Tremble Privacy Policy
Last updated: 9 September 2026
Data Controller: AMS Solutions d.o.o. Frenkova ulica 23, 6280 Ankaran, Slovenia privacy@trembledating.com
1. Introduction
Tremble is a proximity-based dating application built on a principle of privacy by architecture. We collect the minimum data necessary to operate real-time proximity detection.
For ordinary use of the app, your exact GPS coordinates are never stored — they are converted to a coarse geographic cell in memory and discarded. There are two exceptions, and we explain both in full rather than round them off:
- Precision Finding (§2.2) — the one time we store your exact position. It only happens when you deliberately switch it on.
- Gym search (§2.6) — when you type a gym name during sign-up or in settings, your device sends an approximate position directly to Google, so that the suggestions are gyms near you rather than gyms anywhere. It is deliberately rounded to about a kilometre before it is sent, it does not pass through our servers, and we never receive or store it. This one is not a setting you switch on; it happens when you use the search box.
2. Data We Collect and Why
2.1 Location Data
When you use Tremble, your device converts your GPS position to a geohash — a geographic cell of roughly 150 metres across — on the phone itself, and sends only that cell to our servers. Your raw coordinates are never sent to us and never reach our servers — with the single exception of Precision Finding (§2.2), which you switch on yourself. We store only the geohash, never raw GPS coordinates.
One flow sends a position somewhere other than us. The gym search box (§2.6) sends an approximate location straight from your device to Google, to bias the suggestions towards gyms near you. It is rounded to roughly a kilometre before it leaves, that request does not travel through our servers, and no Tremble system ever sees it. We describe it here because "your location stays on your phone" would not be a truthful summary of the app as a whole.
That geohash expires 24 hours after it is written. The record is overwritten every time your position updates while discovery is on, so what exists at any moment is your current coarse area, not a history of where you have been. Deletion is enforced by an automatic expiry policy on our database; that removal is an automatic background process, so it follows expiry rather than happening at the same instant (see §4).
No user can read this record. Our security rules deny all client access to it outright; only our server functions can use it, and they use it only to answer "is anyone near this person right now".
Bluetooth signals work alongside GPS geohash proximity to confirm physical proximity. Bluetooth signal strength (RSSI) is evaluated entirely on your device and is never transmitted to or stored on our servers. Only the outcome of that on-device check influences what the app shows you.
Legal basis: Performance of contract (Art. 6(1)(b) GDPR) — proximity discovery is the service you signed up for and cannot be delivered without it. You can stop the processing at any time by turning discovery off in the app or by disabling location permission in your device settings.
No GPS reaches our servers in normal use
Your coordinates are converted to a cell roughly 150 m across on the device itself.
Only the cell ID is sent to us. It expires after 24 hours. There are two exceptions:
Precision Finding (§2.2), which you switch on and which we do store for two
minutes, and gym search (§2.6), where your device sends an approximate location —
rounded to about a kilometre — directly to Google and not to us at all.
Bluetooth never leaves your phone
Signal strength is measured and compared on your device. We never receive it.
2.2 Precision Finding (the one time we store your exact location)
When you and a match are both nearby and you both tap to find each other, Tremble switches into Precision Finding — the mode that shows an arrow and a live distance.
To calculate a bearing and distance between two people, exact coordinates are unavoidable; a 150-metre cell cannot produce a 3-metre readout. So during an active Precision Finding session, and only then, we store:
- your exact latitude and longitude,
- the accuracy radius your device reports,
- a timestamp.
These are the controls on it:
| Control | Value |
|---|---|
| Opt-in | Stored only after you actively start Precision Finding. Never in background or ordinary use. |
| Lifetime | 2 minutes. Each record carries a hard expiry, after which it is no longer used. Deletion follows as an automatic background sweep — typically within a day, not at the same instant (see §4). |
| Stop = delete | Ending the session deletes your record immediately. |
| Readable by | No one inside the app — not you, not your match, not any app client. Our security rules deny client access to this record outright. Only the server function that computes the distance reads it. |
| What your match receives | A distance and a direction. Never your coordinates. |
| Quality gate | Positions less accurate than 30 metres are refused outright. |
Your match never receives your coordinates — only how far away you are and which way to turn. The coordinates expire two minutes after they are written, are deleted automatically thereafter, and cannot be read by any user of the app.
