1. Who we are
SoworeNow is the official supporter app of the Take It Back Movement, a Nigerian political movement. The data controller for the purposes of the NDPA, GDPR and CCPA is:
Take It Back Movement (d.b.a. SoworeNow)
[Address — registered office, Nigeria]
Email: [email protected]
Data Protection Officer: [email protected]
If you contact our DPO, we will respond within the timeframes set in Section 11 — Your rights.
2. The information we collect
We collect the following categories. Where the data is optional, that is called out explicitly.
2.1 Account information
| Field | When we collect it | Why |
|---|---|---|
| First name, last name | Sign-up | Identify you to coordinators / other supporters |
| Email address | Sign-up | Verification, account recovery, security alerts, briefings (opt-in) |
| Phone number | Sign-up | Verification, login fallback, urgent rally notifications |
| Username | Sign-up / Edit Profile | Public identifier on community posts and chat |
| Password (hashed) | Sign-up | Authentication — never stored in plain text |
| Profile photo | Optional | Avatar on posts, chats, profile |
| Date of birth | Optional | Age-gating for events / donations |
| Gender | Optional | Anonymised demographic reporting |
| Country / state / LGA | Sign-up / Edit Profile | Show local rallies, coordinators, supporters |
| Bio | Optional | Public self-description on profile |
| AAC member ID | Optional | Link your AAC party membership (see §3.7) |
2.2 Verification data
- 6-digit OTP codes emailed or texted to you for email or phone verification. The plain-text code is never stored; only a salted hash is held while the code is valid (10 minutes).
- The fact that your email or phone is verified, and the timestamps of successful verifications.
2.3 Community content
Anything you choose to publish to the community feed:
- Post text and any photos / videos you attach.
- Comments and replies.
- Reactions (👍 ❤️ 🔥 ✊ 😢) on posts and comments.
- Reports you submit against other content (reason + optional detail).
This content is public by default once published — see Section 7 — Sharing.
2.4 Messaging data
- Private one-to-one and group chats: message text, attachments (photos, videos, voice notes), read receipts, typing indicators.
- Conversation membership, mute / archive / pin state, mentions.
- Audio voice notes you record in chat (stored encrypted at rest).
Group chats are visible to every member of that group. Direct messages are visible only to you and the recipient (plus admins for moderation when a report is filed).
2.5 Rallies & volunteering
- Your RSVPs to rallies (the list of supporters going is visible to other supporters).
- Volunteer requests you submit (your name, the interests you tick, any free-text message) — visible to admins and coordinators in the relevant area.
2.6 Donations & payments
When you donate or pledge in-kind:
- Donor name (optional — you may donate anonymously).
- Donor email and phone where required by the payment processor.
- The amount, currency, campaign, payment method and transaction reference.
- For in-kind pledges: the item, quantity, fulfilment status.
We do not store full card numbers, CVV codes, or bank account credentials. Card details are entered directly on Paystack or Flutterwave payment pages and stored by them under PCI-DSS controls; we receive only the tokenised transaction reference and the last 4 digits.
2.7 Location data (opt-in)
- Coarse / precise location when you tap “Supporters near you”, “Find rally” or “Share your location” — you choose each time.
- Saved delivery / contact addresses (label, line 1/2, city, state, LGA, latitude / longitude) when you choose to save one.
We never collect your location in the background.
2.8 Device & technical data
- Device model and OS version.
- App version and locale.
- Anonymised crash / error reports (no message content, no chat bodies).
- Push notification tokens (Apple Push, Firebase Cloud Messaging) — used only to deliver pushes you’ve opted into.
- Approximate IP-address-derived country (for rate-limiting + fraud prevention; not stored beyond 30 days for that purpose).
2.9 AI feature data
In-app permission. Before any AI feature sends data to a third-party provider, we ask for your permission in-app. The first time you tap Movement AI (the assistant on the Home tab) or Key Points on a news article, an AI consent sheet opens telling you exactly what is sent, to whom, and how it is treated. AI features do not work until you accept. You can change your mind at any time at Profile → Settings → AI Assistant — turning the toggle off revokes the permission and the AI endpoints stop accepting your data until you turn it back on.
Provider. Our default provider is OpenAI, a U.S. company. (The provider is configurable per environment, and we may add Google Gemini as a fallback; if so, the in-app sheet names whichever provider will receive your data.)
