Touch helps you notice the people you actually cross paths with in the real world. While you have the app open, it notes the places where your day happens and builds a private Journey of them. It never senses your location in the background.
A few promises, in plain language:
- Your exact location is never shared with another person. A Station shows a place and a time; it never points at you on a map, and it never shows where you are now.
- You're only ever shown to people you genuinely crossed paths with, and only if you both fit what the other is looking for. There is no browsable directory of users, no feed, and no "who liked you".
- We don't sell your data and we don't use it for advertising.
- You can switch sensing off at any time in Settings, and you can delete your account and the personal data tied to it.
The rest of this document is the detail behind those promises.
1. Who we are
Touch ("Touch", "we", "us") is a proximity-based social discovery app. This policy explains what personal data the Touch mobile app and its backend collect, why, how long we keep it, who processes it, and the choices you have.
Contact: support@touchapp.app (privacy questions, data requests)
2. The data we collect
| What | Examples | Who can see it |
|---|---|---|
| Phone number (required) | The mobile number you verify by SMS, and when you verified it. It is the credential you sign in with, so an account cannot be created or used without one | Only you. Never shown to other users, never part of your profile, never used for matching or marketing |
| Linked sign-in accounts (optional) | If you link Google or Facebook as another way to sign in: that account's identifier and email address. We ask these providers for your email address only | Only you |
| Recovery email (optional) | An address you may add so we have a quiet way to reach you, and when you confirmed it. It is not a way to sign in. Until you confirm it by following the emailed link it is kept separately and treated as unconfirmed | Only you |
| Account details | Your account status and when you last used the app | Only you |
| Profile | Display name, age (a whole number you enter; we don't verify it), gender and whether you choose to show it, up to six photos, intentions, interests, an optional bio, and your city of residence (a city you pick, not GPS) | People you crossed paths with see your name, age, photos, intentions, city, and your gender if you chose to show it. People you match with also see your bio and interests |
| Who you'd like to meet | The genders and age range you're interested in | Only you. Used to decide who you're shown to and who is shown to you. Your gender is used for this even if you choose not to display it |
| Location estimates | While the app is open, roughly every two and a half minutes: one estimated position (latitude and longitude) plus measures of its accuracy and whether you were still, walking or travelling. The individual GPS readings stay on your phone; only the estimate is sent | No one, including you. Server-side only; used by automated processing |
| Places and visits | The visits your estimates add up to (a representative position and time window), and approximate areas (about 150 m across) where you are often at night, which we use to recognise your home so it is never treated as a place to meet people | No one. Server-side only |
| Encounters and Stations | A record that you and another person were at the same place at around the same time. A Station holds the place's name, its location (the venue's position, or the centre of an area about 150 m across), the time window, and who you crossed paths with | Your Stations are visible only to you |
| Likes, "Not for me", and matches | Who you liked, who you chose "Not for me" for, and your mutual matches | Only you see your likes and "Not for me" choices. A like is revealed only if it's mutual. A match is visible to its two participants |
| Messages | The content of 1:1 chats with your matches, and whether they were delivered and read | The two participants only, while the match lasts. Notifications show who wrote, never what they wrote |
| Device | A push-notification token and your phone's platform (Android or iOS) | Used only to deliver notifications |
| Facebook SDK | The app includes Meta's Facebook SDK so you can use Facebook Login. It starts with the app for everyone, and Meta documents that the SDK collects technical device information (such as device identifiers, device model, operating-system and app version, and IP address). We have switched off its automatic event logging and its advertising-ID collection | Sent to Meta by the SDK; see §6 |
| Crash diagnostics | A per-install identifier, device model, OS and app version, and a technical stack trace if the app crashes | Sent to Google Crashlytics so we can fix crashes. Contains no profile, message or location data |
| Service diagnostics | Technical records of what the service did for your account (for example, that a step ran or failed), with names, contact details and coordinates removed | Our team only, to find and fix faults |
| Photo checks | When you upload a photo, an automated check for adult or violent content, and that your first photo shows a face. We keep only the result | Our team only |
| Safety records | Reports (the reason and anything you write), blocks, moderation outcomes, automated location-spoofing signals, rate-limit counters, and a log of any admin access to accounts | Our team only; never readable by other users |
We do not collect your contacts, browsing history or advertising identifiers. We don't use facial recognition: the photo check only detects whether a face is present, and nothing about the face is kept.
3. How we use your data
- To run the core feature: note the places where your day happens while the app is open, build your private Journey of Stations, and surface people you genuinely crossed paths with who fit what you're each looking for and who are discoverable.
- To enable connection: likes, mutual matches and 1:1 chat.
- To send notifications you'd want: a new match, a new message, or a new place worth a look. You can turn each one off. We do not send engagement, streak or "come back" nudges.
- For safety: to check photos, act on reports and abuse, detect location spoofing, and keep a record of admin access.
