PEEPSBIO - PRIVACY POLICY Last Updated: 20 April 2026 Effective Date: 20 April 2026 This Privacy Policy explains how PeepsBio ("PeepsBio", "we", "us", "our") collects, uses, shares, and protects personal data when you use the PeepsBio mobile application, website (peeps.bio), and related services (the "Service"). This Policy is designed to comply with the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), Brazil's LGPD, Canada's PIPEDA, and Apple's App Store Review Guidelines (including App Tracking Transparency and Privacy Nutrition Labels). ---------------------------------------- 1. DATA CONTROLLER ---------------------------------------- PeepsBio is the data controller of your personal data. Contact: info@peeps.bio Data Protection Officer (EU/UK): info@peeps.bio ---------------------------------------- 2. INFORMATION WE COLLECT ---------------------------------------- A. Information You Provide Directly * Account data: email address, password (hashed), full name, username, date of birth, gender, phone number (optional). * Profile data: bio, profession, photos, interests, prompts/answers, height, languages, religion, politics, education, drinking/smoking/exercise preferences, family/children info, looking-for, hometown, star sign. * User-generated content: messages (1-to-1 and event chats), event details (title, description, date, location, emoji), reactions, social-media links. * Connection data: connection requests sent/received/accepted, blocked users. * Support communications: any information you send when contacting support. B. Information Collected Automatically * Device data: device model, OS version, app version, language, time zone, unique device identifiers. * Log data: IP address, access timestamps, crash logs, performance data. * Push-notification token: provided by Apple Push Notification Service (APNs) to deliver notifications. * Approximate or precise location data (only with your OS-level permission) for event discovery and proximity-based matching. C. Information from Third Parties (Optional Integrations) If you choose to connect a third-party account, we receive limited data via OAuth: * Google: email, name, profile picture (sign-in only). * Apple: email (or private relay), name (sign-in only). * Spotify: top artists, top tracks, currently playing (display on profile). * Instagram: recent media (display on profile). * Other connectors as added in-app. You may disconnect any integration at any time from in-app settings. D. Information We Do NOT Collect * We do not collect government-issued IDs. * We do not collect payment-card numbers (purchases are processed by Apple). * We do not perform background checks. * We do not access your device contacts, calendar, or microphone unless you explicitly grant permission for a specific feature. * We do not use third-party advertising SDKs and do not engage in cross-app tracking. Therefore, we do not display the App Tracking Transparency (ATT) prompt. ---------------------------------------- 3. HOW WE USE YOUR DATA (PURPOSES & GDPR LEGAL BASES) ---------------------------------------- Purpose | Legal Basis (GDPR Art. 6) ---------------------------------------------------------|-------------------------------- Create and manage your account | Contract (Art. 6(1)(b)) Display your profile to other users | Contract (Art. 6(1)(b)) Enable messaging, events, and connection requests | Contract (Art. 6(1)(b)) Send transactional push notifications | Contract (Art. 6(1)(b)) Verify age (18+) and prevent under-age access | Legal obligation (Art. 6(1)(c)) Process special-category data (e.g., religion, | Explicit consent (Art. 9(2)(a)) politics, sexual orientation if inferred from gender/ | looking-for) | Approximate/precise location for event matching | Consent (Art. 6(1)(a)) Marketing emails (where applicable) | Consent (Art. 6(1)(a)) Detect, prevent, and respond to fraud, abuse, security | Legitimate interest (Art. 6(1)(f)) incidents, and Terms violations | Improve the Service, debug, and aggregate analytics | Legitimate interest (Art. 6(1)(f)) Comply with legal obligations and respond to lawful | Legal obligation (Art. 6(1)(c)) requests | You may withdraw consent at any time without affecting the lawfulness of prior processing. ---------------------------------------- 4. SHARING & DISCLOSURE ---------------------------------------- We do NOT sell your personal data. We do NOT share your personal data for cross-context behavioural advertising. We share data only as follows: (a) Other Users: Your public profile (name, username, photos, bio, interests, profession, social links, age, approximate location for events) is visible to other users of the Service. Messages and event chats are visible to recipients/participants. (b) Service Providers (Processors), bound by data-processing agreements: * Supabase (hosting, database, authentication, storage, real-time, edge functions) - EU region. * Apple (Push Notification Service, Sign in with Apple, App Store payments). * Google (Sign-in, optional Maps/geocoding). * Optional OAuth providers you connect (Spotify, Instagram, etc.). (c) Legal & Safety: When required by law, court order, or to protect the rights, property, or safety of PeepsBio, our users, or the public (including investigating violations of our Terms or fraud). (d) Business Transfers: In connection with a merger, acquisition, or asset sale, with appropriate notice and choice where required by law. ---------------------------------------- 5. INTERNATIONAL DATA TRANSFERS ---------------------------------------- Our primary data hosting is in the European Union. Where data is transferred outside the EU/EEA or UK (e.g., to Apple in the United States), we rely on: * Adequacy decisions (e.g., EU-U.S. Data Privacy Framework, where applicable); * Standard Contractual Clauses (SCCs) approved by the European Commission; * Additional safeguards as required. You may request a copy of the safeguards by emailing info@peeps.bio. ---------------------------------------- 6. DATA RETENTION ---------------------------------------- * Account & profile data: retained while your account is active. * Messages: retained until deleted by you or until your account is deleted. * Account-deletion requests: data is permanently deleted within 30 days, except where retention is required by law (e.g., tax, fraud-prevention records, typically up to 7 years). * Backups: deleted within 90 days from rolling backup cycles. * Logs: typically 90 days. * Blocked-user records: retained while either party maintains an account, to enforce the block. ---------------------------------------- 7. YOUR RIGHTS ---------------------------------------- A. EU / UK / EEA Residents (GDPR / UK GDPR) You have the right to: * Access your personal data (Art. 15) * Rectify inaccurate data (Art. 16) * Erase your data ("right to be forgotten") (Art. 17) * Restrict processing (Art. 18) * Data portability (Art. 20) - receive your data in a machine-readable format * Object to processing based on legitimate interest (Art. 21) * Withdraw consent at any time (Art. 7) * Not be subject to automated decision-making with legal effects (Art. 22) - we do not engage in such processing * Lodge a complaint with your local supervisory authority B. California Residents (CCPA/CPRA) You have the right to: * Know what personal information we collect, use, and disclose * Delete your personal information * Correct inaccurate personal information * Opt out of "sale" or "sharing" - we do NOT sell or share personal information for cross-context behavioural advertising * Limit use of sensitive personal information * Non-discrimination for exercising your rights You may designate an authorised agent to act on your behalf. C. Other Jurisdictions Brazilian (LGPD), Canadian (PIPEDA), and other users have analogous rights under their local laws. D. How to Exercise Your Rights * In-app: most rights can be exercised via Settings (edit profile, delete account). * By email: info@peeps.bio - we will respond within 30 days (extendable by 60 days for complex requests). We will verify your identity before fulfilling requests. ---------------------------------------- 8. SECURITY ---------------------------------------- We implement appropriate technical and organisational measures to protect your data, including: * Encryption in transit (TLS 1.2+) and at rest; * Hashed passwords (industry-standard algorithms); * Row-Level Security (RLS) on all database tables; * OAuth tokens stored encrypted server-side; * Access controls and least-privilege principles; * Regular security reviews and dependency scans. No system is 100% secure. In the event of a personal-data breach affecting your rights, we will notify you and the competent supervisory authority within 72 hours where required by law. ---------------------------------------- 9. CHILDREN'S PRIVACY ---------------------------------------- The Service is not directed at children under 18. We do not knowingly collect personal data from children under 18. If we learn that we have collected such data, we will delete it promptly. Parents/guardians who believe their child has provided us with personal data may contact info@peeps.bio. ---------------------------------------- 10. APPLE PRIVACY NUTRITION LABEL SUMMARY ---------------------------------------- Data linked to your identity: Contact info (email, name, phone if provided), User content (photos, messages, profile content), Identifiers (user ID), Usage data (interactions), Diagnostics (crash data), Location (coarse/precise - with permission). Data NOT linked to you: aggregated, anonymised analytics. Data used to track you across other companies' apps/websites: NONE. ---------------------------------------- 11. COOKIES & SIMILAR TECHNOLOGIES ---------------------------------------- The mobile app does not use browser cookies. Our website (peeps.bio) uses strictly necessary cookies for authentication and session management. Advertising measurement: peeps.bio uses the Meta Pixel and Meta's Conversions API to measure how our ads perform. This sets Meta cookies (_fbp, _fbc) and sends Meta a record of page views and of survey submissions. If you give us your email address in the survey, we send it to Meta only as an irreversible SHA-256 hash, never in plain text. You can opt out in your Facebook or Instagram ad settings, or by blocking these cookies in your browser. ---------------------------------------- 12. CHANGES TO THIS POLICY ---------------------------------------- We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notice or email at least 30 days in advance. The "Last Updated" date at the top reflects the latest revision. ---------------------------------------- 13. CONTACT US ---------------------------------------- PeepsBio Privacy enquiries: info@peeps.bio Data Protection Officer (EU/UK): info@peeps.bio General: support@peeps.bio Web: https://peeps.bio EU Representative (Art. 27 GDPR): If you are in the EU and wish to contact our designated representative, please email info@peeps.bio and we will provide current details.