Seapull Privacy Policy
Effective date: September 26, 2026 · Last updated: September 26, 2026
Seapull is operated by Tosemum Holdings LLC, based in Surprise, Arizona ("Seapull," "we," "us"). This policy explains what personal information we collect through the Seapull mobile app and the seapull.com website, how we use it, who we share it with, and the choices you have.
Seapull is offered in the United States only and is for adults 18 and older.
Questions or requests: privacy@seapull.com.
Plain-language summary up front: we don't sell your data, we don't run ads, and other users can never see your exact location, only a coarse distance range. The details below say exactly what we store and why.
1. What we collect
Information you provide
- Name: the display name you choose (up to 40 characters).
- Email address: used to create and sign in to your account, and for service email such as password-reset codes. Passwords are handled by our authentication provider and stored only as a cryptographic hash. We cannot see them.
- Date of birth: used to verify you are 18 or older and to show your age. Your birthday itself is never shown to other users, only your age.
- Gender: woman, man, nonbinary, or other.
- Who you're interested in meeting: the genders you want to see in Discover. Because this can indicate sexual orientation, it is used solely to decide who appears in whose Discover feed and is shown to nobody.
- Photos: up to 6 profile photos, stored in a private storage bucket and shown only to signed-in Seapull users who can view your profile under our matching rules. Each photo is automatically screened for explicit or violent content when uploaded (see section 5).
- Approximate location: your city or area and a geographic point for it, plus your chosen discovery radius (1 to 50 miles in the app). When you set your location, the app asks for the operating system's foreground location permission and, if you allow it, reads your device position once to suggest a nearby city. You can decline and pick a city by hand. What we save is the point for the city or area you confirm, not your live device position. We never track location in the background. See section 3 for how location is protected.
- Activities and preferences: your activities (chosen from our catalog of 24), your intensity level, your typical availability, and a short bio (up to 500 characters).
- Messages: the messages you send in Seapull conversations (up to 2,000 characters each), with timestamps and whether each message was sent before or after a match.
Information generated as you use Seapull
- Activity signals: who you like (including super-likes), who you pass on, your matches and unmatches, your conversations (including a preview of the last message used to render your chat list), your per-conversation "read up to here" markers, and a "last active" timestamp updated when you open the app.
- Safety records: blocks you create, and reports you file or that are filed about you, including the reason, any details written, and pointers to a specific message or photo attached as evidence.
- Verification status: whether your profile is unverified, pending, verified, or rejected. Profile verification is not yet offered; every account is currently unverified.
- Account tier: free or premium. Payments are not live; see section 5.
- Device or other IDs: a random install identifier generated by the app on your device. It is not your advertising ID, phone number, or hardware serial; it only lets us replace an old notification token from the same device instead of accumulating stale ones.
- Push notification tokens: if you allow notifications, the push token issued for your device, the platform (iOS or Android), and whether notifications are switched on. We use it to notify you about new matches, messages, and intros. You can turn notifications off in the app or in your OS settings at any time.
- Technical logs: our infrastructure providers keep standard server logs (such as IP address and request metadata) needed to operate and secure the service. A login session token is stored on your device so you stay signed in.
What we do NOT collect
No advertising SDKs, no third-party analytics SDKs, no contact-list access, no background location tracking, no precise location stored, and no data brokers. If any of that ever changes, this policy changes first.
2. How we use your information
- Matching and discovery: your activities, intensity, availability, age, gender, who you're interested in, and coarse distance feed the compatibility score and determine who you see and who sees you. Matching filters run on our servers; other users receive only the limited profile fields listed in section 4.
- Chat: delivering your messages to your match, in real time, and notifying you when you receive one.
- Safety and moderation: operating block and report tools, screening photos, reviewing reported content, enforcing the 18+ rule, and preventing abuse (for example, daily like limits).
- Service email: account emails such as password-reset codes. No marketing email without separate consent.
- Legal: complying with law and responding to valid legal process.
We do not sell your personal data. We do not share it with advertisers. Seapull shows no ads.
3. Location: exactly how it works
Location privacy is engineered into Seapull's database, not just promised:
- Your stored coordinates never leave our servers and are never sent to another user in any form.
- Every distance another user sees is computed between grid-snapped points (a fixed grid of roughly 1.4-mile cells), and then shown only as a coarse band: "within 2 mi," "2 to 5 mi," "5 to 10 mi," "10 to 25 mi," or "25+ mi."
- Because distances are computed from snapped cells and shown as bands, another user cannot narrow down your location by repeatedly querying from different positions.
- Direction indicators on the map screen are decorative, not your real bearing.
- Only people within a mutually compatible discovery radius can see you at all.
You control your discovery radius in the app. Deleting your account removes your stored location entirely (section 7).
