privacy policy
Effective date: 2026-06-08
This Privacy Policy describes how City Girl Questions ("we", "us", "our") collects, uses, and shares information when you use our website at citygirlquestions.com or our mobile app (the "Service"). Operated by Bringham Labs LLC. You can reach us at support@citygirlquestions.com.
Notice at collection (California): at or before collection, the categories we collect are identifiers (your email or phone number and a random user ID we assign), your year of birth (used only to confirm your age), optional profile details you add (display name, bio, city, Instagram handle, and a one-way phone-number hash if you turn on contact matching), and the content you create (questions, votes, reactions, reports, blocks, feedback). We use this only to operate the Service and the purposes in Section 2, including the optional discovery and matching features you choose to turn on. We retain it as described in Section 6. We do not currently sell or share personal information, and we do not use it for cross-context behavioral advertising. If this ever changes, we will update this notice and provide the choices the law requires before doing so.
1. Information we collect
We collect only what we need to run the Service.
Account information you provide:
- Email address (Google sign-in or email)
- Phone number (phone sign-in)
- Display name you choose
- Year of birth (used only to confirm you meet the minimum age)
- A short bio (optional) you can add to your profile
- City (optional). If you enter a city in Settings, we store it on your profile. We use it to show city-targeted questions and to power same-city matching in the optional Discovery and Like-Minded features, and we record the city associated with each vote so per-city results stay accurate if you later move. Clear the field in Settings to remove it.
- Instagram handle (optional). Stored on your profile so it can be exchanged after a mutual Like-Minded match.
- Contact matching (optional, off by default; Pro and phone sign-up only). If you turn on "let people with my number find me" in Settings, we create a one-way SHA-256 hash of your phone number and store it, linked to your user ID, so other people who already have your number can find you. When you search your contacts, we hash the numbers you select on your device and check them against this index; we never store the contacts you look up. Turning the feature off deletes your phone hash and removes you from the index.
Content you create:
- Questions you submit
- Votes you cast
- Reactions you post
- Reports you file
- Users you block
- Voting activity used to calculate your daily streak (the date you last voted and your current streak length)
- Feedback you send. When you submit feedback in Settings, we store your message along with basic technical context to help us reproduce issues: your browser/device type (User-Agent), window size, and the in-app page you were on. We do not capture full web addresses or query strings.
- Questions you send to a friend. When you share a question with a friend in the app, we store a small record of that share (who sent it, to whom, the question, and when) so it can appear for them. Either of you can remove it.
Information we collect automatically:
- Firebase user ID (a random identifier we assign)
- Approximate region: a coarse 3-letter geohash, only if you opt in to the "show how my city voted" feature. It is stored on your device only and is never sent to our servers. This is separate from the City you can type into Settings (listed above), which is stored on your profile.
- Device timezone (so daily limits reset at your local midnight)
- Whether you are a paid subscriber (set by our payment processor)
Information you can choose to make visible to other users:
- Display name. Shown on your own profile and to people you've accepted as friends. Not shown on questions you submit; those appear anonymously to everyone (including your friends).
- Display name and city in the "Like-Minded" match feature, only if you opt in under Settings → Discovery. When on, other Pro users in your city who agree with most of your votes can see your display name and city as a "match" in their results. Your votes, email, phone, and age are never exposed by this feature. Off by default. You can turn it off at any time, which immediately deletes your discoverable profile entry; cached results in other users' apps clear within 24 hours.
- Like-Minded matches (optional, Pro). If you opt in and both you and another user accept a match, the app reveals to each of you the Instagram handle the other chose to share, plus your city and a vote-agreement score, so you can continue the conversation off-platform. Neither handle is shown until both people have accepted. Either party can end the match, which removes future access. When you send or accept a match, we store a record of it, including a snapshot of your vote-agreement score and shared city.
- Your "@handle" (if you choose to set one): a short name that resolves to your user ID, used by the friends feature below. Any signed-in user can resolve a handle to the random user ID behind it (this is how friend-add works), but the handle never reveals your name or contact details. Older accounts may also have a short friend code that works the same way for links shared before handles existed.
- Friends feature: when you and another user mutually accept a friend request, you become each other's "friend" inside the app. Friends can see each other's votes on questions you have both voted on (and only those), the proportion of those shared votes that align, each other's display names, and each other's bio. Friends never see your email, phone, age, or region. Either party can end the friendship at any time in the Friends page, which immediately ends future visibility; cached summaries in the other party's app clear within 24 hours.
