Privacy Policy
Effective date: August 27, 2026
Duuble is a social network for profiles, hubs, posts, anonymous vote aggregates, vote receipts, comments, saved hub discussions, notifications, reports, blocks, and media uploads. This policy explains the data handled by the app and backend services.
Information We Collect
- Account and sign-in information, such as phone number, session tokens, and accepted policy versions.
- When an active member writes in a private Hub discussion, the member's verified phone number is used as the author label for other active members of that same Hub. The same private label is used beside the display name on an exact, locked post card sent only to active members of its single target Hub, while the author remains active there. Public comments use the public username instead.
- Profile information, such as username, display name, bio, profile image, and onboarding state.
- User-generated content and activity, such as posts, comments, hub details, vote receipts, anonymous aggregate vote counts, saved hub discussions, follows, memberships, reports, blocks, and uploaded media. Vote receipts show that a user voted and where the vote counted, but not the selected vote position. Aggregate vote results may be displayed from the first vote, including in Hubs with few members, so a result can be inferable when very few people have voted.
- Local contacts access is used on the device for hub invite selection and Hub readiness. We do not upload or store the full address book. The backend stores the date and time when contact access was successfully completed as a one-time Hub-readiness acknowledgement; later device-permission changes do not automatically erase that acknowledgement.
- The backend receives only phone numbers explicitly selected for a specific Hub invitation action. Under the current retention policy, those selected invitation numbers are retained without a fixed expiration period, subject to applicable account or data-deletion requests and legal, security, fraud-prevention, or abuse-investigation requirements. Hub invite SMS messages are sent from the user's device through the native SMS/share flow, not by our servers.
- Operational and security data, such as IP address, request metadata, abuse-prevention signals, reCAPTCHA results, rate-limit events, logs, and error diagnostics.
- Notification data needed to deliver the durable in-app inbox, unread badges, live in-app updates, and device push notifications. This includes the notification type and referenced post, comment, Hub, invitation, or join request where applicable; read state; timestamps; recoverable per-channel and per-device delivery status; device platform; and Firebase Cloud Messaging registration token. A registration token identifies an app installation for delivery and is not shown to other users. We retain at most five current tokens per account and stop using tokens that have not been refreshed for 60 days. Terminal delivery diagnostics are retained for 30 days before pruning.
How We Use Information
- To create and secure accounts, authenticate users, and prevent abuse.
- To operate social features, including feeds, hubs, comments, votes, follows, saved hub discussions, reports, blocks, and notifications. Eligible notifications may be delivered in the app and through Firebase Cloud Messaging; on iOS, Firebase delivers through Apple Push Notification service.
- To show verified phone-number identity inside private Hub discussions, their saved previews, and locked single-Hub post cards so active members of the same Hub can identify one another.
- To store and deliver user-uploaded media through secure cloud storage.
- To investigate safety reports, enforce policies, debug services, and keep the app reliable.
Sharing
We show an active Hub author's verified phone number to other active members of that same Hub inside private discussions, saved discussion previews, and the author row of an exact locked post card targeted only to that Hub. The display name remains visible and the phone replaces the gray public handle. We do not include this phone label on Public or otherwise shareable posts, expanded source cards, Public comments, public profiles, or people search. Invited or pending users, removed members or authors, and users outside the shared Hub cannot access this private identity. Post-card responses that can contain it are marked private and no-store. We also use cloud infrastructure providers, Firebase Cloud Messaging, Apple Push Notification service, and SMS delivery providers to operate the service. Push providers receive the delivery token and notification payload needed to deliver an alert. We do not sell personal data. We do not use collected data to track users across apps or websites owned by other companies.
User Controls
Users can update profile information, mute content notifications for an individual Hub, control device notification permission in Android or iOS settings, block other users, report abusive content, and request account or data deletion by contacting support. Disabling device push does not erase the in-app notification inbox. Device tokens are removed through device-token deletion, redundant logout cleanup, Firebase token invalidation, logout from all devices, confirmed permanent provider invalidation, account deletion, or account merge; tokens not refreshed for 60 days are no longer eligible. Some records may be retained when required for security, fraud prevention, legal compliance, or abuse investigations.
Contact
For privacy questions or data requests, contact [email protected].