Legal
Privacy Policy.
Last updated: August 14, 2026
This policy describes what Encore collects, how it's used, and what control you have. Plain English only. No dark patterns.
Encore is operated by Encore Connections LLC, a New York limited liability company ("Encore," "we," "us"). If you have a question about this policy, write to admin@encoreconnections.com.
What this website collects
Encore is application-only, and since August 14, 2026 the application itself happens in the app: it is the profile you build there — name, photos, and the rest — read by a person before you're let in. What this site collects is smaller: it takes your name and email, hands you the link to get the app, and files those details so the review knows you're coming. Here is exactly what we store from this site:
- Your name — required, so a person (not an algorithm) can address you.
- Your email — required. It's the address you'll create your account with, and where we write if you're accepted.
- A referral code — optional. If someone on Encore gave you theirs, we record it so they get credit. A code doesn't skip the review.
- Your browser's user-agent string — captured once at submission for abuse review only. Not used to track you across sessions or sites.
- An anonymized hash of your IP address — held briefly so we can rate-limit submission attempts and stop bots. We do not retain the raw IP.
Before August 14, 2026, this form also collected a birthday, a phone number, and an Instagram handle. If you applied then, we still hold what you gave us, under the same rules the app section below describes for those same fields — and those fields now live in the application you build in the app.
One deliberate quirk worth naming: the form never tells anyone whether an email, phone number, or Instagram handle is already on file. A duplicate application and a brand-new one look identical from the outside. On a product where people disclose where they physically were, "is this person registered?" is not a question a stranger gets to ask.
Before August 13, 2026, this site ran a waitlist instead of applications. If you joined it, we still hold what you gave us then — your email, name, city and neighborhood, how you heard about us, a referral code, your 18-or-older attestation, and your marketing-email consent, stored with its timestamp so we can show, if challenged, exactly what you agreed to and when. Everyone on the waitlist was moved into the application queue on the same terms. If you opted into marketing email, every email we send includes an unsubscribe link, and you can unsubscribe at any time without losing your place. To be removed entirely, write to admin@encoreconnections.com and we'll confirm and delete your record.
We do not currently sell or share your personal information for cross-context behavioral advertising. If our practices ever change, we'll notify you in advance and provide an opt-out as required by applicable state privacy laws (including California's CCPA right to opt out of sale and sharing).
We retain applications and waitlist entries until you ask us to delete them. If you're accepted, your application (and any waitlist entry) becomes part of your membership record and is kept with it. If your application is a profile built in the app, deleting your account from the app's settings deletes it — photos included — whether or not it was ever accepted.
The site uses no third-party analytics, no advertising trackers, and no cookies beyond what's strictly required to render the page. Nothing about your visit is shared with Google, Meta, or anyone else — with one narrow exception, which only happens when something breaks.
No analytics, advertising, or tracking code runs in your browser on this site — nothing that watches which pages you open, what you click, or how long you stay. The one outside script we load is Cloudflare's bot check, which guards sign-in to our own admin tools; it is there to keep bots out, not to follow you. Error reporting does not run in your browser at all: when a request to Encore fails, the Encore server that failed sends the details to Sentry, a crash-reporting service, so we find out a page is broken instead of waiting for someone to tell us.
A server error report contains three things: the address that was requested, with everything after the "?" stripped out so the one-time codes in our email links never travel with it; the error and the trace of where in our code it happened; and the time. It does not contain your IP address, your location, your browser, your language, any cookie, or any account identity — and there is no recording of your screen. We strip the contents of whatever you submitted, and every header your browser sent, before the report leaves our server. The one thing we can't promise is the wording of the error itself: if something you typed is what broke, the message describing the failure may quote part of it. Nothing at all is sent while the site is working. An error report exists so a broken page gets fixed, not so we can count you.
What we collect when you use the Encore app
The sections below describe what we collect once you have downloaded the Encore mobile app and created an account — which, since August 14, 2026, happens at application time: the profile you build, photos included, IS your application, and a person reads it before you're let in. Three things are true about that review, and we consider each a promise. First, while your application is under review — and if it is never accepted — your profile is sealed: no member of Encore can see it, be matched with it, or learn it exists; the only people who can see it are you and the reviewer. Second, we don't write rejection letters — if you don't hear from us, that's our answer — so the record of an unaccepted application simply stays sealed. Third, you can take it back: deleting your account deletes the profile and its photos, reviewed or not.
When you use the Encore app, we store:
- Your account email and password. The password is hashed — we never see it in plaintext.
- Your phone number. Every Encore account has one, for two reasons: it enforces one account per phone number, and it powers the "people you'd rather not see" shield described below. Your number is never shown to any other user, never used for marketing, and never sold. When phone verification is on, we confirm the number is yours by texting a one-time code.
