# Privacy Policy
**Effective Date:** March 8, 2026
**Last Updated:** March 29, 2026
**1+1 App** ("1+1", "we", "us", or "our") is operated by 1+1 Development ("Company"). This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our mobile application and related services (collectively, the "Service").
By using 1+1, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service.
**Contact:** privacidad@1mas1.app
---
## 1. Information We Collect
### 1.1 Information You Provide
- **Account Information:** Email address, password (stored as a secure hash, never in plain text), or OAuth credentials when signing in with Google or Apple.
- **Profile Information:** Name, date of birth, gender, bio (up to 500 characters), interests, and relationship intent (romance, friendship, or both).
- **Photos:** Images you upload for your profile. We store originals and generate thumbnails for performance.
- **Preferences:** Gender preference, age range, maximum distance, visibility settings (hide profile, show active status, show distance).
- **Messages:** Text messages exchanged with matched users (up to 5,000 characters per message).
- **Reports:** If you report another user, we collect the reason and optional description.
- **Payment Information:** We do not directly collect or store payment card details. All subscription purchases are processed through Apple App Store, Google Play Store, or Stripe, and we only receive transaction identifiers and subscription status.
### 1.2 Information Collected Automatically
- **Location Data:** With your explicit permission, we collect precise GPS location data to show you nearby users and calculate distances. You may also use our Aventura feature to set an alternate location. You can revoke location permission at any time through your device settings.
- **Device Information:** Device type, operating system version, unique device identifiers, and Firebase Cloud Messaging (FCM) tokens for push notifications.
- **Usage Data:** Interactions with the Service including swipe actions (like, pass, mega like), match activity, feature usage, and session timestamps.
- **Crash and Performance Data:** Through Firebase Crashlytics and Firebase Performance Monitoring, we collect crash reports, error logs, and app performance metrics to improve reliability.
- **Security Data:** Failed login attempts, account lock events, and authentication timestamps for fraud prevention.
### 1.3 Information from Third Parties
- **Authentication Providers:** If you sign in with Google or Apple, we receive your name, email address, and a unique provider identifier. We do not receive your password from these providers.
- **App Store/Play Store:** Subscription purchase status and transaction identifiers for verifying your subscription tier.
---
## 2. How We Use Your Information
We use your information to:
- **Provide the Service:** Create and display your profile, facilitate discovery of nearby users, enable matching, and support real-time messaging.
- **Personalize Your Experience:** Apply your preferences (age range, distance, gender preference, relationship intent) to filter discovery results.
- **Process Subscriptions:** Verify in-app purchases and provide access to premium features (Plus, Premium, Elite tiers).
- **Ensure Safety:** Moderate user-uploaded photos using automated content analysis (Sightengine), review user reports, detect and prevent fraud, and enforce our Community Guidelines.
- **Send Notifications:** Deliver push notifications about new matches, messages, and service updates via Firebase Cloud Messaging.
- **Improve the Service:** Analyze usage patterns, diagnose technical issues via crash reports, and optimize performance.
- **Comply with Legal Obligations:** Respond to legal requests and enforce our Terms of Service.
---
## 3. How We Share Your Information
We do **not** sell your personal data.
We may share your information with:
- **Other Users:** Your profile information (name, age, photos, bio, interests, distance, verification status) is visible to other users through the discovery feed and match conversations. Your exact GPS coordinates are never shared with other users — only an approximate distance is displayed.
- **Service Providers:** Third-party companies that help us operate the Service, including:
- **Cloudflare (R2):** Secure cloud storage for photos.
- **Firebase (Google):** Push notifications, crash reporting, performance monitoring, and device attestation.
- **Sightengine:** Automated photo moderation and content safety analysis.
- **Neon:** Managed PostgreSQL database hosting.
- **Redis:** In-memory caching for performance and rate limiting.
- **Apple/Google/Stripe:** Payment processing and subscription verification.
- **Law Enforcement:** When required by law, court order, or governmental request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- **Business Transfers:** If 1+1 is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
---
## 4. Data Storage and Security
- **Storage Location:** Your data is stored on servers in the United States (Neon PostgreSQL, Cloudflare R2, Redis).
- **Encryption:** Passwords are hashed using bcrypt with 12 rounds. Data in transit is protected via TLS/SSL. Certificate pinning is implemented on mobile clients.
- **Access Controls:** Administrative access is restricted to authorized personnel with role-based permissions.
- **Rate Limiting:** We implement rate limiting on API endpoints and swipe actions to prevent abuse.
- **Account Security:** Accounts are automatically locked after 10 consecutive failed login attempts. Biometric lock (Face ID/Fingerprint) uses your device's native secure enclave — we never access or store your raw biometric data.
- **App Check:** We use Firebase App Check to verify that requests come from our official app, preventing unauthorized API access.
---
## 5. Data Retention
- **Active Accounts:** We retain your data for as long as your account is active.
- **Deleted Accounts:** When you delete your account, we immediately:
- Delete all your photos from cloud storage (originals, thumbnails, and blurred variants).
- Delete your profile, preferences, swipes, and matches.
- Anonymize your messages (sender set to anonymous, content preserved for the other user).
- Anonymize your email address.
- Soft-delete your account record.
- Revoke all active sessions.
- **Reports:** User reports are retained for safety and legal compliance even after account deletion, but reporter/reported identifiers are anonymized.
- **Backups:** Database backups may retain anonymized data for up to 30 days after deletion.
---
## 6. Your Rights and Choices
### 6.1 Access and Portability
You can request a copy of your personal data through the app (account data export feature) or by contacting us at privacidad@1mas1.app.
### 6.2 Correction
You can update your profile information, preferences, and photos at any time through the app.
### 6.3 Deletion
You can delete your account at any time through **Settings > Delete Account** in the app. This action is permanent and cannot be undone.
### 6.4 Location
You can disable location access at any time through your device settings. Note that the discovery feature requires location access to function.
### 6.5 Notifications
You can manage push notification preferences through your device settings.
### 6.6 Visibility
You can hide your profile from discovery at any time using the "Hide Me" feature in Preferences.
---
## 7. California Residents (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, and disclose.
- Request deletion of your personal information.
- Opt out of the "sale" of personal information (we do not sell personal information).
- Not be discriminated against for exercising your privacy rights.
To exercise these rights, contact us at privacidad@1mas1.app.
---
## 8. European Residents (GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights:
- **Legal Basis:** We process your data based on consent (location, notifications), contract performance (providing the Service), and legitimate interests (safety, fraud prevention).
- **Data Portability:** You can request your data in a structured, machine-readable format.
- **Right to Object:** You can object to processing based on legitimate interests.
- **Right to Restrict Processing:** You can request that we limit how we use your data.
- **Data Protection Authority:** You have the right to lodge a complaint with your local data protection authority.
---
## 9. Children's Privacy
1+1 is intended for users aged **18 and older**. We do not knowingly collect personal information from anyone under 18. Our automated photo moderation includes detection of underage individuals. If we discover that a user is under 18, we will immediately terminate the account and delete all associated data. If you believe a minor is using our Service, please contact us at seguridad@1mas1.app.
---
## 10. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies.
---
## 11. International Data Transfers
Your information may be transferred to and processed in the United States, where our servers are located. By using the Service, you consent to this transfer. We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy.
---
## 12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy in the app and updating the "Last Updated" date above. Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.
---
## 13. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
**Email:** privacidad@1mas1.app
**Support:** https://1mas1.app/soporte
---