Privacy Policy
Last updated: 8 September 2026
Leer esta política en español →
This policy explains how Bluprox processes your personal data when you use the app and this website, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD). Bluprox is a proximity-based connections app: using Bluetooth, it detects other users who are physically near you at a given moment, to enable real connections outside the app. It has no in-app messaging and no advertising.
1. Data controller and contact
The controller of the personal data collected through the Bluprox app and this website is:
- Controller: Alberto Flores Quintanilla (natural person).
- Contact email: support@bluproxapp.com
- Alternative address: soporte@bluproxapp.es
You can use either address for any question about the processing of your data or to exercise your rights (section 8). Bluprox has not appointed a Data Protection Officer; requests are handled directly by the controller.
2. What data we process, why, and on what legal basis
We apply data minimisation: we only process what is necessary to provide the service. Each processing activity is detailed below.
2.1 Account data
- Email address: identifies your account and lets you sign in and recover it.
- Password: never stored in clear text; we store only its cryptographic hash (bcrypt). We cannot know your password.
- Email verification: we send a temporary code to confirm the email is yours. Unverified accounts are automatically deleted after a set period.
Legal basis: performance of the contract (Art. 6(1)(b) GDPR).
2.2 Profile data
- Name and date of birth: provided at sign-up. They cannot be edited manually in the app once your account exists; they can only be updated through the optional NFC ID verification (section 2.9). The date of birth is also used to confirm you are over 18.
- Base gender (mandatory): Man, Woman or Non-binary. This is the only value we use for matching (who you see and who sees you). You can choose whether it is visible on your profile.
- Profile photos: the images you upload. They are automatically screened before publication to check they meet our content rules (section 2.7).
- Bio (optional): free text you choose to show.
Legal basis: performance of the contract (Art. 6(1)(b)); for age checking, legal obligation (Art. 6(1)(c)) and legitimate interest in preventing access by minors (Art. 6(1)(f)).
2.3 Special categories of data (Art. 9 GDPR): sexual orientation and gender identity
- Gender identities (optional, you may add several) and sexual orientations (optional, you may add several) are data you choose to provide or not. You can leave them blank, and you can show or hide them on your profile at any time.
- These data are not used for matching: they are profile information, not a filter. Matching relies solely on base gender and your preference about who you want to meet.
- Their visibility is opt-in: even once filled in, they stay hidden by default. Each has its own privacy toggle, switched off to begin with, and until you turn it on these data are not shown to other people.
- You can clear or hide them at any time from your profile, without affecting the rest of the service.
How your decision is captured today: when you sign up you accept this privacy policy and the terms of use via a checkbox. For these specific fields there is no separate consent checkbox yet: the processing rests on the voluntary, informed act of filling them in — they are optional, empty to begin with, and their visibility is off by default. A specific, separately recorded consent for these categories is planned for launch.
This section describes how the app currently works and is pending legal review before the commercial launch. If you do not want us to process these data, leave the fields empty: the app works normally without them.
2.4 Location
- Your GPS location is taken only occasionally, when you tap to confirm attendance (check-in) at an event, to validate that you are at the event venue.
- Ordinary proximity detection does not use GPS: it relies on Bluetooth (section 2.5). We do not track your location continuously or in the background, and we do not build a history of your movements.
Legal basis: performance of the contract (Art. 6(1)(b)) for the events feature.
On Android, the operating system requires the location permission in order to scan for nearby Bluetooth devices, so the app requests it in the foreground only. The app neither declares nor uses the background location permission (ACCESS_BACKGROUND_LOCATION): we cannot know your location while you are not using the app.
2.5 Bluetooth (BLE) proximity
- Your device broadcasts and detects a rotating, encrypted identifier (a 16-byte token that changes every 15 minutes) over Bluetooth Low Energy, to recognise the presence of other Bluprox users near you.
- The broadcast does not contain your identity, gender, orientation or any filter: it is only the token. A passive observer cannot infer sensitive data or track you across rotations. The token-to-person mapping is resolved only by our server.
- An encounter records only the fact that two devices were near each other (with a timestamp and signal strength). No location coordinates are ever tied to an encounter.
