Skip to content

Privacy Policy

Effective August 23, 2026. See also our Terms of Service.

This policy describes what Real actually collects and does today, based on the current product. It needs to be re-reviewed any time a feature that touches personal data changes — new analytics, ads, location tagging, etc. — and should get a lawyer's review before wide launch, especially if EU/UK users are expected (GDPR imposes requirements — like data processing agreements with our sub-processors — that this draft does not fully address).

1. Scope

This Privacy Policy explains how [Your Legal Entity or Name] ("Real," "we," "us") collects, uses, and shares information when you use the Real website and app (the "Service"). It applies to everyone who visits or uses the Service, whether or not you have an account.

2. Information we collect

Account information. When you sign up, we collect your email address, the username you choose, and your password. Your password is handled by our authentication provider (Supabase Auth) and stored in hashed form — we do not store or have access to your plaintext password.

Profile information. Your username, optional display name, and optional avatar image are visible to other users and to logged-out visitors, since they're shown alongside your posts and on your profile page.

Content you post. When you create a post, we store the photo(s) you upload — both the original file and a resized/optimized version we generate for display — along with any caption. If your photo file contains EXIF metadata, we read and store the camera make, camera model, and capture timestamp fields from it, and may display them alongside your post. This is parsed from your file at upload time; we do not currently read or store GPS/location EXIF data, and do not ask for your location.

Reports and moderation activity. If you report a post, we store which post you reported and why. Your identity as the reporter is kept confidential from the post's author — it is visible only to our moderators, for the purpose of preventing abuse of the reporting system (e.g. coordinated false reporting). If you contest a report against your own post, we store the statement you submit. Moderators' decisions and notes are kept in an internal record.

Information collected automatically. Like most web services, our hosting providers (Supabase and Vercel) log standard technical information as part of operating the Service — things like IP address, browser/device type, and request timestamps. We use a session cookie to keep you signed in. We do not currently use third-party analytics, advertising, or tracking cookies. (If that changes — we're planning to add basic analytics and, eventually, sponsored posts — this policy will be updated first, and this section is the one that needs rewriting when it happens.)

3. How we use information

  • to create and secure your account, and authenticate you;
  • to operate the core product — storing and displaying your posts, showing you the feed, sending in-app notifications (e.g. when your post is flagged, restored, or removed);
  • to run the reporting and moderation process described in our Terms of Service, including detecting abuse of that process;
  • to communicate with you about your account (e.g. password resets) — we do not currently send marketing email;
  • to enforce our Terms of Service and keep the Service safe; and
  • to maintain, secure, and improve the Service.

4. How we share information

We do not sell your personal information. We share information in these circumstances only:

  • With other users, by design. Your username, display name, avatar, and any post that's currently visible are public — that's the point of a public photo feed. Whether one of your posts is currently flagged, under review, or was removed is also visible to you and, for removed/flagged states, may be reflected in notifications and on the post itself.
  • With service providers who run our infrastructure. Supabase (database, authentication, file storage) and Vercel (application hosting) process data on our behalf, under their own privacy and security commitments, solely so we can operate the Service. We don't let them use your data for their own purposes.
  • For legal reasons. We may disclose information if required by law, subpoena, or other legal process, or if we believe in good faith it's necessary to protect the rights, property, or safety of Real, our users, or the public — including reporting apparent child sexual abuse material to the relevant authorities, as described in our Terms.
  • In a business transfer. If Real is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction; we'll provide notice before your information becomes subject to a different privacy policy.

5. Data retention

We retain your account and content for as long as your account is active. If a post is removed by moderation, we retain a record of it (and the moderation decision) for audit and appeals purposes rather than immediately hard-deleting it, similar to most platforms with a review/appeals process. Real does not currently offer self-service account deletion — to request deletion of your account and associated content, contact us at [your-contact-email], and we'll process the request within a reasonable time, subject to reasonable retention for backups, fraud prevention, and legal compliance.

6. Your choices and rights

You can update your display name and avatar at any time from your account settings. You can request a copy of, or the deletion of, your personal information by contacting [your-contact-email] — we don't yet have a self-service export/delete tool, so these are handled manually for now.

California residents: depending on applicable law, you may have the right to know what personal information we collect, to request deletion, and to non-discrimination for exercising these rights. We do not sell personal information, so there is nothing to opt out of on that front. Contact us at [your-contact-email] to make a request.

EU/UK/other residents with data-protection rights: you may have rights to access, correct, delete, or port your data, and to object to certain processing. Contact us at [your-contact-email]. (This section is a starting point, not a complete GDPR-style rights framework — get that reviewed if you're expecting a meaningful EU/UK user base.)

7. Children's privacy

Real is not directed at children under 13, and we do not knowingly collect personal information from anyone under 13. If you believe a child under 13 has provided us with personal information, contact us at [your-contact-email] and we will delete it.

8. Security

We use industry-standard measures appropriate to a service of this size, including encrypted connections (HTTPS) between your device and our servers, hashed password storage via our authentication provider, and database-level access control (Row Level Security) so that, for example, only you can modify your own profile and only moderators can see report details. No method of transmission or storage is 100% secure, and we can't guarantee absolute security.

9. International data transfer

Our infrastructure providers may process and store data outside your home country. Our current hosting region is [confirm your Supabase/Vercel project region]. If you're accessing the Service from outside that region, your information will be transferred there.

10. Cookies

We use one essential cookie to keep you signed in between visits. We do not currently use analytics, advertising, or third-party tracking cookies. If we add any (analytics is on our near-term roadmap), we'll update this section and, where legally required, add a consent mechanism before doing so.

11. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we'll update the effective date above and, where appropriate, notify you directly. Continued use of the Service after changes take effect means you accept the updated policy.

12. Contact

Questions about this policy, or a privacy request? Reach us at [your-contact-email].