Privacy Policy
Troy Circle is built on trust. We collect only what is strictly necessary, never sell your data to third parties, and give you full control over your information at all times. This policy is drafted in compliance with the EU General Data Protection Regulation (GDPR), the Spanish Organic Law on Data Protection (LOPDGDD), and the EU Digital Services Act (DSA).
1. Data Controller
The data controller responsible for processing your personal data is:
Borja de la Riva Ruiz
Operating under the brand Troy Circle
NIF: [NIF PENDIENTE]
Registered address: [DOMICILIO FISCAL PENDIENTE], Spain
Email: hello@troycircle.app
Website: troycircle.app
As a data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring such processing complies with applicable data protection law, including GDPR 2016/679 and LO 3/2018 LOPDGDD.
2. Personal Data We Collect
2.1 Data you provide directly
- Account data — email address, password (hashed with bcrypt via Firebase Auth; never stored in plaintext), and date of birth.
- Profile data — display name, city, biography, profile photos, height, body type, life situation, education, and the optional contact fields you choose to fill in (Instagram handle, WhatsApp number).
- Application data — information submitted when requesting membership, including name, age, and Instagram handle provided for review purposes.
- Communications — messages, images, audio recordings, and location data shared through in-app chats. New chat-message text is encrypted at the application layer using AES-256-GCM before storage. Older conversations may use a legacy encryption format. This is encryption at rest, not end-to-end encryption: authorised Troy Circle personnel can decrypt content when necessary to operate the service or investigate a safety or abuse report.
- Invitations — email addresses you enter when inviting someone to join the platform.
- Reports — content and context you provide when reporting another user.
2.2 Data collected automatically
- Usage data — number of profiles viewed per day, stored solely to enforce daily discovery limits. We do not build behavioural advertising profiles.
- Push notification token (FCM) — stored in a private, access-controlled subcollection within your account record, invisible to other users.
- Last active timestamp — the time you last opened or brought the app to the foreground. Displayed as an online indicator, controlled by your privacy settings.
- Profile view log — a record of which users have viewed your profile (for premium members who choose to enable this feature).
- Location data — GPS coordinates used to show distance to other members and to power Travel Mode. Coordinates stored on your profile are reduced in precision to approximately 1 km. If you deliberately send a location pin in a chat, that pin contains exact coordinates and is stored as part of the message until it is deleted or redacted. We do not track your location in the background.
- Device information — operating system type and version, app version, collected for crash reporting and compatibility purposes.
2.3 Data received from third parties
- Google Sign-In — if you authenticate via Google, we receive your verified email address and display name from Google LLC. We do not receive your Google password, search history, or any other Google account data.
3. Special Category Data
Sensitive data notice. Troy Circle optionally processes data that falls within the special categories defined in GDPR Art. 9: sexual orientation and sexual-behaviour indicators. This data is processed exclusively on the basis of your explicit and freely given consent, which you can withdraw at any time.
Troy Circle does not collect health data. There is no HIV-status field and no prevention-practices field anywhere in the app. We removed both, and we do not ask for, store, or display any information about your health.
The following fields are classified as special category data and are subject to heightened protection:
- Sexual orientation — implied by membership of a platform for adult networking. Governed by GDPR Art. 9(2)(a) — explicit consent.
- Body type — may be considered health-adjacent data. Treated with the same heightened protection as other special category data.
- Sexual behaviour indicators (position, tribe) — optional fields processed only when you explicitly enable the "intimate details" toggle. Treated as sensitive personal data.
You may withdraw consent for special category data at any time by disabling the "Show intimate details" toggle in your profile settings or by deleting the relevant field from your profile. Withdrawal does not affect the lawfulness of prior processing.
Special category data is never used for advertising, shared with third-party data brokers, or disclosed to any party except as strictly required by law.
