oolby
Legal Center

Privacy Policy

How Boolby collects, uses, shares, stores and protects personal data.

Last updated 8/27/2026

1. What this policy covers

This Privacy Policy explains how Boolby handles personal data when you use the Service, including signup, closed beta waitlist, profiles, matching, chat, safety tools, premium, support, optional first-party analytics, legal requests and admin/moderation systems.

Boolby is intended for users aged 18 and older. We do not knowingly allow minors to create accounts.

2. Data we collect

We may collect:

  • Account data: email, password hash, account ID, username, gamertag, birthdate, age, gender, account status, role, signup date and verification status.
  • Linked identity data: provider name, provider account identifier, provider display name or username, linking timestamps and limited profile data returned during sign-in. Boolby should request only the scopes needed for login and optional linked-account features.
  • Security data: sessions, trusted devices, 2FA status, recovery-code metadata, password reset/change logs, IP address, user agent and security events.
  • Profile data: photos, bio, games, genres, languages, active hours, playstyle tags, social-vibe tags, gender, optional pronouns, looking-for choices, country/city/location preferences, verification status, premium theme choices and profile settings.
  • Matching data: swipes, passes, likes, super likes, matches, blocks, unmatches, reputation, profile views, photo-access status and compatibility signals.
  • Chat data: messages, timestamps, moderation signals, flags and report context.
  • Safety/moderation data: reports, warnings, bans, appeals, AI flags, verification submissions, admin notes and audit logs.
  • Support data: support tickets, replies, attachments and categories.
  • Premium/billing data: plan status, coupons, grants, subscription IDs, payment provider references, renewal/cancellation events, monthly and purchased consumable balances, referral rewards and billing portal metadata.
  • Referral data: referral code/link, inviter and invited-account identifiers, qualification progress, active-day milestones, rewards, disqualification reasons and anti-abuse signals.
  • Notification data: in-app notification preferences, optional activity-email preferences, delivery or unsubscribe status and notification history.
  • Waitlist data: email address, joined date, invited/emailed status and signup conversion marker.
  • Technical data: cookies, local storage, device/browser information, IP address, country inferred at country level from an IP address, logs, performance data and error diagnostics.
  • Analytics and attribution data, when optional analytics is enabled: first-party anonymous/session identifiers, consent state, page and feature events, landing/referrer information, campaign/UTM parameters, broad device/browser/OS information, country-level context, timestamps and sanitized performance/error categories. Analytics is designed not to copy private message bodies, passwords, authentication tokens or payment-card data.

3. How we use data

We use data to:

  • Create and secure accounts, including supported social sign-in and linked identity providers.
  • Verify email, age eligibility and account ownership.
  • Run profiles, Discover, matching, filters, photo-based access controls, location/near-me, likes, matches, chat, optional Steam/Discord sharing and reputation.
  • Operate Closed Beta, waitlists and beta wave emails.
  • Provide premium features, consumable balances, coupons, referral rewards, grants and billing support.
  • Send service emails and notifications according to account and optional preference settings.
  • Detect spam, scams, harassment, threats, ban evasion and abuse.
  • Review reports, appeals, support tickets and verification submissions.
  • Show truthful country-level community information on public pages without storing a precise location for that feature.
  • Improve reliability, troubleshoot bugs and measure service health.
  • Understand aggregated community composition, such as games, languages, playstyles, social-vibe choices and broad gender/pronoun categories. Community-composition reporting is designed as aggregate reporting and does not provide a user-level drill-down from those statistics.
  • When optional analytics is enabled, understand how people find Boolby, measure campaigns and product funnels, and improve signup, onboarding, Discover and other product flows.
  • Comply with legal obligations and enforce our Terms and policies.

4. Legal bases for processing

Where GDPR or similar laws apply, our legal bases may include:

  • Contract: to create your account and provide the Service.
  • Legitimate interests: to keep Boolby safe, prevent fraud, moderate abuse, improve reliability and operate a social platform.
  • Consent: where we ask for optional permissions, such as first-party analytics cookies/identifiers, marketing or device/browser features.
  • Legal obligation: where records, reports, tax, accounting, consumer or law-enforcement obligations apply.
  • Vital interests: where needed to protect someone from serious and immediate harm.

The specific basis depends on the feature and context.

5. AI moderation and human review

Boolby may process profile text, support text, reports, chat messages, images and behavior signals with automated moderation tools. These tools help detect scams, harassment, threats, adult-service promotion, spam, unsafe sexual content, self-harm risks and other policy violations.

Automated moderation may block content, flag it for review, or create a risk signal. Human staff may review relevant context where needed. You can appeal warnings or bans through Safety & appeals or Support.

6. Who can access data

Access is limited based on role and need. Normal users see public profile and chat information. Staff tools may give Owner, admins, moderators or support access to specific data needed for support, reports, safety, GDPR handling, billing support or platform health.

Sensitive admin actions should be audit logged. We do not sell your personal data.

7. Service providers

We may use service providers for hosting, database, object storage, email delivery, payments, analytics, moderation APIs, monitoring, security and support tooling.

Providers may process data only as needed to provide their service to Boolby, subject to applicable agreements and safeguards.

Country-level IP detection may use GeoLite2 data created by MaxMind, available from https://www.maxmind.com. Boolby performs this lookup against a local country database where configured and does not store the visitor IP as part of the public community-count feature.

8. Retention

We keep data only as long as needed for the purposes described here, unless a longer period is required or permitted by law.

Examples:

  • Account, linked-identity and profile data is kept while the account exists or until an identity is unlinked, subject to security and audit retention.
  • Deleted accounts may enter a recovery window before permanent deletion.
  • Safety, ban, report and audit records may be retained longer to prevent abuse and enforce rules.
  • Billing records may be retained for accounting, tax and dispute purposes.
  • Backups may retain deleted data for a limited period until overwritten.
  • Detailed analytics and attribution records may have shorter retention than core account records. Aggregated or anonymized statistics may be kept longer when they no longer identify an individual.

When data is no longer needed, it is deleted, anonymized or isolated according to our processes.

9. Your choices and rights

You can edit profile fields, pause your profile, change settings, block users, delete photos, request data export, request deletion and contact Support. You can also change optional analytics at any time from Cookie settings. Choosing Necessary only disables optional browser analytics and removes Boolby's local analytics identifiers from that device.

If GDPR or similar laws apply, you may have rights to access, correct, delete, restrict, object, port data, withdraw consent, and complain to a regulator. See GDPR Information for more detail.

10. Changes to this policy

Boolby can update this Privacy Policy at any time to reflect product changes, legal changes, safety changes, provider changes or business changes. The latest version is posted in the Legal Center. Material changes may be announced in-app or by email.