Privacy Policy
On this page
- 1. About SFSocial
- 2. Who we are
- 3. Development status: please read this
- 4. Who this policy applies to
- 5. What we collect
- 6. Special category data
- 7. Why we use your data, and our legal basis
- 8. Matching and automated ranking
- 9. What other people can see
- 10. Who we share data with
- 11. Where your data is stored, and international transfers
- 12. How long we keep data
- 13. Deleting your account, and what happens to your messages
- 14. Your rights
- 15. Security
- 16. Age, and users under 18
- 17. Cookies and similar technologies
- 18. Changes to this policy
- 19. Contact
This policy explains what personal data SFSocial collects, why we collect it, who we share it with, how long we keep it, and what rights you have over it.
We have written it to describe what SFSocial actually does today, not what we plan to build. Where a feature is not yet built, we say so rather than describing it as though it exists.
1. About SFSocial
What it is
SFSocial is a community-first social and dating app for adults. The idea is simple: you meet people through shared interests and public conversation first, and move into private conversations only when both people agree to it.
It is deliberately not a swipe app. There is no endless deck of faces, no public ranking of members, no "hot or not", and no way to see who has looked at you.
How it works
Communities and channels. You join public communities built around topics and interests, and take part in ordinary group conversation there. This is where most meeting happens.
Profiles. A profile is more than photos. It carries your bio, interests, pronouns, country, and optionally the city you are in. You control what is shown.
Consent-based direct messages. You cannot simply message a stranger. You send a request, and the other person can accept, decline, block or report it. Declining closes the request and does not notify the sender. Requests are rate limited, so nobody can ask repeatedly, and blocking stops contact permanently. A conversation only opens when both people want it.
Optional dating and matching. Dating is switched off until you turn it on. If you do, SFSocial suggests one person at a time based on your stated intentions, interests, personality answers and preferences. You can skip anyone, privately, and they are never told.
Safety tools. Blocking, reporting, rate limits and human moderation are built into the product rather than added afterwards.
Why it was made
Most dating apps ask you to judge strangers on a photograph and a sentence, at speed and in volume. That produces a lot of matches and very little context, and it puts the people who are most likely to be harassed in the least protected position.
SFSocial was built on the opposite assumption: that people connect better when there is something shared to connect over, and when contact requires consent rather than persistence. Communities come first, dating is optional, and private contact is something you agree to rather than something that happens to you.
It is also built for adults only, and moderated on the basis that safety is part of the product rather than a feature to add later.
What it is not
- Not free of risk. We do not verify who anyone is. See sections 3 and 16.
- Not finished. See section 3.
- Not advertising-funded. We run no ads and sell no data. There is nothing to pay today; if that changes we will publish the terms first.
2. Who we are
SFSocial is operated by Mohamed Mefjouj, an individual trading as SFSocial (publicly known as Simo Jumpur). There is no company: the service is run by one person, with a small number of volunteers who help with moderation.
For data protection purposes, Mohamed Mefjouj is the controller, meaning the person who decides why and how your personal data is processed.
| Controller | Mohamed Mefjouj, trading as SFSocial |
|---|---|
| Based in | Morocco |
| Contact | privacy@sfsocial.app |
| This policy | https://sfsocial.app/privacy |
| Terms of Service | https://sfsocial.app/terms |
3. Development status: please read this
SFSocial is under active development and is not a finished product. This matters for your privacy, so we would rather be blunt about it than reassuring.
What that means in practice:
- Features change. Parts of the service described here may be altered or removed, and new features will be added. We will update this policy when that happens.
- Data export is handled by email, not by a button. We do not yet have in-app data export; it is available today by emailing privacy@sfsocial.app, and we handle it manually. Account deletion is in the app and runs automatically. See sections 13 and 14.
- Some clean-up processes are still manual. Section 12 says how long we keep each kind of data. Where a routine is not yet running automatically, we remove the data by hand, and always on request.
- Age is self-declared. We ask for your date of birth at signup and require you to be 18 or over, but we do not currently verify it against any document or external source. See section 16.
- Messages are not end-to-end encrypted. They are encrypted in transit, but we can technically access message content stored on our systems. See section 15.
- Not everything has been independently reviewed. This is a small, self-funded project. We have applied the security measures described in section 15, but we have not undergone an external security audit or certification.
