GRRRLHOOD ("we", "us") runs a community app for women navigating life's transitions. This policy explains what personal data we process, why, the legal basis for it, how long we keep it, and the rights you have under the EU/UK General Data Protection Regulation (GDPR). We are the data controller for the data described here. Questions or requests: privacy@grrrlhood.com.
1. Data we collect
Account & profile
- Email address and a password (we never store your password in plain text — it is kept only in securely hashed form). If you use Sign in with Apple or Google, we receive a verified email and a provider account identifier instead of a password.
- Display name, the country and city you choose, the life phase(s) you're in and the stage within each, the sub-topics and interests you select, any optional "how I'm feeling" tags, and any free-text you add to your profile ("what you're navigating").
- If you're moving abroad: your destination city/country, rough timing, and a language you're learning — used only to improve matching.
- Your preferred app language, a shareable GRRRL ID / connect code, your invite (referral) code and who invited you, and your end-to-end encryption public key.
Location
- We convert the city you enter into an approximate centroid coordinate (the centre of that city, via an OpenStreetMap-based geocoder — not your device GPS). We use it to place you in matching and to build a k-anonymized traffic map for our admins. Your individual coordinate is stored only on our servers and is never shown to other members or exposed in the app; the map only ever displays cells that aggregate at least five people (see §3).
Content you create
- Posts, replies, votes, and hashtags in the community feed. Posts are visible to the audience you choose (everyone, your matches, or your close circle) and may be permanent or ephemeral (auto-deleting after 1–24 hours). Posts are not end-to-end encrypted — they are stored so we can display them to their audience and moderate them. Your up/down votes and the karma they produce are stored.
- Direct and community messages you send. Direct messages are end-to-end encrypted — stored only as ciphertext we cannot read.
- Media you upload (images, GIFs, short video), your community memberships, connections, and reports you file (plus any evidence you choose to attach).
Activity, notifications & technical data
- A device identifier and, if you enable notifications, a push token (via Expo and Apple/Google push services) so we can send you alerts (e.g. a new reply, a reaction to your post, a check-in reminder). You can turn notifications off in Settings or your OS.
- Your IP address (used for rate-limiting and abuse prevention) and basic device/app information, plus a limited admin activity/audit log of privileged actions.
- Limited error and security logs (auto-deleted after 30 days).
Translation
- When you tap "Translate" on a post or message, that text is sent to our own self-hosted translation service running on our servers (no third-party translation provider) to return a translation. We do not retain the text after translating it.
Waitlist
- If you join the waitlist on our website, we store your email to notify you about launch.
2. Why we use it & legal basis
- To provide the service (accounts, matching, the feed, messaging, communities, translation, notifications) — performance of a contract.
- Safety & abuse prevention (moderation, reports, rate-limiting, bans, audit logs) — legitimate interests in keeping the community safe.
- Understanding and improving the community at an aggregate level (the k-anonymized activity map and statistics in §3) — legitimate interests; you can object at any time.
- Waitlist & launch updates — consent, which you can withdraw at any time.
- Legal compliance where we must keep certain records — legal obligation.
We do not use third-party advertising or cross-app tracking SDKs, and we do not sell your personal data or your individual location.
3. Aggregate & de-identified statistics
We produce aggregate, de-identified statistics about how the community is distributed and active — for example, how many members are engaging in a region. These are built under a strict k-anonymity rule (k ≥ 5): a location or group is only ever included when it combines at least five distinct people, and the underlying individual coordinates and identifiers are never included. Because these statistics cannot identify any individual, we may share, license, or sell them to third parties (for example, partners or researchers). We never share your personal data, your account, your messages, or your individual location in this way — only counts and aggregates that stand for five or more people.
4. Who we share it with
We share personal data only with processors that help us run the service under contract: our hosting/infrastructure provider, and the push-notification services (Expo, Apple, Google) needed to deliver your alerts. Sign-in providers (Apple, Google) process your login if you use them. Admins on our team can see account metadata and reported content for moderation only — they cannot read your end-to-end-encrypted messages or any individual member's coordinates. De-identified aggregates may be shared as described in §3. We may disclose data if legally required.
5. International transfers
Our infrastructure and the services above may process data outside your country. Where required, such transfers rely on appropriate safeguards (e.g. Standard Contractual Clauses).
6. How long we keep it
- Account, profile & location: until you delete your account.
- Posts: until you delete them; ephemeral posts auto-delete at the time you set.
- Error logs: 30 days. Moderation/audit records: up to 12 months.
- Aggregate statistics (§3): retained on an ongoing basis as historical, de-identified records that no longer relate to you individually.
- Waitlist email: until you ask us to remove it or you join the app.
- Messages: encrypted content may remain after your account is deleted, but it is keyed to an anonymous identifier and contains no readable personal data we can access.
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, and object to the processing of your data, and the right to data portability and to withdraw consent. You can:
- Export your data in-app (Settings → Export my data) or via privacy@grrrlhood.com.
- Delete your account and data in-app (Settings → Delete account). This erases your profile, memberships, connections, reports, and removes you from others' block lists.
You also have the right to lodge a complaint with your local data protection authority.
8. Security
We protect your data with industry-standard safeguards: traffic is encrypted in transit, passwords are stored only in securely hashed form, direct messages are end-to-end encrypted, and access to internal admin tools is restricted and audited.
9. Children
GRRRLHOOD is for adults (18+). We do not knowingly collect data from anyone under that age; if you believe a minor has registered, contact us and we will remove the account.
10. Changes
We may update this policy; we will revise the "last updated" date and, for material changes, notify you in-app.
11. Contact
Privacy requests and questions: privacy@grrrlhood.com. See also our Terms of Service.