Privacy Policy
Version: 2026-10-01.2
1. Data controller
Sin Límite Apps, based in Bogotá, Colombia, is the controller of your data. Privacy and rights requests: [email protected]. This policy complies with Colombian Law 1581 of 2012 and Decree 1377 of 2013 and follows the principles of the EU General Data Protection Regulation (GDPR) and the California privacy law (CCPA/CPRA).
2. Data we collect
- Account: email, password (hashed), display name, date of birth, language and, if you use Google or Apple, the identifier that provider gives us.
- Profile: profile type (individual or couple), photos, bio, gender identity, pronouns, orientation, relationship styles, what you are looking for, interests, country, region and city.
- Sensitive data: sexual orientation, gender identity and relationship style (e.g. polyamory) are sensitive data. We only process them with your explicit consent, which you can withdraw by removing that data or deleting your account.
- Location: if you allow it, an approximate point rounded to a ~1 km grid. We never show your exact location; other people only see an approximate distance (and you can hide it).
- Activity: likes, matches, blocks, reports, chat messages and images, plans you organize or attend, reviews, places you suggest and last activity date.
- Device: push notification token, platform (iOS/Android) and minimal technical data (IP address in server logs) for security and abuse prevention.
- Technical and diagnostic data: if the App or the server fails, error logs (error message and stack trace), App version and build, device model, operating system version, screen or route name and approximate request timing. It is linked only to a pseudonymous internal identifier of your account. Before sending it we filter out chat messages, like notes, photos, emails, names, precise location and access tokens. We do not record your session or your screen.
- Premium: if you subscribe, the plan, store, purchase, renewal and expiration dates, transaction number and your Premium settings (badge visibility and the Travel mode city). We never receive your card details.
3. How we use it (purposes and legal bases)
- To provide the service: create your account, show your profile, suggest people, plans and places, and enable chat (performance of a contract).
- Safety: verify age, moderate photos with automated tools and human review, handle reports and prevent fraud (legitimate interest and legal obligation).
- Communications: verification, security and account emails, and push notifications you can configure (contract and consent).
- Stability: detect and fix failures and keep the service secure and stable using technical and diagnostic data (legitimate interest and performance of a contract).
- To improve the App with aggregated statistics (legitimate interest). We do not use your sensitive data for advertising, nor sell or share it for advertising.
4. Who we share it with (processors)
Only with providers that help us run the service, under contract and only for the purposes above:
- Railway (United States): server hosting.
- Neon (United States): database.
- Upstash (United States/EU): queues and real-time messaging.
- Cloudflare R2: private storage for photos and images.
- Resend (United States): email delivery.
- Expo and Google Firebase Cloud Messaging (United States): push notifications.
- Sightengine (France/EU): automated image moderation.
- Google and Apple: sign-in, if you choose to use them.
- RevenueCat (United States): Premium subscription management. It receives your internal account identifier (not your name or email) and the status of your purchases; Google Play or Apple process the payment.
- Sentry (Functional Software, Inc., United States): error and crash monitoring. It only receives the technical and diagnostic data described above, linked to your pseudonymous internal identifier, never your messages, photos, email, name or precise location.
Some providers are outside your country (for example Railway, Neon, Expo and Sentry, in the United States), so your data is transferred internationally. We require appropriate safeguards (standard contractual clauses or equivalent). We may also disclose data to authorities when required by law.
5. What other people see
Your public profile (display name, age, approved public photos, bio, interests, city and approximate distance unless you hide it). Your email, exact birth date and precise location are never shown. Private album photos are only visible to people you approve. If you like someone with Premium, they see your profile and whether you were active today or this week (never the exact time); without Premium they only see your age range and a heavily blurred thumbnail of your photo.
6. How long we keep it
- While your account is active.
- If you delete your account, we deactivate it immediately and after 30 days we delete or anonymize your data: profile, photos, likes, matches and album. Your messages in other people’s conversations are replaced with "message deleted" and your reviews remain as "Deleted user".
- We keep, in limited form, reports and moderation decisions (without your email or profile) and the audit log, to protect the community and comply with legal requests, for as long as the law requires or up to 5 years.
- "Download my data" copies expire after 7 days. Backups are overwritten in cycles of up to 30 days.
- Technical and diagnostic data is kept in Sentry for our plan’s retention period (around 90 days) and then deleted.
- If you had Premium, when you delete your account we keep a minimal record of purchases (store, plan, dates and transaction number, without your profile or email) for as long as accounting and consumer laws require. Deleting your account does not cancel the subscription in the store.
7. Your rights
You can access, update, correct and delete your data, withdraw consent, request proof of it, object to or restrict certain processing, and request data portability. In the App you can: edit your profile, download your data (Settings > Privacy > Download my data), pause your profile, hide your distance and delete your account. For any other request, email [email protected]. We will respond within the legal deadlines (typically within 30 days). You may also complain to your local data protection authority (in Colombia, the Superintendencia de Industria y Comercio).
California residents: we do not sell or "share" your personal information for cross-context behavioral advertising, and we will not discriminate against you for exercising your rights.
8. Minors
Poliamore is for adults 18+ only. We do not knowingly collect data from minors. If we detect an account belonging to a minor, we close it and delete its data.
9. Security
We use encryption in transit (HTTPS), hashed passwords, private photo storage with temporary links and restricted staff access. No system is 100% secure; if an incident affects you, we will notify you as required by law.
10. Changes
If we materially change this policy we will notify you in the App and ask you to accept it again.