Privacy Policy

1. Introduction and scope

This Privacy Policy explains what information NearTree ('NearTree,' 'we,' 'us,' or 'our') collects when you use the NearTree mobile app and related services (together, the 'Service'), how we use and share it, how long we keep it, and the choices and rights you have. It applies to everyone who creates a NearTree account, anywhere in the world.

NearTree is a consent-based, proximity-aware discovery app. For each encounter context you choose a discovery mode — off, invisible, friend, professional, romantic, or mixed — and nothing about you is shown to another person until both of you have independently and separately opted in to being visible to each other. That two-sided consent gate is the core of how we protect your privacy, and it's described in full technical detail in Section 3 below because it matters more than any other part of this Policy.

Capitalized terms not defined here have the meaning given in our Terms of Service.

2. Who is responsible for your information (data controller)

NearTree, operated by QuickGive, LLC, a company organized under the laws of Michigan with a registered address at 36098 Hees Street, Livonia, Michigan 48150, is the data controller (or, under CCPA/CPRA terminology, the 'business') responsible for the personal information described in this Policy.

If you are located in the European Economic Area or the United Kingdom and have questions about our processing of your personal data, you can reach our privacy team at privacy@neartreeapp.com. We have not appointed a separate EU or UK representative under Article 27 GDPR / UK GDPR at this time because we do not yet have an established, ongoing user base in those regions; [placeholder: revisit this once EEA/UK usage becomes regular and appoint a representative if required].

3. How our consent-based discovery actually works

Discovery is off by default and fully opt-in. You separately choose whether to be discoverable in each mode — off, invisible, friend, professional, romantic, or mixed — and you can turn discovery off, switch modes, or hit the panic-stop pause instantly, at any time, from the app. Pausing or turning discovery off stops your device from advertising or scanning for anyone else within seconds.

We never use GPS, cell-tower triangulation, Wi-Fi positioning, or any other form of precise location to find people near you, and we never ask for or use your device's 'precise location' permission for this purpose. Instead, when discovery is on, your device broadcasts a short-range Bluetooth Low Energy (BLE) advertisement containing a rotating token — a string of characters that changes on a short, frequent cycle and carries no information about your identity, account, or device that would mean anything to someone who happened to intercept it over the air. The token only resolves into anything meaningful when our server matches it against an active encounter session created by two devices that were actually in range of each other; nothing persistent, and nothing identifying, is ever broadcast.

Invisible mode keeps you out of the browsable Discover list and skips any identity-adjacent broadcast, while still allowing BLE proximity detection to keep running in the background — so you can still be matched into a private consent queue through a passive encounter without ever appearing as a card someone browses. It exists specifically for people who want the matching mechanism without the exposure of active browsing.

When two devices that both have discovery on detect each other's rotating token at close range, that's called an 'encounter.' An encounter, by itself, never creates a match, never notifies the other person of your interest, and never reveals either person's identity, photos, bio, or any profile information to the other. It is placed into a private consent queue on each side, entirely separately.

Each person independently decides 'interested' or 'pass' on that encounter, without any visibility into what the other person chose or whether they've decided yet. Only if both sides independently choose 'interested' does it become a mutual match. Only at that point — after both sides have opted in — do identity, photos, profile details, and compatibility tier become visible to each other, and chat unlocks. A one-sided 'interested' is never disclosed to the other person in any form: no notification, no partial reveal, no hint.

We estimate rough proximity — labeled as buckets like 'very close,' 'nearby,' or 'in range' — from Bluetooth signal strength alone, not from any distance-measurement or location technology. We do not know, and cannot reconstruct, your or anyone else's precise physical location, address, or movement history from this signal.

Consent-queue entries that neither side acts on expire automatically after 14 days. Encounter tokens themselves rotate and expire on the order of minutes, so a token observed at one moment is meaningless shortly after.

You can permanently and instantly stop all of this by switching your discovery mode to 'off' or pausing discovery — no encounters can be created, and your device stops advertising and scanning, from that moment on.

