Privacy Policy
The short version. We collect what the app needs to work. We do not sell your data and we do not track you across other apps or websites. Queer Town carries two kinds of advert. Our own, sold and served by us, which are told nothing about you. And, for a while, an occasional ad from Google in a few places — not personalised, with nothing about you sent to Google, and never where being queer is against the law; but when one loads, Google does learn that a phone is using Queer Town. See Advertising below, where this is said in full.
We also know who this app is for. Information about someone's sexual orientation or gender identity can put them in real danger in parts of the world, so the sections below say plainly what is stored, who can reach it, and what we cannot protect you from.
Who we are
Queer Town is operated by the person running queertown.in. We are a very small operation, not a company with a privacy department. You can reach us at hello@queertown.in and a person reads it.
What we collect
Things you give us
- Your email address. Required — it is how you sign in, with a one-time link. You can also add a password, or connect a Google account, as extra ways back in; both are optional. Addresses from temporary "throwaway" email services cannot be used to join. Private email services such as Proton, Tuta or DuckDuckGo's address protection are welcome.
- Your profile: display name, username, pronouns, identity tags, interests, bio, links, photo, and your current mood if you set one.
- What you write: posts, comments, board posts, room messages, private messages, reactions, voice notes and photos, and files you send in private chats, together with the file's name.
- Tags: people you tag in a post, and tags other people add you to. A tag waits for your approval unless you switch that off.
- Your city, region and country, if you enter them. These are text fields you type. See Location below.
- Dating and Bubble information, only if you choose to use them: gender, orientation, who you are open to, what you are looking for, birth year, and dating photos.
- Verification video, if you ask for a tick: three seconds of you holding a code we give you, with no sound needed. It is deleted once a person has decided — we never keep it.
- Reports you make, and anything you write in them.
Things the app creates
- Timestamps — when you joined, posted, signed in.
- A notification token, if you allow notifications, so your phone can receive them.
- A record of moderation actions — reports, warnings, restrictions, verification decisions. This record is kept even after the thing it refers to is deleted, because an audit trail that can be erased is not an audit trail.
- Ordinary server logs kept by the companies below, which include IP addresses.
- Your signed-in devices — a short description of the browser or phone (its "user agent") and when it was last used, so you can see where you are signed in and end a session you do not recognise. The IP address on that record is never read by us, and nothing about your location is derived from it.
- The country your connection comes from, for a moment. Our hosting network labels each request with a two-letter country code. We may read that code to hide something that has been blocked in your country (see the Terms) and for nothing else. It is never stored, and no city, position or internet address is read from it.
- Warning signs for staff. The database counts patterns that spam and targeting usually leave — for example many message requests declined, the same words sent to many people, a new account posting links, or several different people blocking or reporting one account — and shows staff a short list. These are counts, never who blocked or reported whom. It never reads a private conversation; the only message it looks at is the single message a message request carries, compared automatically and never shown. Nothing posted without your name is counted. A warning sign never acts on its own: a person looks, and decides.
Three things we deliberately do not record
These are worth stating on their own, because in each case the information is absent from the data rather than hidden behind a setting.
- Who voted for what in a poll. We record that you
voted, so nobody can vote twice, and we keep a running total for each answer.
The link between a person and their answer is never written down. Not by us,
not for the person who made the poll, not for staff, and there is nothing for
a court order to reach. The cost of that, honestly, is that you cannot change
a vote — changing it would mean knowing which total to reduce.
On a platform where a poll may ask "have you come out to your parents?" or "are you on a waiting list?", we would rather not hold the answer at all. - That two accounts on one phone belong to the same person. You can keep more than one account on a device, and the list of them lives on the phone — not in a table, not in a column, not in a header. Nothing on our side records that they are connected. The trade-off is that only the account you are signed in to receives notifications, because a device can be linked to one account at a time and linking it to several is exactly the record we are refusing to keep.
- Your app lock PIN. If you set a PIN to open the app, it is kept on your phone only, scrambled, and never sent to us. We cannot see it or reset it; "forgot PIN" signs you out on that phone instead.
Special category data — said plainly
Sexual orientation and gender identity are, under UK and EU law, "special category" personal data, meaning the most sensitive kind. So is anything you write about your health, including transition.
Queer Town exists so people can share exactly this, so the legal basis for handling it is your explicit consent, given by choosing to fill in those fields and to post. You are never required to disclose any of it to use the app. You can remove it at any time, and you can post anonymously on boards and in the Support Hub, where your name is genuinely not stored on the post.
Location
We never store your coordinates, and nothing in the app shows how far away another person is. Your city is a field you type. It changes only when you change it, and never on its own.
There is one optional button, beside the city field, marked “Use my location”. If you press it, your phone works out the name of the town you are in and types it into the box for you. That name is all that is saved — the coordinates are used on your phone to find it and are never sent to us, never written down, and never kept. You can type the town yourself instead and nothing is lost by doing so; the button is a spelling convenience, not a requirement. We never ask for location in the background, and we never watch where you go.
