findmeIRL (“Findme”, “we”, “us”, or “our”)
Welcome to findmeIRL, a privacy-first social discovery mobile application and related services (collectively, the “App” or “Services”). The App enables users to discover nearby individuals with shared interests while protecting exact location through grid-based obfuscation, and allows registered businesses and venues to create public profiles, post updates, and engage with followers.
This Privacy Policy (“Policy”) explains how we collect, use, disclose, and protect personal information when you use the App. By downloading, installing, or using the App, you consent to the practices described in this Policy. If you do not agree, do not use the App.
This Policy should be read together with our Terms of Service. Capitalized terms not defined herein have the meanings set forth in the Terms of Service.
We collect the following information directly from you:
Personal Profiles: We collect precise GPS coordinates (latitude and longitude) only when you actively enable location sharing. These coordinates are stored server-side solely to compute a grid cell identifier (approximately 1 km²) and generate an obfuscated position (randomized offset of approximately 500–800 meters). Your exact GPS coordinates are never displayed to other users.
Business Venues: Venue locations are selected by the Business User and are intentionally public and non-obfuscated. These fixed coordinates are used to display venue pins on the Discover map and are visible to all App users. Business Users may update these coordinates at any time through the App.
Automatically Derived: Grid cell identifiers for proximity matching.
We collect and process your selected interests, language, demographics, optional catalog hobbies or custom hobbies/interests, and related profile fields (including semantic or hybrid match scores where enabled) to power personalized recommendations, soulmate matching scores, and Discover ranking. Custom interest submissions are subject to administrative review before being added to the public catalog. Match scores may be computed server-side and shown to other authenticated users in previews or rankings as part of discovery.
AI Profile Assistant (opt-in). If you enable it in Settings, you may generate suggested bios and related profile text via our Supabase Edge Functions. Outputs are transient unless you deliberately save edited text into your profile. Enabling AI Profile Assistant is separate from in-app chat suggestion features.
AI Chat “Wingman” (opt-in). If you enable it in Settings, snippets of chat draft text—and limited profile-derived context permitted by our policies (such as curator-approved vibe tags derived from uploaded gallery imagery where available)—may be sent to Edge Functions so the service can propose optional reply phrases. Inputs are processed for that request only and not used for model training. Premium subscribers receive monthly Wingman credits; remaining usage may rely on allowance or promotional rules shown in-app.
Formatting and validation pipelines for manually entered hobby or interest text may similarly call automation to improve spelling or suggest catalog labels prior to moderator review.
The App includes an in-experience loyalty layer (“coins”), badges/cosmetics, optional venue-based coin offers or pool funding flows, gifting coins to accepted contacts (with optional short messages), leaderboard participation in your city where you explicitly opt in, explorer-style milestones tied to broad grid-location activity, referrals and attendance-related rewards, plus server-side badges and leaderboard rows associated with social “combo” milestones. Associated data typically includes identifiers, timestamps, ledger entries/coin deltas, badges earned, boosts or frames expiry, leaderboard opt-in, referral attribution tied to installs or installs plus eligible real-world behaviors, Stripe checkout session metadata for pooled venue funding initiated by Venue Owners who choose optional paid top-ups or physical fulfilment postal details when you voluntarily request mailed items.
Premium subscriptions: When you subscribe through Apple App Store or Google Play, billing is handled exclusively by Apple or Google pursuant to their terms. RevenueCat securely maps Store receipts with your authenticated account so we can grant premium entitlement (shown in-profile and used for perks such as earn multipliers, Discover tie-breaking, cosmetics, Wingman allowances, optional frame unlocks).
We do not integrate advertising SDKs, sell personal data to data brokers, or use your information for behavioral advertising.
All images uploaded to the App (avatars, banners, gallery photos, event covers/memories, business logos, banners, and posts) are first placed in a private staging bucket and scanned by an automated AI system (Google Cloud Vision Safe Search) before being promoted to public storage. The scan detects illegal, explicit, or harmful content. Content that fails the scan is blocked from publication.
User-submitted text—such as profile biographies, business descriptions, custom hobby or interest submissions, and business posts—is processed by an automated AI content moderation system. This system analyzes text for prohibited categories including hate speech, harassment, threats, explicit or sexual content, violence, spam, scams, and other violations. Content that exceeds defined risk thresholds may be blocked from publication or flagged for review. This helps maintain a safe environment for all users.
