Qlub is a home for the LGBTQ+ community, and protecting your privacy — especially sensitive information like your identity and location — is core to what we do. This policy explains what we collect, why, who we share it with, and the control and rights you have.
Our promise, in one line
We do not sell your personal information, and we never use your sexual orientation, gender identity, or precise location for advertising. You choose what to share, and you can change your mind at any time.
1 · Who we are
Qlub is operated by Yeoman Ventures (“Qlub,” “we,” “us,” or “our”), which is the controller responsible for your personal data. This policy applies to the Qlub mobile app, our websites, and related services (together, the “Service”).
You can reach our privacy team at support@qlubapp.com. If you are in the EEA, the UK, or Switzerland, you can also contact our data-protection representative and lead supervisory authority as described in Section 18.
2 · Information we collect
We collect information you give us, information we collect automatically as you use the Service, and information from a few third parties.
Account & profile
Email, password, and date of birth (to confirm you’re 18+) when you sign up; and, for your profile(s), your name, @handle, bio, pronouns, gender, interests, photos (avatar, cover, gallery), and any home-location city you add.
Identity & community information
By using an LGBTQ+ app and building a profile, you may reveal information about your sexual orientation or gender identity. We treat this as sensitive data (see Section 3). You decide what to share.
Content you create
Listings, events, groups, hangouts, spots, posts, trips, RSVPs, ratings, reactions (likes/saves), check-ins, reports, and the photos and text in them.
Messages
Direct messages between two people are end-to-end encrypted — we cannot read them. Every other chat — group, event, hangout, trip, community, and chats attached to a post — is not encrypted, and we can read its contents. We hold metadata (who messaged whom, and when) for all chats, including encrypted ones. See Section 10.
Verification documents
If you claim a business or verify ownership, any ID or proof you upload. These are stored privately and used only to review your claim.
Location
With your permission, your device’s precise or approximate location to show nearby places, events, and (if you opt in) people, and for check-ins and travel features. Sharing your location with other users is off by default.
Device & usage data
Device model, operating system, app version, language, general (city-level) location from your IP address, push-notification tokens, diagnostic and crash logs, and how you interact with the Service.
From third parties
If you use Sign in with Apple, the identifier (and email, unless you hide it) Apple shares with us; and results from our content-moderation providers.
3 · Sensitive & special-category data
The Service may involve these categories of sensitive personal data:
- information that reveals your sexual orientation or gender identity;
- your precise geolocation;
- account login credentials; and
- any government-issued ID you upload for a business claim.
We process sensitive data only where the law allows — in the EEA/UK, on the basis of your explicit consent (which you give by choosing to provide it and by turning on location), or another Article 9 basis such as data you have manifestly made public. In the United States, we process it only as needed to provide the Service you request. We do not sell it, we do not share it for advertising, and we do not use it to infer characteristics about you for marketing. You can withdraw consent or turn off location at any time in settings — this won’t affect processing that already happened.
4 · How we use your information
We use personal data to:
- create and run your account and profiles, and provide the Service;
- show you nearby LGBTQ+-owned and -affirming places, events, groups, and — if you opt in — people, and match content to your interests;
- enable messaging, follows, RSVPs, check-ins, ratings, and other social features;
- keep Qlub safe: verify age and eligibility, screen images and public text for prohibited content, review reports, and detect fraud, spam, scams, and abuse;
- send you service and (with your permission) notification messages;
- operate, maintain, secure, debug, and improve the Service;
- comply with law and enforce our Terms and Guidelines.
Legal bases (EEA / UK / Switzerland)
Where GDPR or UK GDPR applies, we rely on: performance of our contract with you (to provide the Service you sign up for); your consent (for location sharing, sensitive data, push notifications, and other optional features); our legitimate interests (to secure, improve, and promote the Service and keep the community safe), balanced against your rights; and compliance with legal obligations. You can withdraw consent at any time.
5 · Automated moderation
To protect the community, images you upload are automatically screened for adult or illegal content before they’re shown publicly, and public text you write may be automatically screened for prohibited content before it’s published. Content flagged as unsafe may be blocked or held for review.