We state this precisely rather than claiming nobody at all can ever read it: the record sits in our database, so our own administrative access reaches it the way it reaches any other record, under the access controls and staff obligations that apply to all of it. What we can promise, and what the security rules actually enforce, is that no client — including your match's phone — is ever able to fetch it.
Legal basis: Consent (Art. 6(1)(a) GDPR), given by starting the session. You may withdraw it at any moment by stopping Precision Finding, which erases the data.
Two minutes, and only when you ask
Precision Finding is the only feature that stores your exact position. It lasts two
minutes, deletes when you stop, and no user — including your match — can ever read it.
2.3 Profile Data
At registration and onboarding we collect identity, profile content, lifestyle preferences, special category attributes that users voluntarily provide, and device identifiers needed to operate the application.
- Identity: display name, email address, and date of birth. Your date of birth is stored and used for age verification; the age shown on your profile is calculated from it.
- Profile content: profile photos, gender, matching preference (
interestedIn), age, height, hair colour, hobbies, languages, occupation, school, job status, free-text prompt answers, and relationship preferences. - Lifestyle preferences: exercise habits, sleep schedule, drinking habits, nicotine use, pet preferences, children preferences, and an introversion scale.
- Special category attributes (GDPR Art. 9): religious beliefs and ethnicity, both provided voluntarily.
- Device identifiers and settings: Firebase UID, Firebase Cloud Messaging push token, and your device's reported time zone (used for the Weekend Getaway Pass window — see §2.9).
We do not collect political affiliation.
Legal basis: Performance of contract (Art. 6(1)(b)) for core profile data, including gender and matching preference — providing these is necessary to deliver the proximity-matching service itself, in the same way as your date of birth. There is no reduced version of Tremble that functions without them. Legitimate interests (Art. 6(1)(f)) for the lifestyle scales. Explicit consent (Art. 9(2)(a)) applies to special category data (religious beliefs, ethnicity).
Gender and matching preference may in some jurisdictions be considered adjacent to special category data on sexual orientation. We process it strictly to provide the matchmaking service you signed up for, never for advertising, profiling, or any purpose beyond operating the app, and it is never shared with third parties beyond what is described in this policy.
Hobbies and interests are shown on your profile but are not used to filter who you see.
Every profile photo is screened automatically for objectionable content before it can appear to anyone — see §2.12.
Consent for special category data is granular and recorded separately:
| Attribute | Consent field | Required? |
|---|---|---|
| Religious beliefs | religionConsent | Optional — the attribute is only processed if given |
| Ethnicity | ethnicityConsent | Optional — the attribute is only processed if given |
If you do not give consent for religion or ethnicity, those attributes are not used in matching at all, either as your own attribute or as a preference applied to others.
2.4 Automated Matching and Filtering
Tremble decides which profiles you are shown using automated logic. You should understand how it works.
Ordering: Profiles on your radar are ordered by physical distance only. Hobbies, personality scale, exercise habits, and sleep schedule are descriptive — shown on a profile, never used to filter or order who you see.
Hard filters: A profile can be excluded from your radar entirely by a small set of deterministic preference rules: mutual gender/matching preference, mutual age range, and — where you've set a preference — drinking habit and nicotine use (Signal Prime). Gender and matching preference are ordinary matching criteria necessary to run the service and are applied the same way for every user; none of these are special category data.
Religion and ethnicity behave differently. Where both users have consented and a preference has been set, a mismatch excludes the profile entirely. This is an automated decision that determines whether two people can ever see each other in the app, not a soft score.