4. What other users can see
Other signed-in users who pass the mutual matching rules can see: your display name, age (not birthday), gender, bio, activities, intensity, availability, city, verification status, whether you were recently active, your photos, and a coarse distance band. They can never see: your email, birthday, who you're interested in, exact location or coordinates, who else you've liked, passed, or matched, your reports or blocks, or your settings.
5. Service providers (processors)
We share data only with the services that run Seapull, and only what each needs:
| Provider | What it does | What it handles |
|---|---|---|
| Supabase (hosted on AWS in the US West, Oregon, region) | Database, authentication, file storage, realtime message delivery, and the server functions that run deletion, photo screening, and notification sending | All app data described above; passwords as hashes; standard server logs |
| Firebase Cloud Messaging (Google) and Apple Push Notification service, reached through the Expo push service | Delivering push notifications to Android and iOS devices | Your push token and the notification text (for example, "It's a match!" or "New message from" a first name) |
| Resend | Transactional email delivery (password-reset codes and other service email) | Your email address and the content of those service emails |
| Cloudflare | Hosting and network protection for the seapull.com website | Standard visitor logs (such as IP address and request metadata) when you visit the website |
| Google Cloud Vision | Automated screening of uploaded profile photos for explicit or violent content | The photo image, sent once at upload; Google returns likelihood scores and we store only those scores |
Not yet in use: payment processing (Stripe) is planned for a future premium tier. It will be added here before any payment feature ships.
We may also disclose information if required by valid legal process, or where necessary to investigate safety threats, fraud, or violations of our Terms.
6. Data retention
- Profile, photos, messages, and activity signals are kept while your account is active.
- Safety records (reports and blocks) are retained even after the people involved delete their accounts, so account deletion can never erase an abuse case.
- Notification tokens are kept while your account is active so you can switch notifications off and on without a new system prompt.
- Standard infrastructure logs are retained per our providers' default schedules.
7. Deleting your account: what actually happens
Seapull has in-app account deletion (Profile tab, then Account, then Delete account). It runs immediately and does the following, in this order:
- Photos: your photo files and records are deleted from storage, except any specific photo attached as evidence to a report that is still open or under review; that photo is held until the case closes.
- Likes and passes: deleted entirely, in both directions.
- Matches: closed permanently (the other person's match ends; you can never be re-matched).
- Profile: anonymized in place. Your display name, bio, date of birth, gender, interested-in, activities, availability, intensity, city, and location are all erased. You disappear from Discover, the map, and search immediately.
- Sessions: you are signed out everywhere.
What is retained, and why: messages you sent remain in your former conversations, attributed to an anonymized profile, so that (a) the other person keeps their own conversation history and (b) evidence in any safety report is preserved. Reports and blocks involving you are always retained. Your login email stays on the closed account record until final purge so the same address cannot be used to slip past a block or an open report. The anonymized remainder is kept only as long as needed for safety and legal purposes, then permanently erased.
A fuller description is in our Account Deletion page. If you cannot sign in, or want a specific erasure beyond this (for example, message bodies), email privacy@seapull.com and we will handle it individually unless a safety or legal hold applies.
8. Your rights and choices
- Access and correction: view and edit your profile data directly in the app.
- Deletion: in-app (above) or by emailing privacy@seapull.com.
- Location: control your radius in-app; control the device-level location permission in your OS settings. Declining the permission does not stop you using Seapull; you pick a city by hand instead.
- Notifications: switch them off in the app's Notifications settings or in your OS settings.
- Email: transactional email is required to operate your account.
- We honor these rights for everyone regardless of state. California residents: we do not sell or "share" (for cross-context ads) personal information; the rights above cover CCPA-style access and deletion requests.
9. Age policy: 18+
Seapull is for adults 18 and older. The date-of-birth check is enforced both in the app and in the database itself (a profile with an under-18 birthday cannot exist). "Underage" is a first-class report reason; verified underage accounts are removed along with their data. We do not knowingly collect any data from anyone under 18.
10. Security
All traffic is encrypted in transit (TLS). Every database table is protected by row-level security: messages, matches, and conversations are readable only by the two participants, enforced by the database, not just the app. Unauthenticated access to user data is fully revoked. Passwords are hashed. Location protections are described in section 3. No system is perfectly secure; if a breach affects your data, we will notify you as required by law.
11. Changes
We'll update this policy as Seapull grows (for example, when payments, verification, or venue suggestions ship). Material changes will be announced in the app before they take effect, and the "last updated" date always reflects the current version.
12. Contact
Tosemum Holdings LLC · Surprise, Arizona
- Privacy requests: privacy@seapull.com
- General support: support@seapull.com
- Legal notices: legal@seapull.com