Privacy Policy
Draft v0.1 · pending counsel review
HUSH — PRIVACY POLICY
DRAFT v0.1 — NOT YET REVIEWED BY COUNSEL
The honest version first: we built Hush so that the most private thing you do here — what you share with another person — is also the thing we keep least. Below is exactly what we collect, why, and when it dies.
1. WHAT WE COLLECT
· Account: phone number (login + one-account-per-human), chosen display name, birthday (to verify age — never shown to anyone as a date).
· Verification: our independent verification partner processes a liveness selfie and, if needed, a government ID. WE NEVER RECEIVE OR STORE YOUR FACE SCAN OR ID — we receive only a signed confirmation ("verified adult, date"). See Section 3 (Biometric Data).
· Profile: what you choose to share — photos, bio, preferences, filters.
· Location: your device's location is converted ON YOUR DEVICE into an approximate zone (about a 3-mile cell). Your precise coordinates are never transmitted or stored. Other users see distance bands only.
· Messages and media: content you send, and metadata (who, when, what type). Media is machine-scanned before delivery (Section 4).
· Purchases: handled by Apple/Google; we receive entitlement status, never card numbers.
· Device and usage data: crash reports and product analytics.
2. THE BURN SCHEDULE — WHAT "DELETED" MEANS
Chats expire and media burns as shown in the app; burned content is immediately unavailable to all users. Server-side, media enters an encrypted SAFETY HOLD FOR 30 DAYS (so recipients can report abuse even after burning, and so illegal content can be preserved for authorities), then is permanently destroyed. What outlives the pixels: content fingerprints (hashes), scan results, and sender/recipient/time records — kept to stop banned content and banned people from returning.
3. BIOMETRIC DATA (Illinois BIPA and similar laws)
Age and liveness verification involves biometric processing performed by our verification partner, with your explicit consent captured in the app at the moment of the check. The partner's retention schedule and policy: [link — COUNSEL + vendor contract]. Hush itself never possesses or stores biometric identifiers. You may not use Hush without verification.
4. SAFETY ACCESS — WHO CAN SEE YOUR CONTENT
Every upload is scanned automatically against illegal-content databases and safety classifiers before delivery. Authorized safety personnel may review content and account activity for safety and legal compliance — including content routed by automated systems, reported by users, or sampled for quality of our safety systems. EVERY HUMAN ACCESS IS RECORDED in a tamper-evident log, including access by company leadership. The other person in your chat can never keep, forward, or export your content.
5. WHO ELSE TOUCHES DATA (processors)
Supabase/AWS (hosting, us-east-1), our verification partner, Apple/Google and RevenueCat (billing), Sentry (crashes), PostHog (analytics). Each is bound by contract to use data only to provide their service. WE DO NOT SELL OR SHARE YOUR PERSONAL DATA for advertising. No ad networks.
6. LEGAL DISCLOSURES
We disclose data when legally required (subpoena, warrant, court order) and report apparent child sexual abuse material to NCMEC as federal law requires. Law-enforcement guidelines: hushdate.app/legal/law-enforcement.
7. YOUR RIGHTS (California CCPA/CPRA and similar state laws)
Access, correction, deletion, and portability — deletion is built into the app (Settings → Delete account) and is immediate. What survives deletion, under legal obligation, disclosed here: content fingerprints, scan and access logs, your consent/acceptance records, and any content under an active legal preservation. We honor these rights for everyone, not just Californians. Requests: privacy@hushdate.app.
8. RETENTION SUMMARY
Burned media: 30 days (encrypted hold), then destroyed. Chats: deleted at expiry/unmatch. Account data: deleted on account deletion. Hashes, audit logs, acceptance records: retained. Verification confirmation: retained while your account exists.
9. SECURITY
Encryption in transit and at rest; row-level access controls; media deliverable only through short-lived signed links; no public content anywhere in the service. No system is perfect — our breach response plan commits to notifying affected users per state law timelines.
10. CHILDREN
Hush is 18+ only, enforced by verification. We do not knowingly collect data from minors; suspected minor accounts are terminated and reported where required.
11. CHANGES
Material changes require renewed in-app acceptance.
Contact: privacy@hushdate.app