Privacy Policy
Draft — last updated 2026-09-04, pending legal review before public launch.
CommonGround is operated by Common Ground Dating LLC.
This is a health-adjacent app, and we treat status data with the same rigor as sensitive health data as a matter of trust — regardless of what any specific regulation requires. For detail specific to your HIV/HSV status -- collection, disclosure consent, sharing, and retention -- see our Consumer Health Data Privacy Policy.
What we collect
Your profile information (name, date of birth, city, gender, orientation, bio, photos), your status (HIV+/HSV-1/HSV-2, self-reported), your prompt answers, and your messages with matches. We collect and retain your full date of birth — not just an age — because we need to confirm you're 18 or older and keep your displayed age accurate on an ongoing basis, not only at signup. Other members, and every other part of the app, only ever see the age we calculate from it — never your birth date itself. We collect only what the app needs to function — no location beyond city/metro level, ever.
Location
We store the city or metro area you select from a fixed list, and the maximum distance you're willing to match within. We use those to work out roughly how far apart two members are, so we only show you people within both of your chosen ranges.
That distance is calculated on our servers from the published geographic centre of each city — public reference data about places, not a location reading from you. We never ask your browser or device for your location, and we never collect or store your coordinates, street address, workplace, or postcode. Other members only ever see your city and state plus an approximate range such as “Within 25 miles” — never an exact distance, and never a map.
How it's protected
Status and message content get the same protection as everything else in the app: the database and network connections are encrypted in transit and at rest, provided by our hosting and database infrastructure. This is not end-to-end encryption — it protects your data from outside interception and from anyone accessing the underlying infrastructure without authorization, but CommonGround's own systems can access message and status content where necessary to operate the service, respond to a report, or handle a support request. Photos are stored with signed, access-controlled URLs, never a public bucket.
Who can see it
Once you've given separate disclosure consent, your status is visible to other members within the app, the same way your city is — never hidden, never indexed by search engines, never accessible outside an authenticated session. You can withdraw that consent any time from Settings, which stops new sharing immediately.
Who we work with
CommonGround has no ad-tech or analytics vendor of any kind. We do rely on a small set of infrastructure providers to run the app, who process data on our behalf under their own security commitments rather than for their own purposes: Supabase (database, authentication, file storage, and realtime messaging), Resend (delivering account emails like password resets), and Vercel (hosting).
What we never do
We never sell your status data, and we never share it for advertising or with a data broker — no ad-tech, no "anonymized" data sales, no ads, ever. The one exception is the infrastructure providers named above, who process data only to run the app itself, under contract, and never for their own purposes.
Account existence
Signup, login, and password reset all return identical responses whether or not an email is already registered. On most apps that's a minor hygiene detail; here, confirming an account exists would effectively confirm someone's status to whoever tried the address, so we treat it as a hard requirement.
Your data, your control
From Settings → Privacy & Data Center, you can confirm what we process, download a copy of your data, correct your profile, view and withdraw your health-data consent, or permanently delete your account and all of your data — a real purge, not a soft deactivation. Deletion removes your profile, status, messages, matches, and photos from the app immediately -- including a shared match and its message history, for both people in it, since a conversation is one shared record, not two separate copies. Two exceptions: routine infrastructure backups may retain deleted data for a limited period before they roll over, and a report you filed or were named in is kept on file (with your identity removed from it) rather than deleted with your account, so a safety record isn't lost simply because one side of it deleted their account. Can't log in, or need something else? Use our privacy request form.
Legal review
Several states have specific statutory confidentiality protections for HIV/STI status. This policy is a draft pending legal review before public launch, not a final legal document.
