A Acaso

Privacy policy

Mohammad Danial Barkhordar (Danial), trading as Acaso ("we"), runs the Acaso app and the website at acaso.place, and is the data controller for what they collect. This policy says what we collect, why we are allowed to, who else sees it, where it goes, and what you can do about it. Version 1.0, last updated 16 September 2026.

What we collect

DataWhyKept
Apple Account sign-in — the identifier Apple gives us for you, and the email you choose to share (your own, or Apple's private relay address)To sign you in and to keep fake accounts out. Never shown to other users.Until you delete your account. If an account is closed for breaking the rules, the identifier and email are kept so it cannot come back
Profile — first name, date of birth, gender, home country, languages, interests, travel styles, countries visited, bio, prompts, photos, Instagram handle if you add oneTo show other users who you are. Your date of birth is never shown; only your age. Gender is used only for your profile and for the seating preference some tables offer.Until you delete your account
Approximate locationTo show who is nearby. We store your neighbourhood and a position rounded to about a kilometre (two decimal places) for distance maths; the app rounds it before it leaves your phone and the database rounds it again. Other users only ever see your neighbourhood and a distance band such as "2 km away" — never your coordinates. You can turn this off in Settings.Replaced each time you refresh; stale after 14 days. We keep no history of where you have been
Plans, trips, table answersTo run the features you use them in. Your table answers are used only to seat you and are never shown to anyone.Until you delete them or your account
Messages and chat photosTo deliver them to the people you sent them to.Until you delete them or your account
Verification selfie (optional)To confirm the face on your profile is yours. You are asked to agree in the app before the camera opens. Stored in a private bucket no user can access, compared with your profile photo by an automated review and, if that review is unsure, by a person. It is compared only with your own photos, never searched against anyone else's, and it is not used for anything else.Until the review is done, usually within minutes: the file is deleted the moment the decision is recorded, and in any case when you delete your account
Push tokenTo notify you of new messages and of things that involve you.Until you sign out or uninstall
Profile views, blocks, reportsTo keep people safe, and to run the "who viewed you" feature. Reports are never shown to the person reported.Until you delete your account. A record of a report we upheld is kept after that, so the account cannot come back
Moments in the app — you joined a plan, shared a link, came backTo see whether Acaso works, in aggregate. Read only by us, never shown to anyone.Until you delete your account
Crash reports — the phone model and system version, the app version, and where in the code a crash happenedTo fix crashes on phones we cannot see. No name, email, location or IP address is sent.90 days
Waitlist email — if you leave your email on the website before the app is outTo tell you when it is.Until we have told you, or you ask us to remove it

We do not collect contacts, precise or background location, advertising identifiers, or anything from other apps. There are no third-party ad or analytics SDKs, and we do not sell data.

Why we are allowed to

UK and EU data protection law asks us to say which legal basis covers each use.

UseBasis
Signing you in, showing your profile, delivering messages, running plans, trips and tables, sending you the pushes you chosePerforming our contract with you (these terms)
Your approximate locationYour consent, given when you allow location in the app; withdraw it in Settings
The verification selfieYour explicit consent, a line you tick in the app before the camera opens; withdraw it by not sending the selfie, or by asking us to delete it while a review is still open
The automated filter, reports, blocks, suspensions and the records we keep of themOur legitimate interest in keeping people safe and enforcing the terms, and, where a report describes a crime, our legal obligations
Aggregate counts of what people do in the app, and crash reportsOur legitimate interest in knowing whether Acaso works and fixing it when it does not
Keeping the identifier of a closed accountOur legitimate interest in stopping a banned person coming back
Answering a request from the police, a court or a regulatorA legal obligation

Where we rely on legitimate interests we have weighed them against your rights and kept the data to the minimum that serves the purpose. You can object; see "Your rights".

Who else sees it

Nobody else, with three exceptions. If the law requires it, or a court, the police or a regulator asks in a way we must comply with, we hand over what is asked for and no more. If we reasonably believe someone is in danger, we may pass what is needed to the emergency services. And if Acaso is ever taken over by a company, including one of our own, your data goes with it under this same policy, and we tell you first.

Where your data goes

Your data lives in Ireland, inside the EU. Some of the services above run in the United States: Apple, Expo, Anthropic, Resend, RevenueCat, Sentry and Google. When data goes to them it is covered by the UK's data-bridge and adequacy decisions where they apply, and otherwise by the standard contractual clauses and the UK addendum that the law provides for, which each of these providers has signed up to.

Decisions made by software

Some decisions in Acaso are automatic: a filter can hold or refuse a message before anyone sees it, a profile photo waits for a look before it is shown, three reports in a week hide a profile for thirty days, and the selfie check is done by an automated review first. None of these closes your account on its own: closing an account is always a person's decision, and you can ask for a person to look at any automatic decision by writing to us. The Terms of Use, section 4, say how.

Your choices

Your rights

Under the UK GDPR and, if you are in the EU, the GDPR, you can ask us to:

Write to the address below. We answer within a month and never charge for it. We may ask you to confirm it is you, from the email on your account. If you are unhappy with our answer you can complain to the Information Commissioner's Office at ico.org.uk, or, in the EU, to your own data protection authority. We would rather you wrote to us first.

Security

Data travels encrypted and is stored encrypted. Every user can only read what the database rules let them read; the verification selfies are in a bucket no user can reach at all; and the keys that run the service are held in the hosting provider's vault, not in the app. No system is perfect, and if a breach ever affects you we will tell you and the ICO as the law requires.

Children

Acaso is for people aged 18 and over. The date of birth check is enforced in our database, a report that says someone is under 18 pauses their account until a person has looked, and we remove accounts we discover to be under 18.

Changes to this policy

When we change this policy we update the version and the date at the top and show it in the app. If a change matters, we tell you in the app or by email before it takes effect.

Contact

Mohammad Danial Barkhordar (Danial), trading as Acaso hello@acaso.place · [POSTAL ADDRESS]