4. Categories of personal information we collect

Account credentials: your email address and a securely hashed password (we never store your password in plain text), or, if you choose to sign in with Google or Apple, the verified identifier and basic profile information (name, email) that provider discloses to us as part of that sign-in. We also generate and send short-lived numeric verification codes to confirm your email address.

Phone number and SMS verification (not currently active): our onboarding flow has a field for a phone number and was designed to support SMS-based verification through a text-messaging provider. That feature is not live: no verification codes are currently sent by SMS to any phone number you provide, and no phone number is currently transmitted to any SMS provider. If we activate this feature, we will update this Policy and notify you in-app before doing so.

Profile and onboarding information: your display name, birthdate (used to confirm you meet our 18+ minimum age and, if you choose, to set age preferences for who you're matched with), gender identity, a written bio, up to several profile photos (stored with our cloud storage provider), your chosen discovery mode(s) and 'intents,' and your answers to our compatibility/matching questionnaire.

Compatibility scoring and inferences: your questionnaire answers feed an algorithm that computes a numeric compatibility score between you and another user. We never disclose the raw score, or your underlying answers, to the other person — only a coarse tier (high, medium, or low compatibility) is ever surfaced, and only after a mutual match.

Proximity and encounter data: the rotating BLE tokens your device broadcasts and scans for, coarse proximity buckets derived from Bluetooth signal strength, records that an encounter occurred between two devices, your consent-queue decisions ('interested' / 'pass'), and records of resulting mutual matches.

Messages: the content of messages you send and receive once you've mutually matched with someone, delivered through our real-time chat system.

Safety and moderation data: blocks you place or that are placed against you, reports you submit or that are submitted about you, the outcome of our moderation review of those reports, automated safety signals that flag content or activity for review (see Section 6), and any account warning, suspension, or termination history.

Device and push notification data: if you enable push notifications, a device push token that lets Apple's or Google's push infrastructure (via Expo) deliver notifications to your device. We do not use this token for advertising or cross-app tracking.

Diagnostic and crash data: technical information automatically collected when the app or our servers encounter an error or crash — for example, stack traces, device model, operating system version, and app version — used to find and fix bugs. This is collected on both the mobile app and our backend through our crash-monitoring provider.

We do not collect precise geolocation, government-issued identification, biometric identifiers (we do not use facial recognition, fingerprint, or voiceprint technology on your photos or otherwise), payment card information (we do not currently process payments), or audio/video recordings.

5. Sensitive personal information and consumer health data

Some of the information described above is legally 'sensitive' under privacy laws like the California Consumer Privacy Act as amended by the CPRA, and may also qualify as 'consumer health data' under laws like Washington State's My Health My Data Act and similar state laws that define that term broadly enough to reach information about sexual orientation and intimate or romantic activity.

Specifically: your gender identity, your choice to use romantic-mode discovery, and inferences reasonably drawable from your matching activity (such as your apparent sexual orientation or relationship interests) fall into this category. We treat this information with the same consent-gated design described in Section 3 — it is never shown to another person unless you've both mutually matched — and we do not sell it, do not use it for advertising, and do not share it with data brokers.

If you are a California resident, you have the right to limit our use of sensitive personal information to what's necessary to provide the Service; we do not use it for any purpose beyond operating discovery, matching, and safety as described in this Policy, so there is no separate advertising or profiling use to limit.

If you are a Washington State resident (or a resident of another state with a similar consumer-health-data law), we do not sell consumer health data and do not use geofencing around any facility that could reveal an attempt to obtain health-care services. We collect the categories described above solely to operate the discovery, matching, and safety features you've opted into, and we do not share consumer health data with third parties except the service providers described in Section 8, each acting on our behalf and under contractual confidentiality obligations, or as required by law.

6. Automated processing, safety signals, and profiling

We use automated systems to help flag content or behavior that may violate our Terms of Service or Community Guidelines — for example, patterns associated with harassment, spam, or account-farming. These signals inform and prioritize human review by our moderation team; they are one input into moderation decisions, not a substitute for human judgment, and we do not take irreversible enforcement action (such as permanent account termination) based on an automated signal alone without human review.

