Policy effective date: August 29, 2026.
This Privacy Policy explains how Solstice Labs LLC, doing business as NearbyGrid (“NearbyGrid,” “we,” “us”), collects, uses, discloses, retains, and protects personal data in the NearbyGrid mobile applications, websites, and related services (the “Service”). The Service is operated in the United States and is currently offered only in supported U.S. locations.
The Service is for adults. You must be at least 18 years old. We do not knowingly permit an under-18 account.
Account and authentication data. Depending on the method you choose, this includes email address, mobile number, password verifier, one-time proof records, Apple or Google authentication identifier, account and session identifiers, date of birth, residence declaration, signup source, legal-version acceptance, security events, and account status. We do not receive your Apple or Google password.
Profile and discovery data. This may include display name, profile photos, bio, gender, pronouns, sexual orientation, body type, height, interests, lifestyle information, relationship status and intent, visibility settings, hearts, pins, connections, groups, events, RSVPs, and presence. Information you place on a public or shared surface is visible to the audience described there.
Location data. With permission, we collect device coordinates and related timestamps to provide map, distance, nearby discovery, travel, check-in, group, and event features. NearbyGrid may store true coordinates but sends other members only an obfuscated position or approximate distance under the current location policy. Visibility and obfuscation reduce risk but cannot prevent every inference.
Communications and private content. We process direct, group, and event messages; message metadata; private-album photos; direct-photo messages; album access and revocation; reactions; report evidence; and the identifiers needed to enforce access. Private album content may contain highly sensitive sexual or intimate information. “Private” means access-controlled, not exempt from storage, security, reports, legal process, or restricted safety review.
Photos and moderation data. For public photos and public group/event imagery, we process the normalized image, content hash, surface, automated classification, status, reason category, moderation provenance, timestamps, appeal or reviewer action, and derived display variants. Private album and direct-photo uploads are not currently sent to the automated public-photo classifier at upload; they may be reviewed by authorized safety personnel when reported or when law requires.
Optional selfie-review data. If you voluntarily use the current supporting-member selfie check, we temporarily process one static image and send it to Anthropic's commercial Messages API with an image-classification prompt. We record the pass/fail result needed for the badge and may record privacy-minimized reliability or error information. NearbyGrid's current application code does not intentionally write the submitted selfie into the member photo table or photo-storage directory. The check does not compute a NearbyGrid face template, perform face matching, prove liveness, verify identity, or guarantee age. This statement must be re-reviewed before any vendor, model, logging, or age-assurance change.
Device, network, and operational data. This includes IP address, device and platform type, app and build version where available, language, time zone, push token, request timing, coarse failure and performance diagnostics, security and rate-limit signals, cookie and local-storage identifiers, feature configuration, and crash information. NearbyGrid's observability rules prohibit raw passwords, proof codes, message text, precise coordinates, intimate images, Affiliate bearer credentials, and similarly sensitive payloads from analytics and crash telemetry.
Support and feedback data. When you contact support or voluntarily send in-app feedback, we process the message and the contact information you provide. Signed-in feedback also uses the existing account name, account identifier, and reply address needed to investigate and respond. Under the target 1.0.3 support design, the client may attach a separate privacy-minimized context containing only platform, support surface, app version, build, runtime and update identity, whether an embedded update state is known, a coarse route, a coarse last authentication/onboarding/support stage, client and receipt timestamps, and a random correlation identifier. That structured context excludes raw paths and queries, precise coordinates, account/message/entity identifiers, photos, passwords, proof codes, tokens, cookies, Affiliate or Legal authority, and free-text logs. Ordinary feedback does not automatically append a detailed Map lifecycle log under that target design. If you separately choose **Send map diagnostics**, the displayed lifecycle text you choose to send becomes part of the support message. These target-design statements must not be published until `NG-20260825-008` is composed and released on the covered clients; current clients may behave differently.
Purchases and subscriptions. Apple, Google, and subscription processors provide product, status, renewal, transaction or provider-event identifiers, price/currency where supplied, and refund, chargeback, and entitlement state. NearbyGrid does not receive your full app-store payment card.
Affiliate data. If you follow or enter a referral, enroll in the Affiliate Program, or are attributed at creation, we process the code or share token, signed first-party browser/app context, capture and expiry, consent choice, account-creation attribution, enrollment and Terms evidence, email preference, eligibility, privacy-safe subscription-accounting events, Points ledger, reversals, redemption requests and fulfillment records, fraud and reconciliation cases, and audit records. An Affiliate does not receive a referred person's identity, email, private content, exact purchase, or raw payment identifier.
