Privacy Policy
1. Who We Are
Choofin ("the App") is developed and operated by Choofin ("we", "us", "our"). This Privacy Policy explains how we collect, use, and protect information when you use the App.
2. Information We Collect
Information you provide
- Sign in with Apple account identifier (stored as a one-way hashed identifier).
- Profile fields: first name, last name, email, phone number, home ZIP code.
- Birthday (stored on device and cleared on sign-out or account deletion), with age bracket derived for default-on crowd compatibility sharing.
- Profile signals including age bracket, orientation, background, lifestyle, and discovery interests. Height bucket stays on-device for local discovery and is not sent in venue aggregate payloads.
- Notification preferences and alert settings.
Information collected automatically
- Short-lived pseudonymous location presence events tied to a venue identifier and time buckets after a sustained arrival.
- In-app check-ins that you submit.
- Push notification device token, only after you grant notification permission.
- Apple App Attest key and receipt used to verify genuine app installations; DeviceCheck proof is validated by Apple when App Attest is unavailable.
- App diagnostics needed to operate core features.
3. How We Use Your Information
We use the information we collect to:
- Display real-time and predicted crowd levels at venues.
- Personalize venue recommendations based on your interests.
- Send crowd alerts and notifications you have requested.
- Maintain and improve the App.
- Prevent bots, modified apps, replay attacks, and fraudulent crowd submissions.
4. Sensitive Personal Information
We collect sexual orientation, gender-expression, ethnicity/background, and certain lifestyle tags that may qualify as Sensitive Personal Information (SPI) under the California Privacy Rights Act (CPRA).
If you use Choofin, you must agree that age, orientation, background, and lifestyle signals may be included in anonymous venue aggregates. Height stays on-device for local discovery. Sensitive categories and historical venue patterns appear only after at least 2 distinct consenting Choofs support them; no individual profile or exact contributor count is shown. General live activity is bucketed as 1–5, 6–15, 16–30, or 31+ Choofs.
We do not use sensitive profile signals for advertising or secondary purposes. There is no pause switch; deleting your account removes data that can be linked to your profile.
5. How We Share Your Information
We do not sell your personal information.
We do not share your personal information with third parties for advertising or marketing.
We use the following processors and platform services to operate the App:
- Apple CloudKit - private profile storage
- Sign in with Apple - authentication and credential revocation on deletion
- Apple Push Notification service - opt-in alerts
- Apple App Attest and DeviceCheck - app-integrity and fraud-prevention verification
- Apple MapKit - map display
- Cloudflare Workers and D1 - trusted pseudonymous crowd-signal ingestion and aggregation
- Apple CloudKit public database - thresholded live aggregates and anonymous historical venue patterns
- OpenAI - AI venue-context guesses based only on public venue details and local time context; profile, crowd, demographic, and account data are not sent.
App Store Connect privacy labels and permission prompts are maintained to match this policy and app behavior.
6. Data Retention
- Login-session keychain values are cleared on sign-out. The per-account App Attest key reference is retained on that device to avoid unnecessary key rotation and is removed when you delete your account.
- Private CloudKit profile fields and preferences are retained until deleted through "Delete Account & Data".
- Pseudonymous raw presence signals expire within about 1 hour and check-ins within about 3 hours; expired raw signals may remain for up to 24 additional hours before scheduled cleanup, or are removed when you delete your account.
- Non-linkable historical venue/time-slot rollups are retained to provide typical crowd patterns. They are not deleted merely because an account becomes inactive.
- A deleted account tombstone may retain the one-way account key, contribution identifier, consent flag, creation timestamp and deletion timestamp to prevent stale sessions and complete backend cleanup.
- Expired and revoked login-session rows are temporary security records and are cleaned up separately; inactive accounts are not deleted.
- If Apple credential revocation fails, cleanup is retried without retaining the app's local session token.
- App Attest public keys, receipts, and single-use challenges are deleted with the account; expired challenges are also removed by scheduled cleanup. DeviceCheck tokens are validated and not retained.
7. Your California Privacy Rights
If you are a California resident, you have the following rights under the CCPA and CPRA:
- Right to Know — you may request information about the personal information we collect and how we use it.
- Right to Delete — use "Delete Account & Data" while signed in so Choofin can verify you and delete both private CloudKit and backend account data. Email us if you need help completing that flow.
- Right to Opt-Out of Sale — we do not sell personal information. This right is not applicable.
- Right to Non-Discrimination — we will not discriminate against you for exercising your privacy rights.
- Right to Limit Use of Sensitive Personal Information - Choofin does not use these signals for advertising or secondary purposes.
To submit a privacy rights request, contact us at info@choofin.com. For security, an email address alone does not identify a pseudonymous backend account, so account deletion must be verified in the signed-in App. We will respond within 45 days.
8. Children
Choofin is intended for choofs 18 years of age and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us at info@choofin.com and we will delete it promptly.
9. Security
We implement reasonable security measures, including Apple App Attest assertions on crowd-changing requests, DeviceCheck compatibility verification, single-use anti-replay challenges, pseudonymous identifiers for crowd processing, private CloudKit storage for profile fields, publication thresholds, and access controls around deletion. Pseudonymous signals remain linkable to an account for deletion and abuse prevention while retained.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Significant changes will be communicated through the App. Continued use of the App after changes take effect constitutes acceptance of the updated policy.