Privacy Policy
Last updated: 21 August 2026 · Version: v1.24
Lee esta Política de Privacidad en español
About this translation. This is an English translation provided for your convenience. The Spanish version is the legally binding one; if the two ever differ, the Spanish text prevails. The Terms of Service and the Content Rules linked below are currently available in Spanish only.
1. Data controller
The controller of the personal data processed by the Tegaria application (app.tegaria.com) is Linkprop Home S.L. («Tegaria» is a trade mark of Linkprop Home S.L., with a registration application pending before the European Union Intellectual Property Office):
- Controller: Linkprop Home S.L.
- Tax identification number: ESB88894423
- Registry details: Registered at the Commercial Registry of Madrid, Sheet M-889268, 1st Entry (IRUS 1000475612872).
- Registered address: Calle Carretas 33, 4º CD, 28012 Madrid, Spain
- Contact email: info@tegaria.com
This policy applies to the Tegaria application. The informational website tegaria.com has its own privacy policy.
2. Data we collect
Depending on how you use the application, we may process the following categories of data:
- Account and authentication: email address and, if you sign in with Google, your name, email, profile picture and user identifier.
- Profile data: first and last name, description, housing preferences, employment situation, income range, photo and any contact details you provide voluntarily.
- Motivation tag: if you add a motivation tag to your search profile, it forms part of your profile. It is visible to counterparties and to anyone you share your link with.
- Living preferences (may include special category data): if you are searching for or renting shared housing, you can state what you want the home to be like: the gender space (mixed, women's or men's), the identity space (mixed or LGBTI+), an age range and the lifestyle. These fields are optional: the default is «mixed» and you are not required to declare anything. By choosing the «LGBTI+ space» you may be revealing data about your sexual orientation or gender identity, which is special category data (art. 9 GDPR) and is processed with your explicit consent, given when you select that option. It is used solely to suggest compatible counterparties and is visible to the counterparties the system matches you with. You can go back to «mixed» whenever you want by editing your listing or your search profile.
- Property data: if you publish a home or you are a partner agency, its address, features, photos and financial terms.
- Phone: phone number, verified through our verification provider.
- Identity verification (special category data): to guarantee that there is a real and unique person behind every account, we use an identity verification provider (Didit) that processes your identity document and your facial biometric data (liveness check and facial recognition). This is special category data (art. 9 GDPR) and is processed with your explicit consent.
- Payment data: if you purchase paid services (for example, publishing a listing or topping up your wallet), we process the amount, the date, the transaction identifier and your movement history (wallet balance and entries). The payment method details (card number or, with Bizum, your phone number and the authorisation at your bank) are collected and processed directly by our payment gateway (Stripe): Tegaria never sees or stores your card numbers or your banking credentials.
- Usage and interaction data: matches, messages, reviews and activity within the app.
- Reviews: when a relationship between two users ends, both parties have 10 days to review each other: scores from 1 to 5, reasons from a closed catalogue and an optional free text of up to 300 characters. Once published, the review is visible to any user signed in to the application, together with the visible name of its author and the context of the dealing (whether there was an agreement and, where applicable, the listing title). The reviewed person may publish ONE reply to each review they receive (free text of up to 300 characters), shown next to that review, with their visible name and to the same readers. Once sent, the reply cannot be edited or deleted separately: it disappears if the review it answers disappears.
- Technical and security data: IP address, device identifiers and access and security logs.
- Usage measurement data (analytics): application usage events (for example, which screens are shown or at which step a process is abandoned), measured with Google Analytics for Firebase through an identifier specific to the app installation. We have disabled advertising identifiers and ad personalisation signals: this measurement is used only for internal statistics and to improve the service, never for advertising.
- Queries to the help assistant: if you use the help assistant built into the app, we process the text of your question, the screen you are asking from, the language and the generated answer, in order to answer you. So that we can give you a specific answer, along with your question we send the provider a summary of your account status produced by our system, only when there is some issue (for example: identity pending verification, listings pending payment —together with your balance—, hidden or expired, or that you have not yet created your listing or your search profile); if there is none, we only send an indication that there are no issues. That summary never includes your name, email, phone, the titles or areas of your listings, or the content of your messages or reviews. After answering you we keep no personal data from the query: we keep only an anonymous record, to improve the help guide, made up of the question and the answer after automatically removing personal data from the text (names, phone numbers, emails, addresses and the like are replaced with generic placeholders; if that automatic cleaning fails, the record is stored without the text), together with the screen, the language, whether you got an answer and, where applicable, the generic issue types of your account (for example «identity pending verification», with no amounts or figures), with a rounded timestamp. That record contains neither your account identifier nor any code derived from it: it does not allow us to know who made each query. In any case, we recommend not including personal data in your questions: it is not needed to help you.
