Effective date: July 27, 2026
Last updated: July 27, 2026
This Privacy Policy explains what personal information Therr, Inc. ("Therr", "we", "us", or "our") collects, why we collect it, who we share it with, how long we keep it, and the choices and rights you have. It applies to the Therr mobile application, our websites at www.therr.app and www.therr.com, and the related services we operate (together, the "Service").
The rest of this policy is the detail behind those points. If anything here is unclear, email us at info@therr.com.
Therr, Inc., 8 The Green STE B, Dover, DE, 19901, United States, is the controller of your personal information for the purposes of the EU and UK General Data Protection Regulation ("GDPR") and the business that collects your personal information for the purposes of US state privacy laws.
Contact: info@therr.com | Attn: Privacy, 8 The Green STE B, Dover, DE, 19901, USA.
EEA, UK, and Québec users: we are in the process of appointing a representative under GDPR Article 27 and a person in charge of the protection of personal information under Québec's Law 25. Until that appointment is published here, you may direct any request or complaint to info@therr.com and we will handle it under the same timelines the law requires of a representative.
Each of the following requires an operating-system permission that you grant, and that you can revoke at any time in your device settings. Revoking a permission disables the feature that depends on it but does not otherwise affect your account.
We do not collect biometric identifiers. We do not run facial recognition, face grouping, voiceprint, or fingerprint analysis on any content you upload. We do not collect government identification numbers, Social Security numbers, health or medical information, precise financial account numbers, or information about your race, ethnicity, religion, sexual orientation, or political affiliation. We do not buy personal information from data brokers.
We use personal information only for the purposes below. The GDPR legal basis for each purpose is shown in brackets for users in the EEA and UK.
If we ever want to use your personal information for a materially different purpose, we will update this policy and, where the law requires it, ask for your consent first.
We do not sell your personal information, and we have not sold it in the preceding 12 months. We do not share your personal information for cross-context behavioral advertising, and we have not done so in the preceding 12 months. This applies to all categories of personal information we collect, including precise geolocation and other sensitive personal information, and it applies to the personal information of users we know to be under 16.
We also do not use or disclose sensitive personal information for purposes other than those permitted under California Civil Code §1798.121(a) and its implementing regulations — that is, we use it only to provide the Service you requested, to keep the Service secure, and for the other operational purposes described in this policy.
Because we do not sell or share personal information, there is nothing for you to opt out of. We nonetheless honor browser-based opt-out preference signals, including Global Privacy Control (GPC), by disabling non-essential analytics cookies for that browser. You can review and change your cookie choices at any time from the "Cookie settings" link in our website footer, and you can read more on our Your Privacy Choices page.
We disclose personal information only in the situations below. In every case involving a service provider, we have a written contract that limits them to processing the information for us and prohibits them from using it for their own purposes.
Your username, profile photo, bio, and the content you post are visible to others according to the visibility settings you choose. Content you post publicly, and Space and Event pages, may be indexed by search engines and visible to people who do not have a Therr account. Direct messages are visible to the people in the conversation. Anything you post publicly should be treated as public.
| Provider | What they do for us | Their privacy policy |
|---|---|---|
| Google Analytics | Aggregate website and app usage analytics | policies.google.com/privacy |
| Google Firebase & Firebase Cloud Messaging | App analytics, crash reporting, push notification delivery | firebase.google.com/support/privacy |
| Google Maps Platform & Places | Maps, geocoding, and place information | policies.google.com/privacy |
| Stripe | Subscription and payment processing | stripe.com/privacy |
| Apple App Store / Google Play | In-app purchase processing | apple.com/legal/privacy · policies.google.com/privacy |
| ImageKit | Image and media storage and delivery (CDN) | imagekit.io/privacy-policy |
| Brevo | Email newsletter and transactional email delivery | brevo.com/legal/privacypolicy |
| Our SMS delivery provider | Sending verification codes and invitations you initiate | Named on request at info@therr.com |
| Cloud hosting and database providers | Running the Service infrastructure | Named on request at info@therr.com |
We keep this list current. If you would like the complete, dated list of our subprocessors, email info@therr.com.
