Privacy Policy
Version 1.2 · Effective 23 September 2026 · Last updated 28 September 2026 · What changed
This Privacy Policy explains how DQCLabs (“we”, “us”) collects, uses and shares information when you use the TouchBack app for iOS and Android and the website touchbacklove.web.app. For users in the EU and UK, we are the data controller for the processing described here, except where a third party acts as an independent controller.
In short. TouchBack has no login and never asks for your name, email address or phone number. To connect you with one other person, our servers keep an anonymous identity for your phone, the nickname you choose, your pairing, an optional profile photo, and small summaries of your sessions. The live movement of your touch is sent only to your partner and is never stored. A touch you choose to leave for later (up to 10 seconds, or a good-morning touch) is stored as the path your finger drew and deleted after 30 days. The app never asks for your location, contacts or microphone. Analytics and crash reports can be turned off, the free version shows ads with consent where the law requires it, and we never receive your payment card details. We do not sell your personal information; in the free version we do share advertising identifiers with Google to show personalised ads, and you can stop that — see section 9. You can delete your data at any time.
1. Information we collect
No login
You do not create an account. The first time you open TouchBack, the app creates an anonymous identity for your installation. A secret that proves it is yours is kept in your phone’s secure storage (the iOS Keychain or the Android Keystore); our servers keep only a one-way hash of it.
Information you give us
- Nickname — the short name your partner sees (up to 24 characters). It does not need to be your real name.
- Profile photo (optional) — a picture you take with the camera or choose from your photo library. It is resized on your phone (at most 720×720) before it is uploaded, and it is stored as a private file in our file storage. Only you and the one person you are paired with can open it, and only through a link that expires after an hour. You can replace it with another photo, swap it for one of the drawn avatars, or remove it, at any time, from Settings → Profile; the old file is deleted from our storage shortly afterwards.
- Gender and avatar style (optional) — if you set a gender (female, male, non-binary, or “prefer not to say”), the app uses it to choose the right words about you: your partner’s screen says “feel her” or “feel him” rather than “feel them”. If you pick one of the drawn avatars instead of a photo, we store which one. You can leave both unset.
- Invitations — when you invite someone, we create a single-use invitation that expires. We store only hashes of its link token and short code, never the readable code itself.
- Support messages — if you email us, we receive your email address and whatever you choose to write.
Information created as you use the app
- Your pairing — which two anonymous identities are connected, when the connection started and, if it ends, when.
- Session summaries — for each Touch Room session: when it started and ended, its length, how many touches, connections and hugs there were, the longest hold, and a seed used to draw your Touch Print.
- The time of day you use it — each session summary also records the local date and the local hour it happened in, and we keep a running count per day of how many sessions fell in each of the 24 hours. This is how your streak counts against your day rather than UTC, and how a Recap can tell you the hour the two of you touch most. It is a picture of when you two are together, so we treat it as part of your shared history: it is visible only to the two of you, it is deleted on the same schedule as the rest of that history, and it is never used for advertising.
- Touch Prints, Find Me rounds and statistics — the Touch Prints you keep (their style and a preview image), whether a Find Me round succeeded and how long it took, and daily and monthly totals used for your streak, Our Connection and Recaps.
- Presence — whether you are in the Touch Room right now, shared with your partner while you are there, and when you were last seen. Our sky and milestones (day 100, anniversaries) are drawn from the days you met and the date your connection started; nothing new is collected for them.
- Our moment — if either of you sets a daily time, we store that minute, the time zone it was set in and which of you set it; both of you see it, and it is deleted with your connection.
- Installation details — your platform (iOS or Android), app version, and a push notification token so Knocks and pair events can reach you. On an iPhone that supports it, also the tokens Apple issues for Live Activities, so that your partner being in the Touch Room can show on your Lock Screen (you can turn this off in Settings).
- Time zone and language — the time zone and the language your phone is set to, stored with your installation and, when you create an invitation, carried onto the pair. They decide when your day rolls over for streaks, daily statistics and Recaps, and they let a notification arrive in the language you read and at a sensible hour.
- Recovery and transfer — if you create a recovery code or a device-transfer code, we keep only a hash of it, and a record of when it was used.
- Settings — your haptics, sound and notification preferences, including whether you have opted in to occasional messages from us about new features. That one is off unless you turn it on in Settings → Notifications. These preferences now also include a quiet-hours window and a temporary knock snooze; your partner is never told that you set either one and cannot see them. They also include your switches for milestone, Our moment and live-presence notifications, and whether to show your streak; the streak itself remembers which month's rest day has been used.
