Privacy at ToBoMin
Notice version: 15 September 2026
ToBoMin operates ToBoMin. Our dedicated privacy and support contact is being set up. Contact details will appear on the support page when available.
What you share
We collect your email, nickname, first and last names, date of birth, gender, country, country preferences, stated religious community, profile photo, verification selfie, and answers to membership questions. We also store saved likes, message requests and their acceptance status, messages, read status, posts, blocks, reports, and moderation records needed to operate the community.
Membership and matching
You explicitly consent to the use of your religious community and verification answers to review your application and apply community matching rules. You can withdraw that consent by deleting your account. Your date of birth determines age eligibility. Matching uses your stated gender, community, age and country preferences; it does not infer religion or identity from your face.
Who can see what
Your last name is private by default and available to authorized reviewers. It appears on your member profile only if the admin enables public last names and you choose to share yours in Settings. Turning either setting off hides it. Existing profile eligibility and blocking rules still apply.
Your nickname, age, country, biography and approved profile photo are visible to eligible, approved members. Your date of birth, verification selfie and application answers are private to you and authorized reviewers. Your first name is shared with a message recipient only when you choose to share it. A first introduction can arrive without a mutual like; further messages require the recipient to accept. Conversations are private to the participants through application access controls; they are not end-to-end encrypted. Infrastructure administrators may have operational access.
Posts created in the Feed appear only in the Feed; posts created on a member’s profile appear only on that profile. Both follow the same visibility and blocking rules. Post heart counts are visible to people who can view the post. The post owner can see which eligible members hearted it and open their profiles; other members cannot see that list.
Admin support
Admin support is a separate conversation shared with the moderation team, including when your application is rejected or your membership is suspended or banned. All staff replies appear as “Admin.” Authorized staff can read the whole support conversation; private audit logs record which staff member replied. Support messages are removed with your account.
Storage and service providers
Supabase provides authentication, database and private photo storage. The website hosting provider processes requests needed to deliver the service. Photos are validated and converted on the server, and embedded location metadata is removed. Photo links expire shortly, but recipients can still take screenshots or save information they can see. We do not sell member information or run advertising trackers.
Retention and deletion
Verification selfies and answers are scheduled for deletion 30 days after a review decision. Pending applications retain their evidence while awaiting review. Account deletion immediately hides your profile and queues removal of your account, photos, posts, matches and messages. Cleanup normally completes immediately; interrupted jobs retry daily. Administrators keep the deleted nickname and optional departure reason for 90 days. Administrative activity logs are also limited to 90 days. Infrastructure backups follow the configured provider retention schedule and are not instantly overwritten by an individual account deletion.
Your controls
In My profile, you can update preferences, download account data, block members or delete your account. A deletion reason is optional. Contact support for corrections to verified information or to request data that is not included in the self-service download. The account owner must transfer ownership to another moderator before deleting their own staff account.
Browser storage
The app stores authentication session information in your browser so you can remain signed in. Sign out when using a shared device. Application drafts and private verification answers are not saved in browser local storage.