Pineapple Play Date

Draft pending legal review

Privacy Policy

Last updated: [Effective date]

This policy explains how [Company legal name] ("we", "us") handles personal information in Pineapple Play Date, the product at https://pineappleplaydate.com. Our mailing address is [Mailing address].

This copy is a draft for a lawyer to review. It describes the product as it works in the app today. The Consumer Health Data Privacy Policy is part of this document and is also published on its own page.

Who this policy covers

This policy covers hosts, co-hosts, guests, and people who apply or sign in. It covers the public marketing pages and the signed-in app.

A host's house rules are written by that host. They are not this policy. If a host asks you for information in person, that request is the host's, not ours.

Sensitive information

Much of what the service stores is sensitive. It can describe your sex life, who you want to meet, and your body. We treat sexual orientation, sex life, and related profile and chat content as sensitive personal information.

We use that information to run the private event you joined. We do not use it to advertise to you, and we do not sell it.

We do not collect lab results, diagnoses, or medical records. Preferences, profile text, and chat can still be treated as consumer health data under the Washington My Health My Data Act. That is covered in the Consumer Health Data Privacy Policy.

Information we collect

Account. An email address. If you use Google sign-in, Google sends us an account id, your email, and the name on the Google profile when Google includes one. We store the sign-in method (email or Google). We never receive your Google password. Apple sign-in is not offered.

Profile. A display name, about me, what you are into, boundaries, age, height, body type, whether you smoke or drink, what you are looking for, tags, swap style, room style, and experience. We also store gender and who you are open to meeting. A host can require age, about me, and looking for before you finish swiping. You can hide some fields from other guests. The host can still see the guest list.

Photos. Up to 5 profile photos. Before a photo is stored, camera metadata is removed, including EXIF and GPS, and similar text in JPEG, PNG, and WebP files. An iPhone HEIC photo is re-encoded to JPEG first, which drops that metadata too. The same strip runs for chat photos. By default the file is stored in the database. If object storage is configured, the file is stored there instead. A saved account photo is the stripped file, and it is copied onto later events unless you change it.

Swipes. Yes, no, and a single super yes. The time of the answer. Speed-date events store a yes or no from a person toward a couple. We store whether the answer came from a speed-date round.

Partner preview. Sharing with your partner is on unless you or your partner turn it off, and only while the host allows it and swiping is still open. If either of you turns it off, neither of you can see the other's answers.

Matches. Pair matches, and group matches when the host turned groups on and the person opted in. Round seats after a reveal. Speed-date matches between couples.

Chat. Message text, sender name, photos, emoji reactions, whether a photo is view-once, and whether a message has an expiry. A host can set a timer or delete chat after the party. Those settings hide or remove messages in the product. They do not pull a copy off someone else's phone.

Agreements. The time you confirmed you are 18 or older, the time you accepted the terms, and which version of the house rules you agreed to. A host can also record that they checked your age offline. That host note stays with the event.

Door. A check-in code, a QR pass built from that code, and the time you checked in.

Need the host. If you tap that button after check-in, we store the time and the short note you typed. The host and co-hosts can see that it was you.

Screening. If you apply through a host's link, we store the application, the names, ages, genders, about text, and looking-for answers on it, and your answers to the host's questions. A referral can store the email address a guest typed for the person they invited.

Host notes. A host can mark a seat "do not invite again". That flag is private to the host. It is not a public badge.

Test parties. A host can make a practice party with fake names and generated photos. Those parties do not send email or push. If you delete your account, a test party you host is not automatically deleted.

Device storage.

Notifications. If you turn on reminders, we store the browser push endpoint and its keys. Email reminders use the email on the account. Sign-in email uses the product name and includes the sign-in link. Email and push about an event do not use the real party name. They say "Your event", unless the host set a public-safe name. The calendar title follows the same rule. The real name stays in the app after you sign in.

Logs. We do not have a field in the database for your IP address. The company that hosts the website can keep request logs, which may include an IP address, for its own operations. Our app does not run a separate analytics product.

Why we use it

We use this information to:

We do not use your information to train public advertising profiles. We do not sell personal information, and we do not share it for cross-context behavioral advertising.

Where a law asks us to name a legal basis, we rely on:

We do not sell personal information

We do not sell personal information. We do not share it for targeted advertising. There is no advertising partner on the app.