What is sent. Only the prompt or content you choose to send: the text of your question or message to the assistant, the body of an article you ask us to summarise, or the short UI string being translated for the in-app language switcher.
What is never sent. Your name, email address, phone number, AAC member ID, polling-unit assignment, address, location, or any identifier that links the prompt back to you on the provider’s side. Requests are sent over our shared API key.
Provider treatment. OpenAI processes the data as our service provider under their API terms. They do not use API data to train their models; they retain the request for at most 30 days for abuse monitoring, then delete it; and they contractually provide protection equal to or stronger than this Privacy Policy commits us to.
You can withdraw the AI permission for any reason and continue using every non-AI feature of the app — the consent is not bundled with the rest of the Terms.
2.10 Linked accounts
If you link your account to an external service, we store the OAuth tokens needed to act on your behalf:
- AAC membership (via the link flow): the AAC-issued
linked_app_idand the canonicalmembers.id. No AAC password. - X / Facebook / Instagram / TikTok cross-posting (future): OAuth access + refresh tokens. You can disconnect any of these at any time from Settings → Connected accounts.
2.11 Information you give us when you contact us
Emails to support@, privacy@ or dpo@ are stored for as long as the request is open, plus a short retention window for audit.
2.12 Points, rank & rewards
SoworeNow includes a points & rank programme that rewards participation. When you take part, we collect and store:
- Your points balance, spendable balance and rank / level, plus an append-only points ledger — each entry records the action that earned or spent points (e.g. opening the app, donating, volunteering, redeeming an event code, a referral, a reviewed claim, or a support redemption), the amount, and the time.
- Your referral code and, when you sign up through a supporter’s invite link, the fact that they referred you (and, for the referrer, that a referred visit or sign-up occurred). Referral visits are de-duplicated using a first-party identifier — see Section 13.
- Evidence you submit to claim points for off-app activities (for example a photo or a link, plus an optional note, date and location). Evidence is reviewed by an admin before any points are awarded.
- For support redemptions (e.g. spending points for data / airtime credit): the request, the phone number or other contact you give us to deliver the reward to, the network, and the fulfilment status. A contact you provide for a redemption is used only to arrange and deliver that reward (in addition to the purposes in §2.1). Rewards are fulfilled by the movement’s team at their discretion and the delivery itself may happen outside the app; we do not run an automated airtime / payment integration for this.
Points have no monetary value, cannot be exchanged for cash, and are governed by the Terms of Use.
3. The App Clip
The SoworeNow App Clip — the lightweight version that opens when someone scans a QR code or sticker — is anonymous by design. It does not require sign-in, does not have access to your full app data, and reads only the public endpoints (countdown, today’s briefing, latest news, upcoming rallies, community feed). When you tap Install in the Clip, you are taken to the App Store; the full app collects data only after you actively sign in.
4. How we use your information
We use your data for the following purposes only:
| Purpose | Examples |
|---|---|
| Provide the service | Authenticate you, render your feed, deliver chats, process donations, run RSVPs and volunteer matches. |
| Verify identity | Email / phone OTP, AAC link verification — to gate community-posting and other actions. |
| Communicate | Account-related emails (sign-up, password reset, donation receipt), in-app notifications, push notifications you’ve opted into. |
| Personalise the experience | Show rallies / coordinators / supporters / weather near you (based on the state on your profile). |
| Safety & moderation | Review reports, remove content that breaks the community guidelines, ban abusive accounts. |
| AI summaries & briefings | Generate the daily briefing and per-article key-points from the public news + rally + donation totals — never from your private chats. |
| Points, rewards & referrals | Award and track points for participation, run rank / level benefits, attribute referral sign-ups and visits, review point claims, and fulfil reward redemptions (e.g. data / airtime credit) — see §2.12. |
| Analytics & product improvement | Aggregate, anonymised counts — daily active users, top posts, donation totals. No individual tracking profile and no cross-site advertising. (Referral attribution is a separate, first-party feature disclosed in §2.12 and §13.) |
| Security & fraud prevention | Rate-limit suspicious requests, detect duplicate sign-ups, audit admin actions. |
| Legal compliance | Respond to lawful requests from courts, regulators (NITDA, EFCC, etc.) and tax authorities — see §10. |
We do not sell your data, and we do not use it for targeted advertising.
