Privacy & Safety Center
Duruha is designed to be an intentional, reputation-aware community. Review our strict data safeguards, identity protections, and community guidelines below.
Verification IDs Deleted
Government IDs uploaded for persona verification are permanently deleted immediately after approval or rejection. We store no copies.
No Background Tracking
Location coordinates are captured once at onboarding to place you in the community hierarchy. No passive or background tracking.
No Advertising Profiles
We do not sell, rent, trade, or lease personal data. Duruha is completely free from third-party advertising trackers.
Privacy Policy
Effective Date: May 19, 2026 • Last Updated: September 24, 2026
This Privacy Policy explains what information Duruha collects from you when you use the Duruha mobile application ("App"), why we collect it, how we use and protect it, and what choices you have. By creating an account, you agree to the collection and use of information described here.
1. Introduction
Duruha ("we," "our," or "us") is a trust-first social platform that connects people through verified identities, geo-filtered communities, and credibility-based content. Our mission is to enable meaningful, accountable communication by ensuring that the people behind profiles are who they say they are. This Privacy Policy explains what information we collect from you when you use the Duruha mobile application ("App"), why we collect it, how we use and protect it, and what choices you have. By creating an account or using the App, you agree to the collection and use of information described in this policy.
2. Information We Collect
We collect information you provide directly and information generated automatically as you use the App:
2.1 Information You Provide Directly
When you create an account or use the App, we may collect: - Account information: Email address, password (stored as a hashed credential, never in plain text), and display name. - Profile information: Date of birth, place of birth, persona labels, username, bio, profile photo, and any links you add to a persona. - Location information: If you choose to provide it during onboarding, we collect your device's GPS coordinates to place you within our geographic community hierarchy. This is optional. See Section 5 for details. - User-generated content: Posts (text, images, video, audio), comments, reactions, votes, poll votes, agenda items, wiki entries, and other content you create or share on the platform. - Feed preferences and muted topics: Your algorithm configuration choices, muted geographic areas, and muted communities. - Connections (social graph): When you send or accept a connection request, we record the link between your persona and the other persona. This connection graph powers connections-scoped visibility (such as posts you share only with your connections) and notifies the other party. You can remove a connection at any time. - Profile and search visibility preference: Your choice of who can find your profile in search and see your activity history — public, connections only, or private — plus your stealth-mode and per-activity anonymity settings. See Section 10. - KLIPY media search and selection data: If you use the media picker, your search terms are sent to KLIPY so the App can display GIF, clip, meme, or sticker results. If you attach KLIPY media to a post or comment, the selected media URL, preview URL, provider, dimensions, media type, and media slug may be stored with that content. - AI search queries: If you use the AI news search ("Ask" or "Digest"), the question or request you type is processed to generate an answer grounded in news content on the platform. Queries are sent server-side to our AI model provider (Alibaba Cloud Model Studio; see Section 8), logged per persona for daily-quota metering, and answers may be kept in a short-lived shared cache. AI features are optional and available only to signed-in users. - Facebook Page connection data: If you connect a Facebook Page to a community or custom persona in order to cross-post, we store the Page's ID, name, and avatar URL, the connecting persona, and the connection's status and expiry. The Facebook access token itself is held in an encrypted secrets vault, never in an ordinary database column. See Section 8. - Feature requests and feedback: Suggestions you submit through the in-app feature request tool, stored with your submitting persona. - Deactivation and deletion reasons: If you deactivate or delete your account, the reasons you select and any free-text reason you type are stored with that request. See Sections 9 and 10. - Subscription, credits, and wallet data: Your persona's and your communities' subscription tier, daily publishing/AI ("Urduha") credit usage, storage usage, and a community wallet balance and transaction history (e.g. admin top-ups). This is a virtual, platform-internal accounting system — Duruha does not currently process real-money payments or integrate a payment processor, and no card, bank, or e-wallet information is collected. See Section 8 (Payments). - Messages and discussions: The content of messages you send in one-to-one chats, group chats, community chats, and news "Discussions" — including text, attached images, GIFs and other media, mentions of other personas, reply quotes, and edits — together with chat membership, invitations, join requests, and moderation state (muted, archived, frozen, removed). IMPORTANT: messaging on Duruha is NOT end-to-end encrypted. See Section 7. - Journal entries: Personal journal posts and the audience you choose for each one (private, unlisted, or public). A private entry is visible only to you; an unlisted entry is reachable only by direct link; a public entry behaves like any other public post. - Calendar and event data: Events you create or save in your personal calendar and in community calendars, including titles, descriptions, dates and times, and your participation in community events. - Cosmetic items: Which avatar frames, post borders, loaders, and similar cosmetic items you own, when you acquired them, and the wallet credits spent on them. Cosmetics you apply are visible to other users.