We apply the religion/ethnicity filter only because a user explicitly asked us to, on data they explicitly consented to provide, under Art. 9(2)(a). You can change or clear these preferences at any time in the app, and doing so takes effect immediately.
You have the right under Art. 22(3) GDPR to obtain human intervention, to express your point of view, and to contest this processing. Contact privacy@trembledating.com.
2.5 Pulse Intercept
Pulse Intercept is optional and allows you to share a phone number or a view-once photo with a nearby matched user. View-once photos are screened automatically on our servers before they are delivered, and a photo we cannot check is not sent — see §2.12.
- Phone numbers. When you send your number, we read it from your profile and place it in a short-lived delivery record held by Upstash, our ephemeral-storage processor. That record expires automatically after 10 minutes. Unlike a photo, it is not destroyed when the recipient reads it — reading a number is non-destructive, so the record simply lives out its 10 minutes and is then deleted. Your number is not added to the recipient's stored data by us; what they keep afterwards is whatever they choose to save on their own device.
- View-once photos are stored on Cloudflare R2 for the moments between sending and opening. The delivery pointer is destroyed before the image is fetched, so a photo can never be delivered twice — that part is guaranteed. The image itself is then deleted immediately, on that single read. If that deletion does not succeed — during a storage outage, for example — the object is left with no pointer to it and a daily lifecycle rule removes it within a day. If the photo is never opened, the pointer expires after 10 minutes and the same lifecycle rule removes the image.
For photos, only an opaque object reference travels through our delivery records; the image itself is streamed to the recipient and destroyed on read.
Unless the recipient reports it. "Destroyed after viewing" is true of every photo nobody reports, and it is not the whole story. A view-once photo is shown from the recipient's device memory after our copy is already gone, so if they report it there is nothing left for a moderator to look at. If — and only if — a recipient files a report on your photo, their device uploads a copy of that image to us as evidence at the moment they report it. We keep it for 30 days, after which it expires and is deleted automatically and the report continues without the image. A photo nobody reports is never copied to us at all.
That evidence copy is stored privately, is readable only by a moderator, is not screened by Cloud Vision (§2.12), and is deleted if the person who filed the report deletes their account.
2.6 Run Club and Gym Mode
Run Club activates when your device detects another Tremble user running nearby. When two runners cross, we create a crossing record containing both user IDs, whether each of you signalled, and the time. It is what lets the two of you wave at each other before the moment passes.
Retention: the crossing record expires 30 minutes after it is created and is then deleted automatically. After 30 minutes the app stops acting on it, and our database removes it on its own; that removal is an automatic background process, so it follows expiry rather than happening at the same instant. If you delete your account, we delete any crossing records involving you immediately, without waiting for that process.
You can avoid creating these records entirely by leaving Run Mode off.
Gym Mode activates when your device remains at one of your saved gyms for 10 minutes. No GPS coordinates are sent to our servers for this. Gym detection reads the same coarse cell your device already writes for the radar (§2.1) and checks whether that cell falls inside one of your own saved gyms, so our servers never resolve your position more precisely than that cell.
Choosing a gym is a different matter, and it involves Google. When you search for a gym by name — during sign-up, or later when editing your gyms — the search box sends an approximate latitude and longitude, together with the text you type, from your device directly to Google's Places API. This is what makes the suggestions gyms near you instead of gyms anywhere. Four things are worth being precise about:
- It is deliberately imprecise. Your position is rounded before the request is built, to roughly a kilometre. Google receives the neighbourhood, not the doorway. We round it because the search does not need more: the request asks Google to prefer results within 50 km, so a kilometre of slack changes nothing about what you see.
- It does not go through our servers. We never receive these coordinates and never store them. Google receives them; what Google retains is governed by Google's terms, not by this policy.
- It can happen before you have an account. The gym step is part of sign-up, so if you search for a gym and then abandon registration, that request has still been made.