- Age: you declare that you are 18 or older when you accept the terms. We do not ask for your date of birth in any form in the application; if you verify your identity, the date shown on your document is kept within your verified identity, as explained in the next point.
- Verified identity (document data): when identity verification is approved, we keep the data the provider extracts from your document: first and last name exactly as they appear on it, document type and number (for example, your national identity document) and date of birth, together with the date it was verified. They are stored separately from the name you declared when you signed up, which is not modified. Their purpose is to establish who each party is —fraud prevention and, when you activate it, the formalisation of agreements between users— and they are not shown to other users; only you and, where applicable, the other party to an agreement you sign would see that information.
Data provided by partner organisations. When a partner organisation registers the profile or the listing of a person from the group it supports, it is the organisation that provides that data and that warrants having the legal basis and the consent to do so, as well as having informed the person. The organisation is the point of contact for the exercise of those persons' rights.
3. How we use your information
- Authenticate your access and provide the service: profile, matches between tenants and landlords, and messaging.
- Show your profile or property to other relevant users where a possible rental relationship may arise.
- Verify your identity and prevent fraud: confirm that you are a real and unique person, and prevent duplicate accounts or the return of previously blocked or deleted accounts, by means of facial biometric comparison (1:N search) against already verified identities.
- Community safety and moderation: allow you to report other users, handle those reports and act on accounts when a breach is confirmed. Reporting also blocks contact between the two people.
- Respect your contact preferences: if you block a person, we store that decision —who blocked whom, since when, whether it arose from a report, and the visible name of the blocked person so that you can manage your list— and we apply it in both directions: their listings and their profile stop reaching you and yours stop reaching them, and your open conversations close like any relationship that ends without an agreement. The other person is not notified and you can undo it whenever you want from Settings → «Blocked users».
- Sustain the reputation and trust system (reviews between users).
- Manage service payments: process wallet top-ups and charges for paid services (such as publishing listings), keep the record of your movements and balance, handle refunds or payment claims and issue the corresponding receipts.
- Measure app usage in aggregate form to learn at which steps users get stuck or drop out and improve the service (internal analytics, no advertising).
- Answer the queries you make to the help assistant built into the app.
- Translate the texts that users write (listings, introductions, agency descriptions, reviews and their replies) when the reader is reading in a language other than the one they were written in, so that they can be understood. Chat messages are not translated. This happens both inside the application and on the public page of a listing or profile you have decided to share by link, which anyone can open even without a Tegaria account.
- Automatically review the texts that are published (for example, reviews and their replies) to detect inappropriate content before showing it (moderation).
- Improve the help guide by analysing the anonymous record of queries, which is not linked to any person and contains no personal data (the text is stored with personal data already removed).
- Improve the functionality and security of the service and comply with applicable legal obligations.
4. Legal basis for processing
- Performance of the contract (art. 6.1.b GDPR): provision of the service (profile, matches, messaging), answering the queries you make to the help assistant —sending them to the provider that generates the answer is essential to give you what you asked for when you tapped «An AI answers»—, the translation of the texts you write when another person reads them in a different language —showing what is published in a way its intended reader can understand is part of the service—, management of the payments for the services you purchase (top-ups and publications) and the motivation tag on your search profile. Tags that reveal special category data (art. 9 GDPR) are not allowed, in accordance with the Content Rules.
- Explicit consent (art. 9.2.a GDPR): processing of your biometric and identity verification data (special category), and of the living preferences that may reveal your sexual orientation or gender identity (the «LGBTI+ space» option), which are only processed if you voluntarily choose that option.
- Legitimate interest (art. 6.1.f GDPR): fraud prevention, platform security, preventing duplicate or evasion accounts, protecting the community —including the reputation system between users (the publication of reviews) and the automatic review (moderation) of published texts— and internal, aggregate measurement of app usage (analytics without advertising identifiers).
- Compliance with legal obligations (art. 6.1.c GDPR): among others, retention of invoicing records and payment transactions required by commercial and tax law.
You can withdraw your consent at any time; this will not affect the lawfulness of prior processing or retention covered by other legal bases (for example, fraud prevention).
5. Who we share your data with
We do not sell your personal data. To provide the service we rely on providers (data processors) that access your data on behalf of the controller:
- Google Firebase (Google Cloud): authentication and data storage on servers in the European Union (European region).
- Google Analytics for Firebase (Google Ireland Ltd.): app usage measurement, with advertising identifiers and ad personalisation disabled; measurement data is processed for internal service statistics.
- Gemini API (Google): we use it for three distinct purposes:
(a) Help assistant. Generation of the answers of the help assistant built into the app and automatic removal of personal data from the text before storing the anonymous query record. For this purpose it receives only the text of your question (and of the generated answer, for that cleaning), the screen you are asking from, Tegaria's public help guide and the status summary described above (or the indication that there are no issues) — never your account identifier or your name.
