This Privacy Policy explains how ComeThru LLC ("ComeThru," "we," "us," or "our") collects, uses, discloses, and protects information when you use the ComeThru mobile application and related websites and services (the "Service"). The Service is offered to U.S. residents. Capitalized terms not defined here have the meaning given in our Terms of Service.
Contents
- Information We Collect
- Information We Do Not Collect
- How We Use Your Information
- Legal Bases & Why We Process
- How We Share Your Information
- Visibility & the Hang Privacy Model
- Children & Age Policy
- Data Retention & Deletion
- Security
- Your Choices & Rights
- California Privacy Rights (CCPA / CPRA)
- International Users
- Third-Party Links & Services
- Changes to This Policy
- Contact
1. Information We Collect
A. Information you provide
- Account identifiers. A U.S. phone number in E.164 format, required email address, Firebase user ID, display name, and username. Phone/SMS is the only sign-in method; the email is account information, not a sign-in method.
- Profile and business information. Profile photo, biography, banner, vibe, rep, awards, optional home-area location, and friendship or group relationships. If business features are enabled, we also collect business name, handle, description, avatar and cover, categories, venue, website and social links, team roles, follows, blocks, and business activity.
- Date of birth. We send your date of birth to a server-side age-validation function to confirm you are at least 16. If eligible, it is stored in an owner-only private user record. If not eligible, the date of birth is not retained; the phone number and any authentication email are blocklisted for 90 days and the attempted account is deleted.
- Hangs and interactions. Hang titles, descriptions, dates and times, invitation and visibility lists, selected venue name and physical address, precise coordinates, place ID, city and broad venue class, cover image, RSVP, reminders, chat text, GIF URL and dimensions, mentions, reply references, reactions, Gallery uploads, comments, awards, and related activity.
- Photos, videos, audio, and metadata. Avatars, covers, Gallery images and videos, thumbnails, and related technical metadata. Videos may contain audio. The app usually compresses or resizes uploads and creates thumbnails, but processing can fall back to the original file and is not guaranteed to remove all embedded metadata.
- Recap media-sharing choices. Owner-only private records hold an account mode—All Hangs, Ask Me Per Hang, or Off—and, in Ask mode, a choice for an individual Hang. New members choose All or Ask during profile onboarding. A nonblocking invitation can appear after a successful personal upload or on a completed Hang; Yes then offers All Hangs or Just This Hang, No dismisses that Hang, and Don't Show Again changes the account to Off. These choices never block an upload or other Hang activity.
- Customer support. Information you send to support. An in-app bug report includes your description, current screen, signed-in user ID and username when available, device and app/build information, and up to the last 200 in-memory log entries. The report also sends the description and a smaller recent-log set to Sentry for debugging.
- Safety reports. Report reason and optional description, reporter and target identifiers, and a server-created snapshot. Depending on the target, that snapshot can include Hang title/description, message text and GIF URL, Gallery media URL/type, or Gallery-comment text/GIF plus its parent media ID. User-only reports do not include a profile-content snapshot.
- Subscription and consumer purchase information. Product and transaction identifiers, receipt or purchase token, subscription and entitlement state, store, and limited device/app/storefront information received through Apple, Google, and RevenueCat. Apple and Google process the payment instrument; ComeThru does not receive your full card or bank-account number for a subscription.
- Business advertising and billing information. New advertiser purchasing is disabled for the initial public launch; the native link is hidden and the portal cannot create a new draft or checkout. Existing promotion and billing records remain in scope. When purchasing is enabled in a later reviewed release, the web advertising portal stores promotion drafts and creative, line items and totals, the selected business and Hang, the initiating member's user ID, order and Stripe object identifiers, and authorization, capture, cancellation, refund, dispute, and delivery status. At the first checkout, ComeThru creates a persistent Stripe customer linked to the business name and business ID, stores that Stripe customer ID in the business's private billing record, and reuses it for later checkout, bounded invoice summaries, and authorized payment-method management. Card and other billing details are entered on Stripe-hosted pages and processed by Stripe; ComeThru receives customer, transaction, invoice, and status information but not the full card or bank-account number. Checkout first authorizes the displayed total. ComeThru captures it only after human review approves the promotion, or voids/cancels the authorization when the promotion is rejected or the authorization expires.
- Advertising choices and events. For eligible adults, in-app personalization choices and, if visible, separate off-platform audience choices. We also record house-ad or third-party-ad impressions and clicks if those placements run. These choices default off unless the app clearly presents otherwise.
B. Information collected automatically
- Foreground location. With device permission, ComeThru reads precise or approximate foreground location for nearby sorting, distance, map display, location picking, and Places ranking. The app generally keeps the feed/map fix in memory, but exact coordinates can be transmitted transiently to ComeThru's Places proxy and Google Places as an origin or bias. A Hang's selected address and exact coordinates are stored with the Hang.
- Live location. If an eligible creator or confirmed participant expressly turns on live sharing while the full Hang map is open, ComeThru stores exact latitude/longitude, sample time, speed, heading, accuracy, publishing mode and interval, and profile display fields. The pin is readable only from one hour before the Hang starts through 30 minutes after its effective end, by the sharing user and eligible friends participating in that Hang. Turning sharing off deletes the pin; stale records may remain until retention cleanup, but security rules close access after the window.
- Approximate map location. If a user chooses a map in a Recap, the server rounds the Hang coordinate to two decimal places (approximately a 1.1-kilometer cell) before requesting a static image from Mapbox. Public Hang teaser pages do not include map imagery or coordinates.
- Device and service identifiers. Expo push token, Firebase/App Check or installation identifiers, RevenueCat identifiers, and, if third-party ads run, advertising ID, App Set ID, and other Google Mobile Ads identifiers where available.
- Diagnostics. In production, Sentry receives errors, stack traces, breadcrumbs, device/app data, signed-in Firebase UID and username, and sampled performance traces. The client samples approximately 20% of performance transactions, and Cloud Functions sample approximately 10%. Central redaction attempts to remove common phone, email, token, and authorization values, but information intentionally typed into a bug report is included.
- Usage data (analytics). We record app opens, completed sign-ups, sign-ins, Hang creations and views, RSVPs, messages sent (including whether a GIF was used), gallery uploads (including media type), friend requests, profile views, and ad impressions/clicks. Backend services replace your user ID with a keyed pseudonym before writing an analytics event. Analytics records do not contain your name, contact information, Hang title or ID, exact venue/place ID/address/coordinates, message text, or media URL. Routine product-admin tools cannot read raw or per-user analytics; admin reports suppress any daily row representing fewer than 10 pseudonymous users. Privileged cloud-infrastructure access is restricted to an audited break-glass path.
- Venue category. When you select a Google Places result for a Hang, our server automatically converts Google's detailed place type into a broad ComeThru venue class, such as food and drink, nightlife, arts and entertainment, outdoors and recreation, shopping, sports and fitness, travel and lodging, community and events, faith and community, health and wellness, education, civic and services, or residential. The detailed Google place type is discarded from analytics. These categories describe the setting of a Hang, not your identity, beliefs, diagnosis, financial state, or political affiliation. We do not infer religion or political affiliation from venue data.
- Advertising SDK data. The Google Mobile Ads SDK is present in the native app and contributes native privacy disclosures, but a hard production-code gate prevents ComeThru from loading or initializing it for this public release; remote configuration cannot bypass that gate. The checked-in native configuration uses Google's test app IDs and delays app measurement until a reviewed ad request. ComeThru must update this Policy and its store disclosures before a later release enables third-party ad requests. Google's published SDK disclosures state that, when used, the SDK can collect and share IP-derived general location, product interactions, diagnostics, and advertising, App Set, or other device/account identifiers for advertising, analytics, and fraud prevention. House promotions may appear without sending an ad request to Google.
