Privacy Policy
Effective date: [CONFIRM: publication date] Who we are: [CONFIRM: legal entity name, e.g., Town App, Inc., a Delaware corporation] ("Town," "we," "us"), [CONFIRM: registered address] Contact: [CONFIRM: privacy@townapp.co — needs mailbox set up]
Town is a location-based social app that shows you face-verified people and happenings near you. This policy explains what we collect, why, who processes it, how long we keep it, and the controls you have. It applies to the Town iOS app and our websites (townapp.co and apply.townapp.co).
The short version
- We collect what the app needs to work: your account details, profile, interests, messages and posts, and whether you're near other Town users.
- We never store or share your precise location. Other users only ever learn one thing: nearby or not nearby — never where you are, never how far away.
- We verify every face once, at signup, through a US-based identity verification provider (Persona). Biometric data used for verification is destroyed after verification is complete. We never sell it, and we never use it for anything except verification.
- We don't sell your personal information. We don't share it with advertisers. There are no ads in Town.
- You can delete your account — and the data that goes with it — from inside the app at any time.
1. Information we collect
Account and profile. Date of birth (to confirm you're at least 17), name, profile photo, a short status line, and the interests you pick. [CONFIRM: auth credential — phone number / Apple ID / email — per final build.] Your date of birth is used for the age gate and is not shown to other users.
Interests. You choose interest tags in categories. You control which categories are public on your profile. Tags in categories we designate sensitive are never shown to other users, never used in match counts, and never surfaced in any density or discovery feature.
Face verification (biometric information). At signup we confirm you're a real person and that your profile photo is really you. See Section 3 — it is the detailed, standalone disclosure for biometric data.
Location. With your permission, the app uses your device's location to determine one thing: which other Town users are within your chosen detection radius (adjustable from 50 feet to 2 miles). Location is processed to compute presence ("nearby / not nearby") and is not retained as a movement history. [CONFIRM with dev team: raw coordinates are discarded after presence computation and never written to durable storage — this is the intended architecture; verify implementation.] Coarse, aggregated neighborhood-level identifiers (e.g., which NYC neighborhood a session occurred in) are used for analytics; precise coordinates and distances are never included in analytics data.
Content you create. Messages (one-to-one and group), emoji Waves, Bulletin Board posts, comments and RSVPs, group chats you start or join, and reports or blocks you submit.
Usage data. We collect app-interaction events (screens viewed, features used, taps on core actions) through our analytics provider, including session replays of in-app activity, to fix bugs and understand which features work. Analytics properties are restricted by a server-side allowlist: no message text or other content you write, no precise location, no distances, and no device fingerprinting are ever included. If you browse before completing verification, that activity is tied to a temporary random identifier and deleted within 14 days if you don't finish signup.
Device data. Push notification token (if you enable notifications), device type, OS version, app version, crash logs.
What we don't collect: precise location history, contacts, photos other than those you choose to upload, advertising identifiers, and any data from third-party social accounts.
Website forms. If you apply for a Town role at apply.townapp.co, we collect what you submit (name, email, application answers, and — for paid roles — work-authorization status), used only to evaluate the application and, if accepted, to work with you. townapp.co itself has no forms, no analytics pixels, and collects nothing.
2. How we use information
- Show you who and what is nearby (the core function of Town)
- Verify identity and age at signup and when a profile photo changes
- Deliver messages, Waves, posts, and notifications
- Compute your profile's activity indicators (e.g., how often you start or answer conversations)
- Keep Town safe: automated content screening, report review, and abuse-pattern detection (Section 5)
- Fix bugs and improve the product (analytics)
- Comply with legal obligations
We do not use your personal information for advertising, we do not build advertising profiles, and we do not sell or rent personal information to anyone. We do not use your content or biometric data to train AI models. [CONFIRM: vendor DPAs must contractually exclude model training — see companion memo.]
3. Biometric information — notice, consent, retention, destruction
This section is written to the standards of the Illinois Biometric Information Privacy Act (740 ILCS 14) and equivalent state laws, and serves as Town's publicly available biometric retention and destruction policy.
