Naturista Social: Naturist — Legal

Privacy Policy

Last updated: October 9, 2026

This Privacy Policy explains how SunSeekers ("SunSeekers," "we," "our," or "us") collects, uses, shares, keeps, and protects personal information when you use the mobile app published on the Apple App Store as SunSeekers and on Google Play as Naturista Social: Naturist (package com.sunseekers.android, developer listing "XcodeDeveloper"), together with our websites and related services (the "Service"). It applies worldwide. Region-specific sections cover the EU/EEA and UK (Section 12), California and other U.S. states (Section 13), and other countries (Section 14).

The short version:

1. Who Is Responsible for Your Data

SunSeekers is the controller of the personal data processed through the Service. Contact:

2. Information We Collect

2.1 Information you give us

Category Examples Required?
Account Email address; name; identifiers from Sign in with Apple (your Apple ID token and, if you share it, a real or relay email) or Google Sign-In; password (stored as a hash by our authentication provider) Yes
Age confirmation Your confirmation that you are 18+, birth date or age range, and age-assurance signals from Apple, Google, or your device where available Yes
Profile Username, display name, bio, profile and cover photos, country, state/province, city, age, gender, pronouns, naturist experience and interests, links Some fields optional
User Content Posts, photos, videos, stories, "memories," comments, reactions, polls, place reviews, event listings and RSVPs, group membership Optional
Messages and calls Direct and group messages, attachments, voice notes, and the audio of real-time calls and audio rooms, which we transmit but do not record Optional
Invites Invite or promo codes you enter. When you invite friends, you pick specific contacts with your device's contact picker, and only that contact's details are used to send the invite. We do not upload or store your address book. Optional
Reports and safety Reports you file, blocks, appeals, and any evidence you send us Optional
Support and feedback Messages to support, feature requests, survey answers Optional
Consent records Records of your acceptance of these policies, and of photo-consent confirmations Yes

2.2 Information collected automatically

Category Examples
Device and app Device model, OS version, app version, language, time zone, an app-generated install identifier, and push-notification tokens (Apple APNs / Firebase Cloud Messaging)
Log and security IP address, timestamps, request and error logs, crash reports, sign-in events, and fraud and abuse signals
Usage and analytics Screens viewed, features used, taps, onboarding steps, paywall views, and session length. These are keyed to a pseudonymous ID, not your name or email
Location Approximate location (country or region, derived from IP or your profile). Precise device location only if you grant permission, and only when you use a feature that needs it, such as "find nearby places" or tagging a post with your current area. You can turn this off at any time in your device settings
Purchases Subscription status, product, price tier, transaction and original-transaction IDs, renewal and cancellation events. We never receive your card or bank details

2.3 Information from others

2.4 Information we do not collect

3. How We Use Information, and Our Legal Bases

Purpose Data used Legal basis (EU/EEA/UK GDPR)
Create and run your account; provide the Service; show your profile and content to the audiences you choose; deliver messages and calls Account, profile, User Content, messages, device Contract (Art. 6(1)(b))
Sensitive information you choose to share (Section 4) Profile, User Content Explicit consent (Art. 9(2)(a)) and information you have manifestly made public (Art. 9(2)(e))
Precise location features Location Consent (Art. 6(1)(a))
Process subscriptions, restore purchases, prevent purchase fraud Purchases, account Contract; legal obligation (Art. 6(1)(c))
Safety, integrity, and moderation: detect, prevent, and act on CSAM, exploitation, non-consensual imagery, harassment, spam, fraud, ban evasion, and security threats All categories as needed, including reported messages Legitimate interests (Art. 6(1)(f)); legal obligation; vital interests (Art. 6(1)(d))
Age assurance Age confirmation, signals Legal obligation; legitimate interests (keeping minors off an adult service)
Push and in-app notifications Device tokens, activity Contract; consent where required (device permission)
Measure and improve the Service; debug; build new features Usage, device, logs (pseudonymous) Legitimate interests
Customer support, appeals, and communications about the Service Account, support messages Contract; legitimate interests
Legal compliance: responding to lawful requests, enforcing our Terms, establishing or defending legal claims As needed Legal obligation; legitimate interests

We do not use your personal data for third-party advertising, and we do not sell it. Where we rely on legitimate interests, we have weighed those interests against your rights. You can object at any time (Section 12).

