Privacy Policy
Last updated: 2026-07-31
This Privacy Policy explains how [COMPANY/LEGAL NAME] ("we", "us") collects, uses, and shares information when you use the DateTrails mobile app and this website (the "Service"). You acknowledge it when you create an account; it forms part of the Terms of Service.
Information we collect
- Account information — email address and, if you use Google Sign-In, your Google account name and profile photo. Authentication is handled by Supabase.
- Agreement records — when you create an account we record that you confirmed being 18 or older and that you accepted the Terms of Service and this Privacy Policy, together with the time and the document version accepted. We store these attestations instead of your date of birth — no birth date is collected.
- Content you create — date itineraries, stops, descriptions, photos you upload, ratings, saved/completed lists, and profile details (display name, bio, avatar).
- Location — with your permission, your approximate or precise device location, used to show nearby dates and sort by distance. Your coordinates are sent to our servers to run the nearby search but are not stored there; the only stored coordinates are the ones you explicitly add to a date's stops. You can use the Service without granting location access; distance features are then unavailable.
- Photos — images you choose from your library or camera to add to dates. Embedded photo metadata (such as the GPS location and timestamp your camera writes into the file) is removed before upload.
- Support messages — if you contact us through Settings → Contact support, we store the topic you chose, your subject and message, the reply-to address you give us, and three technical details attached automatically so we can help: your app version, your device platform (e.g. Android or iOS), and your account ID. These are shown to you on the form before you send. We use them only to answer you and to fix the problem you reported.
- Device & usage data — basic device information and, if enabled, crash/diagnostic data (via Sentry).
- Advertising identifier — for users on the free tier we show personalized ads via Google AdMob, which uses your device advertising ID and ad-interaction data to select ads. On iOS this happens only if you allow it in the App Tracking Transparency prompt; declining (or limiting ad tracking in your device settings) gets you non-personalized ads instead.
- Purchase entitlements — if you subscribe to Premium, our payment provider (RevenueCat, with the App Store / Google Play) processes the purchase and shares subscription status with us. We never see your payment card details.
How we use information
- To provide and operate the Service (accounts, content, maps, search).
- To show relevant date ideas and sort by distance.
- To display ads (personalized where permitted) to free-tier users and to offer/manage subscriptions.
- To keep the Service safe. We moderate content in two ways: (1) proactively — when you publish or edit a date, the photos and text you submit are automatically scanned by third-party safety classifiers (Google Cloud Vision for images; OpenAI, or Google Perspective as a fallback, for text) to detect content that violates our rules, such as sexual, exploitative, violent, or otherwise objectionable material; and (2) in response to user reports. Automated systems may hide or remove content and restrict, suspend, or terminate accounts; when a scan detects an urgent safety concern (such as suspected child sexual abuse material) or an auto-hide occurs, an alert email is sent to our operators (delivered via Resend). We also use information for blocking, abuse prevention, and 18+ enforcement.
- To keep evidence of the agreements you accepted (age attestation, terms/privacy acceptance and version).
- To diagnose crashes and improve reliability.
Legal bases (EEA/UK users)
The Service is currently offered in the United States. Where GDPR (or UK GDPR) applies, we process your data on these bases: performance of a contract (providing the Service you signed up for); legitimate interests (safety and moderation, abuse prevention, crash diagnostics); consent (device location and photo access, and personalized advertising — withdrawable any time in device settings); and legal obligation (retaining records we are required to keep, including acceptance records).
Third-party services
We use: Supabase (authentication, database, storage; hosted in [SUPABASE PROJECT REGION]), Google Maps / Places (maps and location search), Google AdMob (advertising, free tier), Sentry (crash reporting, if enabled), and RevenueCat with the App Store / Google Play (subscription management). For safety and content moderation we additionally use: Google Cloud Vision (automated image safety scanning of the photos you publish), OpenAI and/or Google Perspective (automated text safety scanning of the text you publish), and Resend (delivery of operational safety-alert emails to our operators, and of the support messages you send us through the app so they reach our inbox). Each processes data under its own privacy policy, as our processor or as an independent controller as applicable.
Sharing
We do not sell your personal information for money. To show personalized ads to free-tier users, Google (our advertising partner) receives your device advertising identifier and ad-interaction data; under some laws (e.g. the California CCPA/CPRA) this may be considered "sharing" for cross-context behavioral advertising. You can opt out at any time — see "Your choices & rights" below. Content you publish (itineraries, public profile) is visible to other users. We also share data with the service providers above as needed to run the Service, in connection with a merger or sale of assets (your data remains subject to this policy), and where required by law or to protect users' safety.