- You control it by not using the search box. If you never search for a gym, nothing is sent to Google at all. And if you have not granted location permission — or your device has no recent position — your coordinates are not included: the app instead biases the search around a fixed point at the centre of Slovenia, which tells Google nothing about where you are. The search still works; the results are simply no longer ordered by nearness to you.
Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) — returning nearby results for a search you deliberately performed.
While a gym session is running we store:
- A presence record — which gym you are at, and when you were first and last seen there. It expires 6 hours after it was last updated.
- A gym crossing record, created when another Tremble user is at the same gym at the same time — both user IDs, the gym, whether the encounter was close-range, and the first and last time you were seen together. It expires 24 hours after it was last updated. This is the record the post-session recap reads.
- On your profile, which gym is active for you and until when.
2.7 Contact List (Anonymity Mode)
If you enable Anonymity Mode, the application reads your device contact list, hashes all phone numbers using SHA-256 on your device, and sends only the hashed values to our servers. Hashes are compared against registered users in server memory only and are never stored.
What is saved is the outcome: the accounts that matched are added to your block list and yours to theirs, so you and your contacts stay hidden from each other. That block list is ordinary profile data and lasts until you change it or delete your account. We keep no record of which contact produced which block, and no record of contacts that did not match anything.
Hashed on your device
SHA-256 runs locally. Only hashes leave your phone. We never see your contacts, and the
hashes are discarded after the check — we keep only the resulting mutual blocks.
2.8 Push Notifications
We use Firebase Cloud Messaging and the Apple Push Notification Service to deliver proximity alerts and match notifications. Notification content may include another user's display name, age, and profile photo URL.
2.9 In-App Purchases and the Weekend Getaway Pass
Tremble offers a premium subscription processed through RevenueCat, the Apple App Store, and Google Play. We receive only subscription status and do not receive or store payment card details.
RevenueCat holds a record of your subscription entitlements under its own retention schedule, and the App Store and Google Play retain transaction records under their own policies and applicable accounting law. These records are not removed when you delete your Tremble account — see §5.
Weekend Getaway Pass. Tremble offers a time-limited pass that runs from Friday 19:00 to Sunday 19:00 in your device's current local time zone. We store the activation and expiry timestamps on your account, together with the time zone your device reports.
We read that time zone from your device's own clock settings — not from your location. It is recorded when you register and refreshed when the app resumes and finds that your device's zone has changed. If the value is missing or is not a valid time zone, we fall back to Central European Time (Europe/Ljubljana).
Because the window follows the zone your device is in, travelling across time zones while a pass is pending or active can move it: a pass that has not started yet is rescheduled to the upcoming Friday–Sunday span in your new zone, and an active pass continues only while your new zone still places you inside a live window.
Legal basis: Performance of contract (Art. 6(1)(b)).
2.10 Crash and Error Reporting
We use Sentry to capture crashes and application errors so we can fix them, on both the app and our servers. A crash report may include device model, operating system version, app version, your IP address, and a technical trace of what the app was doing immediately before the error. Crash reports are processed in the EU on Sentry's EU infrastructure.
We also use Firebase Crashlytics for native crash reporting on the same basis.
Retention: Sentry reports are retained for 30 days on the plan we hold, after which they are removed automatically. Firebase Crashlytics reports are deleted according to Google's standard retention period for that service. We do not extend either period or archive reports elsewhere.
Legal basis: Legitimate interests (Art. 6(1)(f)) — keeping the service stable and secure. You may object at any time by contacting privacy@trembledating.com.
2.11 Sign In with Apple
If you register using Sign in with Apple, Apple authenticates your identity and provides us with your name and an email address. If you choose "Hide My Email", Apple provides a private relay address (ending in @privaterelay.appleid.com) instead of your real email address. We receive and store this relay address as your account email.
For erasure requests submitted by email, you must provide either this relay address or your Firebase account UID. To find your relay address: Settings → [Your Name] → Sign in & Security → Hide My Email.
Legal basis: Performance of contract (Art. 6(1)(b)).
