Privacy Policy
Last updated: May 31, 2026 · DRAFT — pending legal review.
What we believe
1. What we collect
- Account basics: name, handle (@you), email, password (stored hashed — we can't read it), date of birth.
- Profile: bio, avatar, location, public interests — whatever you choose to add.
- Messages & Intro Cards: the structured prompts you send and receive.
- Age verification (optional): a copy of your ID image, kept only until an admin reviews it, then deleted (see Section 4).
- Technical: basic logs (IP, browser, timestamps) for security and abuse prevention.
- Push notification token: if you opt-in to Web Push, your browser's push subscription endpoint.
2. What we never collect
3. How we use your data
- To run the service: sign you in, deliver messages, show your profile, ship your merch.
- To keep things safe: detect abuse, block spammers, investigate reports.
- To improve Focus2.me: aggregate, anonymous usage stats — never individual profiling.
- To contact you about your account (e.g. security, important changes). We don't send marketing email without your opt-in.
4. Age verification — the deletion contract
If you upload a government-issued ID for age verification:
- The image is shown only to an admin reviewer.
- The moment the admin approves or rejects, the image bytes are deleted from our database immediately (`$unset`).
- We keep only a status (approved / rejected), reviewer ID, decision timestamp, and any rejection reason — purely for compliance and abuse prevention.
- Your full date of birth is never displayed publicly. Other users only see your computed age (e.g. "30 y/o").
5. Who can see what
- Public on your profile: name, handle, bio, avatar, location (if added), public interest icons, age (if you've added a DOB), Verified 18+ badge (if approved).
- Private: email, password hash, full date of birth, your message history, verification status detail.
- Visible only after an Intro Card: the message thread between you and the other user.
6. Cookies & sessions
7. Sharing your data
- Service providers who help us run the platform (hosting, database, email delivery, push notifications, merch fulfilment). They're bound by contracts to handle your data only on our instructions.
- Legal authorities when required by a valid legal request, or to prevent imminent harm.
8. Your rights
- See what we hold about you (request a copy by emailing us).
- Correct anything that's wrong — most fields you can edit yourself in the app.
- Delete your account anytime from your profile. Some logs may be retained for security/legal reasons.
- Withdraw consent (e.g. turn off push notifications) at any time.
9. Security
10. Data retention
11. International users
12. Changes to this Policy
Last updated
14. Intro Card photographs (optional)
Attaching a photograph to an Intro Card is optional. When you upload a photograph, Focus2.me sends the image to Google Cloud Vision SafeSearch for automated safety screening.
SafeSearch returns likelihood assessments (VERY_UNLIKELY through VERY_LIKELY) across five categories: adult, racy, violence, medical, and spoof (spoof/manipulation). Focus2.me uses those likelihoods to approve, reject, or hold for human review. Automated systems can make mistakes, so an authorized Focus2.me administrator may privately review a photograph when the automated result is uncertain.
Focus2.me does not use this SafeSearch integration to identify the person in the photograph or perform facial recognition. Google Cloud is the data processor for the SafeSearch call; Google's handling of image data is governed by its own agreements, which we link below rather than restate. See SafeSearch documentation, Google Cloud Data Processing Addendum, and Google Cloud privacy information.
15. Photo visibility and retention
- Photographs in review or rejected are never shown to the intended recipient.
- An approved photograph becomes visible only after you explicitly attach and send it with an Intro Card.
- The sender and the intended recipient may view an approved, attached photograph. Authorized Focus2.me administrators may access photographs when required for moderation, reports, safety, or system administration.
- Unattached uploads normally expire after 24 hours.
- A photograph approved through human review receives a fresh 24-hour attachment window from the approval time.
- Approved attached photographs may remain with the associated Intro Card while that record is retained.
- Rejected image bytes are removed promptly, unless a report or safety evidence hold requires temporary preservation.
- Deleting or cancelling a photograph may hide it from normal user access while necessary evidence remains privately preserved.
16. Reporting other users
You can privately report a profile, an Intro Card, an individual conversation message, a photograph, or a safety concern. Focus2.me records the selected reason, an optional explanation you provide, relevant account identifiers, and a limited server-created evidence snapshot.
Authorized administrators review reports and decide the appropriate action, which may include blocking, further review, dismissal, resolution, account restriction, or other appropriate safety action. Reports are not public. Focus2.me does not display public report totals or accusations.
Focus2.me does not show the reporter's identity to the reported user through the normal reporting experience. We may disclose information when required by law or when reasonably necessary to protect safety, rights, and the service.
17. Report evidence retention
- Evidence remains available to reviewers while a report is open or in review.
- When a report is resolved or dismissed, its detailed evidence snapshot and the reporter's explanation are scheduled for removal after 30 days.
- Cleanup normally runs approximately every six hours, so removal may not occur at the exact minute the 30-day period ends.
- Limited report and audit metadata may be retained longer for abuse prevention, security, dispute handling, legal obligations, and protection of the service.
- Photo evidence holds can remain until all reports involving that photograph reach their applicable purge dates.
- If applicable law, safety needs, fraud prevention, or a valid legal request requires longer retention, we may retain records accordingly.
18. Your choices and privacy rights
Contact privacy@focus2.me to request:
- Access to the personal data we hold about you where applicable.
- Correction of inaccurate information.
- Deletion of applicable personal data.
- Information about how your data is processed.
We may not be able to delete every record immediately. Limited records may be retained when reasonably required for safety, fraud prevention, legal obligations, or resolving disputes. For general privacy guidance for Texas residents, see the Texas Attorney General's privacy resource.
19. Age
20. Safety Guidelines — Photographs
Generally permitted:
- Safe profile-style photographs.
- Ordinary swimwear in a legitimate beach, pool, recreational, or athletic setting.
- Ordinary athletic clothing.
- Ordinary nonsexual shirtless photographs.
Not permitted:
- Nudity or explicit sexual content.
- Underwear or lingerie presentation.
- Boudoir-style photographs.
- Sexually suggestive posing.
- Graphic violence or threats.
- Graphic medical content.
- Impersonation or intentionally misleading imagery.
- Content that violates other Focus2.me safety rules.
Automated screening cannot always determine context — contextually acceptable swimwear, athletic, or shirtless photographs may still be sent to human review before appearing to your recipient.
