Privacy Policy
1. Who We Are
Austin Teak Berger, an individual operating Choofin ("the App"), is responsible for the information described in this Privacy Policy. "We", "us", and "our" refer to Austin Teak Berger operating Choofin. This Privacy Policy explains how we collect, use, and protect information when you use the App.
2. Information We Collect
Information you provide
- Sign in with Apple account identifier (kept on your device; one-way identifiers are used in CloudKit and our backend).
- Optional profile fields: first name, last name, email, phone number, and home ZIP code.
- Birthday (stored on device and cleared on sign-out or account deletion), with age bracket derived for default-on crowd compatibility sharing.
- Profile signals including age bracket, self-described gender, orientation, background, lifestyle, and discovery interests. Height bucket stays on-device for local discovery and is not sent in venue aggregate payloads.
- Notification preferences and alert settings. While an age- or lifestyle-match alert is enabled, its current age bracket or selected lifestyle tags are stored with that alert so the service can evaluate the requested match.
Information collected automatically
- Automatic pseudonymous venue-presence events tied to a venue identifier and 15-minute time buckets after the device remains within 500 feet for about 5 minutes. A notification lets you confirm or remove the signal.
- In-app check-ins that you submit.
- Private Choof Points progress derived from accepted presence and check-ins, including rewarded venue/day records, point events, levels, and earned badges.
- Push notification device token, only after you grant notification permission.
- Apple App Attest key and receipt used to verify genuine app installations; DeviceCheck proof is validated by Apple when App Attest is unavailable.
- Place reports you submit, including the listed place, selected reason, optional note, and review status, linked to your account to review incorrect details and privacy or safety concerns. Reports are included in your data export and deleted when you delete your account.
- IP addresses and request counters used to rate-limit requests and prevent abuse. These security records may also use account or venue identifiers.
- Account-linked completed-visit security records, including visit and operation identifiers, completion status, and timestamps, used to prevent replayed or duplicate contributions. These records do not contain venue details or profile fields.
- App diagnostics needed to operate core features.
3. How We Use Your Information
We use the information we collect to:
- Display recent participating-user crowd signals and predicted venue patterns.
- Personalize venue recommendations based on your interests.
- Send crowd alerts and notifications you have requested.
- Provide private Choof Points, level progress, and badges that recognize venue exploration.
- Maintain and improve the App.
- Prevent bots, modified apps, replay attacks, and fraudulent crowd submissions.
4. Sensitive Personal Information
We collect sexual orientation, self-described gender, ethnicity/background, and certain lifestyle tags that may qualify as Sensitive Personal Information (SPI) under the California Privacy Rights Act (CPRA).
Contact and self-description fields other than the birthday used to confirm adult eligibility and derive an age bracket are optional. If you choose to provide gender, orientation, background, or lifestyle signals, they may be included in thresholded venue statistics. Height stays on-device for local discovery. Sensitive categories and historical profile details appear only after at least 2 distinct consenting Choofs support them; no individual profile or exact contributor count is shown. General recent and Typical activity can appear with 1 contributor and is bucketed as 1–5, 6–15, 16–30, or 31+ Choofs. Typical activity may use manual check-ins or completed automatic visits after a delayed venue/time-slot aggregation process.
We do not use sensitive profile signals for advertising or secondary purposes. You can withdraw crowd sharing at any time in Privacy & Data. Withdrawal stops on-device location monitoring, removes active and unpublished contributions, private Choof Points progress, and crowd alerts, revokes active sessions, and blocks access to Choofin crowd data. You can regain access by consenting and signing in again. Previously published thresholded venue statistics are not maintained as individual account profiles and may remain.
5. How We Share Your Information
We do not sell your personal information.
Google AdMob receives limited device, network, advertising, interaction, and diagnostic information to deliver and measure ads as described below. We do not provide Google with Choofin account identifiers, contact details, profile answers, precise location, check-ins, visit history, or crowd demographics for advertising.
We use the following processors and platform services to operate the App:
- Apple CloudKit - private profile storage
- Sign in with Apple - authentication and credential revocation on deletion
- Apple Push Notification service - opt-in alerts
- Apple App Attest and DeviceCheck - app-integrity and fraud-prevention verification
- Apple MapKit - map display
- Cloudflare Workers and D1 - trusted pseudonymous crowd-signal ingestion and aggregation
- Apple CloudKit public database - thresholded recent aggregates and historical venue patterns
- OpenAI - AI venue-context guesses based only on public venue details and local time context; profile, crowd, demographic, and account data are not sent.
We may also disclose information when reasonably necessary to comply with law, respond to valid legal process, protect the safety and rights of users or others, investigate fraud or abuse, or protect Choofin's services.
App Store Connect privacy labels and permission prompts are maintained to match this policy and app behavior.
5A. Advertising and Your Choices
Choofin displays a labeled native advertisement in Trending using Google AdMob. Ad requests are non-personalized, use restricted data processing, and have Google publisher first-party ID disabled. Choofin does not request access to the advertising identifier (IDFA) or permission for cross-app tracking.
When ad services are used, Google may receive your IP address (which can indicate approximate location), app- or device-scoped identifiers, information about ads shown and interactions with them, and crash and performance diagnostics. This information supports ad delivery, measurement, analytics, and fraud prevention. Non-personalized ads still involve data processing and may use device storage.
