Privacy Policy — CouldBeTheOne
Draft, not legal advice. Written to match the actual data this codebase collects and stores (see `docs/prd.md` and `prisma/schema.prisma`). Given the audience includes 13–17 year-olds, get real legal review before launch — including whether any additional youth-privacy notice or consent flow is required in the markets you launch in, beyond the self-declared age gate and ToS clause this product currently implements.
Last updated: [fill in on launch]
What we collect
From Google sign-in: your email address, and a provider account ID (used only to recognize you on future sign-ins — we don't request or store your Google password).
What you give us directly: your handle, bio, up to 3 social links, your age band (13–17 / 18–25 / 26+ — never shown publicly, used only to apply the right defaults for younger users), your answers to 10 (or, in Together mode, 20) profile questions, and an avatar photo if you upload one.
Generated from your activity: match results when someone tests your profile or you complete a Together session (the match percentage and the answer-by-answer breakdown), and, if you opt in, a browser push subscription so we can notify you when someone tests your profile.
If you report someone or get reported: the report reason, any details you add, and who filed it (visible only to us, never to the reported user).
What we don't collect
We don't display your exact age or precise location anywhere, and we don't have a feature that collects either.
How we use it
To run the app: rendering your profile, running the matching logic, generating shareable result images, and sending you a push notification if you've opted in. We also send basic product-usage events (profile published, test completed, share-card exported, Together session completed) to our analytics provider so we can tell what's working — these events do not include your bio, answers, or match content, just that the action happened.
Where it's stored
Profile data, answers, and results live in our PostgreSQL database. Avatars and generated share-card images are stored in Cloudflare R2. Both are only as secure as the infrastructure they run on — see our security practices for specifics if asked.
Who can see what
- Your public profile (handle, bio, links, avatar, your 10 answers) is visible to anyone with your link.
- Individual test results are private to the person who took the test. You (the profile owner) only see an aggregate count and average match percentage, and only if you've turned that on in Settings — never who tested you, unless they choose to reveal themselves.
- Together mode results are visible to both participants once both have answered.
Your choices
- You can change your handle at any time (this invalidates your old public link).
- You can turn profile-tester-stats visibility on or off at any time.
- You can turn push notifications on or off at any time.
- You can request that we delete your account and associated data by contacting us.
Minors
We allow 13–17 year-olds to use the app with the same public-link model as adults, per our age-gate design (see `docs/prd.md` Sec 9). We do not have a separate guardian-consent flow beyond the self-declared age gate and Terms of Service acknowledgment at sign-up — flagged in the engineering plan as something to revisit with legal counsel before launch, especially regarding the decision to allow real photo uploads for all ages.
Contact
[fill in a real contact/support address before launch]