Privacy Policy

Effective date: 13 August 2026

Touch helps you notice the people you actually cross paths with in the real world. To do that, it senses the places where your day happens — including in the background — and builds a private Journey of them.

A few promises, in plain language:

  • Your exact location is never shared with another person. Ever. Stations name a place and a time; they never point at you on a map.
  • You're only ever shown to people who plausibly crossed paths with you. There is no browsable directory of users, no feed, and no "who liked you".
  • We don't sell your data and we don't use it for advertising profiles.
  • You can turn sensing off any time, and you can delete your account and the personal data tied to it.

1. Who we are

Touch ("Touch", "we", "us") is a proximity-based social discovery app. This policy explains what personal data the Touch mobile app and its backend collect, why, how long we keep it, who processes it, and the choices you have.

Contact: support@touchapp.app (privacy questions, data requests)

2. The data we collect

WhatExamplesWhere it lives
Account & identityYour linked sign-in provider (Google, if you choose to link one) and its email address, plus your account statusHeld privately; never shown to other users
Recovery email (optional)An email address you may add so we have a quiet way to reach you, and the date you confirmed it. Entirely optional — an account without one is complete and works exactly the same. It is not a way to sign in: you always sign in with your phone numberHeld privately; never shown to other users. Until you confirm it by following the emailed link it is kept separately and treated as unconfirmed
Phone number (required)A mobile number you verify by SMS, plus the date you verified it. Since 6 August 2026 this is required — it is the credential you sign in with, so an account cannot be created or accessed without oneHeld privately as a sign-in credential and an extra layer of account security. It never appears on your profile and is never shown to anyone you cross paths with
ProfileDisplay name, age, photos, intentions, interests, optional bio, city of residence (a coarse, self-entered text label — not GPS)Shown to other people only inside a Station you both appear in
Precise location (raw)Recent GPS samples, uploaded in batches while sensing is onYour own private records only; automatically deleted within 24 hours
Location (refined)The places ("dwells") your samples resolve to, used to build your JourneyServer-side only; never exposed to other users as coordinates
Encounters & StationsRecords of who was physically near you, grouped into the places + times of your JourneyA Station is visible only to you
Likes & matchesWho you liked (outgoing only), mutual matchesOnly you see your outgoing likes; matches are visible only to the two participants
MessagesThe content of 1:1 chats with your matchesVisible only to the two participants
DevicePush-notification (FCM) tokenUsed only to deliver notifications; never shown to others
Crash diagnosticsA per-install identifier, device model, OS and app version, and — if the app crashes — a technical stack traceSent to Google Crashlytics so we can find and fix crashes; contains no profile, message, or location data
Safety & anti-abuseReports, moderation outcomes, automated abuse/spoofing signals, admin action logsServer-side only; never readable by other users

We do not collect contacts, browsing history, advertising identifiers, or biometric data.

3. How we use your data

  • To run the core feature — sense the places where your day happens and build your private Journey of Stations, then surface people you genuinely crossed paths with (who match your basic preferences and are discoverable).
  • To enable connection — likes, mutual matches, and 1:1 chat.
  • To send real-event notifications — a new match, a new place worth a look, or a new message. We do not send engagement, streak, or "come back" nudges.
  • For safety and anti-abuse — to detect and act on reports, abusive content, and location spoofing, and to keep a minimal admin action record.
  • To manage your account — sign-in, profile, and account deletion.
  • To reach you about your account, if you let us — if you add a recovery email we send a confirmation message to it, and we may use a confirmed address for important account matters. We do not use it for marketing, and adding one never changes how you sign in.

Lawful bases. Where applicable under privacy laws such as the GDPR, our lawful bases for processing are your consent (at sign-up and when you enable sensing) and our legitimate interest in providing the core discovery feature and keeping the service safe.

4. Location, explained

Location is the heart of Touch, so we want to be especially clear:

  • Background use. With your permission, Touch senses location in the background, so your Journey fills in even when the app is closed — co-presence happens throughout your day, not only while you're looking at the app. Foreground-only sensing would mean holding the app open all day, which would defeat the calm design and drain far more battery.
  • It's off until you turn it on. Background sensing only runs after you explicitly enable sensing, following a plain-language explanation that discloses the background use.
  • A standing, visible signal. While background sensing is active, Android shows a persistent notification the entire time. You always have a visible indicator, and a single off-switch in Settings.
  • Raw GPS is short-lived. Your raw location samples are automatically deleted within 24 hours. Only coarse place/dwell information is kept to maintain your Journey — and it is never exposed to anyone else as coordinates.
  • A dignified fallback. You can decline the "all the time" permission and use Touch with reduced (foreground-only) sensing, or deny location entirely and use the rest of the app — only the Journey will be empty.

