BIGZO
Privacy Policy
Bigzo is a location-based dating and social app for adults (18+) in the LGBTQ+ community. This policy explains exactly what we collect, why, and what we never do. We have tried to write it in plain language rather than legal filler.
This website
Everything above and below describes the app. The website is separate and simpler: bigzoapp.com sets no cookies and runs no third-party scripts. Visits to our public pages are measured by our own analytics software, running on our own server in France next to the app, and the measurement is deliberately thin. The same measurement covers the web app at /app when you are signed in — with every identifier in the address replaced before it is sent, so a visit reads as "a profile was opened", never whose:
- What is recorded: which page you opened, the site you arrived from (its address, never its query string), the country, your browser, operating system, device type, screen size and language, and the time.
- What is not: no cookie, no advertising identifier, no name, no email, nothing joined to a Bigzo account — at that point you may not even have one — and no town and no region: those are thrown away before anything is written down, so a country is as precise as it ever gets.
- Your IP address is not kept in these statistics. It is used in the moment to work out the country and a one-way hash, so that one visitor reading three pages counts as one visitor. Two visits from the same browser on the same connection therefore look like the same person returning. We do not store your address, and we never look one up from that hash.
- How long it is kept: 90 days. After that the visit is deleted outright — it is a measurement of a week or a month, and there is no reason to hold it for longer.
- Turning it off: if your browser sends "Do Not Track" or Global Privacy Control, nothing is requested at all — not even the script. You can also switch it off yourself with the button below; it covers this website and the web app in this browser, and it stays off until you turn it back on.
Beside that we keep plain daily totals — this many landing-page views, this many downloads — which carry no visitor identity of any kind.
The one exception to no third-party scripts is /promo, the page our advertising links to. If we are running a campaign, that page — and only that page — can load the Meta Pixel, so we can tell how many people arrived from an advert and how many went on to Google Play. It does not load unless you agree to it first: you are asked on arrival, refusing is one click, and if you refuse or simply ignore it nothing is ever sent. Your answer is remembered in your own browser. The Bigzo app itself contains no third-party trackers of any kind, and nothing on that page is connected to your Bigzo account — you do not even have one at that point.
Who we are
Bigzo, registered in Belgrade, Serbia, is the data controller for the personal data described here. For privacy questions or to exercise any right below, contact admin@bigzoapp.com.
What we collect
- Account: email address, username, display name, and a password (stored only as an Argon2id hash — we cannot read it).
- Date of birth: to enforce the 18+ age requirement. We store the date, and show only your age to others.
- Profile: anything you choose to add — bio, photos, height, weight, pronouns, gender identity, sexual orientation, position, relationship status, what you are looking for, and tags. All optional except a display name.
- Location: your device's approximate position, used to compute distance to other users. See below — this one matters most.
- Messages and photos you send, including private albums.
- Technical: a push notification token (if you allow notifications), and server logs needed to run and secure the service.
Sensitive information
Sexual orientation and gender identity are special-category data under GDPR Article 9. You provide them only if you choose to, by using the app, and they are shown to other users as part of your profile — that is the point of the field. We do not use them for anything else, and we do not share them with anyone.
Location — what other people can see
No other user ever receives your coordinates. The app sends your position to our server; the server stores it rounded to about 11 metres and keeps only your latest position — there is no location history to leak.
Other users are shown a distance computed on the server ("350 m", "2.4 km"), never a point on a map. That distance is bucketed and carries a small, stable per-viewer offset, specifically so that nobody can query from several fake positions and triangulate where you actually are.
If you turn on Hide distance, others see only a coarse band.
- Live location sharing is off unless you switch it on, for one specific person, from inside your chat with them. Even then, what they receive is snapped to a ~50 metre grid — never your doorstep. You can stop it at any time and it ends immediately.
- Blocking someone ends their access to your location instantly, in both directions, and it is not restored if you later unblock them.
- We never ask for background location. Bigzo only uses your position while you are using the app.
- Your position stops appearing to anyone after 7 days without an update.
Groups
A group is a conversation with more than one other person. We record who is in each group, because the group cannot work otherwise — and that record is treated as sensitive: it is never shown outside the group, never used for statistics beyond counts, and never put in a notification.