2.2 Identity Verification Information (KYC)
If you apply for a Verified Persona badge, we collect, for internal identity review only: - Government ID images: A photo of the FRONT and the BACK of a valid government ID (passport, driver's license, or national ID). - A selfie: A photo of your face, used to confirm that the person submitting the ID is its holder. - Identity details: Your full legal name, date of birth, and place of birth, matched against the submitted ID. These images are uploaded to a PRIVATE storage location. They are never displayed on your public profile and are not shared with other users. They are accessible only to a small number of authorized Duruha compliance staff during the review window. Once a request is approved or denied, the raw ID and selfie images are permanently deleted. What remains on the verification record after that deletion is: your full legal name, date of birth, place of birth, the review outcome and any rejection reason, the reviewing administrator, and a one-way SHA-256 "identity fingerprint" derived from the images, used solely to detect duplicate or fraudulent re-submissions. See Section 4. - Persona and community role-verification proof: Photos (e.g. a certificate, professional ID badge, or credential card — never a government ID) and links you submit to support a persona claim (or, for community leaders, to prove ownership/leadership of a community). Unlike the government-ID KYC flow above, this proof is PUBLIC and PERMANENT from the moment you submit it: it is uploaded to a public CDN (Bunny.net) and displayed on your public profile (or the community's public verification page) once approved, with no private staging copy. Do not submit any document containing information you do not want publicly visible. See Section 4E. We do not grant verification based on self-attestation alone. All personas require objective, verifiable, matching proof.
2.3 Automatically Collected Information
The App does not integrate third-party analytics or crash reporting services. We do not collect advertising IDs and do not build advertising profiles. The only automatically collected information is: - App activity signals: Interactions such as votes, saves, shares, and views, used to calculate credibility and reputation signals within the platform and to detect vote manipulation between accounts. - View and visit records: We record views of posts, communities, and agendas, and visits to persona profiles, so we can show view and visit counts and rank content. Each record stores the viewing persona (or, for signed-out or anonymous viewing, a pseudonymous viewer identifier) and a timestamp. If your persona is in stealth mode, your visit is marked as such and is not attributed to you in the viewed profile's list. - Session authentication tokens: Managed by Supabase Auth, stored securely using Android Keystore-backed storage. - Push notification token: A device push token issued by Firebase Cloud Messaging (a Google service) and stored on our servers (associated with your active persona) so we can deliver notifications. The token identifies your app installation, not you personally, and is deactivated when you sign out or when the operating system refreshes it. See Section 7. - AI usage logs: When you use an AI feature, we record the query, timestamp, and outcome per persona to enforce the daily usage quota and detect abuse. See Section 8 (AI model provider) and Section 9 (retention). - Media upload events and publishing credits: We log the kind and time of media uploads, and the publishing credits your persona spends when posting, to enforce fair-use limits. Publishing credits are an internal, non-monetary allowance; they cannot be bought. - App update checks: The App checks for over-the-air code patches through Shorebird, and may check the app store for a newer published version. These checks carry standard request metadata (such as app and patch version); they do not include your identity, advertising IDs, or content data. - Anonymous viewer token: Public content can be browsed without signing in. So that the same device is not counted twice in a post's or profile's view count, the App generates a random identifier on first use and stores it on your device. It contains no personal information, is never used for advertising or cross-app tracking, and is reset if you clear app data. - Activity heartbeat: We record, per profile, the calendar dates on which the account was active. This is used to produce internal aggregate statistics (daily active users, retention) for Duruha administrators. We do not record a minute-by-minute usage timeline. - Content and engagement analytics: View counts, votes, saves, shares, and comment counts on your posts, profile-visit counts, and — for videos served through Bunny Stream — aggregate watch-retention data. Post analytics are shown to the post's author; profile visits are shown only as a combined total, never broken down by visitor. - Screen-time ("Mindfulness") data: If you enable the optional screen-time reminders and blocks, your thresholds, schedule, and accumulated foreground time for the day are stored ON YOUR DEVICE ONLY. This data is never uploaded to our servers.
