Privacy Policy
Version 1.0 · Effective June 1, 2026
This is the current Privacy Policy. The frozen version that the Red Thread Android app links to from Settings is /legal/v1.0/privacy, text is identical at publication and that snapshot will never be edited in place.
This Privacy Policy describes how Red Thread (operated by kobbo, New Jersey, United States) collects, uses, shares, and protects your information when you use the Red Thread application and this website. It also explains your rights and how to exercise them.
By using Red Thread you agree to this Policy. If you do not agree, do not create an account, and stop using the Service.
Contents
- 1. Definitions
- 2. What we collect
- 3. The judge mechanic: what other users see
- 4. How we use your information
- 5. Service providers and third parties
- 6. Photo moderation
- 7. Reporting and blocking
- 8. Legal bases (GDPR / UK GDPR)
- 9. Your rights under GDPR / UK GDPR
- 10. California (CCPA / CPRA) disclosures
- 11. Data retention
- 12. International transfers
- 13. Age policy (18+)
- 14. Deleting your account
- 15. Security
- 16. Changes to this Policy
- 17. Contact
1. Definitions
- Account, a unique account you create to use Red Thread.
- Application, the Red Thread mobile application.
- Company / We / Us, Red Thread, a product operated by kobbo, based in New Jersey, United States.
- Personal Data, any information that relates to an identified or identifiable individual.
- Service, the Red Thread Application together with this website at redthread.social.
- Service Provider, a third party that processes data on our behalf (for example, Google for Firebase services).
- Usage Data, data collected automatically by use of the Service or its infrastructure.
- You, the individual using the Service.
2. What we collect
Information you give us
- Account credentials, email address (and, depending on sign-in method, the credential supplied by Google or Apple).
- Profile basics, display name, date of birth, gender, gender preferences, age preferences.
- Profile content, up to nine photos, a match bio (visible to potential matches), and a judge bio (a private note to the community deciding your pairs).
- Activity content, votes you cast as a judge, messages you send in matches, blocks you create, reports you submit.
- Optional support content, anything you write to us via the contact form, support email, or deletion request form.
Information we collect automatically
- Approximate location, derived from device location with your permission and stored as rounded latitude/longitude so the matching algorithm can scope pairs geographically. Exact location is not stored.
- Device and diagnostic data, device model, OS version, app version, language, IP address, unique device identifiers, crash logs, and stack traces.
- Usage data, which screens you visit, when, for how long, votes per session, basic counters used to calculate your match rate, judging accuracy, and similar stats.
- Push notification tokens, Firebase Cloud Messaging (FCM) tokens used to deliver notifications about new matches and messages.
- Play Integrity attestation, Google's Play Integrity verdict at sign-in time, used to detect tampered installs.
Information from other sources
- If you sign in with Google or Apple, we receive the authentication identifier and the email address you authorize.
- Cloud Vision returns a moderation verdict for each photo you upload (see section 6).
3. The judge mechanic: what other users see
Other users see your photos and bios for the express purpose of voting on potential pairs. This is core to how Red Thread works, and we want to call it out plainly here.
When the matching algorithm identifies a candidate pair that includes you, the pair card, containing your photos, match bio, and judge bio, is shown to other users in the community who vote yes or no on whether the pairing makes sense.
What is and isn't shared with other users:
- Shared with judges: your photos, your match bio, your judge bio, your display name, and broad attributes used in matching (age, gender, gender preferences).
- Shared with matches you accept: the same content above, plus the chat thread between the two of you.
- Not shared with other users: your email address, your phone number (if any), your exact location, your IP address, your device identifiers, your votes, and your reports.
4. How we use your information
We use your information to:
- Run the matching mechanic, surface pair cards to judges, count votes, identify pairs that pass the threshold, and notify both daters when a match is created.
- Operate the Service, deliver messages, keep accounts working, send push notifications, and respond to your requests.
- Keep the community safe, moderate photos, evaluate reports, enforce community guidelines, suspend or ban accounts that violate the rules, and cooperate with law enforcement when legally required.