2.12 Automated Photo Screening
Every photo you upload is screened automatically for objectionable content before it can be shown to anyone else. This applies to profile photos and to view-once photos sent through Pulse Intercept.
How it works. When your photo finishes uploading, we send the image to Google Cloud Vision (SafeSearch), a Google service that returns an assessment of how likely the image is to contain adult, violent, medical or deliberately disguised content. If the assessment crosses our threshold, the photo is deleted immediately and never becomes visible to another user; you are asked to choose a different one. This is the automated content filter required of us under Apple's App Store Guideline 1.2.
The image itself is sent to Google for this check — not a hash, a thumbnail, or a description. Google processes it to return the assessment. This check runs on Google Cloud Vision's European Union endpoint, so like our database and functions — which run in the EU (europe-west1) — Google stores and processes the image for this check in the European Union only.
What we keep. For each screened upload we store one record containing your user ID, a reference to the uploaded file, the decision we took and why, and the assessment Google returned. We keep it so that a wrong decision can be investigated and the threshold corrected against real data instead of guesswork.
How long we keep them. A screening record expires 90 days after the upload was screened, and is deleted automatically thereafter. Ninety days rather than a shorter period for one reason: our rejection threshold was set before we had any real uploads to set it against, and a shorter window would not hold enough decisions to correct it.
Deleting your account deletes these records. They are removed by the in-app deletion routine along with the rest of your data, immediately and on request — not left to run out their 90 days. You do not need to ask us separately, and you do not need to wait.
If the check cannot run, what happens depends on where the photo was going.
- A profile photo is allowed through, rather than blocking every upload in the app during a Google outage, and the record notes that no assessment was received. Reporting and blocking remain available on every photo, and a reported photo is reviewed by a person.
- A view-once photo sent through Pulse Intercept is NOT sent. It is refused and deleted, and the sender is asked to try again. A photo delivered this way is shown once and cannot be recovered afterwards, so there is no later opportunity for anyone to review it — which is why an unchecked photo is refused here rather than allowed.
One exception. A view-once photo that a recipient reports is not screened, because screening deletes what it rejects and that would destroy the evidence the report exists to carry. See §2.5.
Legal basis: Legitimate interests (Art. 6(1)(f)) — keeping sexual, violent and abusive imagery off a service used by adults meeting strangers nearby, and meeting the app-store obligation that lets us distribute the app at all. You cannot opt out of screening while uploading a photo, because an unscreened photo is precisely what the measure exists to prevent; you can decline to upload one.
2.13 Transactional Email
We send email for two purposes, both through Resend, our email delivery processor:
- Welcome email, sent once when you complete onboarding — a short confirmation that your profile is active.
- Safety-alert email, sent internally when a report or a block is filed. This is not sent to you: it goes to our own safety mailbox, carrying the report's reason codes and, if you wrote one, your free-text explanation. See §6 for the delivery chain.
We do not send an email when you get a match. A mutual wave is announced only inside the app and by push notification (§2.8), never by email. We considered sending one and decided against it: an email naming another person would sit in a third party's mailbox indefinitely, and account deletion has no way to reach a message already delivered there. Push is transient, device-local, and the notification you actually opted into.
Account deletion does not currently send a confirmation email. We would rather state this than let anyone assume deletion is confirmed by email — it is not.
We do not control an email once it is sent. How long the recipient's own mail provider (Gmail, iCloud, your company's mail host) keeps a message we sent is governed by that provider, not by us. Deleting your account does not withdraw or delete email we have already delivered — see §5.
Legal basis: Performance of contract (Art. 6(1)(b)) for the welcome email — it confirms the account you just created. Legitimate interests (Art. 6(1)(f)) for safety-alert email — acting on the zero-tolerance content policy described in the Terms of Service.
3. How Location Privacy Works
Outside Precision Finding, your exact GPS coordinates never leave your device. Your phone converts each position to a geohash locally and transmits only that value, which expires after 24 hours. Proximity calculations operate on geohash cells, so our internal systems cannot resolve your position more precisely than roughly 150 metres — we never receive anything more precise.
