Last updated: October 2026

Privacy Policy

How CrowdEye collects, uses and protects your data, in plain language.

CrowdEye exists to turn what citizens witness into verified, safely-handled reports. Protecting the people in those reports—and the people who make them—is central to how the app is built. This policy explains what we collect, why, how we protect it, and the rights you have.

1. Who we are

The data controller is CrowdEye, with its registered address in Lagos, Nigeria.

CrowdEye operates the CrowdEye app and the crowdeye.ng website. For data-protection questions, contact our Data Protection Officer at dpo@crowdeye.ng.

2. Data we collect

We collect only what we need to verify reports, route them safely and run the Service.

CategoryWhat it includesWhy
Report contentPhotos, video, audio and any note you addThe report itself—to verify, handle and route it
Capture metadataApproximate location, date/time and a tamper-evident hash of the captureTo confirm when and where something happened and detect tampering
Device & integrity signalsDevice/OS type and app-integrity or attestation signalsTo screen fake, automated or manipulated submissions—not to identify you
Account data (optional)Phone number and/or display name where you create an accountSign-in, one-time codes and airtime/mobile-money rewards
Support messagesWhat you send us and our repliesTo help you and improve the Service
Website dataIP address, browser/device info and cookie dataTo run and secure the site and understand its use

You can submit many reports without creating an account. Where a feature does not need your identity, we design it—not to collect it.

3. Other people captured in your media

A capture may contain other people’s faces or likenesses. We treat this carefully.

  • Faces are blurred by default before anything is shown outside the authority handling the report.
  • The exception is a public official acting in their official capacity, who may be shown for accountability in a verified Tier 2 (misconduct) report.
  • Tier 4 (alleged crime) evidence is not published publicly—it goes only to the relevant authority, with faces blurred in anything we display.

If you appear in a report and have concerns, contact us using the details in section 16.

4. How & why we use data

We use data to verify reports, handle and route them by tier, prevent misuse, deliver eligible rewards, maintain the Service, and comply with the law.

  • To verify the authenticity of a report (integrity checks, human moderation, tamper-evidence).
  • To handle and route reports according to their tier—publishing, blurring or forwarding to the relevant authority or oversight body.
  • To prevent, detect and investigate fraud, abuse and misuse of the Service and rewards.
  • To deliver rewards for verified Tier 1 reports.
  • To provide support and maintain, secure and improve the Service.
  • To comply with the law and respond to lawful requests.

We do not sell your personal data, and we do not use it for third-party advertising.

5. Our lawful bases (NDPA 2023)

We rely on one or more of the lawful bases recognised under the NDPA, depending on the processing:

  • Consent—for example, creating an account, featuring a consenting individual in a Tier 3 recognition report, or non-essential website cookies.
  • Legitimate interests—verifying reports, preventing abuse, and advancing public safety and accountability, balanced against your rights.
  • Public interest—supporting road safety and civic accountability.
  • Legal obligation—where the law requires us to retain or disclose information.

[Counsel to confirm the exact lawful basis for each processing activity, and any conditions for processing sensitive personal data, against the NDPA and current NDPC guidance.]

6. When we share data

We share data only as needed to run the Service and as described here:

  • Relevant authorities and oversight bodies—verified reports are routed or forwarded according to their tier, such as a road-safety or infrastructure agency for Tier 1, an oversight body for Tier 2, or a competent authority such as NAFDAC or the Police for Tier 4.
  • Service providers (processors)—trusted vendors who host, secure or help verify data under contract and on our instructions.
  • Partners—organisations that receive verified reports or aggregated, non-identifying road-risk information, consistent with the tier and this policy.
  • Legal and safety—where we are lawfully required to disclose, or to protect people from harm.
  • Business transfers—if the Service is reorganised or transferred, subject to this policy.

7. International transfers

Some of our service providers may process data outside Nigeria. Where that happens, we use appropriate safeguards for the transfer.

[Counsel to confirm the transfer mechanism and any adequacy/NDPC requirements.]

8. How long we keep data

We keep personal data only for as long as needed for its purpose and to meet legal, evidentiary and record-keeping obligations. Retention varies by tier and context. When data is no longer needed, we delete it or irreversibly anonymise it.

[Specific retention periods per data category and tier to be set with counsel.]

9. How we protect data

We use technical and organisational measures appropriate to the sensitivity of data, including encryption in transit and at rest, tamper-evident capture hashes, default face-blurring, access controls and human review before reports move. No system is perfectly secure, but we work to protect data and respond quickly to incidents.

10. Your rights

Subject to the NDPA and its conditions, you have rights over your personal data, including:

AccessA copy of the personal data we hold about you
RectificationCorrect data that is wrong or incomplete
ErasureAsk us to delete data where the law allows
Restriction & objectionLimit or object to certain processing
PortabilityReceive certain data in a portable format
Withdraw consentWhere we rely on your consent, at any time

To exercise a right, contact us at privacy@crowdeye.ng. We may need to verify your identity, and some rights have limits—for example, where keeping data is required by law or for the integrity of an ongoing report. You also have the right to lodge a complaint with the Nigeria Data Protection Commission.

[Counsel to confirm the exact rights and any statutory exemptions under the NDPA.]

11. Children

CrowdEye is not directed at people under 18, and you must be 18 or older to use it. We do not knowingly collect data from children. Content that sexualises, endangers or exploits a minor is prohibited and will be reported to the authorities. If you believe a child has given us data, contact us and we will act to remove it.

12. Cookies & the website

The crowdeye.ng website uses cookies and similar technologies that are strictly necessary to run and secure the site, and—with your consent—optional analytics to understand how the site is used. You can manage non-essential cookies through the site’s cookie controls.

13. Data breaches

If a personal-data breach occurs, we will assess it and, where required by the NDPA, notify the Nigeria Data Protection Commission and any affected individuals.

[Counsel to confirm the applicable notification timeline under the NDPA.]

14. Changes to this policy

We may update this policy as the Service or the law evolves. We will change the “Last updated” date above and, for material changes, take reasonable steps to notify you.

15. Contact & complaints

For any privacy question or to exercise a right, contact our Data Protection Officer at dpo@crowdeye.ng or privacy@crowdeye.ng. You may also contact the Nigeria Data Protection Commission (NDPC) with a complaint. See also our Terms of Use.

See also our Terms of Use.