Privacy Policy — Hotdog
Version 1.0.0 · Effective 2026-07-28This Privacy Policy applies to the Hotdog mobile application (iOS and Android), the related API and services we operate, and the website at hotdog.dating (together, the “Service”).
Who we are#
Textintel FZE (“we”, “us”, or “our”) is the data controller for personal data processed through the Service. On the Apple App Store we publish under the name Torapp.
Address: Starcamp Global, DWTC The Offices One, Office Number 01.03, UAE
Contact: support+hotdog@tor.app
We do not appoint an EU or UK representative or a dedicated Data Protection Officer for this Service.
Summary#
Hotdog is a dating app for pet owners. To use it you create an account with your phone number. You build a profile with photos, personal details, location, and preferences. That profile data is stored on our servers so other users can discover and message you.
We do not sell your personal data. We do not show third-party advertising in the app. Purchases go through the App Store or Google Play. To exercise your rights, delete your account, or request a copy of your data, email support+hotdog@tor.app or use the in-app delete path described below.
What we collect#
Account and identity#
| Data | Source | Required? |
|---|---|---|
| Phone number | You enter it at sign-in | Yes — needed to create an account |
| Authentication user ID | Assigned by Supabase Auth | Automatic |
| Profile ID | Assigned by us | Automatic |
| Account deletion reason | You select it when deleting | Optional |
We do not collect an email address as part of account creation. If you email support, we receive the address you send from and the content of your message.
Profile data you provide#
| Data | Required to create a profile? |
|---|---|
| Name | Yes |
| Date of birth (and derived age) | Yes — you must be 18 or older |
| Gender | Yes |
| Interested-in preferences | Yes |
| Height | Yes |
| Precise location (latitude and longitude) and neighborhood label | Yes — used for matching distance |
| Pet name and pet type | Yes |
| Relationship type | Yes |
| Ethnicity | Optional |
| Pet energy, pet age, pet living situation | Optional |
| Dating intention | Optional |
| Education, job title | Optional |
| Religion, politics | Optional |
| Drinking, smoking, marijuana, drugs habits | Optional |
Per-field visibility toggles (*_is_shown) | Defaults on; you can change them |
| Discovery preferences and filters (age range, distance, pet, lifestyle, values filters) | Optional after onboarding |
Gender, ethnicity, religion, politics, relationship preferences, and substance-use answers are sensitive personal data where applicable law treats them that way. You choose whether to provide optional fields.
Content you create#
| Data | Notes |
|---|---|
| Profile photos (human and pet) | Uploaded to our object storage and shown to other users according to your profile |
| Prompt answers | Text shown on your profile |
| Like comments | Text sent with a like |
| Chat messages | Text exchanged after a match |
| Pack Verification selfie | Optional identity check; stored in private object storage |
Technical and diagnostic data#
| Data | Source |
|---|---|
| Device model, OS version, app version | Device / SDKs |
| Crash logs and stack traces | Firebase Crashlytics |
| App usage and analytics events | Firebase Analytics |
| Push notification device token and platform | Firebase Cloud Messaging |
| Local app preferences and cached chat/profile data | Stored only on your device (shared_preferences, local database) |
Advertising identifiers may be available to Google Play services / Firebase on Android for analytics and fraud-prevention purposes. We do not use the App Tracking Transparency prompt on iOS, and we do not use your data to track you across other companies’ apps and websites under Apple’s definition of tracking.
Purchase data#
We do not receive your full payment card number. Apple or Google processes payment. Through Adapty and store receipts we receive purchase and entitlement information (subscription tier, expiry, consumable balances, store product identifiers) linked to your account ID.
Device permissions#
| Permission | What we use it for |
|---|---|
| Camera | Taking profile photos; Pack Verification still photos |
| Photo library | Selecting profile photos |
| Location (when in use) | Setting your match location and neighborhood during onboarding / profile setup |
| Notifications | Sending push and local notifications about likes, matches, and messages |
We do not collect or record microphone audio. Your device may still show a microphone-related permission string because a third-party library declares it; Hotdog does not use the microphone.
What stays on your device#
Local preferences, measurement units, and locally cached chat or profile data stay on your device until you sign out or clear app data. Profile photos, messages, and account data that power the Service leave your device and are stored on our servers and providers listed below.
