Privacy Policy
This policy explains what personal data the Pololos app processes, for what purpose, on what legal basis, and what rights you have over it. It is written in accordance with Chilean personal data protection legislation: Law No. 19.628 and Law No. 21.719.
The short version: we collect the bare minimum, your messages are encrypted and we cannot read them, your exact location is never stored, and we do not sell your data to anyone.
This is a courtesy English translation. In case of any discrepancy, the Spanish version prevails.
1. Data controller
The controller of your data is the Pololos team. For any inquiry, request, or exercise of your rights you can write to: contacto@apppololos.cl.
2. What data we process
When you create an account and use the app, we process the following categories of data:
- Account data: email address and password (stored encrypted and irrecoverable).
- Profile data: name, date of birth (to verify you are over 18 and to show your age), gender, height, city, bio, and your interests.
- Search preference (sensitive data): who you want to meet. This data may reveal your sexual orientation, so it is processed only with your express consent, given when you create your account, and for the sole purpose of connecting you with compatible profiles.
- Photos: the profile photos you choose to upload. They are stored in a private repository and served only through temporary links that expire.
- Approximate location: your coordinates are rounded to a precision of approximately 1 kilometer before being stored. Your exact location is never stored or shared. Location is used only with your prior, explicit consent.
- In-app interactions: likes, matches, scheduled dates, and no-show reports (anti-ghosting system).
- Compatibility quiz (optional): your answers to the "I'm feeling lucky" quiz, only if you choose to answer it and with specific prior consent.
- Public encryption key: required so other users can send you encrypted messages. Your private key never leaves your phone.
- Notification token: a technical identifier for your device so we can send you push notifications.
3. What we do NOT do with your data (privacy by design)
Pololos applies the proportionality and data minimization principles of Law No. 21.719: we collect only what is strictly necessary to provide the service.
- We cannot read your messages. Chats use end-to-end encryption: they are encrypted on your phone and only your match can decrypt them. Neither Pololos nor its providers have access to the content.
- We store your date of birth solely to verify you are over 18 and to display your age; it is never shared with other users.
- We do not store your exact location, only an approximation of ~1 km, and it is never given to other users under any circumstances.
- We do not sell or transfer your data to third parties for commercial or advertising purposes.
- We do not include content in notifications: push alerts say only "You have a new message", with no sender and no content, so nothing readable travels through third-party servers.
- We do not build advertising profiles or share your activity with external ad networks.
4. Purposes and legal bases
We process your data only for the following purposes, each with its legal basis under Law No. 21.719:
- Providing the service (creating your profile, showing you compatible profiles, managing matches, chats and dates) — performance of the contract.
- Showing you nearby people using your approximate location — consent, which you can withdraw at any time by turning off location.
- Suggesting compatible profiles based on the optional quiz — specific consent.
- Suggesting places for dates (venues near the midpoint between both users) — consent given when accepting the privacy notice at sign-up.
- Moderation and safety (control of the main photo —taken with the camera at that moment—, automatic photo analysis with artificial intelligence to block inappropriate content, anti-ghosting system, anti-abuse limits) — legitimate interest in maintaining a safe and respectful community.
- Sending you notifications about new messages and matches — performance of the contract; you can turn them off on your device.
- Statistics for business profiles: aggregated, anonymous counters (how many people saw a venue), which do not identify you — legitimate interest.
- Operating business accounts (account email and venue details: name, address, photos, description, services and promotions, including prior review of the venue) — performance of the contract. Company data itself is not personal data; this basis covers the data of the natural person behind the account.
5. Who we share data with (data processors)
We do not share your data with third parties except for the technical providers strictly necessary for the app to work, which act as data processors under their own data protection commitments:
- Supabase — database hosting, authentication, and photo storage.
- Google Maps Platform — maps and address search within the app.
- Google Cloud Vision — automatic photo analysis for content moderation. Images are analyzed and not kept for other purposes.
- Firebase Cloud Messaging (Google) — push notification delivery. It only receives the generic alert, never the content of your messages.
These providers may process data on servers located outside Chile (international transfer). All of them offer adequate data protection guarantees, as required by Law No. 21.719 for international transfers.
6. Retention period
We apply concrete retention periods, with automatic deletion:
- Your account and profile data are kept for as long as your account exists.
- If you delete your account (how to do it), your profile data, photos, matches, and chats are removed from our systems immediately.
- Messages: messages (always end-to-end encrypted; we can never read them) are permanently deleted from our servers 12 months after being sent.
- Inactive accounts: if you do not sign in for 24 months, your account and all its data are permanently deleted.
- Photo moderation records are kept for 12 months. Reports between users and their evidence (the screenshots attached when reporting) are kept for 24 months, to prevent repeated abuse. This evidence is the only exception to immediate deletion: it survives the deletion of your account until that period ends, because it is the proof of a report that may affect another person. Everything else —profile, photos, messages, matches— is deleted immediately.
- Technical data: notification tokens unused for 12 months and detailed business statistics older than 180 days are deleted automatically (only aggregate counters that cannot identify you persist).
- Encrypted messages that can no longer be decrypted (for example, after your keys are deleted) are permanently unreadable.
7. Your rights
Under Law No. 21.719, you have the following rights:
- Access: to know what data of yours we process and obtain a copy. You can download it instantly from the app: Profile → Settings → "Download my data".
- Rectification: to correct inaccurate data (most of it you can edit directly in your profile).
- Erasure ("right to be forgotten"): to delete your account and your data, from the app itself or by writing to us.
- Objection and restriction: to object to processing based on legitimate interest or request that it be restricted.
- Portability: to receive your data in a structured, commonly used format (JSON), through the same "Download my data" option in the app.
- Withdrawing your consent at any time (for example, by turning off location), without affecting the lawfulness of prior processing.
- Filing a complaint with the supervisory authority: Chile's Personal Data Protection Agency.
To exercise any of these rights, write to us at contacto@apppololos.cl. We will respond within the legal deadlines.
8. Security
We apply technical and organizational measures in accordance with the security duty established by Law No. 21.719, including:
- End-to-end encryption of all messages (Curve25519 + XSalsa20 + Poly1305), with private keys stored in your phone's secure storage that never leave it.
- Verifiable safety numbers per conversation to detect impersonation.
- Photos in private repositories, served only through temporary links that expire.
- Database-level access rules that prevent one user from accessing another user's data.
- Coordinate rounding before storage and protections against triangulation techniques.
- Encrypted communications (TLS) between the app and the servers.
- Automatic anti-abuse limits (frequency of messages, likes, and reports).
9. Minimum age
Pololos is an app exclusively for people 18 and older. We do not knowingly process data of minors; if we detect an account belonging to a minor, it will be deleted.
10. Moderation and anti-ghosting system
To keep the community safe, photos are automatically analyzed before being published, and users can report no-shows to scheduled dates. These reports can only come from people you had a real relationship with inside the app, are protected against false or duplicate claims, and may result in warnings or temporary account suspensions. You can request a review of any moderation decision by writing to us.
11. Changes to this policy
If we modify this policy, we will publish the new version on this page with its update date and, if the change is substantial, we will notify you in the app and ask for your consent again where required by law.
12. Contact
For any questions about this policy or about the processing of your data: contacto@apppololos.cl