Skip to content

Privacy policy

Version [version number] — effective [date]. DareCrush, a dating app built on real, physical encounters detected over Bluetooth.

Document to be finalized before going live. This text faithfully describes the processing the application actually performs, but it must be checked and completed by legal counsel. The highlighted passages remain to be settled.

1. Who is responsible for your data

The data controller is Philippe LeblondTechnologies DareCrush inc., [registered office address].

For any privacy question, to exercise your rights, or to reach the person responsible for the protection of personal information, write to philippe@leblond.info [confirm the “privacy” contact address to publish, and the name of the responsible person].

Your data is hosted in the region matching your country of residence. For Canada, it is hosted in Quebec, in Montreal, and falls under Quebec's Act respecting the protection of personal information in the private sector (Law 25) and under PIPEDA.

2. The data we collect

Sign-in identity

Your email address and your phone number, both verified by a code, plus a password. Identifiers are encrypted in our database — for lookups we keep only a one-way fingerprint. The password is kept only as a hash, never readable.

We do not ask for your real name, your date of birth, or your postal address.

Profile

Age, gender, physical attributes (height, weight, glasses, hair colour, and optionally skin colour), description, the contact details you choose to share, up to two photos, and your search preferences. The description is encrypted at rest.

Encounters and location

The fact that an encounter took place, with the other account involved and the timestamp. An approximate location (on the order of a hundred metres) is attached to it only if you gave your location consent, which is revocable at any time. Without that consent, encounters work normally, without a place.

During a safety location share that you start yourself, your live location is sent to whoever holds the link, for the duration you set, and sending stops automatically at the deadline.

Activity

Likes, matches, contact requests, favourites, blocks, reports, and message metadata (who, when, which match) — never their content, see section 7.

Technical

A device identifier used to send you notifications, and pseudonymous diagnostic data that you can switch off and erase, and that is never contributed to an investigation.

We do not keep your IP address in your profile, not at sign-up, not at each encounter. Two bounded exceptions, solely for the security of your account: the IP address of each sign-in is attached to the session it opens — it is what feeds your “active sessions” list and the “new sign-in” alert, with an approximate location — and disappears with the session; and, when an account is deleted, the address of the deletion request is kept for a bounded time in a separate investigation record (section 6).

Support

If you write to our support, from the app or from the website: the subject you chose, the identifiers of the account concerned, and the email address or number to reply to — encrypted in our database — plus, from the app, the app version and device model. The form has no free-text field.

What we do not collect

Not your real name, not your date of birth, not your postal address, not your contact list, not your browsing history, not your advertising identifier, not your banking details — payments are handled by the app store, never by us.

3. What Bluetooth carries

Encounter detection relies on Bluetooth alone, never on GPS. Your device broadcasts an encrypted sixteen-byte beacon, renewed every fifteen minutes, that only our server can resolve.

No profile data, no photo, no account identifier and no geographic coordinate travel over the radio. A third-party device picking up these beacons could neither identify you nor establish that two successive beacons came from the same phone.

The raw observations your phone reports are destroyed as soon as they are processed; only the encounter remains.

4. Why, and on what basis

We process this data to:

  • provide the service — show you the people you genuinely crossed paths with, handle likes, matches and messages, apply your search preferences;
  • keep people safe — reports, moderation, location sharing, cooperation with authorities on valid legal requests;
  • improve the app — technical diagnostics you can switch off.

The legal basis relied on is [contract, consent, and legitimate interest for safety — allocation to be specified by counsel according to the jurisdiction]. Sensitive data (section 5) rests solely on your consent.

5. Sensitive data

A dating app inherently processes data capable of revealing sexual orientation (your search preferences). Skin colour, which is optional, can reveal ethnic origin.

This data is processed only with your explicit and separate consent, collected and dated at sign-up, and revocable. You can decline to provide skin colour: the app works without it.

No biometric data is processed today. The selfie-based identity verification feature is not switched on. [If automated facial comparison were switched on, it would constitute biometrics and would require specific consent as well as the applicable formalities — notably prior notice to Quebec's Commission d'accès à l'information.] If it were, the selfie would not be kept, no faceprint would be created, and only the result of the comparison would be stored.

