BIGZO
Privacy Policy
Bigzo is a location-based dating and social app for adults (18+) in the LGBTQ+ community. This policy explains exactly what we collect, why, and what we never do. We have tried to write it in plain language rather than legal filler.
Who we are
Bigzo is operated by Taranetiks (Belgrade, Serbia), which is the data controller for the personal data described here. For privacy questions or to exercise any right below, contact admin@bigzoapp.com.
What we collect
- Account: email address, username, display name, and a password (stored only as an Argon2id hash — we cannot read it).
- Date of birth: to enforce the 18+ age requirement. We store the date, and show only your age to others.
- Profile: anything you choose to add — bio, photos, height, weight, pronouns, gender identity, sexual orientation, position, relationship status, what you are looking for, and tags. All optional except a display name.
- Location: your device's approximate position, used to compute distance to other users. See below — this one matters most.
- Messages and photos you send, including private albums.
- Technical: a push notification token (if you allow notifications), and server logs needed to run and secure the service.
Sensitive information
Sexual orientation and gender identity are special-category data under GDPR Article 9. You provide them only if you choose to, by using the app, and they are shown to other users as part of your profile — that is the point of the field. We do not use them for anything else, and we do not share them with anyone.
Location — what other people can see
No other user ever receives your coordinates. The app sends your position to our server; the server stores it rounded to about 11 metres and keeps only your latest position — there is no location history to leak.
Other users are shown a distance computed on the server ("350 m", "2.4 km"), never a point on a map. That distance is bucketed and carries a small, stable per-viewer offset, specifically so that nobody can query from several fake positions and triangulate where you actually are.
If you turn on Hide distance, others see only a coarse band.
- Live location sharing is off unless you switch it on, for one specific person, from inside your chat with them. Even then, what they receive is snapped to a ~50 metre grid — never your doorstep. You can stop it at any time and it ends immediately.
- Blocking someone ends their access to your location instantly, in both directions, and it is not restored if you later unblock them.
- We never ask for background location. Bigzo only uses your position while you are using the app.
- Your position stops appearing to anyone after 7 days without an update.
Photos
Location metadata (EXIF, including GPS tags) is stripped from every photo you upload before it can be viewed. Private album photos are visible only to people you have granted access to, and revoking access takes effect immediately.
Moderation access
When content is reported, trained reviewers see the reported content and the reported profile — evidence-scoped, with the reporter's identity withheld. In addition, a small number of authorized personnel can review account content, including messages and photos, where necessary for user safety, fraud prevention, enforcing our terms, or complying with legal obligations. Every such access is individually logged and auditable, it is read-only, and your exact location is never part of it (staff see at most a country). We do not use this access for anything except the purposes listed here.
What we never do
- We do not sell or rent your personal data. To anyone. Ever.
- We do not run third-party advertising or analytics SDKs.
- We do not log your password, your session tokens, or your raw coordinates.
- We do not share your data with third parties for their own purposes.
Who your data is shared with
Only the service providers required to run the app: Google Firebase Cloud Messaging delivers push notifications (it receives a device token and the notification text — so keep that in mind for message previews, which you can turn off). Everything else — the database, your photos, your messages — runs on our own server infrastructure, not a third-party cloud.
AI companions
Some accounts on Bigzo are AI companions operated by us, not real people. Every one of them says so plainly in its profile. We will never present an AI account as a real human being.
How long we keep things
- Location: latest position only — no history.
- Deleted account: your profile is removed immediately from the app, then permanently anonymised. Your photos and personal fields are erased. Messages you sent remain in the other person's conversation, attributed to "Deleted user" — we cannot delete them without destroying their copy of a conversation they took part in.
- Safety reports: kept for 2 years, as a safety record.
- Push tokens: removed after 60 days of inactivity.
Your rights
You can access, correct, export, or delete your data. Profile fields are editable in the app. Settings → Export my data produces a machine-readable copy of your data (GDPR Article 20). To delete your account, see Delete your account. Under GDPR you may also object to processing or complain to your local data protection authority.
Age
Bigzo is strictly 18+. We check date of birth at sign-up and enforce it on the server. If we learn an account belongs to a minor we remove it.
Security
All traffic is encrypted in transit (TLS). Passwords are hashed with Argon2id. Session tokens are stored in the Android Keystore on your device, and the app opts out of Android cloud backup so your identity and date of birth are not copied into a Google backup.
Changes
If this policy changes materially we will say so in the app. The date at the top always reflects the current version.