Separately, when you choose to set your city of residence, the app may reverse-geocode your device's current location once to suggest a city name; that lookup is performed server-side, and we do not intentionally retain the coordinates after the lookup is completed.

5. What we never do

  • We never deliver one user's exact coordinates to another user's device.
  • We never sell your personal data.
  • We never use your data to build advertising or marketing profiles, and we run no third-party ad SDKs.
  • We never show a public profile, a browsable user directory, an attendance list, or a "who liked you" surface.

6. Who processes your data

We don't sell or rent your data. We use a small number of trusted service providers strictly to operate the app:

  • Google Firebase (Authentication, Firestore, Storage, Cloud Functions, Cloud Messaging, Hosting) — our backend and infrastructure. Data is encrypted in transit and at rest.
  • Google Firebase Crashlytics — crash and stability reporting. It receives a per-install identifier, device model, OS and app version, and a technical stack trace when the app crashes. It does not receive your profile, your messages, or your location, and we do not use it to identify you.
  • Google Maps Platform (Geocoding) — to resolve a coarse place name from coordinates, server-side and one-time. We do not intentionally retain the coordinates used for these requests after the lookup is completed, and the provider does not use them for its own advertising purposes.
  • Resend (email delivery, servers in Ireland) — used only to send the confirmation message when you choose to add or change a recovery email address. It receives that email address and the message we send you. It does not receive your phone number, your profile, your photos, your location, your Stations, or your messages. If you never add a recovery email, we never send it anything.

These are data processors acting on our instructions, not parties we "share" your data with for their own purposes.

We may also disclose information if required to do so by law, or where we believe in good faith that disclosure is reasonably necessary to comply with a legal process, enforce our terms, or protect the rights, safety, or security of our users, the public, or the service.

7. How long we keep it

DataRetention
Account & profileUntil you delete your account
Raw GPS samples≤ 24 hours (automatic)
Refined dwells30 days after the visit ends (automatic)
Stations & encountersKept while your account is active
LikesUntil account deletion or you unlike
Matches & messagesWhile the match exists; removed when your account is deleted
Device (FCM) tokenUntil account deletion
Recovery emailUntil you remove it or delete your account. You can remove it at any time in Settings
Recovery-email confirmation linksEach link is valid for 24 hours and can be used once. The record that a confirmation was requested is kept for a short period afterwards so we can answer "did someone try to add a recovery address to my account?", then deleted automatically
Safety & anti-abuse recordsRetained even after account deletion (see below)

Safety-record exception. A small set of abuse/safety records — reports, moderation outcomes, automated abuse/spoofing signals, and admin action logs — are kept even after an account is deleted, so that we can maintain a safe community and meet our legal and safety obligations. These records are never readable by other users.

8. Your choices and rights

In the app you can, at any time:

  • Toggle discoverability on or off (off stops creating new Stations for others and suppresses you from existing ones going forward).
  • Manage notification preferences.
  • Block, report, or unmatch other users.
  • Edit or remove your profile information.
  • Sign out.
  • Delete your account. Deletion removes your profile, photos, Journey, dwells, encounters, likes, matches and their messages, and your device tokens, and removes you from every other user's Stations. (Safety records are retained per §7.) For step-by-step instructions — and how to request deletion if you can no longer sign in — see How to Delete Your Account & Data.

Depending on where you live, you may also have rights to access, correct, delete, or port your personal data, and to object to certain processing. Account deletion is self-service in the app; for any other request (including a copy of your data), contact us at the address in §1 and we will respond within a reasonable time.

9. Security

Your data is encrypted in transit (HTTPS) and at rest. Access to the user surface requires a signed-in, verified account and an attested app. Backend logs are scrubbed of personal data, and exact coordinates are never written to any record another user can read.

10. Children

Touch is for adults. You must be 18 or older to use it. We do not knowingly collect data from anyone under 18; if we learn that we have, we will delete it.

11. Where your data is processed

Touch launches first in Israel and uses Google Cloud infrastructure. Your data may be processed in the region where our backend is hosted and in other regions where Google operates, with appropriate safeguards for any cross-border transfer.

One exception is worth naming plainly: if you add a recovery email address, that address and the confirmation message are handled by our email provider Resend, on servers in Ireland. Nothing else about your account is sent there, and if you never add a recovery email, nothing is.

12. Changes to this policy

If we make material changes, we'll update the effective date above and, where appropriate, notify you in the app. We'll notify users of material changes where required by applicable law.

13. Contact

Questions, concerns, or data requests: support@touchapp.app.