This is deliberate. Distance between two people is a targeting tool as much as a convenience, and location plus LGBTQ+ identity is the most dangerous combination of information this app could hold. Meetups show an area and release the exact venue only to approved attendees.
Right Now shows who is about and how they are feeling. A mood carries the town you typed in and nothing finer unless you add a neighbourhood yourself, and it disappears after a few hours rather than accumulating. The map of "lights on tonight" shows towns and never people, and a town only appears once at least three people in it have said something — one person on a map is a name to anybody who knows the place.
Who can see what
- Other members see whatever each post's visibility allows — everyone, your connections, or nobody. Your profile visibility and whether you appear in search are your settings, in Settings → Privacy.
- Private messages are visible to the people in the conversation. They are not end-to-end encrypted: they are stored on our database, and someone with administrative access to that database could in principle read them. We do not, but we will not claim a protection we have not built.
- Moderators of a room or board can see content reported in their space. Platform staff can see reported content, account details needed to act on a report, and a verification video while they check it (it is deleted once the decision is made). Every time staff open somebody's record it is logged. Staff cannot search private messages at all; a private message is seen only if somebody in that conversation reports it.
- Anonymous posts do not carry your identity in the post itself. Only you can see that it was yours. Staff can find out only through one recorded route, reserved for serious enforcement, which requires a written reason and is logged.
What you save is yours alone. Saved posts, and any collections you sort them into, are private. Nobody is told you saved something — not the person who wrote it — and there is no count of how many people saved anything. The names you give collections ("binders", "when I move out") are never shown to anyone.
Go quiet, in Settings, sets your search visibility, profile, photo, bio and presence to private in one tap, and is reversible. It does not retract what is already public: a post set to Everyone stays that way until you change it, and rooms you have spoken in still show what you said. Quietly rewriting your published words is not something we will do without being asked.
Companies that process data for us
We use a small number of services to make the app work. Each sees only what it needs to.
- Supabase — database, sign-in and file storage. This is where your account and everything in it lives.
- Resend — sends the sign-in emails. Sees your email address.
- ImprovMX — forwards mail sent to our address. Sees mail you send us.
- Expo, and Google or Apple — deliver push notifications, if you turn them on. They see a device token and the notification text, which is why our notifications do not name rooms or quote messages — unless you switch on message previews in Settings, in which case a message notification shows the sender's name and the start of the message.
- Google — if you choose to sign in with Google or connect a Google account, Google learns that you use Queer Town.
- Vercel — hosts this page and our staff tools.
- Anthropic — will process questions you type into the AI Helper, if that feature is ever switched on. It is currently off. It would receive only the message you send it, never your conversations, rooms or private messages.
These providers operate internationally, so your data may be stored or processed outside your country.
What we do not do
- No selling or renting of personal data, ever.
- No sharing of your data with data brokers.
- No building of profiles about you for targeting.
- No analytics or behavioural tracking SDKs.
Advertising
Queer Town shows two kinds of advert. Running this costs money and there is no investor behind it. This page promised to be updated before anything about advertising changed; this is that update, made before the first ad from Google could appear.
- Our own adverts — sold by us, served from our own systems, read by a person here before they appear, and marked Sponsored. No advertising system is given any information about you for these: no device identifiers, no interests, nothing.
- Ads from Google, for a while — described in full under Ads from Google below, because they are different and you should know exactly how.
For our own adverts, no advertising system is given any information about you. No device identifiers, no interests, no inferred attributes, nothing that could be used to work out who you are or what kind of person you are.
The reason is specific rather than principled posturing. A standard mobile advertising kit collects a device identifier and reports back what it saw, letting advertising companies build a profile of you across every app you use. On an app like this one, the fact that you use it at all becomes an attribute attached to your device — "uses an LGBTQ+ app" — and that attribute is bought and sold by companies neither you nor we have any relationship with. In some countries it is dangerous information.
So our own adverts are the kind that do not need to know anything. A picture or a short video, a headline and a link, sold by us and served from our own systems. Each one is read by a person here before it can appear. The rest of this section, up to Ads from Google, is about these.
What is actually recorded
Two numbers per advert, and nothing about you. How many times it was shown in total, and how many times it was tapped in total. There is no per-person record anywhere — not who saw an advert, not who tapped one, not how many times you personally were shown something.
This is not a promise about intentions. It is what the system is capable of: the counters are single totals on the advert itself, so there is no list of people to hand over, lose, or be compelled to produce.
An advertiser is told how many people their advert could reach, how many times it was shown, and how many times it was tapped. They are never told anything about who those people are. No demographics, no interests, no identities, no list. If an advertiser asks us for that, the honest answer is that it does not exist.
The one thing about you that is used
The city, state and country on your profile decide which adverts you are shown, so a shop in your city can reach people in that city. This happens inside our own systems and the result never leaves them — the advertiser learns that their advert was shown a number of times, not to whom.
That location is the town name in your profile — the one you typed, or the one the optional “Use my location” button filled in for you. Either way it is a word, not a position: we store no coordinates and nothing tracks where you go. See Location above. Leave those fields empty and you will only ever see adverts that were aimed at everybody. You can change or clear them at any time in your profile.
