Blushh Privacy Policy
Blushh (“Blushh,” “we,” “us”) is a dating app for college students. This Privacy Policy explains what we collect, why, how we protect it, and the choices you have. Blushh is operated by Hassan Adegoke, a sole proprietor. If you have questions, contact us at [email protected].
You must be 18 or older and a currently enrolled college student to use Blushh (see our Terms of Service). Your account is created and verified with your phone number.
1. Information we collect
You give us:
- Your phone number, used to sign you in and verify your account (we text you a one-time code). One account per phone number.
- Your school (
.edu) email address — optional. If you choose to verify it (we email you a one-time code), your profile earns a “verified student” badge that other users can see. You can use Blushh without providing it. - Profile details: name, age, school year, major, bio, and up to 6 photos.
- Preferences: the genders you want to see, food and hobby preferences, date vibe, and free-text date ideas.
- Messages you send to your matches.
- Safety reports and blocks you submit about other users.
We collect as you use the app:
- Precise location (GPS) — only when you enable Location. We keep your most recent coordinate to detect when a match is nearby; we do not keep a location history trail.
- Bluetooth proximity signals — when you enable Bluetooth, your phone and a match's phone exchange rotating anonymous codes to detect that you're physically near each other. We record proximity events (that a detection happened, signal strength, time).
- Ring and match activity — when a “ring” is triggered between you and a match, and whether each of you responded.
- Device push token — an identifier used to deliver notifications.
- Likes and passes (swipes) and the matches they create.
We do not use third-party advertising or analytics trackers, and we do not sell your personal information.
2. Sensitive information
Some of what we handle is legally “sensitive.” We collect it only to run the service:
- Precise geolocation and physical-proximity data (to power the ring).
- Information that can indicate sexual orientation — the genders you choose to see. We use this solely for matching; we never sell it or use it for advertising.
- Your photos — used only to build your profile. We do not use facial recognition.
Where the law requires your consent to process sensitive information, we ask for it (for example, the system permission prompt for location and Bluetooth). You can withdraw it any time in Settings (Ghost mode, or turning Location/Bluetooth off).
3. How we use your information
- Create your account and sign you in with your verified phone number.
- If you choose to verify your school email, display a verified-student badge on your profile.
- Show your profile to potential matches and show you theirs, filtered by your preferences.
- Detect when a match is nearby and trigger the ring.
- Deliver rings, matches, and messages, including push notifications.
- Suggest date venues and, if you choose, collect feedback about them.
- Keep the community safe (process blocks and reports, enforce our rules).
- Send optional re-engagement reminders (you can turn these off).
4. How the ring protects your location
The ring is designed to be privacy-first:
- Your exact location is never shown to another user. We only determine whether a match is within a short distance.
- The Bluetooth path uses rotating anonymous codes that only your and your match's phones can correlate — your identity is not broadcast.
- Ghost mode pauses all detection instantly.
5. Who we share information with
We share data only with service providers who help us operate Blushh, under contract:
- Supabase — our database, authentication, photo storage, and server functions.
- Twilio — sends your phone verification texts (receives your phone number).
- Resend — sends your email verification codes (receives your email address).
- Expo, Apple (APNs), and Google (Firebase Cloud Messaging) — to deliver push notifications.
- Apple App Store / Google Play — app distribution.
We may also disclose information if required by law, to protect the safety of users or the public, or in connection with a merger or acquisition (with notice as required).
We do not sell or “share” your personal information for cross-context behavioral advertising.
6. Your choices and rights
In the app you can:
- Turn on Ghost mode to pause all discovery, or toggle Location and Bluetooth individually.
- Turn re-engagement notifications on or off.
- Block or report another user.
- Edit your profile at any time.
- Delete your account (Profile → Delete account), which permanently removes your data (see §8).
Depending on where you live, you may also have the right to access, correct, delete, or receive a copy of your personal information, and to opt out of sale/sharing (we don't sell). To exercise these rights, use the in-app controls or email [email protected]. We won't discriminate against you for exercising your rights.
California residents have these rights under the CCPA/CPRA, including the right to limit the use of sensitive personal information.
7. Data retention
We keep your personal information for as long as your account is active, and:
- Inactive accounts are permanently deleted after 24 months without activity.
- Safety reports are deleted 12 months after we resolve them; unresolved reports are kept until reviewed.
- Blocks you create stay in effect for as long as both accounts exist (removing them automatically would silently re-expose you to the person you blocked).
- If we ban an account for violating our rules, we delete its personal data but keep a one-way cryptographic hash of the phone number (and email address, if one was provided) so the banned person cannot create a new account. This hashed record cannot be used to identify or reconstruct anything about a person, and is retained indefinitely.
When you delete your account, we permanently delete your data as described in §8.
8. Deleting your account
Deleting your account (Profile → Delete account) is permanent and immediate — there is no soft delete. We remove your profile, photos, messages, matches, likes and passes, blocks, reports, location data, Bluetooth/proximity records, and your login account. Our infrastructure does not currently retain automated backup copies, so deletion is immediate and complete. If we add backup infrastructure in the future, we will update this policy with its retention window.
9. Security
We protect your data with row-level access controls so users can only reach their own data, private photo storage with expiring links, rotating anonymous codes for proximity, and encryption in transit and at rest at our providers. No system is perfectly secure; messages and stored data are not end-to-end encrypted, meaning they are technically accessible to us to operate and moderate the service.
10. Children
Blushh is only for users 18 and older. We do not knowingly collect information from anyone under 18. If we learn an account belongs to someone under 18, we will delete it. If you believe a minor is using Blushh, contact [email protected].
11. International users / data transfers
Blushh is operated from the United States and your information is processed there by us and our providers. Blushh is currently intended only for students in the United States. If we begin serving users in the EU or UK, we will update this policy with the additional disclosures those laws require.
12. Changes to this policy
We'll update this policy as the app evolves and revise the “Last updated” date. For material changes we'll provide notice in the app. Continued use after changes take effect means you accept the updated policy.
13. Contact
- Privacy questions and data requests: [email protected]
- Safety concerns: [email protected]
- General support: [email protected]
Hassan Adegoke, sole proprietor