Version 2.0 · 20 June 2026 · Effective immediately · Deutsche Fassung
Privacy Policy
1. Controller and Contact
Hoorly ("we", "us", "the Service") is an 18-and-over dating, chat and social-discovery application for LGBTQ+ users. The data controller responsible for processing your personal data is:
Özgür Kabakcioğlu (Einzelunternehmen), trading as "Hoorly"
Gmelinstr. 73, 72076 Tübingen, Germany
E-mail: support@hoorly.com
Full provider identification: Impressum
If you are located in the European Union or European Economic Area, we act as the controller within the meaning of Article 4(7) GDPR.
2. Categories of Personal Data We Collect
The data we process depends on how you use Hoorly. It may include:
| Category | Examples |
|---|---|
| Account & identity | E-mail address, password hash, date of birth, user ID, authentication tokens (Google, Apple sign-in) |
| Profile information | Display name, username, age, bio, orientation, body type, position, pronouns, relationship goals, tribes, interests, height, weight |
| Photos & media | Profile photos, private album photos, story images, post images, verification selfies |
| Communications | Direct messages (text, photos, stickers, locations), post comments, story replies, emoji reactions |
| Social interactions | Taps, likes, follows, matches, blocks, reports |
| Location data | Approximate GPS coordinates (latitude/longitude), country code, city. Precise location is never shared with other users; only approximate distance is displayed. |
| Travel mode data | Virtual city, coordinates and session timestamps for premium Travel Mode feature |
| Device & technical | Device model, OS version, IP address, push-notification token (OneSignal player ID), app version, session timestamps |
| Purchase data | Premium subscription status, plan type, expiry date. We do not process or store payment card numbers; all payments are handled by Google Play or Apple App Store. |
| Moderation & safety | Automated NSFW scores, moderation flags, ban history, verification status, report content |
| Crash & diagnostics | Crash stack traces, device model, OS version, app version, IP address (processed transiently for event delivery). Collected via Sentry only when the app malfunctions; no advertising use. |
| Consent records | GDPR consent timestamp, privacy-policy version accepted, advertising consent (UMP/CMP) |
3. Special Category Data (GDPR Article 9)
Because Hoorly is designed for LGBTQ+ users, your use of the Service and the profile information you provide may reveal or imply your sexual orientation, gender identity or related characteristics. Under EU/EEA law, this constitutes special category data within the meaning of Article 9 GDPR.
We process this data solely on the basis of your explicit consent (Article 9(2)(a) GDPR), which you provide when you create your account and accept this Privacy Policy. You may withdraw your consent at any time by deleting your account (Settings → Account → Delete Account). Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
4. Purposes and Legal Bases for Processing
| Purpose | Legal basis (GDPR) |
|---|---|
| Account creation and authentication | Performance of a contract (Art. 6(1)(b)) |
| Profile display, nearby discovery, matching, messaging | Performance of a contract (Art. 6(1)(b)) |
| Location-based features (Nearby, Travel Mode) | Consent (Art. 6(1)(a)) |
| Content moderation, NSFW detection, abuse prevention | Legitimate interest in user safety (Art. 6(1)(f)) |
| Identity verification (selfie review) | Legitimate interest / consent (Art. 6(1)(f)/(a)) |
| Push notifications (messages, taps, matches) | Consent (Art. 6(1)(a)) |
| Advertising (banner ads via Google AdMob) | Consent (Art. 6(1)(a)), managed via UMP/CMP |
| Premium subscriptions and in-app purchases | Performance of a contract (Art. 6(1)(b)) |
| Analytics, crash reporting, performance monitoring | Legitimate interest (Art. 6(1)(f)) |
| Legal compliance, law-enforcement requests | Legal obligation (Art. 6(1)(c)) |
| Fraud prevention, ban enforcement | Legitimate interest (Art. 6(1)(f)) |
5. Location Data and Privacy Controls
Hoorly uses your device's GPS to calculate approximate distance to other users. Your exact coordinates are never shared with other users. You may:
- Hide your distance — other users will not see how far you are.
- Blur your location — your coordinates are randomized within a radius to prevent precise triangulation.
- Disable location — you may revoke location permission in your device settings at any time. Some features (Nearby) will be unavailable.