C. Information from your device (with permission)
- Contacts. If you grant Contacts permission, the app reads phone numbers and email addresses (up to bounded limits) but does not upload contact names or complete address-book records. Normalized identifiers are sent to a ComeThru Cloud Function, compared using keyed digests, and not persisted by that matching function. The app keeps match-to-user results in a local device cache while signed in; matches currently do not expire, misses are retried after 30 days, and the cache is cleared at sign-out.
- Camera & microphone. Used only when you capture photos or videos in the app or scan a QR code. Captured media is not sent anywhere until you choose to upload it.
- Photo library. Used only when you pick existing photos or videos to upload.
- Calendar. Used only when you export a Hang to your device calendar; the calendar event is written locally to your device.
- Notifications. Required to deliver push notifications about Hangs, RSVPs, messages, friend requests, reminders, and similar events.
2. Information We Do Not Collect
We want to be clear about what we don't do:
- We do not integrate third-party attribution SDKs such as AppsFlyer, Adjust, Branch, or the Facebook SDK.
- We do not sell personal information for money. Advertising-related processing and opt-out rights are described in this Policy and the consent controls presented in the app.
- We do not collect biometric identifiers or biometric information.
- We do not retain dates of birth submitted by users who fail the age gate.
- We do not upload contact names or complete address-book records; normalized phone and email identifiers are transmitted for server-side matching as described above.
3. How We Use Your Information
We use the information described above to:
- Operate, maintain, and provide the Service — including authenticating users, creating and displaying Hangs, sending messages, posting to galleries, syncing friendships, fanning out push notifications, computing awards, and powering the rest of the app's features.
- Enforce eligibility — validating that you are at least 16 at signup, maintaining a 90-day blocklist of phone numbers and email addresses that have failed the age gate (to prevent immediate re-registration), and acting on reports of suspected underage users.
- Moderate content — using Google Cloud Vision safety findings as advisory triage for Gallery media, personal avatars, and business-profile images; reviewing automated and user-submitted reports; and allowing human moderators to remove or restrict content that violates our Terms. Automated findings do not automatically hide or remove media.
- Provide customer support — responding to your messages, bug reports, and reports of content or users.
- Improve the Service — analyzing aggregated usage and crash data to find and fix bugs, prioritize features, and improve reliability.
- Communicate with you — sending SMS verification codes during sign-in, push notifications about Service activity (subject to your notification preferences), and support, security, legal, or operational email where needed.
- For eligible adult users, select advertising inside ComeThru according to their personalization choice. Sensitive venue classes are excluded from behavioral targeting, and nightlife affinity requires age 21 or older.
- Operate business advertising and billing — authorizing business roles, maintaining promotion drafts and orders, creating and reusing a business-linked Stripe customer, requesting and later capturing or voiding a card authorization, providing invoices and Stripe-hosted payment-method management, handling refunds and disputes, and preventing billing fraud.
- Protect safety and prevent abuse — enforcing blocks, processing reports, detecting fraud, and protecting users and third parties.
- Comply with legal obligations — responding to lawful requests, enforcing our Terms, and complying with applicable child-safety and consumer-privacy law.
4. Legal Bases & Why We Process
For users in the United States, the legal bases on which we process your information include:
- Performance of the agreement between you and ComeThru — processing necessary to provide the Service you signed up for.
- Our legitimate interests — operating, securing, debugging, and improving the Service; preventing fraud and abuse; defending legal claims.
- Your consent — for location, contacts, camera, microphone, photo library, calendar, push notifications, personalized in-app ads, and off-platform audience matching if that dormant feature is ever activated, revocable through the applicable in-app control or device setting.
- Compliance with legal obligations — including applicable child-safety and consumer-privacy laws.