5. Legal bases (NDPA / GDPR)
For each purpose above, the legal basis we rely on is:
- Contract — to provide the SoworeNow service you sign up for.
- Consent — for opt-in features (location sharing, push notifications, marketing email, social cross-posting). You can withdraw consent at any time from Settings.
- Legitimate interests — for safety, fraud prevention, basic analytics, the security of our platform — balanced against your rights.
- Legal obligation — for tax / regulatory reporting, lawful enforcement requests.
- Public interest — for the limited cases where Nigerian electoral law or NDPA Schedule treats political-movement data processing as a matter of legitimate public interest.
6. Sensitive personal data
Political opinions are treated as a special category under GDPR and sensitive data under the NDPA. By creating a SoworeNow account and engaging with the Take It Back Movement, you explicitly consent to us processing the fact of your support, your community-feed contributions, your RSVPs and your donations under that special-category basis. You can withdraw consent at any time by deleting your account (see §11.3).
7. How we share information
We share data only with the parties listed below, and only for the purposes described.
| Recipient | Why | Where |
|---|---|---|
| Other SoworeNow users | Your community posts, profile, RSVPs and group-chat content are visible to other users by design. Private DMs are visible only to participants. | In-app |
| Paystack / Flutterwave | Process card / bank / mobile-money donations. They are independent controllers of the payment data they hold. | Nigeria + their PCI-DSS infrastructure |
| SpeedySMS | Send transactional emails and SMS OTPs from the [email protected] mailbox / SoworeNow domain. | Nigeria |
| OpenAI (and optionally Google Gemini as a fallback) | Generate AI briefings, summaries, translations, and assistant replies. Only the prompt or content you choose to send is transmitted; your name, email, phone, AAC member ID and other identifiers are never sent. Transmission only happens after you explicitly accept the in-app AI consent sheet (revocable at Profile → Settings → AI Assistant) — see §2.9. The provider processes the data as our service provider under API terms equal to or stronger than this policy: no model training on API data, ≤ 30-day abuse-monitoring retention. | OpenAI US / Google global |
| Apple Push, Firebase Cloud Messaging | Deliver push notifications. | Apple US / Google global |
| Google Maps Platform | Render maps and geocode addresses (community map, rallies map). | Google global |
| AAC (African Action Congress) | Verify AAC membership (only when you choose to link). | Nigeria |
| Auditors, accountants, lawyers | Under confidentiality, for finance and compliance. | Nigeria |
| Courts, regulators, law enforcement | Where compelled by valid Nigerian process or where required by NDPA / NDPR. | Nigeria |
We do not sell, rent, or trade your personal data to data brokers, political consultancies outside the movement, or advertisers.
8. International transfers
Some of the providers above (OpenAI, Google, Apple) operate outside Nigeria. Where we transfer your data abroad, we rely on:
- Whitelisted jurisdictions under NDPA §41(1)(a) where applicable (e.g. EU adequacy decisions).
- Standard contractual clauses with the recipient.
- Your explicit consent for the transfer when you use the relevant feature (e.g. the AI assistant).
You can find each provider’s own privacy notice on their website.
9. Retention
We keep your data only as long as necessary for the purpose we collected it.
| Data | Retention |
|---|---|
| Account profile | While your account exists. Deleted within 30 days of you closing it (subject to §10). |
| Community posts & comments | While the post exists. You can delete your own. Reports keep the original content visible to admins for 90 days after resolution for audit. |
| Direct messages | Until you or the other party delete them. We do not read DMs. |
| Donations / payments | 7 years (Nigerian tax + financial-records law). |
| AAC link audit row | While the link exists, plus 12 months. |
| Points ledger, balance & rank | While your account exists; removed on account deletion (§11.3), subject to fraud-prevention tombstoning. |
| Referral code & attributions | While your account exists. |
| Point-claim evidence | While the claim is open, plus a short audit window after a decision; removed with your account. |
| Support-redemption requests | Retained for fulfilment and audit. |
| Website referral visitor ID | Stored in your browser’s local storage until you clear it; the server keeps only the de-duplicated attribution event. |
| OTP codes | 10 minutes (then deleted). |
| Push tokens | While the device is registered; auto-pruned after 90 days of inactivity. |
| Request / error logs (DB) | 30 days for ordinary requests; 1 year for errors and security events. |
| Cancelled / soft-deleted accounts | Tombstoned data hashed and retained for 90 days for fraud-prevention, then fully erased. |
10. Security
We protect your data with technical and organisational measures including:
- HTTPS for every API call from the app and the web.
