Welcome to CLUSTER ("the App", "we"). We are committed to protecting your privacy. This policy explains what data we collect, how we use it, and how you can control your information.
We use Firebase Authentication, Firestore, Realtime Database, Cloud Storage, and Cloud Functions. Data is stored on Google servers in accordance with Firebase Privacy Policy.
Video calls are conducted through a self-hosted LiveKit server. We do not record or store video calls.
We use the OpenAI API (gpt-4o-mini model) to generate the daily couple question. Text is processed server-side only in accordance with the OpenAI Terms of Use.
The global daily question sent to all users is generated from a system template only and does not include any user content. For couple-personalized content features (when active), the only information that may be sent to OpenAI is first names from your profile and the text of previous questions already seen by you and your partner — used solely to avoid repetition. We never send: chat messages, photos, email addresses, passwords, or any other sensitive information. We rely on OpenAI's API data-handling policy for the limited data shared.
Image scanning runs only when a user manually reports a specific photo. On report, the image is scanned via Google Cloud Vision API (SafeSearch) for forensic logging and internal triage before deletion. Automatic scanning of all uploads was discontinued in May 2026. Google does not retain photos after scanning and does not use them to train models. Data is handled in accordance with the Cloud Vision data usage policy.
When you submit a report, we collect: the reported content snapshot, the reason you selected, your user ID, the reported user's ID, and a timestamp. This data is used solely for moderation purposes and is retained for 90 days.
We use Firebase Analytics for general usage measurement and app improvement. General usage data (number of games, scores, usage events) is collected automatically and processed in accordance with Firebase Privacy Policy.
Firebase Crashlytics collects crash report data (not linked to your identity) to improve app stability. No personal information is collected. Data is processed in accordance with Firebase Privacy Policy.
We use Google AdMob to show optional rewarded video ads — shown only when you choose to watch one to earn in-app coins or keys. We request non-personalized ads only (npa), so ads are not targeted using cross-app tracking and the app does not show an App Tracking Transparency prompt. To serve these ads, Google may collect device information, a device/advertising identifier, IP address, and ad-interaction data. AdMob data is handled in accordance with Google's advertising policy.
We use Capgo (capgo.app) for over-the-air (OTA) app updates. Capgo receives an anonymous device identifier to deliver updates. No personal information, messages, or user content is shared.
We use Open-Meteo (open-meteo.com) for weather data. Coordinates are rounded to approximately 1km precision (city-level) before being sent to weather services. No personal identifying information is included.
When you search for a destination or place name, your typed query (and, for reverse geocoding, approximate coordinates) is sent to OpenStreetMap Nominatim (nominatim.openstreetmap.org) and Photon (photon.komoot.io) to return matching places. No account details, messages, or other personal content are sent.
Chat messages are stored on Firebase (Google) servers and are encrypted in transit but not end-to-end encrypted. Messages are accessible only to you and your partner.
We protect your data with encryption in transit (TLS) and encryption at rest on our providers' servers, Firebase security rules, and token-based authentication. Within the app, your data is visible only to you and your connected partner (except optional leaderboards — see below). Our backend (Cloud Functions using the Firebase Admin SDK) and our infrastructure providers can access data as needed to operate, secure, and support the service.
If you choose to join a game leaderboard, your chosen couple nickname and game scores are visible to other CLUSTER users. Your profile photos appear on the leaderboard only if you explicitly enable the photo option. Participation is voluntary — you can leave the leaderboard at any time from the game screen, which removes your entry. We do not share any other account information on leaderboards.
CLUSTER is built for intimate communication between partners, and we recognize that the content you share — including private photos, voice notes, messages, and letters — can be highly personal. We treat this content with heightened care: it is never sold, never used for advertising, and never shared with third parties except the service providers strictly necessary to operate the app (see Section 2). You can delete this content at any time, and deleting your account removes it.
We retain your data as long as your account is active. Upon account deletion, all personal data is deleted immediately. Retention periods by category:
To exercise your rights, contact us at the email address below.
Our service providers (Firebase, OpenAI, Google Cloud Vision, Google AdMob, LiveKit, Capgo) primarily operate data centers in the United States and the European Union. If you are located outside these regions, your data may be transferred to these regions to provide the service. We rely on the EU Standard Contractual Clauses (SCCs) and equivalent contractual safeguards to comply with GDPR requirements.
The app is intended for users aged 16 and older. We do not knowingly collect information from children under 16.
We may update this policy from time to time. Material changes will be published in the app.
CLUSTER App
CLUSTER is operated by Yehonatan Katz, an individual based in Israel, who is the data controller responsible for your information.
Email: clusterusapp@gmail.com