(b) Translation of the texts you write. So that a reader in another language can understand what you wrote, we do send Gemini, for translation, the content of your listings (title, description and the description of the service or exchange you are asking for), the free texts of your search profile (your «about me» introduction, your occupation, the languages you speak and the description of the service you offer), your agency's description and rates, your reviews and the replies you write to the reviews you receive. Proper names are never translated: not your name, nor your agency's, nor addresses or area names. Chat messages are not sent to Gemini: the conversations you have with other users are neither translated nor automatically reviewed. For this purpose Gemini receives only the text to be translated, without your account identifier, your name, your photograph, your location or any other profile data.
Translation is only requested when needed: if the language you wrote in matches the reader's, nothing is sent. In addition, each text is translated only once: we store the result on our own servers (European Union region) for 180 days, so that the next people who read it cause no new transmission. The translation is only displayed: it is not used to decide anything about you, your listing or your profile, and the page or screen tells you that the text is automatically translated and lets you go back to the original.
Who can trigger a translation. Besides application users, if you have shared a listing or a profile through a public link, the person who opens that link —even without a Tegaria account— can trigger the translation of the texts that page shows, and only those: the listing title and description, the profile introduction and occupation, or the agency description. It only affects content you have decided to publish with that link; the rest of your information is not involved and that page never shows your reputation or your reviews. Whoever opens the link cannot request the translation of any other text.
(c) Automatic content review (moderation). The texts you publish that other users can read (for example, reviews and their replies) are sent to Gemini to be reviewed automatically and detect inappropriate content before showing it. For this purpose it receives only the text to be reviewed. The criteria applied are not secret: they are the Content Rules, which you can read before writing. The system never rewrites what you have written: if a text does not comply with those rules, it stops being shown, we notify you and the case goes to human review. A review that has been taken down can be deleted and written again while its 10-day window is still open; a reply that has been taken down cannot be rewritten —there is only one per review—, and its only way back is for human review to restore it. Automatic review does not decide alone and forever: you can ask us to look at the case at info@tegaria.com.
For all three purposes we use the service in its paid tier, in which Google does not use the content to train its models and acts as a data processor in accordance with its Data Processing Addendum for products where Google is a processor. Google retains the content sent for a limited time for the sole purpose of detecting and preventing prohibited uses and to comply with legal obligations. International transfers: in providing the service, data may be stored transiently or cached in any country where Google or its agents have facilities, including countries outside the European Economic Area. Such transfers are covered by the Standard Contractual Clauses approved by the European Commission and, where the recipient is a Google entity in the United States certified for that purpose, by the EU-U.S. Data Privacy Framework, in accordance with Chapter V of the GDPR.
- Didit (identity verification provider): processing of the identity document and biometric data for verification (know your customer) and fraud prevention. International transfers, where applicable, are covered by the appropriate safeguards of Chapter V of the GDPR.
- Stripe (Stripe Payments Europe, Ltd.): payment gateway for service charges, by card or Bizum. Stripe collects and processes the payment method data directly (Tegaria never sees your card numbers); it tells us the outcome of the transaction, its identifier and the amount. In Bizum payments, the service is provided with the participation of Open Bank, S.A. (a Bizum member institution) and Bizum, S.L., which process the data needed to execute the instant transfer (such as your phone number). Any international transfers Stripe may carry out are covered by the appropriate safeguards of Chapter V of the GDPR (standard contractual clauses).
- Resend: sending the application's transactional emails.
- Algolia: indexing and search service we use to discover compatible listings and profiles (the matches). The index contains the listing or profile data needed for that function; Algolia acts as a data processor and international transfers, where applicable, are covered by the appropriate safeguards of Chapter V of the GDPR (standard contractual clauses).
- Other platform users: your profile or property is shown to other users where a possible rental interaction may arise or when you start one (chat, request). In addition, the reviews you write are published within the application and are visible to any signed-in user —not just the person reviewed—, with your visible name. They are published double-blind: until the other party writes theirs or the deadline expires, nobody can read it, not even the person reviewed; then both are published at the same time. While the review has not been published you can delete it (and write it again); once published it cannot be edited or deleted, and to request its removal you must write to info@tegaria.com (see point 7). Likewise, the reply you write to a review you have received is published next to that review, with your visible name and visible to any signed-in user; you can write only one and, once sent, it cannot be edited or withdrawn separately. Reviews never appear on the public page of a shared listing, which includes no reputation.