Reports and safety data. This may include reporter and reported-account identifiers, relationship or thread reference, selected message/photo/event/group item, report reason and narrative, a screenshot or file the reporter chooses to attach, timestamps, recognition-safe display fields, moderator access and action history, appeals, account restrictions, and lawful preservation or disclosure records. Blocking or removing a connection may create a privacy-minimized opaque report reference without restoring contact or private access.
We collect data directly from you; from your device and use of the Service; from other members who interact with or report content; from Apple, Google, payment/subscription providers, email and SMS delivery providers, authentication providers, maps, analytics and crash providers, automated image review providers, and hosting/security providers; and from public or lawful sources used for fraud, safety, legal compliance, or event/group information.
We use data to:
Private-message safety processing. NearbyGrid does not routinely send ordinary private-message text to a generative-AI provider or have a person read each ordinary private message before delivery. Automated local rules may process message text before or after delivery. Current rules include first-contact contact-information prompts, repeated-message comparison, and bounded money-solicitation or scam signals. These rules may retain limited message/account identifiers, matched signal data, confidence, and a bounded text sample for safety review. Authorized personnel may review an exact reported message, restricted report evidence, or a narrowly retained safety sample when reasonably needed for review, appeal, abuse prevention, safety, or law. Current source schedules removal of retained text samples and matched tokens after approximately 90 days while preserving only the limited signal or audit metadata supported by the final production retention schedule. The final published wording and retention period must match the exact enabled rules, administrative visibility, access controls, appeal path, and production minimization evidence.
We do not use member photos, private content, messages, precise location, sexual-orientation data, or selfie images to train a NearbyGrid or third-party general-purpose AI model. We do not license member content for another company to train such a model. Any future change would require a new documented product decision, legal analysis, notice, and any consent required by law.
Location, sexual orientation, sexual activity or preferences, intimate content, account safety status, and any biometric data are sensitive. NearbyGrid collects and uses sensitive data only for specified Service, safety, security, legal, or member-requested purposes and seeks a separate affirmative choice where law requires one. Accepting the Terms or acknowledging this Policy is not blanket consent to optional sensitive-data processing.
NearbyGrid does not currently create or use a face-geometry template or identity-matching biometric system. A future biometric age or identity feature would require a separate point-of-collection notice, explicit consent where required, a manual/refusal alternative, vendor and security review, retention/destruction rules, testing, and separate approval before collection begins.
Current public-photo flow. Profile photos and member-uploaded group/event images are normalized to a JPEG and stripped of ordinary metadata. Except for narrowly defined source-owned bypasses, such as trusted official imported event covers, the current configured public-photo path sends that image to Anthropic with a surface-specific classification prompt before ordinary public use. If screening is unavailable, the upload fails closed instead of becoming an ordinary public approval. The automated result may approve, reject, delay, or refer the image. We store the result and reason/provenance needed to operate the feature, test reliability, and support review. An approved image and display variants remain while the member keeps the photo. A rejected image may be held in a nonpublic moderation-quarantine area for approximately 30 days so an error can be reviewed, then is scheduled for deletion unless a safety or legal hold applies. The final disclosure must enumerate every enabled bypass and import path from exact release bytes.
Current private-media flow. Private-album and direct-photo uploads are normalized and stored behind authorization controls but are not currently sent through the automated public-photo classifier at upload. A recipient can report eligible private content. A report can create a restricted evidence copy and permit authorized human review without restoring album access to the reporter. NearbyGrid does not promise that private media has been proactively reviewed or found safe.
Limitations and review. Automated classification can be inaccurate and may perform differently across people and contexts. An approval is not a finding that content is lawful, consensual, authentic, adult, or safe. A rejection is not by itself a finding of illegal conduct. NearbyGrid provides a reasonable human-review route for eligible content or account actions and tests material error patterns without claiming the system is perfect or bias-free.
Processor retention. Under Anthropic's published standard commercial API policy, API inputs and outputs are ordinarily deleted from its backend within 30 days, but may be retained longer to enforce its usage policy or comply with law; currently published limits allow flagged inputs and outputs to be retained for up to two years and related trust-and-safety classification scores for up to seven years. A zero-data-retention arrangement applies only if separately approved and configured. Before publication, NearbyGrid must verify its actual account, contract, model, region, training settings, and zero-retention status and update this section if a shorter binding rule applies.
Other members. We disclose information to the audience and features you select, such as a public profile, group, event, message recipient, or approved album viewer. We do not disclose true device coordinates as another member's map coordinates under the current product design.
