Effective: August 4, 2026·Last Updated: September 19, 2026
Addiyon ("we", "our", or "us") runs a classifieds marketplace in Ethiopia, available at addiyon.com and as an Android app. This policy describes exactly what information the marketplace collects, why we collect it, who processes it on our behalf, and how you can delete it. It applies to both the website and the app.
Account information. Your name, email address, phone number, and an optional Telegram username. If you register with a password we store only a salted hash of it; if you sign in with Google or Facebook, we receive the provider account identifier, name, email address, and profile picture made available by that provider. If you use Telegram phone verification, we receive your Telegram account identifier and the profile details Telegram makes available, such as your name, username, and profile picture. We receive your Telegram-verified phone number only when you choose to share it for verification. You may upload a profile photo.
Listings you post. Title, description, category, price, item attributes, the locality you select from our list, the contact details you choose to publish, and the photos you upload.
Marketplace activity. Saved listings, sellers you follow, sellers you block, listings you view, searches you run, and your notification preferences and read status. Google Analytics also measures page or normalized app-screen views, sessions, app lifecycle events, and page or screen engagement. The mobile integration does not send route parameters, listing or seller IDs, search text, contact details, or an Addiyon account identifier to Google Analytics. We increment an aggregate popularity score when a listing is opened and aggregate search terms for the Popular searches list; neither is a per-user history.
Safety and moderation records. Reports you submit about a listing or a seller, the reason and details you provide, a snapshot of the reported content, and the outcome of our review.
Job applicant information. If you apply for a role, we collect your name, email address, optional phone number and professional-profile link, the note you provide, your PDF resume, the position, and application status. Applicant information is kept separate from public marketplace listings and is not published.
Device and technical information. IP address, request logs, app/device details, Firebase and Crashlytics installation IDs, Google Analytics browser client or mobile app-instance ID, push notification token, Play Integrity results, crash diagnostics, and coarse location derived by Google Analytics from a masked IP address. When mobile advertising is enabled, Google Mobile Ads also processes ad-request, device/app, Android Advertising ID when available, and ad-view or interaction information needed to select, deliver, secure, limit, and measure ads. Where allowed, AdMob may share the full IP address with eligible buyers as an auction-quality signal.
On-device storage. The app keeps a local cache of public marketplace content so browsing stays fast and works during brief connectivity loss. Your session identifier is held in the device's encrypted secure storage. The website may store a first-party Google Analytics identifier in your browser.
To be explicit, and in contrast to what a generic marketplace policy might claim, the app does not collect or process any of the following:
Every listing is screened automatically before it goes live. The listing's title, description, and photos are sent to third-party AI providers that classify prohibited or unsafe content, and we compare short numeric fingerprints of listing photos against other listings to detect duplicate reposts. A listing may be rejected by this process, and the stored rejection reason explains why. Administrators can review these decisions. This screening applies to listing content only; it is not applied to your account details, and it is not used to profile you.
Listings are public by design. Your listing content, the locality you selected, your seller display name and profile photo, and any contact details you chose to publish are visible to anyone using Addiyon, including people who are not signed in, and may be indexed by search engines. Your email address, password, session data, saved listings, followed and blocked sellers, and the reports you submit are never published. Job applications and resumes are also never published. Do not put information in a listing that you do not want to be public.
Google Play defines collection as data sent off your device, including data sent to processors that operate services for us. Under that definition, the Android app collects the categories below. Optional means you can use the marketplace without providing that category; required means the relevant collection has no in-app opt-out.
We do not use account details, searches, saves, follows, blocks, contacts, or listing-submission data to target ads. Section 6 describes the limited advertising surfaces and the providers involved. The Play Data Safety form for an ads-enabled release must match Google's current Mobile Ads SDK disclosure and the app's actual configuration.
We do not sell or rent the personal information tied to your Addiyon account, or give that account information to advertisers for their own marketing. Eligible website pages may use advertising cookies and similar technologies, and eligible Android marketplace screens may display ads, as described below. When you publish a listing, its public fields are deliberately made available to other users as explained in section 5.
The following providers receive only the information needed to operate services for us and process it on our instructions:
Google Play applies specific definitions to collection, sharing, service providers, and user-directed public disclosures. The Data Safety label for an ads-enabled release is completed from the current Google Mobile Ads and other SDK disclosures rather than inferred from those labels alone. We may also disclose information when legally required or necessary to protect users, rights, safety, or property.
The Android app requests only what it needs: network access, notification delivery if you allow it, and a short vibration for alerts. Choosing photos uses the Android system photo picker, which shares only the images you pick and requires no permission. You can change or withdraw the notification permission at any time in Android settings; the rest of the app keeps working if you do.
All traffic between the apps and our servers uses HTTPS. Passwords are stored only as salted hashes, sessions are server-side and revocable, the session identifier is kept in the device's encrypted secure storage, and the app attaches a Firebase App Check attestation that our servers verify to tell genuine app installs from other traffic. Uploaded images are validated, re-encoded, and stored under server-generated filenames. Access to production systems is restricted. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
You can permanently delete your account from the app, on the Account screen, or from our account-deletion page, which also offers a verified support route if you cannot sign in.
Without deleting your account, you can directly delete your listings, unsave listings, unfollow or unblock sellers, and change notification preferences using the app or website. We do not currently offer a separate public request process for selective data deletion; the account-deletion page is for deleting the complete account.
Deletion removes your profile, sign-in methods, sessions, listings and their media, saved and followed data, blocked-seller records, notifications, preferences, and device tokens. Media deletion is durably queued and retried if storage is temporarily unavailable. Reports and moderation evidence may be retained for safety, fraud prevention, legal compliance, and disputes; structured account, contact, and media identifiers are removed from those retained snapshots. Server logs are kept for a limited period for security and operations. Backup copies age out through our normal backup lifecycle and are not used except for disaster recovery. Aggregate listing-view scores and popular-search counts are not maintained as per-user histories. We do not link the mobile Google Analytics app-instance ID to your Addiyon account, so account deletion does not identify and remove pseudonymous Analytics events or aggregate reports. Event-level Analytics data follows the retention setting configured for our Google Analytics property.
Job applications and privately stored resumes are scheduled for deletion after 12 months unless a shorter period is requested or a longer period is required for an active hiring process, employment, legal compliance, or a dispute. Applicants can contact us using the details below to ask about or request deletion of their application.
Addiyon is intended for adults. Our Terms of Service require you to be at least 18 years old to create an account or post a listing. We do not knowingly collect personal information from children, and we delete such an account if we learn it exists.
We operate in Ethiopia, and some of the providers listed in section 6 process data on servers outside Ethiopia. Where that happens, the information is handled under those providers' contractual commitments to us.
We may update this Privacy Policy. If we make material changes, we will update the "Last Updated" date above and, where appropriate, notify you in the app.
For privacy questions or requests, contact us: