This Privacy Policy explains how ComeThru LLC ("ComeThru," "we," "us," or "our") collects, uses, shares, and protects your information when you use the ComeThru mobile application and related websites and services (the "Service"). It applies to U.S. residents using the Service during the current beta period. Capitalized terms not defined here have the meaning given in our Terms of Service.
Contents
- Information We Collect
- Information We Do Not Collect
- How We Use Your Information
- Legal Bases & Why We Process
- How We Share Your Information
- Visibility & the Hang Privacy Model
- Children & Age Policy
- Data Retention & Deletion
- Security
- Your Choices & Rights
- California Privacy Rights (CCPA / CPRA)
- International Users
- Third-Party Links & Services
- Changes to This Policy
- Contact
1. Information We Collect
A. Information you provide
- Identifiers. Phone number (stored in E.164 format), email address (lowercase, if provided), display name, and username.
- Profile. Profile photo, biography, banner selection, home location (optional, as approximate coordinates).
- Date of birth. Collected at the in-app age gate to confirm you are at least 16. The date of birth is processed server-side by our age-validation Cloud Function and is not retained if you do not qualify. If you do qualify, your date of birth is stored on your user record and can no longer be edited by you (corrections require contacting support).
- Content. Hangs you create (title, description, time, location, optional cover photo), RSVPs, chat messages, gallery photos and videos, gallery comments, GIFs you select from the Giphy picker, and any other content you submit.
- Customer support. Information you provide when contacting us or using the in-app bug reporter, which automatically attaches: your description, the screen you were on, your device brand, model, operating system, app version, Expo SDK version, and the last 200 in-memory log entries from your session (used to debug the reported issue).
- Reports. If you report content or a user, we collect your description of the issue, the reason category (spam, harassment, inappropriate content, violence, suspected underage user, or other), and a snapshot of the reported content.
B. Information collected automatically
- Location data. With your operating-system-level permission, the app reads your device's location to sort the feed by distance and to display nearby Hangs. This live device location is held in memory only and is not persisted to our servers. Location coordinates are persisted only when (i) you set a Hang location (those coordinates are stored on the Hang) or (ii) you opt in to live location sharing within an active Hang (those coordinates are stored in a per-Hang collection that only that Hang's attendees can see, and are removed when you turn sharing off or the Hang ends).
- Device identifiers. An Expo push notification token associated with your device, stored on your user record so we can deliver push notifications.
- Diagnostic device info. When you submit a bug report or when an error is captured by our error-monitoring service, we collect device brand, model name, operating system and version, platform, app version, and Expo SDK version.
- Usage data (analytics). Aggregated event data via Firebase Analytics, including app opens, sign-ups, sign-ins, password-reset requests, hang creations and views, RSVPs, messages sent (with a flag for whether the message includes a GIF), gallery uploads (with media type), friend requests sent and accepted, and profile views. Your user ID is implicit through Firebase Auth context.
- Advertising data. Where advertising is enabled, Google Mobile Ads may process device or advertising identifiers, IP address, general device information, consent choices, and ad impressions, interactions, and diagnostics. Personalized advertising is requested only where the required platform permission and consent have been obtained.
- Crash & performance data. In production, we sample uncaught errors, breadcrumbs, and approximately 20% of performance transactions via Sentry. Breadcrumbs are scrubbed to remove push tokens and phone numbers before being sent.
C. Information from your device (with permission)
- Contacts. If you grant Contacts permission, the app reads contact names, phone numbers, and email addresses on your device. Normalized phone-number and email identifiers (but not contact names or complete address-book records) are sent in bounded batches to a ComeThru Cloud Function, transformed and compared against a server-side digest, and used to return matching ComeThru user IDs. We do not persist the submitted contact identifiers in the matching service.
- Camera & microphone. Used only when you capture photos or videos in the app or scan a QR code. Captured media is not sent anywhere until you choose to upload it.
- Photo library. Used only when you pick existing photos or videos to upload.
- Calendar. Used only when you export a Hang to your device calendar; the calendar event is written locally to your device.
- Notifications. Required to deliver push notifications about Hangs, RSVPs, messages, friend requests, reminders, and similar events.
2. Information We Do Not Collect
We want to be clear about what we don't do:
- We do not integrate third-party attribution SDKs such as AppsFlyer, Adjust, Branch, or the Facebook SDK.
- We do not sell personal information for money. Advertising-related processing and opt-out rights are described in this Policy and the consent controls presented in the app.
