ComeThru

Privacy Policy

Last updated: August 17, 2026

Plain-English summary: ComeThru collects the account, profile, meetup, message, media, location, contact-matching, diagnostic, analytics, subscription, and business-advertising billing information needed for the features described below. An opaque Hang share link can make limited Hang information public; the public profile-link bridge does not display profile data. Photos/videos you upload and a personal Hang cover can appear in future exported Recaps only when you allow all eligible Hangs or that specific Hang. You can ask to decide Hang by Hang or turn sharing fully off in Preferences. Frozen awards, including the winner's name and profile photo, may also appear in a Recap as described below. The Google Mobile Ads SDK is included in the binary, but production code prevents ComeThru from loading or initializing it for this public release. You must be at least 16 and reside in the United States. Account deletion has a 30-day grace period and then deletes, anonymizes, or retains data as specifically described in Section 8.

This Privacy Policy explains how ComeThru LLC ("ComeThru," "we," "us," or "our") collects, uses, discloses, and protects information when you use the ComeThru mobile application and related websites and services (the "Service"). The Service is offered to U.S. residents. Capitalized terms not defined here have the meaning given in our Terms of Service.

1. Information We Collect

A. Information you provide

B. Information collected automatically

C. Information from your device (with permission)

2. Information We Do Not Collect

We want to be clear about what we don't do:

3. How We Use Your Information

We use the information described above to:

4. Legal Bases & Why We Process

For users in the United States, the legal bases on which we process your information include:

5. How We Share Your Information

We share your information with the following categories of recipients, for the purposes described:

RecipientData sharedPurpose
Firebase / Google Cloud (Authentication, Firestore database comethru, Cloud Storage, Cloud Functions, Hosting) Account data, profile, all content (Hangs, messages, gallery, comments), notifications, push tokens, pseudonymous analytics events, and aggregate counters Core infrastructure for the Service
Firebase Auth SMS infrastructure (Google) Phone number Delivering account verification SMS
Expo services, including Expo Push Notification Service Expo push token, notification title/body, and navigation data such as notification type and related Hang identifier or title Delivering push notifications to your device
Google Maps SDK & Google Places API (New) Map requests, location search text, exact origin/bias coordinates, session token, place ID, selected address/coordinates, and place-photo request Google map rendering, place search, ranking, details, and photos
Mapbox A Hang coordinate rounded to two decimal places, map style, and request metadata Returning a static map image when an authorized user selects a map in a Recap
Google Cloud Vision API Gallery image and video-thumbnail bytes, personal-avatar image bytes, and business-profile image bytes Advisory SafeSearch signals for adult content, violence, and racy material to support human moderation
Giphy (Giphy, Inc.) GIF search query and request metadata from ComeThru's authenticated server proxy; selected GIF URL and dimensions remain in ComeThru content Powering GIF search and selection in chat and comments
SendGrid (Twilio Inc.) Contents of bug reports and content reports; admin recipient email addresses Delivering transactional email to ComeThru admins for support and moderation
Sentry (Functional Software, Inc.) Error stacks, scrubbed breadcrumbs, performance traces, signed-in user UID, and display name (production only) Crash and error monitoring
Google Mobile Ads (SDK linked; production loading and initialization disabled for this release) No ComeThru ad request in this release; the linked native SDK remains subject to the exact archive/runtime audit. A later enabled release could process IP-derived general location, product interactions, diagnostics, advertising/App Set or other device/account identifiers, consent signals, and ad interactions. SDK presence and future conditional advertising, analytics, and fraud prevention. House promotions do not make a Google ad request.
Apple App Store / Google Play Store account, payment, transaction, and subscription information Processing native in-app purchases, taxes, cancellations, and refunds
RevenueCat ComeThru user ID, store product and transaction identifiers, receipt or purchase token, subscription status, and limited device/app information Receipt validation, fraud prevention, Premium entitlement delivery, subscription support, and subscription analytics
Stripe Business name and ComeThru business ID; promotion line items, amount and draft/order references; billing and payment-method details entered directly on Stripe-hosted pages; Stripe customer, Checkout, PaymentIntent, charge, invoice, refund and dispute information Creating and reusing a business-linked billing customer, securely authorizing and later capturing or voiding promotion payments, managing payment methods, producing invoices and receipts, processing refunds and disputes, and preventing fraud
Other users and people who receive public links or exported Recaps Profile information inside the signed-in Service; personal or business Hang information; invitations and RSVP; chat, GIFs, Gallery and comments; friend-limited live location while enabled; limited public Hang share-page data; consent-eligible personal Recap media, privacy-limited Hang details, and frozen award winner name/profile photo. Generic public profile links do not display profile data. Operating social, sharing, business, and public-link features. Copies exported outside ComeThru are controlled by the recipient, not ComeThru.
Law enforcement and other authorities Account or content information Responding to valid legal process, protecting rights and safety, complying with applicable law
Successors in interest All categories of information Merger, acquisition, reorganization, sale of assets, or similar transaction (with notice to you)

