hankerchf

Privacy Policy

Effective 2026-05-25. Operator: the hankerchf project. Service available in the United States.

Contents

1. Plain-language summary

hankerchf is a mobile dating app for adults in the United States. To work, it needs to know who you are, what kind of person you are looking for, and roughly where you are. Some of that information — sexual orientation, health information, ethnicity, precise location — is classified as Sensitive Personal Information under California law (CCPA/CPRA) and most other US state privacy laws.

The short version of this policy:

2. What we collect and why

2.1 Account data (always collected)

FieldWhy
Email addressSign-in, account recovery, transactional email (verify your address, reset password).
Password (stored as a salted argon2id hash, never in clear)Sign-in.
Sign-in tokens, device push tokensKeeping you signed in; delivering push notifications.
Approximate location (offset and grid-rounded — see 2.3)Showing you nearby profiles and showing your bucketed distance to other users.

2.2 Profile data you choose to fill in

Every profile field below is optional. You decide what to fill in and which sections are visible to other users; visibility can be toggled per section in Edit Profile.

SectionFields
Basics (always visible if a profile exists)Display name, date of birth (we show age, not DOB), short bio, profile photos.
StatsHeight, weight, body type, relationship status, ethnicity.
IdentityPronouns, position, gender identity, sexual orientation, what you're looking for.
Tribes & FlagsSub-community tags and profile flags.
HealthHIV status, last-tested date, vaccinations.

2.3 Location

When you grant location permission, your phone reports its GPS coordinates to the app. Those raw coordinates never reach our servers. Before any network call, the app:

  1. Picks a stable random direction and a magnitude based on local population density (~400 m in dense metros, ~1.6–3.2 km in suburban areas, ~8 km in rural areas) and shifts your position by that offset.
  2. Rounds the result to the nearest 50 m on a fixed grid.

The server only ever sees the offset, grid-rounded position. The random offset is anchored per-user and persists as long as you stay within five miles of your reference point, so an attacker who watches your stored position over time cannot triangulate your real one by averaging.

If you decline location permission, you can instead provide a postal code and the app uses that postal code's centroid as your location — accurate to city or neighbourhood granularity, never to a street address.

2.4 Photos

You upload photos through the app. They are stored on a private object store hosted in the United States and served back to other app users through authenticated, time-limited URLs. New uploads are held in a pending moderation state and are not visible to other users until they pass our moderation review. Photos you mark as "back-pocket" are visible only to users you have explicitly granted access to in a conversation.

2.5 Messages

Messages you send are stored on our servers so we can deliver them to the recipient and to your other devices. Both you and the recipient can delete messages from your own view at any time. If you have "vanish on read" enabled, the message body is permanently nulled on the server shortly after the recipient reads it. Messages flagged as harassment or abuse may be retained beyond the normal window solely for safety-team review and law-enforcement requests (see section 7).

2.6 Technical data

Our servers automatically log:

We do not embed third-party analytics SDKs (no Google Analytics, no Amplitude, no Mixpanel, no Sift, no Braze, no Firebase Crashlytics with PII payloads) in the app.

3. Sensitive personal information

The California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), defines a category of "Sensitive Personal Information" (SPI) that includes precise geolocation, racial or ethnic origin, the contents of personal communications, and information concerning sex life or sexual orientation, among other categories. Most other US state privacy laws (VCDPA in Virginia, CPA in Colorado, CTDPA in Connecticut, UCPA in Utah, TDPSA in Texas, OCPA in Oregon, and the parallel laws in approximately a dozen other states) have substantially similar "sensitive data" categories that overlap heavily with this list.

The following fields we collect are SPI under one or more of those laws:

For each of these categories we obtain your affirmative, separate consent before collecting. You can revoke any individual consent at any time from Settings → Your Consents, and revocation is processed immediately. We do not use any SPI for purposes beyond delivering the service to you and to other users you have chosen to connect with, and we do not infer additional characteristics about you from SPI (no orientation-prediction, no health-status prediction).

Beyond consent, the following hard restrictions are enforced in code:

4. Sale, sharing, and AI training (we do none of these)

Under California, Virginia, Colorado, Connecticut, and most other US state privacy laws, users have the right to opt out of (a) the "sale" of personal information, (b) the "sharing" of personal information for cross-context behavioural advertising, and (c) profiling that produces legal or similarly significant effects.

We do not engage in any of these activities. There is nothing to opt out of, because:

If we ever introduce any of these uses in the future, we will (i) update this Privacy Policy at least 30 days before doing so, (ii) require a fresh affirmative opt-in for affected processing, and (iii) provide a Global Privacy Control (GPC) signal-honouring opt-out where required by law.

5. Service providers we share data with

We engage a small number of US-based service providers to operate the service. Each one only receives the data they need to do their job, and is contractually restricted from using your data for their own purposes.