During an active Precision Finding session — which you start deliberately and can stop at any time — exact coordinates are stored, and the record expires two minutes after it is written; deletion follows automatically thereafter (see §4). They are unreadable by any app client, including your match's.
Profile photos are stored on Cloudflare R2 and accessible via a unique URL to authenticated users. URLs are not publicly indexed and are not guessable without access to your profile data.
4. Data Retention
Every period below is enforced by an automatic mechanism — a database expiry policy, a storage lifecycle rule, or deletion on read — except where the row says otherwise. Where no automatic enforcement exists yet, the row says so rather than quoting the period we intend.
A period below is an expiry, not a deletion timestamp. When a record expires it stops being used and becomes eligible for deletion; the deletion itself is an automatic background sweep that normally follows within a day, not at the same instant. We state it this way because that is what the mechanism actually guarantees. Erasure on request (§5) is the one path that is immediate, because it is carried out synchronously rather than by a sweep.
| Data | Retention | Enforced by |
|---|---|---|
| GPS coordinates (ordinary use) | Never sent to us — converted to a coarse cell on your device | n/a |
| Approximate location sent to Google for gym search (§2.6) | Rounded to about a kilometre before it is sent. We never receive or store it. Retention of what Google receives is Google's, under Google's terms — we are not in a position to state a period on Google's behalf | Not applicable — the data never enters a Tremble system |
| GPS coordinates (Precision Finding only) | Expires after 2 minutes; deleted immediately if you stop the session | Database expiry policy + deletion on stop |
| Coarse geohash (proximity state) | 24 hours | Database expiry policy |
| Bluetooth signal strength (RSSI) | Never transmitted — evaluated on device only | n/a |
| Proximity events | 10 minutes | Database expiry policy |
| Run Club crossing records | 30 minutes | Database expiry policy + erasure on request |
| Gym presence record | 6 hours after last update | Database expiry policy |
| Gym crossing records | 24 hours after last update | Database expiry policy |
| Pulse Intercept photo | Deleted on open; 10 minutes if unopened; orphaned objects removed within a day | Deletion on read + storage lifecycle rule |
| Reported Pulse Intercept photo (evidence copy) | Expires after 30 days, then the image is deleted and the report continues without it. Only created if a recipient reports the photo — see §2.5 | Scheduled purge + erasure on request |
| Pulse Intercept phone number | 10 minutes, whether or not it is read | Delivery-record expiry |
| Contact hashes (Anonymity Mode) | Never stored — compared in memory | n/a |
| Profile data | Until account deletion | Erasure on request |
| Profile photos (Cloudflare R2) | Until account deletion | Erasure on request |
| Match and wave history | Until account deletion. Neither has an automatic expiry — they last as long as your account does | Erasure on request |
| Proximity pair counters (§2.4) | Expire 90 days after the last encounter. These are counters held by our rate-limiting provider, keyed by the two accounts involved | Provider key expiry and erasure on request — every counter naming your account is deleted when you delete your account |
| Recap dismissal log | Until account deletion — a record of which recaps you closed, and when. No automatic expiry | Erasure on request |
| Registration draft | Saved as you complete sign-up so you can resume it. No automatic expiry | Erasure on request |
| Deduplication keys | Until account deletion. Bookkeeping that stops a repeated request being counted twice | Erasure on request |
| Waitlist sign-ups from our website | No retention period is currently set. If you gave us your name and email on trembledating.com without creating an account, that record is held indefinitely until we set a policy | None yet — see §5 |
| Push notification payloads | 5 minutes delivery window | FCM / APNs expiry |
| Rate-limiting counters | Short-lived, automatically expired | Database expiry policy |
| Crash and error reports (Sentry) | 30 days | Provider |
| Crash reports (Firebase Crashlytics) | Google's standard retention for the service — see §2.10 | Provider |
| Subscription entitlement records (RevenueCat) | Retained by RevenueCat under its own schedule; not removed by account deletion | Provider |
| Store transaction records (App Store, Google Play) | Retained by the store under its own policy and applicable accounting law | Provider |