6. Data Sharing and Sub-processors
We do not sell your personal data. We share data only with the following categories of service providers, acting as data processors under written data-processing agreements:
| Provider | Purpose | Location |
|---|---|---|
| Supabase (AWS) | Database hosting, authentication, edge functions | EU (Frankfurt) |
| Cloudflare R2 | Photo and media object storage | EU/Global CDN |
| Cloudflare Workers | Website hosting and image delivery | Global CDN |
| Sentry (Functional Software, Inc.) | Crash and error reporting | EU (Frankfurt ingestion) |
| OneSignal | Push notifications | USA |
| Google AdMob | In-app advertising | USA/Global |
| RevenueCat | Subscription management | USA |
| Sightengine | Automated content moderation (NSFW detection) | EU |
| Google / Apple | Authentication (Sign-In), payment processing | USA/Global |
Where data is transferred outside the EU/EEA, we rely on EU Standard Contractual Clauses (SCCs) or an adequacy decision, as applicable.
7. Data Retention
- Active accounts: Data is retained for the duration of your account.
- Account deletion: When you delete your account (Settings → Account → Delete Account), we permanently delete your profile, photos, messages, posts, stories and associated data within 30 days. Photos are removed from cloud storage.
- Moderation records: Ban history and report records may be retained for up to 3 years to prevent abuse recurrence and comply with legal obligations.
- Payment records: Transaction metadata may be retained for up to 10 years as required by German tax law (AO §§ 147, 257 HGB).
- Deletion audit log: A minimal pseudonymous record (hashed user ID, deletion date) may be retained to demonstrate compliance with deletion requests.
8. Your Rights Under GDPR
If you are located in the EU/EEA, you have the following rights:
- Right of access (Art. 15) — request a copy of your personal data.
- Right to rectification (Art. 16) — correct inaccurate data via your profile or by contacting us.
- Right to erasure (Art. 17) — delete your account and data. Available in-app: Settings → Account → Delete Account.
- Right to restriction (Art. 18) — request that we limit processing in certain circumstances.
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format. Available in-app: Settings → Privacy → Export My Data.
- Right to object (Art. 21) — object to processing based on legitimate interest.
- Right to withdraw consent (Art. 7(3)) — withdraw consent at any time without affecting prior lawful processing.
To exercise any right, contact support@hoorly.com. We will respond within 30 days. You also have the right to lodge a complaint with a data-protection supervisory authority (Art. 77 GDPR) — either in your habitual place of residence or with the authority competent for us: Landesbeauftragter für den Datenschutz und die Informationsfreiheit Baden-Württemberg (baden-wuerttemberg.datenschutz.de).
9. Advertising and Consent Management
Hoorly displays banner advertisements via Google AdMob. For users in the European Economic Area, we obtain advertising consent through a Consent Management Platform (CMP) compliant with the IAB TCF v2.2 framework, as required by Google. You may change your advertising preferences at any time in Settings → Privacy → Ad Privacy.
We use the Google Advertising ID solely for ad personalization and measurement. You may reset or disable this ID in your device settings.
10. Automated Decision-Making
Hoorly uses automated content moderation (Sightengine) to detect and flag potentially unsafe images (NSFW content). Flagged content may be automatically rejected or queued for human review. This processing is based on our legitimate interest in maintaining a safe environment (Art. 6(1)(f) GDPR). You may contest any automated decision by contacting support@hoorly.com.
11. Security Measures
We implement appropriate technical and organizational measures to protect your data, including:
- Encrypted data transmission (TLS/HTTPS)
- Row-level security (RLS) on database tables
- Hashed and salted password storage (via Supabase Auth / bcrypt)
- Principle of least privilege for server-side functions
- Regular access reviews and security auditing
12. Children
Hoorly is strictly limited to users aged 18 and older. We do not knowingly collect data from anyone under 18. If we discover that a minor has created an account, we will immediately terminate the account and delete all associated data. If you believe a minor is using Hoorly, please report it to support@hoorly.com.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via in-app notice or push notification before they take effect. The "Version" and "Effective" date at the top of this page indicate the current version.
14. Contact
Privacy inquiries: support@hoorly.com
General support: support@hoorly.com