CirclesMM is a small messaging app for staying in touch with people you actually know. This policy describes what data the app collects, who it goes to, and how to reach us if you want it removed. It is written in plain language. There is no fine print.
What we collect
- Your phone number — collected when you sign up so we can send you a one-time verification code by text message. We use it for sign-in only.
- Your profile — the display name you choose to show other members. You can change it at any time on the Profile screen.
- Your previous display name — When you change your display name, people you were already connected with (and you) can see your old name for 90 days. After that it is gone.
- Messages you send — chat messages in your circles, direct messages, and the circles you belong to are stored so the app can show them to you and to the people you sent them to.
- Photos you upload to Dynasty Tracker — if you use the Dynasty Tracker feature, the photos you upload (PS5 screenshots) are stored so the feature works for you, and the image is sent to our image-processing provider (see below) to read the roster data out of it.
- A push notification token — if you allow notifications, we store a device token so we can deliver them. Declining notifications means no token is stored.
- Premium purchase records — if you buy Premium, our payment provider (Stripe, see below) handles your card and billing details directly; we never see your card number. We store what's needed to know your purchase happened: payment status and your membership entitlement.
- Reports — if you report a message, we store the report (including a snapshot of the reported message) so we can act on it.
- A bot check when you sign up — when you tap Send Code, your device runs a check from Cloudflare that confirms a real device is asking, before we send the text. It runs on the sign-up and resend steps only. Details in Bot protection at sign-up below.
We do not collect your location. We do not collect your contacts. We do not run analytics or tracking SDKs inside the app. We do not use advertising identifiers.
The Cloudflare bot check on the sign-up screen, described below, is not analytics and does not follow you around the app.
Bot protection at sign-up
When you tap Send Code, the app runs a bot check from Cloudflare called Turnstile before we send your verification text. Fake sign-ups cost us real money in text messages and eat the hourly limit that real people need, so we check that a real device is asking.
The check runs in a small web view inside the app. It runs on the sign-up screen and on Resend code, and nowhere else. It does not run when you submit your code, and it does not run once you are signed in.
Cloudflare's own privacy notice says Turnstile processes signals “such as client IP address, TLS Fingerprint, User-Agent Header and Sitekey and associated origin.” On top of that, the check runs small tests inside the web view — reading browser characteristics, calling browser APIs, and asking your device to solve lightweight puzzles — which Cloudflare describes as detecting “browser-quirks and human behavior.” Cloudflare does not publish a complete list of those in-browser signals. We would rather tell you that than pretend we have the full list.
Usually you will see nothing but a brief “Verifying…” on the button. Sometimes Cloudflare decides it needs more and shows you a checkbox to tick. That is Cloudflare's decision, made on their side; we do not control when it happens.
We never see any of it. Your device sends those signals to Cloudflare directly. Cloudflare tells our server only whether the check passed. We do not store the signals, and we cannot connect them to your account.
Cloudflare says it “does not have the ability to directly identify any individuals from any of the Signals Turnstile collects, including IP addresses,” and that its business is “protecting websites, not selling ads.” Cloudflare uses these signals for two things. The first is blocking bots for us, which it does on our instructions. The second is improving Turnstile's bot detection for all of its customers — and for that one, Cloudflare says it is acting for itself, not for us. That is Cloudflare's own use of the data, not ours, and you should know it happens.
Cloudflare does not publish how long it keeps these signals. We are not going to make up a number. If Cloudflare publishes one, we will put it here.
Turnstile can set a cookie called cf_clearance, but only on sites that switch on a feature called pre-clearance. We have not switched it on.
You can read Cloudflare's own notice at cloudflare.com/turnstile-privacy-policy.
Who we share it with
We do not sell your data. We do not share it with advertisers. We share data only with the service providers we need to operate the app:
- Supabase — our backend host. Stores your account, your messages, your circle memberships, and your uploaded photos.
- Twilio — delivers your one-time SMS verification code when you sign in. Receives your phone number to deliver that text.
- Cloudflare — runs the bot check on the sign-up screen. Receives the signals described in Bot protection at sign-up from your device. Does not receive your phone number, your messages, or anything else from the app. Cloudflare also uses what it learns from these checks to improve its own bot detection.
- Anthropic — processes Dynasty Tracker photos to read the roster from the screenshot. Receives the photo and returns the extracted text data.
- Stripe — handles Premium payments. Your card and billing details go to Stripe directly through their checkout page; they never touch our servers.
- Expo — delivers push notifications, via Google and Apple's notification systems. A notification preview (the sender's name and the start of the message) passes through these services on its way to your phone.
- Resend — emails us an alert when a message is reported, so we can act on reports quickly. That email is a ping only — at most the report ID, the reason, the circle, and the display names involved. It never includes the reported message or the reporter's note; we read those in our moderation tools, behind login.
These providers are bound by their own terms. They are not permitted to use your information for their own marketing.
We do not sell, rent, or share mobile opt-in information or SMS consent data with any third parties or affiliates for their marketing or promotional purposes. No mobile information collected through SMS sign-in is shared with third parties for marketing. See our SMS Terms & Conditions for the full text-message program terms.
Your choices
- Delete your account: in the app, go to Profile → Delete account — it takes effect immediately. Your name and phone number are erased; messages you sent remain in their conversations attributed to "Deleted user." Full details (including deletion by email if you can't access the app) are on our account deletion page. We do not require a reason. A deletion request also cannot reach material the law makes us keep — see Data retention below.
- Change your display name: edit it at any time on the Profile screen.
- Stop using the app: uninstall it. If you want your stored data removed, use the in-app deletion or email contact@circlesmm.com.
Children
CirclesMM is not directed to children under 13, and we do not knowingly collect data from anyone under 13. If you believe a child has signed up, email us at contact@circlesmm.com.
Data retention
We keep your data while your account exists. When you ask us to delete it, we remove it from our active systems. Backups may retain copies for a short period before they roll off.
Our backend host keeps sign-in logs, which include your IP address, for up to 24 hours.
One exception is set by law, not by us: if content is part of a report of suspected child sexual abuse material that we file with the National Center for Missing & Exploited Children, federal law requires us to preserve it — separately from the rest of the app — for at least a year (18 U.S.C. § 2258A(h)), and longer if law enforcement asks. A deletion request cannot reach that material while the matter is open.
Security
Communications between your device and our backend are encrypted in transit using HTTPS (TLS). Data stored on our backend is encrypted at rest with AES-256, including backups. On your phone, your sign-in session is stored in the device's secure hardware-backed storage (Keychain on iOS, Keystore on Android), not in plain app data.
We do not encrypt messages end-to-end in this version of the app; that means we (and our backend provider) can technically read message contents on the server. We do not access them as a matter of practice, but you should treat the service accordingly.
Changes
If we change this policy in a meaningful way, we will update the effective date at the top of this page.
Contact
Questions, requests, or concerns: contact@circlesmm.com
SMS terms
The full terms for the CirclesMM text-message (SMS) verification program are published separately. See our SMS Terms & Conditions.