- Your "people you'd rather not see" list — optional. You can add phone numbers of people you'd rather never encounter on Encore (an ex, say). We store each number as a one-way scramble plus its last four digits — never the readable number — and use it for exactly one thing: if that number ever belongs to an Encore account, the two of you are hidden from each other, in both directions, silently. This list is never shared with anyone, never used for marketing, and never sold — no exceptions.
- Your profile: name, birth date (to compute your age), photos, city, bio, gender, looking-for preference, height, ethnicity (optional), country of origin, heritage, favorite venues, interests, and your Instagram handle (used for identity verification and shown to your matches).
- Your check-ins: the venue you selected, the date, the time window you chose, and an optional note. When you open the check-in screen or the map, the app reads your device's GPS location — to suggest places near you, center the map, and (when you submit a check-in) compute a confidence score for whether you actually were at the venue. Venue suggestions come from Google Places: your coordinates and search text are sent to Google through our server, without your name or account attached. Only submitted check-ins store your coordinates; we never read your location in the background, and we never share your coordinates with other users.
- Descriptions you write. A check-in note may describe a person you noticed ("tall, dark hair, green jacket"), and you can describe what you yourself looked like that night. These descriptions are used for exactly one thing — finding a mutual match — and are never shown to the person described, never public, and never searchable by other users. Don't put names or contact details in them; that's against our terms.
- Likes and matches: the people you indicated interest in, and who indicated interest in you.
- Messages sent between matched users.
- Device push token, so we can send notifications about new matches, overlap nudges, and gentle reminders. You can disable notifications in your device settings at any time.
- Basic analytics events (e.g. "a user submitted a check-in") — never the content of messages, photos, or profile fields.
- A record of your agreement. When you create an account we record that you accepted the Terms of Service and this policy — which version, and when — and that you were shown our Dating Safety notice. We keep these records so we can both prove what was agreed.
Some of this information is sensitive by nature: who you're interested in meeting can reveal your sexual orientation, and your check-ins say where you were on a given night. We treat both accordingly — they are used only to run the matching service, never used for advertising, never sold, and shared only with the processors listed below.
What we don't do
- We don't track your location in the background.
- We don't build profiles of non-users. One narrow, user-requested exception: if you add someone's number to your "people you'd rather not see" list, we keep a scrambled version of that number solely to keep the two of you apart. It is never linked to anything else, never enriched, never shared, never sold.
- We don't sell your personal information — the data that identifies you. We may share or publish aggregated, anonymized statistics — patterns like "this neighborhood was busy on Thursdays" — that can never identify you or reconstruct anything about any individual. If we ever offer such insights commercially, they will only ever be built this way.
- We don't share the content of your messages, and no human reads them. An automated filter checks messages as they're sent and blocks slurs, explicit sexual language, and things that look like personal identifiers being posted. Your profile text — name, bio, and city — is checked against a broader list that also blocks ordinary profanity. That filtering is automatic: nobody reads what you wrote.
- We don't use your photos for facial recognition or to train AI models.
Who can see what
Encore has a two-tier visibility model. It's the heart of how the product works, so we want it to be unambiguous:
- Aggregated counts are public. Anyone using Encore can see "3 people were here tonight" for a venue — never names, never profiles, never which 3.
- Specific profiles only appear to people you actually overlapped with. When you and another user check in at the same venue on the same date, and your gender-interest preferences match on both sides, you appear to each other as a "potential match." The visible fields are your name, age, and avatar. Exposure is mutual and bounded — it is triggered only by real, shared overlap, never by browsing.
- Your check-in history is private to you. Encore never publishes a list of every place you've been. An individual overlap is what produces visibility, never your timeline.
- Your like is visible to exactly one person — the person you liked. Saying "that's them" shows that person your name, photos, and bio in their "Someone noticed you" list, along with the night in question, so they can decide whether they remember you too. No one else ever sees it, and you are never told whether they looked or passed — a no is silent. If they say it back, a match is created and both of you are notified. Instagram handles and favorite spots stay hidden until a match exists.
- Your messages are visible only to you and the person you matched with.
Third-party services we use
- Supabase hosts our database, storage, and authentication. Your account and app data live there.
- Google Places resolves venue names when you search or view a venue. We send the venue search text you type and, for nearby suggestions, your device's coordinates — routed through our server so your identity is never attached; Google returns matching candidates.
- Expo Push Notifications forward our notifications to your device.
- Twilio verifies phone numbers when verification is enabled: we send your number to Twilio, which texts you a one-time code. Twilio receives the number only — never your name, profile, or anything else about you.