4. Sensitive Information

Simply being a member of a naturist community, along with the photos, interests, and other details you share, may reveal or suggest sensitive information. Depending on the law that applies to you, this may include your beliefs or philosophy, your body, your sex or gender, your sexual orientation, or your sex life. Other laws treat some of this information as "special category" or "sensitive personal information." You decide whether to share it, and you can remove it at any time. We use it only to provide the Service as you direct and to keep the community safe. We do not use it for advertising, profiling, or to infer characteristics about you, and we do not sell or share it. Where the law requires it, we rely on your explicit consent, which you give when you choose to add the information. You can withdraw consent by deleting the information or your account.

5. How We Share Information

We do not sell personal information. We do not share it for cross-context behavioral advertising. We disclose information only as follows:

5.1 With other users and the public

Your username, display name, profile photo, and anything you post to public or community areas can be seen by other users, according to the audience and privacy settings you choose. Messages go to their recipients. Others can copy or screenshot what they see, so share carefully.

5.2 With service providers (processors)

These providers process data for us under contracts that limit their use of it to providing services to us:

Provider What they do Data involved Where
Supabase, Inc. Database, authentication, file storage, real-time sync, server functions Account, profile, content, messages, logs United States (primarily)
Cloudinary Ltd. Image and video hosting, resizing, delivery Photos and videos you upload United States / global CDN
LiveKit, Inc. Real-time audio for calls and audio rooms (transmitted, not recorded) Audio streams, IP address, room metadata United States / global
Ably Real-time Ltd. (Android) Real-time messaging delivery Message events, IP address EU / United States
Mixpanel, Inc. Product analytics Pseudonymous usage events, device info United States
Superwall, Inc. Paywall display and subscription status Pseudonymous ID, purchase events, device info United States
Apple Inc. Sign in with Apple, App Store payments, push notifications (APNs), age signals As needed for each function Global
Google LLC Google Sign-In, Google Play Billing, Firebase Cloud Messaging, age signals As needed for each function Global
GIPHY (Shutterstock) GIF search in chat Your GIF search terms and IP address United States
WishKit Feature requests and feedback Feedback you submit, pseudonymous ID EU / United States

We may update this list as our providers change. Where the law requires it, we will notify you of significant changes.

5.3 For safety and legal reasons

We may preserve and disclose information to law enforcement, government authorities, NCMEC, or others when we believe in good faith that it is reasonably necessary to:

  1. comply with law, regulation, legal process, or an enforceable government request;
  2. report apparent child sexual exploitation to NCMEC, as 18 U.S.C. § 2258A requires;
  3. prevent death or serious physical harm, or respond to an emergency;
  4. detect, investigate, and prevent fraud, abuse, or security issues;
  5. enforce our Terms, including investigating possible violations; or
  6. protect the rights, property, or safety of SunSeekers, our users, or the public.

Where the law permits, and unless doing so could put someone at risk, we try to tell users about requests for their data before we disclose it.

5.4 Business transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, personal information may be transferred as part of that transaction. It will remain subject to this Policy, or to a policy at least as protective, and we will notify you of any change in control.

5.5 With your consent

We may also share information when you direct us to, for example when you share a post outside the app.

6. On-Device Processing and AI Features

Some features use on-device artificial intelligence (Apple Intelligence / Foundation Models on supported iPhones). These include suggesting replies, helping you write a post or bio, suggesting tags, and pre-screening text for obvious violations before you post. On-device processing runs locally. That text is not sent to us or to any AI provider for these features. These features are optional, can make mistakes, and do not make final decisions about your account. Server-side moderation and human review remain authoritative.

When you share a link, your device may fetch that web page to build a preview. The website you link to will see that request.

We do not use your private messages or your photos to train AI models. We do not allow our providers to do so either.

7. Automated Moderation and Decisions

We use automated tools, including keyword filters, hash-matching against known illegal imagery, rate limits, and spam and fraud signals, to help find content and behavior that breaks our Terms. Automated tools may flag content for human review or apply temporary restrictions. We do not make decisions with legal or similarly significant effects based solely on automated processing without human involvement, and you can always appeal (see our Terms, Section 9).