| GDPR request audit log | 2 years | Database expiry policy |
| Moderation reports | Life of account. On erasure, reports you filed are deleted and reports about you are anonymised and kept for legal defence under Art. 17(3)(e) GDPR | Erasure on request |
| Photo screening records (§2.12) | 90 days from the moment the upload was screened | Database expiry policy + erasure on request |
| Welcome email (§2.13) | Sent once, on onboarding completion. Not stored by us after sending — retention at the recipient's own mail provider is theirs, not ours | n/a — nothing to expire on our side |
| Safety-alert email (§2.13) | Sent once, internally, when a report or block is filed. Not stored by us after sending | n/a — nothing to expire on our side |
What "database expiry policy" means
Every period above marked as enforced by a database expiry policy is the point at which
the data expires and becomes eligible for automatic deletion. Our database performs
that deletion as a background sweep, so removal follows expiry rather than coinciding
with it — typically within a day of it. We would rather state this than imply a
precision our database does not offer. Deletion you request under §5 is different: that
runs immediately, not on the sweep.
What is actually short-lived
Your coarse area expires after 24 hours, proximity events after 10 minutes, Run Club
crossing records after 30 minutes, and the only exact coordinates we hold are those
of a Precision Finding session you started, expiring two minutes after they are written.
Bluetooth signal strength never leaves your phone. Your profile stays until you delete
it.
What is not short-lived, stated plainly. The proximity pair counters described above
last 90 days from your most recent encounter. They are keyed by the two accounts
involved, so while they exist they are a record that two particular accounts were near
each other — not merely an anonymous number. Your recap dismissal log, your registration
draft and your deduplication keys have no automatic expiry at all and last as long as
your account.
5. Account Deletion and Right to Erasure
You may delete your account at any time from app settings. Deletion permanently and irreversibly removes your profile, your coarse proximity record, proximity events, waves, matches, Run Club crossing records involving you, Gym Mode presence and crossing records involving you, Precision Finding position records, reports you filed and any photo evidence attached to them, rate-limiting records, your registration draft, your recap dismissal log, and every proximity pair counter naming your account, profile photos and Pulse Intercept media from Cloudflare R2, and your Firebase Authentication record.
Moderation reports filed against your account are anonymised rather than fully deleted, as permitted under Art. 17(3)(e) GDPR, to allow us to defend against legal claims.
Three of those deserve a note, because all are records that would otherwise have been left to expire on their own:
- Run Club crossing records (§2.6) describe two identified people, so erasure deletes the whole record rather than removing your ID from it.
- Gym Mode crossing records (§2.6) are the same shape and are deleted the same way — the whole record, not just your ID. Your gym presence record is deleted outright.
- Precision Finding position records are deleted explicitly, not left to their two-minute expiry. An expiry running out is not the same thing as us deleting data on request, so the deletion routine reaches into them directly.
- Photo screening records (§2.12) are deleted outright — the record of the decision and the assessment Google returned go with the rest of your data, rather than being left to their 90-day expiry.
Three further records are removed that previously were not: your registration draft, your recap dismissal log, and every proximity pair counter naming your account. All three are deleted synchronously as part of the same request, not left to expire.
What account deletion does not reach. We would rather state this than let the list above read as complete:
- Waitlist sign-ups. If you gave us your name and email on our website without ever creating an account, that record is separate from any account and is not covered by in-app deletion. Email privacy@trembledating.com and we will remove it.
Two things account deletion does not reach, and both are outside our systems. Our subscription provider, RevenueCat, holds a record of your subscription entitlements under its own retention schedule, and the Apple App Store and Google Play retain transaction records under their own policies and applicable accounting law. We cannot delete either on your behalf. Reports about you are anonymised rather than deleted, as described above.