- The keys used for the token are derived with ephemeral cryptography (ECDH + HKDF) and deleted from the device on sign-out.
Legal basis: performance of the contract (Art. 6(1)(b)).
2.6 Encounters, matches, reactions, blocks and reports
- Encounters: the record of who you have physically crossed paths with.
- Reactions and matches: your "interested" / "not interested" and mutual matches.
- Blocks: the people you choose to block.
- Reports: the reports you submit about other users, for review.
Legal basis: performance of the contract (Art. 6(1)(b)); and legitimate interest (Art. 6(1)(f)) in community safety for blocks and reports.
2.7 Photo moderation
Each profile photo is automatically screened before publication by an image-moderation system (NudeNet) that we run on our own infrastructure. Images are not sent to third parties for this purpose. The result may approve, blur or reject the photo.
Legal basis: legitimate interest (Art. 6(1)(f)) in keeping the service safe and compliant with our rules.
2.8 Contact exchange (end-to-end encrypted)
- When you have a match, you can share how to reach you (e.g. your WhatsApp, Telegram or Instagram handle).
- Our server is only told the name of the app you offer (e.g. "WhatsApp"), never the handle or number. Your actual handle lives only on your device.
- The handle is exchanged end-to-end encrypted: it is encrypted on your device with an ephemeral key unique to that match, and only the other person can decrypt it. Our server cannot read it: it only stores and relays opaque encrypted bytes.
Legal basis: performance of the contract (Art. 6(1)(b)).
Encryption happens on your device using standard cryptographic libraries (libsodium, sealed boxes). Availability of this feature may vary by platform and app version.
2.9 Age verification via NFC reading of the ID card (optional)
- ID-document verification by NFC is entirely optional: it is not required to register or to use the app.
- The reading happens on your device. From the document we obtain only your name and date of birth, which then replace those in your profile.
- We store no other document data: not the ID number, photo, nationality, cryptographic material or the raw chip bytes. Those remain only in memory during the reading and are discarded when it ends. Nothing from the document reaches our servers beyond the name and date of birth that are already part of your profile.
- Verification proves that an ID belonging to an adult was used; it does not prove ownership of the document.
Legal basis: consent (Art. 6(1)(a)) and compliance with the age-verification obligation (Art. 6(1)(c)).
This verification is optional, and its availability may vary by platform, app version and document type. The server stores no data from the document reading.
2.10 Purchases and coins
- When you buy virtual coins, payment is handled by Apple (StoreKit 2) or Google (Google Play Billing). We have no access to your payment details (card, etc.).
- We store the store's signed receipt, the transaction identifier, the platform, the amount and your balance, to evidence the purchase, prevent fraud and meet tax obligations.
Legal basis: performance of the contract (Art. 6(1)(b)) and tax/commercial legal obligation (Art. 6(1)(c)).
2.11 Technical data, security and notifications
- Login history and security logs: technical information about access and suspicious activity, to protect your account and prevent fraud and abuse.
- Push notifications: if you enable them, we process a device token to send you alerts about your activity (new encounters, matches). Delivery is via Firebase Cloud Messaging (Google).
Legal basis: legitimate interest (Art. 6(1)(f)) in security; and performance of the contract / consent for notifications.
Push notifications are operational on Android. On iOS, the app registers the device token but does not send push notifications yet.
3. Legal bases (summary)
- Performance of the contract (Art. 6(1)(b)): account, profile, BLE encounter detection, matches, contact exchange, payments.
- Explicit consent (Art. 9(2)(a)): sexual orientation and gender identity (special categories).
- Consent (Art. 6(1)(a)): optional ID verification and push notifications.
- Legal obligation (Art. 6(1)(c)): retention of tax and transaction data; age verification.
- Legitimate interest (Art. 6(1)(f)): content moderation, fraud and abuse prevention, platform security.
4. Processors and third parties
To provide the service we rely on the following providers:
- Google — Firebase Cloud Messaging: delivery of push notifications.
- Hetzner (Germany — EU): hosts our servers and the S3-compatible storage where photos and other objects are kept.
- Mailtrap: delivery of transactional email (account verification, password recovery and the link to your data export).
- Photo moderation (NudeNet): an open-source tool we run on our own infrastructure; images are not shared with third parties.