8. How Long We Keep Information

Data How long
Account and profile While your account is active
User Content Until you delete it or your account
Messages Until deleted. Messages you sent are removed when you delete your account, but recipients' own copies and messages they sent to you may remain in their inbox
After account deletion Removed from production systems promptly, and from backups as they roll over, within 30 days
Pseudonymous analytics Up to 24 months, then deleted or aggregated
Logs and security records Up to 12 months, unless needed longer for an investigation
Safety exceptions If an account is removed for serious violations, we keep the minimum information needed to prevent the person from returning (such as hashed identifiers and the reason for removal) for up to 5 years. We keep content and records that are under a legal hold, preservation request, NCMEC report, or active investigation for as long as the law requires or the matter is open (18 U.S.C. § 2258A requires preservation for at least one year)
Purchase and tax records As long as tax and accounting law requires (generally up to 7 years)
Consent and request records As long as needed to show compliance (generally 3 years)

9. Security

We use administrative, technical, and physical safeguards designed to protect your information. These include encryption in transit (TLS), encryption at rest provided by our infrastructure providers, database row-level security, least-privilege access, Keychain/Keystore storage of sign-in credentials on your device, and monitoring for abuse. No system is perfectly secure, and we cannot guarantee absolute security. Protect your devices and accounts. If we learn of a data breach that affects your personal information, we will notify you and the relevant regulators as the law requires.

10. Children

The Service is strictly for adults 18+. We do not knowingly collect personal information from anyone under 18, and we do not allow minors to appear in any content. If we learn that a user is under 18, we close the account and delete the data, except data we must keep to report or prevent harm to a child (Section 8). If you believe a minor is using the Service or appears in content, report it in the app or email skaterdude5321@gmail.com right away. See our Child Safety Standards.

11. Your Choices and Rights (Everyone)

Wherever you live, you can:

We will respond within 30 days, or sooner or later if the law in your region sets a different deadline. We may need to verify your identity first, and we may decline requests that the law allows us to decline (for example, when the data is needed for an investigation). We will not discriminate against you for exercising your rights.

12. EU/EEA and UK Users (GDPR / UK GDPR)

Your rights: access; rectification; erasure; restriction; data portability; to object to processing based on legitimate interests (including profiling), with an absolute right to object to direct marketing; to withdraw consent at any time without affecting earlier processing; and not to be subject to solely automated decisions with legal or similarly significant effects.

Complaints: You can complain to your local data-protection authority. EU authorities are listed at edpb.europa.eu. In the UK, contact the ICO at ico.org.uk. We would appreciate the chance to resolve your concern first.

International transfers: We are based in the United States, and our providers process data in the U.S. and elsewhere. We protect transfers from the EU/EEA, UK, and Switzerland using the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and the EU-U.S. Data Privacy Framework where a recipient is certified, together with supplementary measures where appropriate. You can request a copy of the relevant safeguards from us.

EU/UK representative: If the law requires us to appoint a representative in the EU or UK, we will publish their details here. Until then, contact us directly.

Digital Services Act: Our single point of contact for users and authorities is skaterdude5321@gmail.com. Our Terms explain how to report illegal content and appeal moderation decisions.

13. U.S. State Privacy Rights

13.1 California (CCPA/CPRA): Notice at Collection and Rights

Categories collected in the past 12 months, with sources and purposes as described in Sections 2 and 3:

CCPA category Collected? Disclosed for a business purpose to
Identifiers (name, email, username, IP, device IDs) Yes Service providers (Section 5.2)
Customer records (Cal. Civ. Code § 1798.80(e)) Yes (name, email) Service providers
Protected-class characteristics (age, gender) Yes Service providers
Commercial information (subscription history) Yes Apple, Google, Superwall
Internet or network activity (usage, logs) Yes Service providers
Geolocation Approximate; precise only with permission Supabase
Audio, electronic, and visual information (photos, voice notes, live audio) Yes Service providers
Inferences Limited (product-preference segments) Mixpanel
Sensitive personal information: account login; precise geolocation (if enabled); contents of messages; information about sex life or sexual orientation, if you choose to share it Yes Service providers, only to provide the Service
Biometric information No —

Sale and sharing: We have not sold personal information, and we have not shared it for cross-context behavioral advertising, in the past 12 months. We have no actual knowledge of selling or sharing the data of consumers under 16.

Sensitive personal information: We use it only for purposes allowed under Cal. Code Regs. tit. 11, § 7027(m), so the "right to limit" does not require any action from you. You may still ask us questions about it.

Your rights: to know or access (categories and specific pieces); to delete; to correct; to opt out of sale or sharing (which we do not do); to limit the use of sensitive personal information; and not to receive discriminatory treatment for exercising your rights. You may use an authorized agent, and we may ask for proof of authorization and verify your identity. We honor Global Privacy Control (GPC) signals as opt-out requests where applicable.

