Privacy Policy
Effective Date: August 25, 2026 · Last Updated: October 6, 2026
Bunk Labs, Inc.
1. Introduction
Bunk Labs, Inc. ("we," "us," "our," or "Company") operates Trick Dash, an LGBTQ+ social and dating application. We recognize the sensitive nature of our users' data and are deeply committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, your rights, and our safeguards.
2. Information We Collect
2.1 Information You Provide
When you create an account and use the App, you may provide:
- Profile Information: Name, birth date, bio, headline, body type, ethnicity, height, weight, gender identity, relationship status, known languages, identity tags, position preferences
- Sexual Health (Optional): HIV status (Negative, Undetectable, or Positive) and prevention methods in use (Condoms, PrEP, Doxy PEP, Treatment ART). Both fields are entirely optional and may be left blank. When provided, the values are encrypted at rest with AES-256-GCM using a key held only by our backend, and they are returned only as part of the profile view you choose to make visible to other users. You can clear or change these fields at any time in the profile editor.
- Photos: Profile photos, album photos, Flashes
- Messages and Communications: Text messages, location shares, photos, albums sent through the App
- Events and Groups: Events you create, groups you join, shouts you post
- Optional Email: If you provide an email for account recovery, we hash it with SHA-256
- Sign in with Apple or Google: This is optional. We keep only the provider name and a one way keyed hash of the provider's user id, so you can sign in again. We do not store the email address or name either provider knows.
2.2 Information Collected Automatically
The App automatically collects:
- Device Information: Device type, OS version, browser type, unique device identifiers
- Location: GPS coordinates with intentional jitter applied before storage. You choose the privacy bucket in Settings (25, 100, or 300 meters; default is 25). Other users only see fuzzy distance buckets, never your raw coordinates.
- Usage Data: Features accessed, time spent, swipe patterns, conversation data
- IP Address: Used for rate limiting and abuse prevention; not stored long-term
- Push Notification Tokens: To send Web Push notifications
2.3 Information We Do NOT Collect
- Email addresses stored in plain text (optional recovery email is stored only as a SHA-256 hash)
- We never store, log or share email addresses or names from Apple or Google. Apple's signed sign in token can include an email address. We read it only in memory to verify the token and then discard it.
- Advertising identifiers on iPhone: AppsFlyer Strict does not collect the advertising identifier (IDFA), and vendor identifier (IDFV) collection is disabled. On Android, AppsFlyer reads the Google advertising ID for install measurement, as described in §4.8.7. The app shows no third party ad network ads.
- Facial recognition data or biometric information stored on our servers (optional age verification is processed by Didit; see §4.8)
- Payment card information (handled by third-party processors)
- Medical records, lab results, formal diagnoses, or any health information beyond the optional Sexual Health profile fields described in §2.1 and the general body metrics in your profile
To be precise about analytics: the Trick Dash app itself does not load Google Analytics. The installed app includes AppsFlyer for install measurement and fraud detection, as described in §4.8.7. Our marketing website at trickdash.com and our public events directory at trickdash.com/events do use Google Analytics 4 to count visits. What that measures, how long it is kept, and how to switch it off is set out in §5.
3. How We Use Your Information
- Core Features: Matching, profiles, messaging, event discovery, groups
- Safety and Moderation: Abuse detection, content moderation, fraud prevention, law enforcement cooperation
- Improvement: Aggregate analytics (anonymous, non-identifying) to improve the App
- Legal: Compliance with legal obligations, court orders, and safety concerns
4. Storage and Protection
4.1 Infrastructure
- Database: Neon Postgres (AWS us-east-1, Postgres 17) with encryption at rest
- Storage: Cloudflare R2 for photos and Flashes
- Transmission: All data encrypted in transit with TLS 1.3
- Connection Pooling: Cloudflare Hyperdrive for secure edge connection pooling; caching intentionally disabled for real-time messaging accuracy
- Photo URLs: Signed with HMAC-SHA256, valid for 1 hour
4.2 Location Privacy
We do not store or share your precise GPS coordinates with other users. Instead:
- Your location is intentionally jittered deterministically before it is written to the database. You pick the privacy bucket in Settings: 25 meters (default), 100 meters, or 300 meters. The actual offset applied is randomized within the bucket you select (10 to 25 meters for the 25 bucket, 50 to 100 meters for the 100 bucket, 200 to 300 meters for the 300 bucket).