The compatibility-scoring described in Section 4 is the only other automated processing on your data that could be considered profiling. It has no legal or similarly significant effect on you within the meaning of Article 22 of the GDPR — at most, it changes which coarse tier label is shown to a mutual match — and it is never used for advertising, credit, employment, insurance, or any decision outside the app. If you would prefer not to be scored this way, you can decline to answer the matching questionnaire, though this may reduce the quality of suggested matches.

7. How we use your information

To operate discovery, the BLE proximity system, the consent queue, matching, compatibility scoring, and chat as described in Sections 3 through 6.

To create and secure your account, authenticate you, and confirm you meet our minimum age requirement.

To send account, verification, safety, and match-related communications by email or push notification, based on your notification settings.

To investigate reports of abuse, harassment, or violations of our Terms of Service or Community Guidelines, and to take enforcement action including warnings, suspension, or termination.

To detect, prevent, and respond to fraud, scams, security incidents, and technical problems, including through crash and error monitoring.

To comply with legal obligations, respond to lawful requests from public authorities, and meet our reporting obligations regarding child sexual abuse material described in Section 15.

To enforce our Terms of Service and Community Guidelines and protect the rights, property, and safety of NearTree, our users, and the public.

8. Third parties we share information with

We use a limited set of third-party service providers ('subprocessors') to operate NearTree. Each receives only the data reasonably necessary to perform its function, is contractually restricted from using it for its own independent purposes, and is contractually required to implement appropriate security measures. We do not sell your personal information, and we do not share it with third parties for their own advertising purposes.

Supabase — our database and file-storage provider, hosted on AWS in the us-east-1 (Northern Virginia, USA) region. Supabase stores our primary application database (accounts, profiles, encounters, matches, messages, reports) and your uploaded profile photos.

Railway — hosts our backend API and Redis infrastructure. Data processed by our backend, including in transit between the app and our servers, runs on Railway's infrastructure.

Resend — our transactional email provider, used to deliver verification codes and account/safety notifications to your email address.

Sentry — our crash and error monitoring provider, used on both the mobile app and backend, to help us detect and fix bugs. Sentry may receive technical diagnostic data and, incidentally, fragments of application state present at the moment of a crash.

Google — if you choose to sign in with Google, Google acts as an identity provider and confirms your identity to us; we receive the profile information Google discloses as part of that sign-in, governed by Google's own privacy policy for its own processing.

Apple — if you choose Sign In with Apple, Apple acts as an identity provider under the same model, including support for Apple's private email relay if you choose to hide your email address from us.

Expo / EAS — used to route push notifications to your device through Apple's APNs and Google's FCM, and to distribute app builds and over-the-air updates.

Twilio (not currently active) — we intend to use Twilio in the future to deliver SMS-based phone verification codes. This is not live today: no phone numbers are currently sent to Twilio, and no SMS messages are currently sent through Twilio or any other provider. This Policy will be updated, and you will be notified in-app, before this is enabled.

We may also disclose information: where required by law or valid legal process; to enforce our Terms of Service; to protect the rights, property, or safety of NearTree, our users, or the public, including in the CSAM-reporting circumstances described in Section 15; or in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy (or a materially similar successor policy) continuing to apply to your information.

9. Cookies, SDKs, and tracking technologies

NearTree is a mobile app, not a website, so traditional browser cookies don't apply. We use on-device local storage to keep you signed in and remember your app preferences, and a device push token (see Section 4) if you opt into push notifications.

We do not embed third-party advertising SDKs, and we do not use your device's advertising identifier (IDFA on iOS, or the Google Advertising ID on Android) for cross-app tracking or targeted advertising. Because we don't perform this kind of tracking, Apple's App Tracking Transparency prompt is not applicable to how we currently operate the app.

We do not currently honor Global Privacy Control (GPC) or other browser-based opt-out signals because we don't operate a tracking website; since we don't sell or share personal information for cross-context behavioral advertising in the first place, there is nothing such a signal would need to opt you out of. If that changes, we will update this section and add proper support for recognized opt-out signals.