- Sentry receives crash reports when something goes wrong, from the app and from this website's servers. From the app: device model, stack trace, and your account ID so we can see whether one person or many hit a bug. From the website: only what a failing server request produced — the address requested with the query string removed, the stack trace, and the time — with no account, no IP address, and no browser details attached. Never your email, profile content, messages, or photos.
- PostHog receives product-usage events so we can improve the app. Events are tagged with your account ID — not your email — and never include profile content, messages, or photos.
- Resend sends our email — application decisions, launch invitations, and (for waitlist-era signups who opted in) marketing emails. It receives your email address, your name, and the content of what we send you, and reports back deliveries, bounces, and unsubscribes.
- Vercel hosts this website, so web traffic (including application submissions) passes through it. Cloudflare Turnstile checks that sign-ins to our own admin tools come from humans, not bots.
- Apple distributes the app through the App Store and delivers push notifications to iPhones; the app's maps are Apple Maps.
Each of these providers processes data only to provide its service to us — none of them may use your data for its own purposes. We don't sell personal data to anyone, and we never sell sensitive data — no exceptions, no "partners."
Data retention
- Your account and all associated data are retained while your account is active.
- When you delete your account (Settings → Delete account), we permanently remove your profile, check-ins, likes, matches, messages, and photos from our database and storage. This happens within minutes and cannot be undone.
- A few narrow records survive account deletion, and we want to be exact about them: your original membership application and waitlist entry (name, email, phone, Instagram handle, birthday) — kept as the record of who was admitted and to prevent a removed member from simply reapplying; your acceptance records (which Terms and Privacy Policy versions you agreed to, and when); the email suppression list and email delivery logs if we've emailed you — the suppression list is kept precisely so your unsubscribe keeps working; hashed rate-limiting logs that were never linked to your profile; and crash reports and usage events already sent to Sentry and PostHog, which are keyed to your account ID, not your name or email — the website's server error reports are tied to no account at all — and age out of those systems on their retention schedules. If someone else added your number to their "people you'd rather not see" list, that scrambled entry belongs to their account, not yours, and stays on their list.
- Safety reports pause deletion for what they cover. When a conversation or profile is reported, we snapshot the reported conversation and the reported profile's text at that moment, and we keep that snapshot — even if either account is later deleted — for up to 12 months after the report is resolved. It's access-restricted to safety review and legal process, and nothing else. The report record itself (who reported whom, the reason, the outcome) is retained as part of our safety history. We built this deliberately: deleting an account should not delete the evidence of what someone did with it.
- Our database backups may retain account data for up to 30 days before final purge.
How we protect data
We use reasonable administrative and technical safeguards designed to protect your information: encryption in transit and at rest, row-level access rules in our database so accounts can only read what they're entitled to, restricted admin access, and vendors bound by their own security commitments. No method of transmission or storage is 100% secure, and we can't guarantee absolute security — anyone who tells you otherwise is selling something. If a breach ever affects your personal information, we'll notify you and the authorities as the law requires.
Law enforcement and legal requests
We disclose personal information in response to valid legal process — a warrant, court order, or subpoena — and we may disclose information when we believe in good faith that it's necessary to prevent imminent danger of death or serious physical injury. We don't hand over the content of messages on an informal request; federal law (the Stored Communications Act) forbids it, and we follow it.
Your rights
- Access: your profile and settings show most of what we store. For everything else we hold about you (for example, check-in coordinates or your consent records), email us and we'll provide it.
- Correction: you can edit your profile at any time via Settings → Edit profile.
- Deletion: you can delete your account immediately via Settings → Delete account. A typed confirmation gate prevents accidental deletion.
- Portability: email us for a copy of your data in JSON format — we'll send it within 30 days.
- Block & Hide: you can block another user (mutual — they cannot see you, you cannot see them) or soft-hide a match (removes it from your list without notifying the other person). Both controls are available from any chat thread.
- People you'd rather not see: in Settings, you can list phone numbers of people you'd rather never encounter here. If a listed number ever belongs to an Encore account, neither of you appears to the other — silently, in both directions, for as long as the number stays on your list.
- Wherever you live, write to admin@encoreconnections.com with any access, correction, or deletion request and we'll honor it — we don't make you prove which privacy law applies to you first.
Children
Encore is for adults only. You must be 18 or older to use it. If we learn a user is under 18, we delete their account.
International data transfers
Encore is operated from the United States. If you use the app from outside the U.S., your information is transferred to the U.S. and processed there. We use industry-standard safeguards to protect data in transit and at rest.
Changes
If we update this policy, we'll notify users in-app before the changes take effect. The "Last updated" date above always reflects the current version.
Contact
Questions or requests about your data: admin@encoreconnections.com
