crush-policies

Privacy Policy

Last updated: 2026-02-26

Crush (“we”, “us”, “our”) is a campus connection app that uses SMS login, .edu email verification, daily Crush Drop windows (three scheduled reveal minutes per day hashed by time zone), and in-app chat on Firebase + Cloud Functions. There is no swipe deck in the current release. This Privacy Policy explains what data we collect, how we use and share it, and the choices and rights available to you.

Information We Collect

We collect the following categories of data when you use the app:

  1. Account & Identity Data: Display name, phone number, .edu email, school and state, graduation year, gender + “looking for” by goal bucket, age, Greek-life affiliation, majors, clubs/athletics, connection goals, primary connection goal, relationship preferences (intent, exclusivity, kids, faith importance), roommate preferences (cleanliness, sleep schedule, guests), study preferences (style, time, frequency), gym buddy time and experience preferences, religion, pet preference/has pets, smoking/drinking/going-out style, deal breakers, theme preference, Terms of Service and Privacy Policy acceptance timestamps, and Firebase Auth identifiers.
  2. Verification Data: Phone verification state from Firebase Auth plus .edu email OTP attempts (hashed with a ~10-minute expiry, 1-minute resend cooldown, and school/time zone mapping) stored in the edu_verification collection.
  3. Profile Content (UGC): Bio and profile photos you upload to Firebase Storage, including any optional Greek organization details or interests you add.
  4. Discovery, Location & Presence Data: Scope selection (campus/state/nationwide) and radius sliders, Crush Drop opt-in, time zone + school time zone, GPS coordinates (with source + timestamp) or campus fallback, Crush Drop window metadata (dateKey, windowInstanceId, status, scheduled minute, expiry), per-day pairing flags (crushDropPairedDateKey, crushDropPairedIds), and presence (online, lastActiveAt). Location and presence live on your profile for pairing and chat experience; they are not included in public profile records or shared outside match-only chat presence.
  5. Engagement & Messaging Data: Crush Drop activity feed entries, match records (participants, participantInfo display name/school/photo URL, participantInterest, chatUnlocked, pairing intent/connection goal, matchWindow labels/timestamps, and internal ML linkage IDs), pending spotlight queues (pendingSpotlightMatchIds), match tombstones (participants + archivedAt) used to prevent repeat matches, chat messages (including image or GIF attachments, attachment metadata like storage paths or Tenor URLs, edit/delete markers, typing indicators, and match-only chat presence heartbeats), drop notification queue entries (ready/reminder/expire), drop pairing queue entries that batch Crush Drop pairing, daily polls (prompt + options by date), poll votes (option selected, campus ID, time zone, timestamp) and campus-only aggregate poll results, pairing event logs (drop impressions/responses/nonresponse/outcomes and sampled candidate-evaluation events) stored in mlEvents with pairing intent + score breakdowns, push tokens + last-seen metadata, per-match unread counters and badge counts, messaging rate-limit counters, block lists, archived/hidden match IDs used to hide threads, and account deletion audit logs.
  6. Derived Pairing Features: Precomputed Crush Drop shortlists (candidate IDs) stored briefly to speed pairing, plus numeric embeddings derived from profile photos and pairing outcomes that help rank candidates and train pairing models.
  7. Safety & Support Data: Reports, support requests, SafeSearch moderation results and actions for photos, and removal logs for deleted photos.
  8. Device & Usage Data: App version, device/OS type, Firebase Analytics event identifiers, and basic diagnostics used to monitor delivery of notifications and drops. No marketing trackers are present.

We do not knowingly collect information from individuals under 18; using the app requires a qualifying .edu address and college enrollment.

How We Use Your Information

How We Share Information

We do not sell personal data. We share it only with:

All processors are bound by confidentiality and data protection agreements. We remain responsible for their handling of your data.

Retention

Your Choices & Rights

International Transfers

Data is hosted in Firebase’s U.S. regions. If you access the app from outside the United States, you consent to transferring your data to the U.S., where privacy laws may differ.

Security

We rely on Firebase’s encryption at rest/in transit, hashed verification codes, Firestore security rules that require authentication, match-only presence signals, signed photo URLs for profile cards, cached avatar photo URLs for chat lists, SafeSearch photo moderation, and server-side messaging with rate limits. Admin/audit logging for sensitive reads is planned.

Children

Crush is for college students 18+ and requires .edu verification. We do not knowingly collect data from minors; if we learn we have, we will delete it promptly.

Changes

We will update this policy when we add new fields, processors, or retention schedules. The “Last updated” date reflects the latest change. Significant updates will be announced in-app or via email.

Contact

Email hello@crushso.com for questions, data requests, or privacy complaints. If you are in the EU/UK, you may also contact your local supervisory authority.