ProviderWhat they doData they receive
Our US cloud-infrastructure provider (currently being finalized; will be disclosed before public launch)Application servers and database hostingAll app data (they are our hosting layer; encrypted at rest where applicable).
Cloudflare, Inc. (San Francisco, CA)CDN, DNS, TLS termination for our domain, object storage (R2) for photosConnection metadata (IP, user agent), photo blobs, in-transit request bodies.
Amazon Web Services, Inc. (Seattle, WA)Infrastructure-state and operational-data backupsBackup blobs (encrypted at rest).
Zoho Corporation Pvt. Ltd. (ZeptoMail, US data center)Transactional email delivery (verification, password reset)Recipient email address, message subject, message body.
Google LLC (Firebase Cloud Messaging)Android push-notification deliveryDevice push token, push payload (we keep push payloads opaque — typically just "New message").
Apple Inc. (APNs)iOS push-notification delivery (when iOS app ships)Same as above for iOS.
Hive Inc. (image moderation, San Francisco, CA)Automated review of uploaded photos for prohibited contentImage bytes only, no associated user information.

We do not share your data with any advertising network or data broker. We do not sell your data. We do not engage in advertising as a revenue model.

6. Cross-border data handling

hankerchf is operated from the United States and hosts all production data on infrastructure physically located in the United States. Some of our service providers (listed above) may process limited data outside the United States; where they do, we rely on the protections described in this Privacy Policy and on our contracts with those providers.

7. How long we keep your data

DataRetention
Account, profile, sensitive-profile, photos, messages, locationFor as long as your account is active. Deleted within 7 days of you deleting your account.
Audit-trail entries (consent grants and revocations, deletion requests)Retained for 6 years to satisfy applicable business-records and consumer-protection compliance obligations. These records contain account IDs and timestamps only — no profile content.
IP-address logs30 days.
Vanish-on-read messagesBody permanently nulled within seconds of being read by the recipient; metadata row retained for the conversation's lifetime.
Messages reported as abuseUp to 12 months beyond normal retention, accessible to the safety team only.
Device push tokensPurged automatically if unused for 90 days.
Inactive accountsAuto-deleted after 24 months of no sign-in. You receive an email warning at 22 months.

8. Your rights

Depending on where you live, you have some or all of the following rights regarding your personal information. These rights apply throughout the United States to the extent provided by state law, and many of them are honoured uniformly to all users regardless of state:

To exercise any of these rights, write to [email protected]. We respond within 45 days (Cal. Civ. Code § 1798.130(a)(2)), with one extendable 45-day extension where necessary. Verification of identity may be required and will use the minimum data necessary for the request.

9. State-specific notices

The following sections apply if you are a resident of the named state. The substantive protections we provide above already meet or exceed these state-law requirements; the notices here exist because the relevant statutes require us to call them out explicitly.

9.1 California (CCPA/CPRA)

If you are a California resident: we collect the categories of personal information identified in section 2 above, including the categories of Sensitive Personal Information identified in section 3. We collect those categories from you directly (when you fill out your profile) and from your device (location, technical data). We do not sell or share your personal information for cross-context behavioural advertising. We retain each category for the periods set out in section 7. You can submit a request to know, delete, correct, or limit the use of SPI by emailing [email protected] or by using the in-app Settings controls. You may designate an authorized agent to submit requests on your behalf. To complain about how we handle your information, you can contact the California Privacy Protection Agency at cppa.ca.gov or the California Attorney General at oag.ca.gov/privacy.

9.2 Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other comprehensive-privacy states

If you are a resident of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), or any other state with a comprehensive consumer privacy law, you have substantially the same rights described in section 8. We honour those rights uniformly regardless of which state's law specifically applies. Submit requests to [email protected]. You may also lodge a complaint with the Attorney General of your state.

9.3 Global Privacy Control (GPC)

Where we offer any processing that would otherwise be subject to an opt-out under California or other state law, we treat a Global Privacy Control signal from your browser or device as a valid opt-out request. Today, because we do no selling, sharing, or targeted advertising, GPC signals do not change our behaviour — but the commitment is preserved.

10. Security

We use TLS 1.2+ for every connection between your device and our servers. Passwords are hashed with argon2id (64 MiB / 2 iterations / 32-byte digest). Sign-in tokens are short-lived (15 minutes); refresh tokens rotate on every use. All servers are firewalled and accessible only over SSH with key authentication. Photos are stored in a private object store and served through authenticated URLs.

No system is perfectly secure. If you discover a vulnerability, please write to [email protected].

11. Age requirement and minors

hankerchf is for adults aged 18 or older. We do not knowingly collect data from anyone under 18. We do not direct the service to children and we do not knowingly collect personal information from children under 13 within the meaning of the federal Children's Online Privacy Protection Act (COPPA). If you become aware that a person under 18 has created an account, please notify us at [email protected] and we will delete the account immediately and report the incident to the appropriate authorities, including the National Center for Missing & Exploited Children (NCMEC) where required by law. We may use age- and identity-verification mechanisms (selfie verification, document checks) where required by applicable law; any biometric data processed for that purpose is used solely for verification and deleted immediately after the verification result is recorded.

12. Changes to this policy

We may update this policy from time to time. Material changes (changes to the categories of data we collect, the processors we use, or the purposes for which we use Sensitive Personal Information) will be announced in the app at least 30 days before they take effect, and you will be asked to re-confirm any affected consent.

13. Contact

General support: [email protected]

Privacy / data-subject requests: [email protected]

Security disclosures: [email protected]

Account safety / abuse reports: [email protected]

Legal / other: [email protected]

Postal address and legal-entity registration: to be confirmed before public launch.