10. Children's privacy and COPPA

NearTree is not directed at, and is not intended for use by, anyone under 18, and we do not knowingly collect personal information from anyone under 13 (or under 18 generally). This Policy and the Service are not designed to comply with the reduced-consent framework the Children's Online Privacy Protection Act (COPPA) provides for child-directed services, because NearTree is not a child-directed service and does not permit use by children.

We confirm your age from the birthdate you provide during onboarding; you must be at least 18 to complete onboarding and to use any discovery, matching, or chat feature. This is a self-attestation — we do not currently perform government-ID or third-party age verification. If we learn that an account belongs to someone under 18, we will immediately terminate the account and delete the associated personal data, subject to the limited safety/legal retention described in Section 12.

If you believe a child is using NearTree, or that a user has misrepresented their age, please report it immediately at safety@neartreeapp.com or using the in-app reporting tools.

11. Security

We use industry-standard measures to protect your information, including password hashing (bcrypt) so we never store your password in a readable form, encrypted connections (TLS) between the app and our servers, encryption at rest for our database and stored files through our cloud storage provider, and role- and access-controls limiting which systems and personnel can reach production data.

Access to personal information by our own personnel is limited to what's needed for engineering, safety/moderation, and customer support functions, and is logged.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a security incident that compromises your personal information, we will notify affected users and any regulators or authorities as required by applicable law, generally without undue delay and consistent with the notification timelines those laws specify (which in the US commonly range from 'without unreasonable delay' to a fixed number of days depending on the state).

12. Data retention

We retain your account and profile information for as long as your account is active.

When you delete your account from Settings → Account, we deactivate it immediately, remove you from discovery, and scrub your profile's personal fields (name, bio, photos, questionnaire answers) from active use right away.

Messages and match history are retained for up to 90 days after account deletion, solely to allow investigation of an abuse report filed shortly before or around the time of deletion, after which they are permanently deleted unless retention is independently required by an open investigation or legal obligation.

Encounter tokens rotate and expire on the order of minutes and are never retained long-term. Consent-queue entries that go unactioned expire automatically after 14 days regardless of account status.

Reports, moderation outcomes, and suspension/termination records may be retained for up to 3 years after account deletion, including after account deletion, where necessary to enforce our policies (for example, preventing a banned user from creating a new account), investigate patterns of abuse across multiple users, or comply with legal obligations.

Crash and diagnostic data is retained according to our monitoring provider's standard retention windows, which are on the order of weeks to a few months.

Records we are legally required to produce or retain in connection with a CSAM report (see Section 15) are retained for the period required by 18 U.S.C. § 2258A and related law, which is currently one year from the date of the report.

13. Your privacy rights — general

Regardless of where you live, you can access, edit, or delete your profile information, discovery preferences, and questionnaire answers at any time from Settings.

You can request account deletion from Settings → Account, which triggers the deactivation and data-scrubbing described in Section 12.

You can request a copy of your data, ask us to correct inaccurate data, or ask us to restrict certain processing, by contacting us at privacy@neartreeapp.com. We will respond within the timeframe required by applicable law (see Section 14), and in any case within 45 days.

We will verify your identity before acting on a rights request — typically by confirming you can access the email address or sign-in method associated with the account — to prevent someone else from accessing or deleting your data.

14. State and national privacy law disclosures

California (CCPA/CPRA): you have the right to know what personal information we collect, use, disclose, and (if applicable) sell or share, and the right to request access to and deletion of that information, the right to correct inaccurate personal information, and the right to limit use of sensitive personal information as described in Section 5. We do not sell or share personal information for cross-context behavioral advertising, so there is no sale/share opt-out necessary. You may designate an authorized agent to submit a request on your behalf; we may require proof of that authorization. We will not discriminate against you for exercising any CCPA/CPRA right. Under California Civil Code § 1798.83 ('Shine the Light'), California residents may request information about disclosures of personal information to third parties for their direct marketing purposes; we don't make such disclosures, so there is nothing currently to report in response to such a request.

