1. Introduction
Fixmeapp (“we”, “our”, “us”) is a social booking platform helping users discover, book, and connect with service providers including salons, stylists, and wellness professionals.
We respect your privacy and process information in accordance with the EU General Data Protection Regulation (GDPR), the Swedish Data Protection Act, applicable CCPA provisions, and other relevant international frameworks.
This policy explains how we collect, use, store, and share information — including data received via the Meta Graph API, Google APIs, and other third-party integrations.
2. Data we collect
We may collect the following categories of data:
- Account information: name, username, email address, and profile photo.
- Booking information: appointments, services, providers, preferences, and payment status.
- Device & usage data: IP address, device type, operating system, crash logs, and in-app events.
- Social data (optional): information from Instagram, Facebook, or Google, with your explicit consent.
- Location data: when you enable location access.
- Cookies & tracking: for core functionality, analytics, and security.
- Calendar data (optional): event names, availability, and time slots for scheduling — with your consent.
- User-generated content: photos, videos, and captions you choose to upload.
- Assistant memory (optional): short, paraphrased preference facts learned from your booking conversations — only with your consent, and only after your review. See section 4.
- Health-related memory (optional): allergy and sensitivity facts relevant to your appointments — only with your separate, explicit consent. See section 5.
We request device access only when required to provide core functionality, and we never collect content without your action or consent.
3. How we use your data
We process personal data to:
- provide, maintain, and personalize your experience
- facilitate bookings, payments, and secure messaging
- recommend services based on activity and preferences
- conduct analytics to improve performance and reliability
- prevent fraud, abuse, and security incidents
- comply with legal obligations
- sync bookings with personal calendars when you connect them
- display uploaded media according to your visibility settings
We do not sell personal data to third parties. Voluntary sharing with partners — when offered — only occurs with informed consent, transparent terms, and an optional bonus model where users benefit directly.
4. The AI assistant and what it remembers
Fixmeapp’s booking assistant handles your booking conversations with service providers. Processing those conversations to arrange your appointment is part of delivering the service itself (GDPR Art. 6(1)(b)) — the assistant cannot book for you without reading your messages.
Assistant memory is different, and it is your choice. If — and only if — you switch on assistant memory in your data wallet, the assistant may keep short preference facts after a booking conversation ends, so you don’t have to repeat yourself next time (for example: “Prefers evening appointments”). This is how it works:
- Off by default. Without your consent, no memory is extracted and your conversation content is not sent for memory analysis. Nothing is pre-checked on your behalf.
- Paraphrased facts only, never transcripts. Memory is stored as short, reworded facts. Verbatim quotes from your messages are automatically rejected, as are contact details, addresses, personal identity numbers, and social handles.
- Nothing counts until you approve it.Every fact the assistant learns from a conversation lands in your wallet as “pending” and waits for your review. You approve it or delete it — deleting is immediate and permanent.
- Providers never see your memory. Your memory belongs to you and Fixmeapp, not to salons or stylists. The only exception is appointment prep: facts you explicitly choose to share are visible to your provider from shortly before your appointment until it ends, then become invisible again.
- Every consent has a receipt. When you say yes, we record the date and the version of this policy you agreed to, and we show you that receipt in your wallet. If we ever want to use your data for a new purpose, that is always a new question — never a silent extension of an old yes.
You can withdraw assistant-memory consent at any time in your wallet. Withdrawal stops all new memory immediately, and you can delete any stored fact individually at any time.
5. Health-related information
Some things worth remembering for your appointments are health-related — an allergy to a nail adhesive, a scalp that reacts to bleach, a sensitivity to strong chemicals. Under the GDPR this is special category data (Art. 9), and we treat it that way:
- Its own explicit consent. Health-related memory has a separate switch with its own deliberate consent moment — it is never bundled into another yes.
- Both switches must be on. Health-related memory only works when you have enabled both assistant memory and health-related memory. Turning off assistant memory stops health memory too.
- Always your review first.Health-related facts are never auto-approved. They wait as “pending” in your wallet until you decide.
- Your health information is never part of what we sell — never without your explicit yes, and never as individual data.
You can withdraw health-data consent at any time, which immediately stops any new health-related memory, and you can permanently delete any stored health fact in your wallet.
6. Integration with Meta services (Instagram Graph API)
Fixmeapp connects with the Meta Graph API to import media, profile information, and insights from Instagram or Facebook. Data retrieved from the Instagram Graph API is refreshed or deleted within 24 hours, unless you have explicitly granted consent for longer storage.