Why we use it, and on what basis#
| Purpose | Data used | Legal basis | Retention |
|---|---|---|---|
| Create and secure your account (SMS OTP) | Phone number, auth user ID | Contract | Until account deletion, then as in “How long we keep it” |
| Show your profile to other users and power discovery | Profile fields, photos, preferences, location | Contract | Until you delete or we remove the account |
| Matching, likes, and chat | Profile, likes, comments, messages | Contract | Messages and match history until account deletion / purge |
| Pack Verification | Verification selfie, reference profile photo | Contract (optional feature); legitimate interests in reducing fake accounts | Private verification images purged after verification, rejection, or expiry |
| Push notifications | Device token, notification content metadata | Contract; consent where the OS requires notification permission | Until you revoke permission, uninstall, or we delete the token on account deletion |
| Process subscriptions and consumables | Purchase receipts, entitlement state, account ID | Contract; legal obligation for tax/accounting records where required | Entitlement state while account exists; purchase records up to 10 years where tax law requires |
| Analytics and product improvement | App usage events, device and app metadata | Legitimate interests — understand feature use and improve the Service | Kept for analytics while we operate the Service; not part of your user profile after account purge |
| Crash diagnosis | Crash logs, device and app metadata | Legitimate interests — keep the Service stable and fix bugs | Kept for debugging while we operate the Service; not part of your user profile after account purge |
| Customer support | Email address and message content you send | Legitimate interests — respond to your request; contract if about your account | Support correspondence retained as needed to resolve the request, then deleted or archived under ordinary email retention |
| Safety, abuse prevention, and legal compliance | Reports, blocks, account status, relevant profile/content | Legitimate interests — protect users and the Service; legal obligation when required | Reports and ban records retained as needed for safety; deletion pointers retained after purge (see below) |
| Enforce age restriction (18+) | Date of birth | Legal obligation / legitimate interests — keep minors off the Service | Until account deletion |
Where we rely on legitimate interests, you may object by emailing support+hotdog@tor.app. Where processing is based on consent (for example OS-level notification or location permission), you withdraw it in your device settings.
We do not use your photos or chat content to train general-purpose AI models for third parties. Pack Verification and photo embedding features use automated processing solely to operate those features of the Service.
Who receives it#
We share personal data with the following recipients, only as needed for the roles below.
| Recipient | Role | Data | Privacy information |
|---|---|---|---|
| Supabase | Authentication and primary database | Phone/auth data, profiles, preferences, likes, matches, messages, reports, blocks, device tokens, entitlements metadata | supabase.com/privacy |
| Twilio (via Supabase Auth) | SMS delivery for one-time passcodes | Phone number, OTP message metadata | twilio.com/legal/privacy |
| Cloudflare (Workers, R2, and related infrastructure) | Hosts our API and stores profile / verification images | API traffic; photo and verification objects | cloudflare.com/privacypolicy |
| Cloudflare Workers AI | Pack Verification analysis | Verification selfie and reference photo as needed for the check | Cloudflare privacy policy above |
| Google Cloud (Vertex AI) | Photo embeddings used for discovery features | Profile photo bytes | cloud.google.com/terms/cloud-privacy-notice |
| Upstash Redis | Caching and rate limiting | Account/session keys, subscription tier cache | upstash.com/trust/privacy.pdf |
| Firebase Crashlytics (Google) | Crash reporting | Crash diagnostics, device and app metadata | firebase.google.com/support/privacy |
| Firebase Analytics (Google) | Product analytics | App usage events, device and app metadata | firebase.google.com/support/privacy |
| Firebase Cloud Messaging (Google) | Push delivery | Device tokens; notification payloads | firebase.google.com/support/privacy |
| Adapty | Subscription and entitlement infrastructure | Account ID, purchase and access events | adapty.io/privacy |
| Apple / Google | App distribution and payment (merchants of record) | Store account, purchase receipts | apple.com/legal/privacy · policies.google.com/privacy |
| Google Maps Platform / Geocoding / Geolocator stack | Maps UI and reverse geocoding for neighborhood labels | Location coordinates you grant | policies.google.com/privacy |
Google ML Kit Face Detection runs on your device during Pack Verification to check that a face is present. Those frames are not uploaded for that on-device check.
Other users of Hotdog receive the profile information and content you choose to make visible (photos, prompts, visible profile fields, like comments you send them, and chat messages in a match).
We do not sell personal data. We do not share personal data for cross-app advertising. If a corporate transaction (merger, acquisition, or asset sale) involves Hotdog, personal data may transfer to the successor under this policy.
