Privacy Policy
Last updated: August 2026
PUNCH is built privacy-first. This policy explains what we collect, why, how long we keep it, and the control you have over it. Plain language, no dark patterns. If anything here is unclear, email hello@punchsocial.co.
1. What we collect
- Account information — your handle, email, and/or phone number, and your display name and avatar.
- Date of birth — asked for once, when you create your profile, so we can apply our 13+ minimum (section 6). It is stored separately from your profile, is never shown on it, and no other member can read it.
- Content you create — posts, comments, stories, live streams, and the media you upload.
- Direct messages — we store the messages you send so we can deliver them and keep them in sync across your devices. DMs are encrypted in transit and at rest, and section 2 below limits what we will ever do with them.
- Device & technical data — device model, operating system, app version, and IP address.
- Usage signals — likes, saves, and how long you watch, used to rank your feed and improve the product. There is no third-party product-analytics SDK in the app.
- Crash & error reports — diagnostic data when something breaks (via Sentry, with content stripped and no user identity attached).
- Payment information — if you subscribe or tip, processed by Stripe. We never see or store your full card number.
2. What we never do
- Use your DM contents for anything beyond delivering them. We don't proactively scan DM content, and we never use it for ads, recommendations, analytics, or AI training. If a participant reports a DM, the report is reviewed from the context the reporter submits with it (see our moderation policy).
- Run facial recognition on your photos, or collect facial recognition data.
- Collect your contacts. PUNCH has no contact-syncing feature.
- Collect your location. PUNCH has no location features of any kind — precise or approximate.
3. How we use your information
To operate and secure the service, deliver your content to the people you choose, power features you turn on (such as discovery or notifications), process payments, prevent abuse and enforce our moderation policy, and comply with the law. We do not sell your personal data, and we do not train AI models on your private content.
4. Third-party services
We rely on a small set of trusted providers to run PUNCH:
- Supabase — database, authentication, and media storage
- Agora — live video streaming
- Stream — direct messaging infrastructure
- Mux — video processing and playback. Mux also auto-generates captions by machine-transcribing the audio of live streams and video posts.
- Cloudflare — DNS and content delivery
- Hive AI & OpenAI — automated content moderation
- OpenRouter — routes PUNCH's AI features (summaries, translations, draft assist, automatic image descriptions, feed tuning) to third-party model providers. Direct messages are never sent to any AI service.
- Stripe — payments and creator payouts
- Resend — transactional email
- Sentry — crash and error monitoring
A note on the AI features: they receive only public content, or your own unpublished draft when you explicitly ask for writing help — never DMs, and never other people's private content. Public content processed by an AI feature (including images that get an automatic description when you post them) may be retained by the model provider under that provider's own terms. Your drafts are routed only to providers configured to refuse collection and training on prompts.
5. Your rights and choices
- Access — request a copy of your data.
- Deactivate — hide your account in-app (Settings → Account) for 30 days. It is reversible: sign back in any time to reactivate.
- Delete — delete your account in-app (Settings → Account). Deletion is permanent, and your account data is erased within 28 days. Records we are legally required to keep (such as the payment ledger) and copies held by service providers are handled per their retention terms.
- Portability — export your data in-app as a machine-readable JSON file (profile, posts, comments, likes, saves, and follows).
- Correction — update your profile and account details any time.
- Opt out — turn off marketing email and tune or disable algorithmic recommendations entirely.
6. Children and minors
PUNCH is 13+. When you create your profile we ask for your date of birth. If the date you give puts you under 13, we stop there: the account is not created, you are signed out, and the date you entered is not stored. The 13+ rule is applied by our database, not only by the app, so it holds for anything that writes to your account.
To be clear about what that is and is not: the date of birth is self-reported. We do not verify ages, check documents, or estimate age from your face, voice, or behaviour. It is an honest-answer gate, and it only catches people who answer honestly.
We do not knowingly collect personal information from children under 13. If we learn that an account belongs to a child under 13, we will remove the account and delete its data — you can report one to hello@punchsocial.co. Accounts created before we added this question are asked for their date of birth the next time they open the app; until they answer, the account can read and export its data but cannot post, comment, react, or follow. If the date they give puts them under 13, the account is removed and its data is deleted, as described above. As we add default protections for users under 18, we will describe them here.
7. Data retention
We keep account data until you delete your account. If you deactivate your account, it is hidden for 30 days during which you can sign back in to reactivate it. If you delete your account, deletion is permanent and your account data is erased within 28 days. Records we are legally required to keep — such as the payment ledger — and copies held by service providers are handled per their retention terms. You can delete individual posts at any time. Operational logs are retained for up to 90 days and encrypted backups for up to 35 days, after which they are purged.
8. Government and legal requests
We disclose data only when legally required, we push back on overbroad requests, and we intend to publish a regular transparency report summarizing the requests we receive.
9. Data location and transfers
Data is primarily stored in the United States (US-East region). Where we serve users in other regions, we apply appropriate safeguards for cross-border transfers consistent with GDPR and other applicable laws.
10. Security
Data is encrypted in transit (TLS) and at rest. Direct messages are encrypted. Access to production systems is restricted and logged, and we conduct security reviews before major releases.
11. Changes to this policy
We will update this page as PUNCH evolves and note the date at the top. For material changes we will notify you in-app or by email before they take effect.
12. Contact
Questions or requests: hello@punchsocial.co.
This policy is a working draft prepared for launch and will be reviewed by counsel before broad public release. It reflects PUNCH's current data practices in good faith.