If you still want this recorded, email privacy@pineappleplaydate.com with the subject "Do not sell or share". We will note the request. There is nothing to opt out of in an ad system, because we do not operate one.

Who can see what

Other guests in your event can see your display name, your photos, and the profile fields you have not hidden. They do not see your email. They do not see a "no" as a no. They see a match when the rules say it is time. They can see group chat, if chat is open and they are still in the event.

Your partner can see your swipes only during partner preview: the host has it on, swiping is still open, and both of you still have sharing on. Either of you can turn it off, and then it stops for both.

The host and co-hosts can see the guest list, profile details, photos, check-in codes and times, house-rule agreement, and the swipe grid, including yes, no, and super yes. They can see need-the-host alerts, including who sent one. They can see screening applications for their links. Co-hosts see the same host tools.

We can access the database to operate and support the service. Support access is limited to people who run the product.

Other people's content that mentions you can remain in their chat messages. We do not silently rewrite someone else's message.

Service providers

These companies process information for us. They are not allowed to use it for their own advertising.

We do not use a separate analytics vendor in the app.

Discreet notices

Party email, push, and calendar titles are written so a lock screen does not show the real party name. They say "Your event", or the public-safe name the host typed. The sign-in email is different: it says Pineapple Play Date, because it is a sign-in to the product, and it contains the link.

Cookies and storage on your device

The cookies and storage keys are listed above. The session cookie is how you stay signed in. The age confirmation on the marketing pages is localStorage only. Blocking cookies will sign you out and can stop Google sign-in. Blocking localStorage will show the 18+ notice again on the public pages.

We do not use advertising cookies.

How long we keep information

We do not automatically delete accounts, photos, swipes, or chat on a timer, except for the chat timer and the "delete chat after the party" switch a host turns on for that event.

We keep information until you delete it, you delete your account, a host deletes the party, or we delete it to enforce the terms. A host's do-not-invite flag is meant to stay on that host's seat after the event.

Backups. The app does not keep a second archive of its own. Supabase may keep automatic database backups after a live row is deleted. We cannot erase a backup on the same day from inside the app. Email privacy@pineappleplaydate.com if you need the backup window for the current project.

Parties you host. Deleting your account does not delete those parties. Other guests would lose the event. We remove your email and your sign-in methods so the old login stops working. The party stays.

Delete your account

Open Settings, then Delete account, and type DELETE. The control is on the Settings page at /account, linked from your party list, the host home, and the guest profile tab. You can also email privacy@pineappleplaydate.com. We will use the same deletion for a verified request.

Removed from the live database

Left in place

We sign you out when deletion finishes. Signing in again with Google or the same email creates a new, empty account. It does not restore the old one.

Your choices and rights

You can correct profile fields, photos, and notification choices in the app. You can turn off partner preview and, where the event allows it, group matching. You can withdraw a swipe until the deadline. You can skip check-in. You can delete your account as described above.

Depending on where you live, you can also ask us to:

Email privacy@pineappleplaydate.com from the email on your account. We may need to confirm it is you. We will respond within 45 days, or sooner if your local law requires it. We will not discriminate against you for asking.

There is no in-app download button. A portability request is handled by email from what is still in the live database.

California

If the California Consumer Privacy Act, as amended by the CPRA, applies, this section is our notice.

We collect the categories listed above: identifiers (name, email), customer records (account), commercial information is not collected because we do not sell the service today, internet activity limited to host logs described above, and sensitive personal information. Sensitive personal information includes account log-in, the contents of your messages, and information about sex life or sexual orientation that you put in a profile, swipe, or chat.

We use sensitive personal information only to provide the service you asked for, for security, and for the short-term transient use of showing an event. We do not use it to infer characteristics for advertising. You can still ask us to limit use by emailing privacy@pineappleplaydate.com with the subject "Limit use of sensitive information".

We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not offer financial incentives for your data.

You have the rights listed in the section above. You can use an authorized agent if you give the agent signed permission and we can verify you. We will not discriminate for exercising these rights.

Consumer Health Data Privacy Policy

This section is the Consumer Health Data Privacy Policy for Washington's My Health My Data Act. It is also published at https://pineappleplaydate.com/privacy/health.