5. How We Share Your Information
We share your information with the following categories of recipients, for the purposes described:
| Recipient | Data shared | Purpose |
|---|---|---|
Firebase / Google Cloud (Authentication, Firestore database comethru, Cloud Storage, Cloud Functions, Hosting) |
Account data, profile, all content (Hangs, messages, gallery, comments), notifications, push tokens, pseudonymous analytics events, and aggregate counters | Core infrastructure for the Service |
| Firebase Auth SMS infrastructure (Google) | Phone number | Delivering account verification SMS |
| Expo services, including Expo Push Notification Service | Expo push token, notification title/body, and navigation data such as notification type and related Hang identifier or title | Delivering push notifications to your device |
| Google Maps SDK & Google Places API (New) | Map requests, location search text, exact origin/bias coordinates, session token, place ID, selected address/coordinates, and place-photo request | Google map rendering, place search, ranking, details, and photos |
| Mapbox | A Hang coordinate rounded to two decimal places, map style, and request metadata | Returning a static map image when an authorized user selects a map in a Recap |
| Google Cloud Vision API | Gallery image and video-thumbnail bytes, personal-avatar image bytes, and business-profile image bytes | Advisory SafeSearch signals for adult content, violence, and racy material to support human moderation |
| Giphy (Giphy, Inc.) | GIF search query and request metadata from ComeThru's authenticated server proxy; selected GIF URL and dimensions remain in ComeThru content | Powering GIF search and selection in chat and comments |
| SendGrid (Twilio Inc.) | Contents of bug reports and content reports; admin recipient email addresses | Delivering transactional email to ComeThru admins for support and moderation |
| Sentry (Functional Software, Inc.) | Error stacks, scrubbed breadcrumbs, performance traces, signed-in user UID, and display name (production only) | Crash and error monitoring |
| Google Mobile Ads (SDK linked; production loading and initialization disabled for this release) | No ComeThru ad request in this release; the linked native SDK remains subject to the exact archive/runtime audit. A later enabled release could process IP-derived general location, product interactions, diagnostics, advertising/App Set or other device/account identifiers, consent signals, and ad interactions. | SDK presence and future conditional advertising, analytics, and fraud prevention. House promotions do not make a Google ad request. |
| Apple App Store / Google Play | Store account, payment, transaction, and subscription information | Processing native in-app purchases, taxes, cancellations, and refunds |
| RevenueCat | ComeThru user ID, store product and transaction identifiers, receipt or purchase token, subscription status, and limited device/app information | Receipt validation, fraud prevention, Premium entitlement delivery, subscription support, and subscription analytics |
| Stripe | Business name and ComeThru business ID; promotion line items, amount and draft/order references; billing and payment-method details entered directly on Stripe-hosted pages; Stripe customer, Checkout, PaymentIntent, charge, invoice, refund and dispute information | Creating and reusing a business-linked billing customer, securely authorizing and later capturing or voiding promotion payments, managing payment methods, producing invoices and receipts, processing refunds and disputes, and preventing fraud |
| Other users and people who receive public links or exported Recaps | Profile information inside the signed-in Service; personal or business Hang information; invitations and RSVP; chat, GIFs, Gallery and comments; friend-limited live location while enabled; limited public Hang share-page data; consent-eligible personal Recap media, privacy-limited Hang details, and frozen award winner name/profile photo. Generic public profile links do not display profile data. | Operating social, sharing, business, and public-link features. Copies exported outside ComeThru are controlled by the recipient, not ComeThru. |
| Law enforcement and other authorities | Account or content information | Responding to valid legal process, protecting rights and safety, complying with applicable law |
| Successors in interest | All categories of information | Merger, acquisition, reorganization, sale of assets, or similar transaction (with notice to you) |
Advertiser analytics and targeting. ComeThru's first-party ad-event pipeline can record pseudonymous impressions and clicks, but the app does not currently expose an advertiser reporting product or activate off-platform audience transport. Any future advertiser reporting must use aggregate cohorts and comply with the safeguards described in the current Service. Sponsored placements are restricted to users established as age 18 or older; alcohol-related delivery is not activated. Faith/community, health/wellness, education, civic/services, residential, and unknown venue history are not used to build behavioral advertising affinity. Nightlife affinity is restricted to eligible users age 21 or older for a first-party ComeThru campaign and is not exported as an advertiser-curated audience.
We do not sell your personal information. We do not currently activate off-platform audience matching or a provider transport that sends phone-derived match keys to an advertising platform. Code and default-off controls for that possible feature are present but dormant. We will update this Policy, store disclosures, and required privacy choices before activating such a transfer. Hashing a phone number for matching would not make it anonymous.
6. Visibility, Sharing & Public Links
Personal Hangs. In-app access is invitation-based. Server-side rules limit a personal Hang to:
- The Hang's creator,
- Users who have selected ComeThru,
- Users the creator has explicitly invited,
- Members of friend groups the creator has invited, and
- Friends of the creator, only if the creator has set visibility to "all" (their friends).
Hang content. Chat, Gallery, and comments are visible to the authorized Hang circle. Live-location pins have a narrower rule: only the sharing user and eligible friends participating in the Hang can read the pin during the limited time window.
Businesses. Active business profiles can be searched by signed-in users. Surfaced business Hangs are public listings inside the signed-in Service and may be shown to followers and business-profile visitors. When a signed-in user blocks a business, ComeThru prevents direct access/follow/join actions and filters that business from normal discovery for that account.
Public profile links. A comethruapp.com/user/... URL can be opened without a ComeThru account, but it now returns only a generic ComeThru deep-link bridge and does not fetch or display the user's name, username, avatar, or other profile data. The Firebase UID remains part of the URL itself.
Hang share pages. Where a valid opaque share token has been created, a public comethruapp.com/h/... page can show the Hang title, host name/avatar, date/time, and general area. It does not show map imagery, coordinates, or the exact venue address. Anyone who receives the bearer link can view it until it is revoked.
Recaps. Hang access alone is not permission to publish another member's personal media. A current owner-controlled choice allows future Recaps to include personal Gallery photos/videos that member uploaded and a personal Hang cover they own either across eligible Hangs or only for a separately approved Hang. Missing, denied, Off, invalid, or revoked choices remain excluded. Choosing Off invalidates earlier Hang grants; returning to Ask Me Per Hang does not restore them without a new Include choice. A server-generated manifest enforces the current choice before export; business-attributed media and business covers are excluded. Aggregate attendance and frozen award facts—including the winner's name and profile photo—can appear, but other attendees and a different personal host remain anonymous. The media-sharing preference does not control award identity. The operating-system share sheet can send the finished image outside ComeThru. Changing a choice controls future media exports but cannot recall a copy already exported or held by a recipient.
7. Children & Age Policy
The Service is intended for users 16 years of age or older. We do not knowingly collect personal information from anyone under 16. We enforce the age requirement through a server-side validation Cloud Function that runs at signup; users who do not qualify are not allowed to create an account, and their submitted date of birth is not retained. Phone numbers and email addresses associated with a rejected signup are added to a blocklist with a 90-day time-to-live to prevent immediate re-registration. Any user can report another user they suspect is under 16, and we may investigate and take action.
Users aged 16–17 may use the core Service but are not eligible to receive sponsored ComeThru or Google Mobile Ads placements. Advertising eligibility fails closed if the stored date of birth is missing or invalid.
If you believe we have collected information from a person under 16, please use the in-app report control or email hello@comethruapp.com. We may investigate, restrict the account, remove content, preserve evidence, and make legally required reports. ComeThru prohibits child sexual abuse and exploitation, grooming, sextortion, trafficking for sexual exploitation, and child sexual abuse material. We remove confirmed prohibited material when we obtain actual knowledge and report it where required by law. See our Child Safety Standards.