What is collected. At signup, you take a live selfie. Our identity verification provider, Persona Identities, Inc. ("Persona"), a US-based company acting as our service provider, performs a liveness check and compares face geometry extracted from your selfie against your uploaded profile photo. If you later change your profile photo, the face-match runs again.
Purpose. Solely to (a) confirm you are a real, live person, (b) confirm your profile photo is a genuine photo of you, and (c) prevent fraudulent or duplicate accounts. Nothing else. Face geometry is never used for advertising, tracking, or identification of you to other users beyond the verified checkmark on your profile.
Consent. Before any biometric capture, the app presents this disclosure and asks for your express written consent, given electronically. If you decline, we don't collect biometric data — and you won't be able to complete signup, because verification is a condition of membership on Town.
Retention and destruction. Biometric identifiers and biometric information are permanently destroyed when the verification purpose is satisfied, and in all cases within [CONFIRM: recommend 30 days] of verification completion — except where a longer period is required by law. In no event later than 3 years after your last interaction with Town. Town's own servers store the verification outcome (pass/fail) and a verification reference ID — not your face geometry. [CONFIRM with dev + Persona configuration: Persona's scan-data destruction schedule set per our instruction; Persona's default is destruction upon completion of services or within 3 years of last interaction, whichever comes first.]
No sale, no disclosure. We never sell, lease, or trade biometric data. It is disclosed only to Persona (as processor, under contract), or if required by law, warrant, or subpoena.
Security. Biometric data is transmitted and stored encrypted, and protected at least to the standard we use for all other sensitive data.
4. Location: exactly what others can learn
Town is built so that the answer is: almost nothing.
- Other users see only that you are nearby or not nearby — a binary. Never a map location, never a distance, never a direction.
- You can set your detection radius (50 ft – 2 mi) or go invisible entirely (Ghost Mode) in Settings. Ghost Mode removes you from every nearby surface immediately; friends can still message you.
- Counts of nearby people shown in the app include only users who have chosen to be visible.
- Our own analytics never receive your coordinates — only coarse neighborhood-level aggregates.
5. Content moderation and safety
To keep Town safe, content is screened by automated systems, and reported content is reviewed by our team:
- Public posts and messages are screened by automated moderation tools (including services from OpenAI and, for reported content, Anthropic) for content that violates our rules. These providers process content transiently as our service providers and are contractually barred from using it for other purposes. [CONFIRM: zero-retention / no-training API terms in both DPAs.]
- Uploaded photos are screened for known child sexual abuse material (CSAM) using industry hash-matching. Apparent CSAM is reported to the National Center for Missing & Exploited Children (NCMEC), as required by law.
- If you report content or a person, a human reviewer (Town staff or a trained volunteer Steward) sees the reported content and the surrounding context needed to act on the report. Reporters are never named to the person they report.
- We monitor aggregate behavioral signals (e.g., abnormal volumes of contact requests) to detect spam and abuse.
Moderation records are retained 180 days generally, 365 days where CSAM-related law requires, and permanently for account-ban audit records.
6. Who we share information with
Service providers (processors), under contract, only to run Town:
| Provider | What they process | Why |
|---|---|---|
| Persona | Verification selfie, profile photo, liveness data [CONFIRM: whether the Persona flow also performs age estimation or receives DOB — locked onboarding flow is selfie + liveness + face-match only] | Identity verification |
| PostHog | Usage events, session replays (allowlisted properties only) | Analytics |
| Amazon Web Services | App data, encrypted backups and event archive | Hosting and storage |
| Apple | Push token | Notifications |
| OpenAI | Post and message text, transiently | Automated content safety screening |
| Anthropic | Reported content, transiently | Safety review assistance |
| Google (Places) | Venue searches you type when creating an event post | Venue lookup |
| [CONFIRM: Spotify API — only if interest-matching integration ships in v1] | Interest tag queries | Interest matching |
Other users: your profile (photo, name, status, public interest categories, activity indicators, verified badge), your posts and messages to their recipients, and your binary nearby status — all governed by your visibility settings.
