dear bestie

Privacy Policy

Dear Bestie LLC

Effective Date: May 12, 2026
Last Updated: July 25, 2026

1. Introduction

Dear Bestie LLC ("Dear Bestie," "we," "us," or "our") respects your privacy. This Privacy Policy describes how we collect, use, share and protect information about you when you use the Dear Bestie mobile application, website at dearbestie.app and related services (collectively, the "Service").

By using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, do not use the Service.

This Privacy Policy is incorporated into and forms part of our Terms of Service.

2. About Dear Bestie

Dear Bestie is the friendship app built specifically for women, including transgender and non-binary women. We believe women's friendships matter and we are committed to protecting your data with the same care that we put into building this community.

3. Information We Collect

3.1 Information You Provide

Account information.

When you sign up, we collect your name, email address, password (encrypted) and date of birth.

Identity verification.

To confirm your eligibility to use the Service, we require identity verification through our verification partner, Didit. As part of this process, we (and Didit) collect:

  • An image of your government-issued identification document (driver's license, passport or state ID)
  • A real-time selfie photograph for biometric matching against your ID
  • Information extracted from the ID document, including name, date of birth, gender marker, document number and document expiration

Profile information.

You may provide additional information for your profile, including profile photos, bio, vibes, interests, employment, education, location preferences and other details you choose to share.

User content.

Messages, posts, comments, event attendance and other content you create or share through the Service.

Communications.

Information you provide when you contact us, including support requests, feedback and other communications.

3.2 Information We Collect Automatically

Device and technical information.

Device type, operating system version, mobile device identifier (such as Apple's IDFV), app version and language settings.

Location data.

With your permission, we collect approximate location at the city or neighborhood level. We use location data for two purposes:

  • A "primary city" you select, which is sticky and used to surface relevant friends and events;
  • Approximate travel location to power travel-mode features that show you friends and events near where you are.

We do not share your exact location or precise GPS coordinates with other users or third parties. Distance-based features rely on coarse, city-level location only.

You can revoke location permission at any time through your device's settings. Without location permission, certain features will not be available.

Analytics.

We use Firebase Analytics, a service provided by Google, to understand aggregate user engagement with the Service. Firebase Analytics collects information including app instance identifiers, app version, device type and event data (such as which features you use). This information is tied to a pseudonymous identifier and is used solely to improve the Service. Learn more in Google's privacy policy at policies.google.com/privacy.

3.3 Information from Third Parties

Verification partner.

Didit provides us with the results of identity verification, including a pass/fail signal and the underlying identity attributes from the verification process.

Authentication providers.

If you choose to sign in using Apple Sign In or Google Sign-In, we receive basic profile information (such as your name and email address) from those providers in accordance with their respective privacy policies.

Service providers.

Push notification services, analytics tools and other vendors may provide information related to your use of the Service.

4. How We Use Information

We use the information we collect to:

  1. Provide, operate and maintain the Service;
  2. Verify your identity and confirm your eligibility for the Service;
  3. Match you with other users based on your preferences and location;
  4. Personalize your experience, including event recommendations and friend suggestions;
  5. Communicate with you, including responding to your requests, sending notifications and providing customer support;
  6. Send service-related communications, including updates, announcements and security alerts;
  7. Send marketing communications you have opted into (you may opt out at any time);
  8. Detect, prevent and respond to fraud, abuse, harassment and security incidents;
  9. Enforce our Terms of Service and community guidelines;
  10. Comply with legal obligations and respond to lawful requests from law enforcement;
  11. Conduct internal analytics, research and development;
  12. Backup and recover data;
  13. As otherwise described to you at the point of collection or with your consent.

5. Identity Verification: Special Provisions

Identity verification involves sensitive personal information. We treat this data with extra care.

5.1 What Verification Data We Collect

As described in Section 3.1, our verification partner Didit collects:

  • An image of your government ID
  • A real-time selfie for biometric matching
  • Identity attributes extracted from the ID

5.2 How We Use Verification Data

Verification data is used solely to:

  • Confirm your identity and eligibility for the Service;
  • Detect and prevent fraud, including duplicate accounts and impersonation;
  • Comply with legal obligations.

5.3 Verification Data Retention

Dear Bestie does not retain copies of your government ID image or your selfie. After Didit completes verification, Dear Bestie retains only:

  • A pass/fail verification status;
  • A hashed identifier linking your account to a successful verification event;
  • The information necessary for fraud prevention, audit and legal compliance.

Didit, our verification partner, retains verification data in accordance with their own privacy policy and applicable data protection law. We encourage you to review Didit's privacy policy at didit.me/privacy to understand their independent data practices, including their retention periods.

5.4 Trans Women and Manual Review

Dear Bestie welcomes all women, including transgender and non-binary women. Our identity verification process exists to confirm membership in our women's community. If our automated verification doesn't reflect your identity, we offer a manual review process. Reach out to hello@dearbestie.app and we'll review additional documentation to confirm your account.