Information we do NOT collect:
- We do not currently show advertising. If we add it, we will update this policy and request any consent the law requires before any ads appear.
- We do not use third-party tracking pixels and do not sell or share personal information for cross-context behavioral advertising. We may use limited first-party measurement to keep the Service fast and reliable.
- We do not knowingly collect information from anyone under 13
- We never upload your full contact list or any contact's name; the optional contact-matching feature only sends one-way hashes of phone numbers you choose, and only when you enable it. We do not access your photos or microphone except with your explicit per-feature permission
- We do not use your data to train AI models
2. How we use your information
- Run the Service: show questions, count votes, save drafts
- Enforce daily limits and the rules in our Terms of Service
- Detect abuse: investigate reports, hide content with 5+ reports, support per-user blocks
- Bill you for Pro if you subscribe
- Communicate about service issues, security alerts, and policy changes
3. Legal basis (EU, UK, Switzerland)
- Performing our contract: account, voting, subscriptions
- Legitimate interests: moderation, abuse detection, security
- Consent: location feature, voice features, future analytics; withdrawable at any time
- Legal obligation: lawful government requests, tax record-keeping for paid subscriptions
4. Sharing
We share information only with vendors that operate the Service:
- Google LLC (Firebase Authentication, Cloud Firestore, Cloud Functions, Hosting): stores account data and operates the app under Google's Data Processing Addendum and the EU-US Data Privacy Framework
- Stripe, Inc.: processes Pro subscription payments; receives your email address and subscription details to manage billing
- Cloudflare, Inc.: runs our payment webhook handler
We share with law enforcement only with valid legal process. We do not transfer data to other third parties for their independent purposes.
5. International transfers
Our processors store data in the United States. Transfers from the EU, UK, or Switzerland are protected by the EU-US Data Privacy Framework, the UK Extension to the DPF, the Swiss-US DPF, and the EU Standard Contractual Clauses with the UK Addendum, as applicable.
6. Retention
- Account data: while your account is active
- Votes and reactions: while your account is active or until the parent question is deleted
- Questions you authored: until you or we delete the question
- Reports: 12 months after resolution
- Backups: rolling 30-day system backups; deleted-account data is purged from backups within 35 days
- Subscription billing records: 7 years (US tax requirement)
7. Your rights
Wherever you live, you may:
- Access a copy of your data: Settings → Download my data
- Correct your display name: Settings → Profile
- Delete your account: request deletion in Settings → Delete my account, or by emailing support@citygirlquestions.com. We permanently remove your profile, votes, reactions, reports, and authored questions within 30 days of your request; backups are purged within 35 days
- Withdraw consent for optional features in Settings
- Lodge a complaint with your local data protection authority
EU/UK/Swiss residents additionally have rights to restriction, objection, and portability. California, Virginia, Colorado, Connecticut, Texas, Utah, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Maryland, Minnesota, Rhode Island, Indiana, Tennessee, and Kentucky residents have rights to know, delete, correct, port, and opt out of sale, sharing, and profiling. We do not currently sell or share personal information.
We honor Global Privacy Control signals. We treat a GPC header as an opt-out for any future use that would qualify as sale or sharing.
Your privacy choices: we do not currently sell or share personal information or run targeted advertising, so today there is nothing to opt out of. If that ever changes, we will provide a clear "Do Not Sell or Share My Personal Information" control and honor it, alongside the Global Privacy Control signal we already respect. You can also exercise any right above and turn optional features (location, discovery, friends) on or off in Settings.
To exercise any right, email support@citygirlquestions.com. We respond within 30 days (45 days for US state requests, extendable once with notice). We may verify your identity by asking you to confirm from the email associated with your account.
8. Security
We use TLS in transit, Google's encryption at rest, Firestore security rules, and short-lived authentication tokens. We follow least-privilege access. No system is perfectly secure; please use a strong, unique password.
9. Children
The Service is for users 13 and older. EU/UK users must be 16 or older unless their member state has lowered the age. We do not knowingly collect information from anyone below the applicable age. If you believe a child has signed up, email us and we will delete the account.
10. Changes
We will email you and post a notice in the app at least 7 days before any material change.
11. Contact
Bringham Labs LLC support@citygirlquestions.com