Legal: we disclose information if required by law, subpoena, or court order, or to protect the safety of users or the public. We notify affected users where legally permitted.
Corporate: if Town is acquired or merges, personal information may transfer to the successor, which must honor this policy. Biometric data is never transferred without fresh consent where law requires it.
We do not share personal information with advertisers, data brokers, or analytics resellers. We have not sold or shared personal information for cross-context behavioral advertising, and we won't.
7. Retention
| Data | Kept |
|---|---|
| Biometric verification data | Destroyed on verification completion (Section 3); never later than [30 days, CONFIRM] |
| Pre-signup usage data | 14 days max |
| Profile, interests, settings | Life of account + 30 days after deletion |
| Messages and chats | Life of account; deleted from your side on account deletion [CONFIRM: recipient copies persist — "Jordan keeps their copy" is the product behavior; counsel to confirm policy language] |
| Bulletin Board posts | Expire automatically after the event; underlying records [CONFIRM: retention window] |
| Usage analytics | [CONFIRM: recommend 12 months in PostHog] + raw event archive [CONFIRM: deletion pipeline — see companion memo item 4] |
| Moderation records | 180 days / 365 days (CSAM-related) / permanent (ban audit) |
| Crash logs | [CONFIRM: recommend 90 days] |
8. Your rights and controls
In the app, right now: set your radius, go invisible (Ghost Mode), control which interest categories are public, turn read receipts and typing indicators on or off, block anyone (immediate, total, and silent), and delete your account (Settings → Delete Account — two-step confirmation; deletion removes your profile, content, and personal data per the table above, subject to legal retention exceptions).
By request ([CONFIRM: privacy@townapp.co]): access a copy of your data, correct inaccurate data, delete data, or withdraw consent. We verify requests and respond within the time your state's law requires (generally 45 days). We never discriminate against you for exercising privacy rights.
State-specific rights. Residents of California, Colorado, Connecticut, Virginia, Texas, Oregon, and other states with comprehensive privacy laws have rights to access, correct, delete, and port personal data, and to opt out of sale, sharing, and profiling — Town doesn't do any of those three. Biometric data and precise geolocation are "sensitive data" under these laws; Town processes biometrics only with your opt-in consent (Section 3) and does not retain precise geolocation. [COUNSEL: confirm whether Town meets any state's applicability thresholds at launch scale; rights are offered to all users regardless.]
New York users under 18. Town's minimum age is 17. For 17-year-old New York users, the New York Child Data Protection Act applies: we process their personal data only as strictly necessary to provide Town or with their informed consent, obtained separately and revocable at any time; we do not sell their data or use it for advertising or profiling. [COUNSEL: this section, the consent flow it implies, and the 17-vs-18 age-floor decision are the top open item — companion memo item 1.]
9. Age policy
Town is for people 17 and older. We use a date-of-birth gate and identity verification at signup. We do not knowingly collect personal information from anyone under 17; if we learn we have, we delete the account and its data. If you believe someone under 17 is on Town, contact [privacy@townapp.co].
10. Security
Data is encrypted in transit (TLS) and at rest. [CONFIRM with dev team: at-rest encryption coverage across primary DB + S3 archive.] Access to personal data is limited to those who need it to operate Town. Volunteer moderators (Stewards) see only reported content, never private data browsing. If a breach affects your personal information, we'll notify you and regulators as state law requires.
11. Where Town operates
Town is offered in the United States, and data is stored and processed in the United States. Town is not offered in the European Union or United Kingdom at this time.
12. Changes
If we change this policy in a way that matters, we'll tell you in the app before the change takes effect, and we'll ask for fresh consent where the law requires it (for example, any new use of biometric data). The current version always lives at townapp.co/privacy.
13. Contact
[CONFIRM: legal entity name] · [CONFIRM: address] · [CONFIRM: privacy@townapp.co]