4. Legal Basis for Processing
We process your personal data only where we have a valid legal basis under GDPR Art. 6 and, where applicable, GDPR Art. 9. The table below sets out the legal basis for each category of processing.
| Processing activity | Legal basis | GDPR provision |
|---|---|---|
| Account creation and authentication | Performance of contract | Art. 6(1)(b) |
| Membership application review | Performance of contract / Legitimate interests | Art. 6(1)(b)(f) |
| Profile display in the discovery feed | Performance of contract | Art. 6(1)(b) |
| Private messaging and connections | Performance of contract | Art. 6(1)(b) |
| Transactional emails | Performance of contract | Art. 6(1)(b) |
| Push notifications | Consent (opt-in during setup) | Art. 6(1)(a) |
| Safety, abuse investigation and reporting | Legal obligation / Legitimate interests | Art. 6(1)(c)(f) |
| Daily usage limits and Moral Score | Legitimate interests (community quality) | Art. 6(1)(f) |
| Fraud and spam prevention | Legitimate interests | Art. 6(1)(f) |
| Premium subscription management | Performance of contract | Art. 6(1)(b) |
| Sexual orientation (membership) | Explicit consent / Manifestly made public | Art. 9(2)(a)(e) |
| Intimate profile fields (position, tribe) | Explicit consent | Art. 9(2)(a) |
| Compliance with legal obligations | Legal obligation | Art. 6(1)(c) |
Where processing is based on legitimate interests (Art. 6(1)(f)), we have conducted a balancing test and determined that our interests do not override your fundamental rights and freedoms. You may request a copy of our legitimate interests assessment by contacting us.
5. How We Use Your Data
We use your personal data solely for the purposes listed below. We do not use your data for automated individual decision-making that produces legal or similarly significant effects without human review.
- Creating, maintaining, and managing your account and profile.
- Reviewing your membership application and communicating the outcome by email.
- Displaying your profile to other approved members in the discovery feed, subject to your visibility settings.
- Facilitating connections, messaging, and interactions between members.
- Delivering transactional emails (verification, application status, invitation notifications, approvals) via Resend.
- Delivering push notifications for messages, connections, and platform activity.
- Computing and displaying your Moral Score from your community participation (peer ratings shown anonymously in the app, Circle attendance and no-shows, and moderation outcomes). The score influences where your profile appears in other members' feeds and can affect access to some Circles.
- Automatically screening every profile photo you upload with an AI classifier (Google Vertex AI) to detect nudity and possible minors; a photo may be automatically hidden if flagged. You can request human review of a hidden photo at hello@troycircle.app.
- Processing Troy Circle Premium subscriptions and synchronising payment status through Stripe.
- Enforcing community standards, investigating abuse reports, and taking enforcement action.
- Complying with legal obligations, including mandatory CSAM reporting obligations.
- Improving the platform through anonymised, aggregated analytics that cannot be linked back to individual users.
We will never use your data for: advertising by third parties, sale to data brokers, training of third-party AI models, or any purpose incompatible with the purposes listed above.
6. Data Processors and Third-Party Sharing
We do not sell your personal data. We use the following service providers to operate Troy Circle. Their applicable data-protection terms and international-transfer safeguards are reviewed as part of our compliance process:
| Processor | Role | Location | Safeguard |
|---|---|---|---|
| Google LLC / Google Ireland Ltd. (Firebase & Cloud) | Authentication, database (Firestore), file storage, push notifications (FCM), backend functions, hosting, App Check | Primary functions in europe-southwest1 (Madrid); some Google services US / EU | Standard Contractual Clauses (SCCs); Google Cloud DPA |
| Google Cloud Secret Manager | Management of conversation encryption keys | EU / US per configuration | Google Cloud DPA; SCCs |
| Google Vertex AI (Gemini) | Automated moderation of profile photos (nudity & suspected-minor detection) | United States (us-central1) | Google Cloud DPA; SCCs. Profile photos are transferred to the US for this check |
| Google Firebase Crashlytics | Crash reporting and diagnostics (device model, OS/app version, session state) | Google (global) | Google Cloud DPA; SCCs |
| Device-attestation (App Check): Google Play Integrity, Apple App Attest, Google reCAPTCHA v3 | Verify requests come from a genuine app/browser; anti-abuse. reCAPTCHA v3 (web/admin) processes device signals + IP | Google / Apple (global) | Provider data-protection terms; SCCs |