3. How We Use Your Information
We use the information we collect to: - Create and manage your account and verified persona - Authenticate your identity and secure your session - Populate and personalize your geographic and interest-based feeds - Display community and content relevant to your location or persona - Calculate and display credibility and reputation signals, and detect coordinated voting - Establish connections between personas and apply your chosen profile and search visibility (public, connections only, or private) - Deliver your messages to the chats and discussions you take part in, and operate chat membership, invitations, join requests, and moderation - Show your journal entries to the audience you selected for each entry - Operate your personal calendar and community event calendars - Show you and other users cosmetic items you own and have applied - Produce view, engagement, and retention analytics for authors and aggregate usage statistics for Duruha administrators - Send you push notifications about activity relevant to you - Let you search, preview, and attach GIFs, clips, memes, and stickers through KLIPY - Generate AI answers, digests, document summaries, and community assistance panels from your queries, uploaded documents, and platform news content, and meter your daily AI usage quota - Track subscription tier, publishing/AI credit usage, storage usage, and community wallet balance to meter and gate paid-tier features - Publish your posts to a Facebook Page when you explicitly choose to cross-post - Deliver official Duruha announcements and app updates (including over-the-air code patches via Shorebird) - Review and act on feature requests and feedback you submit - Review and process verification applications - Enforce community safety, investigate reports, and take moderation action - Detect and prevent fraud, spam, impersonation, and misuse - Respond to support requests - Comply with applicable laws and legal obligations We do NOT use your information for targeted advertising. We do NOT use your information to build advertising profiles. We do NOT sell, rent, trade, lease, or license your personal data to any third party.
4. Identity Verification Documents (Private KYC Model)
Verification on Duruha is a private "know your customer" (KYC) review. There is NO publicly displayed copy of your ID. The images you submit are never shown to other users. What you submit: - A photo of the FRONT of your government ID. - A photo of the BACK of your government ID. - A SELFIE used to confirm you are the holder of the ID. - Your full legal name, date of birth, and place of birth. How it is handled: - All three images are uploaded to a private, access-controlled storage bucket. They are encrypted at rest. - Access is restricted to a small number of authorized Duruha compliance staff under strict confidentiality obligations, only during the review window. - Before upload, the app computes a one-way SHA-256 "identity fingerprint" over the combined image bytes. This fingerprint is checked against existing records so that duplicate or recycled documents are flagged as a potential fraud signal. - When a reviewer approves OR denies your request, the raw ID and selfie images are permanently and securely deleted from our systems by an automated purge, and the request is stamped with the time of that purge. The same purge runs on any earlier pending submission that a resubmission supersedes. - After the purge, the verification record retains your full legal name, date of birth, place of birth, the outcome, and the non-reversible identity fingerprint — never the images themselves. Those retained details are removed when you delete your account. - If a verification request is rejected, you may resubmit; rejected images are likewise not retained beyond the review. Because the images are never made public, you do NOT need to redact them. Submit clear, unaltered images so review can succeed. Verification does not constitute endorsement. A verified badge means only that the submitted evidence was reviewed and matched the stated persona at the time of approval. It does not guarantee the accuracy of any future statements, advice, or opinions the user may post.
5. Location Data
What we collect: If you choose to provide location during onboarding, we collect your device's GPS coordinates (latitude and longitude) using Android's location services. Why: Location is used to place you within our geographic community hierarchy (barangay, city, province, region, country) and to show you geographically relevant content, communities, and posts. Background location: We do NOT request or use background location. Location is captured only during the one-time onboarding step, with your explicit permission. Public visibility: Your raw GPS coordinates are not displayed to other users. Community-level placement (e.g., city or barangay association) may be visible through your profile or content, and — subject to your visibility setting — your persona may appear in location-based people search. Control: Location permission is optional at onboarding. You may deny location access and enter your location manually using the geographic hierarchy picker (barangay to city to province to region to country). You may update your location through the edit-identity screen at any time, and you can revoke location permission at any time through your Android device settings.