- Users see fuzzy distance buckets ("Steps Away," "< 1 km," "3 km") instead of exact distances
- Roam locations (when exploring a different city) are temporary and expire after 3 hours
- Nearby search uses PostGIS geographic queries for privacy-preserving radius filtering
4.3 Message Retention
Our servers hold a message only long enough to deliver it. A message is kept for up to 30 days and is then permanently deleted from both our database and our storage, along with any photos attached to it. Deleted messages cannot be recovered and we do not keep backups of them. Cleanup runs when a conversation is opened and again in a nightly sweep, so messages in conversations nobody has opened are removed on the same schedule. The 30 days is the same for everyone and is not something you or the person you are talking to can change. Your own device keeps your copy of the conversation, so your history stays readable there after our copy is gone.
There is one exception. When an account is banned as a bot or for spam, we keep the messages that account sent, with no time limit. We use them to recognise the same abuse when it returns and to tune and test our spam and bot detection. We do not use them to train AI models. We never keep the replies of the people it wrote to past the normal 30 days.
4.4 Photo Metadata
Photos uploaded to Trick Dash (profile photos, album photos, Flashes, and chat photos) are stripped of EXIF metadata before transmission to our servers. EXIF data on phone photos commonly includes precise GPS coordinates (often the user's home address), camera model and serial number, and capture timestamp. We re-encode every uploaded image client-side via canvas to produce a fresh JPEG with no metadata, ensuring this information is never transmitted to us or to other users.
4.5 Vanity Usernames
You may optionally choose a vanity username (e.g., trickdash.com/@yourname) to share your profile.Vanity usernames are public identifiers by design. Anyone with the URL can view the corresponding profile.
4.6 Account Inactivity
If you stop using Trick Dash, we wind your account down automatically. If you signed up on the web and never shared a location, your profile may be hidden from the map and from search after about two weeks without activity. For everyone, after about two months of inactivity your profile is hidden from the map and from search, while your data is kept in case you return. After about six months of inactivity your account and all associated data are permanently deleted from our database and storage and cannot be recovered. Simply opening the app resets the clock. You can also delete your account at any time from Settings or at trickdash.com/delete.
4.6a Automatic Safety Actions and Abusive Accounts
To keep the community safe, Trick Dash automatically contains accounts whose activity matches patterns we associate with bots or spam. A contained account is hidden from other members or is asked to complete a quick face check before messaging can continue, and stronger cases are suspended. Every automatic action is recorded, and every one can be appealed: pass the face check shown in the app, or contact support and a human will review the decision and restore the account if it was made in error.
An account that stays contained for 30 days without a successful appeal or a passed face check, and that shows no signs of genuine human use, may be permanently deleted along with all associated data, and the deletion cannot be undone. An appeal or a face check that succeeds at any point before deletion stops it entirely. Accounts that are simply inactive are never deleted on this schedule: ordinary inactivity follows the wind down described in Section 4.6.
4.7 Authentication Audit Log
Authentication events (successful logins, failed login attempts, passkey registration and revocation, and recovery code use) are recorded in an append-only audit log with the request IP and user agent. The log is retained for 12 months for security investigation, abuse detection, and SOC 2 audit-readiness purposes. The log cannot be edited or deleted by application code; integrity is enforced at the database layer.
4.8 Automated Processing and Third Parties
Several Trick Dash features rely on automated systems or third party processors. This section names the external services that process user content or app measurement data and explains what they receive and how they are used.
4.8.1 Chat Translation (powered by an AI language model)
The translate button on profiles, chats, shouts, and groups uses Cloudflare Workers AI running the @cf/google/gemma-4-26b-a4b-it open-source language model. When you tap translate, the source message text is sent to Cloudflare Workers AI; the translated text is returned and shown only to you (it is not stored as a separate message). Cloudflare processes the request entirely on Cloudflare's infrastructure under our existing Data Processing Agreement; no external LLM provider (OpenAI, Google, Anthropic, etc.) receives the message. Translation is optional and on-demand. Untranslated messages never pass through the model. Workers AI does not retain prompts or responses beyond the request lifecycle per Cloudflare's published policy.
4.8.2 Photo Moderation (Sightengine)
Every profile photo, album photo, and chat photo uploaded to Trick Dash is sent to Sightengine for automated moderation analysis (nudity classification, weapon detection, hate symbol detection, minor likeness detection). Photos are also checked automatically for signs of having been generated by artificial intelligence rather than taken with a camera. Sightengine returns a numeric score per category; we store the scores alongside the photo record and use them to flag the photo for human review or auto-block it. Sightengine processes the image and returns the result within seconds; per their DPA they do not retain the image beyond the processing window. Sightengine is a subprocessor under our Data Processing Agreements and is bound by applicable privacy commitments. You cannot opt out of moderation while using Trick Dash because moderation is a safety-essential feature, but you can decline to upload photos.