If you check in at a Space, rate it, or redeem a promotion, the business that owns that Space may receive aggregate engagement metrics and, for a redemption, the limited information needed to honor the offer. Businesses do not receive your contact information, your location history, or your activity elsewhere on the Service.
We may disclose information when we believe in good faith that it is necessary to comply with a law, regulation, subpoena, court order, or other valid legal process; to enforce our terms; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Therr, our users, or the public. Where we are legally permitted to do so, we will make reasonable efforts to notify you before disclosing your information in response to a legal request.
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our business, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy, and the acquirer will remain bound by this policy for information collected before the transfer unless you agree otherwise.
We will disclose your information for any other purpose only with your consent.
We use automated systems to order and recommend content. You should know how they work:
| Category | Retention |
|---|---|
| Account and profile data (name, email, profile information) | For the life of your account. If you delete your account, purged within 30 days except where the law requires retention. |
| Content you post (Moments, Spaces, Events, Thoughts, media) | Until you delete it or delete your account, then purged within 30 days. Copies other users saved or shared may persist. |
| Location data (foreground and background) | Up to 30 days for proximity features, then aggregated or deleted. |
| Uploaded phone contacts | Up to 90 days from upload, or until you ask us to delete them, whichever is sooner. |
| Usage and analytics data (device info, interaction logs) | Up to 24 months for service improvement and security analysis. |
| Transaction and payment records | Up to 7 years, to comply with financial and tax regulations. |
| Rewards ledger (TherrCoin, XP, redemptions) | Up to 7 years, for anti-fraud and tax recordkeeping. |
| Communications and support records | Up to 3 years after your last interaction with support. |
| Trust-and-safety records (reports, enforcement actions) | Up to 3 years, so we can act on repeat behavior. |
| Server and security logs | Up to 12 months. |
We may keep information longer where we must do so to comply with a legal obligation, resolve a dispute, or establish or defend a legal claim. When a retention period ends, we delete the information or irreversibly aggregate it so it no longer identifies you.
We use safeguards appropriate to the sensitivity of the information, including: encryption of data in transit using TLS; encryption of sensitive data at rest; password hashing with a modern algorithm; encrypted local storage for credentials and tokens on mobile devices; role-based access controls limiting employee access to what their job requires; separate read and write database credentials per service; multi-factor authentication on administrative accounts; logging and monitoring of access to production systems; and contractual security commitments from our service providers.
No system is perfectly secure. If we become aware of a breach of security affecting your personal information, we will notify you and the applicable regulators as required by law and without undue delay. Please help us by using a strong, unique password and enabling every verification option available on your account.
We are based in the United States, and we store and process personal information there. If you use the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws differ from those in your country.
For transfers of personal information out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary technical and organizational measures. You may request a copy of the relevant transfer mechanism by emailing info@therr.com. For transfers of personal information outside Québec, we conduct a privacy impact assessment before the transfer as Law 25 requires.
We do not charge for exercising a privacy right, and we will never discriminate against you for doing so — we will not deny you the Service, charge you a different price, or give you a lower quality of service because you exercised a right.
You have the right to: request access to your personal data; request rectification of inaccurate or incomplete data; request erasure; request restriction of processing; object to processing based on our legitimate interests, and object at any time to processing for direct marketing; request data portability; withdraw consent at any time, without affecting processing already carried out; and not be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.
To exercise any of these rights, email info@therr.com. We will respond within one month and may extend that by two further months for complex requests, telling you why. You also have the right to lodge a complaint with your local supervisory authority; a list of EEA authorities is published by the European Data Protection Board, and UK users may contact the Information Commissioner's Office.
Residents of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia — and of any other state whose comprehensive privacy law takes effect after the date of this policy — have some or all of the following rights, depending on their state:
How to submit a request. Email info@therr.com with "Privacy Request" in the subject line, tell us which right you are exercising, and include the email address or phone number on your Therr account. We will verify your identity — for a request about specific pieces of personal information we may ask you to confirm details only the account holder would know — and respond within 45 days, extendable once by another 45 days with notice to you. Disclosures cover the 12 months before your request.
