borough

Privacy Policy

Effective date: TO BE FILLED IN ON LAUNCH · Last updated: 2026-05-04

Borough takes your privacy seriously, especially because identity, location, and personal connections are sensitive information that can have real-world consequences if mishandled. This policy explains what data we collect, how we use it, who we share it with, and the rights you have over it.

Introduction

Borough is a mobile social and dating application for the LGBTQ+ community. By using Borough, you agree to this Privacy Policy. If you don't agree, please don't use the app.

Borough is operated by Borough (referred to in this policy as "we," "us," or "Borough"). You can reach us at borough@borough-app.com.

What we collect, and why

Information you provide directly

DataWhy we need it
Email addressAccount identifier; used for sign-in and essential service notifications
PasswordAuthenticates you (hashed, never stored in readable form)
Date of birthRequired to verify you are 18 or older; not displayed to other users
Display nameShown to other users on your profile
BioShown to other users on your profile (optional)
Profile photosShown to other users; used for identity verification
Photos sent in messagesShared end-to-end-encrypted with the recipient

Information we collect automatically

DataWhy we need it
Approximate location (city-level, ~5km precision)Powers the proximity-based "Nearby" tab; never shown precisely
Device timezoneFor accurate scheduling of events and reminders
Device identifierEnables push notifications across multiple devices
Push notification tokenLets us deliver notifications to your device
Last-seen timestampShows whether other users are recently active
Crash and error logsHelps us fix bugs (PII scrubbed before transmission)
Anonymized usage eventsHelps us understand which features are used

What we do not collect

To make our position explicit, Borough does not collect:

How we use your data

To provide the service

To keep the service safe

What we do not use your data for

End-to-end encrypted messages

Direct messages between users are end-to-end encrypted using NaCl box encryption. The encryption keys live only on your device and the recipient's device. We cannot read your messages on our servers, and we cannot help you recover them if you lose your device.

What this means in practice:

How long we keep your data

DataRetention
Account profile, photosUntil you delete your account
Messages and message photosAutomatically deleted 18 months after they were sent
Read notificationsAutomatically deleted 30 days after they were marked read
Reports, blocks, audit log entriesRetained indefinitely for safety investigations
Crash and error logsUp to 30 days
Encrypted CSAM scan hashesOnly retained on positive match, in compliance with NCMEC reporting requirements

Third parties we share data with

ServiceWhat we shareWhy
Supabase (US-East region)All app dataBackend hosting and database
MapboxPlace-name search textPowers location search when picking event venues
OpenStreetMap (Photon and Nominatim)Place-name search textSame as above
Expo Push Notification ServiceYour push token + notification contentDelivers push notifications
Apple/Google native push servicesNotification contentNative delivery
Microsoft PhotoDNA Cloud ServiceHashes of uploaded photosDetects child sexual abuse material
SentryCrash reports (PII scrubbed)Bug tracking
PostHogAnonymized usage eventsProduct analytics
NCMEC (CyberTipline)Image, account info, metadata for confirmed CSAM matchesMandatory reporting under 18 USC §2258A

We do not sell your data, share it with advertisers, or share it with marketing analytics services.

Your rights

All users

EU residents (GDPR)

California residents (CCPA/CPRA)

To exercise any of these rights, contact us at borough@borough-app.com or use the in-app account management features.

Security

We protect your data using:

No system is perfectly secure. If we discover a data breach affecting your information, we will notify you in accordance with applicable law.

Children

Borough is for adults 18 and over. We require date-of-birth at signup and reject accounts where the calculated age is under 18. If you believe a minor has created an account, please report it to borough@borough-app.com.

We comply with the Children's Online Privacy Protection Act (COPPA) by not knowingly collecting any data from children under 13.

International data transfers

Borough's primary backend is hosted in the United States (Supabase US-East region). If you use Borough from outside the United States, your data will be transferred to and processed in the United States. By using Borough, you consent to this transfer.

Changes to this policy

We will update this policy as we add features, change vendors, or respond to legal changes. Material changes will be announced via in-app notification at least 30 days before they take effect. The "Last updated" date at the top of this policy reflects the most recent change.

Contact us

For privacy questions, requests, or complaints: borough@borough-app.com