications useful to the service.
- Keep the service secure and prevent fraud and abuse.
- Improve the product, only from pseudonymized analytics if you have enabled analytics.
Privacy by default (the core model)
Handsly is built so your relationships stay private. That is what makes the service both useful and discreet:
- Your address book and relationships are never shown to other members, nor published.
- The relationship graph is computed server-side: only derived distances (for example, "2 handshakes away") are returned.
- An intermediary's identity stays hidden until they accept the introduction.
- Your contacts' emails and phone numbers are kept only as irreversible hashes, never in clear text.
Legal bases
Under the GDPR, we process your data on the following bases:
- Performance of the contract: to provide the service you use.
- Consent: for access to your contacts, notifications and analytics. You can withdraw it at any time.
- Legitimate interest: for security and fraud prevention.
Sharing with third parties (subprocessors)
We never sell or rent your data. We rely on a small number of subprocessors, strictly to operate the service:
- The server and database host: a VPS in Europe and MongoDB Atlas.
- The email provider: SMTP via OVH.
- Expo: for delivering push notifications.
- An optional analytics provider (for example PostHog), only if it is enabled.
- Anthropic: only if you use the optional AI message assistant, and only the text of the message you choose to improve.
Each of these providers acts on our instructions and does not use your data for its own purposes.
Retention and deletion
We keep your data while your account is active.
You can delete your account directly in the app (Profile, then "delete my account"). This permanently erases your profile, connections, requests, invitations and notifications.
Minimal technical data may persist briefly in backups and logs before it is purged.
Security
We protect your data with strong technical measures:
- Passwords protected with bcrypt hashing.
- Contacts protected with SHA-256 hashing.
- Authentication tokens stored in the device secure vault (iOS Keychain / Android Keystore).
- HTTPS everywhere, security headers, rate limiting and strict input validation.
Your rights
The GDPR grants you rights over your data: access, rectification, erasure, portability, restriction and objection.
You can exercise most of these rights directly in the app or by writing to app@handsly.io.
You also have the right to lodge a complaint with a supervisory authority. In France, this is the CNIL.
International transfers
Your data is hosted in Europe. Where some subprocessors process data outside the European Economic Area, that processing is covered by appropriate safeguards, in accordance with the GDPR.
Children
Handsly is intended for professionals and is not directed at minors. We do not knowingly collect data about minors.
Changes to this policy
We may update this policy to reflect changes to the service or to the law. If we make an important change, we will let you know. The date of the latest update appears at the top of this page.
Contact
For any question about this policy or your personal data, write to us at app@handsly.io. The data controller is the company Fibroweb (https://fibroweb.fr).