Advertiser analytics and targeting. ComeThru's first-party ad-event pipeline can record pseudonymous impressions and clicks, but the app does not currently expose an advertiser reporting product or activate off-platform audience transport. Any future advertiser reporting must use aggregate cohorts and comply with the safeguards described in the current Service. Sponsored placements are restricted to users established as age 18 or older; alcohol-related delivery is not activated. Faith/community, health/wellness, education, civic/services, residential, and unknown venue history are not used to build behavioral advertising affinity. Nightlife affinity is restricted to eligible users age 21 or older for a first-party ComeThru campaign and is not exported as an advertiser-curated audience.

We do not sell your personal information. We do not currently activate off-platform audience matching or a provider transport that sends phone-derived match keys to an advertising platform. Code and default-off controls for that possible feature are present but dormant. We will update this Policy, store disclosures, and required privacy choices before activating such a transfer. Hashing a phone number for matching would not make it anonymous.

6. Visibility, Sharing & Public Links

Personal Hangs. In-app access is invitation-based. Server-side rules limit a personal Hang to:

Hang content. Chat, Gallery, and comments are visible to the authorized Hang circle. Live-location pins have a narrower rule: only the sharing user and eligible friends participating in the Hang can read the pin during the limited time window.

Businesses. Active business profiles can be searched by signed-in users. Surfaced business Hangs are public listings inside the signed-in Service and may be shown to followers and business-profile visitors. When a signed-in user blocks a business, ComeThru prevents direct access/follow/join actions and filters that business from normal discovery for that account.

Public profile links. A comethruapp.com/user/... URL can be opened without a ComeThru account, but it now returns only a generic ComeThru deep-link bridge and does not fetch or display the user's name, username, avatar, or other profile data. The Firebase UID remains part of the URL itself.

Hang share pages. Where a valid opaque share token has been created, a public comethruapp.com/h/... page can show the Hang title, host name/avatar, date/time, and general area. It does not show map imagery, coordinates, or the exact venue address. Anyone who receives the bearer link can view it until it is revoked.

Recaps. Hang access alone is not permission to publish another member's personal media. A current owner-controlled choice allows future Recaps to include personal Gallery photos/videos that member uploaded and a personal Hang cover they own either across eligible Hangs or only for a separately approved Hang. Missing, denied, Off, invalid, or revoked choices remain excluded. Choosing Off invalidates earlier Hang grants; returning to Ask Me Per Hang does not restore them without a new Include choice. A server-generated manifest enforces the current choice before export; business-attributed media and business covers are excluded. Aggregate attendance and frozen award facts—including the winner's name and profile photo—can appear, but other attendees and a different personal host remain anonymous. The media-sharing preference does not control award identity. The operating-system share sheet can send the finished image outside ComeThru. Changing a choice controls future media exports but cannot recall a copy already exported or held by a recipient.

7. Children & Age Policy

The Service is intended for users 16 years of age or older. We do not knowingly collect personal information from anyone under 16. We enforce the age requirement through a server-side validation Cloud Function that runs at signup; users who do not qualify are not allowed to create an account, and their submitted date of birth is not retained. Phone numbers and email addresses associated with a rejected signup are added to a blocklist with a 90-day time-to-live to prevent immediate re-registration. Any user can report another user they suspect is under 16, and we may investigate and take action.

Users aged 16–17 may use the core Service but are not eligible to receive sponsored ComeThru or Google Mobile Ads placements. Advertising eligibility fails closed if the stored date of birth is missing or invalid.

If you believe we have collected information from a person under 16, please use the in-app report control or email hello@comethruapp.com. We may investigate, restrict the account, remove content, preserve evidence, and make legally required reports. ComeThru prohibits child sexual abuse and exploitation, grooming, sextortion, trafficking for sexual exploitation, and child sexual abuse material. We remove confirmed prohibited material when we obtain actual knowledge and report it where required by law. See our Child Safety Standards.

8. Data Retention & Deletion

While your account is active

When you delete your account

You can delete your account at any time from the in-app Profile screen.