| Apple Inc. | Sign in with Apple (identifier, email/private-relay) and push delivery via APNs (iOS) | Apple (global) | Apple provider terms; SCCs |
| OpenStreetMap Foundation | Map tiles for the Travel Mode destination picker (receives IP + map area browsed) | EU / UK | OpenStreetMap Foundation privacy/tile-usage policy |
| Google Places | City / address / place search when you use location fields | Google (global) | Google Cloud DPA; SCCs |
| Resend Inc. | Transactional email delivery (incl. invited people's email addresses) | United States | Provider data-protection terms; SCCs |
| Stripe | Hosted checkout, recurring billing, customer portal, payment status, invoices, and refunds | EU / US, depending on the service and account configuration | Provider data-protection terms; SCCs |
| Google Identity Platform (SMS) | Two-factor SMS codes for administrator/moderator accounts only (not members) | Google (global) | Google Cloud DPA; SCCs |
We also share your data in the following circumstances:
- Other members — your profile (name, age, city, photos, bio, Moral Score, online status) is visible to other approved members. Intimate details (position, tribe) are only visible when both you and the viewer have opted in. Contact details (Instagram, WhatsApp) are only visible after a mutual connection is established.
- Law enforcement and regulatory authorities — we may disclose data when required by law, court order, or where necessary to protect the safety of users or the public, including mandatory CSAM reporting obligations (see our Child Safety Policy).
- Business transfer — in the event of a merger, acquisition, or asset sale, your data may be transferred to the acquiring entity. We will provide any notice and choices required by applicable law.
7. International Data Transfers
Some of our service providers (including Google/Firebase, Resend, and Stripe) may process personal data outside the European Economic Area (EEA), including in the United States, depending on the service and account configuration.
Where a provider processes personal data outside the EEA, the transfer must rely on a valid mechanism under GDPR Chapter V, such as:
- Standard Contractual Clauses (SCCs) adopted by the European Commission under GDPR Art. 46(2)(c), where incorporated into the relevant provider terms.
- Google's EU Data Boundary — where applicable, we configure Firebase services to store and process data within the European Union.
For information about the transfer mechanism applicable to a particular provider, contact us at hello@troycircle.app.
8. Data Retention
We retain your personal data only for as long as necessary for the purposes set out in this policy, or as required by law.
| Data type | Retention period | Reason |
|---|---|---|
| Account and profile data | While the account is active; erased or de-identified when account deletion is processed, except where retention is legally required | Service delivery and legal compliance |
| Profile and verification photos | Until the photo is removed or account deletion is processed, subject to operational backups and retry procedures | Service delivery and safety review |
| Chat messages | While needed to provide the conversation. On account deletion, the departing member's content is removed or redacted when the other participant remains; an orphaned conversation is deleted | Erasure rights balanced with the other participant's legitimate interest in their own messages |
| Access applications | For as long as needed to review the application, administer re-applications, prevent abuse, and handle disputes; removed when account deletion is processed unless retention is legally required | Application review, security, and legal claims |
| Safety and investigation records | For as long as reasonably necessary for the investigation, enforcement, legal claims, or a binding legal obligation | Safety, evidence preservation, and legal compliance |
| Billing and transaction records | For the period required by applicable tax, accounting, payment, and consumer law | Legal compliance and payment disputes |
| Irreversibly anonymised aggregates | May be retained because they can no longer be linked to an individual | Product improvement |
When account deletion starts, the app first hides the profile and removes locally accessible profile photos on a best-effort basis. Deleting the Firebase Authentication account then starts a server-side process that erases or de-identifies linked data across Firestore, Storage, and Stripe. The process is designed to continue across independent data stores and can be re-run by an authorised administrator if one part fails. Some records may be retained where required by law or needed to establish, exercise, or defend legal claims. Conversation data is handled as described in the table above.