- We do not collect biometric identifiers or biometric information.
- We do not retain dates of birth submitted by users who fail the age gate.
- We do not upload contact names or complete address-book records; normalized phone and email identifiers are transmitted for server-side matching as described above.
3. How We Use Your Information
We use the information described above to:
- Operate, maintain, and provide the Service — including authenticating users, creating and displaying Hangs, sending messages, posting to galleries, syncing friendships, fanning out push notifications, computing awards, and powering the rest of the app's features.
- Enforce eligibility — validating that you are at least 16 at signup, maintaining a 90-day blocklist of phone numbers and email addresses that have failed the age gate (to prevent immediate re-registration), and acting on reports of suspected underage users.
- Moderate content — running automated safety scans on gallery uploads via Google Cloud Vision, reviewing user-submitted reports, and removing or restricting content that violates our Terms.
- Provide customer support — responding to your messages, bug reports, and reports of content or users.
- Improve the Service — analyzing aggregated usage and crash data to find and fix bugs, prioritize features, and improve reliability.
- Communicate with you — sending SMS verification codes during sign-in, push notifications about Service activity (subject to your notification preferences), and transactional email.
- Protect safety and prevent abuse — enforcing blocks, processing reports, detecting fraud, and protecting users and third parties.
- Comply with legal obligations — responding to lawful requests, enforcing our Terms, and complying with applicable law (including COPPA, California AADC, and CCPA/CPRA).
4. Legal Bases & Why We Process
For users in the United States, the legal bases on which we process your information include:
- Performance of the agreement between you and ComeThru — processing necessary to provide the Service you signed up for.
- Our legitimate interests — operating, securing, debugging, and improving the Service; preventing fraud and abuse; defending legal claims.
- Your consent — for location, contacts, camera, microphone, photo library, calendar, and push notifications, granted via your device's operating-system permission prompts and revocable at any time in your device settings.
- Compliance with legal obligations — including child-safety laws (COPPA at 15 U.S.C. §§ 6501–6506; California AADC at Cal. Civ. Code § 1798.99.28) and consumer-privacy laws (CCPA / CPRA).
5. How We Share Your Information
We share your information with the following categories of recipients, for the purposes described:
| Recipient | Data shared | Purpose |
|---|---|---|
Firebase / Google Cloud (Authentication, Firestore database comethru, Cloud Storage, Cloud Functions, Hosting, Analytics) |
Account data, profile, all content (Hangs, messages, gallery, comments), notifications, push tokens, aggregated analytics events | Core infrastructure for the Service |
| Firebase Auth SMS infrastructure (Google) | Phone number | Delivering account verification SMS |
| Expo Push Notification Service | Expo push token, notification title and body | Delivering push notifications to your device |
| Google Maps SDK & Google Places API (New) | Location search queries, place IDs, coordinates | Location search and map rendering when you create or view a Hang |
| Google Cloud Vision API | Image and video-thumbnail bytes from gallery uploads | Automated SafeSearch scanning for adult content, violence, and racy material |
| Giphy (Giphy, Inc.) | GIF search queries (no user identifiers) | Powering the GIF picker in chat |
| SendGrid (Twilio Inc.) | Contents of bug reports and content reports; admin recipient email addresses | Delivering transactional email to ComeThru admins for support and moderation |
| Sentry (Functional Software, Inc.) | Error stacks, scrubbed breadcrumbs, performance traces, signed-in user UID, and display name (production only) | Crash and error monitoring |
| Google Mobile Ads | Consent state, device and advertising identifiers where available, IP address, ad impressions/interactions, and diagnostics | Displaying, measuring, limiting, and protecting advertising |
| Apple / Google (when paid subscriptions launch) | Subscription receipts | Payment processing through native in-app purchase |
| Other ComeThru users | Your profile (display name, avatar, vibes, reps, awards, banner), Hangs you create or attend, your chat and gallery contributions within those Hangs, your live location while you have sharing turned on | Operating the social features of the Service |
| Law enforcement and other authorities | Account or content information | Responding to valid legal process, protecting rights and safety, complying with applicable law |
| Successors in interest | All categories of information | Merger, acquisition, reorganization, sale of assets, or similar transaction (with notice to you) |
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. The service providers above process information on our behalf and are bound by contractual obligations to use it only for the purposes we authorize.
