Privacy Policy

Effective date: 16 June 2026

Touch helps you notice the people you actually cross paths with in the real world. To do that, it senses the places where your day happens — including in the background — and builds a private Journey of them.

A few promises, in plain language:

1. Who we are

Touch ("Touch", "we", "us") is a proximity-based social discovery app. This policy explains what personal data the Touch mobile app and its backend collect, why, how long we keep it, who processes it, and the choices you have.

Contact: support@touchapp.app (privacy questions, data requests)

2. The data we collect

WhatExamplesWhere it lives
Account & identityEmail address, sign-in provider (Google / Apple / email), account statusHeld privately; never shown to other users
ProfileDisplay name, age, photos, intentions, interests, optional bio, city of residence (a coarse, self-entered text label — not GPS)Shown to other people only inside a Station you both appear in
Precise location (raw)Recent GPS samples, uploaded in batches while sensing is onYour own private records only; automatically deleted within 24 hours
Location (refined)The places ("dwells") your samples resolve to, used to build your JourneyServer-side only; never exposed to other users as coordinates
Encounters & StationsRecords of who was physically near you, grouped into the places + times of your JourneyA Station is visible only to you
Likes & matchesWho you liked (outgoing only), mutual matchesOnly you see your outgoing likes; matches are visible only to the two participants
MessagesThe content of 1:1 chats with your matchesVisible only to the two participants
DevicePush-notification (FCM) tokenUsed only to deliver notifications; never shown to others
Safety & anti-abuseReports, moderation outcomes, automated abuse/spoofing signals, admin action logsServer-side only; never readable by other users

We do not collect contacts, browsing history, advertising identifiers, or biometric data.

3. How we use your data

Lawful bases. Where applicable under privacy laws such as the GDPR, our lawful bases for processing are your consent (at sign-up and when you enable sensing) and our legitimate interest in providing the core discovery feature and keeping the service safe.

4. Location, explained

Location is the heart of Touch, so we want to be especially clear:

Separately, when you choose to set your city of residence, the app may reverse-geocode your device's current location once to suggest a city name; that lookup is performed server-side, and we do not intentionally retain the coordinates after the lookup is completed.

5. What we never do

6. Who processes your data

We don't sell or rent your data. We use a small number of trusted service providers strictly to operate the app:

These are data processors acting on our instructions, not parties we "share" your data with for their own purposes.

We may also disclose information if required to do so by law, or where we believe in good faith that disclosure is reasonably necessary to comply with a legal process, enforce our terms, or protect the rights, safety, or security of our users, the public, or the service.

7. How long we keep it

DataRetention
Account & profileUntil you delete your account
Raw GPS samples≤ 24 hours (automatic)
Refined dwellsWhile their Station is retained
Stations & encountersKept while your account is active
LikesUntil account deletion or you unlike
Matches & messagesWhile the match exists; removed when your account is deleted
Device (FCM) tokenUntil account deletion
Safety & anti-abuse recordsRetained even after account deletion (see below)

Safety-record exception. A small set of abuse/safety records — reports, moderation outcomes, automated abuse/spoofing signals, and admin action logs — are kept even after an account is deleted, so that we can maintain a safe community and meet our legal and safety obligations. These records are never readable by other users.

8. Your choices and rights

In the app you can, at any time:

Depending on where you live, you may also have rights to access, correct, delete, or port your personal data, and to object to certain processing. Account deletion is self-service in the app; for any other request (including a copy of your data), contact us at the address in §1 and we will respond within a reasonable time.

9. Security

Your data is encrypted in transit (HTTPS) and at rest. Access to the user surface requires a signed-in, verified account and an attested app. Backend logs are scrubbed of personal data, and exact coordinates are never written to any record another user can read.

10. Children

Touch is for adults. You must be 18 or older to use it. We do not knowingly collect data from anyone under 18; if we learn that we have, we will delete it.

11. Where your data is processed

Touch launches first in Israel and uses Google Cloud infrastructure. Your data may be processed in the region where our backend is hosted and in other regions where Google operates, with appropriate safeguards for any cross-border transfer.

12. Changes to this policy

If we make material changes, we'll update the effective date above and, where appropriate, notify you in the app. We'll notify users of material changes where required by applicable law.

13. Contact

Questions, concerns, or data requests: support@touchapp.app.