9. Your Rights Under GDPR and LOPDGDD
As a data subject in the EEA (or Spain specifically), you have the following rights under GDPR Art. 15–22 and LO 3/2018 LOPDGDD:
- Right of access (Art. 15) — request a copy of all personal data we hold about you, including a description of purposes, categories, recipients, and retention periods.
- Right to rectification (Art. 16) — correct inaccurate or incomplete data at any time directly from your profile settings or by contacting us.
- Right to erasure / "right to be forgotten" (Art. 17) — request deletion of your data. You may also delete your account at any time via Settings → Account → Delete account. Erasure may be limited where we are required to retain data by law (e.g. financial records, safety investigation records).
- Right to restriction of processing (Art. 18) — request that we limit processing of your data while a complaint or dispute is resolved.
- Right to data portability (Art. 20) — receive your personal data in a structured, commonly used, machine-readable format (JSON) and transmit it to another controller.
- Right to object (Art. 21) — object to processing based on legitimate interests at any time. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests.
- Rights related to automated decision-making (Art. 22) — Troy Circle does not make fully automated decisions with legal or similarly significant effects: account suspensions and terminations are reviewed and confirmed by a person. The Moral Score is computed algorithmically but does not by itself terminate an account. Profile photos are screened automatically and may be hidden; you can request human review, express your view, and contest that outcome at hello@troycircle.app.
- Right to withdraw consent — where processing is based on consent (e.g. intimate profile fields, push notifications), you may withdraw consent at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint — if you believe we have violated your data protection rights, you have the right to lodge a complaint with the competent supervisory authority: the Agencia Española de Protección de Datos (AEPD) at aepd.es, or the supervisory authority in your country of residence.
To exercise any of these rights, contact us at hello@troycircle.app with subject line DATA RIGHTS REQUEST and proof of identity. We will respond within 30 calendar days as required by GDPR Art. 12(3). Complex requests may be extended by an additional 60 days with notice.
10. Security Measures
We implement technical and organisational security measures appropriate to the risk, in accordance with GDPR Art. 32:
- AES-256-GCM encryption — new chat-message text is encrypted at the application layer with authenticated encryption before storage. Conversation keys are held in Google Cloud Secret Manager and supplied only after server-side participant checks. This is not end-to-end encryption, and authorised service or moderation workflows can decrypt message text when necessary.
- Firebase App Check — enforced on all Firebase services (Firestore, Storage, Authentication, Functions). Only verified, genuine app builds can make API calls.
- Firestore security rules — granular, server-side access control ensuring users can only read and write data within their authorised scope.
- Password hashing — all passwords are hashed by Firebase Authentication using bcrypt. We never store plaintext passwords.
- Private data subcollections — sensitive data such as push notification tokens is stored in access-restricted subcollections, invisible to other users or the app layer.
- Screenshot prevention — FLAG_SECURE (Android) prevents screenshots, screen recording, and app-switcher thumbnail exposure. iOS privacy overlay prevents content capture during app switching.
- Application-based access — every application is individually reviewed. An invitation may support an application, but it does not guarantee admission.
- HTTPS / TLS — all data in transit is encrypted using TLS 1.2 or higher.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the AEPD within 72 hours of becoming aware of the breach, as required by GDPR Art. 33. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay (GDPR Art. 34).
11. Cookies & Tracking Technologies
The Troy Circle mobile application does not use cookies. Authentication state is managed via Firebase Auth's secure token system.
The troycircle.app website uses only strictly necessary session cookies required for navigation. We do not use:
- Advertising or targeting cookies.
- Third-party analytics scripts (no Google Analytics, no Meta Pixel).
- Social media tracking pixels.
- Cross-site tracking technologies of any kind.
As we use only strictly necessary cookies, a cookie consent banner is not required for those cookies under ePrivacy Directive 2002/58/EC and LSSI Art. 22.
Two surfaces load third-party resources that receive your IP address as a technical necessity to render them: the interactive members map loads the Leaflet library from a CDN and map tiles from the OpenStreetMap Foundation and CARTO; and the separate staff-only administration panel uses Google reCAPTCHA for anti-abuse protection. These are not advertising or cross-site tracking technologies.