Last updated: [Effective date]

The controller is [Company legal name], [Mailing address]. Contact privacy@pineappleplaydate.com.

Consumer health data we collect. We do not collect lab tests, diagnoses, or records from a clinic. The app can still hold information Washington treats as consumer health data, because it can identify sexual health or sex life. That includes gender, who you are open to, sexual preferences and boundaries, body details you choose to add, swipe answers, match results, and chat or photos that describe sex or your body.

Consent. We collect this information only after you put it into the service, or after you confirm you are an adult and accept the terms. You can refuse to fill optional fields. Required fields for an event are age, about me, and looking for. If you do not want to provide them, do not finish joining that event.

Why we collect it. To run the private matching event, to show a profile to the people described in this policy, and to enforce age and safety rules. We do not use it for advertising. We do not sell consumer health data. We do not share it with data brokers.

Who receives it. Hosts and co-hosts of your event, other guests to the extent described above, and the service providers listed in this policy (Vercel, Supabase, Resend when email is on, Google when you use Google sign-in, a browser push service if you enable reminders, and object storage if it is configured).

Your rights. You can ask for confirmation, access, and withdrawal of consent. You can delete consumer health data by using Settings, then Delete account, or by emailing privacy@pineappleplaydate.com. Deletion follows the "Delete your account" section. We will tell service providers to delete the same information when we are required to, except where a backup or a legal duty keeps a copy for a limited time.

Appeals. If we deny a request, reply to that email and ask for an appeal. If you are in Washington and the appeal is denied, you can contact the Washington Attorney General.

Texas, Colorado, Virginia, and Connecticut

Residents of Texas, Colorado, Virginia, and Connecticut can ask to access, correct, delete, and obtain a portable copy of personal data, and to appeal a denial. You can also opt out of sale, targeted advertising, and certain profiling. We do not sell personal data, we do not run targeted ads, and we do not profile you for decisions that produce legal or similarly significant effects.

Email privacy@pineappleplaydate.com. We will answer within the time your state's law requires, and explain how to appeal if we say no. If an appeal is denied, Colorado, Virginia, and Connecticut residents can contact their state attorney general. Texas residents can contact the Texas Attorney General.

Visitors outside the United States

If you use the service from outside the United States, including from the European Economic Area, the United Kingdom, or Switzerland, you can ask for access, correction, deletion, restriction, portability, and a copy. You can object to processing based on legitimate interests. You can withdraw consent. You can complain to your local data protection authority.

We do not appoint a European representative in this draft. [Company legal name] will add one if a lawyer says the service needs it. Contact privacy@pineappleplaydate.com in the meantime.

Security

We protect the service with HTTPS, a signed httpOnly session cookie, and hashed sign-in links. The database connection is encrypted in transit. Some tables have row level security enabled so the public database roles cannot read them. The app server uses a privileged database login, so row level security is not what stops one guest from reading another guest's swipes. The app decides that.

Chat is not end-to-end encrypted. Photos are not end-to-end encrypted. People who operate the database can access rows. Camera metadata, including GPS, is removed from every uploaded photo before it is stored.

No method is perfect. We cannot promise that a guest will not screenshot a profile.

Children

The service is not for anyone under 18. We do not knowingly collect personal information from anyone under 18. If you believe a minor has an account or appears in a photo, email privacy@pineappleplaydate.com and legal@pineappleplaydate.com. We will delete that information and close the account.

International transfers

The website is hosted by Vercel and the database is hosted by Supabase. Those providers can store data in the United States or in the region selected for the project. Email privacy@pineappleplaydate.com if you need the current region. If we transfer personal information from your country, we do so to run the service you joined. Where the law requires a transfer tool, we will use one. This draft does not name a specific transfer contract yet. A lawyer should add it if the service has users in those countries.

Changes

We will post changes on this page and change the date at the top. If a change is material, we will post it before it applies and we may email the address on your account. The consumer health policy date will change in the same way.

Contact

[Company legal name] [Mailing address] Privacy: privacy@pineappleplaydate.com Legal: legal@pineappleplaydate.com

Use the privacy address for access, correction, deletion, portability, appeals, and "do not sell or share" requests.

Home · Terms · Privacy · Consumer health · Contact