Privacy Policy

Last updated: September 30, 2026 · Contact: [email protected]

House is a dating app. Instead of browsing a general pool of profiles, House only ever shows you people you were actually near — at a curated real-world venue or at an Event you both joined — and reveals a match only after a delay. This policy explains what information we collect to make that work, how we use it, and the controls you have over it. It applies to every House account, whether you're using House to date or only to host Events for friends.

1.Information we collect

Account information (every account)

  • Name
  • Date of birth — used only to confirm you're 18 or older; never shown to other users
  • Email address — never shown to other users
  • Phone number — never shown to other users

We collect these four fields from every account — including a Host-only account created just to run an Event for friends, with no dating profile at all.

Dater profile information (only if you build a dating profile)

  • A profile photo, reviewed by us before it's ever shown to anyone. Before we store it, we re-encode it so that any location or camera metadata embedded in the original (EXIF data, including GPS coordinates of where it was taken) is removed.
  • Gender (with an optional free-text description if you choose "other"), and who you're interested in matching with
  • Optionally: a short "about me," your height, and a link to one external social profile
  • Your age, calculated from your date of birth, is also shown when your profile is displayed to another user — your date of birth itself never is

Events you host

  • The Event's name and date, and optionally an address you enter and a cover image chosen from a fixed set we provide (you can't upload your own)
  • If you pick an address from the suggestions shown while typing, we store its coordinates solely to place a pin on your own "My House Parties" map. Event coordinates are never used to detect or verify anyone's presence.
  • The Event's name is shown to people who join it (and, after a match, as the name of the shared location)
  • The time zone your phone is set to when you create an Event, so the Event's matching window closes at 4am local time. It isn't shown to anyone.

Presence & match data

  • Which Venue or Event you registered presence at, and when: for a Venue, the time you were detected entering and leaving; for an Event, the time you joined it
  • Whether you indicated interest in someone you were shown as a candidate, and whether that interest was mutual
  • Messages you send and receive in a chat with a match
  • When you last opened each chat, so we can show how many unread messages and new matches are waiting for you
  • Any user you block, and any report you file (including the reason you give)
  • Venues you've chosen to permanently exclude yourself from

Beta program record

  • During the beta, whether you have accepted the House Beta Tester Terms, and the date and time you did so (recorded on our servers when you tap "Agree and continue")

Notifications

  • If you allow notifications, a device identifier (a "push token") that lets us send alerts to your phone, the type of phone (iPhone or Android) it belongs to, and a random code that proves your phone is the one behind that identifier. We keep only a scrambled (hashed) version of that code; the original stays on your phone.
  • Your notification settings: whether you want alerts for new matches, new messages, and Venue visits

Technical information

Standard server logs generated when the app talks to our backend (such as request timestamps and error details), used to keep the service running and to investigate problems. We don't run advertising or analytics trackers in the app.

2.How we use it

  • To figure out who else was at the same Venue or Event as you during the same window, filtered to your stated interest category
  • To create a match only when interest is mutual — co-presence alone never creates a match
  • To reveal, on a match, the name of the shared location only — never the date or time of the overlap, and never coordinates
  • To deliver chat messages between you and a match
  • To notify you, if you allow it, when you have a new match or a new message (see "Notifications" in section 4 for exactly what an alert contains)
  • To send account essentials, like your sign-in code (House signs you in with a one-time code emailed to you; there is no password)
  • To review a profile photo before it goes live
  • To show you your own history of Venues and Events — including a map with a pin for each one — and to let you opt out of any of them
  • To look into a report, honor a block, and enforce our community standards
  • To automatically check Venue visit records for patterns that suggest a visit was faked (for example, appearing at two places at once), so that a person on our team can review the account. We never act on an account automatically, and these checks use only the visit records described above, which are deleted on the usual schedule.
  • To keep a record that you accepted the beta terms while House is in beta

3.Location data in detail

Location is the most sensitive thing we handle, so here's exactly how it works, with no fine print left out:

Off by default. Venue-based matching is opt-in. Until you turn it on, you're never entered into a Venue matching pool. Creating or joining an Event never requires location access at all.