- Hashed passwords (bcrypt with strong cost factor).
- JWT-signed sessions with refresh-rotation and revocation lists.
- OTP hashing + rate limits (5 attempts then a fresh code is required).
- Per-app API keys for partner integrations (AAC, etc.).
- Encryption at rest on the database and the file-storage layer used for chat attachments and post media.
- Least-privilege access for the operations team — every admin action is logged in an audit table.
- RBAC — user, supporter, coordinator, admin, super_admin roles.
No system is perfectly secure. If you believe your account has been compromised, change your password immediately and email [email protected].
11. Your rights
Under the NDPA / GDPR / CCPA, you have the following rights. We honour them whether or not the strict legal basis applies to you.
11.1 Right to access
You can request a copy of the personal data we hold about you. We respond in machine-readable form (JSON archive).
11.2 Right to rectification
You can correct any inaccurate or incomplete profile data from Profile → Edit profile in the app, or by emailing [email protected].
11.3 Right to deletion (“right to be forgotten”)
You can delete your account at any time from Profile → Sign out → Delete account (or by emailing [email protected]). We will:
- Hard-delete your profile, posts, comments, reactions, messages and preferences within 30 days.
- Tombstone your donations / payments record (replace personal fields with hashes) but retain the financial entry for the legally required 7 years.
- Retain admin-audit entries referencing your account for the time required by §10.
11.4 Right to portability
You can export your data as a JSON archive containing: profile, addresses, posts, comments, reactions, RSVPs, donations summary, linked accounts (without tokens). Email [email protected] — typical turnaround is 7 days.
11.5 Right to restrict / object
You can ask us to stop processing your data for any specific purpose (e.g. AI features, push notifications) while remaining a user.
11.6 Right to withdraw consent
Any feature you opted into can be opted out of in Settings or by emailing the DPO. Withdrawing consent does not affect lawful processing already carried out.
11.7 Response times
- NDPA / NDPR: within 7 working days of a valid request.
- GDPR: within 30 days, extendable by 60 days for complex requests with notice.
- CCPA: within 45 days, extendable by 45.
We may verify your identity before acting on a request — see Data Request Policy.
11.8 Right to lodge a complaint
If you believe we have mishandled your data, you can complain to the relevant authority:
- Nigeria — Nigeria Data Protection Commission (NDPC): https://ndpc.gov.ng
- EU / UK — your local Data Protection Authority.
- California — California Privacy Protection Agency (CPPA).
We would rather hear from you first — [email protected] — so we can fix things directly.
12. Children
SoworeNow is not intended for users under 18. Nigerian electoral participation begins at 18, and we apply the same threshold here. If you believe a child has created an account, email [email protected] and we will delete it within 7 days.
13. Cookies & similar technologies
The mobile app does not use browser cookies. The website at soworenow.org uses:
- Strictly necessary cookies — session and CSRF tokens. No opt-in required.
- Functional cookies — language preference. Set when you change language.
- Referral attribution (local storage). If you open the website through a supporter’s invite link (a
?ref=link), we store a random first-party identifier (soworenow_visitor_id) in your browser’s local storage so the same visit isn’t credited to that supporter more than once. It is a first-party de-duplication identifier only — it is not shared with advertisers, not used to build an advertising profile, and not used to track you across other websites. Clear your browser storage to remove it. - No advertising or cross-site tracking cookies.
The App Clip does not persist any data after eviction by iOS (typically ~8 hours after last use).
14. Automated decision-making
We do not use automated decision-making that has legal or similarly significant effects on you. AI features generate summaries / language translations only — they do not make moderation, donation or account decisions on their own. Moderation actions are reviewed by a human admin before being applied.
15. Changes to this policy
We may update this policy from time to time. Material changes are notified by email (to the address on your account) and in-app at least 14 days before they take effect. The “Last updated” date at the top reflects when the current version was published. Older versions are archived at https://soworenow.org/legal/privacy.
16. Contact us
| Topic | Address |
|---|---|
| Privacy / data requests | [email protected] |
| Security issue | [email protected] |
| General | [email protected] |
We are based in Nigeria. Email is the fastest way to reach us.
This document is provided in plain English for accessibility. The authoritative legal text — if and where it differs — is the version filed with our regulator and available on request.