Documentation we may accept for manual review includes:

  • A name change court order
  • An updated state ID showing your gender marker
  • A letter from a healthcare provider confirming your identity
  • Other reasonable documentation

We treat all manual review information confidentially. Manual review information is used solely to confirm eligibility and is retained only as long as needed for verification, audit and legal purposes.

5.5 Your Rights Regarding Verification Data

You may request access to, correction of or deletion of your verification data by contacting hello@dearbestie.app, subject to legal limitations and our retention obligations.

6. How We Share Information

We do not sell your personal information.

6.1 With Other Users

When you use the Service, certain profile information is visible to other users in our community, including your first name, age, profile photos, bio, vibes, interests and approximate city. You control much of this through your profile settings and visibility controls.

We never share your exact location or precise GPS coordinates with other users. Distance-based features use only approximate city or neighborhood-level information.

Messages you send to other users are visible to those users. Posts you make in circles or events are visible to other members of those groups.

6.2 With Service Providers

We share information with third-party service providers who help us operate the Service, subject to confidentiality and data protection obligations:

  • Didit (identity verification)
  • Firebase / Google Cloud Platform (hosting, authentication, push notifications, analytics)
  • Hostinger (transactional email delivery)
  • Apple App Store / Google Play Store (app distribution and in-app purchases)

These providers process your information only as necessary to provide their services to us and are bound by privacy and security obligations consistent with this Privacy Policy.

6.3 For Legal Reasons

We may share information when we believe in good faith that disclosure is necessary to:

  1. Comply with applicable law, regulation, court order, subpoena or other legal process;
  2. Protect the safety of any person, including users and third parties;
  3. Protect the rights, property or safety of Dear Bestie LLC, our users or others;
  4. Detect, prevent or address fraud, security or technical issues;
  5. Cooperate with law enforcement when we believe such cooperation is required by law.

6.4 Business Transfers

If Dear Bestie LLC is involved in a merger, acquisition, financing, sale of assets, bankruptcy or similar transaction, your information may be transferred as part of that transaction. We will notify you of any change in ownership or control.

6.5 With Your Consent

We may share information for any other purpose with your consent.

7. Data Retention

We retain personal information only as long as necessary to provide the Service and fulfill the purposes described in this Privacy Policy, unless a longer retention period is required by law.

  • Account information: Retained for the life of your account. Deleted within thirty (30) days of account deletion request, except as required for legal, audit or backup purposes.
  • Verification data: As described in Section 5.3.
  • Messages and user content: Retained for the life of your account. May persist after deletion in messages you sent to others (because the recipient still has a copy) and in our backups for a reasonable period.
  • Backups: Standard backup retention is approximately ninety (90) days.
  • Logs and analytics: Aggregated, non-identifying analytics may be retained indefinitely. Identifying logs are retained for up to twelve (12) months unless required for security or legal reasons.

8. Your Rights and Choices

8.1 Account Access and Updates

You can review and update much of your information directly in the app's profile settings.

8.2 Marketing Communications

You may opt out of marketing communications at any time by following the unsubscribe link in any marketing email or by contacting hello@dearbestie.app.

8.3 Push Notifications

You may turn off push notifications through your device settings or in-app settings.

8.4 Location

You may revoke location permission at any time through your device settings. Without location permission, certain features will not be available.

8.5 Account Deletion

You may delete your account at any time through in-app settings or by contacting hello@dearbestie.app. Account deletion will:

  • Remove your profile from the Service;
  • Delete your messages, posts and content (subject to backup retention and content shared with other users that we cannot recall);
  • Retain limited information as required for legal, audit, fraud prevention and backup purposes.

8.6 United States State Privacy Rights

Depending on the U.S. state you live in, you may have specific rights over your personal information. Dear Bestie extends the core rights below to residents of every U.S. state that grants them, including California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island and others as their laws take effect.

Your rights may include:

  • The right to know and access the personal information we hold about you;
  • The right to correct inaccurate personal information;
  • The right to delete personal information we collected from you;
  • The right to data portability (a copy in a usable format);
  • The right to opt out of the "sale" or "sharing" of personal information and of targeted advertising. Note that Dear Bestie does not sell your personal information or use it for cross-context behavioral advertising;
  • The right to opt out of profiling that produces legal or similarly significant effects. Dear Bestie does not engage in this kind of profiling;
  • The right to limit the use of sensitive personal information, including your verification and biometric data;
  • The right to be free from discrimination for exercising any of these rights;
  • The right to appeal a decision we make about your request.

Sensitive data. Some state laws treat verification/biometric data, precise location and similar categories as "sensitive." We process sensitive data only for the limited purposes described in this Policy and, where required, with your consent.