If any of this is not acceptable to you, please do not create an account.
4. Who this policy applies to
- Anyone aged 18 or over who uses SFSocial. The service is 18+ everywhere. Where the age of majority in your country is higher than 18, that higher age applies to you.
- All platforms we currently ship: Android, web, Windows and Linux. macOS and iOS are not yet available.
- All features: profiles, communities and channels, group chats, direct messages, matching, reporting and moderation, and notifications.
- People on our launch email list, who may not have an account at all. Section 5K covers what we hold about them.
Definitions
- Personal data: information that identifies you or relates to you, directly or indirectly.
- Processing: anything done with that data, including collecting, storing, using, sharing or deleting it.
- Controller: the person who decides why and how data is processed (us).
- Processor: a company that processes data on our instructions (our suppliers).
5. What we collect
A. Account and identity
| Data | Why |
|---|---|
| Email address | Login, password reset, account and safety notices |
| Password | Stored only as a hash by our authentication provider. We never see or store your plaintext password |
| Date of birth | To apply our 18+ rule. Never shown to other users |
| Age confirmation | A flag recording that you confirmed you are 18+ |
| Username | Your unique public handle (3 to 32 characters, lowercase) |
| Display name | The name shown to others |
B. Profile
Information you choose to add. Most of it is visible to other users:
- Bio: free text
- Gender and pronouns: optional
- Country: required, and always visible
- City: optional, and only visible if you turn on "show city"
- Approximate coordinates: a latitude and longitude used only to calculate distance for matching. Never shown to anyone, and never returned to other users' devices
- Profile photo and banner: stored in our media storage
C. Dating profile, only if you opt in
SFSocial can be used without dating. Dating features are off until you explicitly turn them on. If you do turn them on, we additionally collect:
- Occupation (a field of work, not an employer)
- Height, and the height range you are open to
- Personality tags
- Lifestyle answers (smoking, drinking, exercise, pets, children)
- Matching preferences: age range, distance, and your dealbreakers
Two of your matching settings, strict dealbreakers and never show this person again, are private by design. They are never exposed to other users through any part of our system.
If you turn dating off, this information is hidden, not deleted, so that turning it back on restores your answers. If you want it erased rather than hidden, email us.
D. Interests
The interests you pick from our predefined list. Visible on your profile and used for matching.
E. Connections and messages
- Connections: friend requests, DM requests, matches and blocks, including the optional message you can attach to a request
- Direct, group and community messages: the content you send, including any links, images or GIFs
- Conversation metadata: who is in a conversation, timestamps, and read state
- Reactions: which messages you reacted to, and with what
- Mentions: structured data recording who you @mentioned in a message
- Typing indicators and online status: sent live between devices and not stored
F. Reports and moderation
- Reports you submit: the category, your description, any screenshots or links you attach, and a snapshot of the reported content
- Reports about you: the same information, submitted by someone else
- Moderation outcomes: warnings, suspensions and bans applied to your account, with the reason
- Staff notes: internal notes written by our moderators. These are not visible to you unless we choose to share them
Moderation is carried out by the operator and by a small number of volunteer moderators. See section 10.
G. Device and technical data
- Device and app information: device type, operating system, app version, language
- IP address: seen whenever your device connects. Used for rate limiting, abuse detection, temporary blocks, and moderation. Three things about the moderation use, added in version 1.1: - We record the address you sign in from, and whether it is one your account already signs in from. When you sign in from a network your account has not used before, we email a one-time code to your account's address, and that sign-in cannot use your account until the code is entered. To avoid asking every time, we keep a list of the addresses your devices sign in from; each one is deleted 90 days after it was last used to sign in. - When our moderators investigate an account, they can see the addresses that account has acted from in the last 90 days, and how many other accounts have used the same address. That second figure is how ban evasion and fake accounts are found. It is a count, never a list of who those accounts are. - A moderator can ask for an approximate location (country, and usually city) for one of those addresses. This is used to check a claimed location against an observed one, which is how we investigate impersonation and fake profiles. It is approximate, it is often wrong for anyone using a VPN or travelling, and it is never used on its own to decide anything about your account. See section 10 for who performs that lookup
- Security events: sign-in attempts, rate-limited actions, blocked actions and temporary blocks
- Trust level: an internal rating (
new,normal,trusted,restricted) calculated from your account age and any reports or blocks against you. It adjusts your rate limits and how often you see a CAPTCHA - CAPTCHA clearances: short-lived tokens proving you passed a bot check
We use PostHog for anonymous usage measurement and crash counts, described in section 5J. It is not linked to your account and you can switch it off.
