Privacy Policy
Effective: 2026-07-13 · Policy version: 2026-03-stage1
1. Who we are
2. Scope
3. Data we collect
- Account identifiers: email address used to sign in (OTP / magic link via Supabase Auth).
- Profile data: display name, date of birth (age gate: 18+), gender / preferences, bio, work, education, and other fields you choose to provide.
- Media: profile photos (original + server-generated blurred variants), profile audio prompts, and chat voice notes you send.
- Messages & matching: likes, matches, chat text, voice-message metadata (paths/duration), reveal / frozen-match state.
- Location: coarse and/or precise location when you opt in, used for discovery distance.
- Device & push: Expo push tokens and device-related identifiers needed to deliver notifications.
- Safety & moderation: reports you submit, blocks, and related moderation actions.
- Subscriptions: entitlement state synced from RevenueCat (purchase tokens / app user id = your account UUID).
- Diagnostics & analytics: crash/error events (Sentry), product analytics events (PostHog). We configure these to avoid shipping other users' raw UUIDs or unnecessary PII.
- Website deletion request: the email and optional reason you submit on /delete-account. We verify you control that email with a one-time code (Supabase Auth) before recording the request; no bot-protection token is collected on this page.
4. How we use data
- Operate matching, messaging, media reveal, and premium features.
- Authenticate you and secure accounts (including rate limits and disposable-email blocking).
- Moderate content for safety (including automated photo screening and human review queues).
- Send transactional email (OTP, confirmation, safety alerts to our ops inbox).
- Measure product reliability and improve the app (analytics / crash reporting).
- Comply with law (including child-safety reporting obligations).
5. Where data is stored (sub-processors)
| Service | Role | Region / notes |
|---|---|---|
| Supabase | Auth, Postgres, Storage, Edge Functions | Primary app backend (project CUVR-APP) |
| Resend | Transactional email sending | Sending domain cuvr-app.com (ap-northeast-1) |
| RevenueCat | Subscriptions / entitlements | Billing sub-processor; app_user_id = auth UUID |
| Sentry | Crash / error monitoring | user.id = auth UUID; sendDefaultPii disabled |
| PostHog | Product analytics | us.posthog.com; distinct_id = auth UUID |
| Expo / FCM | Push delivery | Push tokens stored on profile |
| Azure Content Safety / Sightengine | Photo moderation signals | Used during upload processing |
| Vercel | This marketing/compliance website | Static pages + form posts to Supabase |
We do not sell your personal data.
6. Retention
- Active account data (profile, matches, messages, media): retained while your account is active.
- After match ends: chat content associated with a match follows product lifecycle; residual rows are removed when accounts delete or matches cascade.
- Account deletion: in-app / DB cascade removes auth user, profile, matches, likes, messages, subscriptions, blocks, policy acceptances, and storage objects under your folders. Non-PII
account_deletion_auditevidence is retained for ops/compliance. - Sub-processor purge: PostHog / Sentry / RevenueCat copies keyed by your UUID are cleaned up under our ops checklist, targeting completion within 30 days of account deletion (subject to legal/CSAE preservation holds).
- Analytics events: typically retained on the order of ~12 months (product tooling defaults; subject to vendor settings).
- Crash data: typically retained on the order of ~90 days.
- Safety evidence: suspected CSAM/CSAE material may be preserved longer as required by law / NCMEC / law enforcement (see Child Safety page).
7. Your rights (including India DPDP)
Depending on applicable law (including India's Digital Personal Data Protection Act, 2023, where it applies), you may request:
- Access / export of personal data we hold about you
- Correction of inaccurate data
- Erasure / account deletion
- Withdrawal of consent for optional processing (e.g. precise location)
Export (v1): email support@cuvr-app.com from your account email. Self-serve export is planned for a later release.
Deletion: use in-app Settings → delete account, or the public page at /delete-account (no app login required — we email you a one-time verification code to confirm you control the account email, then record the request). Deletion is processed according to our ops workflow and may take time to fully cascade across sub-processors.
8. Children
CUVR is for adults 18+ only. We do not knowingly allow minors. Child Sexual Abuse Material (CSAM) and Child Sexual Abuse and Exploitation (CSAE) are strictly prohibited and reported per our Child Safety standards. Contact safety@cuvr-app.com.
9. Security
Data in transit uses HTTPS. Database and storage are hosted on Supabase with row-level security on user-facing tables. Media buckets are private and accessed via signed URLs. No security measure is perfect; please use a strong email account and report issues to support.
10. Changes
We may update this policy. Material changes will bump the policy version shown in-app (CURRENT_POLICY_VERSION) and may require re-acceptance before profile completion. The public version on this site is the full text.
11. Contact
- Support / grievance: support@cuvr-app.com
- Legal / privacy: legal@cuvr-app.com
- Child safety: safety@cuvr-app.com
India IT Rules 2021 (Intermediary Guidelines) grievance contact: Vedant Choudhary via support@cuvr-app.com — acknowledge within 24 hours; resolve within applicable timelines.