Privacy policy
Danial Barkhordar (Danial), an individual ("we"), runs the Acaso app and the website at acaso.place (served by Cloudflare Pages), and is the data controller for what they collect. This policy says what we collect, why we are allowed to, who else sees it, where it goes, and what you can do about it. Version 1.2, last updated 25 September 2026.
What we collect
| Data | Why | Kept |
|---|---|---|
| Apple Account sign-in — the identifier Apple gives us for you, and the email you choose to share (your own, or Apple's private relay address) | To sign you in and to keep fake accounts out. Never shown to other users. | Until you delete your account. If an account is closed for breaking the rules, the identifier and email are kept so it cannot come back |
| Profile — first name, date of birth, gender, home country, languages, interests, travel styles, countries visited, bio, prompts, photos, Instagram handle if you add one | To show other users who you are. Your date of birth is never shown; only your age. Gender is used only for your profile and for the choice some people make to be visible only to women and non-binary people. | Until you delete your account |
| Approximate location | To show who is nearby. We store your neighbourhood and a position rounded to about a kilometre (two decimal places) for distance maths; the app rounds it before it leaves your phone and the database rounds it again. Other users only ever see your neighbourhood and a distance band such as "2 km away" — never your coordinates. You can turn this off in Settings. | Replaced each time you refresh; stale after 14 days. We keep no history of where you have been |
| Plans and trips | To run the features you use them in. | Until you delete them or your account |
| Messages and chat photos | To deliver them to the people you sent them to. | Until you delete them or your account |
| Push token | To notify you of new messages and of things that involve you. | Until you sign out or uninstall |
| Profile views — whose profile you opened, and when you last did | For a "who viewed you" list that is not switched on. Today nobody is shown who looked at their profile; if that changes, this policy will say so first. | Until you delete your account |
| Blocks and reports | To keep people safe. Reports are never shown to the person reported. | Until you delete your account. A record of a report we upheld is kept after that, so the account cannot come back |
| Moments in the app — you joined a plan, shared a link, came back | To see whether Acaso works, in aggregate. Read only by us, never shown to anyone. | Until you delete your account |
| Crash reports — the phone model and system version, the app version, and where in the code a crash happened | To fix crashes on phones we cannot see. No name, email, location or IP address is sent. | 90 days |
| Waitlist — your email, and the city you name, if you ask to hear when Acaso opens there | To tell you when it does. | Until we have told you, or you ask us to remove it |
We do not collect contacts, precise or background location, advertising identifiers, or anything from other apps. There are no third-party ad or analytics SDKs, and we do not sell data.
Why we are allowed to
UK and EU data protection law asks us to say which legal basis covers each use.
| Use | Basis |
|---|---|
| Signing you in, showing your profile, delivering messages, running plans and trips, sending you the pushes you chose | Performing our contract with you (these terms) |
| Your approximate location | Your consent, given when you allow location in the app; withdraw it in Settings |
| The automated filter, reports, blocks, suspensions and the records we keep of them | Our legitimate interest in keeping people safe and enforcing the terms, and, where a report describes a crime, our legal obligations |
| Aggregate counts of what people do in the app, and crash reports | Our legitimate interest in knowing whether Acaso works and fixing it when it does not |
| Keeping the identifier of a closed account | Our legitimate interest in stopping a banned person coming back |
| Answering a request from the police, a court or a regulator | A legal obligation |
Where we rely on legitimate interests we have weighed them against your rights and kept the data to the minimum that serves the purpose. You can object; see "Your rights".
Who else sees it
- Supabase (database, file storage, sign-in) hosts the data, in the EU (Ireland).
- Apple signs you in and, if you chose Hide My Email, forwards our email to you through its relay. Apple learns that you use Acaso.
- Expo delivers push notifications and sees your push token and the notification text.
- Apple Maps (on iPhone) and Google Maps (on Android) draw the map and see the area you are looking at, as any map app's does.
