Privacy Policy
Effective date: February 6, 2026
DuoFeed ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and what choices you have. We do not sell your personal data to third parties.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address
- Birthdate (used to verify you are at least 13 years old)
- Profile information you choose to provide (e.g., display name, profile photo, bio)
1.2 User Content
We collect content you create and share on DuoFeed, including posts, photos, and messages.
1.3 Location Data
If you choose to tag a post with a location, we store the latitude and longitude associated with that post. We do not store your current or real-time location. Location permission is requested during onboarding and can be managed at any time through your device settings. Location is entirely optional — you can use DuoFeed without granting location access.
1.4 Identifiers
We collect your user ID and device ID to authenticate your account and deliver the Service.
1.5 Push Notification Tokens
If you enable push notifications, we store a device token to deliver notifications to your device.
2. How We Use Your Information
We use the information we collect solely to:
- Provide, operate, and maintain the Service and its features.
- Authenticate your identity and secure your account.
- Enable location-based discovery features (when you opt in).
- Categorize your posts using AI-powered tagging to improve content discovery (see Section 5).
- Deliver push notifications you have opted into.
- Respond to support requests and communications.
- Maintain security, prevent abuse, and enforce our Terms of Use and Community Guidelines.
- Improve the Service and develop new features.
We use your data only to improve the app for our users and never sell or disclose personal data to third parties for their own purposes.
3. Location Privacy
DuoFeed is designed to protect your location privacy:
- Your exact location is never shown to other users. Users can only see an approximate proximity (e.g., "3 miles away"), with a minimum display distance that never goes below 1 mile.
- We only store location data for posts you explicitly choose to tag with a location. We do not track or store your real-time location.
- Location data associated with a post is retained for the life of that post (until you delete it).
- You can browse the local discovery feed without your own location appearing in others' feeds.
- You can disable location entirely and continue using DuoFeed, including the Close Friends feed.
4. Sharing & Disclosure
We do not sell, rent, or trade your personal information. We may share information only in the following circumstances:
- Service providers — We share data with trusted third-party service providers who help us operate the Service (see Section 6), under appropriate data protection agreements and only to the extent necessary to provide their services.
- Legal requirements — We may disclose information when required by law, legal process, or government request, or to protect the rights, safety, or property of DuoFeed, our users, or the public.
- Safety — We may share information to prevent fraud, abuse, or illegal activity, or to enforce our Terms of Use.
We do not use any third-party analytics, advertising, or tracking services. No data is shared for targeted advertising purposes.
5. AI-Powered Content Categorization
DuoFeed uses artificial intelligence (via OpenAI's API) to automatically assign category tags to posts. This process:
- Only adds tags and categories — it does not edit, summarize, rewrite, or otherwise modify your original content.
- Does not modify your images in any way.
- Is processed via OpenAI's API, which does not store your content or use it for model training, in accordance with their data processing policies (content is deleted within 30 days per OpenAI's retention policy).
6. Third-Party Services
We use the following third-party services to operate DuoFeed:
- Supabase — Authentication (JWT-based), database hosting, cloud storage (S3 buckets for media), and push notification infrastructure.
- OpenAI — AI-powered post categorization and tagging.
- Expo — Push notification delivery to mobile devices.
We do not currently use any third-party analytics, crash reporting, or advertising services.
7. Data Security
We implement reasonable security measures to protect your information:
- All data transmitted between your device and our servers is encrypted using SSL/HTTPS and secure WebSockets.
- Authentication data is encrypted.
- Access to production user data is restricted to the CEO/CTO only.
- We use Supabase's built-in security infrastructure for database and storage protection.
While we take reasonable precautions, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
8. Data Retention & Deletion
8.1 Active Accounts
We retain your personal data for as long as your account is active and as needed to provide the Service. Post location data is retained for the life of the post (until deleted by you).
8.2 Account Deletion
When you delete your account:
- Your account and posts are immediately hidden from all other users.
- Your profile is anonymized during a 30-day grace period.
- After 30 days, all your data — including posts, profile information, and associated content — is permanently deleted, including from backups.
8.3 Data Export
Automated data export is not currently available. You may request a manual export of your data by contacting support@duofeed.app.
9. Your Choices & Rights
- You may delete your account at any time, which will result in the permanent deletion of your data within 30 days (see Section 8.2).
- You may manage location permissions at any time through your device settings.
- You may enable or disable push notifications through your device settings.
- You may request a manual export of your data by contacting support.
- Depending on your jurisdiction, you may have additional rights to access, correct, restrict processing of, or delete your personal data. To exercise these rights, contact support@duofeed.app.
10. Children's Privacy
DuoFeed is not directed to children under 13. We require users to provide their birthdate during registration, and accounts for users under 13 are not created. If you believe we have inadvertently collected information from a child under 13, please contact us immediately at support@duofeed.app and we will promptly delete the information.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected on this page with an updated effective date. We may also notify you through the app or via email for significant changes. Your continued use of the Service after changes become effective constitutes your acceptance of the revised policy.
12. Contact
If you have questions about this Privacy Policy or our data practices, email support@duofeed.app.