Privacy Policy

Effective: [DATE — fill in on launch] · Operator: Incultnito LLC · Contact: [email protected]

This policy applies to the Homeboy mobile app and the homeboys.app website. It is published in English; a Traditional Chinese translation is available on request.

1. What we collect

We collect only what we need to make activity discovery and group coordination work.

CategoryDataWhyStored
AccountEmail/phone, hashed password, signup timeAuthenticate youSupabase Auth
ProfileDisplay name, bio, optional avatar/selfie, DOB, district, languageShow you to other members of joined activitiesSupabase Postgres
VerificationSelfie image (encrypted), phone number, push tokenConfirm real person; prevent abuseSupabase Storage + Postgres
LocationApproximate coordinates (rounded ~100m)Show activities near youSupabase PostGIS
ActivityActivities you create, join, swipe, check in toMatching + chatSupabase Postgres
ChatGroup + direct messages, timestampsDeliver chatSupabase Postgres
ReportsReports you submitModerationSupabase Postgres
DiagnosticCrash reports, app/OS versionFix bugsExpo (no PII)

We do not collect: contacts, calendar, browsing history, advertising IDs, microphone audio (camera is used only for the selfie), or biometric data beyond the single verification selfie.

2. How we use it

We do not use your data for advertising, do not sell it to data brokers, and do not allow third-party trackers.

3. What we share

We do not share data with advertisers or analytics brokers.

4. Your controls

In the app: edit any profile field; delete your account from Profile → Settings (purges all data within 30 days); toggle push notifications via system settings; switch language between English and 繁體中文.

By email ([email protected]): request a copy of your data; immediate deletion (within 7 days); correction of inaccurate data; withdraw consent for non-essential processing.

5. Retention

Account recordActive + 30 days after deletion
Verification selfie90 days after approval, then deleted
Chat messagesWhile group exists; max 12 months
Reports24 months (repeat-offender detection)
Crash logs30 days

6. Children

This app is for ages 17+. We do not knowingly collect data from anyone under 17 and will delete it immediately if discovered.

7. International transfers

Data is stored on Supabase infrastructure (currently AWS, region: ap-northeast-1, Tokyo). If you sign up from outside Taiwan, your data is transferred there with appropriate safeguards (Standard Contractual Clauses where applicable).

8. Security

If we suffer a breach affecting your data, we will notify you within 72 hours by email or in-app notice.

9. Changes

If we materially change this policy, we will notify you in-app at least 14 days before the change takes effect.

10. Contact

Questions, complaints, or data requests: [email protected]. For Taiwan residents: you may also contact the Personal Data Protection Commission.