CIRL Privacy Notice Terms package 2026-09-12

This notice describes how Michael Christen (Connect In Real Life / CIRL), Champs Thiébauts 12, 2735 Valbirse, Switzerland, processes personal data. Contact: support@cirl.app.

This is not blanket consent to every processing activity. Agreeing to the Terms of Service is separate. Sensitive matching (using sexual orientation and family-plan fields in Discover filters and CIRL Match) is off unless you opt in, with no pre-ticked boxes. CIRL Match readings are part of providing the score explanation: names, bios, shared interests, and the match percent may be sent to the configured large-language-model (LLM) host. Orientation and family-plan values are not put in that prompt unless you opted into sensitive matching. If the host is down, CIRL uses a local template.

Unverified: launch countries, hosting/backup country of the Virtual Private Server (VPS), and processor contracts are not fully recorded yet. Present-tense vendor statements below match what the current software actually does.

1. Categories of data Depending on how you use CIRL, we may process:

- Account: email, password hash (not the password itself), role, signup device fields (operating system, app version, language, time zone), signup Internet Protocol (IP) address, session tokens.
- Profile: display name, @handle, photo, bio, interests (including want/avoid), languages, intentions (friendship / relationship / connection goals).
- Optional intimate fields: gender, sexual orientation, height, education, occupation, drinking, smoking, exercise, pets, family plans, communication style, love language, Myers–Briggs type, birth date/time/place/coordinates, natal-chart style text. These do not raise the access-score used for feature unlocks.
- Area and availability: a manually entered broad area (city or region) can earn access points. Device Global Positioning System (GPS) and home coordinates are optional. Birthplace is for optional astrology, not for earning access.
- Use of the service: activities you create or join, messages, groups, saved searches, reports and optional screenshots, Discover “first shown” records, access logs, feature-unlock and (when launched) reward records.
- Computed data: CIRL Match scores and embeddings, cached explanations, optional large-language-model (LLM) bios or talk drafts.
- ChatGPT connected app: if you connect ChatGPT to CIRL (Developer Mode / custom connector), ChatGPT may send relevant memory or conversation excerpts to CIRL only after you connect and authorize a write. CIRL stores only the catalog profile fields you allow (for example interests, languages, occupation). CIRL does not accept sexual orientation, politics, religion, or Myers–Briggs type from that connector.
- Speech: if you use voice typing, the phone may send audio to a platform/cloud speech service (`onDevice: false`). CIRL then stores the text, not a promise that audio never left the device.
- Maps: your device fetches map tiles from CARTO / OpenStreetMap. CIRL does not proxy those tiles on our server.

Database fields on the profile are stored in PostgreSQL without field-level encryption. Transport uses Hypertext Transfer Protocol Secure (HTTPS). We do not claim end-to-end encryption of messages or encryption at rest.

2. Why we use data (purposes) - Run, secure, and debug CIRL (account, sessions, abuse prevention). - Show you activities and people according to your settings and the server-side access ladder. - CIRL Match as a **computed suggestion**, not a probability that a relationship will work. Astrology text is optional interpretation, not a validated prediction. - Email you one-time codes and important account mail via the configured mailbox (Namecheap Private Email for `support@cirl.app` when that password is set). - Handle reports and keep a limited safety trail. - Optional writing helpers: when an Application Programming Interface (API) helper is configured, prompts can include text you typed. CIRL Match readings may include **two** users’ names, bios, shared interests, and match score sent to the configured LLM host so the explanation can improve. That helper is part of providing CIRL Match text (not an off switch). Local template if the host is down. Orientation and family-plan values are omitted unless you opted into sensitive matching.

We load Google Mobile Ads (AdMob) on Android and iOS only, for optional rewarded ads that Community members can watch to unlock a named reach boost. Ads are not loaded on web or desktop. We do not sell your personal information for money to data brokers. Watching a rewarded ad is not consent to personalized advertising.

3. Legal bases (where the General Data Protection Regulation (GDPR) or Swiss Federal Act on Data Protection (FADP) apply) Launch markets are not finally declared. If those laws apply:

- Contract: account, core app features you request, including CIRL Match readings that may call the configured LLM host.
- Legitimate interests: security logs, fraud, aggregated product improvement that does not require sensitive data.
- Consent: optional sensitive matching (orientation and family-plan fields used in Discover filters / matching), optional natal fields, optional precise location. Withdrawal does not remove unrelated earned access (the access-score floor is kept).
- Legal obligation: where we must keep or disclose records.
- Article 9 GDPR (special categories): sexual orientation and similar data are used for matching only with explicit opt-in. A hidden field is not used as a Discover filter against people who did not opt in, so others cannot infer it from search results.

We have not appointed a Data Protection Officer (DPO) or an EU representative. Whether those are required depends on markets and processing scale — that is still an owner decision.

4. Who sees what You choose field visibility (only you / friends / wider) on Edit profile. That controls **profile display**. It is not the same as matching consent. Staff (the operator, and any future support person) can see reports, messages needed for a report, and account records in admin/ops tools. Other users see what your visibility and Discover settings allow.

5. Recipients and locations - CIRL application database and file storage on the configured server (country **unverified** in the owner-decisions file). - Email delivery provider when mail is enabled. - Map tile providers on your device (CARTO, OpenStreetMap). - Optional inference host (`AI_BASE_URL`) and, if configured, an OpenAI-compatible compatibility request. - Apple/Google if you later buy a store subscription (not launched). - Authorities if the law requires it.

International transfers are not documented with signed processor clauses in this repository. Treat that as an open operator task before public launch in the EU.

6. Retention (engineering targets, not a legal safe harbor) These numbers are **not** yet run as live cleanup jobs against real users:

| Record | Target idea |
|---|---|
| Active account | Until you delete it or we close it |
| Ordinary account data after a verified deletion request | Aim to erase from live systems within 30 days |
| Access logs / archives | About 90 days |
| Bug screenshots | After the report is done, with a 90-day default cap — still partly a TODO in code |
| Backups | Rolling; a deleted account must not be restored as a live user |
| Safety reports, bans, legal holds | Kept only as long as needed for the incident or the law |
| Optional AI drafts after you withdraw consent | Remove from active stores and caches |

Safety is not a reason to keep everything forever. Legal holds are recorded per case.

7. Your rights Depending on the law that applies, you may ask for access, correction, deletion, restriction, objection, and portability. You may withdraw consent without losing unrelated features. We will ask enough to verify it is you. We will not put another person’s messages or password hashes in your export.

Complaints: support@cirl.app. You may also contact the Swiss Federal Data Protection and Information Commissioner, and if you are in the European Economic Area, your local data protection authority.

How to delete: in the app (Settings → Delete my account) or the public page `/legal/delete-account` (also linked from the website). Legal documents are a separate list under Settings → Legal / About CIRL → Legal documents. You do not need to reinstall the app to learn how. Closing (hiding) an account is not the same as erasure.

8. Children CIRL is 18+. We will close underage accounts we learn about.

9. Changes We will post a new version date. A new Privacy Notice is not automatically new consent. Material new purposes need a fresh lawful basis.

10. Contact support@cirl.app — Michael Christen, Champs Thiébauts 12, 2735 Valbirse, Switzerland.