Service providers. We disclose only data reasonably needed to providers for hosting/storage, content delivery, maps, authentication, email/SMS/push delivery, payments/subscriptions, analytics, crash diagnosis, security, customer support, and automated image review. Providers are restricted by contract and law to authorized purposes, confidentiality, security, and retention. A current subprocessor list should identify material providers and functions before this draft is published.
Safety and legal disclosures. We may disclose data to NCMEC, law enforcement, courts, regulators, victims or authorized representatives, or other parties when required by law, valid legal process, an emergency, the protection of rights and safety, or the handling of a valid intimate-image removal request. We evaluate legal requests and seek to limit disclosures to what is lawful and necessary.
Business transactions. Data may be reviewed or transferred in a financing, merger, acquisition, reorganization, bankruptcy, or sale, subject to confidentiality and applicable notice/choice rights.
NearbyGrid does not sell personal data or share it for cross-context behavioral advertising. We do not disclose sensitive data to advertisers. If those practices change, NearbyGrid must update the Policy and provide legally required opt-out or consent before the change.
A report includes only the items the report flow identifies plus any screenshot or narrative the reporter adds and the minimum account/relationship context needed to authenticate, investigate, and prevent abuse. For a post-block report-history feature, NearbyGrid may privately preserve a bounded set of eligible prior items and expose them through opaque handles. The reported account does not routinely receive the reporter's identity or report contents from the report flow. Reports are not absolutely confidential or anonymous: authorized personnel and limited service providers may access them, and NearbyGrid may disclose limited information when reasonably necessary to investigate, protect people, address fraud or abuse, provide a legally appropriate process, or comply with law or valid legal process.
Blocking ends ordinary contact and album access but does not delete restricted safety evidence. Report-history access must not reveal live location, reopen a profile or conversation, expose a private album, or allow new contact. The current `NG-20260825-002` target DTO uses display-name text for recognition and requires its recognition photo field to be literal null; it does not provide an ordinary profile or image URL. Any later recognition-image proxy requires separate private, authenticated, no-store review and disclosure. Authorized safety access is logged and limited. The final published text must match the exact evidence window, item types, account-deletion behavior, and retention established by `NG-20260825-002`.
An identifiable person or authorized representative may submit a TAKE IT DOWN request without a NearbyGrid account through the clear public process on the Safety/Privacy pages. We collect the minimum request, contact, depiction, location, attestation, and status information required to validate and process it. For a valid request, we remove or disable the identified depiction and make reasonable efforts regarding known identical copies within 48 hours, provide a request identifier and status, secure the request, and retain the case only as needed for compliance, disputes, abuse prevention, and law. This covers qualifying real and digitally created or altered intimate imagery.
The Service is adult-only. If we learn an account belongs to a minor, we restrict it and delete ordinary account data subject to child-safety and legal duties. If NearbyGrid obtains actual knowledge of an apparent violation covered by 18 U.S.C. §2258A, it reports to NCMEC and preserves the submitted and reasonably accessible contextual material under secure, restricted access for the legally required period. Child-safety material is not part of ordinary account exports or general support access.
We retain data only for defined operational, safety, financial, dispute, and legal purposes. The final production retention schedule controls and must be tested before this draft is published. Current intended categories include:
Deletion cannot recall content another member copied outside the Service. Deletion may be delayed or limited for security, chargebacks, tax/accounting, dispute, abuse prevention, NCMEC, TAKE IT DOWN, law-enforcement, litigation-hold, or other legal reasons. Restricted retention does not permit ordinary member display.
NearbyGrid uses administrative, technical, and physical safeguards appropriate to the sensitivity and risk of the data, including access control, encryption in transit, private-media authorization, credential hashing/signing, restricted evidence handling, audit logging, and vendor review. No system is completely secure. We investigate incidents and provide legally required notice.
You can edit profile fields, manage visibility and distance, check out or disable location, manage album grants, block members, control available notifications and email preferences, clear or replace an unbound Affiliate code before account creation, and delete your account. Revoking an album grant stops future in-Service access but cannot erase a copy made outside the Service. Turning off an optional choice does not erase records lawfully retained for prior processing, security, or law.
NearbyGrid does not require acceptance of a later Terms or Privacy bundle solely to exercise an applicable privacy right or use the narrow safety, opt-out, withdrawal, revocation, deletion, cancellation, export, or sign-out controls that remain available through the legal-reacceptance screen. Those controls do not restore ordinary Service access. The final published statement is conditioned on the exact server, Web, Native, accessibility, and rolling-client recovery matrix.
Affiliate email is a separate optional preference. Opting out does not disable transactional, security, legal, event, or other independently authorized messages. General account creation never constitutes consent to Affiliate marketing.