- Photon, an OpenStreetMap search service run by komoot, answers the place search: it sees the words you type and the area to centre the results on. If we switch to Google Places, the same.
- Resend carries the email that tells us about a report: the first names of the two people, the reason and any note.
- Sentry receives crash reports, once we switch them on: the phone model, the system version, the app version and the stack trace. Nothing about you.
Each of them uses your data only to provide its service to us, and protects it to the same standard as this policy or an equal one.
Nobody else, with three exceptions. If the law requires it, or a court, the police or a regulator asks in a way we must comply with, we hand over what is asked for and no more. If we reasonably believe someone is in danger, we may pass what is needed to the emergency services. And if Acaso is ever taken over by a company, including one of our own, your data goes with it under this same policy, and we tell you first.
Where your data goes
Your data lives in Ireland, inside the EU. Some of the services above run in the United States: Apple, Expo, Resend, Sentry and Google. When data goes to them it is covered by the UK's data-bridge and adequacy decisions where they apply, and otherwise by the standard contractual clauses and the UK addendum that the law provides for, which each of these providers has signed up to. Either way it is protected to the same standard as in the UK and the EU, or an equal one.
Decisions made by software
Some decisions in Acaso are automatic: a filter refuses a message, plan or bio that clearly breaks the rules before anyone sees it, and flags some posts and new photos for us to look at afterwards; a serious report, or reports from two people, pauses an account and hides it until we have looked; and three reports in a week hide a profile for thirty days. None of these closes your account on its own: we decide that after looking, and you can ask us to look again at any automatic decision by writing to us. The Terms of Use, section 4, say how.
Your choices
- Who can find you — everyone, women and non-binary people only, or nobody (Settings).
- Hide from Nearby — one switch, keeps everything else working.
- Who can message you — everyone, people from your plans and friends, or friends only.
- Which pushes you get — each kind on or off in Settings, or all off in your phone's settings.
- Block anyone from their profile, a chat or a message; you will never see each other again.
- Delete your account — Settings → Delete account removes everything: your profile, messages you sent, your photos and the photos you posted into chats. A copy can remain in our backups and logs for a short time afterwards. Nothing else is kept except aggregate counts and, if a report against you was upheld, the identifier that stops the account coming back.
Your rights
Under the UK GDPR and, if you are in the EU, the GDPR, you can ask us to:
- tell you what we hold about you and give you a copy, in a form you can take elsewhere;
- correct anything wrong (most of it you can change yourself in the app);
- delete it (Settings does this instantly; writing to us does the same);
- restrict what we do with it, or object to a use based on our legitimate interests;
- withdraw a consent you gave, without affecting what was done before.
Email us at the address below. We answer within a month and never charge for it. We may ask you to confirm it is you, from the email on your account. If you are unhappy with our answer you can complain to the Information Commissioner's Office at ico.org.uk, or, in the EU, to your own data protection authority. We would rather you wrote to us first.
Security
Data travels encrypted and is stored encrypted. Every user can only read what the database rules let them read; a photo posted in a chat can be opened only by the people in that chat (and by us, to check it against the guidelines), through a link that expires within the hour; and the keys that run the service are held in the hosting provider's vault, not in the app. No system is perfect, and if a breach ever affects you we will tell you and the ICO as the law requires.
Children
Acaso is for people aged 18 and over. The date of birth check is enforced in our database, a report that says someone is under 18 pauses their account and hides it until we have looked, and we remove accounts we discover to be under 18.
Changes to this policy
When we change this policy we update the version and the date at the top and show it in the app. If a change matters, we tell you in the app or by email before it takes effect.
Contact
Danial Barkhordar (Danial), an individual in London, United Kingdom, who runs Acaso.
Email: hello@acaso.place. Every question, complaint, notice, legal claim and privacy request can be sent to it; it counts as received when it arrives. If you need a postal address to serve a legal document, ask at the same email and we will give you one.