6. User-Generated Content, Anonymity, and Moderation Access
Content you post on Duruha — including text posts, images, videos, audio recordings, comments, and linked credentials — may be visible to other users of the platform depending on the community context in which it is shared. Anonymous posting: Where the App lets you post, comment, vote, or view anonymously, other users do not see which persona is behind that activity, and the identity-masking is applied by the database itself rather than by the app. Anonymity is a display protection, not deletion: the link between you and your content still exists on our servers so that moderation, safety enforcement, and legal obligations remain possible. Authorized administrators can reveal the persona behind an anonymous post, comment, or report when investigating a moderation case. Every such reveal is written to an access log recording who looked, whose identity was revealed, and the stated reason. You should not post sensitive personal information (government ID numbers, financial information, home addresses, phone numbers) in publicly visible posts or comments. Journal entries are governed by the audience you pick for each entry (private, unlisted, or public). Messages in chats and news Discussions are visible to the other members of that chat, and to Duruha staff for moderation and legal compliance — see Section 7. Stealth mode: a persona may post, comment, and chat with its identity masked from other users. Masking is applied on our servers when content is served, so other users see a masked name and avatar. Stealth mode is not anonymity from Duruha: we still know which account and persona created the content, and we may reveal it where required by law or to enforce our guidelines. If you believe content violates our Community Guidelines, you can report it through the in-app reporting tool. See Section 10 (User Rights) for your deletion rights.
7. Messaging, Discussions, and Push Notifications
7.1 Messaging and discussions. The App includes in-app messaging: one-to-one chats, group chats, community chats, and "Discussions" attached to a news post. Please read the following carefully: - Messaging on Duruha is NOT end-to-end encrypted. Messages are transmitted over TLS and stored encrypted at rest on our Supabase infrastructure, but they are stored in a form we can read. - Message content, attached media, mentions, and edit history are stored on our servers and are accessible to authorized Duruha moderation staff when handling a report, investigating abuse, or complying with a legal obligation. - Everyone else in a chat can read what you send there, can quote it in a reply, and may be able to copy or screenshot it. Deleting a message removes it from the App for other members, but we cannot recall copies other people already made. - Chats record membership and moderation state: who is a member, who invited whom, join requests and their outcome, who is muted, frozen, or removed, and per-chat blacklists. - Live presence: while you have a chat open you appear in that chat's online roster. A persona in stealth mode publishes an opaque per-session identifier and no name or avatar, so presence does not unmask it. - Do not send government ID numbers, financial account details, passwords, or other sensitive information through chat. If end-to-end encrypted messaging is introduced in a future release, this policy will be updated before it ships. 7.2 Push notifications. Duruha uses Firebase Cloud Messaging (FCM), a service provided by Google, to deliver push notifications about activity relevant to you (such as replies, post and chat mentions, new chat messages and chat invitations, news discussion join requests, connection requests and acceptances, community join-request approvals and invites, moderation updates, and official Duruha announcements). How it works: - When you enable notifications, your device is issued an FCM push token. We store this token, associated with your active persona, so we can route notifications to your device. - The token identifies your app installation, not your real-world identity. - The token is deactivated when you sign out and is refreshed periodically by the operating system. - To deliver a notification, the message payload is transmitted through Google's FCM infrastructure. We minimize the personal content included in notification payloads. - Notifications and push tokens are persona-scoped: tokens, preferences, and delivered notifications are all tied to the active persona. - Delivered notifications are stored so you can see them in your in-app notification list; they are removed when you delete your account. - You can disable notifications at any time in your device settings. NOTE (updated September 24, 2026): Earlier versions of this policy stated that no messaging of any kind shipped. That is no longer true — see Section 7.1. What remains true is that no END-TO-END ENCRYPTED messaging ships: the Signal Protocol implementation removed in June 2026 has not returned, and the messaging that ships today is readable server-side. Comments on posts remain public within their community context.
