Privacy Policy

Chopped or Not

Last updated: 2026-08-24

This policy describes what Chopped or Not collects, why, who else touches it, how long it is kept, and what you can do about it. It describes the app as it is actually built. Where the app enforces something in code rather than only promising it, this policy says so.

Chopped or Not ("we", "us") is an independently operated app. We do not publish a postal address; contact is by email only. You can reach us at choppedornotapp@gmail.com, and we answer every message sent there.


The short version


What we collect

Everything below is listed in the app's iOS privacy manifest as well, and the two are meant to match.

Sign-in identity — one email address

You sign in with Apple or with Google. We hold one email address, and nothing else that identifies you. It lives in the authentication system (Supabase Auth), separately from the application data, and no other user can read it. Settings shows it back to you masked.

If you use Apple's Hide My Email, the address we hold is the relay address Apple generates for this app — we never receive your real address, and you can break the relay at any time from your Apple ID settings.

We do not collect phone numbers. There is no SMS in this app.

Apple privacy manifest: Email Address — App Functionality.

About you: age band, gender, US state, and (optionally) ethnicity

During first run the app asks four questions:

Question Required? What is stored
Date of birth Yes The year only. The day and month are never stored.
Gender Yes One of: woman, man, nonbinary.
US state Yes The two-letter state code.
Ethnicity No One or more categories, only if you pick some.

The birth year is used for two things: to check that you are 18 or older, and to derive an age band (18-24, 25-34, 35-44, 45-54, 55+). Only the band is ever used in any breakdown.

The state is the state you select from a list. The app never asks for location permission and never reads your device location. Settings shows "Location permission: never requested", and that is accurate.

Ethnicity is optional and is treated as sensitive. See Ethnicity, specifically below.

Apple privacy manifest: Sensitive Info — App Functionality and Analytics.

Your photo

One photo at a time is "live". You take it in the app with the camera; there is no way to submit an image from your photo library, from another app, or from a file. Before upload the image is downscaled (longest edge 1280px) and re-encoded as a JPEG.

Photos are stored in a private storage bucket. They are not public, are not listed anywhere, and are not reachable by URL guessing. See How photos are stored and served.

Apple privacy manifest: Photos or Videos — App Functionality.

Identifiers

Apple privacy manifest: User ID, Device ID — App Functionality.

Your activity in the app

Apple privacy manifest: Other Data Types — App Functionality and Analytics.

Crash reports

The app can send crash and error reports to Sentry. This is only active in builds where a Sentry DSN has been configured; with no DSN, nothing is sent anywhere. When it is on, it is configured not to attach personal information (sendDefaultPii: false) and a share of performance traces is sampled. Crash reports may still contain technical details such as device model, OS version and a stack trace.

Apple privacy manifest: Crash Data — App Functionality.

Purchases

If you subscribe, the purchase itself is handled by Apple (or Google Play). We do not see or store your payment card. We receive, via RevenueCat, whether the "premium" entitlement is currently active for your account, and we store that as a single true/false flag.


What we never do


How photos are stored and served


Voting is anonymous in both directions

This is enforced in the database, not just in the interface:


Analytics, and the 20-person floor

Subscribers see breakdowns of how people responded to their photo — by age band, gender, state and ethnicity, plus a "biggest fans" segment and a distribution chart. These are built with real counts of real votes; nothing is invented or synthesised. Several protections apply, and they exist to stop a poster reverse-engineering an individual voter's answer:

Raw counts (how many people responded, how many liked) are free and are shown to everyone for their own photo. The subscription unlocks the breakdowns.


Ethnicity, specifically

Ethnicity is a special category of personal data under the GDPR and "sensitive personal information" under California, Colorado, Connecticut and Virginia privacy law. It is handled accordingly:


Moderation and reporting


Notifications

If you turn notifications on, we store an Expo push token against your account and may send you:

We do not send engagement nags, streaks, or invented events. You can turn notifications off in Settings or in the OS. Push messages are delivered through Expo's push service and then Apple's (or Google's) push service.


Who else processes your data

Processor What it handles
Supabase Hosting, database, authentication (your email), private photo storage, and the server-side functions.
AWS Rekognition (or Hive, if configured) Automated moderation. Receives the photo's image bytes for the scan.
Expo push service Delivery of push notifications, including the notification text and your push token.
Apple (and Google Play on Android) Payment processing for the subscription, and push delivery. We never see your payment details.
RevenueCat Subscription state management. Receives your account ID and purchase events, and tells us whether the entitlement is active.
Sentry Crash and error reporting. Only active in builds with a Sentry DSN configured; configured not to attach personal information.
Google Only if you choose Google sign-in; the sign-in itself.

These are processors acting on our instructions, not parties we sell data to. Each has its own privacy policy.

the United States (US West)


How long we keep things


Your choices and controls

All of these are in the app, in Settings or on your own photo:

You want to What to do What happens
Stop being seen, without losing anything "Take it down" on your live photo It leaves everyone's feed immediately. It keeps its counts in your own grid.
Delete one photo permanently Delete it from your grid The row, the votes on it, and the image bytes are removed.
Withdraw your ethnicity Settings → Ethnicity Cleared from your profile and from every vote you have cast.
Turn off notifications Settings → Notifications The push token is cleared.
Manage or cancel the subscription Settings → Cancel or manage subscription Opens the App Store / Play Store subscription page.
Sign out Settings → Sign out Nothing is deleted. Your photo and counts are waiting when you return.
Erase everything Settings → Delete everything See below.

Deleting everything

One tap, one confirmation, no grace period and no retention dark pattern. It runs in this order:

  1. Your data rows are deleted — your profile, your photos, your reports, and every vote you have cast. Deleting your votes also withdraws them from other people's counts: every photo you voted on is recounted so it no longer includes your answer.
  2. Your image bytes are removed from storage.
  3. Your sign-in is deleted from the authentication system, so the email address we held is gone too. You cannot sign back into that account; signing in again creates a new one.

What can survive an erasure, honestly stated:

To make a privacy request other than through the in-app controls — including access, correction, deletion, or a right guaranteed to you by the GDPR, the CPRA or another state privacy law — write to choppedornotapp@gmail.com. We will verify the request against the sign-in identity on the account.


Children

Chopped or Not is 18+. You must be 18 or older to use it.


Security

No system is perfectly secure, and we cannot guarantee absolute security.


Changes to this policy

If we change this policy we will update the "Last updated" date above. If a change materially affects how we handle information you have already given us — particularly anything about ethnicity, photos, or who can see what — we will say so in the app rather than only editing this page.


Contact

choppedornotapp@gmail.com Chopped or Not