6. Visibility & the Hang Privacy Model
ComeThru is invitation-only by design. There is no "public" Hang visibility. Server-side security rules enforce that a Hang is visible only to:
- The Hang's creator,
- Users who have RSVP'd "Coming Thru,"
- Users the creator has explicitly invited,
- Members of friend groups the creator has invited, and
- Friends of the creator, only if the creator has set visibility to "all" (their friends).
Chat messages, gallery uploads, gallery comments, and live location shared within a Hang are visible only to that Hang's circle. Your profile (display name, avatar, vibes, reps, banner, awards) is visible to your friends and to other users who find you through search or who interact with you in a Hang. Your phone number and email are not shown on your public profile.
7. Children & Age Policy
The Service is intended for users 16 years of age or older. We do not knowingly collect personal information from anyone under 16. We enforce the age requirement through a server-side validation Cloud Function that runs at signup; users who do not qualify are not allowed to create an account, and their submitted date of birth is not retained. Phone numbers and email addresses associated with a rejected signup are added to a blocklist with a 90-day time-to-live to prevent immediate re-registration. Any user can report another user they suspect is under 16, and we will investigate.
Our age policy is designed to meet the requirements of the Children's Online Privacy Protection Act (15 U.S.C. §§ 6501–6506) and the California Age-Appropriate Design Code (Cal. Civ. Code § 1798.99.28). If you believe we have collected information from a person under 16, please email support@comethruapp.com and we will promptly investigate and, where appropriate, delete the information.
8. Data Retention & Deletion
While your account is active
- Hangs live for the duration of the Hang's lifecycle plus an expiration window of 72 hours after the Hang ends. Free-tier users lose interactive access at the 72-hour mark; premium-tier users (and, during the beta, all users) retain access indefinitely. Underlying records may persist longer for purposes of co-attendees' access.
- Chat messages and gallery items are retained alongside their Hang and are not auto-deleted. On account deletion they are anonymized (not deleted) so that co-attendees keep their shared memory of the Hang.
- Push tokens are cleared when you sign out and refreshed when you sign back in.
- Bug reports and content reports are retained indefinitely for audit, debugging, and safety purposes.
- Age-gate blocklist entries are retained for 90 days; no date of birth is stored.
- Analytics events are retained according to Firebase Analytics' default policy (currently 25 months).
- Sentry error and performance data are retained for up to 90 days, in accordance with Sentry's standard retention.
When you delete your account
You can delete your account at any time from the in-app Profile screen.
- You are signed out immediately. Your push token is cleared and your refresh tokens are revoked.
- Your account enters a 30-day grace period. You can reinstate the account during that period by signing back in and confirming.
- After 30 days, a daily scheduled job performs a permanent deletion and anonymization cascade:
- Your Firebase Authentication record and your user document are deleted.
- Your profile photo is deleted from Cloud Storage.
- Your friendships and hang reminders are deleted.
- Notifications you received are deleted.
- Hangs you created, chat messages you sent, gallery uploads you contributed, gallery comments you posted, awards you won, and notifications you triggered for others are anonymized — your identifying information is replaced with "Former member."
- Gallery files you uploaded are preserved in Cloud Storage with anonymized metadata, so co-attendees retain the shared memory of the Hangs you attended.
- Your username, phone number, and email are released for reuse.
- A deletion-audit record is written for our internal records.
If you would like your gallery files fully removed (rather than anonymized and retained), email support@comethruapp.com and we will use commercially reasonable efforts to remove them, subject to legal retention obligations.
9. Security
We take security seriously and use a range of safeguards, including:
- Encryption in transit (TLS) for all client–server traffic.
- Encryption at rest for data stored in Firebase / Google Cloud.
- Authentication via Firebase Authentication, including SMS verification.
- Firestore security rules that enforce per-user access controls, Hang visibility, and admin role checks via Firebase Auth custom claims.
- Cloud Storage rules that enforce file size and content-type limits.
- Sensitive operations (such as profile-cascade updates, push fan-outs, account deletion, and content moderation) running server-side as privileged Cloud Functions rather than from client devices.
- Centralized scrubbing of phone numbers, email addresses, verification IDs, push tokens, authorization values, and share-link bearer tokens from diagnostic logs and Sentry context before transmission.
No system is 100% secure. We encourage you to protect your device with a passcode or biometric lock and to notify us promptly at support@comethruapp.com if you believe your account has been compromised.