Global Privacy Control. Where required by law, we honor recognized universal opt-out signals, such as the Global Privacy Control (GPC), as a valid request to opt out of sale/sharing and targeted advertising for the browser or device sending the signal.

How to exercise your rights. Email hello@dearbestie.app or use the controls in the app. We will verify your identity before acting on a request and will respond within the time required by your state's law. You may use an authorized agent to submit a request on your behalf where the law permits; we may require proof of the agent's authority.

Appeals. If we decline your request, you may appeal by replying to our decision or emailing hello@dearbestie.app with "Appeal" in the subject line. If we deny your appeal and you believe it was wrongly denied, you may contact your state Attorney General.

8.7 European Economic Area, United Kingdom and Switzerland Residents (GDPR)

If you are in the EEA, UK or Switzerland, you have additional rights under the General Data Protection Regulation:

  • Right of access to your personal data;
  • Right to rectification of inaccurate data;
  • Right to erasure ("right to be forgotten");
  • Right to restrict processing;
  • Right to data portability;
  • Right to object to processing based on legitimate interests;
  • Right to withdraw consent at any time;
  • Right to lodge a complaint with your local data protection authority.

The legal bases for our processing include: performance of a contract (Service), consent (marketing, location), legitimate interests (security, fraud prevention, analytics) and compliance with legal obligations.

To exercise these rights, contact hello@dearbestie.app.

8.8 Consumer Health Data (Washington "My Health My Data" and Nevada)

If you are a Washington or Nevada resident, certain information we process may be treated as "consumer health data" under those states' laws, including your biometric verification data. We want to be clear about how we handle it:

  • We collect this data only to verify identity and eligibility and to keep our community safe. Never to infer or market anything about your health.
  • We do not sell consumer health data, and we will not share it except with our verification partner to perform verification, with your consent, or as required by law.
  • With limited exceptions, we collect and share consumer health data only with your consent, which you provide during verification (see our Biometric Data Notice).
  • You may request access to, or deletion of, your consumer health data, and you may withdraw consent, by emailing hello@dearbestie.app. Withdrawing consent does not affect processing that already occurred and may mean you can no longer use the Service, which requires verification.

9. Subscriptions and Payments

Dear Bestie offers an optional auto-renewing subscription, "Dear Bestie Premium." Payment is processed by Apple through your App Store account. We do not collect or store your payment card information. Apple processes your payment data in accordance with its own privacy policy.

You can manage or cancel your subscription at any time through your device's Settings > Apple ID > Subscriptions. Subscription fees are non-refundable except as required by applicable law or as offered under Apple's refund policies.

For full subscription terms, see Section 12 of our Terms of Service.

10. Children's Privacy

The Service is not intended for individuals under 18. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected information from someone under 18, we will delete it promptly. If you believe a minor has provided us with personal information, contact hello@dearbestie.app.

11. Security

We implement administrative, technical and physical safeguards designed to protect your personal information, including:

  • Encryption of data in transit (TLS) and at rest;
  • Access controls and authentication;
  • Identity verification through Didit to prevent fake accounts;
  • Regular security review and audits;
  • Storage rules limiting who can read or write data;
  • Industry-standard cloud infrastructure (Firebase / Google Cloud Platform).

However, no security measures are perfect. We cannot guarantee absolute security. You are responsible for protecting your account credentials and for the security of devices you use to access the Service.

If we become aware of a security incident affecting your personal information, we will notify you and applicable regulators as required by law.

12. Cookies and Similar Technologies

The Service uses cookies and similar technologies (such as web beacons, pixels, local storage and SDKs) to:

  • Authenticate you;
  • Remember your preferences;
  • Understand and analyze how you use the Service;
  • Improve the Service.

Most browsers and mobile devices allow you to control cookies and similar technologies through their settings. Note that disabling these may affect functionality.

13. Third-Party Links and Services

The Service may contain links to third-party websites or integrate with third-party services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any information.

14. International Data Transfers

Dear Bestie is based in the United States. If you access the Service from outside the United States, your information will be transferred to, stored and processed in the United States. By using the Service, you consent to this transfer.

For users in the EEA, UK or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses for international data transfers.

15. Do Not Track

Some browsers offer a "Do Not Track" signal. Our Service does not currently respond to these signals due to the lack of an industry standard.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the Service and update the "Last Updated" date. Your continued use of the Service after the updated Privacy Policy takes effect constitutes acceptance of the changes.

17. Contact

For questions, concerns or requests regarding this Privacy Policy or your personal information, contact:

Dear Bestie LLC

Attn: Privacy Officer

777 Brickell Ave Suite 500

Miami, FL 33131

Email: hello@dearbestie.app

For DMCA copyright matters, please contact our Designated Agent as described in our Terms of Service (DMCA Agent ID: DMCA-1072533).

By using Dear Bestie, you acknowledge that you have read and understood this Privacy Policy.