A welcome or safety-alert email we have already sent is outside our systems too (§2.13). Once delivered, retention belongs to the recipient's own mail provider, not to us, and account deletion cannot withdraw a message that has already arrived.
Deleting your account does not cancel an active subscription. Subscriptions renew until cancelled and must be cancelled manually in your Google Play or App Store settings. Cancel first, then delete — once your account is gone we can no longer act on it for you.
You may also submit a deletion request via the erasure form at trembledating.com/erasure or by emailing privacy@trembledating.com.
6. Sub-processors
We do not sell your data. We use the following data processors to operate Tremble:
| Processor | Purpose | Location |
|---|---|---|
| Google LLC (Firebase) | Database, authentication, push notifications, native crash reporting, app integrity | EU (europe-west1) |
| Google LLC (Places API) | Gym search autocomplete, during sign-up and later in settings. Receives an approximate location — rounded to about a kilometre — and the text you type, directly from your device; it does not pass through our servers. See §2.6 | Google endpoint; not pinned to a region by us |
| Google LLC (Cloud Vision) | Automated screening of uploaded photos for objectionable content — see §2.12. Receives the image itself | EU (eu-vision.googleapis.com) |
|---|---|---|
| Upstash, Inc. | Rate limiting, notification throttling, and Pulse Intercept delivery records. When you send a phone number through Pulse Intercept, the number itself is held here for up to 10 minutes — see §2.5. Photo intercepts store only an opaque object reference. Also holds the proximity pair counters described in §4, which are keyed by two accounts and expire 90 days after the last encounter — this is the one thing here that is not short-lived. | EU |
| Functional Software, Inc. (Sentry) | Crash and error reporting | EU region hosting; US entity (SCCs in place) |
| Resend, Inc. | Transactional email — see §2.13. Sends the welcome email (your email address and display name) and safety-alert email (a report's or block's user IDs, reason codes, and your free-text explanation if you wrote one) — the latter to our own internal safety mailbox, never to another app user | EU |
| Cloudflare, Inc. (Email Routing) | Forwards safety-alert email (above) from info@trembledating.com to our company mailbox. A separate service from Cloudflare R2 above (photo and Pulse Intercept storage) — same vendor, different data | — |
| Google LLC (Google Workspace) | Hosts the company mailbox that Cloudflare Email Routing forwards safety-alert email to, so this is where a report's contents come to rest. A separate Google service from Firebase, Cloud Vision and Places above, under a separate processor agreement | Not pinned to a region by us |
| RevenueCat, Inc. | Subscription management | US (SCCs in place) |
| Apple Inc. | App distribution, push notifications (APNs), Sign In with Apple, in-app purchases | US (SCCs in place) |
| Google LLC (Play Store) | App distribution and in-app purchases | EU |
7. Your Rights
Under GDPR and ZVOP-2 you have the right to access, rectification, erasure, restriction, portability, and objection. Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
Where an automated decision affects you — the matching filters in §2.4, and the automated photo screening in §2.12 that can reject a photo you upload — you have the right under Art. 22(3) to obtain human intervention, to express your point of view, and to contest the decision. For a rejected photo, write to privacy@trembledating.com and a person will review it.
To exercise any of these rights, contact us at privacy@trembledating.com. We will respond within 30 days.
You have the right to lodge a complaint with Informacijski pooblaščenec RS (www.ip-rs.si) if you believe your data is being processed unlawfully.
8. Children
Tremble is not available to persons under the age of 18. Age is verified at registration. If we become aware that a user is under 18, their account will be permanently deleted.
18+ only — ZVOP-2 člen 14
Age is verified at registration. Any account found to belong to a person under 18 is
permanently deleted with no recovery option.
9. Changes to This Policy
We will notify users of material changes to this policy via in-app notification. The current version is always available at trembledating.com/privacy. Continued use of the app after changes constitutes acceptance of the updated policy.