Information collected automatically
- Usage information, such as screens opened, features used (for example, pairing, sending a Knock, finishing a session, opening the Premium screen), and basic device and app information (device model, operating system, app version, language and country). Collected through Google Firebase Analytics while analytics are turned on.
- Crash and diagnostic information, such as crash logs, error reports and the part of the app in use when a problem occurred. Collected through Firebase Crashlytics while crash reporting is turned on. We configure it not to include pairing codes, recovery codes or tokens.
- Configuration requests — the app fetches settings from Firebase Remote Config, which receives an app-instance identifier and basic device information.
- Advertising information in the free version — see section 5.
- Purchase information if you subscribe — see section 6.
- Network information — like any internet service, our servers and providers receive your IP address when the app connects. We do not store it and we do not use it to work out where you are. Where we have to rate-limit a sensitive action — recovering an identity is the one that matters — we store a keyed one-way hash of the address rather than the address itself, and only for two days. Google’s advertising services do derive an approximate location from your IP address; that is described in section 5.
Cameras, photos, and what we do not collect
TouchBack does not access your location, microphone or contacts, and it never uploads your contacts or your photo library as a whole. What it does ask for is narrower than that:
- The camera — when you scan an invite or device-transfer QR code, and when you choose to take a profile photo. A QR code is read on your phone and the image is never uploaded.
- Your photo library — when you choose an existing picture as your profile photo. Only the one picture you pick is read, and it is resized on your phone before it leaves it. Nothing else in your library is read, listed or uploaded.
- Permission to save to your photo library — only when you tap to save a Touch Print, a Touch Print video or a Recap to your phone.
- Face ID, Touch ID, your fingerprint or your passcode — only if you turn on App lock, or confirm it is you before showing a device-transfer QR or recovery code. Your phone does the check; the app is told only whether it succeeded, and we never receive any of it.
There is no public profile, no user search, no chat, and no contact upload.
Our website
Our website does not use cookies, analytics or advertising scripts. It is hosted on Firebase Hosting, which keeps standard server logs (such as IP address, browser type and pages requested), and it loads fonts from Google Fonts, which receives your IP address. A language choice you make on the site is stored only in your browser. Invitation links that open this website are not logged or analysed by us.
2. Live touch
While you are in the Touch Room, the position and movement of your finger, and Find Me and Follow me game messages, are sent through an encrypted realtime channel that only you and your partner are authorised to join. These messages are ephemeral: they are relayed to your partner and are not written to our database or kept as a log. What remains afterwards is only the session summary described in section 1. Live touch data is never used for advertising or shared with advertisers.
3. How we use information
- To provide TouchBack — to pair you with your partner, relay touch between you, send Knocks, show your history, Touch Prints, streaks and Recaps, and let you recover or transfer your connection.
- To keep it safe — to make sure only the two members of a pair can reach each other, to rate-limit Knocks, invitation and recovery attempts, and to prevent abuse.
- To improve reliability — to find and fix crashes and errors.
- To understand usage — to see, in aggregate, which features are used so we can improve the app, and to tune or roll out features safely.
- To fund the free version — to show, measure and limit the frequency of ads, and prevent ad fraud.
- To provide Premium — to confirm your subscription and unlock its benefits for you.
- To support you — to answer questions you send us.
- To meet legal obligations — for example, keeping financial records.
Under EU and UK data protection law, we rely on the performance of our contract with you to provide the app and Premium; on our legitimate interests for security, analytics and crash reporting (which you can switch off); on your consent for personalised advertising and, where required, for storing or accessing information on your device for advertising; and on legal obligations for financial records.
We do not sell your personal information, and we do not use it for any purpose not described in this policy. In the free version we do allow Google to receive advertising identifiers and ad interaction data in order to show you personalised ads — which California law calls “sharing” for cross-context behavioural advertising. You can stop it; section 9 explains how.
4. What your partner sees
TouchBack is a shared space, so some information is visible to the one person you are paired with: your nickname, your profile photo and the gender you set if you set them, whether you are in the Touch Room and when you were last there, your touch in real time, Knocks and touches you send, the Our moment time either of you sets, and the history, Touch Prints, statistics and Recaps you create together — including the hours of the day you tend to be in the room. Your photo is visible only to the two of you: their app opens it through a short-lived link, and nobody else, paired or not, can read it. Premium applies only to the person who subscribes; your partner may see the touch trail and room theme you choose with it. Nobody else can see any of this.