6. How long we keep it

Data Retention period
Encounter that goes nowhere (visible in the app) 24 hours (free account) or 7 days (paid plan), then automatic expiry
Encounter stored server-side 180 days
Approximate location of an encounter 6 months
Delivered encrypted message 30 days on our servers (the archive stays on your phone)
Undelivered encrypted message 90 days
Heatmap data (aggregated) 180 days
Sign-in session (device, IP, approximate city) Until the session expires or is revoked
Account created but never verified 48 hours, then erased
Closed support request 1 year
Investigation record after account deletion 6 months
File related to child safety 365 days, then destruction
Profile, photos, contact details Life of the account; genuinely erased on deletion

When you delete your account, your profile — description, contact details, attributes, preferences, photos — is genuinely erased, the image files are destroyed, and your sign-in identifiers are released. Any location share in progress is cut off.

A minimal investigation record — your sign-in identifier (encrypted), the last known location of a meeting, and the IP address of the deletion request — is placed in a separate, access-restricted store, kept for six months and then automatically destroyed. It exists only to answer a valid legal request from authorities following an incident.

7. Messages: end-to-end encryption

Your messages are encrypted end to end: we cannot read them. The key that decrypts them stays in your phone's hardware keystore and is never sent to our servers, which store only an opaque encrypted block.

Faced with a demand from authorities, we can provide metadata — who wrote to whom, and when — never the content.

A practical consequence: if you lose access to your device, your conversation history is permanently gone. We cannot restore it.

8. Who it is shared with

We do not sell your data and do not share it for advertising purposes. We rely on technical providers who process certain data on our behalf, each bound by a written data protection agreement [agreements to be signed before launch]:

Provider What it processes Where
Amazon Web Services Hosting of servers, database and photos; sending email Canada (Montreal)
Cakemail Delivery of our emails: codes, security alerts, receipts Canada (Montreal)
Swift SMS Gateway Delivery of verification codes by text message Canada, outside Quebec
Twilio (fallback) Text delivery if the primary provider is unavailable United States
Amazon Rekognition Automatic analysis of each photo on upload, to screen out nudity and violence. Only the image is sent, without your identity, and it is not retained United States
Google Firebase Cloud Messaging Notification delivery, deliberately opaque: an event type and an identifier, with no content and no dating activity United States
Google Play (and Apple, in future) Billing and validation of your subscription United States
Our own diagnostics server Pseudonymous technical reports, unless you switched them off. Never a third party Quebec

Transfers outside Quebec have been the subject of a privacy impact assessment and are governed by contractual data protection commitments [assessment to be validated by legal counsel].

We may disclose data to authorities on a valid legal request. We are legally required to report any child sexual exploitation content.

Advertising

Paid plans carry no advertising. If advertising were shown to free accounts, it would be non-personalized: we would pass the ad network neither your location, nor your profile, nor your account identifier. [Advertising is not enabled at this time — remove or activate this paragraph depending on the state of the service at publication.]

9. Your rights

At any time, you can:

  • Access your data and obtain a complete copy — “Download my data”, in the app's settings or on the “My account” web portal.
  • Correct your information by editing your profile.
  • Withdraw a consent — location, sensitive data, re-encounter alerts — one at a time, without losing access to the service.
  • Delete your account, from the app or from the web portal, even after uninstalling the app.
  • Switch off and erase diagnostic data.

Depending on where you live, you may also have rights to portability, to object, to restrict processing, and to be informed of an automated decision.

If our answer does not satisfy you, you can complain to the competent authority: in Quebec, the Commission d'accès à l'information; [elsewhere: applicable supervisory authority to be specified — the CNIL or another EU authority, the ICO in the United Kingdom, etc.].

10. Security

Exchanges with our servers are encrypted in transit (HTTPS). Your messages are end-to-end encrypted; your sign-in identifiers and private fields are encrypted at rest; the authentication token is stored encrypted on your device. Passwords known to have been publicly breached are refused at sign-up.

No system is infallible. In the event of an incident presenting a serious risk, we will inform the people concerned and the competent authority within the timeframes set by law.

11. Age

The app is restricted to people 18 and over. We do not knowingly collect data from minors. Any account suspected of belonging to a minor is frozen and reviewed.

12. Changes

We may amend this policy; the current version is shown at the top. In the event of a substantial change, we will ask you to accept it again in the app.

See also our terms of use. For any question, write to us. This English text is a translation of the French version. [Counsel to confirm which language version governs.]