We use no other analytics or crash-reporting service. There is no Google Analytics, no Firebase Analytics, no Crashlytics and no Sentry in the app.
H. Notifications
- Push tokens: a device registration token, on Android and web only
- Notification preferences: which notifications you want. Moderation notices cannot be switched off
- Notification records: a record of notifications sent to you, including a short preview of the message that triggered them
Push notifications are currently available on Android and web only. They are not available on Windows, Linux, macOS or iOS.
I. Matching activity
- Impressions: a record of each profile shown to you, so the same person is not shown again immediately
- Passes: a record of profiles you skipped. The other person is never told. There is no notification, and our access rules prevent them from seeing it
- Match requests: sent, received, accepted, declined or withdrawn
We also keep a record of how you use the people we suggest, so that we can tell a suggestion that worked from one that did not, and improve the suggestions over time:
- Profiles you opened: which suggested profiles you opened in full, where they were in your list, and how well they scored. Opening a profile is private: the other person is not told, then or ever
- How long you looked, as one of five broad bands (under 3 seconds, 3 to 10, 10 to 30, 30 seconds to 2 minutes, over 2 minutes). Never the actual number. The band is worked out on your device and only the band is ever sent
- Whether a match turned into a conversation: for people you matched with, whether a message was ever sent, when the first one was, how many there are now, and whether both of you have written. Never what any message says
- Summary counts about you, worked out once a night from your matching activity above: how often you were shown to other people, how often somebody said they were interested, how often somebody passed, how much interest is waiting for you right now, and how often you say yes
None of this is visible to anybody but us. No member can see any of it, about themselves or about anybody else. It is not on your profile, it is not in the app, and the database rules that hold every other members-cannot-read-this rule hold these too. In particular, how selective you are is never shown to anyone, in any form, exact or rounded: that is a fact about you and it is nobody else's to know.
This is behavioural data about you, kept against your account, and it is not the same thing as the anonymous product measurement in section J. The two are kept separately and are never joined. We keep the record of what you opened for 180 days; the summaries are worked out fresh each night rather than stored up (section 12). All of it is erased when your account is (section 13).
J. Anonymous usage and crash data
We measure how people move through the app so we can find the parts that are confusing or broken. This data is not linked to your account.
Instead of your account, each installation of the app generates a random identifier when it first runs. It is a random number. It is not derived from your account, your email, your name or your device, and we have no way to connect it back to you. It stays on your device and is reset if you reinstall the app.
Attached to that random identifier, we collect:
- App opens: that the app was launched, how many times, and whether this is the first launch
- Sign-in and sign-up events: that a sign-in or sign-up completed. Not who
- Onboarding progress: which setup steps you reached, which you completed, which you skipped, and which you left blank
- Your gender answer (male or female) and your country, so we can see the overall balance of who is joining. Never your city
- Your age as a broad band:
18-24,25-29,30-34,35-39,40-49or50+. This is worked out on your device from the date of birth you gave when you signed up, and only the band is ever sent. Never your date of birth, and never your exact age - Your dating preferences, if you turn dating on: what you are hoping to find, the age range and the distance you are looking within, and whether you have switched on strict dealbreakers or "never show them again". These are your settings, sent so we can see which ones people actually want. Never who you were shown, who you matched with, or who you passed over
- How you use Discovery: that a suggested profile was opened, roughly how long it was open as one of five broad bands, whether you said you were interested, passed, or closed it without deciding, how well the suggestion scored as a band, and roughly how far down your list it was. Never who it was. There is no name, no user ID and nothing in these that could point at a particular person. The version of this that is linked to your account is in section 5I and is kept separately from this
- Crashes: the type of error, the screen it happened on, and one line of our own source code. Never the error message itself
- Platform:
android,ios,web,windows,macosorlinux
We do not collect, and have built the app so that it cannot send:
- Your user ID, email address, name or username
- Your date of birth, or your exact age. Only the broad band listed above, which cannot be turned back into either
- Your bio, your messages, your photos, your interests or anything else you type
- Your city, your precise location, or a location guessed from your IP address. (This is about the anonymous usage data in this section only. Section 5G describes the separate, moderator-initiated location lookup used to investigate reports)
- The content of any answer you write in your own words. Everything we take from an answer is a category from a fixed list, a yes/no, or a number
- The identity of another member, in any form. Not their name, not their user ID, not their city, not their photo, and nothing that could be traced back to a particular person. Until September 2026 we sent nothing at all about another member; we now send what the Discovery entry above describes, which is that a suggestion was opened, how long it was open as a band, and what you decided, all as broad categories with nobody attached. Who it was has never been sent and cannot be
- Error messages, which can quote things you have typed
You can turn this off. Settings → Privacy & safety → "Share anonymous usage data". Turning it off stops collection immediately and discards anything not yet sent.