8. Data Retention & Deletion
While your account is active
- Free-tier Hang cleanup. A Hang reaches its expiration point one week after its effective end. Free creator and confirmed ComeThru participants may receive reminders 24 hours and 2 hours before that point. At the retention decision, if neither the Hang creator nor any confirmed ComeThru participant has Premium, the scheduled cleanup removes chat, Gallery documents and comments, live-location records, related notifications/reminders/coordination records, and unprotected Gallery storage objects. Basic Hang metadata and final awards remain. If an eligible creator or confirmed participant has Premium at that decision, the shared Hang content is preserved; a later cancellation does not retroactively delete it. Invited-only or chat-only viewers do not preserve it. Deleted content cannot be restored by buying Premium later.
- Contest and Hall of Fame media. An exact media object submitted with the separate contest/promotion consent can be retained for that entry even if ordinary Hang cleanup otherwise removes the Gallery copy.
- Live location. Turning live sharing off deletes the current pin. Security rules end access after the live window even if a stale record remains; ordinary Hang cleanup later removes the collection for an eligible free-tier Hang.
- Public links. Public profile URLs return a generic deep-link bridge without profile data. Opaque Hang share tokens have no automatic expiration in the current implementation and remain resolvable until revoked or the backing data is unavailable.
- Contact matches. The matching service does not retain submitted address-book identifiers. The signed-in app's local device cache retains successful identifier-to-user matches without a fixed expiration, retries misses after 30 days, and clears the cache at sign-out.
- Bug and safety reports. Signed-in bug reports are deleted in the account-deletion cascade. Anonymous bug reports cannot be associated with an account for automatic deletion. Safety reports are retained for moderation, evidence, abuse prevention, and legal purposes and are anonymized when an associated account is deleted.
- Age-gate blocklist entries are retained for 90 days; no date of birth is stored.
- Analytics events. Pseudonymous raw events are retained for up to 90 days, daily uniqueness markers for up to 32 days, and non-identifying daily aggregate counters for up to 400 days. Firestore time-to-live deletion is asynchronous, so an expired record can remain briefly while deletion is processed.
- Advertising choices. Your current choices remain with your active account. Pseudonymous consent-audit entries expire after up to 400 days and may remain briefly while asynchronous deletion is processed. Provider queue records do not store your phone number or provider match hash.
- Sentry error and performance data are retained under ComeThru's configured Sentry project retention, currently up to 90 days.
- Purchase and subscription records may be retained by Apple, Google, RevenueCat, and ComeThru for as long as needed to provide subscription access, handle disputes and refunds, prevent fraud, satisfy accounting and legal obligations, and maintain an audit trail.
- Business advertising and billing records may be retained by ComeThru and Stripe for promotion delivery, payment-method management, invoicing, accounting, fraud prevention, authorizations, refunds, disputes, and legal or audit obligations. Promotion drafts have a 30-day cleanup timestamp, but that cleanup is not the authority for active or historical orders; Stripe's separate retention is governed by its terms and applicable law.
When you delete your account
You can delete your account at any time from the in-app Profile screen.
- You are signed out immediately. Your push token is cleared and your refresh tokens are revoked.
- Your account enters a 30-day grace period. You can reinstate the account during that period by signing back in and confirming.
- After the grace period, a daily process handles up to a bounded number of accounts, so final processing can occur after the exact 30-day point. It then performs a permanent deletion and anonymization cascade:
- Your Firebase Authentication record and your user document are deleted.
- Your profile photo is deleted from Cloud Storage.
- Your friendships, business follows and blocks, friend/group/Hang memberships, reactions, reminders, referral claims, advertising choices and queues, and other private relationships are deleted or disconnected.
- Notifications you received are deleted.
- Personal Hangs you created, chat messages you sent, comments, awards, safety reports, and notifications you triggered for others are anonymized — personal identifying fields are replaced with "Former member" or a deleted-user sentinel.
- Ordinary personal Gallery files, their thumbnails, and personal Hang covers you uploaded are deleted from Cloud Storage. Their Gallery records are anonymized and hidden. An exact media object protected by a separate promotion/Hall of Fame submission can remain, as can business-attributed media and records retained for safety, legal, dispute, audit, or backup purposes.
