# CHOOSE - Privacy Policy

**Effective Date**: January 1, 2026 
**Last Updated**: January 1, 2026

---

## 1. Introduction

Welcome to CHOOSE. This Privacy Policy explains how chooseapp.net ("we," "our," or "us") collects, uses, discloses, and protects your personal information when you use the CHOOSE mobile application and related services (the "Service").

We are committed to protecting your privacy and handling your data transparently. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy.

### About the Operator

This app (the "App") is operated and maintained under the domain chooseapp.net.

For the purposes of this Privacy Policy, "we," "us," or "our" refers to the App and its operator.

**The App is developed and operated by an individual developer.**

If you have any questions or concerns, you may contact us at:
- **Email**: contact@chooseapp.net
- **Website**: https://chooseapp.net

**Service**: CHOOSE Mobile Application  
**Operator**: chooseapp.net

---

## 2. Information We Collect

### 2.1 Information You Provide Directly

#### 2.1.1 Account Registration
When you create an account, we collect:
- **Email address** (if registering via email)
- **Phone number** (if registering via phone, if enabled)
- **Apple ID information** (if using Apple Sign-In: user identifier, email)
- **Password** (encrypted and securely stored)
- **Username** and **display name**

#### 2.1.2 Profile Information
You may provide:
- **Profile photos/avatar** (voluntarily uploaded)
- **Age, gender, bio** (optional fields)
- **Preferences and interests** (through questionnaires)

#### 2.1.3 User-Generated Content
We collect content you create within the Service:
- **Questions** you ask other users
- **Answers** you provide to questions
- **Chat messages** sent to other users
- **Care list** (users you save as interesting)
- **Survey responses** (feedback you provide)

#### 2.1.4 Support Communications
If you contact us for support:
- **Email correspondence**
- **Bug reports and feedback**
- **Survey responses**

---

### 2.2 Information Collected Automatically

#### 2.2.1 Usage Data
We automatically collect:
- **Device information**: Device model, operating system version, unique device identifiers
- **App usage**: Features used, screens visited, session duration, interaction patterns
- **Log data**: IP address, access times, error logs, crash reports

#### 2.2.2 Location Information
- We **do not** currently collect precise geolocation data
- We may infer approximate location from IP address for analytics and security purposes

#### 2.2.3 Cookies and Similar Technologies
- We use local storage and session tokens to maintain your login state
- We do not currently use third-party tracking cookies

---

### 2.3 Information from Third Parties

#### 2.3.1 Apple Sign-In
If you use Apple Sign-In:
- We receive your Apple-provided user identifier
- Email address (if you choose to share it with us)
- Name (if you choose to share it)

We comply with Apple's guidelines and do not receive additional personal information without your consent.

---

## 3. How We Use Your Information

We use your information for the following purposes:

### 3.1 Provide and Improve the Service
- **Account management**: Create, maintain, and secure your account
- **Matching system**: Connect you with compatible users based on your answers
- **Communication**: Enable chat and messaging features
- **Personalization**: Customize your experience based on preferences
- **Service improvement**: Analyze usage patterns to enhance features

### 3.2 Safety and Security
- **Fraud prevention**: Detect and prevent fraudulent or malicious activity
- **Terms enforcement**: Ensure compliance with our Terms of Service
- **Security**: Protect against unauthorized access and data breaches
- **Dispute resolution**: Investigate and resolve user disputes or reports

### 3.3 Communication
- **Service notifications**: Send important updates about your account or the Service
- **Customer support**: Respond to your inquiries and provide assistance
- **Surveys**: Request feedback to improve the Service (optional participation)

### 3.4 Legal Compliance
- **Legal obligations**: Comply with applicable laws and regulations
- **Legal requests**: Respond to subpoenas, court orders, or legal processes
- **Rights protection**: Enforce our rights and protect our property

---

## 4. How We Share Your Information

We **do not sell** your personal information to third parties. We may share your information in the following circumstances:

### 4.1 With Other Users
- **Profile information**: Your username, display name, avatar, and bio are visible to users you match with
- **User-generated content**: Questions, answers, and messages you send are visible to intended recipients
- **Matching interactions**: Your activity in the matching pool is shared according to app functionality

### 4.2 Service Providers
We may share information with third-party service providers who perform services on our behalf:
- **Cloud hosting**: AWS, Google Cloud, or similar (server infrastructure)
- **Push notifications**: Apple Push Notification Service (APNs)
- **Analytics**: Crash reporting and performance monitoring tools (if implemented)
- **Payment processors**: Apple App Store (for future paid features)

Service providers are contractually required to protect your information and use it only for specified purposes.