We use this integration to:
- display verified business portfolios or content
- sync and verify social profiles
- recommend relevant professionals or services
Our commitments:
- Access only occurs after explicit OAuth consent.
- We comply with Meta Platform Terms, Meta Developer Policies, and the Facebook Data Protection Addendum.
- Data is stored on encrypted servers with industry-standard protections.
- We never sell, transfer, or use Meta data for advertising outside our platform.
- You can disconnect or request deletion via in-app settings or by emailing privacy@fixmeapp.ai.
6.1 Integration with Apple and Google services
When you connect Apple or Google accounts, we may receive limited data such as your name, email, and — with your explicit consent — calendar events or availability to enable scheduling and booking features.
Access is granted through secure OAuth and is revocable at any time. We never access your photos, contacts, or other personal data unless you explicitly request and approve it. Our authentication flows comply with Apple and Google Identity Services policies.
7. Data sharing
We share limited personal data with trusted service providers (“processors”) only when necessary to operate and improve Fixmeapp. All partners are bound by Data Processing Agreements and must comply with GDPR-level standards.
Cloud hosting & infrastructure
We use infrastructure providers with encryption in transit and at rest, and limited authorized access.
Analytics & error monitoring
We may use privacy-compliant analytics and error-tracking services under GDPR-compliant DPAs, used solely for product improvement — never for marketing.
AI language-model providers
The booking assistant and the optional memory feature (section 4) are powered by AI language models from providers such as OpenAI, acting as our processors under GDPR-compliant data processing agreements. Conversation content is shared with them only as needed to run the assistant, and memory extraction only happens with your consent. Your data is not used to train their models. We never perform profiling or automated decision-making with legal effect without your explicit consent.
Third-party integrations (OAuth)
Where you connect external services, we access only the limited data required for the integration to function. You can revoke access at any time.
We never sell, rent, or share user data for advertising or marketing purposes outside our platform.
8. Your data rights
Under the GDPR, you have the right to:
- access and receive a copy of your data
- request correction or erasure (“right to be forgotten”)
- restrict or object to processing
- withdraw consent at any time
- port your data to another service
To exercise any of these rights, email privacy@fixmeapp.ai with “Data Request” in the subject line. We respond within 30 days as required by law.
9. Data retention and deletion
We retain personal data only as long as necessary to provide the service and comply with legal obligations. When you delete your account, your data is permanently removed within 30 days, unless certain records must be kept for legal reasons.
Assistant-memory facts (sections 4 and 5) can additionally be deleted one by one in your data wallet, at any time, without deleting your account. That deletion is a hard delete, effective immediately.
To request deletion, email privacy@fixmeapp.ai with the subject “Data Deletion Request” from the email address connected to your account. We verify identity before permanent deletion, as required by GDPR and Meta Platform Policy.
10. Security
We use industry-standard safeguards including HTTPS/TLS for all connections, encryption at rest for stored data, role-based access controls, and encrypted OAuth tokens. We perform regular security reviews, backups, and vulnerability testing.
No system is 100% secure, but we work to continuously improve our posture. Production access is limited to authorized personnel under confidentiality and multi-factor authentication.
11. Ethical data economy — our vision
We believe users should be able to monitor and benefit from their own data. Our long-term goal is to enable an ethical data economy where you choose what to contribute, see a receipt for every contribution, and earn value from voluntary sharing. This will only be implemented with clear consent and compliant frameworks. Until then, no part of your data is shared beyond what is described in this policy.
When contribution channels launch, three promises will hold from day one: every channel is off by default and each is its own separate yes; what we sell is aggregated market insight, never individual data, never your words, never your identity; and deletion is worded honestly — you can stop future contributions immediately and destroy the link between you and past contributions, but statistics you already contributed to stay published, with your connection to them provably destroyed.
Read more about our research in this area on our Ethical Data Economy page.
12. International data transfers
Where personal data is processed outside the EU/EEA, we apply appropriate safeguards including:
- EU Standard Contractual Clauses (SCCs), or
- transfers to entities under an adequacy decision (e.g. the EU–U.S. Data Privacy Framework).
13. Changes to this policy
We may update this policy to reflect changes in technology or legal requirements. Updates will appear here with a new version number and a revised “Last updated” date. Every consent you give is recorded against the policy version in force at that moment. For material changes, we will notify you via email or in-app alert and ask you to review and accept the updated policy before continued use — a new purpose is always a new question.
14. Contact
For any privacy questions or concerns, contact us at privacy@fixmeapp.ai.
Fixmeapp AB · Stockholm, Sweden · © 2026 FIXMEAPP AB. All rights reserved. FIXMEAPP™ is a registered trademark.