This data is processed by PostHog on servers in the European Union. See section 10.
K. The launch email list
SFSocial has not launched publicly yet. On our pre-registration page you can leave an email address and ask to be told when it launches. You do not need an account for this. For each address we keep:
| Data | Why |
|---|---|
| Email address | To send you the launch email |
| When you agreed | A record of your consent |
| What you agreed to | A record of your consent: to be emailed when SFSocial launches, and nothing else |
| Where you agreed | Our pre-registration page, or the earlier SFDating page described below |
We do not ask for your name and we do not link the address to an account. Like every request to our servers, the request that adds you is rate limited using your IP address (section 5G), but the IP address is not stored with your email address.
We use the address for one thing: to email you when SFSocial launches. It does not go on a newsletter, it is not used for marketing, and it is not shared with anyone except the suppliers who run our systems (section 10). Using it for anything else would need your separate agreement first.
People who pre-registered for SFDating. Before SFSocial had its current name, a pre-registration page at sfdating.simoapps.com asked people to sign in with Discord and offered a launch day notification. We moved only the email addresses from that list onto this one, for that same launch notification. We did not keep the Discord usernames or account IDs, and we do not know when each person signed up, so no date of agreement is recorded for those addresses.
To come off the list, email us from that address (section 14). How long we keep it is in section 12.
6. Special category data
Some of what SFSocial processes falls into what EU and UK law call special category data, meaning information that needs stronger protection.
Using our dating features can reveal something about your sexual orientation. Our matching currently pairs people of opposite genders, so your gender combined with your decision to use dating features indicates the kind of partner you are looking for. Under the GDPR that counts as data revealing sexual orientation, even though we never ask you the question directly.
We rely on your explicit consent (Article 9(2)(a) GDPR) to process this. That is why dating is a separate, deliberate choice rather than something switched on for you:
- Dating is off by default. You are asked a direct question and must answer yes.
- Turning it on is recorded as a distinct setting. We never infer it from the presence of other data.
- You can withdraw at any time by turning dating off in your settings. Your dating profile is then hidden from everyone and you are removed from other people's matching pools.
- Withdrawing consent hides your dating answers so you can return later. If you want them permanently erased instead, email us and we will delete them.
If you never turn on dating, we do not process special category data about you.
7. Why we use your data, and our legal basis
| What we use it for | Examples | Legal basis (EU and UK GDPR) |
|---|---|---|
| Running your account | Creating your account, signing you in, keeping you signed in | Performance of a contract |
| Applying our 18+ rule | Recording and checking your stated date of birth | Legal obligation; legitimate interests (child protection) |
| Core features | Profiles, communities, messages, notifications | Performance of a contract |
| Dating and matching | Building your dating profile, finding and ranking candidates | Explicit consent (Article 9(2)(a)), and performance of a contract for the underlying features |
| Safety and moderation | Investigating reports, applying warnings, suspensions and bans, detecting repeat offenders | Legitimate interests (protecting our users); legal obligation where applicable |
| Security and anti-abuse | Rate limiting, CAPTCHA, blocking brute-force attempts and spam | Legitimate interests (securing the service) |
| Service communications | Password resets, email confirmation, important account and safety notices | Performance of a contract; legal obligation |
| Support | Answering your questions, handling your data requests | Performance of a contract; legal obligation |
| Notifications | Sending push notifications you have enabled | Consent (where your device or local law requires it); legitimate interests otherwise |
| Launch email list | Emailing you when SFSocial launches, because you asked us to (section 5K) | Consent, which you can withdraw at any time |
| Legal claims | Keeping records needed to defend or bring a legal claim | Legitimate interests; establishment, exercise or defence of legal claims |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and you can object at any time (section 14).