If you share a Touch Print or Recap image, it goes to the app you choose in your phone’s share sheet, under that app’s own privacy policy.
5. Advertising and consent
The free version of TouchBack shows ads served by Google AdMob, including optional rewarded ads you can choose to watch for a temporary cosmetic reward.
When ads are requested, the Google Mobile Ads SDK may collect your IP address and the approximate location derived from it, device information, your device advertising identifier where available, and interactions with ads. Your touches, presence, pairing and recovery information are never used for ad targeting.
Consent
The app uses Google’s User Messaging Platform to check whether a consent message is required where you are (for example, in the EEA, the UK and Switzerland). Where it is, the message is shown before ads are requested, and lets you accept, refuse or choose specific purposes. If you do not consent to personalised ads, you may still see non-personalised or limited ads. Where available in your region, you can change your choice later from the app’s privacy settings.
Tracking on iOS and the Android advertising ID
On iOS, the app may ask for permission to track your activity across other companies’ apps and websites; the advertising identifier (IDFA) is only available if you allow it, and declining limits no feature. You can change this in iOS Settings → Privacy & Security → Tracking. On Android, you can reset or delete your advertising ID in your device settings (usually Settings → Privacy → Ads or Settings → Google → Ads).
Google acts as an independent controller of the advertising information it collects. See How Google uses information from sites or apps that use its services. We receive only aggregate reports from AdMob.
6. Subscriptions and purchases
TouchBack Premium is an optional subscription sold through the Apple App Store and Google Play. Payment is processed entirely by Apple or Google. We never receive your card number, billing address or other payment credentials.
We use RevenueCat to confirm whether a subscription is active, to show plans and prices, and to restore purchases. RevenueCat and our servers receive purchase information from the store (such as the product, transaction identifier, purchase and expiry dates, price, store country and status), linked to your anonymous identity so that Premium can be unlocked for you.
You can manage or cancel your subscription in your App Store or Google Play account settings. Deleting the app does not cancel a subscription.
7. Service providers
The app and website use the following services, which receive or process information as described above:
| Service | Purpose | Privacy policy |
|---|---|---|
| Supabase | Anonymous identity, database, realtime touch relay, file storage and server functions | Supabase Privacy Policy |
| Firebase Analytics | Understanding app usage | Firebase privacy |
| Firebase Crashlytics | Crash and error reporting | Firebase privacy |
| Firebase Remote Config | Feature settings and safe rollouts | Firebase privacy |
| Firebase Cloud Messaging, Apple Push Notification service | Delivering Knocks and pair notifications | Firebase privacy · Apple |
| Google AdMob, Google User Messaging Platform | Serving and measuring ads; collecting ad consent | Google Privacy Policy |
| RevenueCat | Subscription status and purchase restore | RevenueCat Privacy Policy |
| Apple App Store, Google Play | App distribution and payment | Apple · Google |
| Firebase Hosting, Google Fonts | Serving this website | Google Privacy Policy |
Providers that process information on our behalf do so under data processing terms that require them to protect it. Google, when serving ads, and Apple and Google, as app stores, handle information under their own privacy policies. These providers may process information outside your country, including in the United States, using legally recognised transfer safeguards such as Standard Contractual Clauses.
8. Retention and security
- Live touch: not retained — relayed and discarded.
- Your profile (nickname, photo, gender, avatar style): kept while you use TouchBack, and erased the moment you use Delete my data. A photo you replace, remove or delete is taken out of our storage by a cleanup job that runs every ten minutes. What is left of a deleted account is an empty marker holding only the anonymous identifier and the date — no nickname, no photo, no gender, no settings — kept for 30 days so the same identity cannot be re-created, and then deleted.
- Your pairing and the history it creates (session summaries with their local date and hour, Touch Prints and their preview images, Find Me rounds, daily and lifetime statistics, Recaps): kept while the pair is active, and deleted automatically 30 days after the pair is disconnected. That window exists so an accidental disconnect — or a disconnect the two of you undo — does not destroy a shared history: reconnect inside the window and it comes back. When you disconnect you can also choose Delete our memories now: the shared history is then deleted at once, for both of you, and nothing comes back if you reconnect. Ask us and we will delete it sooner. If either of you uses Delete my data, that history is removed immediately instead, for both of you — see section 9.
- What you can see of it: in the free version the app shows the last 30 days of history; Premium removes that limit. History you cannot see is still deleted on the schedule above, not kept longer.