Why we ask for background ("Always") location

To detect that you've spent time at one of our curated venues even when House isn't open, we ask for background location access. We use it only to check your proximity to a short list of nearby curated venues — we do not log your route, your speed, or a continuous trail of everywhere you've been.

How detection actually works

  • Your phone keeps watch on roughly the 20 curated venues nearest to you, and refreshes that list only when you've moved a significant distance — about half a kilometer, or sooner if you've moved toward venues that aren't on the list — not on a timer. To know when, your phone remembers the area where it last made the list; that stays on your phone.
  • Your phone's operating system tells House when you enter or leave one of those venue areas. We don't poll your location continuously.
  • A visit only counts once you've stayed for a minimum dwell time (currently about 5 minutes, which we may tune). A brief walk-by is never a visit.
  • What we store for a visit is the Venue, and the entry and exit times — not your precise coordinates within it
  • When a visit registers, House shows you a prompt so you can opt out of that Venue's matching pool on the spot. If you allow notifications, your phone also shows a notification saying which Venue's House Party you're in. That notification is created on your phone itself: it is never sent through our servers or through Expo, Apple, or Google, and the fact that you received it isn't shared with anyone.

What we never do

  • We never show your real-time location to anyone, matched or not
  • We never show another user your exact coordinates, at any point, even after a match
  • We never show another user the date or time you were somewhere — a match reveals the name of the place only
  • We never store more location precision or history than matching needs

If you deny location access, or grant it only "while using the app," House still works for everything except Venue-based matching: you can keep your profile, chat with existing matches, and host or join Events. The app will tell you that Venue matching is off and why, with a link to your phone's settings.

4.How we share information

  • We do not sell your personal information, to anyone, ever, and we don't share it with advertisers or data brokers
  • We never share your email or phone number with other users
  • The only things another user ever sees are what's on your Dater profile (if you have one), messages you send them after a mutual match, and — after that match — the name of the location you were both at
  • We may disclose information if required by law, or as part of investigating a safety report

Service providers we rely on

House runs on a small number of third-party services that process data on our behalf, under their own security and privacy commitments. We share with them only what's needed to do the job:

  • Supabase — hosts our database, sign-in system, and photo storage. Everything described in this policy is stored there, on servers in the United States. Profile photos live in private storage that other users can only read once a photo has passed review.
  • Google Maps Platform — when a host types an Event address, the text is sent to Google's Places service to show suggestions, and if the host picks one, Google returns its coordinates. We also use Google's Places data when curating venues, and Google's map tiles to draw the "My House Parties" map on Android (iOS uses Apple Maps). Google receives the address text you type and standard map requests, not your account or presence data.
  • Resend — sends your sign-in code and any account emails to the address you gave us.
  • Push notifications (Expo, Apple, Google) — when you get a new match or message, we send the alert through Expo's push notification service, which delivers it through Apple Push Notification service (iPhone) or Firebase Cloud Messaging (Android). For a new match, the alert includes the other person's first name and the name of the place or party where you both were. For a new message, it includes only the sender's first name, never the message itself. Each alert also carries your phone's push token and an internal ID so that tapping it opens the right chat. These services don't receive your email, phone number, profile, or location. Venue-visit notifications don't use these services at all (see section 3).
  • Cloudflare — hosts the page House Party invite links open (go.joinhouse.co). When someone opens an invite in a browser, Cloudflare receives the request like any web host, including the address (which contains that party's invite code) and the visitor's IP address. The page itself loads nothing else, stores nothing, and shows no party or user details.
  • Apple TestFlight (during the beta) — Apple distributes beta builds and handles any feedback or crash reports you submit through the TestFlight app, under Apple's own privacy terms.

