Privacy Policy
CR4VE Privacy Policy
Effective date: 2026-01-14
This Privacy Policy explains how CR4VE collects, uses, and shares personal data when you use the Service. CR4VE is operated by It Junior Software Ltd, Ireland.
Contact: legal@mail.cr4ve.app
Phone: +353 89 952 7998
Address: 34a Patrician Villas, Stillorgan, A94VW74 - Ireland
1. Data controller
CR4VE is the data controller for the personal data described in this policy.
2. Personal data we collect
We collect data you provide and data generated by your use of the Service:
- Account data: Auth0 subject identifier, handle, display name
- Profile data: avatar, bio, preferences, tags, and other profile fields you choose to share
- Content: messages and media you send
- Location: your approximate or precise location (to show nearby users and when you choose to share a location in chat)
- Sensitive profile data: optional details you choose to share such as gender, tribes, looking for, and health information (for example, HIV status)
- Device and usage data: basic device identifiers, app version, and logs for security and support
- Safety data: reports, blocks, and moderation decisions
- AI moderation data: limited moderation outputs for photo safety checks (for example, model decision, confidence signals, and moderation audit metadata)
- Billing data: app store purchase status, product identifiers, and receipt metadata (we do not receive your full payment card details)
- Local device storage: cached chats and authentication tokens stored on your device
We do not use analytics providers at this time.
3. How we use your data
We use your data to:
- Provide core app features (profiles, chat, nearby grid)
- Show nearby users and online presence
- Moderate content and handle reports
- Send service-related emails (for example, account deletion and safety/report confirmations)
- Perform AI-assisted photo moderation for avatars and public album assets, with human review fallback
- Maintain security and prevent abuse
- Support you when you contact us
You can control optional email categories in the app settings and through unsubscribe links included in email messages. Some service-critical emails (for example, account deletion lifecycle notices) may still be sent when needed to operate the service and meet legal obligations.
4. Legal bases (GDPR)
We process personal data under the following legal bases:
- Contract: to deliver the Service you request
- Legitimate interests: to keep the Service safe and reliable
- Consent: for optional features like location sharing (where required)
- Explicit consent: for special category data (for example, health information or sexual orientation)
- Legal obligations: to comply with applicable law
You can withdraw consent at any time in the app or by contacting us. Withdrawing consent may limit certain features (for example, showing sensitive profile details) and may clear sensitive fields you have provided.
5. Sharing and processors
We share data with service providers who process data on our behalf:
- Auth0 (authentication)
- Cloudflare R2 (media storage)
- Expo (mobile app services and notifications)
- Amazon Web Services SES (transactional email delivery)
- Hetzner (hosting infrastructure)
- OpenAI (automated moderation processing for avatar and public album image safety checks)
Payment processing is handled by the Apple App Store (iOS) and Google Play (Android), each acting as an independent controller for your payment data. We receive purchase status and store receipt/token metadata needed to enable subscriptions.
We require processors to protect your data and use it only to provide services to CR4VE.
We do not sell your personal data.
6. Profile sharing links
If you enable profile sharing, we generate short-lived links (tokens) that let others open your profile inside the app. We store the token, who created it, its expiry, and basic access metrics (for example, access count and last accessed time) to help you control sharing and to detect abuse. We may show an in-app alert after a link is accessed multiple times (currently 3+). These records are kept only as long as needed to operate the feature, prevent misuse, and meet legal obligations. You can disable profile sharing at any time to revoke active links.
7. International transfers
Some processors may process data outside the EEA (for example, infrastructure or support providers). This may include OpenAI for moderation processing. Where required, we use appropriate safeguards such as Standard Contractual Clauses.
8. Cookies
CR4VE does not use advertising cookies at this time. We may use strictly necessary cookies (for example, to keep you signed in) if and when we introduce a web portal. If we add optional cookies or analytics in the future, we will update this policy and request consent where required.
9. Retention
We retain data while you maintain an account or as needed for safety, security, and legal obligations. You can request deletion of your account in-app or through the web deletion resource at `https://cr4ve.app/account-deletion`, which will remove your profile and associated data unless retention is required by law or for safety investigations.
Typical retention (may vary by legal need):
- Account/profile data: kept until you delete your account.
- Messages and media: kept until deleted by you or both chat participants, or until account deletion, unless needed for safety/legal reasons. If you clear a chat, it is removed from your view; messages are permanently deleted only once both chat participants have cleared them.
- One-time media: media marked as one-time is deleted shortly after it is viewed; minimal metadata may remain for safety and fraud prevention.
- Blocking: when you block someone, chats and related interactions between you and that user are deleted from our systems, except where we must retain data for safety or legal reasons.
- Location history: kept only as long as needed for nearby and safety features, and not kept longer than necessary for service operation.
- Security and audit logs: retained for a limited period for security and abuse prevention.
- Reports and moderation records: retained for at least 28 days and for the duration of investigations and a reasonable period afterward. We periodically purge reports older than 28 days unless they are needed for safety or legal investigations.
- Reports may include message snapshots from the reported chat (for example, the last 50 messages) and can be retained even if the chat is later deleted or a user is blocked.
- AI moderation logs/metadata for avatars and public albums: retained only as needed for moderation quality, abuse prevention, legal compliance, and to support review/appeal handling.
- Local device storage: cached data remains on your device until you log out, clear app storage, or uninstall the app.
10. Your rights (EU/EEA)
You have rights to:
- Access your personal data
- Correct inaccurate data
- Delete data (subject to legal/safety limits)
- Restrict or object to processing
- Data portability
- Withdraw consent where processing is based on consent
To exercise your rights, contact legal@mail.cr4ve.app or +353 89 952 7998.
We respond to verified requests within 30 days. We may ask for additional information to confirm your identity or clarify your request. Data export responses are typically provided in a machine-readable format (such as JSON).
You also have the right to lodge a complaint with the Irish Data Protection Commission (DPC): https://www.dataprotection.ie/
11. Automated decision-making
We use limited automated checks for content moderation of avatars and public album media. These checks are used to support platform safety and do not, by themselves, produce legal or similarly significant effects under GDPR. Content that does not clearly pass automated checks is routed for human moderator review. You can challenge moderation outcomes by contacting us at support@mail.cr4ve.app or +353 89 952 7998.
12. Security
We use technical and organizational measures to protect your data, including access controls and secure storage. No system is perfectly secure; please use strong credentials and keep your device secure.
If you believe your account or data has been compromised, contact us at support@mail.cr4ve.app or +353 89 952 7998.
13. Children's privacy
CR4VE is not intended for anyone under 18. We do not knowingly collect data from minors.
14. Changes to this policy
We may update this policy from time to time. Material changes will be communicated within the Service or by email.
15. Contact
Questions or requests: legal@mail.cr4ve.app or +353 89 952 7998. We do not have a designated Data Protection Officer; use this contact for all privacy inquiries.