12. Contact & Supervisory Authority
For all privacy-related enquiries, data rights requests, or to report a concern:
Troy Circle — Privacy
Email: hello@troycircle.app
Subject: DATA RIGHTS REQUEST
Response time: within 30 calendar days
If you are not satisfied with our response, or if you believe we are processing your data unlawfully, you have the right to lodge a complaint with the competent supervisory authority:
- Spain — Agencia Española de Protección de Datos (AEPD): aepd.es · Tel: 901 100 099
- EU (other countries) — the supervisory authority in your country of habitual residence or place of work.
This Privacy Policy may be updated from time to time. We will provide notice of material changes, and request renewed consent where required, in the manner and within the period required by applicable law.
Terms of Service
These Terms of Service ("Terms") constitute a legally binding agreement between you and Troy Circle (operated by Borja de la Riva Ruiz, Barcelona, Spain) governing your access to and use of the Troy Circle mobile application and website. Please read them carefully. If you do not agree, do not use the service.
1. Eligibility
To use Troy Circle you must:
- Be at least 18 years of age. Access by minors is strictly prohibited under any circumstances.
- Have received and accepted a valid invitation or been approved through the standard application process.
- Not be prohibited from using online services under the laws of your jurisdiction.
- Not have previously been banned or permanently suspended from Troy Circle.
- Provide accurate, complete, and current information during registration and maintain it up to date.
- Use the service solely for lawful purposes and in compliance with these Terms.
We verify minimum age at registration (date of birth required) and reserve the right to request identity confirmation at any time. Accounts found to belong to minors will be permanently removed without notice, and may be reported to law enforcement in accordance with our Child Safety Policy.
By registering, you represent and warrant that all of the above eligibility conditions are met.
2. Community Conduct
Troy Circle is a curated community built on respect. The following conduct is strictly prohibited and will result in immediate and permanent account termination, and may result in referral to law enforcement:
- Harassment, intimidation, threats, bullying, or abuse of any member in any form.
- Creating a fake profile, impersonating another person, or misrepresenting your identity or age.
- Generating, sharing, soliciting, or distributing child sexual abuse material (CSAM) in any form.
- Sharing another member's private information, photos, or communications without their explicit consent (doxxing).
- Non-consensual sharing or threat to share intimate images (revenge pornography).
- Using the platform for commercial solicitation, spam, escort or sex work advertising, or pyramid schemes.
- Attempting to manipulate the Moral Score system or any rating mechanism through coordinated or fraudulent actions.
- Reverse-engineering, scraping, crawling, or otherwise attempting to extract data from Troy Circle by automated means.
- Attempting to circumvent security measures, authentication systems, or access controls.
- Transmitting malware, viruses, or any code designed to disrupt or damage our systems.
- Any conduct that violates applicable law, including Spanish criminal law, EU consumer law, or international human rights standards.
We encourage members to report misconduct using the in-app report function available on every profile and in every chat. All reports are reviewed personally by our team within 24 hours.
3. Your Content
You retain full ownership of all content you post on Troy Circle (photos, messages, biography text, and other user-generated material). By posting content you grant Troy Circle a limited, non-exclusive, royalty-free, worldwide licence to store, display, and transmit that content to other members solely as necessary to operate the service. This licence terminates automatically when you delete the content or your account.
You represent and warrant that:
- You own or have all necessary rights and licences to post the content.
- The content does not infringe any third party's intellectual property, privacy, personality, or other rights.
- The content is accurate and does not constitute defamation, fraud, or any other unlawful act.
- The content complies with these Terms, our Community Conduct rules, and all applicable law.
- Any persons depicted in photos you upload have consented to their inclusion.
Troy Circle does not claim any ownership over your content and will not use it for any purpose beyond operating the service.
5. Intellectual Property
All intellectual property rights in the Troy Circle application, website, brand, design, trademarks, logos, and original content created by Troy Circle are the exclusive property of Borja de la Riva Ruiz / Troy Circle and are protected by Spanish intellectual property law (Real Decreto Legislativo 1/1996 LPI), EU trademark and design law, and international intellectual property conventions.
