Privacy Policy
Last updated: 3 August 2026
Go Dutchie ("we", "us") helps you find people in your contacts who use the
same services and subscriptions so you can share costs and referrals. This policy
explains what we collect, why, and your choices. Questions?
[email protected].
Information we collect
- Account details — your email address and display name, used to
authenticate you and to create and manage your Go Dutchie account.
We never store your profile photo. If you sign in with Google, we
receive your Google account email address, display name, and a link to your
Google profile picture — the link only, never a copy of the image, and we do not
display it. We do not access or request any other Google user data. If you choose to
set a profile picture yourself — however you signed in — that photo is copied
into the app's own storage on your phone and never leaves the
device — it is not uploaded to us and no one else can see it.
Your name is shown to you, in your own account. Matching alone does
not display it to anyone: the app shows each match under the name
you saved them as in your own phone. The one exception is a Dutchie request, which
you send deliberately — see Dutchies below.
- Phone number — used to match you with your contacts.
It is hashed (a one-way cryptographic digest with a secret
key) so it can be compared without being readable.
- Contacts — with your permission, we read your device
contacts on your device to find matches. Your contacts' names stay
on your device. To find matches, candidate phone numbers and email
addresses are sent to our server over an encrypted connection, where they
are hashed with a secret key and compared against other users' hashes. We
do not store the raw phone numbers or emails you send for matching.
- Service usage you choose to share — the services you mark as
"My Services", referral links you add, and service suggestions/edits you submit.
- Dutchie requests and shares — when you ask another member
to share a subscription we store the request: who sent it, who received it, which
service, your optional note, and whether it was accepted, declined, or expired.
We also store the members you have blocked and your contact-sharing preferences.
See Dutchies below for what the other member sees.
- Photos — only when you choose a service or profile image
from your photo library; used solely to set that image. Go Dutchie does not
use your camera.
- Push notification token — a device token (via Firebase
Cloud Messaging) so we can notify you, e.g. when your service suggestion is
approved. It is stored against your account, along with your device
platform and app version, and replaced whenever you sign in on a different
device. It is used only to deliver notifications, never to track you, and
it is deleted with your account.
- Basic technical data — device platform and app version
needed to deliver notifications and run the service.
How we use it
- To authenticate you and keep your account secure.
- To match you with contacts who use the same services, using hashed values.
- To power the community service list and approvals.
- To send you notifications you've enabled.
How matching protects your contacts
Matching is designed to reveal as little as possible. Your contacts' names
never leave your device. When you search, candidate phone numbers and emails
are sent securely to our server and converted to keyed
HMAC-SHA-256 hashes with a secret pepper. We compare only the
hashes, do not store the raw values you send, and cannot reverse a hash back
to a phone number or email. They are not written to our server logs either:
the numbers exist only for the moment the comparison runs, and are gone when
it finishes.
A match is shown to you under the name you saved in your own phone.
Matching itself sends nothing about the other person to your device — not
their profile name, and never their profile picture, which we do not store at
all. What a match reveals is that someone already in your contacts uses the same
service: nothing about them that you did not already have.
Names are exchanged only when one of you asks for it. If you send that match a
Dutchie request, your profile name goes with it, so they can see who is asking
— described in full below.
Dutchies: sharing a subscription
A "Dutchie" is a subscription you agree to share with another member. It starts
when you send that member a request and completes only if they accept. Nothing in
this section happens without that deliberate step.
- When you send a request — the recipient is shown your
profile name (the name on your Go Dutchie account, not the name
they saved you as), which service the request is about, and the optional note
you wrote. They are not shown your phone number or email address at this stage.
You already know who you are sending to: you picked them from your own contacts.
- Your note — a request may carry one short free-text note (up
to 300 characters). We store it so the recipient can read it, and it is checked
automatically for disallowed content. We blank the note text
90 days after the request is answered or expires; the request record itself is
kept so neither of you loses the history of what was agreed.
- If they accept — you each see the other's profile name and the
contact details each of you has chosen to share, so you can arrange the split
yourselves. Which details are shared is your setting: your phone number (which
covers calls, texts and WhatsApp, since they all reach the same number) and
your email can each be turned on or off under Profile → Privacy &
safety. Turn both off and only your profile name is shared. The email shared is the
address on your Go Dutchie account, which may not be the one they already had
for you.
- If they decline, or do nothing — you are told it was declined
and, if they picked one, the broad reason (for example "plan is full"). No
contact details are exchanged. An unanswered request expires by itself after
7 days.
- Blocking — you can block another member. They can no longer
send you Dutchie requests, and we store the fact that you blocked them so it
keeps working. We never tell them they were blocked.
- Split terms — either of you can propose what the
subscription costs, how often it renews, and who pays what. We store those
figures and who proposed and agreed them, so you both have the same record.
- Reporting — the optional note on a request is the only
thing one member can send another; there is no chat and no reply. You can report
the request that carried it as spam, harassment, or an inappropriate note, with
optional details. Reports go to our administrators so we can act on them; the
person reported is not told who reported them.
- Money — Go Dutchie does not take payments, hold funds, or see
what you pay each other. Whatever you settle on is between the two of you, and
the terms of the underlying service are between each of you and that provider.
Community announcements — "a new app has been proposed", "a new app was
approved" — are shown to everyone without naming who submitted the app. We
record the submitter internally so that your own submissions still reach you when
you have muted community updates; that attribution is not readable by other
members.
Service providers
We share data only with providers that run the service on our behalf:
- Supabase — authentication and database backend.
- Google Firebase — push notifications and this website.
- Google & Apple — to facilitate secure third-party authentication (OAuth) when you sign up or log in using your Google or Apple accounts.
We do not sell your personal information.
Google API User Data Policy Compliance
Go Dutchie's use and transfer to any other app of information received from Google APIs will adhere to the
Google API Services User Data Policy,
including the Limited Use requirements. We only access basic profile information (email, display name, profile picture) using secure OAuth 2.0 protocols, and do not use this data for advertisements, targeting, or transfer it to third-parties outside of our core authentication services.
Retention & deletion
We keep your data while your account is active.
Deleting your account yourself. Open Profile → Delete
account — in the app or on this website — and confirm. This is the
fastest route and needs no request to us:
your profile, your saved services, your referral links, your community
suggestions, your Dutchie requests and active Dutchies, your block list, and your
notification token are removed, and your phone and email
hashes are deleted so you can
no longer be matched by anyone's contacts. Deletion is immediate and cannot be
undone — signing up again later starts a fresh, empty account.
By email. You can instead ask us to delete your account by
emailing [email protected] from the
address on your account. We will complete the deletion within 30 days.
In both cases we may retain a limited record where the law requires it — for
example to meet accounting or fraud-prevention obligations. Anything another
member has already saved to their own device (a referral link they copied, a
contact they already had) is outside our systems and is not affected by deletion.
Your choices
- Contacts, photos, and notifications are permission-based — you can
grant or revoke them in your device settings.
- You can hide services from your profile or remove referral links in the app.
- Under Profile → Privacy & safety you choose which contact details
(phone number, email) a Dutchie partner receives, mute community updates, and
manage your block list.
Children
Go Dutchie is not directed to children under 13 (or the minimum age in your
country), and we do not knowingly collect their data.
Changes
We may update this policy; material changes will be reflected by the "Last
updated" date above.
Contact
Go Dutchie — [email protected]