Legal

Privacy Policy

Effective June 26, 2026·Draft — pending legal review

This Privacy Policy explains how Crush Inc. ("CRUSH," "we," or "us") collects, uses, and protects your information when you use the CRUSH platform.

1. Information We Collect

Information you provide

  • Account information: email address, phone number (hashed), password (bcrypt)
  • Profile information: display name, age, photos, bio, icebreaker responses
  • Messages and voice notes sent through the Service
  • Payment information (processed by Stripe — we never store card numbers)
  • Reports and support tickets you submit

Information collected automatically

  • Location data — GPS coordinates collected when you use the map. Your exact coordinates are never stored in plaintext. Coordinates are fuzzed server-side within your chosen radius (minimum 200 m) before any client receives them.
  • Device type, browser, operating system, and IP address
  • Usage events: pages visited, features used, session duration
  • Trust score signals (report history, spam patterns)

Third-party sign-in

If you sign in via Google, Apple, or Facebook, we receive basic profile information (name, email) from that provider. We do not receive your social media password.

2. How We Use Your Information

  • To operate the Service and display your profile to nearby users
  • To enable messaging and voice notes
  • To verify your phone number via OTP
  • To process subscription payments through Stripe
  • To detect and prevent abuse, spam, and prohibited content
  • To send transactional emails (account verification, password reset, receipts)
  • To improve the Service using aggregated, de-identified analytics
  • To comply with legal obligations

3. Location Data — Special Protections

  • Raw GPS coordinates are never stored in our primary database.
  • Only the fuzzed coordinate (within your chosen radius) is persisted.
  • Location data is automatically purged after 5 minutes of inactivity.
  • We do not sell location data to data brokers or advertisers.
  • Law enforcement location requests require a valid legal process.

4. Sharing Your Information

We do not sell your personal data. We share data only with:

  • Other users — fuzzed location, public profile info, and messages you send
  • Stripe — payment processing
  • Cloudinary / Cloudflare R2 — photo storage and delivery
  • Twilio — phone OTP delivery
  • Resend — transactional email delivery
  • Sentry — error monitoring (no PII in error payloads)
  • NCMEC — mandatory reporting of CSAM under 18 U.S.C. § 2258A
  • Law enforcement — when legally compelled by valid process

5. Data Retention

  • Active account data is retained while your account is open
  • Deleted account data is purged within 30 days
  • Message content is deleted when both parties delete the conversation
  • Payment records retained for 7 years for tax compliance
  • Abuse reports and CSAM-related records may be retained indefinitely

6. Your Rights (CCPA / CPRA)

California residents have the right to:

  • Know what personal data we collect and how we use it
  • Request deletion of your personal data
  • Opt out of sale or sharing of personal data (we do not sell data)
  • Correct inaccurate personal data
  • Non-discrimination for exercising these rights

To exercise these rights, email privacy@crush.app. We will respond within 45 days.

7. Security

We use industry-standard security: TLS 1.3 in transit, AES-256 at rest, httpOnly cookies for auth tokens, rate limiting on all endpoints, and regular security audits. If you discover a vulnerability, report it to security@crush.app.

8. Children

CRUSH is strictly for users 18 and older. We do not knowingly collect data from anyone under 18. If we discover a user is under 18, the account is terminated immediately. Contact safety@crush.app to report a suspected minor.

9. Contact

Privacy questions: privacy@crush.app · Crush Inc., Delaware, USA.