- To run and fix the service: sign-in, your account, crash and service diagnostics, and account deletion.
Lawful bases. Where privacy laws such as the GDPR apply, we rely on: providing the service you signed up for; your consent where we ask for it (for example your phone's location and notification permissions); and our legitimate interest in keeping the service safe and working.
4. Location, explained
Location is the heart of Touch, so we want to be especially clear.
- Only while the app is open. Touch asks your phone for location access while you use the app only. It never senses in the background, so there is no background process and no standing notification: when you leave the app, sensing stops.
- When it starts, and how to stop it. Sensing starts only when you choose it: by tapping Allow on the Location step while setting up, after reading what it does, or by turning on Settings → Location & sensing. Allowing location for something else, such as filling in your city, does not start it. You can switch it off at any time in the same place, or withdraw the permission in your phone's settings. If you never turn it on, the rest of the app still works; only your Journey stays empty.
- What is sent. Roughly every two and a half minutes while the app is open, your phone combines a few GPS readings into one estimated position and sends that estimate, with measures of its accuracy and whether you were moving. The individual readings stay on your phone. If you're offline, unsent estimates wait on your phone for up to 7 days, then are discarded.
- What we keep, and for how long. Precise positions are kept on our servers for 30 days and are used only by automated processing: to recognise the places you spent time and whether you and someone else were genuinely there at the same time. They are never readable by another user, or through the app.
- Your home is protected. We keep a record of approximate areas (about 150 m across) where you are often late at night, for up to 180 days. If an area looks like your home, it is never treated as a place to meet people, never becomes a Station, and is never sent to a place-naming service.
- Naming places. To find out whether an area is a café, a park or similar, our servers send the centre of an area about 150 m across, with no information about you, to public OpenStreetMap services (see §6).
- Stations keep the place and time of an encounter for 30 days after the visit, then are deleted automatically, like the encounter records they come from (see §7).
- Discoverability is separate from sensing. Turning off Be discoverable in Stations means you stop appearing to other people (and they stop appearing to you), but it does not switch sensing off. Use Location & sensing for that.
- Choosing a city. If you set your city by typing, only the text you type is sent to Google to suggest city names. If you choose use my location instead, your phone's current position is sent once, through our servers, to Google to look up the city. We keep only the city name, filed under an area of about 1 km that is not linked to your account.
5. What we never do
- We never deliver one user's location to another user's device, and never show anyone a map of where you are or were.
- We never sell your personal data.
- We never use your data to build advertising or marketing profiles, and we run no third-party ad SDKs. Automatic event logging and advertising-ID collection in the Facebook SDK are switched off.
- We never show a public profile, a browsable user directory, an attendance list, or a "who liked you" surface.
6. Who processes your data
We don't sell or rent your data. We use a small number of service providers to operate the app:
- Google Firebase and Google Cloud (Authentication, Firestore, Storage, Cloud Functions, Cloud Messaging, Hosting, App Check): our backend and infrastructure. When you verify your phone number, Firebase Authentication sends the one-time SMS code on our behalf.
- Google Cloud Vision: checks each photo you upload for adult or violent content, and that your first photo shows a face. We keep only the result.
- Google Maps Platform (Geocoding, Places Autocomplete): to suggest and look up your city (see §4). These requests go through our servers.
- Google Crashlytics: receives crash reports (a per-install identifier, device model, OS and app version, and a stack trace). They contain no profile, message or location data.
- Google Sign-In and Meta (Facebook Login): if you link Google or Facebook as a sign-in method, the provider receives the sign-in request, and we receive your account identifier and email address. We do not ask for anything else.
- Meta's Facebook SDK: included in the app for Facebook Login, it starts with the app whether or not you use Facebook. Meta documents that the SDK collects technical device information (such as device identifiers, device model, operating-system and app version, and IP address). We have switched off the SDK's automatic event logging and its advertising-ID collection, and we send Meta no data about how you use Touch.
- Resend (email delivery, servers in Ireland): sends two kinds of email only: the confirmation when you add or change a recovery email address, and the confirmation or notice when a Google or Facebook sign-in is linked to your account (sent to that account's email address). It receives that email address and the message. It does not receive your phone number, profile, photos, location, Stations or messages. If you never add a recovery email or link a sign-in account, we never send it anything.
- Google reCAPTCHA: only on our web page for deleting an account without the app (touchapp.app/delete-account/verify). It checks that the request comes from a person, and Google collects device and browser information to do so, under Google's Privacy Policy. The rest of our website makes no requests to other companies.
- OpenStreetMap public services (Overpass): independent, publicly operated servers that tell us what kind of place an area is (see §4). They receive the centre of an area about 150 m across and nothing that identifies you.
These providers act on our instructions, with two exceptions: the OpenStreetMap services, which are public services we query without sending any account information, and Meta, which handles what its SDK collects under its own data policy.