- Album shared with a group: one permission for the whole room. Whoever is in the group can see it, including someone admitted after you shared it, and nobody who has left. You can withdraw it at any time, which withdraws it for everyone at once.
- Leaving: the moment you leave a group, or a block takes one of you out of it, that group stops being able to see the photos you sent there and any album you shared with it.
- How long: group messages are deleted after 60 days — 7 days for a group created for a specific meet-up. A group is deleted entirely a week after it is closed, and the record that you were once in a group you have left is deleted on the same 60-day clock.
Photos
Location metadata (EXIF, including GPS tags) is stripped from every photo you upload before it can be viewed. Private album photos are visible only to people you have granted access to, and revoking access takes effect immediately.
Photos you send in chat are deleted from our storage 30 days after you send them — not because we ran out of room, but because we should not be holding them. The message stays in the conversation; the picture does not. A photo you unsend, and a view-once photo once it has been opened, leaves the conversation straight away and our storage after 7 days. We keep those 7 days for one reason only: if someone reports that photo, we have to still be able to look at it — and if a report is open, we hold it until that report is settled.
One exception, so you are not surprised by it: a photo you share into a chat from a private album is the album photo itself, not a copy. Taking it out of the conversation removes it from that chat, but the picture stays in your album where it belongs to you — deleting it there is what deletes the file.
Moderation access
When content is reported, trained reviewers see the reported content and the reported profile — evidence-scoped, with the reporter's identity withheld. In addition, a small number of authorized personnel can review account content, including messages and photos, where necessary for user safety, fraud prevention, enforcing our terms, or complying with legal obligations. Every such access is individually logged and auditable, it is read-only, and your exact location is never part of it (staff see at most a country). We do not use this access for anything except the purposes listed here.
What we never do
- We do not sell or rent your personal data. To anyone. Ever.
- We do not run third-party advertising or analytics SDKs.
- We do not log your password, your session tokens, or your raw coordinates.
- We do not share your data with third parties for their own purposes.
Who your data is shared with
Only the service providers required to run the app: Google Firebase Cloud Messaging delivers push notifications (it receives a device token and the notification text — so keep that in mind for message previews, which you can turn off). Everything else — the database, your photos, your messages — runs on our own server infrastructure, not a third-party cloud.
AI companions
Some accounts on Bigzo are AI companions operated by us, not real people. Every one of them says so plainly in its profile. We will never present an AI account as a real human being.
How long we keep things
- Location: latest position only — no history.
- Photos sent in chat: deleted from our storage 30 days after sending. The message stays in the conversation; the picture does not. An unsent photo, or a view-once photo once opened, leaves the chat immediately and our storage after 7 days — we hold it that week only so a report about it can still be investigated.
- Deleted account: your profile is removed immediately from the app, then permanently anonymised after a 30-day grace period. Your photos and personal fields are erased. Messages you sent remain in the other person's conversation, attributed to "Deleted user" — we cannot delete them without destroying their copy of a conversation they took part in.
- Group messages: deleted after 60 days; 7 days in a group made for a specific meet-up. The whole group goes a week after it closes.
- Safety reports: kept for 2 years, as a safety record. While a report is open we keep the message it is about, and we do not delete it on the schedules above until the case is closed — otherwise a report could be defeated by waiting.
- Lawful requests: if a court, prosecutor or the police makes a lawful request about a specific account, we may suspend the deletion schedules for that account for as long as the request requires. We record who did this and why. We do not keep a hidden archive of deleted content for any other reason.
- Push tokens: removed after 60 days of inactivity.
Your rights
You can access, correct, export, or delete your data. Profile fields are editable in the app. Settings → Export my data produces a machine-readable copy of your data (GDPR Article 20). To delete your account, see Delete your account. Under GDPR you may also object to processing or complain to your local data protection authority.
Age
Bigzo is strictly 18+. We check date of birth at sign-up and enforce it on the server. If we learn an account belongs to a minor we remove it.
Security
All traffic is encrypted in transit (TLS). Passwords are hashed with Argon2id. Session tokens are stored in the Android Keystore on your device, and the app opts out of Android cloud backup so your identity and date of birth are not copied into a Google backup.
Changes
If this policy changes materially we will say so in the app. The date at the top always reflects the current version.