who.

Privacy Policy

Effective date: July 5, 2026 · Last updated: July 14, 2026

In plain English: we collect what you put in your profile, basic account info from sign-in, and what’s needed to run search, connections, and messaging. We don’t sell your data. If you’re not connected with someone, they only ever see the limited preview your visibility settings allow — never your full profile, and never your messages. Messages are stored to make the messaging feature work; they are not end-to-end encrypted.

1. What We Collect

We collect the following categories of information:

  • Account info: your email and name, provided by your sign-in method (Google).
  • Date of birth: we collect your date of birth to check that you meet our 18+ age requirement. This is a self-reported age gate, not independent identity verification. It is stored privately, is never shown on your profile, and is not visible to other users.
  • Profile content: whatever you choose to add to your profile — name, handle, photo, location, headline, values, interests, current focus, and any other fields you fill in.
  • Connections and messages: who you’ve requested/accepted as connections, and the content of messages you send.
  • Usage data: basic technical information (e.g. that you searched, viewed a profile, or sent a connection request) used to operate and improve the Service, and to detect abuse.
  • Device and log data: your IP address, a device identifier, browser type, and similar technical metadata. We collect these automatically to operate and secure the Service, prevent fraud and abuse, and enforce our age requirement (for example, to stop a device that failed the age check from immediately retrying).

2. How We Use It

We use your information to:

  • Create and display your profile according to your visibility settings.
  • Power search, QR/link sharing, connection requests, and messaging.
  • Check that you meet our 18+ age requirement (based on your self-reported date of birth).
  • Scan images you upload for illegal or prohibited content before they are published (see “Content Moderation and Safety” below).
  • Keep the Service secure and prevent abuse (e.g. rate-limiting, spam prevention, fraud detection, enforcing our Terms).
  • Communicate with you about your account (e.g. security notices), if we ever need to.

We do not sell your personal information, and we do not use your profile content to train third-party models.

3. Profile Visibility and Who Can See What

Your profile has a visibility setting: preview-until-connected (the default), fully public, or hidden from search. Regardless of setting, anyone with your link or QR code can view the limited preview (name, handle, photo, headline, and any location/status/what-you-do fields you’ve chosen to show). Your full profile is visible only to you, your accepted connections, or — if you set your profile to public — anyone. Fields you turn off in your visibility toggles are never included in what people you’re not connected with, search results, or previews can see.

Search results and profile previews only ever include the limited preview fields — never your full About section, values, current focus, personality details, or anything you’ve marked hidden.

4. Messages

Messages are only exchanged between accepted connections and are stored so the messaging feature works — they are not end-to-end encrypted. We do not read your messages as a matter of course, but we may access message content if required to investigate abuse, enforce our Terms, or comply with law.

5. Sharing and Third Parties

We use a small number of infrastructure providers to run the Service, each of which processes data on our behalf:

  • Supabase — database, authentication, and file storage.
  • Vercel — hosting.
  • Google — sign-in (OAuth) and push notifications (Android/Firebase).
  • Expo — delivery of push notifications to the mobile app.
  • Upstash — rate-limiting and abuse prevention (processes your IP address and account identifier to enforce request limits).
  • Image-safety tools — where used, automated services that help detect illegal or prohibited content in uploaded images (including known child sexual abuse material). These process the image to return a safety result; we do not use them to advertise to you or build a profile of you.

We do not sell your data to advertisers or data brokers. We may disclose information if required by law, to protect the rights and safety of our users, or in connection with a merger, acquisition, or sale of assets (in which case we’ll make reasonable efforts to notify you).

6. Cookies and Similar Technologies

We use strictly necessary cookies to keep you signed in and to operate core functionality (for example, your authentication session). We do not use third-party advertising cookies or cross-site tracking cookies. We may use basic, privacy-respecting analytics (such as aggregate page-view counts) to understand how the Service is used; this does not involve selling your data or building an advertising profile of you.

7. Data Retention and Deletion

We retain your profile and message data for as long as your account is active. You can request deletion of your account and data at any time from your account settings, from the account deletion page, or by emailing hello@getwho.app. Deleting your account is complete and permanent: it removes your profile, all of your uploaded images (profile picture and Moments), your connections and messages, your date of birth, your notification settings, and your underlying sign-in itself. Some information may be retained briefly in backups or logs for security and legal-compliance purposes before being fully purged.

One exception: where content has been reported and preserved as evidence of a serious safety violation (such as material we are legally required to report), we may retain that specific evidence as required by law even after an account is deleted.

8. Your Choices

  • Control what’s visible on your profile via the visibility toggles on each field.
  • Set your overall profile visibility to preview-only, public, or hidden from search.
  • Delete individual profile fields at any time.
  • Request full account deletion at any time.
  • Contact us with any privacy question at hello@getwho.app.

9. California Privacy Rights (CCPA)

If you are a California resident, you have the right to request that we disclose the categories and specific pieces of personal information we’ve collected about you, request deletion of your personal information, and be free from discrimination for exercising these rights. We do not sell personal information as defined by the CCPA. You can exercise these rights by emailing hello@getwho.app; we may need to verify your identity before fulfilling certain requests.

10. Age Requirement and Child Safety

who. is strictly for adults 18 and older. We verify age at sign-up by collecting your date of birth and blocking anyone under 18. It is not directed to, and is not intended for use by, anyone under 18.

We have zero tolerance for child sexual abuse and exploitation (CSAE). You may not upload any image containing an identifiable minor, and any sexual content involving a minor is strictly prohibited. To enforce this:

  • All uploaded images are automatically scanned before they are published, including matching against databases of known child sexual abuse material (CSAM).
  • We remove prohibited content and, where required by law, preserve it and report it to the National Center for Missing & Exploited Children (NCMEC) and/or relevant authorities.
  • You can report a profile, image, or message at any time in the app, or by emailing our safety team at safety@getwho.app.

If we learn we have collected information from anyone under 18, we will delete it promptly. See our Terms of Service for our full age and conduct policy.

11. Security

We use industry-standard practices to protect your data, including row-level database access controls that restrict who can read your profile and messages at the database layer, not just in the app’s interface. Sensitive fields (such as your date of birth, IP address, and device identifier) are never exposed through our public interfaces. Uploaded images are pre-moderated — scanned before they are ever made visible to anyone. No method of transmission or storage is 100% secure, and we can’t guarantee absolute security.

12. United States Only

who. is intended only for users located in the United States. The Service is not offered to, or directed at, anyone outside the United States, and we do not intend to subject ourselves to the data-protection or other laws of any country other than the United States. If you are located outside the United States, please do not use the Service.

The Service is operated from, and our infrastructure providers store data in, the United States. To the extent you access the Service, you understand that your information will be processed in the United States.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we’ll make reasonable efforts to notify you (e.g. by posting a notice on the Service or updating the “Last updated” date above).

14. Contact

Questions about this policy or your data? Contact us at hello@getwho.app or hello@getwho.app.