Depending on your state and applicable thresholds or exemptions, you may request access, confirmation, correction, deletion, portability, or an appeal, and may opt out of sale, targeted advertising, or certain profiling. NearbyGrid currently states that it does not sell personal data or use it for cross-context behavioral advertising. We honor legally applicable recognized opt-out signals, including Global Privacy Control, for covered processing.
Submit a request to [email protected] or through available account controls. We verify a request proportionately and will not discriminate for exercising a right. An authorized agent may submit where state law permits. We may deny or limit a request under a lawful exception and will explain applicable appeal rights.
Sexual-orientation/activity, precise-location, and intimate-content processing requires specific state-law analysis. Before publication, counsel must determine whether NearbyGrid needs separate Washington or Nevada consumer-health notices, authorizations, processor contracts, or geofenced workflows. A broad Terms acceptance is not a substitute for a required consumer-health authorization.
NearbyGrid opens Canadian provinces only after the availability page lists them as available. Quebec is not open. NearbyGrid is operated by Solstice Labs LLC in the United States, and personal information is processed in the United States by us and the service providers listed in this Policy. Those providers may be subject to lawful access by U.S. authorities.
We process account, profile, interest, communication, report, device, subscription, and optional location information to provide and secure the Service. Profile choices may reveal sexual orientation or gender identity. A map check-in may reveal an approximate area and allow others to infer places you spend time. We do not sell this information or use it for advertising.
Map publication is optional and requires a separate affirmative choice. Immediately before the first check-in for a notice version, NearbyGrid explains what location information is stored, who can see the result, the purpose, expiry, and material inference risk. NearbyGrid does not continuously track your location. You can check out at any time; checkout removes the published check-in and withdraws current map consent.
You may request access to or correction of your personal information, ask questions, challenge compliance, or withdraw an optional consent by contacting [email protected]. Withdrawal does not affect processing already lawfully completed and may make the optional feature unavailable. You may also download account data and delete your account in the Service. After deletion we keep only a keyed hash of the email address and phone number tied to any signup promotion, so the promotion cannot be claimed a second time, and the hash cannot be turned back into the address or number. We answer access requests within 30 days.
Privacy officer: Tim Hess, [email protected], Solstice Labs LLC, 7234 W North Ave, Ste 208 #268, Chicago, IL 60707, United States. Backup contact: [email protected].
NearbyGrid opens New Zealand only after the availability page lists it as available. NearbyGrid is operated by Solstice Labs LLC in the United States. Personal information you provide is held and processed in the United States by us and the service providers listed in this Policy (Privacy Act 2020, principle 12, overseas disclosure). By joining you agree to that transfer, and we apply the protections described in this Policy wherever the information is held.
We collect account, profile, interest, communication, report, device, subscription, and optional location information directly from you, and some information from other members (for example reports or group activity). We use it to provide and secure the Service and for the purposes stated in this Policy. Profile choices may reveal sexual orientation or gender identity. A map check-in reveals an approximate area for a limited time and only after your separate affirmative choice; NearbyGrid does not continuously track you, and checkout removes the check-in and withdraws that consent.
You may ask for access to or correction of your personal information at any time by contacting [email protected], and you may download your data or delete your account in the Service. We answer access requests within 20 working days. We keep information only as long as needed for the purposes above. If a privacy breach is likely to cause serious harm we will notify the Office of the Privacy Commissioner and affected people as the Act requires.
Privacy officer: Tim Hess, [email protected], Solstice Labs LLC, 7234 W North Ave, Ste 208 #268, Chicago, IL 60707, United States. Backup contact: [email protected].
NearbyGrid uses first-party cookies or local credentials for authentication, security, preferences, legal state, and time-limited Affiliate referral context. Web analytics and crash tools are limited to disclosed operational purposes and must not receive message text, precise location, private media, passwords, proof codes, raw Affiliate bearers, or other prohibited payloads. NearbyGrid does not run third-party advertising networks or use cross-company behavioral advertising under this version.
NearbyGrid is not directed to anyone under 18. If you believe a minor is using the Service, contact [email protected]. We restrict the account and handle data under applicable child-safety, reporting, preservation, and deletion duties.
For a material update, we provide legally required notice, identify the version and effective date, and request affirmative acknowledgment or consent where required. A Privacy acknowledgment records presentation; it is not blanket consent to an optional use. Urgent legal, safety, security, or fraud changes may use a shorter lawful notice period.
Solstice Labs LLC 7234 W North Ave, Ste 208 #268 Chicago, IL 60707, United States
Privacy requests: [email protected] Support and safety: [email protected] Child safety: [email protected]
Privacy officer (Canada and New Zealand): Tim Hess, [email protected]. Backup contact: [email protected].
END OF DOCUMENT