Before requesting ads, Choofin checks regional privacy requirements through Google’s User Messaging Platform and presents required messages. When available, Manage Ad Privacy in Privacy & Data lets you change these choices. If privacy requirements cannot be confirmed or no eligible ad is available, the ad placement is hidden and browsing continues.
Google handles ad-related information under its applicable terms and privacy policy, including its retention practices. Deleting your Choofin account removes the account-linked records described in this policy; it does not automatically delete information held separately by Google. Learn more at https://policies.google.com/technologies/partner-sites and https://policies.google.com/privacy.
6. Data Retention
- Login-session keychain values are cleared on sign-out. The per-account App Attest key reference is retained on that device to avoid unnecessary key rotation and is removed when you delete your account.
- Private CloudKit profile fields and preferences are retained until deleted through "Delete Account & Data".
- Private Choof Points rewarded-visit, point-event, and badge records are retained while sharing is active and are deleted when you withdraw sharing or delete your account. An occupied OG Choofer slot is retired without an account link during either action and is not reissued.
- Automatic presence normally ends after the device remains outside the confirmed-presence boundary for about 90 seconds or you choose “Not here.” The boundary is normally 750 feet from the venue center, or the venue radius if larger. While the device remains nearby, later location or background checks can refresh the signal. A 12-hour server expiration, extended by successful refreshes, is a fallback if iOS does not report an exit. Check-ins expire within about 3 hours.
- Thresholded historical venue/time-slot statistics are retained while needed to provide Typical patterns and are periodically reviewed under our retention schedule. They are not maintained as individual profiles.
- A deleted-account tombstone may temporarily retain one-way identifiers and deletion metadata to prevent stale sessions and finish cleanup. It is deleted after 30 days unless Apple credential-revocation retry work is still pending.
- Login sessions remain active until sign-out, sharing withdrawal, account deletion, or Apple credential revocation. Revoked login-session rows are temporary security records and are deleted after 30 days; inactive accounts are not deleted.
- IP-based and other rate-limit records are retained for about 7 days and removed by scheduled cleanup. IP-scoped records are not mapped to an individual account for deletion.
- Completed-visit security records are retained until account deletion to prevent replayed or duplicate contributions, including after crowd-sharing withdrawal. They are included in your data export without internal operation identifiers.
- Place reports, their submitted place details and notes, and review records are retained until you delete your account so we can investigate and track the reported issue. Your export includes submitted report information and status, but not internal review notes.
- If Apple credential revocation fails, cleanup is retried without retaining the app's local session token.
- App Attest public keys, receipts, and single-use challenges are deleted with the account; expired challenges are also removed by scheduled cleanup. DeviceCheck tokens are validated and not retained.
- A data copy is assembled on your device from private CloudKit, local account settings, and redacted backend records. Choofin does not upload or email the generated file.
7. Your U.S. Privacy Rights
Choofin offers the following privacy choices to every U.S. user, whether or not a particular state privacy law applies:
- Access and portability — use "Download My Data" in Privacy & Data to create a portable JSON copy of account-linked information retained by Choofin.
- Correction — edit available profile fields in Profile or contact us to request correction of other inaccurate account information.
- Deletion — use "Delete Account & Data" while signed in to delete private CloudKit and backend account data, subject to the retention exceptions described above.
- Advertising choices — Choofin requests non-personalized ads with restricted data processing and does not use your Choofin profile or visits for ad targeting. Where regional privacy choices are required, use Manage Ad Privacy in Privacy & Data to review or change them. These choices do not withdraw crowd sharing.
- Right to Non-Discrimination — we will not discriminate against you for exercising your privacy rights.
- Right to Limit Use of Sensitive Personal Information - Choofin does not use these signals for advertising or secondary purposes.
To submit a privacy request or ask for help, use Privacy & Data in the App or contact info@choofin.com. We acknowledge emailed requests within 10 business days and target completion within 45 calendar days. A legally permitted extension may be used when reasonably necessary, with notice before the initial deadline. You may use an authorized agent where applicable; we may request proof of authority and direct identity verification. If we deny a request, you may appeal by replying with “Privacy Appeal,” and we will explain our decision and applicable next steps.
For security, an email address alone does not identify a pseudonymous backend account. Account-specific access, correction, and deletion requests normally require verification through Sign in with Apple in the App. Data copies exclude authentication secrets, full notification tokens, Apple refresh tokens, and cryptographic material.
Our public policy website does not serve ads. In the app, we apply restricted data processing to all Google ad requests, regardless of browser Do Not Track or Global Privacy Control signals. Use the in-app ad privacy controls where available or contact us for help with your choices.
8. Children
Choofin requires an 18-or-older confirmation before account creation and restricts the birthday picker to adult dates. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us at info@choofin.com and we will investigate and delete it promptly.
9. Security
We implement reasonable security measures, including Apple App Attest assertions on crowd-changing requests, DeviceCheck compatibility verification, single-use anti-replay challenges, pseudonymous identifiers for crowd processing, private CloudKit storage for profile fields, publication thresholds, and access controls around deletion. Pseudonymous signals remain linkable to an account for deletion and abuse prevention while retained.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated through the App. We will request fresh affirmative acceptance before applying a materially changed sensitive-data use; otherwise the updated policy applies from its stated effective date as permitted by law.
11. Contact Us
Austin Teak Berger, operating Choofin
info@choofin.com