These checks are not used to make decisions producing legal or similarly significant effects about you without human involvement; you can ask us to review a decision by writing to support@qlubapp.com. We do not use your content to build advertising or personality profiles.
6 · How we share information
We disclose personal data only as described here:
- With other users. Your public profile, content, and — per your settings — approximate distance or presence are visible to other members. What you post publicly is public; what you send in a one-to-one direct message is end-to-end encrypted and readable only by you and the person you sent it to, on the devices they have registered (Section 10).
- With service providers. Vendors that process data on our behalf under contract, only to provide the Service (see Section 7). They may not use it for their own purposes.
- For safety & legal reasons. To comply with law, respond to lawful requests and legal process, enforce our Terms, or protect the rights, safety, and property of users, the public, or Qlub — including reporting child-safety content to authorities and NCMEC.
- Business transfers. In a merger, acquisition, financing, or sale of assets, your data may be transferred subject to this policy.
- With your consent. When you direct us to share it, or otherwise with your permission.
- Aggregated / de-identified. Data that can no longer reasonably identify you may be shared freely.
7 · Service providers (subprocessors)
We rely on a small set of trusted providers, bound by contract to protect your data, including:
- Supabase authentication, messaging, and notifications.
- MongoDB Atlas our primary application database.
- Amazon Web Services cloud hosting and infrastructure (United States).
- Cloudflare image storage and network/security services.
- Sightengine automated image moderation.
- OpenAI automated text moderation.
- Google / Firebase & Apple push notifications and Sign in with Apple.
- Email & maps providers transactional email delivery and map imagery.
We keep an up-to-date list of subprocessors and will provide it on request at support@qlubapp.com.
8 · International data transfers
Qlub is operated from the United States, and our providers may process your data in the United States and other countries whose data-protection laws may differ from yours. Where we transfer personal data out of the EEA, the UK, or Switzerland, we use appropriate safeguards — such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, and transfers to jurisdictions or frameworks recognized as providing adequate protection. Contact us for a copy of the relevant safeguards.
9 · How long we keep your data
We keep personal data only as long as needed for the purposes in this policy — generally while your account is active. When you delete your account, we delete or de-identify your personal data, release any listings you claimed, and purge your claim documents, subject to limited exceptions where we must retain certain data to comply with law, resolve disputes, prevent fraud or abuse, or enforce our agreements. Backups and moderation logs are retained for a limited period and then deleted. End-to-end-encrypted messages are stored only as ciphertext we cannot read; deleting your account also deletes the device keys registered to it, after which that ciphertext is permanently unreadable by anyone.
10 · How we protect your data
We use technical and organizational measures to protect your data, including encryption in transit (HTTPS/TLS), end-to-end encryption for one-to-one direct messages, access controls, and a private, restricted store for verification documents. No system is perfectly secure, so we cannot guarantee absolute security; please help by using a strong, unique password and keeping your device secure. If a breach affects your data, we will notify you and regulators as required by law.
End-to-end encryption, and its limits
One-to-one direct messages are encrypted on your device and decrypted on the recipient’s. The keys are generated on your device and never leave it, so we hold only ciphertext we cannot read. It is important that you also understand what this does not protect, so you can judge what is safe to send:
- Only one-to-one direct messages are encrypted. Group, event, hangout, trip, community and post chats are not — treat those as readable by us.
- We can still see message metadata — who you message and when — even for encrypted chats, and we use it to fight spam, scams and abuse.
- You can use Qlub on more than one device (up to five). Each device gets its own key, and a message is encrypted to the devices registered at the moment you send it. A newly added device can read messages from then on, but not older ones.
- When someone you are chatting with adds a device, that device can read your future messages to them. We show a notice in the conversation when this happens, and that notice is the signal to check with them if it is unexpected.
- Encryption protects messages in transit and on our servers. It cannot protect you from someone who has your unlocked device, and it cannot stop the person you are messaging from screenshotting or sharing what you send.
- If your device keys were ever obtained, past messages that device can read could be read too. We do not currently use a key-rotation scheme that would prevent this.