What we do not do
- We do not sell your personal data.
- We do not run advertising and we are not connected to any ad network.
- We do not profile you for advertising or share your data for cross-context behavioural advertising.
- We do not charge for anything today. SFSocial currently has no paid features, no subscriptions and no payment processing, and we hold no payment or card data. If we introduce paid features we will update this policy and the Terms first.
8. Matching and automated ranking
If you use dating features, SFSocial ranks other members for you automatically. We think you should know how that works.
- We compare your answers with other members' answers and produce a compatibility score, built from your stated intentions, personality answers, shared interests and height preferences. Categories only count when both people have answered, so skipping an optional question does not count against you.
- The score is shown to you as a number, a tier and a short list of reasons.
- Members are then filtered by hard rules covering age range, distance, gender, blocks, and whether you have passed on them or already matched. Suggestions are delivered a page at a time, with a limit on how many you can be shown in a day.
- Your own filters and score are never shown to anyone else. Other members do not see the criteria they were judged against, and never see a distance or the size of your pool.
- Passing on someone is completely private. They are not notified and cannot find out.
- We record what you do with a suggestion (section 5I): which profiles you opened, roughly how long you looked, and whether a match turned into a conversation. We keep it so that the suggestions can get better at what they are for, which is finding people you would actually want to meet. It is recorded, and today nothing uses it: the score described above is worked out from stated answers only. If that changes, we will update this section before it does.
- Nothing you do is fed back to the other person. Opening a profile, reading it for a long time, or leaving without deciding are all invisible to them.
This ranking decides the order in which we suggest people. It does not produce any legal effect and has no consequence outside the app. If you would like a human to look at how you have been ranked, or to object to your behaviour being used to shape your suggestions, email us.
9. What other people can see
| Always visible | Visible only if you choose | Never visible |
|---|---|---|
| Username, display name | City | Email address |
| Profile photo and banner | Dating profile (only if dating is on) | Date of birth |
| Bio, gender, pronouns | Exact coordinates | |
| Interests | Your matching preferences and dealbreakers | |
| Country | Who you passed on | |
| Your age (not your birthdate) | Reports you have submitted | |
| Whether you are online now | Your trust level | |
| Your activity in communities you join | Moderation notes about you |
Online status is live. SFSocial shows other members when you are online in real time, for as long as the app is open. There is currently no way to appear offline or invisible. We plan to add one, but it does not exist yet.
Blocking someone hides your profile from them.
10. Who we share data with
Volunteer moderators
Moderation is handled by the operator together with a small number of volunteer moderators. To review a report they can see the reported content, a snapshot of the surrounding conversation, any evidence attached to the report, and the profile of the person reported. Access is limited by role, so a moderator only sees what their role allows, and every moderation action is written to an audit log.
Volunteers are not employees. They act under our instructions and are required to keep what they see confidential and to use it only for moderation.
Moderators do not have routine access to your private conversations. They see a conversation only where it has been reported, or where they are investigating a specific report.
Addresses and locations are restricted further. Only administrators, not ordinary moderators, can see the IP addresses an account has connected from or ask for an approximate location for one. Every such look-up is written to the audit log with the name of the person who made it.
Suppliers
| Supplier | What they do | What they receive |
|---|---|---|
| Supabase | Our entire backend: database, authentication, file storage, realtime and server functions | All data described in this policy |
| Resend | Transactional email delivery for account confirmation, password resets, sign-in verification and, when enabled, critical report alerts for staff | Your email address and the email content. Authentication messages contain account or sign-in information. Staff alert messages contain the alert severity, counts, wait time and dashboard link, but no report details or evidence |
| Google (Firebase Cloud Messaging) | Delivers push notifications on Android and web | Your device token, and the notification content, which includes the sender's name and a short preview of the message |
| Cloudflare (Turnstile) | Bot and abuse protection | Your IP address and a challenge token at the moment you are challenged |
| ipinfo.io | Turns an IP address into an approximate country and city, for moderation only (section 5G) | One IP address at a time, and only when an administrator investigating an account asks for it. They do not receive your account, your name, your email or anything else about you, and there is no automatic or bulk lookup. The answer is cached so the same address is not sent twice. If this supplier is not configured on our deployment, no address is ever sent and no location is shown |
| Klipy | GIF search in the media picker | Called directly from your device, so Klipy receives your IP address and your search terms whenever you open or search the GIF picker. This only happens if you use the GIF picker |
| PostHog (EU Cloud, Frankfurt) | Anonymous usage and crash measurement (section 5J) | The events listed in section 5J, tied to a random per-installation identifier and never to your account. They receive your IP address as part of the connection, but we instruct them not to derive your location from it and not to build a profile of the device. Nothing is sent if you switch this off |
| Websites you link to | Link previews | When you share a link, our server fetches the preview. The site sees our server's address, not yours |
We are working through formal data processing agreements with these suppliers and had not completed them at the time of writing. We will update this section once they are in place.