8. Sharing of Information
We do not sell your personal data. We share information only in the following limited circumstances: - Service providers: We use Supabase as our backend infrastructure provider (database, authentication, and file storage). Supabase processes data on our behalf under contractual data processing terms. See supabase.com/privacy. - Media storage and delivery: We use Bunny.net for storage, transcoding, and content-delivery of user media (profile photos, post images, and video), and as the public CDN for persona/community role-verification proof photos and links (see Sections 2.2 and 4E — unlike your private government ID, this proof is served publicly once approved). Media you upload, and the requests made to play it back, are processed on Bunny.net's infrastructure. Videos served through Bunny Stream also produce aggregate watch-retention data, which we retrieve server-side and show to the video's author. See bunny.net/privacy. - Push notifications: We use Firebase Cloud Messaging (Google) to deliver push notifications. Your device push token and notification payloads are processed through Google's infrastructure for this purpose. See Section 7 and Google's privacy policy at policies.google.com/privacy. - Media search provider: We use KLIPY to provide GIF, clip, meme, and sticker search, trending results, previews, and selected media. When you open the media picker or search for media, your search terms and standard request metadata are sent to KLIPY for app functionality. If you attach KLIPY media to a post or comment, the selected media URL and related media metadata may be stored with that content. - AI model provider: We use Alibaba Cloud Model Studio (Qwen large-language and embedding models) to power AI news search, AI community assistance panels, and AI document summarization. When you use an AI feature, your query and relevant news content excerpts from the platform are sent — server-side, through our Supabase edge functions — to Alibaba Cloud to generate embeddings and answers. We do not send your account credentials, verification documents, or private profile data. Answers may be stored in a short-lived shared cache on our servers and shown to other users who make the same or a similar query. AI features are optional and signed-in-only. If you use the AI document summarization tool when composing a post, the App extracts the text content of the PDF you select on your device and sends that extracted text (not the original PDF file) to our servers, which forward it to Alibaba Cloud to generate a summary. Do not upload documents containing other people's private or sensitive information. - Facebook (Meta): Cross-posting to Facebook is entirely optional and off unless you set it up. If a community or custom persona you manage connects a Facebook Page, you authorize us through Facebook's own login flow — the permissions we request are pages_show_list, pages_manage_posts, and pages_read_engagement — and we store the resulting access token in an encrypted server-side secrets vault that the app never sees. When you then choose to cross-post a Duruha post, that post's text and media are transmitted to Meta and published on the connected Page, where Meta's own terms and privacy policy govern it. We record the resulting Facebook post ID so the cross-post can later be removed. Removing a post on Duruha triggers an attempt to remove the corresponding Facebook post, but once content is on Facebook we cannot guarantee its deletion from Meta's systems. You can revoke a Page connection at any time. See policies.google.com/privacy for Google and facebook.com/privacy/policy for Meta. - App update delivery: We use Shorebird to deliver over-the-air code patches. Update checks transmit standard request metadata (app and patch version) to Shorebird's servers; no personal data, identity data, or advertising IDs are shared. - Font delivery: The App uses Google Fonts, which may result in font requests being sent to Google's CDN. No personal data is transmitted in these requests. - Community visibility: Certain profile information, persona credentials and supporting links you choose to add, posts, and content you create are visible to other authenticated users of the platform, subject to your profile and search visibility setting (public, connections only, or private; see Section 10). Subject to the same setting, your persona may also appear in location-based people search and discovery. Journal entries are visible according to the audience you set on each entry, messages are visible to the members of that chat or discussion, and cosmetic items you apply are visible wherever your persona appears. Your government ID and verification selfie are never part of this — they are private; see Section 4. - Legal obligations: We may disclose information if required by law, court order, or government authority, or to protect the rights, safety, or property of Duruha, our users, or the public. - Business transfers: [NEEDS FOUNDER CONFIRMATION — if Duruha is acquired or undergoes a corporate transaction, describe how user data would be handled] - Payments: Duruha does not process real-money payments and does not collect or store any card, bank, or e-wallet data. No payment processor is integrated. The App includes a virtual, platform-internal credit and "community wallet" system used to meter publishing and AI feature usage and to buy cosmetic items. The App's top-up sheet names GCash, Maya, and Card as methods, but no payment is actually taken in the App: the method you pick is recorded only as a text label on the wallet transaction, and any real settlement happens outside the App with a Duruha administrator. Credits are not money, have no cash value, and are not redeemable. If real-money payment processing is added in the future, this section, the Terms, and the Data Safety form will be updated first. We do not share your personal data with advertisers, data brokers, or any third party for marketing purposes.