You are granted a limited, non-exclusive, non-transferable, revocable licence to use the Troy Circle application solely for personal, non-commercial purposes in accordance with these Terms. You may not:
- Copy, reproduce, distribute, or create derivative works of Troy Circle's proprietary content or code.
- Use Troy Circle's trademarks, logos, or brand identity without prior written consent.
- Remove or obscure any copyright, trademark, or other proprietary notices.
6. Service Availability and Disclaimer
Troy Circle is provided "as is" and "as available" without warranties of any kind, whether express or implied, including warranties of merchantability, fitness for a particular purpose, or non-infringement, to the fullest extent permitted by applicable law.
We do not warrant that:
- The service will be uninterrupted, error-free, or secure at all times.
- Profile information provided by other members is accurate, complete, or up to date.
- Any particular connection, interaction, or outcome will result from use of the service.
Troy Circle is a platform for connections between adults. We are not responsible for the behaviour, actions, or representations of other members, whether online or offline.
7. Account Suspension and Termination
By you: You may close your account at any time via Settings → Account → Delete account. Upon deletion your profile is immediately hidden, and your personal data is removed in accordance with our Privacy Policy.
By Troy Circle: We reserve the right to suspend or permanently terminate your account, with or without prior notice, if we determine that you have:
- Violated any provision of these Terms or our Community Conduct rules.
- Provided false information during registration.
- Engaged in conduct that poses a risk to the safety of other members or the integrity of the platform.
- Been subject to a final court order or regulatory decision requiring termination.
Upon termination by Troy Circle for cause, no refund of any unused Premium subscription will be issued, without prejudice to your mandatory consumer rights. When we suspend or terminate your account or restrict your content, and unless the law prevents it (for example, in child-safety investigations or where a legal order applies), we will inform you of the reason and you may request a review by a person by contacting hello@troycircle.app. This internal complaint route does not limit any right you have to bring the matter before a competent authority or court.
8. Limitation of Liability
To the fullest extent permitted by Spanish law and applicable EU consumer protection regulations, Troy Circle's total liability for any claim arising out of or in connection with your use of the service shall not exceed the greater of: (a) the total amount paid by you to Troy Circle in the 12 months immediately preceding the event giving rise to the claim, or (b) €50.
Troy Circle shall not be liable for:
- Indirect, incidental, special, consequential, or punitive damages of any kind.
- Loss of data, profits, goodwill, or business opportunities.
- The acts or omissions of other members.
- Events outside our reasonable control (force majeure), including natural disasters, government actions, internet outages, or third-party service failures.
Nothing in these Terms excludes or limits our liability for: death or personal injury caused by our negligence; fraud or fraudulent misrepresentation; or any other liability that cannot be excluded or limited under applicable Spanish or EU law, including consumer protection rights under Real Decreto 1/2007 LGDCU and Directive 2019/770/EU.
9. Governing Law and Dispute Resolution
These Terms are governed by and construed in accordance with the laws of Spain, without regard to its conflict of law provisions.
Any disputes arising out of or in connection with these Terms or your use of Troy Circle shall be subject to the exclusive jurisdiction of the courts of Barcelona, Spain, except where applicable EU consumer protection law grants you the right to bring proceedings before the courts of your country of habitual residence.
EU consumers may also use the European Commission's Online Dispute Resolution platform at ec.europa.eu/consumers/odr to resolve disputes.
If any provision of these Terms is found to be invalid or unenforceable by a competent court, the remaining provisions shall continue in full force and effect (severability). These Terms, together with our Privacy Policy and Child Safety Policy, constitute the entire agreement between you and Troy Circle regarding your use of the service.
We may update these Terms. We will provide notice of material changes, and request renewed acceptance where required, in the manner and within the period required by applicable law.
Troy Circle · Operated by Borja de la Riva Ruiz · Barcelona, Spain
hello@troycircle.app · troycircle.app