- Your business memberships are removed. If another business owner remains, ownership and retained management records transfer to a remaining owner. If you are the only owner, the business is closed, its public identity fields and listings are cleared or disabled, its memberships are deleted, and its business-profile images are removed.
- Business-attributed promotion, order, invoice, refund, dispute, and audit records may remain as needed for delivery, accounting, fraud prevention, disputes, and legal obligations. Those records can retain the initiating account or deleted-user sentinel as an audit identifier. If a business closes, ComeThru deletes its private Firebase billing record, but Stripe may separately retain its customer and transaction records under Stripe's terms and applicable law.
- Your username, phone number, and email are released for reuse.
- Your pseudonymous raw analytics events, daily uniqueness markers, legacy user-level ad events, advertising-consent audit, and audience queue or membership records are deleted. Non-identifying aggregate counters remain.
- A deletion-audit record remains with a SHA-256 hash of the former Firebase UID, completion time, and deletion/anonymization counts. It does not contain your phone, email, username, or content.
The automated account-deletion cascade removes ordinary personal Gallery files and personal Hang covers after the grace period; a separate full-media request is not required for those objects. You may email hello@comethruapp.com to identify other media you believe remains. ComeThru cannot remove Recap exports or copies held by other users, and promotion/Hall of Fame, business, safety, legal, dispute, audit, or backup exceptions can apply.
9. Security
We take security seriously and use a range of safeguards, including:
- Encryption in transit (TLS) for all client–server traffic.
- Encryption at rest for data stored in Firebase / Google Cloud.
- Authentication via Firebase Authentication, including SMS verification.
- Firestore security rules that enforce per-user access controls, Hang visibility, and admin role checks via Firebase Auth custom claims.
- Cloud Storage rules that enforce file size and content-type limits.
- Sensitive operations (such as profile-cascade updates, push fan-outs, account deletion, and content moderation) running server-side as privileged Cloud Functions rather than from client devices.
- Centralized scrubbing of phone numbers, email addresses, verification IDs, push tokens, authorization values, and share-link bearer tokens from diagnostic logs and Sentry context before transmission.
No system is 100% secure. We encourage you to protect your device with a passcode or biometric lock and to notify us promptly at hello@comethruapp.com if you believe your account has been compromised.
10. Your Choices & Rights
- Location. Revoke the location permission in your device settings at any time. Live location sharing inside a Hang is opt-in and can be turned off at any time.
- Notifications. Manage push notification categories in the in-app Preferences screen (including a master "Pause All" toggle and per-category toggles for invites, RSVPs, reminders, friend requests, chat messages, and gallery uploads). Disable notifications system-wide in your device settings.
- Recap media sharing. In Preferences, choose All Hangs, Ask Me Per Hang, or Off for personal Gallery photos/videos you upload and a personal Hang cover you own. Off suppresses contextual invitations and makes prior Hang grants ineligible while Off remains selected. A No in context dismisses only that Hang; Don't Show Again selects Off. These choices apply to future media exports, do not control frozen award identity, and cannot recall an image already exported or held by a recipient.
- Contacts. Revoke Contacts permission in device settings. Contact names and complete address-book records remain on-device; normalized identifiers are transmitted transiently and not stored by the matching function. Sign out to clear ComeThru's local contact-match cache.
- Profile. Edit your display name, bio, avatar, banner, vibe, and rep in the app.
- Block other users or businesses. Blocking is available where supported, with the limits described in the Terms and Section 6.
- Report. Report content or users using the in-app reporting feature.
- Delete your account. Use the in-app account-deletion flow (see Section 8), or follow the web instructions at comethruapp.com/delete-account.
- Access & portability. Request a copy of the personal information we hold about you by emailing hello@comethruapp.com. We will respond within the time period required by law (45 days under CCPA). Automated data export is not yet available; we provide exports manually upon request.
