← Back

Privacy Policy

This policy explains what LighthouseGG collects, why, and the choices you have. We aim to collect the minimum needed to run a friend-finding service, in line with UK GDPR.

1. What we collect

Account data (username, email, password hash, date of birth), the profile details you choose to add (bio, gender, interests, friendship goals, photos), a city/country you type in yourself, your matches and messages, and reports you file or that are filed about you. We also keep minimal security logs (e.g. failed sign-in attempts).

2. What we never collect

We do not track your location. There is no GPS access. Your location is only ever a city or country name you typed in. Photos you upload are re-encoded on our servers, which strips embedded metadata (including any GPS coordinates your camera added) before storage.

3. How your data is used

To operate the service: showing your profile in discovery, creating matches, delivering messages, and keeping the community safe (automated image screening for explicit content, and human review of reports and borderline cases). We do not sell your data or use it for advertising.

4. Sharing

Your public profile (username, age, bio, interests, goals, photos, city/country) is visible to other signed-in users. Infrastructure providers process data on our behalf: Supabase (database, auth, storage), Vercel (hosting), our image-moderation provider (uploaded images only, for screening), and Giphy (GIF search queries).

5. Retention & deletion

Deleting your account removes your profile, photos, matches and chat history permanently — a real deletion, not a hide. Reports you filed are kept without your account attached, to preserve moderation records. Unmatching deletes the conversation for both people.

6. Your rights

Under UK GDPR you can request a copy of your data, correct it, or delete it. Deletion is self-service from your profile menu; for access/correction requests contact us at the address published in the app.

7. Security

Passwords are hashed (never stored in plain text), all traffic is encrypted in transit (HTTPS), database access is restricted per-user by row-level security, and admin actions are logged.

Last updated: July 2026