4.8.3 Age Verification (Didit, optional)
If you opt into biometric age verification, Didit (operated by Didit GmbH) processes your government ID photo and a live selfie to confirm you are 18 or older. Didit returns only a verified/not-verified verdict and an estimated age range; we never receive, see, or store the underlying biometric template, the ID image, or the selfie. Didit retains its processing artifacts per its own privacy policy and applicable regulation. Age verification is optional in most places; users may instead rely on self-attestation at signup, and declining does not restrict access to the app's core features. In jurisdictions whose laws require age or identity verification for apps like ours (for example Arkansas under Act 612), completing verification through Didit is required before the app can be used there, and the verification method offered follows the standard the local law requires, up to a government ID check with a matching live selfie. In every case we receive only the pass or fail outcome.
4.8.3a Spam Verification (Didit)
If account activity matches patterns we associate with spam, such as sending obfuscated links or messaging many people in a short burst, we may ask for a quick face check through Didit before messaging can continue. The check confirms a live, real person. As with age verification, Didit processes the selfie and we receive only the pass or fail result; we never receive, see, or store the photo or any biometric data. An account owner who believes the check was triggered in error can contact support and a human will review it.
4.8.3b AI Generated Content and Automated Processing
Some of what you read on our public pages, and some of the checks that run in the background, are produced by artificial intelligence models rather than by a person. Here is the full list, what each one reads, and what it produces:
- Public event descriptions and city overviews. The event listings on trickdash.com/events, and the "What's happening" paragraph on each city page, are composed by an AI language model (Cloudflare Workers AI, running an open model from the Google Gemma family) from public listing data: the title, date, venue, price, and the description published by the venue, promoter, or listing site. The model never reads user profiles, messages, or photos. Events submitted by a user are published in the user's own words and are not rewritten.
- Flyer text extraction. Many events are announced only as a picture of a poster. When a venue, an organizer, an administrator, or a user submits such an image to the events directory, a vision model reads the text printed on it so that the title, date, and venue can be captured. Only the flyer image is read, and only to build the listing. Every listing created this way is held for human review before it is published.
- Event classification and quality review. Automated systems sort listings into categories such as nightlife, drag, shows, community, and sports, and screen listings from untrusted sources for spam and for content that does not belong on the directory.
- Translation of what other people write. Messages, profiles, shouts, and group posts are translated by an AI language model at the moment you tap translate, and the result is shown only to you. Described in full in §4.8.1.
- Translation of our own interface text. The buttons, labels, and notices we write are a separate case. They are translated ahead of time by an AI language model, reviewed before a release, and shipped inside the app as a fixed set of phrases. Nothing you write is involved, no text leaves your device for this, and no model runs while you read the interface.
- Profile text screening. As described in §4.8.5.
- Photo moderation. As described in §4.8.2.
- Age verification and spam verification. As described in §4.8.3 and §4.8.3a.
Two commitments go with this:
- It can be wrong. AI generated text may contain errors, may be out of date, and is not a promise that an event will happen as listed. Please confirm with the venue or the organizer before you travel. Report an error to [email protected] and we will correct or remove it.
- Your data is not training data. No user personal data, message, photo, or profile is used to train any AI model, ours or anyone else's.
Automated decisions that materially affect you have a human review path. If an age check does not pass, if a hold is placed on your messaging by our spam checks, if a profile text edit is declined or messaging is limited by profile text screening, or if a photo is rejected by moderation, write to [email protected] and a person will review the decision. No account is permanently closed by an automated system without that review being available to you.
4.8.4 Automated Safety Scoring (internal)
Independent of Sightengine, every account carries an internal trust score derived from account age, verification status, report-free streak, and moderation history. This scoring runs on our own infrastructure and is not sent to any third party. The score influences how aggressively automated safety actions are applied (e.g., a brand-new account hits stricter rate limits than an established one). Users may request their current trust score via a Data Subject Access Request (§7).
4.8.5 Profile Text Screening
Profile text screening. When you save your name, headline or bio, an automated check on our own servers looks for commercial solicitation and for phone numbers or messaging handles written in disguised form. This check does not use an AI model and does not send your text to any third party. A match is recorded in our moderation log with the category of the match. If enforcement is switched on, a matching edit is declined and messaging may be limited until the text is corrected or a person on our team clears it. A short sample of the headline and bio may also be scored by an AI language model running on Cloudflare Workers AI, the same service described in section 4.8.1. That score is used only to review the quality of the automated check and is never shown to other users. Write to [email protected] to have any restriction reviewed by a person.
