Privacy Policy

Effective: 16 May 2026 · Last updated: 16 May 2026 · Operator: Incultnito LLC (Wyoming, USA) · Contact: [email protected]

Hi — I'm Peng, the founder of Homeboys. I built this app because I'm a guy in my 30s and making friends as an adult is hard. Homeboys is for men 30+ who want to do things together — boxing, hiking, basketball, hotpot, whatever — and walk away with a real friend. It is not a dating app.

This page explains, in plain language, what data the app collects, why, who else sees it, and how you can get rid of it. The operator of the service is Incultnito LLC, a Wyoming limited liability company. If anything below is unclear, email me at [email protected] and I'll fix it.

1. Who this policy covers

This policy covers the Homeboys mobile app (iOS and Android) and the homeboys.app website. It applies to anyone who creates an account or visits the site.

Minimum age: 18. Homeboys is for adults. If you are under 18, do not create an account. If we learn an account belongs to a minor, we will delete it.

2. Who is the data controller

We do not have a dedicated Data Protection Officer because we are a small pre-launch team. Privacy requests go to the email above and I answer them personally.

3. What we actually collect (and why)

We collect only what the app needs to do its job: help you find activities near you, let you join groups, and keep bad actors out. Here is the full list.

DataWhy we collect itWhere it livesLegal basis
Email address + password (hashed)Create and authenticate your accountSupabase AuthContract
Display nameShow you to other members of activities you joinSupabase databaseContract
Avatar photo (optional)Help group members recognise youSupabase StorageConsent
Bio (optional, free text)Let you introduce yourselfSupabase databaseConsent
Interests, preferred time, preferred distance, skill level, preferred group size, languageRank activities you are more likely to enjoySupabase databaseContract
Approximate location (GPS coordinates, rounded so it does not pin your home)Show activities within your chosen radiusSupabase database (PostGIS)Consent — you can deny location permission and use the app at city/district level
Phone number (when you opt into phone verification)Confirm you are a real person; required to send DMs and to host evening activities (after 21:00 Taipei local time)Supabase database + Twilio (SMS delivery)Contract + legitimate interest in fraud / safety
Selfie photo (when you opt into selfie verification)Confirm a real human is behind the account; required to host activities. The image is sent once to OpenAI's Vision API to check for a live face, then a verified=true flag is set on your profile.Supabase Storage (see retention below) + OpenAI (transient)Consent + legitimate interest in safety
Activities you create, swipe on, join, or check in toMatch-making, group chat, and the "mutual attendance" rule that unlocks DMsSupabase databaseContract
Group chat messages + direct messagesDeliver messages to the right peopleSupabase databaseContract
Reports you file (against a user, message, or activity)Safety review and moderationSupabase databaseLegitimate interest in safety
Push notification token (Expo)Send you push notifications about chats, joins, remindersSupabase database + Expo push serviceConsent — denying notification permission disables this
Date of birth (only if you fill it in)Confirm 18+ for accounts that opt to set itSupabase databaseConsent

What we do not collect

4. Legal basis for processing (GDPR-style summary)

For users in jurisdictions that require a legal basis to be named:

5. Who else sees your data (sub-processors)

Homeboys is a small team. We use a handful of established vendors to actually run the service. We do not sell data to anyone. The vendors only process data on our behalf and only for the purpose described.

We may also be required to share data with law enforcement if served with a valid legal order. We will only disclose what the order compels.

6. Where the data is stored (international transfers)

Most of our vendors are based in the United States. If you use Homeboys from Taiwan, the EU, the UK, or anywhere outside the US, your data will be transferred to and processed in the US. For users in the EU/UK, we rely on the vendors' Standard Contractual Clauses and their own transfer safeguards (see each vendor's privacy policy above). For users in Taiwan, transfers comply with the Personal Data Protection Act ("個人資料保護法").

7. How long we keep it (retention)

8. Your rights

Regardless of where you live, you can ask us to:

How to exercise these rights:

9. Security

No system is perfectly secure. If you believe your account has been compromised, email us immediately and we will lock it.

10. Cookies and web analytics

The homeboys.app marketing website does not use cookies or web analytics. There are no third-party scripts, no Google Analytics, no pixels, no consent banner because there is nothing to consent to. The app itself does not use web cookies (it stores an auth token via expo-secure-store, which is the device keychain, not a browser cookie).

11. Push notifications

If you grant notification permission, we send you push notifications about new messages, activity joins, and reminders. Delivery happens through Expo's push service (which routes via Apple APNs and Google FCM). You can disable notifications any time in your phone's settings.

12. Children

Homeboys is for adults aged 18 or older. We do not knowingly collect data from minors. If you become aware that a minor has an account, email us and we will delete it.

13. Changes to this policy

If we make a meaningful change (new vendor, new data category, change in retention), we will update the "Last updated" date at the top and, for material changes, notify you in-app or by email before it takes effect. Minor wording fixes will be made silently.

14. Contact

Any question, request, or correction — email [email protected].