We may also disclose information if the law requires it, or where we believe in good faith that disclosure is reasonably necessary to comply with a legal process, enforce our terms, or protect the rights, safety or security of our users, the public or the service.
7. How long we keep it
| Data | Retention |
|---|---|
| Account, profile, phone number, who you'd like to meet | Until you delete your account |
| Linked sign-in accounts | Until you unlink them or delete your account |
| Location estimates | 30 days (automatic) |
| Unsent location estimates on your phone | Up to 7 days (automatic) |
| Visits and encounter records | 30 days (automatic) |
| Night-time area records (home protection) | Up to 180 days (automatic) |
| Stations | 30 days after the visit (automatic) |
| Likes and "Not for me" choices | Until you delete your account |
| Matches and messages | Until either participant deletes their account. After an unmatch or a block, neither of you can open the conversation again; it stays on our servers, visible to no one, until one of you deletes your account |
| Device (push) token | Until you delete your account |
| Service diagnostics | 30 days (automatic) |
| Crash reports | For the limited period Google Crashlytics keeps them |
| Recovery email | Until you remove it (any time, in Settings) or delete your account |
| Confirmation links | Each is valid for 24 hours and can be used once. The record that one was sent is deleted automatically about a week later |
| Reports and moderation outcomes | Until a moderator has reviewed them, then 24 months (automatic), including after account deletion |
| Photo-check results | While the photo is on your profile, then 24 months after it is removed (automatic), including after account deletion |
| Summary of reports about an account (how many, and by whom) | 24 months after the most recent report (automatic), including after account deletion |
| Location-spoofing signals | 12 months (automatic), including after account deletion |
| Rate-limit counters | 7 days (automatic), including after account deletion |
| Admin access log | 12 months, including after account deletion |
Safety-record exception. A small set of safety records (reports, moderation outcomes including photo-check results, automated location-spoofing signals, rate-limit counters, and the admin access log) are kept even after an account is deleted, so that we can keep the community safe and meet our legal obligations. They are never readable by other users, and each is deleted automatically after the period in the table above. A report that has not been reviewed yet is kept until it is, so that no report is lost unread.
8. Your choices and rights
In the app you can, at any time:
- Switch Location & sensing off or on.
- Turn Be discoverable in Stations off or on. Off means you stop appearing in other people's Stations and they stop appearing in yours (sensing is a separate switch).
- Choose which notifications you get (matches, messages, new places).
- Block, report or unmatch someone. Blocking ends any match with that person, and they won't appear in your Stations or matches again.
- Edit or remove your profile information, and remove your recovery email.
- Sign out.
- Delete your account. Deletion removes your profile and photos; your Journey (Stations, location estimates, visits, encounter records and home areas); your likes and "Not for me" choices; your blocks; every match you are in, with its messages, for both participants; your recovery email and linked sign-in accounts; your device tokens; and your service diagnostics. It also removes you from every other user's Stations. Some short-lived records in our matching pipeline can still refer to your account for up to 30 days before they expire automatically. Safety records are kept as described in §7. For step-by-step instructions, and how to ask for deletion if you can no longer sign in, see How to Delete Your Account & Data.
Depending on where you live, you may also have rights to access, correct, delete or port your personal data, and to object to certain processing. Account deletion is self-service in the app; for any other request (including a copy of your data), contact us at the address in §1 and we will respond within a reasonable time.
9. Security
Your data is encrypted in transit (HTTPS), and Google Cloud encrypts it at rest. The app's requests to our servers require a signed-in account with a verified phone number, and we use Firebase App Check to help make sure they come from the genuine app. (Links in our emails work on their own, with a single-use code that expires.) Our backend logs are designed to leave out names, contact details and coordinates. No record that another user can read ever contains your location.
10. Children
Touch is for adults. You must be 18 or older to use it. Age is entered by you and we don't verify it, but we act on reports. We do not knowingly collect data from anyone under 18; if we learn that we have, we will delete it.
11. Where your data is processed
Touch launches first in Israel. Our database, file storage (your photos) and backend run in Google Cloud's Tel Aviv region. Some Google services we use (Firebase Authentication, Cloud Messaging, Crashlytics, Cloud Vision, Maps and, on the web deletion page, reCAPTCHA) operate across Google's global infrastructure, so data they handle may be processed in other regions where Google operates, with appropriate safeguards for any cross-border transfer.
Two exceptions are worth naming plainly:
- Emails we send through Resend are handled on servers in Ireland. That covers recovery-email confirmations and sign-in-link notices only; nothing else about your account is sent there.
- Place lookups go to public OpenStreetMap servers operated by independent organisations. They receive only the centre of an area about 150 m across, with nothing that identifies you.
12. Changes to this policy
If we make material changes, we'll update the effective date above and, where appropriate, tell you in the app. We'll notify users of material changes where required by applicable law.
13. Contact
Questions, concerns or data requests: support@touchapp.app.