4.8.5a Safety Review of First Messages
Safety review of first messages. When an account trips a safety alarm, for example several refused first messages or a report, an automated system reads that account's recent first messages to people it has not spoken with before, together with its headline and bio, and assigns a category such as spam or harassment. This runs on Cloudflare Workers AI. To check that the system is accurate, the owner of Trick Dash and an AI assistant working for the owner (Claude, by Anthropic) may read samples of those first messages.
4.8.6 Sign in with Apple or Google (optional)
If you choose Apple or Google, we send a sign in request to that provider. It returns a signed token with a stable user id. We retain only the provider name and a one way keyed hash of that user id as your sign in identity. A short lived record of the token's fingerprint is kept only to stop the same sign in being replayed. We never store email addresses or names from either provider. An email address may appear briefly in the signed token while we verify it. We discard it without storing or logging it, and we do not return it from our servers to the app or send it to any other service. We do not use it for account matching, recovery or contact.
Google sign in, and Apple sign in on Android, use the system browser sheet, and Google sign in requests only the openid scope. On iPhone, Sign in with Apple uses the built in Apple sheet and requests no name or email scopes. Passkeys and recovery codes remain available. You can delete your account at any time, which removes the stored provider id. You can also revoke Trick Dash in your Apple account settings under Sign in with Apple, or in your Google account settings under connections to third party apps and services. Revoking access at Apple or Google does not delete your Trick Dash account; use Delete account in the app.
4.8.7 Install Measurement (AppsFlyer)
We use AppsFlyer to measure which campaign or link led to an app install and to detect fraudulent installs. AppsFlyer processes this information on our behalf as a service provider.
On iPhone, we use AppsFlyer Strict. There is no App Tracking Transparency prompt, no advertising identifier (IDFA) collection, and vendor identifier (IDFV) collection is disabled. Campaign attribution uses Apple's aggregate SKAdNetwork reports and, for installs that come from Apple Search Ads, Apple's AdServices attribution token. This integration does not track you across apps.
On Android, AppsFlyer reads the Google advertising ID and install referrer data available to the app, which includes the Google Play install referrer and, where present, Meta's install referrer (when Facebook or Instagram is installed) and Samsung's preload referrer. The referrer can contain campaign information and, for a valid invitation, an encrypted single use invitation proof that only our own servers can resolve. It does not contain your handle or an invite or deep link URL.
On both platforms, AppsFlyer receives technical information from its software, including your network address, from which a general region can be derived, device model, operating system and app version, and install and session start times. The only app event we send is a registration completed event when a new account is created, with no additional details attached.
We never send AppsFlyer your account identifier, handle, profile data, photos, messages, location, invite or deep link URLs, or health or sensitive profile fields. A general region derived from your network address is separate from the location you share with Trick Dash.
On Android, you can limit use of the advertising ID by deleting or resetting it in Android settings. This control applies to the advertising ID; it does not stop install referrer or other technical information from being sent. AppsFlyer explains its handling of this information in its Services Privacy Policy.
4.9 Screenshot Protection on Sensitive Surfaces
In the installed Android app, Trick Dash asks the operating system to shield certain screens from capture: any open conversation, your private albums, and albums you have received. While one of these screens is open, Android prevents the content from being screenshotted, screen recorded, or shown in the recent apps preview. Because this also prevents screenshotting the text of a chat, we give you a copy option instead: press and hold any message to copy it, or use Copy conversation in the chat menu to copy the whole thread.
On Apple devices and when you use Trick Dash in a web browser, this capture blocking is not available: Apple does not provide a way for apps to block screenshots, and browsers give apps no control over screen capture. On those platforms, please assume that anything shown on your screen can be captured. And on every platform, no app can stop someone from photographing their screen with a separate device. For all of these reasons, treat screenshot protection as a deterrent, not a guarantee, and only share content with people you trust.
5. Website Analytics (Google Analytics)
Our marketing website at trickdash.com, including the language versions of the home page, and our public events directory at trickdash.com/events use Google Analytics 4, a measurement service provided by Google LLC. The Trick Dash app does not load Google Analytics. Signing in, browsing profiles, and messaging happen entirely outside this measurement.
- What it measures: page views, which page you arrived from, the general country and city that Google derives from your network address, approximate device and browser type, clicks on links that leave our site, and clicks on the App Store and Google Play buttons.