Incultnito LLC · Wyoming, USA · Operator: Peng (Taiwan)


隱私權政策

生效日期:2026 年 5 月 16 日 · 最後更新:2026 年 5 月 16 日 · 營運者:Incultnito LLC(美國懷俄明州)· 聯絡:[email protected]

嗨,我是 Homeboys 的創辦人 Peng。我做這個 app,是因為自己也是三十幾歲的男生,長大之後要交朋友真的很難。老友 Homeboys 是為 30 歲以上的男性而生——一起打拳、爬山、打球、吃火鍋,做完一件事,認識一個真的朋友。這不是交友軟體(dating app)

這份政策用最直白的話說明:我們收集哪些資料、為什麼收集、誰會看到、你怎麼把它拿回來或刪掉。本服務的營運者是 Incultnito LLC,一家設立於美國懷俄明州的有限責任公司。任何不清楚的地方,請來信 [email protected]

1. 本政策適用範圍

適用於 Homeboys 行動應用程式(iOS 與 Android)以及 homeboys.app 網站。任何註冊帳號或造訪網站的人都適用。

最低年齡:18 歲。未滿 18 歲請勿註冊。若我們發現帳號屬於未成年人,將予以刪除。

2. 個資管理者是誰

我們是上線前的小團隊,沒有專職的資料保護官(DPO)。所有來信由我本人回覆。

3. 我們實際收集了哪些資料(以及為什麼)

只收 app 真正需要用到的——幫你找到附近的活動、加入群組、把行為不當的人擋在外面。完整清單如下:

資料為什麼儲存在哪法律依據
電子郵件 + 密碼(雜湊處理)建立帳號、登入Supabase Auth履行契約
暱稱讓同活動的成員認得你Supabase 資料庫履行契約
頭像照片(選填)群組裡好辨識Supabase Storage同意
自我介紹(選填,純文字)讓你介紹自己Supabase 資料庫同意
興趣、偏好時段、活動半徑、技能等級、人數偏好、語言把你比較會想去的活動排前面Supabase 資料庫履行契約
大概的位置(GPS 座標,會做精度模糊化,不會精準到你家)顯示你選定半徑內的活動Supabase 資料庫(PostGIS)同意——你可以拒絕定位權限,仍以行政區層級使用 app
手機號碼(開啟手機驗證時)確認是真人;發送私訊與主辦晚間活動(台北時間 21:00 之後)需先通過手機驗證Supabase 資料庫 + Twilio(簡訊發送)履行契約 + 反詐騙正當利益
自拍照(開啟自拍驗證時)確認帳號背後是真人;主辦活動需通過此驗證。照片會傳一次給 OpenAI Vision API 做活體檢測,然後在你的個人檔上設為 verified=trueSupabase Storage(保留方式見下節)+ OpenAI(暫存)同意 + 安全正當利益
你建立、滑動、加入或報到的活動媒合、群組聊天、雙方都到場後才開啟私訊的規則Supabase 資料庫履行契約
群組聊天訊息 + 私訊把訊息送到正確的人那裡Supabase 資料庫履行契約
你提出的檢舉安全審查與內容審核Supabase 資料庫安全正當利益
推播通知 token(Expo)傳送聊天、加入、提醒等通知Supabase 資料庫 + Expo 推播服務同意——拒絕通知權限會自動停用
出生日期(僅在你自願填寫時)確認 18 歲以上Supabase 資料庫同意

我們收集的東西

4. 處理的法律依據(GDPR 風格摘要)

5. 還有誰會看到你的資料(次處理者)

Homeboys 是個小團隊,我們把實際運作交給幾家成熟的服務商。我們不販售任何資料。這些服務商只在我們的指示下、為了上述目的處理資料。

若收到合法的執法機關命令,我們可能會依命令範圍提供必要資料,並僅限該範圍。

6. 資料的存放位置(跨境傳輸)

我們大部分的服務商在美國。如果你從台灣、歐盟、英國或美國以外的地方使用 Homeboys,你的資料會被傳輸到美國處理。對於歐盟/英國使用者,我們依賴各服務商的標準契約條款(SCCs)與其本身的傳輸保障措施(請參閱上述各家隱私政策)。對於台灣使用者,相關傳輸符合《個人資料保護法》之規範。

7. 我們保留多久(保存期間)

8. 你的權利

不論你居住在哪裡,你都可以要求我們:

如何行使這些權利:

9. 安全措施

沒有完美安全的系統。若懷疑帳號被盜,立刻來信,我們會立即鎖定。

10. Cookie 與網站分析

homeboys.app 行銷網站不使用 cookie 或任何網站分析工具。沒有第三方腳本、沒有 Google Analytics、沒有像素、沒有 cookie 同意橫幅——因為沒有東西需要你同意。App 本身也不使用網頁 cookie(登入 token 透過 expo-secure-store 存於裝置 keychain,並非瀏覽器 cookie)。

11. 推播通知

若你授予通知權限,我們會傳送新訊息、活動加入與提醒等推播。實際派送透過 Expo 的推播服務(再轉送至 Apple APNs 與 Google FCM)。可隨時於手機系統設定關閉。

12. 兒少保護

Homeboys 服務對象為 18 歲以上成年人。我們不會明知而收集未成年人之資料。若你發現帳號屬於未成年人,請來信,我們會予以刪除。

13. 政策變更

如有重大變更(新增服務商、新增資料類別、保存期間調整),我們會更新頁首的「最後更新」日期,並於 app 內或以電子郵件先行通知。文字小幅修正則不另行通知。

14. 聯絡我們

任何問題、要求或更正,請來信 [email protected]

Incultnito LLC · 美國懷俄明州 · 營運者:Peng(台灣)