Colorado (CPA), Connecticut (CTDPA), Virginia (VCDPA), Utah (UCPA), and other states with comprehensive privacy laws: you have similar rights to those described above — access, correction, deletion, data portability, and the right to opt out of targeted advertising, the sale of personal data, and (where applicable) certain profiling. We do not engage in targeted advertising or sell personal data, so those opt-outs are not applicable to how we currently operate. You can exercise your available rights by contacting privacy@neartreeapp.com, and we will not treat you differently for doing so. If we deny a request, you may appeal by replying to our decision email, and if the appeal is denied you may have a right to contact your state Attorney General.

Nevada: Nevada law gives residents the right to opt out of the sale of certain covered information. We do not sell covered information as defined under Nevada law, so there is no sale to opt out of; you may still submit a request to privacy@neartreeapp.com and we will confirm this in writing.

European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR): our processing is based on your consent (for discovery, matching, and the compatibility questionnaire), the performance of our contract with you (the Terms of Service, for core account and messaging functionality), and our legitimate interests in safety, fraud prevention, and service security, balanced against your rights. You have the right to access, rectify, erase, or restrict processing of your personal data; the right to data portability for data you provided to us; the right to object to processing based on legitimate interests; the right to withdraw consent at any time (which you can do simply by turning discovery off); and the right to lodge a complaint with your local data protection supervisory authority. Because our infrastructure is hosted in the United States, transfers of personal data from the EEA/UK/Switzerland are made subject to Standard Contractual Clauses or another lawful transfer mechanism with each subprocessor that processes EEA/UK/Swiss users' data — see the open item at the top of this file regarding actually executing those clauses before EEA/UK users are onboarded at scale.

This section is not an exhaustive list of every US state privacy law; if you reside somewhere with rights not specifically named above, contact privacy@neartreeapp.com and we will honor rights required by the law applicable to you.

15. Cooperation with law enforcement and reporting of child sexual abuse material

We have zero tolerance for child sexual abuse material (CSAM) and for the sexual exploitation of minors on NearTree. As a US-based online service provider, we are required by federal law (18 U.S.C. § 2258A) to report apparent CSAM to the National Center for Missing & Exploited Children's (NCMEC) CyberTipline, and we do so. A report to NCMEC may include the reported content, the account information of the user who posted or sent it, and any other information reasonably related to the apparent violation. We immediately terminate any account found to have violated this policy and may refer the matter to law enforcement.

We may also disclose account or usage information in response to a valid subpoena, court order, search warrant, or other legal process, and in circumstances involving an imminent risk of death or serious physical harm to any person. Where legally permitted, we will attempt to notify the affected user before disclosing their information in response to legal process, unless we're prohibited from doing so (for example, by a non-disclosure order) or believe notice would create a safety risk.

16. Do-Not-Track and third-party links

Because we don't track you across other apps or websites (see Section 9), we don't currently have a mechanism to respond differently to a browser 'Do Not Track' signal, and none is applicable in a native mobile app context.

Other users' profiles, bios, or messages may contain links to third-party websites or services. We don't control, and aren't responsible for, the privacy practices of those third parties; review their own privacy policies before providing them any information.

17. International users

Our servers and databases are hosted in the United States (AWS us-east-1 via Supabase; Railway for compute). If you use NearTree from outside the United States, your information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your country. By using NearTree, you understand that your information will be processed in the United States as described in this Policy.

18. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. If we make a material change, we will notify you in-app before it takes effect and update the effective date once one is set. Your continued use of NearTree after a change takes effect constitutes acceptance of the updated Policy.

19. Contact us

General privacy questions or rights requests: privacy@neartreeapp.com.

Safety concerns, including reports involving a minor or suspected exploitation: safety@neartreeapp.com, or use in-app reporting.

General support: support@neartreeapp.com.

Postal notices: QuickGive, LLC, 36098 Hees Street, Livonia, Michigan 48150.