Privacy Policy

Last updated: 3 August 2026

Go Dutchie ("we", "us") helps you find people in your contacts who use the same services and subscriptions so you can share costs and referrals. This policy explains what we collect, why, and your choices. Questions? [email protected].

Information we collect

How we use it

How matching protects your contacts

Matching is designed to reveal as little as possible. Your contacts' names never leave your device. When you search, candidate phone numbers and emails are sent securely to our server and converted to keyed HMAC-SHA-256 hashes with a secret pepper. We compare only the hashes, do not store the raw values you send, and cannot reverse a hash back to a phone number or email. They are not written to our server logs either: the numbers exist only for the moment the comparison runs, and are gone when it finishes.

A match is shown to you under the name you saved in your own phone. Matching itself sends nothing about the other person to your device — not their profile name, and never their profile picture, which we do not store at all. What a match reveals is that someone already in your contacts uses the same service: nothing about them that you did not already have.

Names are exchanged only when one of you asks for it. If you send that match a Dutchie request, your profile name goes with it, so they can see who is asking — described in full below.

Dutchies: sharing a subscription

A "Dutchie" is a subscription you agree to share with another member. It starts when you send that member a request and completes only if they accept. Nothing in this section happens without that deliberate step.

Community announcements — "a new app has been proposed", "a new app was approved" — are shown to everyone without naming who submitted the app. We record the submitter internally so that your own submissions still reach you when you have muted community updates; that attribution is not readable by other members.

Service providers

We share data only with providers that run the service on our behalf:

We do not sell your personal information.

Google API User Data Policy Compliance

Go Dutchie's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We only access basic profile information (email, display name, profile picture) using secure OAuth 2.0 protocols, and do not use this data for advertisements, targeting, or transfer it to third-parties outside of our core authentication services.

Retention & deletion

We keep your data while your account is active.

Deleting your account yourself. Open Profile → Delete account — in the app or on this website — and confirm. This is the fastest route and needs no request to us: your profile, your saved services, your referral links, your community suggestions, your Dutchie requests and active Dutchies, your block list, and your notification token are removed, and your phone and email hashes are deleted so you can no longer be matched by anyone's contacts. Deletion is immediate and cannot be undone — signing up again later starts a fresh, empty account.

By email. You can instead ask us to delete your account by emailing [email protected] from the address on your account. We will complete the deletion within 30 days.

In both cases we may retain a limited record where the law requires it — for example to meet accounting or fraud-prevention obligations. Anything another member has already saved to their own device (a referral link they copied, a contact they already had) is outside our systems and is not affected by deletion.

Your choices

Children

Go Dutchie is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data.

Changes

We may update this policy; material changes will be reflected by the "Last updated" date above.

Contact

Go Dutchie — [email protected]