- Because keys never leave your devices, we cannot recover encrypted messages for you. If you lose access to all of your devices, that message history is gone — including for us.
- Other signed-in members can see that an account has registered devices, and how many, but never any key that would let them read anything.
Because we cannot read encrypted direct messages, we cannot moderate their contents or produce them in response to a legal request. You can still report a user, and you can block or mute anyone at any time.
11 · Your choices & controls
- Profile visibility: make a profile public or private.
- Location: turn location on or off, hide your distance, or set a travel area — sharing with other users is off by default.
- Notifications: manage push and in-app notification categories in settings, and change device permissions in your OS.
- Blocking & reporting: block or report any user; blocking is private and hides you both ways.
- Access & deletion: edit your information in the app, or delete your account at any time from account settings.
12 · Your rights — EEA, UK & Switzerland
If you are in the EEA, the UK, or Switzerland, you have the following rights, subject to legal conditions and exceptions:
- Access obtain a copy of the personal data we hold about you.
- Rectification correct inaccurate or incomplete data.
- Erasure ask us to delete your data (“right to be forgotten”).
- Restriction ask us to limit how we process your data.
- Portability receive certain data in a portable format, or have it transmitted to another controller.
- Object object to processing based on our legitimate interests, and to any direct marketing.
- Withdraw consent withdraw consent at any time, without affecting prior processing.
- Automated decisions not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
- Complain lodge a complaint with your local data-protection authority.
To exercise these rights, email support@qlubapp.com. We respond within the time the law requires (generally one month under GDPR).
13 · Your rights — U.S. states
Depending on your state of residence — including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Tennessee, Indiana, Kentucky, Rhode Island, Maryland, and others as their laws take effect — you may have some or all of these rights:
- Know / access the categories and specific pieces of personal information we collect, use, and disclose.
- Delete request deletion of personal information we hold about you.
- Correct request correction of inaccurate personal information.
- Portability obtain a copy of your personal information.
- Opt out of the sale or sharing of personal information and of targeted advertising — though we do none of these.
- Limit sensitive data direct us to limit the use of your sensitive personal information to what’s necessary to provide the Service.
- Non-discrimination we won’t discriminate against you for exercising your rights.
- Appeal appeal a decision on your request where your state provides that right.
To exercise these rights, email support@qlubapp.com or use the in-app account tools. We will verify your request (and may need to confirm your identity), and you may use an authorized agent where the law permits. We honor the Global Privacy Control (GPC) browser signal as a valid opt-out where applicable.
California “Shine the Light”
California residents may request information about disclosures of personal information to third parties for their direct-marketing purposes. We do not disclose personal information for third-party direct marketing.
14 · Children’s privacy
Qlub is strictly for adults 18 and older. We do not knowingly collect personal information from anyone under 18. If we learn that someone under 18 has created an account, we will remove it and delete their data. If you believe a minor is using Qlub, contact us at support@qlubapp.com.
15 · Cookies & tracking technologies
The Qlub app does not use third-party advertising trackers or cross-app tracking, and we do not track you across other companies’ apps or websites for advertising. We use only the identifiers and local storage needed to run the app, keep you signed in, remember your preferences, deliver push notifications, and keep the Service secure. Any Qlub website uses only essential and, where required, consent-based cookies. We honor the Global Privacy Control signal where applicable.
16 · Third-party links & services
The Service may link to third-party sites, businesses, or services we don’t control. Their privacy practices are governed by their own policies, and we are not responsible for them. Please review the privacy policy of any third-party service you use.
17 · Changes to this policy
We may update this policy from time to time. If we make material changes, we’ll provide notice in the app or by email and update the “Last updated” date below. Where the law requires, we’ll obtain your consent. Please review this page periodically.
18 · How to contact us
One address for everything
support@qlubapp.com — privacy questions, data-rights requests, and general support all reach us here. Please say in the subject line what your message is about (for example “Privacy request”) so we can route it quickly.
EEA / UK representative & supervisory authority
EEA, UK, and Swiss users may contact our data-protection representative via support@qlubapp.com and may lodge a complaint with their local data-protection authority.