Phych LLC · Choid
Privacy Policy
What Choid collects, why it is used, and how it is protected.
Last updated: September 17, 2026
1. Overview
This Privacy Policy explains how Phych LLC, the operator of Choid, collects, uses, shares, stores, and protects personal information in the app and on choid.app. Profile details, messages, photos, location, and interaction data can be sensitive.
For privacy requests, contact support@choid.app.
2. Information You Provide
- Account information: email address, display name, password handled by Supabase Auth, account id, authentication session, and signup or password reset state.
- Profile information: age, height, gender label, looking-for preference, bio, photos, prompts, interests, hobbies, school, field of study, job title, relationship intent, religion, political views, lifestyle fields, kids preference, languages, and verification status.
- Preferences: discovery filters, notification settings, theme choice, blocked users, and privacy-related choices.
- Messages and chat media: text messages, GIF metadata, private chat photo and voice recording paths, photo dimensions, voice durations, voice waveform metadata, message reactions, typing indicators, unsend state, and message reports.
- Dating interactions: swipes, matches, opening message requests, blocks, reports, missed connections, and leaderboard visibility.
- Game, swipe, and purchase history: swipe balance, refill timestamps, swipe ledger entries, blackjack hands, roulette spins, poker queue and table state, local Lounge progress, weekly leaderboard scores, and Google Play swipe-pack transactions.
- Purchase records: product, order, test-purchase marker, purchase and consumption status, account-binding evidence, refund or chargeback state, timestamps, and one-way receipt hashes. Google handles payment-card details; Choid never receives your card number or other payment-card details.
- Safety and support information: report reasons, support emails, relevant profile and message snapshots, reported media copies, moderation decisions, and legal preservation records.
- Website waitlist: the email address you submit, used for launch updates. Contact support to remove your waitlist entry. Internal testing feedback may include a description and screenshot; the in-app bug reporter is disabled in production.
3. Information Collected Automatically
- Device and app data needed for push notifications, including Expo push token, platform, app ownership, notification events, delivery attempts, and delivery errors.
- Foreground location when you grant permission, including latitude and longitude saved for discovery and missed connections.
- Local device storage such as session persistence, theme mode, cached discovery filters, message read timestamps, first-view hints, and local Lounge game progress.
- Basic technical information from service providers, such as logs, IP-derived security metadata, crash or delivery errors, and timestamps.
- Raw purchase tokens used to verify or recover a Google Play transaction. They are temporary device-bound client recovery material and are not stored permanently server-side; Choid's server stores one-way receipt hashes instead.
4. How We Use Information
- Create and secure accounts.
- Build and display profiles, discovery candidates, matches, missed connections, and read-only profile views.
- Send and receive chat messages, GIFs, chat photos, voice recordings with waveform metadata, reactions, typing indicators, and push notifications.
- Run swipes, virtual swipe balance, opening message requests, games, and leaderboards.
- Verify Google Play purchases, prevent duplicate grants, deliver purchased swipes, record consumption, and reconcile refunds, revocations, and chargebacks.
- Moderate content, investigate reports, block abuse, enforce the Terms, and protect users.
- Operate, debug, test, analyze, and improve Choid.
- Comply with law, legal requests, security obligations, accounting, and dispute handling.
5. What Other Users Can See
- Public profile fields shown in discovery, matches, blocked-user views, and leaderboard profile views may include display name, gender label, age, height, bio, photos, interests, prompts, school, work, relationship and lifestyle fields, languages, looking-for preference, verification badge, and account creation time.
- Exact email address, precise coordinates, notification tokens, filters, swipe ledger details, push delivery records, and payment or verification session data are not meant to be shown to other users.
- Matched users can see messages, GIFs, chat photos, voice recordings, reactions, typing indicators, and unsend markers in that match.
- Leaderboard users can see profile basics and visible swipe stats for the leaderboard mode.
6. Location
Choid uses foreground location only after permission is granted. Location supports local discovery and missed connections. Missed connections are delayed and summarized; exact coordinates are not displayed to other users.
You can deny or revoke device location permission. Some local discovery and missed connection features may not work without location.
7. Photos, Chat Media, And Storage
Profile photos are hosted at public URLs so they can be shown in the dating experience. Anyone with a photo URL may be able to access or save that photo; profile photos are not private chat media.
Chat photos and voice recordings use private storage and temporary access links controlled by match membership. Messages are not end-to-end encrypted. Authorized service operations and restricted safety reviewers can access relevant content. Recipients can still save, record, or share content outside Choid.
When content is reported, relevant profile/message snapshots and media copies may be retained in separate restricted evidence storage. Those copies are not visible to other app users and may outlive the original message, match, photo, or account.
Internal bug report screenshots, when enabled for prerelease testing, are stored in a private Supabase bucket and may be attached or linked to GitHub issues.
8. Verification
Identity verification is unavailable in this release. Choid does not collect identity documents, biometric verification scans, or new verification submissions through the app. Do not send identity documents to support.
Previously recorded verification status or test session metadata may remain on an account. A stored status does not establish a current identity check. We will explain any future verification service and its data use before asking you to use it.
10. Advertising And Sale Of Data
Choid does not sell personal information or share it for cross-context behavioral advertising. We will update this notice and provide legally required choices before changing those practices.
11. Retention And Deletion
We keep account information while your account is active and as needed to provide Choid. Deleting your account removes the account and associated active profile, relationships, messages, swipe/game history, and notification records. Media deletion can finish through a background cleanup process. It does not retrieve copies already saved by another person.
Reported content is an exception: restricted report snapshots, relevant media, and decision records are normally retained for 180 days from the report. They are then scheduled for deletion unless a legal preservation requirement or documented legal hold requires longer retention. Unmatching, unsending, and account deletion do not shorten that safety-evidence period.
A legal hold can preserve relevant evidence beyond 180 days for child-safety reporting, a legal request, or a dispute. Access remains restricted. Information included in a required CyberTipline report is preserved for the legally required period, which can be at least one year after the report. Records are reviewed for deletion when the hold ends.
After account deletion, minimal hashed transaction and replay-prevention evidence may remain for accounting, fraud and replay prevention, disputes, refunds, chargebacks, tax, and legal obligations. This can include one-way receipt hashes and transaction status, while raw purchase tokens are not stored permanently server-side.
Unsend removes active message content and may leave an unsent marker. Technical logs, backups, and security records may remain for the limited period needed for security, recovery, or legal obligations; contact us for information about a specific request.
Local device data can remain on your device until you clear app storage or uninstall the app.
12. Your Choices And Rights
- Edit most profile fields in the app.
- Change notification preferences in settings or revoke notification permission at the device level.
- Update or revoke location permission at the device level.
- Block users and report profiles or messages.
- Delete your account from Profile settings using your current password, or request deletion through the public account-deletion page if you cannot access the app.
- Request access, correction, deletion, or other privacy rights available under your local law by contacting us.
13. Security
Choid uses Supabase authentication, row-level security policies, scoped storage access, private chat media, signed URLs, and service-role-only backend operations where appropriate. No system is perfectly secure, and you should avoid sharing information you would not want another user to save or disclose.
14. Children
Choid is only for adults 18 and older. We do not knowingly allow minors to create accounts. Report any profile that appears to involve a minor.
15. Changes
We may update this Privacy Policy as Choid changes. Material updates will be shown in the app or otherwise communicated when required.