Privacy, in detail.

The manifesto is what we believe. This page is how it is built. Where something has a limitation, we say so.

What the industry does, and what we do

Common practice

  • Sell or broker location data
  • Share sexual-health signals with ad partners
  • Store precise GPS coordinates
  • Build ad profiles from behaviour
  • Keep deleted profiles in cold storage
  • Require phone numbers or real names

Sitches

  • Never sell data. Full stop.
  • Sensitive fields are revealed mutually or not at all
  • Location snapped to ~200m hex zones, server-side
  • No advertising profile, no third-party trackers
  • Account deletion wipes everything within 30 days
  • Email-only sign-in, no phone number

Location: a zone, not a point

When your phone sends its position, the server immediately snaps it to a hexagonal zone roughly 200 metres across. That hex is what gets stored, and that hex is what powers Radar. Raw GPS coordinates are never stored and never returned by the API, to anyone, including you. Distances other people see are approximate by construction, so there is no "precise mode" to leak.

Mutual disclosure, technically

Sensitive profile fields carry a visibility level: public, shared, or private. Shared fields are stored on our servers like everything else, but the API only reveals them to another user when that user has disclosed the same thing. The filtering happens server-side, so a modified client cannot see more than it should. Private fields are never shown to anyone and only inform matching.

What we collect and why

Email address Authentication only. Magic-link sign-in means there is no password to store or breach.
Profile content Photos, bio, tags and preferences, stored to power your profile. Deleted with your account.
Hex-zone location The ~200m zone described above. Used to show nearby people. Never a GPS point.
Messages Stored on our servers to deliver them. They are not end-to-end encrypted today, and we won't pretend otherwise.
Device token Push notifications only. Never linked to advertising.

Screenshot protection

Screenshot protection runs across the whole app, not just private photos. On Android, captures are blocked at the OS level. On iOS, where blocking is not possible, screenshots are detected and logged, and the first attempt triggers a clear warning. Chat media is view-once by default, so what you send does not stick around unless you choose it.

This website

The site you are reading loads no analytics, no tracking pixels, and no third-party fonts or scripts. Every request stays on our own domain. That is a small thing, but it is the same posture the app takes: your attention is not a product.

Your rights

You can request a copy of your data, correct inaccuracies, or delete your account at any time from within the app. Deletion is permanent and processed within 30 days. We comply with UK and EU GDPR and applicable privacy laws.

Questions? Email privacy@sitches.app. The formal policy lives at /privacy.

Commitments to LGBTQ+ users

We understand the specific risks queer people face in many places. Sexual orientation, gender identity, and relationship-style data will never be advertising fuel here. When we receive legal requests, we review them narrowly and challenge overbroad demands where the law allows.

Last updated: August 2026