DuoQueue Privacy Policy

Effective date: August 5, 2026 Version: 1.0 (draft)

This policy explains what DuoQueue collects, why, who we share it with, and what control you have over it. It's written in plain language on purpose — if anything here is unclear, contact us using the details below.


1. Who we are

DuoQueue is a swipe-based app for finding gaming duos, built for players 18 and older.

Wherever this policy says "contact us," use the email above.


2. What we collect, and why

We only collect what the app actually uses. Here's every category, itemized.

Account information

Profile information

Content

Usage information

Device information

Purchases

Optional linked gaming accounts

Bot-protection signals

What we do NOT collect

We do not collect precise GPS location, contacts-list access, or browsing history outside the app. We do not run any advertising or analytics SDK — there is no Meta/Google ad pixel, no Mixpanel/Amplitude/Segment-style tracker, or any comparable dependency anywhere in the app's code today.


3. Who we share data with

We use a small number of specialized service providers ("processors") to run the app: Supabase, Sightengine, Expo, Resend, RevenueCat, Apple, Google, Cloudflare, and Steam. We use each of them as a service provider/processor under that provider's own standard terms of service, and none of them can use your data for their own purposes beyond providing their service to us.

ProviderRoleWhat they receiveLocation
SupabaseHosting, database, authentication, file storage, and realtime chat delivery — the backbone the whole app runs onEffectively all account and profile data described in Section 2United States
SightengineAutomated photo moderation, when configured (see below)When our automated moderation provider is active, every photo you upload is sent to Sightengine to be automatically screened for nudity, graphic content, and whether the person in the photo appears to be a minor, before it's shown to anyone elseUnited States
Expo (push notification service)Delivers push notificationsYour device push token and the notification content (e.g. "You matched with X")United States
ResendSends transactional email (signup confirmation, account emails), if configured as our email providerYour email address and the content of the email being sentUnited States
RevenueCatManages subscriptions and in-app purchasesYour app-level user ID and purchase/subscription events from Apple/Google — never your payment detailsUnited States
Apple (App Store) / Google (Play Store)Processes your payment when you buy a subscription or consumableYour payment details, handled entirely by Apple/Google — we never receive themVaries by platform
Cloudflare (Turnstile)Bot-protection challenge at signupDevice/browser signals used to distinguish humans from botsGlobal network (may include US)
SteamOnly if you choose to link an accountWe send your account link request to Steam and receive back the public profile fields listed in Section 2United States (approximate, platform-dependent)

Sightengine and Resend are config-gated, not hard-wired. Our photo-moderation pipeline defaults to routing every photo straight to human review and only calls Sightengine when a provider setting and API credentials are set in our live environment; if that configuration is ever unset, no photo is sent to Sightengine at all. As of this writing, our live production environment has that provider setting and both Sightengine credentials configured, so automated screening is active. Transactional email — account confirmation codes and similar — is sent through Resend, which is configured as our custom SMTP provider.

Where your data is processed. DuoQueue is currently offered only in the United States, and your data is processed in the United States by the providers listed above. DuoQueue is not directed to, and is not currently offered to, users in the EU, UK, or Switzerland. If that changes, we'll put an appropriate international transfer mechanism in place and update this section before it does.

We do not sell your personal information. We do not share your data with data brokers or advertising networks, and we don't run any advertising or analytics SDK that would make this a "sale" or "share" under CCPA/CPRA. See Section 6 for the CCPA-specific disclosures.


DuoQueue is currently offered only in the United States and is not directed to users in the EU, UK, or EEA (see Section 1). We're including this section for completeness in case that changes. If you're in a region covered by the GDPR or UK GDPR, here's the legal basis for each category of processing:


5. How long we keep data


6. Your rights

You have the following rights over your data. Most are available directly in the app; the rest are a quick email away.

RightWhat it meansHow to exercise it
AccessSee what we hold about youView it directly in the app (profile, matches, messages, settings), or email us for a full export
CorrectionFix inaccurate dataEdit your profile directly in the app for anything editable; email us for anything you can't change yourself (e.g. date of birth)
DeletionDelete your account and dataSettings → Delete Account, or email us if you'd rather we do it
PortabilityGet a copy of your data in a portable formatEmail us — there's no self-service export button in the app yet, so this is handled manually, within a reasonable turnaround (GDPR: 30 days; CCPA: 45 days)
ObjectionObject to processing based on legitimate interestsEmail us with what you're objecting to
Withdraw consentRevoke any consent-based processing at any timeUnlink a gaming account, stop sharing Discord in a chat, or turn off notification permissions — all directly in the app

California residents (CCPA/CPRA)

In the last 12 months, we've collected the categories of personal information described in Section 2 (identifiers, profile/characteristics data, commercial/purchase information, internet/app activity, and — via linked gaming accounts — information about your other online activity). We've disclosed those same categories to the service providers listed in Section 3, for the business purposes described there.

EU/UK/EEA residents (GDPR)

DuoQueue is currently offered only in the United States and is not directed to users in the EU, UK, or EEA. We don't have a lead EU/UK supervisory authority because we don't yet operate there. If we expand to those regions, we'll designate one and update this section before we do.


7. Security

We take reasonable steps to protect your data, but no system is perfectly secure, and we can't guarantee absolute security.

If you believe you've found a security vulnerability, please report it to the contact email in Section 1 rather than exploiting or publicly disclosing it first.


8. Automated decision-making (photo moderation)

When you upload a photo, and our automated moderation provider (Sightengine) is configured (see Section 3), it analyzes the photo to check for nudity, graphic content, and whether the person appears to be a minor, and can automatically reject a photo without a human reviewing it first. If your photo is rejected and you believe that was a mistake, you can contact us to request human review. Photos that the automated system can't confidently judge — or every photo, if the automated provider isn't configured — are held for manual review by our team rather than being auto-approved or auto-rejected.


9. Age restriction

DuoQueue is for adults only — you must be 18 or older to create an account. We verify your date of birth at signup and technically block anyone under 18 from completing a profile.

If we learn that someone under 18 has created an account (for example, through a report using the "underage" report reason, or otherwise), we will terminate that account and delete the associated data as described in Section 5. If you believe a minor is using DuoQueue, please report that profile in the app (profile → Report) or contact us directly using the email in Section 1.

We do not knowingly collect personal information from anyone under 18. If you're a parent or guardian and believe your child has provided us with personal information, contact us and we will investigate and delete it.


10. Changes to this policy

We may update this policy as the app changes. If we make a material change, we'll update the effective date at the top of this document, and — for significant changes — we'll make a reasonable effort to notify users in-app before the change takes effect. We encourage you to review this policy periodically.


Contact us

Email support@duoqueue.io with any question about this policy. For our full legal entity name and business address, see Section 1.