- Improve Red Thread, analyze usage patterns in aggregate, debug crashes, measure feature performance, and inform product decisions.
- Communicate with you, security alerts, policy changes, support replies, and (with your consent) occasional product updates.
- Comply with law, respond to legal process, defend our rights, and meet record-keeping obligations.
5. Service providers and third parties
We rely on the following service providers to run Red Thread. Each receives only the data needed for its specific role.
- Google Firebase Authentication, account creation and sign-in.
- Google Cloud Firestore, account, match, and message storage.
- Google Firebase Data Connect (Cloud SQL / PostgreSQL), relational data (profiles, votes, pair candidates, blocks, reports).
- Google Cloud Functions for Firebase, server-side logic such as match creation, report mirroring, and deletion pipelines.
- Google Cloud Storage for Firebase, photo storage.
- Google Cloud Vision (SafeSearch), automated photo moderation, see section 6.
- Firebase Cloud Messaging (FCM), push notifications.
- Firebase Crashlytics, crash diagnostics.
- Firebase Analytics, aggregate usage analytics.
- Google Play Integrity API, sign-in attestation against tampered installs.
- Google Sign-In / Sign in with Apple, authentication if you choose those providers.
- FormSubmit, relays submissions from our website contact form and deletion request form to our email inbox.
We do not sell your Personal Data. We share information only as described in this Policy.
Other situations where we share
- Other users: as described in section 3.
- Legal compliance: when required by valid legal process, to investigate fraud or abuse, to protect our rights or the safety of users, or as otherwise permitted by law.
- Business transfers: if Red Thread is acquired, merged, or its assets are sold, your Personal Data may transfer to the successor entity. We'll notify you before that transfer changes how your data is governed, and give you the option to delete first.
- With your consent: any other sharing requires your explicit permission.
6. Photo moderation
Every photo you upload is automatically scanned by Google Cloud Vision SafeSearch. The scan returns a verdict across categories including adult content, violence, racy content, and spoof. The verdict is stored alongside the photo metadata. Photos flagged as unsafe are blocked from going live.
Cloud Vision processes the image to produce the verdict and does not retain it beyond the API call. Google's Cloud Vision data handling is governed by the Google Cloud Platform terms.
7. Reporting and blocking
Reports are stored against the reported user with the reporter's identifier, the reported user's identifier, the report reason, any free-text detail, and the timestamp. Reports are visible only to our moderation team and are anonymous to the reported user.
Blocks are stored as a directed relationship between two accounts and used by the matching algorithm to filter out the other party from your pair feed and chat list.
8. Legal bases (GDPR / UK GDPR)
If you are in the European Economic Area or the United Kingdom, we process your Personal Data under the following bases:
- Contract (Art. 6(1)(b)): running the Service that you signed up for, including matching, messaging, and account management.
- Legitimate interests (Art. 6(1)(f)): moderating the community, preventing fraud, ensuring security, improving the product, and defending our legal interests, balanced against your rights and freedoms.
- Legal obligation (Art. 6(1)(c)): responding to law enforcement, complying with tax and record-keeping requirements, and meeting any other applicable legal duty.
- Consent (Art. 6(1)(a) and Art. 9(2)(a)): for processing of sensitive attributes such as data revealing sexual orientation (inferred from gender preferences) and for optional analytics or marketing if we ever offer them. You can withdraw consent any time by editing your profile or deleting your account.
9. Your rights under GDPR / UK GDPR
You have the right to:
- Access the Personal Data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase your data ("right to be forgotten"), covered by the in-app deletion flow and the web deletion form.
- Restrict certain processing.
- Object to processing based on legitimate interests.
- Port your data to another service in a structured, machine-readable format.
- Withdraw consent at any time where consent is the legal basis.
- Lodge a complaint with your local supervisory authority.
To exercise any right, email legal@redthread.social. We respond within one month and will explain any reason we can't fulfill a request in full (for example, because we have a legal obligation to retain certain records).
