Privacy Policy
Your information should serve your experience, not become the product.
This policy explains what SocialSession collects, why, who else processes it, how long it is kept, and the controls you have over it.
The short version. We collect what the app needs to let adults plan safer public meetups: your email, your declared age, your profile, the meetups you create or join, chat with people you have accepted, safety reports, and an optional coarse Nearby area. We do not sell your data. We do not run advertising or behavioural-analytics SDKs. You can export everything and permanently delete your account from inside the app.
1. Information we collect
Information you give us
| What | Why we need it |
|---|---|
| Account and eligibility — email address, password (held by our identity provider, never by us), date of birth and the resulting 18+ result, account status | Create and secure your account; enforce the adults-only rule |
| Policy acceptance — which document version you accepted and when | Prove versioned consent |
| Profile — display name, headline, pronouns, general area, interests, connection goals (including optional mutual dating interest), smoking and drinking preferences, languages, accessibility preferences, optional biography, work or learning notes, social prompts, and your visibility choices | Let other adults decide whether to meet you and privately calculate compatible choices. Dating interest is disclosed only when both adults select it. |
| Profile photo (optional) — the image, its size and dimensions, and its moderation review state | Optional self-representation, reviewed before other members see it |
| Meetup listings — title, shared interest, named public venue, approximate area, start and end time, capacity, status, safety acknowledgement | Create and discover public meetups |
| Participation — join requests, invitations, host decisions, roster membership, attendance, completion and no-show state | Run the meetup and support reliability |
| Chat — message text and timestamps, visible only to accepted participants of that meetup | Coordinate a meetup you are both part of |
| Friendships — who you are connected to, who asked, whether a request is waiting, declined or accepted, and whether you met at a meetup or connected online | Run Friends, and let a moderator see how a connection began if it is reported |
| Private messages — message text and timestamps between two people who have accepted each other | Let friends keep in touch after a meetup |
| Reactions, mutes and read position — the ❤️ or 👍 you leave on a message, who you have muted, and one timestamp per conversation recording how far you have read | Run the inbox. Your read position is never shown to anyone else |
| Private feedback and endorsements — structured post-meetup feedback, a "meet again" signal, and positive trait endorsements (reliable, respectful, good conversation, welcoming, great host, would meet again) | Reliability and trust signals |
| Safety reports and appeals — category, the details you write, the member or meetup referenced, status, severity, resolution, and any appeal | Investigate harm and enforce the Community Standards |
| Blocks — who blocked whom, and when | Suppress discovery, messaging and notifications in both directions |
| Product feedback — the message you send from Help & feedback, its category, and the app version, build number, OS version and device model attached to it | Fix bugs and decide what to build |
Information collected as you use the app
- Approximate Nearby presence (opt-in). Nearby is off by default. When you turn it on, the app asks for foreground, approximate location permission, rounds the coordinates on your device, and sends them once so the server can place you in a coarse area cell. Your exact latitude and longitude are never stored in our database and are never shown to any member. Only the coarse cell, an optional mood, and update/expiry information are kept for discovery. Presence expires after your selected timer or stays on until you turn it off. We do not collect background location updates.
- Nearby abuse prevention. To limit excessive area browsing, we retain up to six approximate area identifiers and their latest publishing times and limit new areas within a rolling 24-hour window. These are coarse areas, not exact coordinates, and are not shown to other members. We also keep a per-account version counter to prevent delayed requests from undoing an OFF action. Approximate-area records are included in your account export.
- Authentication and device-session security. Session identifier, device name and platform, and the times a session was created, last seen, expired or revoked, plus authentication audit events (such as sign-in and password change).
- Notifications. Your notification categories, quiet hours and time zone, your Expo push token and a hash of it, and the delivery state of each notification. Push payloads carry generic copy only — never chat text and never the contents of a safety report.
- Operational telemetry. Our API logs a request ID, the normalised route, method, status code, duration, and a redacted error type. These logs exclude member content, raw query strings, coordinates, and tokens.
- On your device. The app stores your sign-in session in the operating system's secure storage and caches limited app state so it can recover offline. Signing out, "Delete local app data", and account deletion clear those values. On Android, app backup is disabled so these caches are not copied into a device or cloud backup.
What we do not collect
- No government ID, biometrics, or background checks. We verify an email address and record your 18+ self-attestation — we do not claim to have verified your identity.
- No payment information. SocialSession is free and contains no purchases.
- No advertising SDK, no behavioural-advertising profile, and no third-party product-analytics SDK. We do not sell or share personal information for cross-context behavioural advertising.
- No background location, no precise-location history, and no contacts, calendar, microphone, or health data.
- No tracking across other apps or websites, and no Apple App Tracking Transparency prompt, because we do not track.
2. How we use information
- To create your account, verify your email, and enforce the 18+ platform requirement and the 21+ requirement for alcohol-centred Meetups.
- To show your profile and meetups to other eligible, unblocked adult members.
- To run join requests, rosters, chat, attendance and cancellations.
- To operate the optional Nearby feature while you have it switched on.
- To send the notifications you have opted into.
- To investigate reports, enforce the Community Standards, decide appeals, and keep an append-only record of moderation actions.
- To keep the service secure and reliable, and to detect and prevent fraud, abuse and account takeover.
- To fix bugs and improve the product based on the feedback you send us.
- To comply with legal obligations and respond to lawful requests.
We do not use your content to train advertising models, and we do not build behavioural advertising profiles.