5.Your choices & controls

  • Turn Venue-based location matching on or off at any time through your phone's location settings — the app links you there
  • Opt out of one specific visit at any time, even while that Venue's matching window is still open — this deletes the underlying presence record for that occasion, not just hides it
  • Leave an Event you joined at any time, before or after its date — same effect: the record of you joining is deleted
  • Permanently exclude a specific Venue (say, your home or workplace) so it never registers your presence there again — from that Venue's entry or from Settings
  • Turn off new-match, new-message, or Venue-visit notifications individually in Settings → Notifications, or turn off all House notifications in your phone's settings
  • Edit your profile at any time; delete or deactivate your account at any time, from Settings (see the next section)
  • Block another user at any time
  • Report a user for review

6.Retention & deletion

  • Presence data is short-lived by design. A Venue's or Event's matching window stays open for about a week after the relevant day; if you haven't matched with someone from that location by then, the non-matched presence records for it are deleted, and the location disappears from your list.
  • If you opt out of a visit or leave an Event, that presence record is deleted right away — not at the end of the week
  • A match, and the chat that goes with it, persists after the location's window closes. Blocking ends access to the chat for both of you; the records themselves are deleted when either account is deleted.
  • If there's an open report against a user when the week ends, we keep their presence records until it's resolved, then delete them
  • Your phone's push token is removed from our records when you sign out, and is deleted with your account. If another account later signs in on the same phone, the token moves to that account, so alerts go only to whoever is signed in.
  • Deleting your account is a true, permanent deletion — your profile, photo, matches, chat history, presence records, notification settings and push tokens, and beta acceptance record are all removed. Events you host that haven't happened yet are deleted with your account; an Event whose date has already passed keeps running for its remaining attendees, without you, until its window closes.
  • When you ask us to delete your account, it's hidden from everyone immediately and permanently deleted 7 days later. If you sign in before then, you can restore it and everything comes back — except your profile photo, which is deleted the moment you ask, so no photo of you lingers in storage during the window.
  • If we ban an account for violating our rules, we delete it immediately, with no recovery window, and keep only a one-way hash of the email address, the reason, and the date. That's enough to refuse a new signup with the same address; it can't be reversed into the email, and nothing else about the account is kept.
  • You can deactivate instead of deleting — this hides your profile from other users while keeping your data intact, so you can pick back up later
  • If you switch a Dater profile to Host-only mode, your Dater profile is hidden immediately, and your dating data — profile, presence at Venues and Events, interests, matches, and messages — is kept for 7 days so you can restore it from Settings, then permanently deleted. Your profile photo is deleted immediately, as with account deletion. Your account, the Events you host, your blocks, and your Venue exclusions are kept. Adding a Dater profile to a Host-only account doesn't remove any hosting data.

7.The beta program

While House is in beta, a few extra things apply:

  • Before you can use the app, you'll be asked to accept the House Beta Tester Terms. We record that you accepted and when, and we keep that record for as long as your account exists.
  • Feedback you send through the TestFlight app goes to Apple and to us. Feedback you send us directly goes only to us.
  • Beta builds are pre-release software. Features, and the data practices described here, may change between builds; we'll update this policy when they do.

8.Age requirement

House is for people 18 and older. We ask for your date of birth at signup and won't let you finish creating an account if it works out to under 18.

9.Security

We use industry-standard safeguards to protect your information: all traffic between the app and our servers is encrypted in transit; access to your data on the server is restricted by rules that only let your own account read and change your own records; profile photos are held in private storage and are only readable by others once they've passed review; and photos are stripped of embedded location metadata before they're stored. No method of storage or transmission is 100% secure, and we can't guarantee absolute security.

10.Changes to this policy

As House changes, this policy will too. We'll update the date at the top whenever we make a change.

11.Contact us

Questions about this policy or your data? Reach us at [email protected].