Privacy Policy

Plain English. Last updated: May 2026.

Tremble Privacy Policy

Last updated: 12 May 2026

Data Controller:
AMS Solutions d.o.o.
Frenkova ulica 23, 6280 Ankaran, Slovenia
privacy@trembledating.com

1. Introduction

Tremble is a proximity-based dating application built on a principle of privacy by architecture. We collect the minimum data necessary to operate real-time proximity detection. Your exact GPS coordinates are never stored on our servers.

2. Data We Collect and Why

2.1 Location Data

When you use Tremble, your device sends GPS coordinates to our servers to calculate proximity to other users. This calculation happens in server memory only. Coordinates are immediately converted to a geohash, a geographic cell approximately 75 metres in diameter, and discarded. We store only the geohash, never raw GPS coordinates.

Bluetooth signals work alongside GPS geohash proximity to confirm physical proximity on your device. RSSI values are temporarily written to our database with a 10-minute automatic deletion policy and are never linked to a stored location history.

Legal basis: Consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time by disabling GPS location or Bluetooth permissions in your device settings.

2.2 Profile Data

At registration and onboarding, we collect identity, profile content, lifestyle preferences, special category attributes that users voluntarily provide, and device identifiers needed to operate the application.

  • Identity: display name, email address, date of birth for age verification, then stored as age value.
  • Profile content: profile photos, gender, age, height, hobbies, languages, and relationship preferences.
  • Lifestyle preferences: exercise habits, sleep schedule, drinking habits, nicotine use, pet preferences, and children preferences.
  • Sensitive attributes: religious beliefs, ethnicity, political affiliation, and sexual orientation inferred from the interestedIn field. These are processed only to enable compatibility filtering between users who voluntarily provided them.
  • Device identifiers: Firebase UID, FCM push notification token, and Bluetooth advertising ID used by Bluetooth and GPS proximity checks.

Legal basis: Performance of contract (Art. 6(1)(b)) for core profile data. Explicit consent (Art. 9(2)(a)) for special category data.

2.3 Pulse Intercept

Pulse Intercept is optional and allows users to share a phone number or a view-once photo with a nearby matched user. Phone numbers are shared directly between users at the moment of interaction and are not stored after transmission. View-once photos are deleted after opening or after 10 minutes if unopened.

2.4 Run Club and Gym Mode

Run Club activates when your device detects another Tremble user running nearby. Encounter data is stored with a 10-minute automatic deletion policy. Gym Mode activates when your device remains within a geofenced gym location for 10 minutes. GPS coordinates used to verify gym proximity are processed in server memory only and are not stored.

2.5 Contact List (Anonymity Mode)

If you enable Anonymity Mode, the application reads your device contact list, hashes all phone numbers using SHA-256 on your device, and sends only the hashed values to our servers. Hashes are compared against registered users in server memory only and are never stored.

2.6 Push Notifications

We use Firebase Cloud Messaging and Apple Push Notification Service to deliver proximity alerts and match notifications. Notification content may include another user display name, age, and profile photo URL.

2.7 In-App Purchases

Tremble offers a premium subscription processed through RevenueCat, Apple App Store, and Google Play Store. We receive only subscription status and do not receive or store payment card details.

2.8 Sign In with Apple

If you register using Sign in with Apple, Apple authenticates your identity and provides us with your name and an email address. If you choose the "Hide My Email" option, Apple provides a private relay address (ending in @privaterelay.appleid.com) instead of your real email address. We receive and store this relay address as your account email.

For erasure requests submitted via email, you must provide either this relay address or your Firebase account UID. To find your relay address: Settings → [Your Name] → Sign in & Security → Hide My Email.

Legal basis: Performance of contract (Art. 6(1)(b)).

3. How Location Privacy Works

Your exact GPS coordinates are never written to our database. When your device reports a location, our server converts it to a geohash in memory and stores only that value. Proximity calculations use geohash cell centres, so internal systems do not resolve your position to better than approximately 75 metres.

Profile photos are stored on Cloudflare R2 and accessible via a unique URL to authenticated users. URLs are not publicly indexed and are not guessable without access to your profile data.

4. Data Retention

GPS coordinatesNever stored (transient server memory only)
Bluetooth proximity events (GPS coordinates are never stored)10 minutes (automatic deletion)
Run Club encounter data10 minutes (automatic deletion)
Geohash (proximity state)Until account deletion or inactivity
Profile dataUntil account deletion
Profile photos (Cloudflare R2)Until account deletion
Match and wave historyUntil account deletion
GDPR request audit log2 years
Moderation reports (anonymised)Retained for legal defence per Art. 17(3)(e) GDPR

Bug reports and associated metadata (IP address, device information) are retained for 90 days and automatically deleted.

5. Account Deletion and Right to Erasure

You may delete your account at any time from app settings. Deletion permanently and irreversibly removes your profile, proximity state, waves, matches, profile photos from Cloudflare R2, and Firebase Authentication record.

Moderation reports filed against your account are anonymised rather than fully deleted, as permitted under Art. 17(3)(e) GDPR, to allow us to defend against legal claims.

You may also submit a deletion request via the erasure form at trembledating.com/erasure or by emailing privacy@trembledating.com.

6. Sub-processors

We do not sell your data. We use the following data processors to operate Tremble:

Google LLC (Firebase)Database, authentication, push notifications, crash reporting, app integrityEU (europe-west1)
Google LLC (Places API)Location autocomplete during onboardingEU
Cloudflare, Inc.Profile photo storage and delivery (R2)EU
Upstash, Inc.Rate limiting and notification throttling (pseudonymised user identifiers)EU
Resend, Inc.Transactional emailEU
RevenueCat, Inc.Subscription managementUS (SCCs in place)
Apple Inc.App distribution, push notifications (APNs), Sign In with Apple (authentication), in-app purchasesUS (SCCs in place)
Google LLC (Play Store)App distribution and in-app purchasesEU

7. Your Rights

Under GDPR and ZVOP-2 you have the right to access, rectification, erasure, restriction, portability, and objection. To exercise any of these rights, contact us at privacy@trembledating.com. We will respond within 30 days.

You have the right to lodge a complaint with Informacijski pooblascenec RS (www.ip-rs.si) if you believe your data is being processed unlawfully.

8. Children

Tremble is not available to persons under the age of 18. Age is verified at registration. If we become aware that a user is under 18, their account will be permanently deleted.

9. Changes to This Policy

We will notify users of material changes to this policy via in-app notification. The current version is always available at trembledating.com/privacy. Continued use of the app after changes constitutes acceptance of the updated policy.