Privacy Policy
Churr is run by a single person in Toronto — a sole proprietorship registered in Ontario, Canada. This policy describes what Churr collects, why, where it goes, how long it stays and what you can make us do about it. It is written to be read, not to be survived.
If you want to talk to a human about any of it, write to hello@churr.io. That address reaches the person accountable for privacy at Churr, which under PIPEDA has to be a named individual, and is.
The short version
- No photos. No address. No location tracking. No date of birth.
- We store your phone number only as a one-way hash. The sign-in service that texts you the code holds the number itself, because a code cannot be sent to a hash.
- We do not sell your information. No advertising software is active in the app unless the network-ads feature is switched on, and it is off.
- Your twin's conversations are used to run the product. They are used to *improve* the product only if you switch that on, and it is off unless you do.
- How you use the app is measured only if you switch it on, and never by a third party.
- Everything Churr stores lives in Canada. Your twin *thinks* in the United States, because the AI provider that runs it is American. The kinds of company involved are described below, and every one of them is named on a separate page, linked from there.
- Delete your account and everything derived from it goes, including the conversations your twin had with other people's twins.
What we collect, and why
Your phone number. To create the account and to make sure one person is one account. We store a peppered SHA-256 hash — a fixed-length string that cannot be turned back into your number by anyone who does not also hold our server secret. We keep it because we need to recognise you next time, not because we want to call you. That is true of our own systems. The sign-in service that sends your one-time code holds the number in readable form, because that is where the code goes, and the text-message carrier it uses sees the number each time a code is sent. Both are named on the recipients page.
That you are 18 or over. A timestamp, set when you tap the toggle on the age gate. No date of birth is collected or stored. Collecting a birthday to prove someone is not a child means collecting a child's birthday.
A liveness check. Whether a check happened, when, and the verdict. The image is never stored and never leaves your phone. *As of this version, the liveness check is not yet integrated with a vendor: the app records the check as skipped rather than passed, and the screen says so.* When a real check lands, this paragraph will describe the vendor by name.
Your neighbourhood. Typed by you, in words ("Roncesvalles"). It is used to decide which introductions and which open plans you see. The app asks for no location permission, records no coordinates, and has no way to know where you are.
The interview, and your twin. What you say when your twin is built, and the profile it produces: your first name, an age band, your interests, what you are looking for, when you are usually free, and the things you have told it not to say. Every fact is marked shareable or private, by default private, and only the shareable ones can reach another person's twin.
Daily check-ins. Short exchanges with your twin, and whatever it learns from them.
Introductions, plans, chats and check-ins after a meeting. Who you were introduced to, what you agreed to do, what you said in the group chat, and whether you met.
The overnight conversations. Your twin and another person's twin have a conversation while you are asleep. It is stored once, and both of you can read every word of it.
Push tokens. An opaque device identifier, so the morning can arrive.
How you use the app — only if you switch it on. If you turn on "Measuring how Churr is used" in Settings → Your data, the app records which screens you open and when, and the named things you do in it (opening the app in the morning, saying hi to an introduction, declining one and the reason you picked, locking a plan). Each record is a screen name and a few numbers or labels — never anything you typed, never a venue, never a neighbourhood, never your phone number. It is kept by us, in Canada, in the same database as everything else; there is no analytics company involved and nothing about it is shared. We use it for one thing: to tell whether people who are introduced actually meet, and where the way in loses people. It is off unless you switch it on, you can switch it off at any time, and nothing about the product changes either way.
Server logs. Request paths, status codes, timings, your user id, and the internet address your phone connected from. Never message contents, never a profile, never a transcript, never your phone number. This is enforced in code, not by policy. The logs are kept by our hosting provider for seven days and by nobody else; see the retention table.
We do not collect: photographs, contacts, your address book, calendar contents, precise location, health information, payment details, or anything about you from other services.
Why we are allowed to (lawful basis)
Under PIPEDA, we rely on your consent, which we ask for in plain words at the point of collection and record. There are six separate consents, and they are separate on purpose — one "I agree" covering all of them would make the ones you can withdraw inseparable from the ones you cannot:
1. The terms and this policy, when you sign up. Recorded on the first screen, before we ask for your phone number. 2. Using the interview to build your twin. Without this there is no product. Recorded when you approve your twin on the Twin Review screen — nothing runs before that. 3. Using your twin's conversations to improve Churr — including testing changes against real examples. This is off by default, it is a separate switch in Settings, and turning it off later takes effect immediately. 4. Processing in the United States, disclosed and acknowledged at the same moment as 1. 5. Personalised ads. Off unless you allow it. This is what the iOS "Allow tracking?" prompt records, and it only ever means one thing: whether an advertiser may use your device's advertising identifier to choose which ads you see. Saying no costs you nothing — you see the same number of ads, chosen without it — and you can change your mind in Settings. Your answer is recorded either way, because "asked and declined" and "never asked" are different facts. 6. Measuring how Churr is used. Off unless you switch it on in Settings → Your data, and you can switch it off there at any time. Nothing about the product changes either way.