- Correction. Most profile fields are editable in the app. Your date of birth, once submitted, cannot be self-edited; to request a correction, email hello@comethruapp.com.
11. California Privacy Rights (CCPA / CPRA)
This Section applies to California residents and supplements the rest of this Privacy Policy.
Categories of personal information we collect
In the last 12 months, we have collected the following CCPA/CPRA categories of personal information:
- Identifiers — name, username, phone number, email address, user ID, device identifiers.
- Personal records (Cal. Civ. Code § 1798.80(e)) — phone number, email.
- Protected classification characteristics — age (derived from your date of birth at signup to confirm eligibility); the underlying date of birth itself.
- Commercial information — subscription product, transaction, purchase, restore, and entitlement status; business promotion drafts, orders, card-authorization/capture status, invoice summaries, refunds, and disputes.
- Internet or other electronic network activity — analytics events, crash reports, performance traces.
- Geolocation data — precise or approximate foreground location, Hang address/coordinates, opt-in live location, and rounded map coordinates.
- Audio, electronic, visual — photos and videos you capture or upload.
- Inferences — friend-suggestion outputs, "people you may know" matches.
Sources, purposes, and recipients
Sources, purposes, and recipients of each category are described in Sections 1, 3, and 5 of this Privacy Policy.
Sensitive personal information
We collect precise geolocation only when you grant permission, and only as described in Section 1. We use sensitive personal information only for the purposes permitted by Cal. Civ. Code § 1798.121(a) and do not use or disclose it to infer characteristics about you.
Sale and sharing
We do not sell personal information. The current public-release configuration does not activate off-platform audience matching, and production code prevents the third-party ad SDK from being loaded or initialized by ComeThru. Before activating a use that constitutes cross-context behavioral advertising or “sharing” under California law, we will update this Policy and provide required notices and opt-out methods.
Your rights
- Right to know what personal information we have collected, used, disclosed, sold, or shared.
- Right to delete personal information we hold about you, subject to permitted exceptions.
- Right to correct inaccurate personal information.
- Right to portability — receive your personal information in a portable format.
- Right to limit use of sensitive personal information (we already limit use of sensitive PI as described above).
- Right to non-discrimination for exercising your CCPA/CPRA rights.
How to exercise your rights
Submit a request by emailing hello@comethruapp.com with the subject line "California Privacy Request." We will verify your identity by reference to information you have already provided to us (such as your registered phone number or email). We will respond within 45 days, with the possibility of one 45-day extension where reasonably necessary, as permitted by law. You may use an authorized agent to submit a request by providing the agent with signed written authorization; we may also require the agent to verify their own identity.
Notice of financial incentive
ComeThru may offer referral or promotion rewards for qualifying actions under terms presented with the program. We do not offer those rewards in exchange for selling personal information. If a program is treated as a financial incentive under applicable law, we will provide any additional notice required for that program.
12. International Users
The Service and its subscription offering are intended for United States residents and are hosted in the United States through Google Cloud / Firebase and other providers. If you access the Service from elsewhere, you do so on your own initiative and are responsible for local law. We will update this Policy before intentionally expanding availability.
13. Third-Party Links & Services
The Service may link to, embed, or otherwise interact with third-party content and services, including Google maps and Places content, Mapbox static maps, Giphy GIFs, Apple and Google store interfaces, Stripe-hosted Checkout and billing management, and operating-system share sheets. Those third parties have their own terms and privacy practices. Once you direct information or an exported Recap to a third party, its handling is also governed by that third party.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service, by email, or by other reasonable means at least seven (7) days before the changes take effect, except where a shorter period is required by law or by an urgent security or compliance need. The "Last updated" date at the top of this Policy reflects the most recent revision. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.
15. Contact
Questions or requests about this Privacy Policy? Contact us at:
ComeThru LLC
Email: hello@comethruapp.com
California, United States