We use the information we collect to:
We use in-App reports and automated tools—including AI text moderation for user-generated content and AI triage of reports—to detect and respond to violations. Repeated reports against the same subject may trigger escalation review. Event creation requires hosts to confirm compliance with our non-discrimination policy (see the Terms of Service section on Open Events and Non-Discrimination for details). This attestation is recorded and helps maintain an inclusive environment.
We share information in the following limited circumstances:
Obfuscated location plus profile cues for Personal Users (honoring Nearby discovery, strip-only-map modes, privacy flags, connections). Economy-oriented signals you deliberately surface—examples include coin tiers, cosmetic frames/badges, premium indicators, Discover boosts or explorer summaries, optional city leaderboard entries, gift notifications, curated gallery vibe tags feeding previews—travel with whichever UI exposes them. Venue pins share owner-selected coordinates, descriptive fields, follower-only or public posts consistent with moderation/approval workflows. Business posts remain visible to followers and, for approved venues, may be exposed through public read paths or APIs we maintain.
Data is shared with contracted processors bound by confidentiality and data protection obligations:
When required by law, legal process, or to protect the rights, safety, or property of Findme, Users, or the public.
In connection with a merger, acquisition, or sale of assets (with notice to affected Users where required).
Precise location access supports core discovery experiences. Device OS permissions (“When In Use”) control whether fresh GPS readings are captured. Stored coordinates—for Personal Users—power grid/obfuscation logic, Nearby discovery eligibility, explorer rewards keyed to coarse grid footprints, referrals or attendance checks where disclosed in-product, and never expose your exact latitude/longitude pins to strangers. Turning off Nearby discovery removes you from other users’ Nearby queries and disables persisting fresh precise coordinates onto your profile as implemented today, though other tabs may invite device permissions independently. Separate controls let you suppress your people-marker on the Discover map while still appearing in contextual strips when eligible. Venue coordinates remain owner-published and inherently public-facing.
We retain personal data for as long as your account remains active or as necessary to provide the Services and comply with legal obligations. Upon account deletion (initiated by you in Profile → Account or by us for violations), we perform cascading deletion of your profile, messages, connections, events, business profiles (if owned), posts, follows, gallery photos, coin ledgers, badges, subscription mirrors, referral metadata, and related economy records tied to your user id where configured, subject to any legal hold or backup retention requirements. Location history for Personal Users is retained only for a limited period. Anonymized or aggregated data (including match score statistics and usage analytics) may be retained indefinitely for service improvement.
Account suspension or Business Venue pause temporarily restricts access or visibility while retaining the underlying data. Full deletion only occurs on explicit user request or permanent termination. Suspended/paused records remain subject to the same retention rules until the account is fully deleted.
Depending on your jurisdiction, you may have the right to:
You may exercise these rights directly in the App (Profile → Account section for deletion and certain edits) or by contacting us at the address below. We respond to valid requests within 30 days (or sooner for deletion requests). Business Users may additionally manage venue visibility, follower lists, and post content through the App. If your account or venue has been suspended or paused for policy violations, you may appeal the decision through the in-App support flow or by contacting us.
We implement appropriate technical and organizational measures to protect personal data, including Row-Level Security (RLS) policies in our database, encryption in transit (TLS) and at rest where applicable, strict access controls, scoped API keys, and regular security reviews. Automated pre-publication scanning of user-uploaded images (via Google Cloud Vision Safe Search on the private staging bucket) helps prevent the distribution of illegal or harmful content. No system is 100% secure. We strongly encourage you to use a strong, unique password and enable any available two-factor authentication.
The App is intended exclusively for individuals aged 16 years and older. We do not knowingly collect, solicit, or process personal data from anyone under the age of 16. If we become aware that a User is under 16, we will promptly delete the account and all associated data. Business accounts are subject to the same age restriction. Parents or guardians who believe their child has provided data should contact us immediately.
Our primary infrastructure provider (Supabase) processes data in secure data centers located primarily in the European Economic Area. When personal data is transferred outside your country of residence, we ensure appropriate safeguards are in place, including standard contractual clauses and compliance with applicable data protection laws (including GDPR and the Swiss Federal Act on Data Protection).
We may update this Policy from time to time to reflect changes in our practices, the App, or legal requirements. We will notify you of material changes via in-App notice, push notification, or email. Your continued use of the App after the effective date of any update constitutes acceptance of the revised Policy.
For questions, requests, or complaints regarding this Privacy Policy or our data practices, please contact us at:
We are committed to responding promptly and transparently to all legitimate inquiries.