← Back to Smolder
Privacy Policy
Effective Date: February 15, 2026 | Last Updated: May 29, 2026
Smolderâ„¢ is an intimacy app built for couples who value depth, trust, and connection. We take your privacy as seriously as we take your relationship. This policy explains exactly what data we collect, why we collect it, how it is stored and protected, and what rights you have over your information.
Smolder is operated by Smolder Intimacy, a Canadian company ("we," "us," "our"). This Privacy Policy applies to the Smolder mobile application (iOS) and the website at smolderintimacy.com. By using Smolder, you agree to the practices described below.
Given the intimate nature of our app, we want to be unambiguous: we have designed our entire data architecture around the principle of collecting the absolute minimum data necessary, and we have built deliberate technical barriers between your identity and your activity within the app.
1. Information We Collect
1.1 Account Information (Personally Identifiable)
When you create a Smolder account, we collect:
- Email address, used solely for authentication (login/password reset)
- Display name, a name you choose to be shown in the app
- User ID (UUID), a unique identifier generated by our authentication system to link your account to your profile
- Authentication provider, whether you signed in via email/password, Apple Sign-In, or Google Sign-In
This is the only personally identifiable information (PII) we store. We do not collect your real name, phone number, home address, date of birth, gender, sexual orientation, or any other demographic information.
1.2 Profile Preferences
To personalize your experience, we store:
- Excluded content categories (content types you have chosen to skip)
- Intensity preferences (your comfort level settings)
- Favorite vibes (journey styles you prefer)
- Onboarding completion and consent confirmation status (boolean flags only)
These preferences are functional settings that control what content you see. They do not reveal details about your intimate activities.
1.3 Analytics Data (Kept Separate from Your Identity)
We track app usage for product improvement, and we keep that usage separate from your identity. Analytics are recorded under a dedicated activity token rather than your name or email.
Here is how that separation works:
- When you use the app, a dedicated activity token (UUID) is generated. Analytics events and saved cards are recorded under this token, not under your name or email.
- We do not attach your identity to individual analytics events. We use them only in aggregate, to understand which features and content work.
- Your account stores a reference to your activity token so your saved cards and preferences follow you if you reinstall the app or sign in on a new device. This recovery reference is the one place the two are associated, and it is protected by row-level security so only you can read your own record.
- A separate session ID (UUID) is stored locally on your device and used only to group analytics events from the same session. It is never linked to your user identity.
The anonymized analytics events we track include:
- Event type (e.g., "journey_started," "card_skipped," "card_saved," "journey_completed")
- Event metadata (e.g., which journey type was selected, how many cards were viewed, whether the deep work toggle was enabled)
- Tier and tone tag of content shown (e.g., Tier 1 light question vs. Tier 3 intimate prompt)
- Timestamp of the event
We use this data solely to understand which features are used, which content resonates, and how to improve the app. We never use it to build an individual profile of you or your intimate life, and we never sell or share it.
1.4 Saved/Favorited Cards
If you save or favorite a card, we store:
- The card ID (a text identifier referencing our content library)
- Your activity token (anonymized, not linked to your account)
- A soft-delete timestamp if you remove the favorite (allowing undo functionality)
We do not store what you discussed, what you did, or any outcomes of using a card.
1.5 Aggregate Card Statistics
We maintain aggregate, non-identifiable statistics on our content:
- How many times a card has been viewed, skipped, or saved across all users
These statistics contain no user-identifiable data whatsoever. They exist solely to help us understand which content is most valuable.
1.6 Subscription Information
If you purchase a Smolder subscription, we use RevenueCat to manage your subscription across devices. RevenueCat records:
- Your subscription status and the Apple receipt for your purchase
- A device-level identifier and your purchase history
RevenueCat does not receive your name, email, or payment card details. Apple processes the payment itself, and we never see your card information.
2. What We Do NOT Collect
We want to be explicit about what Smolder never collects, stores, or has access to:
- No details about your intimate activities, conversations, or experiences
- No location or GPS data
- No contacts, photos, camera, or microphone access
- No device identifiers beyond what the Expo framework provides for basic functionality
- No biometric data
- No health or medical data
- No payment card or banking data. Apple processes all payments, and neither we nor our subscription manager ever see your card details
- No browsing history or data from other apps
- No third-party behavioral analytics services (no Google Analytics, no Facebook SDK, no Mixpanel, no Amplitude, no Segment, or any other tracking platform)
- No advertising SDKs or ad tracking of any kind
- No cross-app tracking or fingerprinting
Your data is never sold, rented, traded, or shared with third parties for marketing, advertising, or any commercial purpose.