Authorized agents. You may use an authorized agent to submit a request. We will ask the agent for written proof of your permission and may ask you to verify your identity with us directly. In California, an agent registered with the Secretary of State may act on your behalf.
California Shine the Light. Under California Civil Code §1798.83, California residents may request information about disclosures of personal information to third parties for their direct marketing purposes. We do not make such disclosures.
California minors. Under California Business & Professions Code §22581, California residents under 18 who are registered users may request removal of content they posted publicly. Email info@therr.com from the address on your account. Removal may not be complete or comprehensive — for example, where the law does not require removal, or where other users have already copied the content.
Categories of personal information we collect, using the category names in the California Consumer Privacy Act: identifiers (collected); personal information listed in the California Customer Records statute, Cal. Civ. Code §1798.80(e) (collected — name, phone, and billing status only; we do not collect account numbers, government IDs, or health information); commercial information (collected); internet or other network activity (collected); precise geolocation, which is sensitive personal information (collected with your permission); audio, electronic, or visual information, i.e. the photos and videos you upload (collected with your permission); inferences drawn to personalize content (collected); protected classification characteristics (not collected); biometric information (not collected); professional or employment information (not collected except from job applicants, who receive a separate notice); non-public education information (not collected). We collect these from you directly, automatically from your device as you use the Service, and from the third-party sources listed above. We disclose them for business purposes only, to the service providers and in the situations described in this policy. We do not sell any category of personal information and we do not share any category for cross-context behavioral advertising.
In addition to the rights above, you may request that we cease disseminating personal information or de-index a link where dissemination contravenes the law or a court order, and you may request information about how a decision was reached where it was based exclusively on automated processing. You may also file a complaint with the Commission d'accès à l'information du Québec.
The Service is not intended for or directed to children under 13 (or under 16 in the EEA, the UK, and any other jurisdiction that sets a higher age of digital consent). You must be at least 13 years old — and old enough to consent to the processing of your personal information where you live — to create an account.
We do not knowingly collect personal information from children under 13. We ask for age confirmation at registration and we do not design, market, or promote the Service to children. If we learn that we have collected personal information from a child under 13 without verifiable parental consent, we will delete the account and the information promptly.
If you are a parent or guardian and believe your child under 13 has created an account or provided us with personal information, email info@therr.com with the account's username or email address and we will investigate and delete it. You may also request access to, correction of, or deletion of your child's information, and ask us to stop any further collection.
Some features — including location sharing, direct messaging, contact invitations, rewards redemption, and paid plans — are restricted to users 18 and over, or require a parent's or guardian's consent where local law requires it.
Reporting child sexual abuse and exploitation: we prohibit it absolutely, we report it to the National Center for Missing & Exploited Children and to law enforcement, and you can report it to us immediately at therr.com/child-safety.
Our websites use cookies and similar technologies. Strictly necessary cookies are always on. Analytics cookies load only after you consent, and we honor the Global Privacy Control signal. You can change your choices at any time from the "Cookie settings" link in our footer. For the full detail — what each cookie does and how long it lasts — see our Cookie Policy.
Do Not Track. There is still no common industry standard for how to respond to browser Do Not Track signals, so our websites do not respond to them. We do respond to Global Privacy Control, which is a recognized opt-out preference signal.
We do not serve third-party interest-based advertising on our websites or in the app, and we do not permit third parties to collect personal information through the Service for their own advertising purposes.
The Service contains links to websites and apps we do not operate, including business websites, menu and reservation links, and content other users post. We are not responsible for their content or privacy practices. Review their privacy policies before giving them information.
We may update this policy. When we do, we will change the "Last updated" date above and post the new version here. If a change materially reduces your privacy rights or materially expands how we use information you have already given us, we will give you at least 30 days' advance notice by email or through a prominent in-app notice before it takes effect, and — where the law requires it — we will ask for your consent. We keep prior versions available on request at info@therr.com.
Questions, requests, or complaints about privacy:
We take complaints seriously. If you are not satisfied with our response, you may contact your data protection authority or state Attorney General, as described above.