### 4.3 Legal Requirements
We may disclose information when required by law or in good faith belief that such action is necessary to:
- Comply with legal obligations, court orders, or subpoenas
- Protect and defend our rights or property
- Prevent or investigate fraud, security issues, or technical problems
- Protect the safety of users or the public

### 4.4 Business Transfers
If chooseapp.net is involved in a merger, acquisition, asset sale, or bankruptcy:
- Your information may be transferred as part of that transaction
- We will notify you of any change in ownership or use of your personal information
- You will have the opportunity to delete your account before the transfer

### 4.5 With Your Consent
We may share your information with third parties when you explicitly consent to such sharing.

---

## 5. Data Retention

### 5.1 Active Accounts
We retain your information for as long as your account is active or as needed to provide the Service.

### 5.2 Account Deletion
When you request account deletion:
- **Grace period**: 30-day waiting period during which you can cancel deletion
- **After grace period**: Your account and personal information are permanently deleted within 90 days
- **Legal retention**: Some data may be retained longer to comply with legal obligations (e.g., financial records, dispute resolution)

### 5.3 Retention Periods by Data Type
- **Profile information**: Deleted upon account deletion
- **Chat messages**: Deleted upon account deletion (both sender and receiver views)
- **Timeline records**: Deleted upon account deletion
- **Log data**: Retained for 12 months for security and debugging purposes
- **Backup data**: Removed from backups within 90 days of account deletion

---

## 6. Your Privacy Rights

Depending on your location, you may have the following rights:

### 6.1 Access and Portability
- **Access**: Request a copy of your personal information
- **Data export**: Download your data in a machine-readable format (available in app settings)

### 6.2 Correction and Deletion
- **Correction**: Update your profile information at any time through app settings
- **Deletion**: Request account deletion through app settings (subject to 30-day grace period)

### 6.3 Objection and Restriction
- **Objection**: Object to certain data processing activities
- **Restriction**: Request limitation of processing in certain circumstances

### 6.4 Withdrawal of Consent
- Where processing is based on consent, you may withdraw consent at any time
- Withdrawal does not affect the lawfulness of processing before withdrawal

### 6.5 How to Exercise Your Rights
To exercise these rights:
1. Use the **in-app data management tools** (Settings → Privacy)
2. Contact us at **contact@chooseapp.net**
3. We will respond within **30 days** of your request

---

## 7. Data Security

We implement industry-standard security measures to protect your information:

### 7.1 Technical Measures
- **Encryption**: Data in transit is encrypted using HTTPS/TLS
- **Password security**: Passwords are hashed using bcrypt algorithm
- **Authentication**: JWT tokens with expiration for session management
- **Access controls**: Limited access to personal data by authorized personnel only

### 7.2 Organizational Measures
- **Security reviews**: Regular security audits and updates
- **Incident response**: Procedures for handling data breaches
- **Employee training**: Staff trained on data protection best practices

### 7.3 Limitations
While we strive to protect your information, no security system is impenetrable. You are responsible for:
- Keeping your password confidential
- Logging out of shared devices
- Reporting suspected unauthorized access

---

## 8. Children's Privacy

The Service is **not intended for users under 18 years of age**. We do not knowingly collect personal information from children under 18.

If you are a parent or guardian and believe your child has provided us with personal information:
- Contact us immediately at **contact@chooseapp.net**
- We will delete such information within 30 days of verification

---

## 9. International Data Transfers

The Service is operated in **the United States**. If you are located outside this region:
- Your information will be transferred to and processed in **the United States**
- We will take appropriate safeguards to ensure your information is protected in accordance with this Privacy Policy
- By using the Service, you consent to the transfer of your information to **the United States**

For users in the European Economic Area (EEA), United Kingdom, or Switzerland:
- We rely on **standard contractual clauses** or other approved mechanisms for international data transfers
- You have the right to request information about the safeguards we use

---

## 10. Your California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

### 10.1 Right to Know
You have the right to know:
- Categories of personal information we collect
- Purposes for which we use your information
- Categories of third parties with whom we share information

### 10.2 Right to Delete
You have the right to request deletion of your personal information, subject to certain exceptions.

### 10.3 Right to Opt-Out
We **do not sell** your personal information. If this changes, we will provide an opt-out mechanism.