  1. You are signed out immediately. Your push token is cleared and your refresh tokens are revoked.
  2. Your account enters a 30-day grace period. You can reinstate the account during that period by signing back in and confirming.
  3. After the grace period, a daily process handles up to a bounded number of accounts, so final processing can occur after the exact 30-day point. It then performs a permanent deletion and anonymization cascade:
    • Your Firebase Authentication record and your user document are deleted.
    • Your profile photo is deleted from Cloud Storage.
    • Your friendships, business follows and blocks, friend/group/Hang memberships, reactions, reminders, referral claims, advertising choices and queues, and other private relationships are deleted or disconnected.
    • Notifications you received are deleted.
    • Personal Hangs you created, chat messages you sent, comments, awards, safety reports, and notifications you triggered for others are anonymized — personal identifying fields are replaced with "Former member" or a deleted-user sentinel.
    • Ordinary personal Gallery files, their thumbnails, and personal Hang covers you uploaded are deleted from Cloud Storage. Their Gallery records are anonymized and hidden. An exact media object protected by a separate promotion/Hall of Fame submission can remain, as can business-attributed media and records retained for safety, legal, dispute, audit, or backup purposes.
    • Your business memberships are removed. If another business owner remains, ownership and retained management records transfer to a remaining owner. If you are the only owner, the business is closed, its public identity fields and listings are cleared or disabled, its memberships are deleted, and its business-profile images are removed.
    • Business-attributed promotion, order, invoice, refund, dispute, and audit records may remain as needed for delivery, accounting, fraud prevention, disputes, and legal obligations. Those records can retain the initiating account or deleted-user sentinel as an audit identifier. If a business closes, ComeThru deletes its private Firebase billing record, but Stripe may separately retain its customer and transaction records under Stripe's terms and applicable law.
    • Your username, phone number, and email are released for reuse.
    • Your pseudonymous raw analytics events, daily uniqueness markers, legacy user-level ad events, advertising-consent audit, and audience queue or membership records are deleted. Non-identifying aggregate counters remain.
    • A deletion-audit record remains with a SHA-256 hash of the former Firebase UID, completion time, and deletion/anonymization counts. It does not contain your phone, email, username, or content.

The automated account-deletion cascade removes ordinary personal Gallery files and personal Hang covers after the grace period; a separate full-media request is not required for those objects. You may email hello@comethruapp.com to identify other media you believe remains. ComeThru cannot remove Recap exports or copies held by other users, and promotion/Hall of Fame, business, safety, legal, dispute, audit, or backup exceptions can apply.

9. Security

We take security seriously and use a range of safeguards, including:

No system is 100% secure. We encourage you to protect your device with a passcode or biometric lock and to notify us promptly at hello@comethruapp.com if you believe your account has been compromised.

10. Your Choices & Rights

11. California Privacy Rights (CCPA / CPRA)

This Section applies to California residents and supplements the rest of this Privacy Policy.

Categories of personal information we collect

In the last 12 months, we have collected the following CCPA/CPRA categories of personal information:

Sources, purposes, and recipients

Sources, purposes, and recipients of each category are described in Sections 1, 3, and 5 of this Privacy Policy.

Sensitive personal information

We collect precise geolocation only when you grant permission, and only as described in Section 1. We use sensitive personal information only for the purposes permitted by Cal. Civ. Code § 1798.121(a) and do not use or disclose it to infer characteristics about you.

Sale and sharing

We do not sell personal information. The current public-release configuration does not activate off-platform audience matching, and production code prevents the third-party ad SDK from being loaded or initialized by ComeThru. Before activating a use that constitutes cross-context behavioral advertising or “sharing” under California law, we will update this Policy and provide required notices and opt-out methods.

Your rights

How to exercise your rights

Submit a request by emailing hello@comethruapp.com with the subject line "California Privacy Request." We will verify your identity by reference to information you have already provided to us (such as your registered phone number or email). We will respond within 45 days, with the possibility of one 45-day extension where reasonably necessary, as permitted by law. You may use an authorized agent to submit a request by providing the agent with signed written authorization; we may also require the agent to verify their own identity.

Notice of financial incentive

ComeThru may offer referral or promotion rewards for qualifying actions under terms presented with the program. We do not offer those rewards in exchange for selling personal information. If a program is treated as a financial incentive under applicable law, we will provide any additional notice required for that program.

12. International Users

The Service and its subscription offering are intended for United States residents and are hosted in the United States through Google Cloud / Firebase and other providers. If you access the Service from elsewhere, you do so on your own initiative and are responsible for local law. We will update this Policy before intentionally expanding availability.

13. Third-Party Links & Services

The Service may link to, embed, or otherwise interact with third-party content and services, including Google maps and Places content, Mapbox static maps, Giphy GIFs, Apple and Google store interfaces, Stripe-hosted Checkout and billing management, and operating-system share sheets. Those third parties have their own terms and privacy practices. Once you direct information or an exported Recap to a third party, its handling is also governed by that third party.

14. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service, by email, or by other reasonable means at least seven (7) days before the changes take effect, except where a shorter period is required by law or by an urgent security or compliance need. The "Last updated" date at the top of this Policy reflects the most recent revision. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

15. Contact

Questions or requests about this Privacy Policy? Contact us at:

ComeThru LLC
Email: hello@comethruapp.com
California, United States