- Anyone you share your public link with (no account needed): if you decide to share your search profile through a link, the page that opens shows any visitor, without signing up: your name, your photo, your introduction, your age, your occupation, whether you are a student, whether you have pets, whether you are a smoker, the date from which you are searching, the minimum stay, the type of search (room or flatmate) and your motivation tag. If you share a listing, the page shows its details and photos; if you share an agency profile, its description and rates. What does not appear on that page: your living preferences (including the «LGBTI+ space» option), your gender declaration, whether you are part of a couple, your social profiles, your employment situation, your search area, your budgets or your reputation. Before publishing the link for the first time we ask you to expressly declare that you understand that this information will be accessible to anyone who receives the link. You can stop sharing it whenever you want: the page stops being served and the published copy is deleted after 30 days.
6. Retention and account deletion
Important: for reasons of fraud prevention and community safety, when you delete your account not all data is erased immediately and completely. Your profile is anonymised, but we deliberately keep certain information for as long as is necessary for those purposes.
While your account is active, we process your data to provide you with the service. When you delete your account:
- We anonymise your profile: we delete your identifying data (real name, email, phone, photo and identity document) and unlink your identity from your interactions (your name is shown as «Deleted user»).
- We keep your verification identity (biometric/know your customer) at the verification provider, for the purpose of preventing a deleted or blocked account from signing up again or creating duplicate accounts through 1:N facial comparison. This is special category data whose retention is based on the legitimate interest in fraud prevention and on the exceptions to the right to erasure of art. 17.3 GDPR.
- We keep the reports linked to your account, and the block that each one carries with it, for other users' safety. From that record we remove the name of the blocked person: it is personal data that does not outlive the deletion of its owner's account.
- The blocks you placed on your own initiative are erased completely, in both directions: the ones you placed and the ones others placed on you. Unlike those that arise from a report, they are not a safety record and are not retained.
- We keep the legal audit trail (for example, acceptance of the terms) by legal obligation.
- We keep payment and wallet movement records for the periods required by commercial and tax law (generally, up to 6 years), by legal obligation.
- We keep your reputation (score and reviews received) in anonymised form, to maintain the integrity of the trust system.
- The content of the messages and reviews you wrote is kept, but anonymised (unlinked from your identity): reviews that were already published remain visible in the application, showing «Deleted user» instead of your name.
- The translations of your texts are stored linked to the content of the text —not to your account— for 180 days, so that they do not have to be translated again. If you edit or delete a text, its previous translation stops being used and is deleted when that period ends.
- The anonymous record of queries to the help assistant is unaffected: it was never linked to your account and contains no personal data (the text is stored with personal data already removed), so there is nothing of yours to delete in it.
- Your motivation tag is kept for as long as you keep it on your profile and disappears when you delete the profile or the account. The shared tag directory is written by Tegaria alone and its entries carry no one's identifier: they are public text and nothing more, so no data of yours is left there to delete.
Anonymised or aggregated data, which no longer allows you to be identified, may be kept without a time limit. Information retained for fraud prevention is kept for as long as that purpose persists, in accordance with our data protection impact assessment; once the applicable period has elapsed, it is permanently deleted.
7. Your rights
You can exercise, free of charge, your rights of access, rectification, erasure, objection, restriction, portability and withdrawal of consent, by writing to info@tegaria.com.
The right to erasure («right to be forgotten») is limited by the exceptions of art. 17.3 GDPR: we cannot delete information that is strictly necessary for fraud prevention, for compliance with legal obligations or for the establishment or defence of legal claims. Outside those cases, we will comply with your deletion request.
Reviews already published. A published review is not withdrawn on simple request, neither by its author nor by its recipient: it forms part of the reputation system between users that sustains trust on the platform (legitimate interest, point 4), and being able to delete it at will would allow people to pressure its author into doing so. If you believe that a specific review —or the reply to a review— should be withdrawn, write to us at info@tegaria.com explaining why: a person will review it and we will reply within one month (art. 12 GDPR). Where the request is well founded, the review stops being shown to other users and stops counting towards reputation. Regardless of this, if you delete your account the reviews you wrote are kept in anonymised form, as explained in point 6.
If you consider that the processing does not comply with the applicable rules, you can lodge a complaint with the Spanish Data Protection Agency (www.aepd.es).
8. Data security
We apply appropriate technical and organisational measures and trusted cloud providers to protect your information against unauthorised access, alteration or loss, taking into account the state of the art and the risks of the processing.
9. Minors
Tegaria is not directed at people under 18. When you sign up you declare that you are at least 18. If we detect an account belonging to someone below that age, we may suspend or delete it.
10. Changes to this policy
We may amend this Privacy Policy to adapt it to legal or service developments. We will publish changes on this page and, where the change is significant, we will notify you and, where appropriate, obtain your consent again.
11. Contact
For any question about this Privacy Policy, write to us at info@tegaria.com.