Effective September 2, 2026. Replaces the Privacy Policy dated June 1, 2020. DigitalTreehouse, LLC ("CROWNS," "we") is the controller of your information.
Account: mobile phone number (or Apple sign-in identifier), first name, date of birth, gender, who you want to see, title style. Profile: photos, a prompt answer, optional "tonight I'm wearing" line, settings. Verification: a live selfie (see Section 3). Activity: crowns you give and receive, matches, messages, gifts sent and received, reports, invite codes. Support: what you tell us when you contact us. Purchases: product bought, price, store transaction identifier (we never see your card number).
Presence: when you tap I'm Here or the app re-verifies presence, your device sends its current location once. Our server compares it to the venue's radius and discards the coordinates. We record only the venue, check-in time, check-out time, and whether the check-in passed our integrity checks. Device: device model, operating system, app version, a device identifier and integrity attestation used for fraud prevention, push notification token, crash reports. Usage: which screens and features you use, without location.
Age range signals from Apple and Google; reports other users make about you; a referrer's invite code; venue data from the Overture Maps Foundation and Foursquare (about venues, not about you).
Some information is "sensitive" under U.S. state privacy laws: precise geolocation (processed transiently, never stored), biometric information (the verification selfie, Section 3), and sexual orientation, which may be inferred from whom you choose to see and crown. We process this information only to run the game, to keep you safe, and to prevent fraud; never for advertising. Where the law requires it, we ask for your consent, and you have the right to limit our use of sensitive information (Section 8). We do not process this information for any purpose beyond what is necessary to provide the Service.
To keep every room real, you take a live selfie ("Coronation Portrait") before you can crown, gift, or chat. Our identity provider (currently Stripe Identity) processes the selfie and your profile photos to confirm liveness and that the photos match. This is biometric information. We ask for your written consent in the app before collecting it. The provider retains face data for no more than 30 days and then permanently destroys it; CROWNS stores only the result (pass/fail), the date, a provider reference number, and a one-way hash used to keep banned users from returning. We never sell, lease, or trade biometric information, and we never use it for any purpose other than verification and ban enforcement. You may withdraw consent by deleting your account; the hash used for ban enforcement is retained only if your account was banned. This section serves as our public retention and destruction policy under Illinois, Texas, Washington, and similar laws.
To run the game (check-ins, rooms, crowns, titles, matches, chat, gifts, Diamonds); to verify that players are real and of age; to keep players safe and enforce our rules (moderation, reports, blocks, bans, fraud detection including location-spoofing detection); to send notifications you chose (crowns, matches, gifts, throne alerts, streaks); to process purchases and refunds; to provide support; to improve the Service through aggregate analytics; and to comply with law. We use automated tools, including third-party AI services, to screen messages and photos and to detect fraud; a person reviews reports and borderline cases. We do not make decisions about you using automated processing that produces legal or similarly significant effects without human review.
With other players: your first name, age, verified badge, photos, prompt, titles, House, gifts received (if you leave the feed name setting on), and the fact that you are checked in at a venue while you are there and not in Ghost mode. Crown-first mode limits this to people you crown. Nobody sees who crowned them unless it is mutual. Coronation cards you choose to share contain your first name, title, and venue.
With venues: aggregate counts only (for example, "38 players tonight"). Never identities, unless you opt in to a venue program.
With service providers who process information on our behalf under contract: Supabase (hosting and database, U.S.), Twilio (text messages), Apple and Google (sign-in, age signals, purchases, push notifications), RevenueCat (purchase records), Stripe (identity verification), OpenAI and Amazon Web Services (automated content screening), Expo (app builds and push delivery), Sentry (crash reports), and PostHog (product analytics). None of these receives your location, and none may use your information for their own purposes.
When required by law or to protect safety: to comply with legal process, to assist law-enforcement investigations of crimes, or to protect any person from harm. We have a policy of requiring valid legal process before disclosing user data and, where lawful, notifying the user.
In a corporate transaction such as a merger or sale, under this policy.
We do not sell personal information, do not "share" it for cross-context behavioral advertising, and do not disclose precise geolocation, biometric, or orientation-related information to any advertiser or data broker.
| Coordinates | Never stored |
| Check-in records (venue, times) | 30 days in identified form, then aggregate counts only; longer only if part of an open report |
| Active room presence | Until checkout, expiry (3 hours), or venue close |
| Crowns, titles, matches, gifts, Diamonds | Life of the account |
| Messages | Until unmatch, block, or deletion; 30 days after if part of a report |
| Verification result | Life of the account; provider deletes biometric data within 30 days |
| Reports and moderation records | 1 year |
| Ban-enforcement hashes (device, phone, verification) | Indefinitely, for banned accounts only |
| After you delete your account | Profile, photos, and messages are removed within 7 days; purchase records are kept as required by tax and accounting law |
We use encryption in transit and at rest, row-level access controls so that only players checked in at the same venue can read each other's cards, signed short-lived photo links, device attestation, and audited access to check-in data. No system is perfectly secure; if we learn of a breach affecting you, we will notify you as the law requires.
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information; to opt out of the sale or sharing of personal information and of targeted advertising or profiling (we do none of these); to limit the use of sensitive information; to withdraw consent; and to appeal a decision we make about a request. To exercise these rights, use the tools in the app (Me → Edit card, Me → Delete account) or email privacy@crowns.club. We respond within 45 days and may need to verify your identity. You may use an authorized agent where the law allows. We will not discriminate against you for exercising your rights. We honor Global Privacy Control signals as an opt-out where required. Device permissions: you control location, camera, photos, contacts, and notifications in your device settings; the app works without location except for checking in. Notifications: adjust in Me → Notifications.
California (CCPA/CPRA). In the past 12 months we collected the categories described in Section 1 (identifiers, personal information such as name and phone, protected classifications such as age and gender, commercial information, internet activity, sensitive personal information including precise geolocation processed transiently and biometric verification, and inferences limited to game preferences) from you, your device, Apple and Google, and other users, for the purposes in Section 4, and disclosed them to the service providers in Section 5 for business purposes only. We have not sold or shared personal information. Retention is in Section 6. California residents have the rights in Section 8, including the right to limit use of sensitive personal information; email privacy@crowns.club with "Limit" in the subject. Colorado, Connecticut, Virginia, Oregon, Texas, Maryland, Utah, Montana, Delaware, New Jersey, and other states with comprehensive privacy laws: the rights in Section 8 apply, including the right to appeal by replying to our response. We do not sell precise geolocation or any sensitive data. Nevada: we do not sell covered information.
The Service is for adults 18 and older. We do not knowingly collect information from anyone under 18. We use age-range signals from Apple and Google (including under the Texas, Utah, Louisiana, and California app-store accountability laws) and block accounts that are declared or verified under 18. If you believe a user is under 18, report them in the app.
The Service is currently offered in the United States and operated from the United States. If you use it from elsewhere, your information is transferred to and processed in the United States. The Service is not currently available in the European Economic Area, the United Kingdom, or Switzerland.
We will notify you in the app before material changes take effect. The current version is always at crowns.club/privacy.
Privacy questions and requests: privacy@crowns.club. Mail: DigitalTreehouse, LLC, 725 Cool Springs Blvd, Franklin, TN 37067-2702, United States.