10. Your Choices & Rights
- Location. Revoke the location permission in your device settings at any time. Live location sharing inside a Hang is opt-in and can be turned off at any time.
- Notifications. Manage push notification categories in the in-app Preferences screen (including a master "Pause All" toggle and per-category toggles for invites, RSVPs, reminders, friend requests, chat messages, and gallery uploads). Disable notifications system-wide in your device settings.
- Contacts. Revoke Contacts permission in your device settings at any time. Contact names and complete address-book records remain on your device; normalized phone/email identifiers are transmitted transiently for matching and are not stored by the matching service.
- Profile. Edit your display name, bio, avatar, banner, vibe, and rep in the app.
- Block other users. Block functionality is available where supported in the app.
- Report. Report content or users using the in-app reporting feature.
- Delete your account. Use the in-app account-deletion flow (see Section 8).
- Access & portability. Request a copy of the personal information we hold about you by emailing support@comethruapp.com. We will respond within the time period required by law (45 days under CCPA). Automated data export is not yet available; we provide exports manually upon request.
- Correction. Most profile fields are editable in the app. Your date of birth, once submitted, cannot be self-edited; to request a correction, email support@comethruapp.com.
11. California Privacy Rights (CCPA / CPRA)
This Section applies to California residents and supplements the rest of this Privacy Policy.
Categories of personal information we collect
In the last 12 months, we have collected the following CCPA/CPRA categories of personal information:
- Identifiers — name, username, phone number, email address, user ID, device identifiers.
- Personal records (Cal. Civ. Code § 1798.80(e)) — phone number, email.
- Protected classification characteristics — age (derived from your date of birth at signup to confirm eligibility); the underlying date of birth itself.
- Commercial information — subscription status (when paid tiers launch).
- Internet or other electronic network activity — analytics events, crash reports, performance traces.
- Geolocation data — approximate location for feed sorting, Hang location coordinates you set, opt-in live location sharing.
- Audio, electronic, visual — photos and videos you capture or upload.
- Inferences — friend-suggestion outputs, "people you may know" matches.
Sources, purposes, and recipients
Sources, purposes, and recipients of each category are described in Sections 1, 3, and 5 of this Privacy Policy.
Sensitive personal information
We collect precise geolocation only when you grant permission, and only as described in Section 1. We use sensitive personal information only for the purposes permitted by Cal. Civ. Code § 1798.121(a) and do not use or disclose it to infer characteristics about you.
Sale and sharing
We do not sell personal information and we do not share personal information for cross-context behavioral advertising. We have not done so in the preceding 12 months.
Your rights
- Right to know what personal information we have collected, used, disclosed, and sold or shared (we have not sold or shared).
- Right to delete personal information we hold about you, subject to permitted exceptions.
- Right to correct inaccurate personal information.
- Right to portability — receive your personal information in a portable format.
- Right to limit use of sensitive personal information (we already limit use of sensitive PI as described above).
- Right to non-discrimination for exercising your CCPA/CPRA rights.
How to exercise your rights
Submit a request by emailing support@comethruapp.com with the subject line "California Privacy Request." We will verify your identity by reference to information you have already provided to us (such as your registered phone number or email). We will respond within 45 days, with the possibility of one 45-day extension where reasonably necessary, as permitted by law. You may use an authorized agent to submit a request by providing the agent with signed written authorization; we may also require the agent to verify their own identity.
Notice of financial incentive
We do not offer financial incentives in exchange for personal information.
12. International Users
The Service is intended for use by United States residents during the current beta period. The Service is hosted in the United States (via Google Cloud / Firebase). If you access the Service from outside the United States, you do so on your own initiative and at your own risk, and you are responsible for compliance with applicable local laws. We do not currently offer GDPR or UK GDPR compliance features; if and when we expand internationally, we will update this Policy and provide appropriate disclosures.
13. Third-Party Links & Services
The Service may link to, embed, or otherwise interact with content and services from third parties (including, for example, map tiles from Google, GIFs from Giphy, and place data from the Google Places API). Those third parties have their own privacy practices, which we do not control. This Policy does not apply to those third parties.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service, by email, or by other reasonable means at least seven (7) days before the changes take effect, except where a shorter period is required by law or by an urgent security or compliance need. The "Last updated" date at the top of this Policy reflects the most recent revision. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
15. Contact
Questions or requests about this Privacy Policy? Contact us at:
ComeThru LLC
Email: support@comethruapp.com
California, United States