3. How Data Is Stored and Protected
3.1 On Your Device
- PII (email, name) is stored locally using iOS Keychain via expo-secure-store, which provides hardware-level encryption
- Non-sensitive app state (card progress, streaks, visual preferences) is stored in AsyncStorage on your device
3.2 On Our Servers
- Backend data is hosted on Supabase (PostgreSQL), which is SOC 2 Type II compliant
- Row-Level Security (RLS) is enforced on every database table, meaning users can only read, update, or delete their own data
- All API communication uses SSL/TLS encryption in transit
- Analytics data uses anonymized activity tokens with no connection to user accounts
3.3 Additional Security Measures
- Client-side authentication rate limiting (5 attempts per minute) to prevent brute-force attacks
- Network request timeouts (15-20 seconds) with AbortController to prevent hanging connections
- Generic error messages returned to the client (no internal system details are ever leaked)
- Passwords are cleared from memory immediately after authentication attempts
- No sensitive data is written to console logs in production builds
4. Third-Party Services
Smolder uses the following third-party services, and only these:
- Supabase: Database hosting, user authentication, and serverless edge functions. Supabase is SOC 2 Type II compliant. Their privacy policy.
- Sentry: Error monitoring and crash reporting only. No personally identifiable information is transmitted to Sentry. Sentry is SOC 2 Type II compliant. Their privacy policy.
- Expo/EAS: App build, deployment, and over-the-air updates. When the app checks for an update, Expo receives basic technical data such as device platform, app version, and a non-personal install identifier. Expo does not receive your account information or in-app activity.
- RevenueCat: Subscription management. When you start a subscription, RevenueCat records your subscription status and Apple receipt so your access works across your devices. It receives a device-level identifier and your purchase history. It does not receive your name, email, or payment card details, and Apple processes the payment itself. Their privacy policy.
- Apple: Sign-In with Apple authentication and App Store payment processing. Apple handles all payment data; Smolder never sees your payment information.
- Google: Google Sign-In authentication only.
We do not use any advertising networks, data brokers, social media SDKs, or cross-app tracking platforms.
5. Children's Privacy and Age Restrictions
Smolder is strictly for adults aged 18 and older. This is not a guideline; it is a firm requirement enforced at multiple levels.
- During onboarding, users must affirmatively confirm: "We're both 18+, consenting adults who agree to the Terms and Privacy Policy" with tappable links to both documents
- The app is rated 17+ on the Apple App Store
In compliance with the Children's Online Privacy Protection Act (COPPA) and equivalent international regulations:
- We do not knowingly collect, use, or disclose personal information from anyone under the age of 18
- If we discover that a user is under 18, we will immediately terminate their account and permanently delete all associated data
- If you believe a minor has created a Smolder account, please contact us immediately at Whisper@SmolderIntimacy.com
6. Your Rights
6.1 Account Deletion
You can delete your Smolder account at any time from the Settings screen within the app. When you delete your account:
- Your profile data (email, name, preferences) is permanently deleted from our servers
- Your saved/favorited cards are permanently deleted
- Your authentication credentials are removed
- Anonymized analytics data (tied to your activity token, not your identity) may be retained in aggregate as it cannot be traced back to you
6.2 Data Minimization
We collect only what is necessary for the app to function. We regularly review our data practices to ensure we are not collecting more than needed.
6.3 GDPR and European Users
If you are located in the European Economic Area, United Kingdom, or another jurisdiction with equivalent data protection laws, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Object to or restrict certain data processing
- Data portability (we do not currently offer an automated export, but will fulfill requests manually)
To exercise any of these rights, contact us at Whisper@SmolderIntimacy.com. We will respond within 30 days.
6.4 California Residents (CCPA)
If you are a California resident, you have the right to know what personal information we collect and how it is used, request deletion of your personal information, and opt out of the sale of personal information. We do not sell personal information. To make a request, contact Whisper@SmolderIntimacy.com.
6.5 Canadian Users (PIPEDA)
Smolder Intimacy is a Canadian company and is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA). Under PIPEDA, you have the right to:
- Know what personal information we hold about you and why we collect it
- Access your personal information upon written request
- Challenge the accuracy and completeness of your personal information and have it amended as appropriate
- Withdraw your consent to the collection, use, or disclosure of your personal information, subject to legal or contractual restrictions and reasonable notice
- File a complaint with the Office of the Privacy Commissioner of Canada if you believe your privacy rights have been violated
We collect personal information only for purposes that a reasonable person would consider appropriate in the circumstances. We obtain meaningful consent for the collection, use, and disclosure of personal information, and we retain personal information only as long as necessary to fulfill the purposes for which it was collected.
To make a PIPEDA-related request or inquiry, contact us at Whisper@SmolderIntimacy.com. We will respond within 30 days.
7. Data Retention
- Account data is retained for as long as your account is active
- Upon account deletion, PII is permanently removed within 30 days
- Anonymized, aggregate analytics data may be retained indefinitely as it contains no personal information
- Backup systems may retain encrypted copies for up to 90 days after deletion, after which they are purged
8. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app or via email. Continued use of Smolder after changes take effect constitutes acceptance of the updated policy.
9. Contact Us
For any privacy-related questions, concerns, or data requests:
Email: Whisper@SmolderIntimacy.com
Website: smolderintimacy.com
Your privacy matters. Your intimacy is yours. We just provide the sparks.