For anyone in the EU or UK reading this, the equivalent GDPR bases are Art. 6(1)(b) (performance of the contract) for 1 and 2, Art. 6(1)(a) (consent) for 3, 5 and 6, and Art. 6(1)(f) (legitimate interests — keeping the service safe) for the safety and moderation records described below.
Where your information goes
Everything Churr stores sits in a database in Canada (Montréal). A small number of companies handle parts of it for us, and they fall into these kinds:
- A database and sign-in service, in Canada. Holds everything the app stores, and holds your phone number in readable form so it can send you the sign-in code.
- A text-message carrier, which the sign-in service uses to deliver that code. It sees your number and the code, once per sign-in, and nothing else.
- An AI provider, in the United States. Runs the model your twin is made of. It receives your twin profile, the interview transcript, check-in text and the twin-to-twin conversations — never your phone number, never anything you marked private. Its commercial terms provide that what we send is not used to train its models; we rely on those terms rather than paraphrasing them.
- A push notification service, in the United States, and the phone maker's own notification system. They receive the notification text, which can include other people's first names, and your device push token.
- A hosting provider, in Canada. Runs our server and keeps its request logs, including the internet address your phone connected from, for seven days.
- A crash reporter, in the United States, only when crash reporting is switched on for the build. Receives the error, your phone model and system version, and an opaque account id — never anything you or your twin wrote.
- A payment provider, only when a paid feature is on. Takes your card on its own page so we never see it; we are told the outcome and keep a reference.
- An advertising network, only when network ads are on. Its software reads your device's advertising identifier only if you allow tracking when iOS asks; none of it passes through us.
- An event listings source and the website host. Neither receives anything from your account.
The names behind each of those, what each one receives and where it is are on one page, Who handles your information. That page changes when a company changes and does not need a new version of this policy; this policy changes when the kind of processing changes, and that does ask you to accept it again.
Under PIPEDA a transfer for processing is a *use*, not a disclosure, and it does not need separate consent — but it does have to be told to you, and Churr stays accountable for what those companies do with it. Your information leaves Canada for the companies marked as being in the United States above, and for nothing else.
Under GDPR the recipients outside Canada are transfers to a third country under Chapter V and are made on each company's standard contractual clauses.
We do not sell your personal information and we do not share it with data brokers, advertisers or ad networks. No advertising software is active in the app unless the network-ads feature is switched on, and it is off. When it is on, an advertising network's software fills the ad slots and reads your device's advertising identifier only if you allow tracking when iOS asks; this policy will say so in the present tense before that happens. There is no tracking pixel, and no analytics company: measuring how the app is used, if you switch it on, is done by us and shared with nobody.
Sponsorship and advertising
Churr has features, currently switched off, that would let a venue or an organiser sponsor an event or a slot in the plans list. To be accurate about what those would and would not do:
- A sponsored item is labelled as sponsored on the card, in the same words every time.
- A sponsor does not receive your personal information. They do not learn who saw the item, who it was shown to, or anything about you. They get counts.
- Sponsorship never changes who your twin is introduced to. Matching is not for sale.
- If any of that ever stops being true, this section changes before the feature ships, and the change makes you re-accept this policy.
Every one of those features is behind a switch that is off today. This section describes them because the honest time to describe an advertising model is before it exists, not after.