### 10.4 Non-Discrimination
We will not discriminate against you for exercising your CCPA rights.

### 10.5 Exercising Your Rights
To exercise your CCPA rights:
- Use the **in-app data management tools**
- Email us at **contact@chooseapp.net** with subject line "California Privacy Rights"
- We may verify your identity before processing your request

---

## 11. Your European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):

### 11.1 Legal Basis for Processing
We process your personal information based on:
- **Consent**: When you provide explicit consent (e.g., optional profile fields)
- **Contract performance**: To provide the Service you requested
- **Legitimate interests**: To improve the Service, prevent fraud, and ensure security
- **Legal obligations**: To comply with applicable laws

### 11.2 GDPR Rights
You have the right to:
- **Access**: Obtain confirmation of processing and access to your data
- **Rectification**: Correct inaccurate or incomplete data
- **Erasure**: Request deletion ("right to be forgotten")
- **Restriction**: Limit processing in certain circumstances
- **Portability**: Receive your data in a structured, machine-readable format
- **Object**: Object to processing based on legitimate interests
- **Withdraw consent**: At any time, without affecting prior processing
- **Lodge a complaint**: With your local data protection authority

### 11.3 Data Controller
chooseapp.net is the data controller for your personal information.

### 11.4 Data Protection Officer (if applicable)
If we are required to appoint a Data Protection Officer (DPO):
- **Contact**: contact@chooseapp.net

---

## 12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes:
- We will notify you by **email** and/or **in-app notification**
- We will update the **"Last Updated"** date at the top of this policy
- We will maintain a **change log** below for transparency

Your continued use of the Service after changes constitutes acceptance of the revised Privacy Policy. If you do not agree to the changes, you must stop using the Service and delete your account.

---

## 13. Third-Party Services and Links

The Service may contain links to third-party websites or services not operated by us:
- We are not responsible for the privacy practices of third-party services
- We encourage you to review the privacy policies of any third-party services you visit
- This Privacy Policy applies only to the CHOOSE Service

**Third-party services we may use**:
- **Apple Sign-In**: Governed by Apple's Privacy Policy
- **Apple App Store**: Governed by Apple's Privacy Policy
- **Cloud hosting providers**: Subject to their respective privacy policies

---

## 14. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices:

**Email**: contact@chooseapp.net
**Service**: CHOOSE Mobile Application  
**Operator**: chooseapp.net

We will respond to your inquiry within **30 days**.

---

## 15. Data Processing Summary

For transparency, here is a summary of data processing activities:

| Data Category | Purpose | Legal Basis | Retention Period |
|---------------|---------|-------------|------------------|
| Account credentials | Authentication, account management | Contract performance | Until account deletion |
| Profile information | Matching, personalization | Contract performance, consent | Until account deletion |
| Questions & answers | Matching algorithm, service functionality | Contract performance | Until account deletion |
| Chat messages | Communication feature | Contract performance | Until account deletion |
| Usage data | Service improvement, analytics | Legitimate interests | 12 months |
| Log data | Security, debugging | Legitimate interests | 12 months |
| Support correspondence | Customer support | Legitimate interests | 3 years |

---

## 16. Cookies and Tracking Policy

**Current Status**: We do **not** use cookies or third-party tracking technologies.

**Future Use**: If we implement cookies or tracking in the future:
- We will update this Privacy Policy
- We will provide an opt-out mechanism
- We will comply with applicable cookie consent laws

---

## 17. Automated Decision-Making

The Service uses **automated matching algorithms** to suggest potential matches based on your question responses. This is essential to the Service's functionality.

You have the right to:
- Understand how the algorithm works (see our FAQ)
- Request human review of matching decisions (contact support)
- Opt-out of automated matching (though this limits Service functionality)

---

## 18. Data Breach Notification

In the unlikely event of a data breach:
- We will notify affected users within **72 hours** of discovering the breach
- We will notify relevant authorities as required by law
- We will provide information about the breach, affected data, and steps we are taking to address it

---

## Change Log

| Version | Date | Changes |
|---------|------|---------|
| 1.0 | December 6, 2025 | Initial Privacy Policy |

---

**By using CHOOSE, you acknowledge that you have read, understood, and agree to this Privacy Policy.**

---

**Document Version**: 1.0  
**Effective Date**: January 1, 2026  
**Last Updated**: January 1, 2026  
**Compliance**: GDPR, CCPA, Apple App Store Privacy Guidelines