3. What other members can see
- Your profile as you have configured it. Several fields (education, work, neighbourhood, preferred meetup vibe, accessibility preferences, mood, and lifestyle details) follow the visibility choices under Me. Dating interest is shown only when both adults selected it.
- Meetups you host or join, at their named public venue and approximate area.
- Chat messages, to accepted participants of that meetup only.
- Private messages, to that one friend only — and only after they accepted. Nobody can message you before you accept: a conversation does not exist until you do, and a connection request cannot carry a note, a greeting or any other words.
- That you are open to connecting online, but only if you turn that setting on. It starts off. While it is off you are not listed to anyone, and while it is on you are listed only to other members who have also turned it on.
- An approximate Nearby area, and only while Nearby is on.
Members never see your exact location, your email address, your date of birth, who reported whom, private reviewer notes, the private feedback others wrote about them, or whether you have read a message — SocialSession has no read receipts, and a push notification about a private message carries the sender's name and never the message. If you block someone, you disappear from each other's discovery, sessions, messaging and notifications.
4. Service providers
SocialSession is a small operation and relies on a short list of processors. They act on our instructions and are not permitted to use your information for their own advertising.
| Provider | What it does for us |
|---|---|
| Supabase | Authentication (email and password), the application database, and profile-photo storage |
| Render | Hosting for the SocialSession API and its redacted operational logs |
| Expo | App builds and push-notification relay to Apple and Google |
| Apple | App distribution through TestFlight and the App Store, and push delivery through APNs |
| Push delivery through FCM (and Play distribution if an Android release is published) | |
| GitHub | Hosting for this policy website |
We may also disclose information when we reasonably believe it is required to comply with law or valid legal process, to enforce our Terms and Community Standards, or to protect the rights, safety or property of members, the public or SocialSession. Legal process and law-enforcement requests should be directed to [LAW ENFORCEMENT CONTACT]. If SocialSession is ever involved in a merger, acquisition or asset sale, information may transfer as part of that transaction, and we will say so before it takes effect.
5. Where information is processed
SocialSession is operated from the United States and its providers process information in the United States. The current release is a controlled United States launch.
6. How long we keep information
- Account and content — for as long as your account exists. Deleting your account removes it (see section 8).
- Nearby presence — expires after your chosen timer, or stays on until you turn it off if you select that option. Closing the app does not end this opt-in. Only your last approximate area is used, not background tracking. Turning Nearby off removes the entry when the server confirms the action. Server-confirmed sign-out or device-session revocation also removes presence. Uninstalling the app, a phone losing power, or signing out while fully offline may leave manual availability visible until you reconnect and turn it off.
- Nearby abuse-prevention records — area records older than 24 hours are removed on your next publishing attempt; they are not automatically deleted at the 24-hour mark. Turning Nearby off does not reset this protection. Deleting your account removes these records and the version counter.
- Meetups — kept through the meetup lifecycle and then expired.
- Operational logs — [LOG RETENTION].
- Safety, moderation and appeal records — [MODERATION RETENTION]. Limited, minimised records may be kept longer where needed for safety, fraud prevention, disputes or legal obligations.
- Provider backups — deleted rows may persist in encrypted provider backups until those backups expire, [BACKUP WINDOW].
7. Security
All traffic uses HTTPS. Passwords are handled by our identity provider and are never stored by the SocialSession API. Sign-in tokens live in the device's secure storage. Uploaded photos are decoded and re-encoded, which strips embedded metadata such as any camera location tag, before storage, and are held for review before other members can see them. Nearby coordinates are rounded on the device and converted to a coarse cell in memory. Exporting your data and deleting your account both require a recent sign-in. Moderator authority is stored in our database and never taken from a client request. No system is perfectly secure, and we cannot guarantee absolute security.
8. Your choices and rights
Controls in the app
- Export your data. Me → Account & notifications → Export my account data. A recent sign-in is required. The export includes your account, profile, meetups, participation, chat, blocks, the reports you filed, notification settings, and any legacy records still attached to your account. It excludes private feedback other people wrote about you and the identity of anyone who blocked or reported you.
- Delete your account. Me → Account & notifications → Permanently delete account. A recent sign-in and an explicit confirmation are required. See Delete your account for the full list of what is removed and how long it takes.
- Turn Nearby off at any time, or deny the location permission entirely and keep browsing manually.
- Choose what shows on your profile under Me → Privacy.
- Manage notifications by category, with quiet hours, under Me → Account & notifications.
- Sign out other devices from the signed-in devices list in the same section.
- Remove your photo, edit or delete your profile fields, and block any member.
- Clear local data with "Delete local app data".
Requests by email
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to withdraw consent, and to appeal a refusal. We honour these requests for all members regardless of location. Email info@socialsessionapp.com from the address on your account. We will not discriminate against you for exercising a privacy right, and we do not sell or share personal information as those terms are used in U.S. state privacy laws.
9. Children
SocialSession is for adults age 18 and older. It is not directed to children, and we do not knowingly collect information from anyone under 18. If we learn that an account belongs to someone under 18, we remove the account and its data. If you believe a minor has created an account, report it in the app or email info@socialsessionapp.com. See Age Eligibility.
10. Changes to this policy
If we make a material change, we will update the effective date, post the new version here, and ask you to accept the new version in the app before you continue to use it. Your acceptance of each version is recorded.
11. Contact us
J&A APPworks LLC
[MAILING ADDRESS]
info@socialsessionapp.com