Privacy Policy
What we collect, why, how long we keep it, and what you can ask us to delete.
Placeholder
[LEGAL REVIEW REQUIRED — do not launch with placeholder text]
This page has no legal effect. It must be replaced with text written or approved by a qualified attorney before the site accepts a single real member.
What the attorney needs to cover
This outline describes how the system actually behaves, so the drafting starts from facts rather than a template.
- CONSUMER HEALTH DATA — the highest-priority item. This service records whether a member has received a Covid-19 vaccination. Washington’s My Health My Data Act treats this as consumer health data, requires separate opt-in consent, and gives individuals a private right of action. Nevada’s SB 370 is similar. HIPAA does not apply, as this is not a covered entity.
- GDPR Article 9 treats the same field as special-category data, requiring explicit consent and a lawful basis, from the moment any member signs up from Europe.
- How that field is stored: in a dedicated, access-controlled table separate from the general profile, readable only by the member it belongs to, and never transmitted to any other member through any feature of the product.
- Consent for that field is captured on its own screen, separately from the general terms, and recorded with a version and timestamp.
- Identity verification: Stripe Identity performs the ID and selfie check. This service stores only a status and a boolean for being 18 or over. It never stores or receives the document image, document number, extracted date of birth, or selfie.
- Photos are scanned by a third-party moderation provider (Sightengine) before publication. Describe that transfer and its purpose.
- Location: the app never requests device GPS. Members type a city, and only the geocoded centre of that city is stored. Distances shown to other members are rounded and never displayed as closer than one mile.
- Phone numbers are stored only as a keyed one-way hash, used to detect reuse across accounts. IP addresses in consent records are likewise hashed, never stored in readable form.
- Deletion: what is permanently destroyed (login, photos, profile text, the health field, phone hash, likes), what is anonymised instead (messages sent to other members, so the other person keeps their own conversation history), and what is deliberately retained and why (moderation audit log, open abuse reports, banned-device records, and Stripe payment records required for tax purposes).
- Cookies and session storage, and the absence of third-party advertising or tracking.
- Data processors used: Supabase, Vercel, Stripe, Sightengine, Twilio, Resend, Sentry.
- How a member exercises access, correction, deletion and portability rights, and the response window.