Privacy Policy

Last updated: July 2026

PUNCH is built privacy-first. This policy explains what we collect, why, how long we keep it, and the control you have over it. Plain language, no dark patterns. If anything here is unclear, email hello@punchsocial.co.

1. What we collect

2. What we never do

3. How we use your information

To operate and secure the service, deliver your content to the people you choose, power features you turn on (such as discovery or notifications), process payments, prevent abuse and enforce our moderation policy, and comply with the law. We do not sell your personal data, and we do not train AI models on your private content.

4. Third-party services

We rely on a small set of trusted providers to run PUNCH:

5. Your rights and choices

6. Children and minors

PUNCH is 13+. When you create your profile we ask for your date of birth. If the date you give puts you under 13, we stop there: the account is not created, you are signed out, and the date you entered is not stored. The 13+ rule is applied by our database, not only by the app, so it holds for anything that writes to your account.

To be clear about what that is and is not: the date of birth is self-reported. We do not verify ages, check documents, or estimate age from your face, voice, or behaviour. It is an honest-answer gate, and it only catches people who answer honestly.

We do not knowingly collect personal information from children under 13. If we learn that an account belongs to a child under 13, we will remove the account and delete its data — you can report one to hello@punchsocial.co. Accounts created before we added this question are asked for their date of birth the next time they open the app; until they answer, the account can read and export its data but cannot post, comment, react, or follow. If the date they give puts them under 13, the account is removed and its data is deleted, as described above. As we add default protections for users under 18, we will describe them here.

7. Data retention

We keep account data until you delete your account, plus a 30-day grace period to allow recovery. You can delete individual posts at any time. Operational logs are retained for up to 90 days and encrypted backups for up to 35 days, after which they are purged.

8. Government and legal requests

We disclose data only when legally required, we push back on overbroad requests, and we intend to publish a regular transparency report summarizing the requests we receive.

9. Data location and transfers

Data is primarily stored in the United States (US-East region). Where we serve users in other regions, we apply appropriate safeguards for cross-border transfers consistent with GDPR and other applicable laws.

10. Security

Data is encrypted in transit (TLS) and at rest. Direct messages are encrypted. Access to production systems is restricted and logged, and we conduct security reviews before major releases.

11. Changes to this policy

We will update this page as PUNCH evolves and note the date at the top. For material changes we will notify you in-app or by email before they take effect.

12. Contact

Questions or requests: hello@punchsocial.co.

This policy is a working draft prepared for launch and will be reviewed by counsel before broad public release. It reflects PUNCH's current data practices in good faith.