Other disclosures
We may also disclose data:
- To other users, as part of using the service. People in your conversations and communities see what you send, and members you match with see your dating profile.
- Where the law requires it, in response to a valid legal request, or to investigate serious abuse, protect someone's safety, or defend a legal claim.
- If the service changes hands. If SFSocial is ever transferred to someone else, your data would transfer with it. We would tell you before your data became subject to a different privacy policy.
We may publish genuinely aggregated statistics that cannot identify anyone, such as the total number of members.
11. Where your data is stored, and international transfers
Your data is stored in the European Union, in a Supabase data centre in Paris, France.
We are based in Morocco. That means we access data stored in the EU from outside the EU, and some of our suppliers are based in the United States. Morocco is not covered by a European Commission adequacy decision.
Where personal data protected by the GDPR is transferred outside the EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses where they apply. Some of our suppliers are certified under the EU to US Data Privacy Framework.
We are honest that this arrangement is still being formalised. We had not completed transfer documentation with all suppliers at the time of writing, and we are taking advice on the correct mechanism for access from Morocco. We will update this section as that work concludes.
Morocco has its own data protection law (Law 09-08), overseen by the CNDP. Any registration or authorisation required under Moroccan law is our responsibility, and we are addressing it.
12. How long we keep data
Here is how long we keep each kind of data.
| Data | How long |
|---|---|
| Account, profile, interests, settings | Until you delete your account, then 15 more days, then erased |
| Dating profile | Same as your account. Hidden immediately if you turn dating off |
| Messages | See section 13. Messages are not deleted when you delete your account |
| Deleted messages | Removed from the conversation immediately. We keep a copy for 90 days, in case it is needed to investigate a report, and then erase it |
| Username and email address | Released when the deletion completes, and usable again |
| Report evidence (screenshots and links attached to a report) | 1 year |
| Reports, and the outcome of each one | 2 years |
| Security and audit records | Records of moderation actions: 7 years. Day-to-day security records, such as sign-in attempts, the IP address each was made from, rate-limited actions and temporary blocks: 90 days |
| Addresses your devices sign in from | 90 days after each was last used to sign in. Kept so that signing in from them again does not ask for an emailed code |
| Approximate location looked up for an IP address | Cached until we clear it, so the same address is not sent to our supplier twice. It is a fact about the address, not about you, and it is not attached to your account |
| Moderation decisions (warnings, suspensions, bans) | Kept after account deletion where needed to enforce a ban and prevent evasion |
| Email identity of a banned account | Kept after deletion, so a ban cannot be evaded by deleting the account and signing up again with the same address. The address itself is erased from our authentication provider; what remains is the identifier that check runs against |
| Account deletion records | That an account was deleted, and when. No personal data beyond the internal account identifier |
| Matching behaviour (profiles you opened, how long you looked) | 180 days, then deleted automatically |
| Match outcomes and the summary counts in section 5I | Worked out fresh each night from the data above. A row disappears at the next nightly run once the match or the account behind it is gone |
| CAPTCHA clearances | Minutes. They expire automatically |
| Push tokens | Until you sign out, uninstall, or the token expires. Removed when your account is deleted |
| Notification records | A short period, so your inbox and unread count work |
| Launch email list (section 5K) | Until the launch email has been sent, then deleted. Removed sooner if you ask |
Account deletion is automatic. When your 15 days are up, your account is erased without you or anyone else having to act. Nothing is deleted before that date. See section 13.