Shine the Light (Cal. Civ. Code § 1798.83): We do not disclose personal information to third parties for their own direct marketing.

Retention: See Section 8.

13.2 Other U.S. states

If you live in a state with a comprehensive privacy law, such as Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you have rights to access, correct, delete, and port your data, and to opt out of targeted advertising, sale, and profiling in furtherance of significant decisions. We do not do any of those. We process sensitive data only with your consent, given when you choose to share it. To exercise your rights, email us. If we deny your request, you may appeal by replying with the subject "Privacy Appeal." We will respond within the legally required time. If your appeal is denied, you may contact your state Attorney General.

Nevada: We do not sell covered information as defined in NRS 603A.

14. Users in Other Countries (Global)

The Service is available worldwide. Wherever you live, you have every right that your local data-protection law gives you, and nothing in this Policy limits those rights. To use any of them, email skaterdude5321@gmail.com. Region-specific notes:

Region / law What applies to you
Switzerland (revFADP) Same rights as Section 12. Complaints go to the FDPIC. Transfers are protected by SCCs and the Swiss-U.S. Data Privacy Framework
Canada (PIPEDA, Québec Law 25, provincial laws) Access, correction, and withdrawal of consent. Québec users also have portability and de-indexing rights, and rights about automated decisions. Our privacy contact (Section 1) acts as the person in charge of personal information. Complaints go to the OPC or the CAI (Québec)
Brazil (LGPD) Confirmation, access, correction, anonymization, portability, deletion, information about sharing, and withdrawal of consent. Complaints go to the ANPD. Our contact in Section 1 acts as data-protection officer (encarregado)
Mexico, Argentina, Colombia, Chile, Peru, and other Latin American countries ARCO rights (access, rectification, cancellation, opposition) and similar rights under local law
United Kingdom See Section 12
Turkey (KVKK) Rights under Art. 11 of KVKK. We transfer data abroad on the basis of explicit consent or standard contracts, as the law requires
Israel (Privacy Protection Law) Access and correction rights
Saudi Arabia (PDPL), UAE (PDPL), Qatar, Bahrain Rights to information, access, correction, and destruction. Cross-border transfers comply with local rules
South Africa (POPIA) Access, correction, deletion, and objection. Complaints go to the Information Regulator
Nigeria (NDPA), Kenya (DPA) and other African countries Rights under local data-protection law
India (DPDP Act 2023) Access, correction, erasure, grievance redressal, and nomination. Contact our grievance officer at the email in Section 1, then the Data Protection Board of India
Japan (APPI) Disclosure, correction, and suspension of use. We disclose third-party transfers as described in Section 5
South Korea (PIPA) Access, correction, deletion, and suspension. Outsourced processing and overseas transfers are listed in Section 5.2
China (PIPL) The Service is not directed to mainland China. If PIPL applies to you, you have rights under PIPL Art. 44–50, and cross-border transfer relies on your separate consent
Singapore (PDPA), Thailand (PDPA), Philippines (DPA), Malaysia (PDPA), Indonesia (PDP Law), Vietnam (PDPD) Access, correction, and withdrawal of consent. Complaints go to your national authority
Australia (Privacy Act 1988, APPs), New Zealand (Privacy Act 2020) Access and correction. Complaints go to the OAIC or the NZ Privacy Commissioner

International transfers. Your information is processed in the United States and in other countries where our providers operate (Section 5.2). Data-protection laws there may differ from yours. Wherever your data is processed, we protect it as this Policy describes, using contractual safeguards (such as Standard Contractual Clauses), adequacy decisions, certifications, or your consent, as your law requires.

Language. If we provide this Policy in other languages and a version conflicts with the English one, the English version controls, except where your local law requires otherwise.

15. Do Not Track

There is no common standard for browser "Do Not Track" signals, so we do not respond to them. We do honor GPC as described in Section 13.1. We do not track you across third-party apps or websites.

16. Third-Party Links and Services

The Service links to, and integrates with, services we do not control, such as Apple, Google, GIPHY, and websites shared in posts. Their own privacy policies govern those services.

17. Changes to This Policy

We may update this Policy. If we make material changes, we will notify you in the app or by email before they take effect, and we will ask for your consent where the law requires it. The "Last updated" date at the top shows the latest revision. Earlier versions are available on request.

18. Contact Us

SunSeekers — Privacy Email: skaterdude5321@gmail.com (subject line "Privacy") Los Angeles, California, United States