How long we keep things
| What | How long | Why that long |
|---|---|---|
| An interview you started and never finished | 30 days | Long enough to come back to; short enough that half a life story is not sitting on a disk. |
| An introduction that expired or that you declined | 90 days | The "don't introduce these two again" filter reads it. |
| The overnight conversation between two twins | 12 months | Both of you can read it while it is a live introduction. |
| Your interview transcript and daily check-ins | 12 months | Your twin is built from it and the accuracy loop reads it. |
| Text the injection screen held back for review | 90 days | Long enough for a person to look at it. |
| Which ads you were shown | 35 days | The frequency cap reads the last day and an advertiser's count reads the last month. After that the row keeps its counts and stops naming you. |
| Which screens you opened and when | 90 days | After that the record keeps its counts and loses your name: a permanent record of which person opened which screen when would be a behavioural profile, and we do not build one. |
| Server logs | 7 days, kept by the hosting provider | The logs are written to our hosting provider and stay there. Seven days is their setting, not a job of ours; we keep no other copy and ship them nowhere. |
| A data export you asked for | 24 hours, one download | A permanent link to everything about you is a bad idea. |
| Cost accounting rows (token counts, prices — never content) | Kept | They survive account deletion with every identifier scrubbed. |
| A record that a deleted account had consented | Kept, as a hash | Proves what was agreed without being a pointer to a person. |
| Your account and your twin | Until you delete it |
A job runs daily and enforces every row in that table with a number in it, except the server logs, which live at the hosting provider and are deleted on its clock. The schedule is not a promise about intentions; it is a description of a program.
Your rights
Under PIPEDA you can ask us for access to everything we hold about you, ask us to correct it, and withdraw consent. Under GDPR — which applies to you if you are in the EU or the UK — you also have rights to erasure, restriction, objection and portability, and the right to complain to your supervisory authority.
In the app, without asking anyone:
- Read everything your twin knows — Settings → What your twin shares — and edit it.
- Fix your name, your neighbourhood and your age band — Settings.
- Export everything — Settings → Your data. You get a JSON file with your profile, your facts, your transcripts, your plans, your check-ins, your flock, your consents, your settings, the people you have blocked, the reports you have filed, and anything you have bought. The other person's side of a conversation is included only where both of you can already read it, and their private facts are never in it. Two things are deliberately left out: reports other people have made about *you*, which are their words about their own experience, and your device's push token, which is a live credential and not something to put in a downloadable file.
- Turn off product-improvement use — Settings → Privacy.
- Delete your account — Settings → Delete my account. Two taps from anywhere. It purges synchronously: your account, your twin, your transcripts, your plans, your messages, your push tokens, and the twin-to-twin conversations you were part of — which are deleted for the other person too, because a conversation belongs to both of you. Any record of how you used the app goes with the account.
Two things about other people, because they are not obvious. A plan you were hosting is called off, and its group chat stays open for the people who had joined — the plan is cancelled, your name comes off it, and what you wrote in the chat is blanked in place, but the conversation and everyone else's messages in it are theirs and are not yours to delete. A plan you had merely joined stays in the same way, minus your seat. And a report someone else has filed about you is kept, with your identity removed from it: deleting your account is not a way to clear a safety record somebody else wrote.
By email to hello@churr.io, or in the app under Settings → Your data → Make a request: any of the above, plus objection and restriction. We answer within 30 days, which is PIPEDA's standard and GDPR's one month.
We do not charge for any of this and we do not make you jump through a support queue for it.
Security
Phone numbers are hashed with a server-side secret. Data is encrypted in transit (HTTPS everywhere) and at rest (the database provider's AES-256). Row-level security policies are written for every table so that, on the paths where a client talks to the database directly, one person cannot read another's rows. Logs are redacted of credentials and request bodies. Everything a user or another user's twin writes is screened for prompt injection before it can reach a model, and anything that trips the screen is quarantined rather than used.
If there is ever a breach that creates a real risk of significant harm to you, we will report it to the Office of the Privacy Commissioner of Canada and tell you, as PIPEDA requires. We keep a record of every breach for 24 months whether or not it is reportable.
Children
Churr is 18+. We do not knowingly collect anything from anyone under 18. If you believe a minor has an account, write to hello@churr.io and it will be removed.
Automated decisions
Matching is automated: your twin's profile is compared with other people's, a model scores the pair, two twins have a conversation, and the results are ranked. Nobody is accepted or rejected for anything with a legal or similarly significant effect — the outcome is which three introductions you are shown on a given morning. You can pause your twin at any time, decline any introduction, and edit or delete anything the matching reads.
Changes
If this policy changes materially, the app shows you the new version and asks you to accept it. You can put that off — there is a "Later" button, because a sheet you cannot get past on a train with no signal is a worse outcome than a delayed acceptance — and it comes back every time you open the app until you do. The version is recorded with your consent, so we can always say which words you agreed to.
Some features this policy describes as switched off — network ads, paid features, a crash reporter — may be switched on later. Switching one on is a material change: before it happens, this policy is rewritten to describe it in the present tense, and you are asked to accept the version that describes it.
Contact
hello@churr.io — for anything in this policy, including a data-subject request or a complaint.
If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in the EU/UK, to your local supervisory authority.