Reports and moderation records outlive the accounts they concern. We keep them for the periods above even after an account is deleted. Without them, a banned member could return simply by deleting their account and signing up again.
If you would like something removed sooner than the periods above, email us and we will look at it. See section 14.
We do not currently maintain long-term backups. We will set up backups before public launch and will update this policy to say how long deleted data may persist in them.
13. Deleting your account, and what happens to your messages
This section describes behaviour that surprises people, so please read it before you create an account.
How to delete your account
In the app: Settings, then Account, then Delete account. You do not need to email us, and you do not need our permission.
We will show you what happens, ask you to confirm it, and ask for your password so that we know it is really you. Your password is checked on our servers, not in the app.
The 15-day recovery period
Deletion is not instant, and it is not instantly irreversible either. When you confirm it:
- Your account is disabled straight away. You are signed out on every device, your profile stops being visible to anyone, and you cannot send or read messages. Nobody else is told that you are being deleted; to them your account simply stops appearing.
- We record the date it will be permanently deleted: 15 days later. We show you that date, and you can see it again at any time by signing in.
- You can cancel for those 15 days. Sign back in and choose Continue. The deletion is cancelled and your account comes back exactly as you left it. Signing in by itself does not cancel anything: you have to choose to stay.
- After 15 days it is permanently deleted, automatically, and cannot be restored by you or by us.
If your account was suspended or otherwise restricted before you asked for deletion, cancelling restores it to that state. Deleting and undeleting is not a way to lift a suspension.
What permanent deletion removes
Your profile, photos, bio, interests, dating profile and matching preferences, settings, friends, message requests, blocks, push tokens, notifications, match history, the matching behaviour described in section 5I, reactions, and your memberships of communities and group chats. Your profile photo and banner are removed from our media storage.
Your authentication record is scrubbed: your password, your email address, your sign-in identities and every active session are erased at our authentication provider. Your login stops working, permanently.
Your username and email address are released, so both can be used again, by you or by somebody else. The one exception is in section 12: if your account was banned, we keep the identifier we check new signups against, because otherwise a ban could be evaded by deleting the account and signing up again with the same address.
This cannot be undone.
If you owned a community or a group chat
Ownership passes to the longest-standing remaining member, so the space keeps working for the people in it. If nobody else is left in it, it is archived and then removed.
What deletion does not remove: messages
We do not delete the messages you have sent. Instead we remove the link between those messages and your account. Your name, username and profile picture are taken off them, and they appear as coming from a former member. The text of the message stays visible to the people you sent it to.
We do this because a conversation belongs to everyone in it. Deleting your side would erase part of another person's record of an exchange they took part in, and would destroy evidence needed to investigate harassment or abuse by someone who then deletes their account. We rely on our legitimate interests and those of other members (Article 6(1)(f) GDPR), and on the need to establish, exercise or defend legal claims (Article 17(3)(e) GDPR).
We do not claim these messages become anonymous. Someone who was in the conversation may still know who wrote them, and in a one-to-one conversation that is obvious. A message may also contain identifying details you typed yourself. Removing the account link reduces how easily the messages can be connected to you. It does not make them untraceable, and we will not pretend otherwise.
If you want your message content gone as well, delete those messages before you confirm the deletion. The 15-day recovery period is also your chance to do it: sign back in, choose Continue, delete what you want gone, and then delete your account again.
What else we keep
Moderation records, reports about you, and the outcomes of any moderation action, for the reasons and periods in section 12. Without these, a banned member could return by deleting their account and signing up again.
Deleting a conversation is not deleting your account
These are different things, and neither one deletes the other:
- Leaving or closing a conversation removes it from your view. The other people in it keep their copy. Nothing is erased from our systems.
- Deleting a message removes its content from the conversation for everyone.
- Deleting your account removes your identity, but not the messages you sent.
14. Your rights
If you are in the EU, the EEA or the UK
The GDPR and UK GDPR give you the right to:
- Access: get a copy of the personal data we hold about you
- Rectification: have inaccurate or incomplete data corrected
- Erasure: have your data deleted, subject to the exceptions in section 13
- Restriction: ask us to limit how we use your data
- Portability: receive your data in a structured, commonly used, machine-readable format
- Object: object to processing based on our legitimate interests
- Withdraw consent: where we rely on consent, including for dating features and the launch email list
- Complain: to your national data protection authority
If you are in Morocco
Moroccan law (Law 09-08) gives you rights of access, rectification and objection. You may contact the CNDP.