International transfers
Our service providers may process data outside your country, including in the United States. Where required (e.g. for EEA/UK data), transfers rely on appropriate safeguards such as Standard Contractual Clauses. [ATTORNEY/OPS: confirm the transfer mechanism for each processor.]
Your choices & rights
- Delete your account in-app (Settings → Delete Account) or via our account deletion page. Deletion removes your account, created content, and uploaded photos.
- Control location and photo permissions in your device settings; the app continues to work without them.
- Opt out of personalized ads: on iOS, decline the tracking prompt (or Settings → Privacy & Security → Tracking); on Android, Settings → Google → Ads → delete or reset your advertising ID / opt out of ads personalization. You will still see ads, just not personalized ones.
- Depending on where you live, you may have rights to access, correct, delete, or port your data, to object to or restrict certain processing, and to withdraw consent (EEA/UK under GDPR), or to know, delete, correct, and not be discriminated against for exercising your rights (California under CCPA/CPRA). Contact us at the address below to exercise them; we will verify your request via your account email. You may also lodge a complaint with your local data-protection authority.
Do Not Sell or Share My Personal Information
We do not sell your personal information for money. However, to show personalized ads to free-tier users, Google (AdMob) receives your device advertising identifier and ad-interaction data, which under the California CCPA/CPRA (and similar state laws) may be treated as "selling" or "sharing" for cross-context behavioral advertising. You can opt out of this:
- In the app: use the "Do Not Sell or Share My Personal Information" toggle in Settings. Turning it on switches your device to non-personalized ads.
- On your device: on iOS, decline the App Tracking Transparency prompt (or Settings → Privacy & Security → Tracking); on Android, Settings → Google → Ads. Because DateTrails is a native mobile app, the in-app "Do Not Sell or Share My Personal Information" toggle above is the opt-out mechanism we honor.
Opting out does not remove ads — you will still see ads, just not personalized ones. We do not knowingly sell or share the personal information of anyone, and the Service is 18+ only.
Data retention
We keep each category of information only as long as we need it for the purpose it was collected, then delete or de-identify it. The table below summarizes our retention periods; where a period is bracketed, it is set by our operational and legal requirements.
| Category | Retention |
|---|---|
| Account & profile (email, display name, bio, avatar) | Kept for the life of your account; deleted when you delete your account. |
| User content (dates, stops, descriptions, photos, ratings, saved/completed lists) | Kept until you delete the individual item or your account (whichever comes first). |
| Moderation scan results, safety-alert records, and reports (filed by or about you) | Retained for a fixed safety-record period of [RETENTION PERIOD—counsel] after they are created, then deleted — even if it outlasts the related account, to keep an audit trail of safety actions. |
| Support messages and the diagnostics attached to them (app version, platform, account ID) | Kept for the life of your account and deleted when you delete your account. Unlike safety records, support correspondence is ordinary correspondence and is not retained beyond the account. |
| Crash & diagnostic data (Sentry, if enabled) | Retained for the Sentry data-retention window [SENTRY RETENTION WINDOW], then automatically purged. |
| Legal-acceptance & age-attestation records (terms/privacy version accepted, 18+ confirmation, timestamps) | Deleted with your account row; we may retain minimal evidence where the law requires or permits it for the establishment, exercise, or defense of legal claims. |
| Backups | Deleted content persists in encrypted backups for up to [BACKUP WINDOW], after which it is overwritten on our normal backup cycle. |
Subscription records held by the app stores and our subscription processor (RevenueCat) are retained under their own policies; RevenueCat's own customer record for your purchases persists there even after you delete your DateTrails account.
Security
We protect your data with industry-standard measures — encrypted connections (TLS), access controls, and row-level security on our database so users can only read what they are authorized to see. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify you and the relevant authorities as required by law.
Children
The Service is for adults only and is not intended for anyone under 18. Every account must affirm being 18 or older at sign-up, and we do not knowingly collect data from anyone under 18. If we learn (through automated moderation, a report, or otherwise) that a user is or may be under 18, our operators can suspend and terminate the account and delete its data; contact us if you believe a minor is using the Service.
Changes to this policy
We may update this policy. Each version is identified by its "Last updated" date above. For material changes we will provide notice in the app before the changes take effect.
Contact
[COMPANY/LEGAL NAME], [ADDRESS] — [email protected]. See our contact page for the right route by topic, or use Settings → Contact support in the app.