- Apple / Google: handle in-app payments under their own privacy policies.
We do not use advertising or any third-party analytics or tracking tools. We do not share your data with advertisers or ad networks.
5. International transfers
Our servers and photo storage are hosted in Germany (Hetzner), within the European Economic Area (EEA).
Other providers may process data outside the EEA: in particular Google (Firebase Cloud Messaging), Apple and Google (in-app payments) and the transactional email provider. In those cases, the transfer relies on mechanisms recognised by the GDPR, such as the European Commission's Standard Contractual Clauses (SCCs) or adequacy decisions, where applicable.
6. Data retention
While your account is active, we keep your data to provide the service. When you request account deletion we apply a deferred-deletion model: the account is hidden and access is blocked immediately, and the data is kept for retention windows and purged when they expire.
- Live credentials and secrets (session tokens, BLE keys): deleted immediately on account deletion.
- Profile, photos, encounters, matches, reactions, blocks and check-ins: kept and purged after 365 days.
- Identity (email, name, date of birth): kept encrypted as a legal archive, retrievable only for a legitimate purpose, and purged when the legal period expires.
- Reports and moderation data: 365 days.
- Tax and transaction data: 5 years, by legal obligation.
- Login history: 1 year.
- Unverified accounts: automatically deleted shortly after sign-up.
On your device, account deletion also purges the encrypted local database. If we update any of these periods, we will let you know as described in section 10.
7. Security
- Encryption in transit: all communication with our servers uses HTTPS/TLS.
- Encryption at rest for sensitive data on the device: on iOS, Keychain restricted to the device itself (no iCloud backup); on Android, encrypted storage (EncryptedSharedPreferences) and an encrypted local database (SQLCipher).
- Screen protection: on Android, capture blocking on sensitive screens (FLAG_SECURE); on iOS, screen-recording detection.
- Certificate pinning is active: on top of the system's standard TLS validation, the apps check that the server certificate comes from a specific certificate authority, using a digitally signed pin bundle. This strengthens server authenticity against interception. If the bundle is ever unavailable, the connection remains protected by standard TLS validation.
8. Your rights
Under the GDPR, you have the right to:
- Access (Art. 15): know what data of yours we process.
- Rectification (Art. 16): correct inaccurate or incomplete data.
- Erasure (Art. 17): request deletion of your data ("right to be forgotten").
- Portability (Art. 20): receive your data in a structured, commonly used format.
- Objection (Art. 21): object to processing based on legitimate interest.
- Restriction (Art. 18): request restriction of processing in certain cases.
- Withdraw consent: at any time, without affecting the lawfulness of prior processing.
- Complaint: lodge a complaint with the Spanish Data Protection Agency (AEPD, www.aepd.es).
How to exercise them from the app
- Access and portability (Arts. 15 and 20) — automated export: under Settings → "Export my data" you can request a full copy. We generate it and email a download link to your account address; the link expires after 24 hours. You receive a .zip file containing your data as JSON — structured, commonly used and machine-readable, as Art. 20 requires — together with your photos. The file never travels as an email attachment, only the link does. The copy includes your profile, encounters, matches, reactions, blocks and reports you made, purchases and coins, and login history, without revealing the identity of third parties you are not entitled to know.
- Erasure (Art. 17): account deletion is available from the app settings and also erases the encrypted local database on your device (see the periods in section 6).
- Rectification (Art. 16): you can edit your profile data at any time from the app.
For any other right, or if you would rather not use the app, write to support@bluproxapp.com, stating which right you wish to exercise and enclosing, where appropriate, documentation to verify your identity.
9. Adults only (18+)
Bluprox is intended exclusively for people aged 18 and over. At sign-up we validate age from the date of birth (the date picker prevents choosing a date corresponding to a minor, and the check is repeated on the server). Optionally, age can be verified by reading the ID card via NFC (section 2.9). If we detect or are notified that an account belongs to a minor, we will suspend and delete it.
10. Changes to this policy
We may update this policy to reflect legal, technical or organisational changes. We will notify you of any substantial change through the app or by email before it takes effect, and we will update the date shown at the top of this document.
11. Effective date
This privacy policy takes effect on 8 September 2026.