- Invitations and device-transfer codes: stored as hashes, unusable once used or expired, and deleted 7 days afterwards. Recovery codes: stored as a hash while active, and deleted 30 days after you revoke one.
- Installation records and push tokens: kept while the installation is in use. The push token is deleted the moment the installation is revoked — when you transfer to a new device — and the whole record, including its secret, time zone and language, is deleted when you delete your data. If you use one-tap Knock (widgets, Siri, Control Center, Quick Settings), the record also holds a one-way hash of a key kept on your device that can only send your Knock to your person; it stops working when the installation is revoked or you are no longer connected, and is deleted with the record.
- Knock records (who knocked whom and when, the rhythm that was tapped — or, for a touch you leave, the path your finger drew on the canvas, and when a good-morning touch is due to arrive — and whether it was opened or answered): 30 days. A rhythm the two of you save as Our Knock is kept with your connection and deleted with it. Notification queue records: 14 days. Rewarded-ad records: 7 days after the reward expires.
- Rate-limiting records: 2 days. Where a rate limit has to be tied to a network address, we store only a keyed one-way hash of it, never the address.
- Usage and crash information: kept under the retention period set on our Firebase project — at most 14 months for analytics events and 90 days for crash reports — then deleted or kept only in aggregate form.
- Advertising information: kept by Google under Google’s retention policies.
- Subscription receipts: kept while the subscription runs and, once you delete your data, for 7 years afterwards to meet tax, accounting and audit obligations — detached from you at the moment of deletion, so what remains is the store transaction reference, product, price and dates, with no link to your profile. Payment notifications we receive from the store are kept for 400 days, and are stripped of everything describing you as soon as you delete your data.
- Emails you send us: kept while we handle your request and for up to 12 months afterwards.
All traffic between the app and our servers, including the realtime channel, is encrypted in transit. Every pair-scoped record is protected by access rules that let only the two members of that pair read it, and secrets on your phone live in the operating system’s secure storage. No method of transmission or storage is completely secure, but we limit what is collected to reduce risk.
9. Your choices and rights
Choices in the app
- Analytics and crash reports: turn them off in the app’s privacy settings. This does not limit any feature.
- Notifications: choose which notifications you receive in Settings → Notifications, or turn them off in your phone’s settings. There you can also set quiet hours and hold knocks for a while. A knock sent while you are quiet is discarded rather than saved for later — we keep no record that it was held — and the person who sent it is told nothing, so it simply goes unanswered; it is still waiting in the app when you open it. Recap notices wait until your quiet window ends, and notices that your connection was created or ended are always delivered, whatever the time. Deciding when a notification may arrive is what your device's timezone (section 1) is used for.
- Ads: change ad consent where your region offers it; use your iOS Tracking or Android Ads setting; or subscribe to Premium. Premium removes ads entirely — no ad is requested at all while a subscription is active, which is the strongest ad control the app offers.
- Your photo, gender and avatar: change or remove any of them at any time in Settings → Profile. Removing a photo deletes the file from our storage.
- Disconnect: end your pairing at any time from Settings. Your partner can no longer reach you. They get a notification unless you choose to leave quietly; either way their app learns the connection ended the next time it opens.
- Delete everything: Settings → Privacy → Delete my data, described below.
Your rights
Depending on where you live (including the EEA, the UK and US states such as California), you may have the right to access, correct, delete or receive a copy of your personal information, to object to or restrict its processing, to opt out of targeted advertising, and to withdraw consent at any time. We will not discriminate against you for exercising these rights.
Deleting your data. The fastest way is in the app: Settings → Privacy → Delete my data. Everything personal is erased at that moment, not marked for later: your profile (nickname, photo, gender and avatar style), your settings, every device registration with its secret, push token, time zone and language, your recovery and transfer codes, your Knocks and queued notifications. Your partner is told the pairing has ended.
It also deletes the history the two of you made together, for both of you. A pair is two people: a session summary merges what both of you did, a Touch Print is drawn from a seed belonging to the pair, and a statistic counts you both. None of it can be split in half or made anonymous, because with exactly two people in the room the other one always knows whose it is. So every pair you have been part of is removed — session summaries, Touch Prints and their preview images, Find Me rounds, statistics and Recaps. Anything either of you already saved to your own photo library stays on your own phone. Your partner’s own account is not touched: their profile, settings, devices, recovery code and subscription all survive, and so does any pairing they have with somebody else. If you only want to stop rather than erase, disconnect instead — that keeps the shared history for 30 days.