Everyone else
Wherever you live, and regardless of whether your local law requires it, you may ask us to access, correct, export or delete your data, and to stop sending you optional messages. We apply the same process to everyone.
We do not currently meet the thresholds that would make us a "business" under the California Consumer Privacy Act. We are not claiming CCPA compliance. We extend the rights above to Californian users voluntarily, and will publish a specific CCPA section if and when the Act applies to us.
How to exercise your rights
Email privacy@sfsocial.app. We may need to confirm your identity first.
We respond within one month. If your request is complex, we may extend this by up to two further months, and we will tell you within the first month if we need to.
Account deletion is in the app (Settings, then Account, then Delete account) and is described in section 13. Data export is still handled by email; we do not yet have an in-app tool for it. See section 3. You can update your profile, settings and notification preferences in the app at any time.
There is no charge for any of this, and we will never treat you differently for asking.
15. Security
What we do
- Encryption in transit: TLS for all traffic between your device and our servers
- Password hashing: passwords are stored only as hashes by our authentication provider. We cannot see them
- Row-level access control: enforced in the database itself, so access rules apply even to direct queries, not just through the app
- Server-side rate limiting: on messages, requests, reports and uploads
- Bot protection: CAPTCHA challenges on higher-risk actions
- Brute-force protection: sign-in lockout after repeated failed attempts
- Link fetching protection: our link preview service refuses to fetch internal or private network addresses
- Separation of privileges: moderation tools require a staff role, roles are limited to what each moderator needs, and internal records are not reachable from the app
- Audit logging: moderation actions are recorded in an append-only log
Known limitations, stated plainly
- No end-to-end encryption. Messages are encrypted in transit but we can technically access them on our servers. Do not use SFSocial to send anything you would not want a service operator to be able to read.
- No independent security audit. We have not been externally audited or certified.
- Age is self-declared. See section 16.
- A small team. SFSocial is run by one individual, with volunteer moderators helping to review reports. We do not have a dedicated security team or 24-hour incident response, and reports are reviewed by people rather than instantly.
If something goes wrong
If a security breach affects your personal data, we will notify the relevant supervisory authority within 72 hours of becoming aware of it where the law requires, and we will tell affected users without undue delay where the breach is likely to present a high risk to them.
16. Age, and users under 18
SFSocial is for adults aged 18 and over. We do not knowingly allow anyone under 18 to use it, and we do not knowingly collect their data.
How our age check actually works: we ask for your date of birth at signup and refuse the signup if it shows you are under 18. We do not verify it. We do not check identity documents and we do not use any external age assurance service. Someone determined to give a false date of birth can currently do so. We consider this a serious limitation and are working on it.
If we find out that someone under 18 has an account, we will block it immediately and delete the associated data.
If you believe someone under 18 is using SFSocial, please report them in the app or email privacy@sfsocial.app. We treat these reports as our highest priority.
17. Cookies and similar technologies
SFSocial uses only the storage needed to keep you signed in, remember your settings, and hold the random identifier used for the anonymous usage measurement in section 5J. We use no advertising or cross-site tracking technologies, and we set no cookies for either.
See our Cookie Policy for details.
18. Changes to this policy
We will update this policy as SFSocial develops, and because it is under active development we expect to update it more often than a finished product would.
- Material changes, such as a new purpose, a new supplier, or a change to how deletion works, will be notified to you by email at least 30 days before they take effect, unless the change is needed immediately for safety or security.
- Minor changes, such as clarifications and corrections, take effect when published.
- The "Last updated" date at the top always reflects the current version.
Continuing to use SFSocial after a change takes effect means you accept the updated policy. If you do not accept it, you can delete your account (section 13).
19. Contact
For any privacy question, or to exercise any right in this policy:
privacy@sfsocial.app
We do not publish a postal address. If you need to reach us in writing for a legal or data protection matter, email us and we will provide an address for correspondence.
We are a very small operation and we read every message, but we are not staffed around the clock. We will always respond within the legal time limits in section 14.
If you are unhappy with our response, you can complain to your national data protection authority, or to the CNDP in Morocco.
Questions about this document? Email support@sfsocial.app.