9. Data Retention
Data Category | Retention Period ----------------------------------|-------------------------------------------- Account data (email, profile) | Until account deletion Verification ID + selfie images | Deleted by automated purge as soon as a reviewer approves or denies the request, and on any submission a resubmission supersedes Verification identity details (legal name, date of birth, place of birth, outcome) | Retained on the verification record after the images are purged; removed on account deletion Identity fingerprint (SHA-256) | Retained for duplicate-fraud detection; removed on account deletion User posts and media | Until deleted by user or account deletion Comments | Until deleted by user or account deletion Reputation and credibility data | Until account deletion View, visit, and upload records | Until account deletion; anonymous viewer records are pseudonymous and not tied to an account Content reports, moderation decisions, restrictions, and appeals | [NEEDS FOUNDER CONFIRMATION — recommended 2 years, retained beyond account deletion where needed to enforce a ban or answer a legal request] Identity-reveal access log | Retained as a security audit record Facebook Page connection + access token | Until you revoke the connection or the token expires; cross-post records retained with the post Authentication tokens | Session-scoped, managed by Supabase Auth Push notification token (FCM) | Until sign-out, token refresh, or account deletion KLIPY media search requests | Not stored by Duruha except selected media metadata saved with posts/comments AI search queries and usage logs | Retained per persona for quota metering and abuse prevention; removed on account deletion AI answer cache | Short-lived shared cache (approx. 60-minute TTL) Persona/community verification proof photos (Bunny CDN) | Public and permanent once approved; not deleted after review (removed only if verification is revoked or on account/community deletion) Chat / discussion messages and their media | Until deleted by the sender, until the chat is deleted, or until account deletion. A message you delete is marked deleted and stops being served; copies other members already saw or saved are outside our control. [NEEDS FOUNDER CONFIRMATION — whether deleted-message rows are hard-purged on a schedule, and retention for chats everyone has left] Chat membership, invites, join requests, blacklists | Until account or chat deletion (kept while needed to enforce a removal) Journal entries | Until deleted by you or account deletion, regardless of audience Calendar and community events | Until deleted by you or the community, or account/community deletion Cosmetic item ownership | Until account deletion Anonymous viewer token | Stored on your device until you clear app data; the server keeps it only as a de-duplication key on view records Activity heartbeat | [NEEDS FOUNDER CONFIRMATION — recommended: aggregate after 24 months] Post / profile / video analytics | For the life of the content; removed on account deletion Screen-time (Mindfulness) data | On your device only; removed when you uninstall or clear app data Subscription / credit / wallet data | Until account or community deletion PDF text sent for AI summary | Not retained beyond generating the summary (subject to the same short-lived AI answer cache as other AI features) Feature requests / feedback | Until account deletion Deactivation records | Retained while deactivated and after reactivation, so we can restore the account Account deletion record | A minimal audit record — your email address, the reasons you gave, your account creation date, general location ID, and counts of personas and posts — is written when you delete your account and is retained after deletion for fraud prevention and abuse enforcement. It contains no posts, media, or verification data. Shorebird update-check metadata | Not stored by Duruha (processed by Shorebird; version metadata only)
| Data Category | Retention Period |
|---|---|
| Account Data (email, profile) | Until account deletion |
| Verification ID + selfie images | Deleted immediately upon approval (and not retained after rejection) |
| Identity fingerprint (SHA-256) | Retained for duplicate-fraud detection; removed on account deletion |
| News, Comments & Media | Until deleted by user or account deletion |
| Reputation & Credibility Data | Until account deletion |
| Content Reports | [NEEDS FOUNDER CONFIRMATION — recommended 2 years] |
| Exchange / Transaction Records | [NEEDS FOUNDER CONFIRMATION — feature not live at launch] |
| Authentication Tokens | Session-scoped, managed by Supabase Auth |
| Push Notification Token (FCM) | Until sign-out, token refresh, or account deletion |
| Persona/Community Verification Proof Photos (Bunny CDN) | Public and permanent once approved; removed only if verification is revoked or on account/community deletion |
| Subscription / Credit / Wallet Data | Until account or community deletion |
10. User Rights and Controls
You have the following rights regarding your data: - Access: View your profile, posts, and settings within the App. - Export: Request an export of your account data and media through the in-app export tool. The export covers your profile, personas, posts, comments, agendas and tasks, votes and reactions, connections, follows, community memberships, blocks and mutes, saved items, verification requests, and notifications. Content that other people posted anonymously is included without their identity. - Correction: Update your profile information at any time in settings. - Deactivation: Temporarily deactivate your account. Your profile is hidden while deactivated and you can reactivate it later; your data is not deleted. - Deletion: Delete your account through the in-app account deletion flow. This permanently deletes your profile, personas, posts, comments, media files, and associated records via cascade deletion. One minimal audit record