10. California (CCPA / CPRA) disclosures
If you are a California resident, you have additional rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act:
- Right to know what categories of Personal Information we collect, the sources, the business purposes, and the categories of third parties we share with. Section 2 (what we collect) and section 5 (third parties) cover this.
- Right to delete the Personal Information we hold about you, subject to legal exceptions.
- Right to correct inaccurate Personal Information.
- Right to opt out of sale or sharing of Personal Information for cross-context behavioral advertising. Red Thread does not sell or share your Personal Information. There is nothing to opt out of.
- Right to limit use of sensitive personal information beyond what's necessary to provide the Service.
- Right to non-discrimination for exercising any of the above rights.
Submit a request by emailing legal@redthread.social. We verify identity using your account email and basic profile details before honoring deletion or access requests.
"Do Not Sell My Personal Information": Red Thread does not sell your Personal Information.
11. Data retention
We retain Personal Data only as long as needed to provide the Service and to meet our legal and operational obligations. Specifically:
- Active accounts: profile data, photos, votes, blocks, matches, and messages are kept while the account is active.
- Deleted accounts: profile data, photos, and votes are removed from production systems within 30 days of deletion. Messages remain in the other party's chat thread, attributed to "Deleted User," because those messages belong to the recipient's account as well.
- Reports: moderation reports and the underlying account snapshot are retained for up to 24 months after the report's resolution so we can identify repeat offenders.
- Tombstones: a minimal "this UID was deleted" record is kept so that we can refuse re-creation under the same identity if required by law or by the abuse-prevention policy.
- Audit logs: security and administrative logs are retained for up to 12 months.
- Backups: encrypted backups are rotated and overwritten on a normal cycle. Deleted data will age out of backups within 90 days.
12. International transfers
Red Thread operates from New Jersey, United States. Our service providers (primarily Google Cloud) host data in the United States and may replicate it to other regions for performance, availability, and disaster recovery. If you use Red Thread from outside the United States, you consent to your data being transferred to and processed in the United States.
For transfers from the EEA or the UK, we rely on Google Cloud's Standard Contractual Clauses and other approved transfer mechanisms.
13. Age policy (18+)
Red Thread is for adults. You must be at least 18 years old to use the Service. We collect your date of birth during signup and reject accounts whose DOB indicates an age under 18. We do not knowingly collect Personal Data from anyone under 18.
If you believe a child has provided us with Personal Data, contact legal@redthread.social and we will investigate and delete it.
14. Deleting your account
You can delete your account two ways:
- Inside the app: Settings → Delete account. Type
DELETEto confirm. The app runs a four-step pipeline: wipe your profile in our relational store, delete all your photos from Cloud Storage, clear your Firestore records, and close your Firebase Authentication entry. Conversations remain in the other party's inbox attributed to "Deleted User." - From this website: use the deletion request form. We verify identity using the information you provide and run the same deletion against your account within 14 days.
Once deletion completes, Personal Data is removed from production systems within 30 days and ages out of encrypted backups within 90 days. Audit-trail and tombstone records remain as described in section 11.
15. Security
Personal Data is encrypted in transit (TLS) and at rest at our cloud providers. Access to production systems is restricted to a small set of personnel who need it for operations, security, and moderation. We monitor for abuse, run automated and manual moderation, and require multi-factor authentication on administrative accounts.
No security system is perfect. If we discover a breach affecting your Personal Data, we will notify you and any applicable supervisory authorities as required by law.
16. Changes to this Policy
We may update this Policy from time to time. Material changes
are accompanied by a version bump (for example, v1.0 to v1.1).
Each version is published as a frozen snapshot at
/legal/v{version}/privacy and stays reachable so
the Red Thread app can link to the exact text you agreed to.
When a material change happens, we will notify you in-app and give you a chance to review and re-accept before the new version takes effect. The "Effective" date at the top of this page shows the activation date of the current version.
17. Contact
Questions about this Policy or your data:
- Email: legal@redthread.social
- Postal: kobbo, New Jersey, United States (full mailing address available on request)
- Support: redthread.social/support