- Address handling: Google states that Google Analytics 4 does not log or store full network addresses. Address truncation, often called IP anonymization, is applied by default in this version of the product.
- Cookies: the measurement sets cookies named _ga and _ga_ followed by a property identifier in your browser. They contain a random number that lets Google count a repeat visit as one visitor rather than two.
- How long it is kept: event and user level data is retained for 14 months, then deleted automatically by Google. Aggregate reports may be kept longer.
- What we never do with it: we do not use it for advertising, remarketing, audience selling, or cross site tracking. Measurement data is never joined to your Trick Dash account, because the website has no way of knowing who you are.
How to switch it off. You can install Google's own opt out add on for your browser at tools.google.com/dlpage/gaoptout, or block cookies for trickdash.com in your browser settings, or use a browser or extension that blocks analytics scripts. Blocking it changes nothing about how the website or the app works for you. Google explains its own handling of this data at policies.google.com/privacy.
If you are in the European Economic Area, the United Kingdom, or Quebec. We rely on our legitimate interest in understanding how many people visit our marketing pages and which pages are useful, under Article 6(1)(f) of the GDPR. Under Quebec Law 25 this is measurement of use, not profiling: it is not used to build a profile of you, to target advertising, or to make any decision about you, and it never touches the app itself. You may object at any time by using any of the methods above or by writing to [email protected].
6. Information Sharing
We do not sell user data to advertisers. Information is shared only in these cases:
- Other Users: Your public profile, messages, photos, and activity (as core App functionality)
- Service Providers: Cloudflare (infrastructure and Workers AI), Neon (database), Resend (transactional email), Sightengine (photo moderation), Didit (optional age verification), Google LLC (Google Analytics on our marketing website and public events directory only, never in the app; see §5), and payment processors. These providers operate under Data Processing Agreements. AppsFlyer also processes install measurement and fraud detection data on our behalf (see §4.8.7). See §4.8 for what data each receives and how it is processed.
- Sign in providers: If you choose Apple or Google sign in, that provider handles your sign in under its own privacy policy. See §4.8.6.
- Legal Obligations: Valid subpoenas, court orders, or warrants from law enforcement
- Safety: If we believe disclosure is necessary to prevent imminent harm, illegal activity, or violate others' rights
7. Your Rights
7.1 All Users
- Access: Request a copy of your data
- Correction: Correct inaccurate information
- Deletion: Delete your account and all associated data (cascade delete)
- Export: Download your data in machine-readable format
7.2 European Union (GDPR)
If you are in the EEA, you have additional rights:
- Right to Access (Art. 15)
- Right to Rectification (Art. 16)
- Right to Erasure (Art. 17)
- Right to Restrict Processing (Art. 18)
- Right to Data Portability (Art. 20)
- Right to Object (Art. 21)
- Right to Withdraw Consent (Art. 7)
- Right to Lodge a Complaint with Your Data Protection Authority
Legal Basis: We process data based on contract (core features), legitimate interests (fraud prevention, safety), and consent (optional features).
7.3 California (CCPA)
If you are a California resident, you have rights under the California Consumer Privacy Act:
- Right to Know what personal information is collected
- Right to Delete personal information
- Right to Opt-Out of selling or sharing information (we do not sell)
- Right to Non-Discrimination for exercising CCPA rights
8. Children's Privacy
The App is intended for users 18 and older. We do not knowingly collect data from children under 18. If we discover a user is under 18, we immediately terminate the account and delete all associated data. If you are aware of a minor using the App, please report to [email protected] immediately.
9. International Data Transfers
Your data is processed and stored in the United States (AWS us-east-1). If you are outside the United States, your data will be transferred to the U.S. for processing. We comply with GDPR and other laws through Standard Contractual Clauses where applicable.
10. Data Breach Notification
In the unlikely event of a data breach, we will notify affected users within 72 hours and notify relevant data protection authorities as required by law. Notifications will include details of the breach, affected data, and recommended actions.
11. Changes to This Policy
We may update this Privacy Policy at any time. Material changes will be notified through the App or email. Your continued use after notification constitutes acceptance of updated terms.
12. Contact
For privacy questions, data subject requests, or concerns:
Privacy Contact: [email protected]
Data Protection Officer: [email protected]
Mailing Address: Bunk Labs, Inc., 111B S Governors Ave, #81507, Dover, DE 19904, United States
For copyright complaints, our designated agent under the Digital Millennium Copyright Act is Dean Malka at [email protected], reachable at the mailing address above and by phone at +1 917 277 3222. The full notice and counter notice procedure is in our Copyright and DMCA policy.