Where adverts never appear
Our own adverts can appear on Home, My Day, the Rooms list, Boards, Marketplace and What's on (Google's, only on Home, My Day and the boards). They never appear inside a room or a conversation, in your inbox, in Dating, in The Bubble, or anywhere in the Support Hub or the crisis pages. A conversation is not a place to sell something, and neither is the page somebody opens on their worst day.
Every advert is marked Sponsored with the advertiser's name on it.
What we do not do
- We do not use anything you post in an advert.
- We do not let anyone target an advert at an identity, an interest, a room, a board, or anything else about you. Place is the only targeting that exists.
- We never take a payment inside the app, and we hold no card details — advertisers pay us directly, outside it.
Ads from Google
Why. A new app has very few advertisers of its own, and the town has to pay its bills while it grows. So for a while Queer Town may show an occasional ad from Google (its AdMob service) — only in a gap between posts that none of our own adverts filled. They are switched off once our own adverts and supporters cover what the town costs to run.
Before the first one, the app tells you, and Google's part of the app does not start until you have read it.
What Google receives, said plainly. When one of these ads loads, your phone asks Google for an ad. That request reaches Google with your internet (IP) address, basic facts about the phone (such as its model, system and language), and the fact that the request comes from Queer Town. Google uses this to deliver the ad, count it and prevent fraud. We cannot remove this: it is how an ad from Google arrives. It means Google can learn that a phone at that internet address is using Queer Town.
What Google does not receive from us:
- Nothing about you. We send Google no name, account, profile, interest, post, room, board or anything you did here.
- No advertising ID. The Android app has the advertising identifier switched off, and on iPhone we never ask to track you, so Google cannot link Queer Town to that ID in other apps.
- No personalisation. We ask Google for non-personalised ads only, rated at most PG (never teen or mature), so an ad is not chosen because of who you are or what you do in other apps.
Where they appear: only between posts on Home, in My Day, in the Boards tab and inside a board, at most one in every eight posts. Never in the Support Hub or the crisis pages, your messages or inbox, rooms' chats, Find, The Bubble or Dating, anyone's profile, replies, Glow, or while signing up. Never inside a board about coming out, transition, family, health or the law, or any other board we have left out, and never beside a post whose photo is covered or that carries a serious heads-up from its author.
Never where being queer is against the law. Google ads are not shown to anyone whose profile, phone region or phone time zone places them in a country that criminalises LGBTQ+ people (the list kept by the Human Dignity Trust, and Russia). If the app cannot tell, it shows none.
Consent. In the European Union, the UK and Switzerland, Google's consent screen appears first, and without consent no Google ad is shown.
Every one is marked Ad · from Google, with Why? and Report. A report tells us where it appeared and what you wrote, and we block that advertiser in Google's tools.
How Google uses information from apps that show its ads is set out by Google at policies.google.com/technologies/partner-sites.
How long we keep things
This section is written honestly rather than reassuringly, because the truthful answer is less tidy than most policies admit.
When you close your account: your profile leaves the town, your posts unpublish, your dating profile switches off, anything you were hosting is cancelled and the people attending are told. Within 30 days you can sign back in and it all returns.
Taking a break is different: for 1 to 30 days, or until you come back, you disappear from the town in the same way, but nothing is on a countdown and everything returns when the break ends.
After 30 days you can no longer restore it yourself. The underlying records are not automatically erased at that point. We have not yet built an automated deletion process, and we would rather say so than imply one exists.
If you want your data actually erased, email hello@queertown.in and ask. We will do it by hand and confirm when it is done. Two things survive any erasure: entries in the moderation audit log, and messages you sent to other people, which are part of their conversations as well as yours.
Your rights
Depending on where you live you may have the right to see what we hold about you, correct it, have it deleted, object to how it is used, or take it elsewhere. Most of it you can see and change in the app. For anything else, email us.
Download my data, in Settings, gives you a copy of what you have written and set. It deliberately leaves out other people's messages to you and the names of anyone who follows you (you get counts), because a file holding those is a file that can be demanded from you by somebody else.
If you are in India, the Digital Personal Data Protection Act, 2023 gives you the right to see, correct and erase your personal data and to have a complaint dealt with; if we do not resolve it, you can complain to the Data Protection Board of India. If you are in the UK or EU and think we have handled your data badly, you may complain to your data protection authority. Either way, we would rather you told us first — see Complaints.
Security, and its limits
Your data is protected by row-level security in the database, which means access rules are enforced on every single query rather than by the app remembering to check. Photos and files are in private storage and reached through links that expire. Sign-in is a one-time emailed link; a password is optional, and if you add one, use one you do not use anywhere else.
No online service can guarantee complete protection from every security threat, legal requirement, technical failure, or human action. Anyone who can read your email can get into your account, so protect that inbox — and turn on two-step sign-in in Settings if anyone else can reach it.
Age
Queer Town is for people aged 18 and over. We ask you to confirm this and we take your word for it — no age check can completely eliminate false declarations. If we learn an account belongs to someone under 18 we remove it.
Changes
If we change this policy in a way that matters, we will say so in the app rather than quietly updating this page.