Privacy Policy
Last updated: June 19, 2026 · GDPR compliant
1. Data Controller
OUT App AB, Stockholm, Sweden. Contact: privacy@out.app
2. Data We Collect
- Phone number (E.164, masked in API responses)
- Profile: name, age, language, city, bio, photos, interests
- Location during active sessions (purged after 7 days)
- Messages, matches, and activity data
- Device push tokens and app version
3. Legal Basis (GDPR)
- Contract: providing the OUT service
- Consent: location permission, push notifications
- Legitimate interest: safety, fraud prevention
4. Data Sharing
We do not sell personal data. Processors include Twilio (SMS), Firebase (push/realtime), and cloud hosting providers.
5. Your Rights
You may access your data via the app (GET /me), request deletion via support@out.app, and withdraw consent for optional features.
6. Retention
Session location history: 7 days. Account data: until deletion request + 30 day grace period.
7. Security
TLS 1.2+ in transit. Photo EXIF stripped on upload. JWT authentication with token rotation.
8. Children
OUT is not for users under 18.