International transfers#
Primary hosting and processing for the Service is in the United States. Providers listed above may also process data in other countries.
If you access the Service from outside the United States, your data is transferred to and processed in the United States and in other countries where our providers operate.
How long we keep it#
| Category | Retention |
|---|---|
| Active account and profile | Until you delete your account or we terminate it |
| Soft-deleted account | About 30 days after deletion, then hard-purged from the primary database and associated photo storage |
| Permanent deletion pointer | After purge we keep a user_pointers record (internal user ID, auth ID, deletion reason, deleted-at timestamp) so we can handle re-registration and abuse — not your full profile |
| Chat messages and likes | Removed with your account according to the soft-delete then purge process; matched users may retain their own copy of messages until their accounts are deleted |
| Pack Verification images | Removed after the verification flow completes (verified, rejected, or expired) under our cleanup jobs |
| Device tokens | Deleted when the account is deleted or the token is replaced |
| Purchase / entitlement records | Kept while needed to provide the purchase and for legal/accounting obligations |
| Analytics and crash data | Kept for product analytics and debugging while we operate the Service; separate from your deleted profile after purge |
| Support emails | For as long as needed to handle your request |
Your rights and how to use them#
Depending on where you live (including GDPR/UK GDPR and CCPA/CPRA), you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data (you can edit most profile fields in the app)
- Delete your data (see Account deletion)
- Receive a portable copy of your data
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Opt out of “sale” or “sharing” for cross-context behavioral advertising — we do not sell or share data for that purpose
- Non-discrimination for exercising privacy rights
How to request: email support+hotdog@tor.app from the contact details tied to your account when possible, and tell us what you need (access, correction, deletion, or export).
Data export: there is no in-app export button. We handle portability requests by email.
Response time: we aim to respond within 30 days (or sooner where local law requires).
EEA and UK users may also lodge a complaint with their local supervisory authority.
Account deletion#
In the app:
- Open Profile → Settings
- Tap Delete Account
- Choose a reason (optional) and confirm on the approval screen
That signs you out and starts soft deletion. After about 30 days we hard-purge your profile and media, subject to the limited pointer and legal retention described above.
If you cannot use the in-app path, email support+hotdog@tor.app and ask us to delete your account. Include your phone number or user ID if you have it.
Deleting the app from your device does not delete your account.
Tracking, analytics, and advertising#
- Hotdog does not include a third-party ad network.
- We use Firebase Analytics for product analytics.
- We do not request App Tracking Transparency permission on iOS.
- Under Apple’s definition, we do not track you across other companies’ apps and websites to target advertising.
- On Android, advertising ID access may be used by Google services for analytics and fraud prevention as disclosed in our store listings.
- You can limit ad personalization and analytics-related identifiers in your device settings (iOS: Settings → Privacy & Security; Android: Google settings → Ads / privacy).
Children#
Hotdog is for adults only. You must be at least 18 to create an account. The app is not directed to children under 13 (or the equivalent age in your region), and we do not knowingly collect personal data from them.
If we learn that a user is under 18, we will delete the account. Report underage users with the in-app Report flow (reason includes underage / minor) or email support+hotdog@tor.app.
Security#
We protect personal data with measures appropriate to the Service, including:
- Encryption in transit (HTTPS/TLS) between the app and our API
- Access controls on our backend and database
- Separation of public profile images from private verification images
- On-device face presence checks for Pack Verification UX
No method of transmission or storage is completely secure. If you believe your account is compromised, contact us immediately.
The website#
This policy also covers hotdog.dating, where this document is published.
The site does not use cookies, analytics scripts, or non-essential tracking technologies at this time. If that changes, we will update this section.
Support contact on the site uses the same email: support+hotdog@tor.app.
Changes to this policy#
We may update this Privacy Policy when the Service or the law changes. We will post the new version at https://hotdog.dating/privacy-policy/ with a new effective date. Material changes may also be signaled in the app. Continued use after the effective date means you accept the updated policy.
Contact#
Textintel FZE
Starcamp Global, DWTC The Offices One, Office Number 01.03, UAE
Starcamp Global, DWTC The Offices One, Office Number 01.03, UAE
Email: support+hotdog@tor.app
If you are in the EEA or UK, you have the right to complain to your data protection supervisory authority.
Change history#
| Version | Effective date | Notes |
|---|---|---|
| 1.0.0 | 2026-07-28 | Initial Hotdog Privacy Policy |