Privacy Policy
Last updated: June 13, 2026
Caught ("we", "our", "us") operates the Caught mobile application and website at appcaught.com. This Privacy Policy explains how we collect, use, and protect your information.
Disclaimer: Caught is an entertainment platform. We do not provide medical, psychological, therapeutic, or health-related services of any kind. Data collected is used solely for entertainment features and is never used for clinical, diagnostic, or treatment purposes.
1. Information We Collect
Account Data: When you create an account, we collect your display name, username, age, and optionally a profile photo.
Read Data: We store your answers, results, personality scores, and completion history to provide personalized experiences.
Usage Data: We collect anonymous usage statistics such as reads completed, time spent, and feature interactions to improve the app. We do not store the text of your answers, your read results, or any AI-generated analysis in our third-party analytics — analytics events carry only counts, identifiers, and result codes, and any personal identifiers (such as your display name) are pseudonymised (hashed) before they reach analytics.
Device Data: We may collect device type, OS version, and app version for debugging and optimization.
2. How We Use Your Information
- Provide and personalize your read experiences
- Generate AI-powered personality analyses
- Enable social features (pair checks, sharing results)
- Track streaks and achievements
- Improve our content and app experience
- Send notifications about fresh reads and activity (with your consent)
3. Data Sharing
We do not sell your personal data. We may share data with:
- AI providers (Anthropic / Claude, OpenRouter, DeepSeek) to generate read analyses. Your read answers are sent to the model, plus a minimal personalization context (first name + age) so the narrative can address you by name and stay age-appropriate. We never send your email, account ID, payment data, location, or contacts — and we never send photos except in the single consent-based case described in the next bullet. We route requests only to providers that contractually do not train models on inference traffic and that offer zero-data-retention or short-term retention for our enterprise tier; routing decisions are configured server-side and audited periodically.
- AI media generation (Vision — optional, consent-based): if you choose to generate an AI video portrait and explicitly consent on the in-app disclosure screen, the selfie you pick is sent to our media-generation provider (fal.ai) solely to render your video. The selfie is used for that one generation, is not used to train models, and the seed image is deleted from our systems once the video is delivered (or on failure). You can always decline and use the photo-free archetype mode instead — the feature works without a photo. Finished videos are stored in your account as the product you purchased.
- Infrastructure providers (Supabase, Vercel) for hosting and data storage
- Analytics tools to understand app usage patterns (anonymized)
4. Legal Basis for Processing (GDPR)
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your data under the following legal bases:
- Consent: You consent to data processing when you create an account and use Caught
- Contract: Processing is necessary to provide the service you signed up for
- Legitimate Interest: To improve our product, prevent fraud, and ensure security
5. Data Storage, Security & Retention
Your data is stored securely on Supabase (PostgreSQL) with row-level security policies. All communication is encrypted via HTTPS/TLS.
Retention periods:
- Account data: Retained while your account is active. Deleted within 30 days of account deletion.
- Read results: Retained while your account is active. Deleted with your account.
- Usage analytics: Anonymized and aggregated. Retained for up to 24 months.
- Device data: Retained for up to 12 months for debugging purposes.
Data transfers: Your data may be transferred to and processed in the United States and other regions where our infrastructure and AI providers (Supabase, Vercel, Anthropic, OpenRouter, DeepSeek upstreams) operate. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses where applicable.
6. Your Rights
All users have the following rights:
- Access: Request a copy of your data at any time
- Delete: Delete your account and all associated data
- Export: Download your read results and personality data (data portability)
- Opt-out: Disable notifications and analytics tracking
7. Additional Rights for EEA/UK Residents (GDPR)
If you are in the EEA or UK, you also have the right to:
- Rectification: Correct inaccurate personal data
- Restriction: Request we limit processing of your data
- Object: Object to processing based on legitimate interest
- Withdraw consent: Withdraw your consent at any time (this does not affect prior processing)
- Lodge a complaint: File a complaint with your local data protection authority
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
Data Controller: Caught, reachable at [email protected].
8. California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: You can request what personal information we collect, use, and disclose
- Right to Delete: You can request deletion of your personal information
- Right to Opt-Out of Sale: We do not sell your personal information. We never have and never will.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
- Right to Correct: You can request correction of inaccurate personal information
To submit a request, email [email protected] with "CCPA Request" in the subject line. We will verify your identity and respond within 45 days.
Categories of personal information collected: Identifiers (username, display name), internet activity (usage data, device data), profile information (age, answers, results). See Section 1 for full details.
9. Automated Decision-Making & Profiling (GDPR Art. 22)
Caught uses AI (large language models from Anthropic and DeepSeek, accessed via Anthropic's API or via the OpenRouter inference gateway) to analyze your answers and generate personality results. This constitutes automated profiling under GDPR.
What happens: Your read answers, first name, and age are sent to an AI model, which generates a personality analysis, result type, and compatibility data. No human reviews individual results before they are shown to you.
Impact: These results are for entertainment only. They do not affect your access to the service, pricing, or any legal rights. No decisions with legal or similarly significant effects are made based on automated processing.
Your rights: You have the right to request human review of any AI-generated result, express your point of view, and contest the output. Contact us at [email protected].
10. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms:
- We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (as required by GDPR)
- We will notify affected users without undue delay via email and/or in-app notification
- We will notify the California Attorney General if a breach affects more than 500 California residents (as required by CCPA)
- Notification will include: the nature of the breach, data affected, likely consequences, and measures taken
11. Children's Privacy
Caught is intended for users aged 13 and older. We do not knowingly collect data from children under 13. If we discover such data, we will delete it immediately. If you believe a child under 13 has provided us with personal information, please contact us at [email protected].
12. Cookies, Local Storage & Advertising
We use local storage (AsyncStorage on mobile, localStorage on web) to save your preferences, session, and progress. We do not use third-party tracking cookies.
Advertising: Free users may see ads served by Google AdMob. AdMob may collect device identifiers and usage data to serve relevant ads. On iOS, you can control ad personalization through the App Tracking Transparency prompt. On Android, you can opt out of personalized ads in your device settings. Premium subscribers see no ads.
13. Third-Party Services
Caught uses the following third-party services that may process your data:
- Supabase (database, authentication) — Privacy Policy
- Anthropic / Claude (AI analysis) — Privacy Policy
- OpenRouter (AI inference gateway) — Privacy Policy
- DeepSeek (AI model, accessed via OpenRouter) — Privacy Policy
- fal.ai (AI media generation for the optional Vision video portrait; receives your selfie only with your explicit in-app consent) — Privacy Policy
- Vercel (hosting) — Privacy Policy
- RevenueCat (payments) — Privacy Policy
- Google AdMob (advertising) — Privacy Policy
- PostHog (product analytics) — Privacy Policy. Optional anonymized session recording is OFF by default; you can opt in from Settings → Privacy. When enabled, only your in-app screens are recorded — no system-level content, no other apps. Sensitive inputs (passwords, payment details) are masked.
- Sentry (error monitoring) — Privacy Policy
- Expo (push notifications, updates) — Privacy Policy
- Apple / Google (in-app purchases) — respective privacy policies apply
14. Changes to This Policy
We may update this policy from time to time. We'll notify you of significant changes through the app or email. Continued use after changes constitutes acceptance.
15. Contact
Questions about privacy? Reach us at [email protected]