survives deletion, as described in Section 9. - Post and comment deletion: You can delete your own posts and comments directly from the App, each behind a confirmation dialog. - Verification data deletion: Your raw ID and selfie images are deleted automatically once verification is reviewed. You may request removal of your verification record and the loss of your Verified Persona badge by contacting us. - Location control: Location permission can be denied at onboarding or revoked at any time through Android device settings. - Feed control: Mute geographic areas and communities through feed algorithm settings. - Connections: Send, accept, decline, or remove persona-to-persona connection requests. Removing a connection withdraws the connections-scoped visibility it granted. - Profile and search visibility: Choose who can find your profile in search and view your activity history — public, connections only, or private — from your profile settings. Stealth mode additionally keeps your profile visits unattributed, and per-activity anonymity settings control whether your posts, comments, votes, reactions, shares, and views are attributed to your persona. - Messaging controls: Mute, archive, or leave a chat; delete or edit your own messages; and, where you administer a chat or a news discussion, freeze, remove, or blacklist a member and require approval to join. - Journal audience: Set each journal entry to private, unlisted, or public, and change it later. - Screen-time tools: Enable, adjust, or turn off the optional Mindfulness reminders and blocks. This data never leaves your device. - Signed-out browsing: You can read public content without an account. To reset the anonymous view-counting token, clear the App's data. - Block users: Block another user directly from their profile or from a post. You can block a single persona, or block all personas belonging to that account. Manage and remove your blocks from profile settings. - Facebook disconnection: Revoke a connected Facebook Page at any time from the connection settings screen. - Withdraw consent: Where processing is based on consent, you may withdraw it at any time. To exercise any of these rights, use the in-app controls or contact us at: lmrtamayor@gmail.com (interim — a dedicated privacy address will replace this before public launch)
11. Security
We implement the following safeguards to protect your data: - TLS/HTTPS encryption for all data in transit - AES-256 encryption for data at rest on Supabase backend servers - Row-level security in the database, so that each account can read and write only its own records and so that visibility rules (journal audience, chat membership, stealth masking, community scope) are enforced on the server rather than in the app - Android Keystore for local cryptographic key storage - Third-party access tokens (such as Facebook Page tokens) held in an encrypted secrets vault rather than ordinary database columns - Zero-trust access controls for unredacted verification documents, with every administrator identity reveal written to an audit log - Automatic permanent deletion of unredacted identity documents once a verification request is reviewed What we do NOT claim: Duruha does NOT provide end-to-end encryption. Messages and other content are encrypted in transit and at rest, but they are stored in a form Duruha can read. Please read Section 7.1 before treating any part of the App as a confidential channel. No system is completely secure. If you believe your data has been compromised, contact us immediately at: trust@duruha.social or lmrtamayor@gmail.com (interim legal/privacy contact).
12. Children and Minors
Duruha is intended for people who are at least 13 years old. We do not knowingly collect personal information from children under 13. If we become aware that a user is below 13, we will suspend the account and delete associated data promptly. Users who are 13 to 17 are treated as minors for child safety enforcement, including our child sexual abuse and exploitation prevention, reporting, and escalation standards. [NEEDS FOUNDER CONFIRMATION: Confirm whether a hard date-of-birth age gate will be implemented at signup (required before public launch), and whether any parental consent mechanism is planned.]
13. Philippines Context and International Users
Duruha is developed and operated by [NEEDS FOUNDER CONFIRMATION — legal entity name], based in the Philippines. This policy covers the Duruha application in all the forms we distribute it — the Android app, and the iOS, web, and desktop builds where and when those are released. By using the App, you understand that your data may be processed and stored on servers operated by Supabase, which may be located in the United States or the European Union; that media is stored and delivered through Bunny.net's global network; and that AI feature queries are processed by Alibaba Cloud Model Studio, whose servers may be located in Singapore or other regions. If you cross-post to Facebook, that content is processed by Meta on its own global infrastructure. Filipino users have rights under the Data Privacy Act of 2012 (Republic Act No. 10173) and may contact the National Privacy Commission (privacy.gov.ph) for concerns not resolved by Duruha. [NEEDS FOUNDER CONFIRMATION: Confirm whether GDPR or other regional laws apply based on intended user base.]
RA 10173 - Data Privacy Act of 2012
Duruha fully supports your rights to access, object, delete, rectify, and file concerns with the National Privacy Commission (NPC) of the Philippines. Contact lmrtamayor@gmail.com for DPA inquiry handling.
14. Contact
If you have questions about this Privacy Policy, want to exercise your rights, or need to report a privacy concern: Trust and Safety: trust@duruha.social Privacy Contact: lmrtamayor@gmail.com (interim — to be replaced with a company address before public launch) Legal Entity: [NEEDS FOUNDER CONFIRMATION] Address: [NEEDS FOUNDER CONFIRMATION]