If you no longer have the app, or want to exercise any other right, use our data deletion page or write to us at the address below. Because TouchBack has no login, include the nickname shown in your app and roughly when you paired so we can find your records; for subscription records, include the order or transaction ID from your Apple or Google receipt — though once your data is deleted we can no longer match a receipt to you, which is the point of detaching it. Please never send us your recovery code. We answer within 30 days. You also have the right to complain to your local data protection authority.
What we keep after deletion, and why. Two things. If you ever subscribed, the receipt is kept for 7 years to meet tax, accounting and audit obligations — a legal obligation — but it is detached from you at the moment of deletion: the link to your profile and the subscription provider’s identifier for you are erased, leaving the product, the price, the dates and an irreversible reference that cannot be traced back to you. The payment notification the store sent us is stripped of everything describing you at the same time, and deleted after 400 days. Second, abuse counters used to rate-limit sensitive actions, which hold only a one-way hash and expire within 2 days. Beyond those, an empty marker — the anonymous identifier and the date you deleted — is kept for 30 days so the identity cannot be re-created, then deleted. Aggregated statistics that cannot be linked back to you may remain.
United States — California and other states
If you live in California — or in another US state with a similar law, such as Colorado, Connecticut, Virginia, Texas or Oregon — you have the right to know what personal information we collect and why, to access or delete it, to correct it, to obtain a portable copy, and to opt out of targeted advertising. We have not sold personal information in the previous 12 months and we do not sell it now. We do allow Google to receive advertising identifiers and ad interaction data in order to show you personalised ads in the free version, which California law treats as “sharing” for cross-context behavioural advertising.
Do Not Sell or Share My Personal Information / opt out of targeted advertising. You can stop it in any of these ways, and you do not need an account to do so:
- on iOS, decline the tracking request when the app asks, or turn TouchBack off under Settings → Privacy & Security → Tracking;
- on Android, switch on Delete advertising ID, or opt out of ad personalisation, under Settings → Privacy → Ads;
- in TouchBack, open Settings → Privacy → Ad privacy choices where your region offers it;
- subscribe to Premium, which stops every ad request;
- or email us with the subject “Do Not Sell or Share” and we will apply it to your installation.
We honour a Global Privacy Control signal sent to this website as a valid opt-out request. We do not use or disclose sensitive personal information for purposes that would give you a right to limit it. We do not knowingly collect or share the personal information of anyone under 16. We will not discriminate against you for exercising any of these rights, and you may appoint an authorised agent to act for you. Because there is no login, we verify a request by matching the details you give us — the nickname in your app, roughly when you paired, a store transaction ID — against our records, and we will tell you if we cannot match them rather than delete someone else’s data.
10. Children, changes and contact
Children
TouchBack is not directed at children under 13 (or the minimum age of digital consent in your country), and we do not knowingly collect personal information from them. If you believe a child is using TouchBack, contact us and we will delete the related information.
Changes to this policy
We may update this policy when the app or the services it uses change. We will update the date at the top of this page and, for material changes, let you know in the app or on this website before they take effect.
What changed in version 1.2
- Added the touches you can leave for later (a tapped rhythm, up to 10 seconds of drawn touch, a good-morning touch) and Our Knock, and how long they are kept (sections 1 and 8).
- Added the one-tap Knock key hash, the Live Activity tokens, Our moment, the new notification and streak settings, and App lock (section 1).
- Added Delete our memories now and leaving quietly when you disconnect (sections 8 and 9), and Follow me to live touch (section 2).
What changed in version 1.1
- Described the profile photo — what is uploaded, where it is stored, that only your partner can see it, and how to remove it — and corrected the old sentence that said we did not access your photo library. We do, when you pick a picture, and only that picture (section 1).
- Added the gender and avatar style you can set, your phone’s time zone and language, and the local hour recorded with each session (section 1), and added the photo and gender to what your partner sees (section 4).
- Replaced the qualitative retention section with the actual periods (section 8).
- Rewrote deleting your data to match a rebuilt deletion that now erases everything personal immediately — including the history of every pair you were in, for both people — and added a data deletion page you can use without the app (section 9).
- Added a California and US states section covering “sharing” for advertising and a Global Privacy Control commitment (section 9).
- Said plainly how your IP address is and is not used (section 1), and that Premium removes ads entirely (section 9).
Contact us
For privacy questions or requests, contact DQCLabs, publisher of TouchBack and the controller of your personal data:
- DQCLabs
- Address
- Phone
- Email cuong.software.dev@gmail.com
You can also complain to the data protection authority in your country.