Privacy Policy

Last updated: 27 September 2026

Tremi is a mobile app for anonymous, one-to-one reciprocal matching and "pokes". This policy explains what the app and its backend collect, why, who processes it for us, and how long it is kept. If you are in Turkey, the KVKK Aydınlatma Metni (information notice under the Turkish Personal Data Protection Law No. 6698) also applies.

1. Who is responsible for your data

Tremi ("we", "us") is the data controller for the personal data described in this policy. For every privacy question or request, contact us at support@tremiapp.com.

2. What we collect

Tremi collects only what the Private mode needs to work and to stay safe:

  • Email address — to sign up, sign in, verify your account and reset your password.
  • Password — never stored in readable form. Only a salted adaptive hash (bcrypt) is kept. We never see, log or retain your plain password.
  • Your chosen ID — stored so that you can see and copy it in Settings. It is shown only to you and cannot be changed.
  • A keyed digest of your ID — matching and uniqueness checks use this digest (HMAC-SHA256 with a secret key), not the plain ID.
  • IDs you enter to match — the text you type is not stored. Only its keyed digest is kept in the attempt record.
  • Age confirmation — only the fact that you confirmed you are at least 13 years old, and when. We do not ask for or store your birth date.
  • Pairing attempts — your internal account number, the digest of the ID you entered, status and times.
  • Match records — internal account numbers of the two members, start and end time and why it ended (for example disconnected or blocked).
  • Blocks — the internal account numbers of the blocked pair, who blocked, and when.
  • Reports — internal account numbers of the reporter and the reported person, the optional reason (Harassment, Spam, Underage, Other) and the time. No free text, email or ID.
  • Daily counters — how many pairing attempts and pokes you used on a UTC day and the time of your last poke.
  • Poke records — the sender's internal account number, the match and the time. There is no poke history and no "delivered" or "read" record.
  • Push notification tokens — for each device you sign in on: its push token, a device identifier used only to tell your devices apart, and the platform (iOS or Android).
  • Notification queue — for a short time, which account a notification is for, its type and times. It never contains the sender.
  • A short-lived digest of your IP address — when the sign-up screen checks whether an ID is available, a keyed, irreversible digest of your IP address is kept for about 10 minutes to limit abuse. The IP address itself is not stored for this.
  • Sign-in security log — account events (for example sign-in or password reset) are recorded with the email address and IP address.
  • Server logs — our hosting providers keep technical request logs, which can include IP addresses and times. Our own code writes no credentials, emails, IDs or tokens to logs.
  • On your device — your sign-in session is kept in the operating system's secure storage. Between sign-up and email verification, the email, the chosen ID and your age confirmation are kept only on that device and are removed afterwards.
  • Crash reports — if the app crashes, technical data (device model, operating system and app version, error trace) is sent to our crash reporting provider with personal-data scrubbing enabled. We do not attach your account number, ID or email.
  • Bot protection — on sign-up, sign-in, password reset and "resend email", a bot check processes technical signals from your device and your IP address.
  • Messages to support — what you send us by email, including your email address.

What we do not collect

Your name, phone number, birth date, contact list, location, photos, advertising identifiers or an analytics profile, messages or chats (Tremi has no chat), or a poke history. Tremi shows no ads and has no purchases.

This website sets no cookies and uses no analytics or trackers.

3. What your match can see

Inside the app, your match never sees your ID, email or any other identifier, and you never see theirs: not on screens, in notifications or in error messages. A notification only says "Poke! :p" or "Something changed in Tremi." When you enter someone's ID, nothing is sent to that person. Keep in mind that whoever you told your ID to outside the app may be able to guess who you are, so Tremi cannot promise absolute anonymity.

4. Why we use it

  • To create and run your account: sign-up, sign-in, verification and password reset.
  • To provide the Private mode: pairing attempts, matches, pokes, daily limits and notifications.
  • To keep Tremi safe: blocks, reports, holding deleted IDs back for a while, rate limits, bot protection and security logs.
  • To find and fix crashes.
  • To answer support and privacy requests and to meet legal obligations.

We do not sell your data, use it for advertising or build profiles. We rely on the performance of our contract with you, our legitimate interest in keeping the service safe and working, and compliance with legal obligations. The legal bases under the Turkish KVKK are listed in the KVKK Aydınlatma Metni.

5. Who processes data for us

  • Supabase — database, sign-in and server functions.
  • Expo (Expo Push Service) — forwards notifications to Apple and Google. It processes device push tokens and the generic notification content. Expo may also deliver app updates.
  • Apple — delivers notifications to iPhones (APNs) and distributes the iOS app.
  • Google — delivers notifications to Android devices (Firebase Cloud Messaging) and distributes the Android app.
  • Sentry — crash reports, with personal-data scrubbing.
  • Email delivery provider — sends verification and password-reset emails, so it processes your email address.
  • Cloudflare — bot protection (Turnstile), hosting of this website and email routing for our support address. It keeps its own technical logs, such as IP addresses.

These providers process data only on our instructions and for the purposes above. We may also disclose data to public authorities where the law requires it. We never disclose your identity to your match or to other users.

6. International transfers

These providers may process data outside Turkey and outside the European Economic Area, including in the United States. For users in Turkey, transfers are made under Article 9 of the KVKK using the standard contractual clauses published by the Personal Data Protection Board. For users in the EU/EEA and the UK, transfers are made under the European Commission's Standard Contractual Clauses or another valid transfer mechanism.

7. How long we keep it

Scheduled jobs on the server delete data automatically when its period ends.

DataKept for
Email, password hash, your ID, age confirmation, push tokensUntil you delete your account.
Accounts whose email was never verifiedDeleted 7 days after sign-up.
Ended pairing attempts (including the digest of the entered ID)Deleted within 24 hours of ending. Only the daily counter remains.
Daily attempt and poke counters7 days after the UTC day ends.
Individual poke records48 hours.
Sent or dropped notification queue entries48 hours after sending.
Delivery tickets from the push service (no account number)At most 24 hours.
Invalid or replaced push tokensDeleted as soon as the provider reports them invalid. Signing out removes that device's token; deleting your account removes all of them.
Ended match records (internal account numbers only), for abuse handling30 days after the match ended, also if an account is deleted.
BlocksUntil either account is deleted.
Reports (internal account numbers only)1 year, also if an account is deleted.
Digest of a deleted account's ID30 days. During this time nobody can take the ID; afterwards anyone can.
Digest of the IP address for the ID availability checkAbout 10 minutes.
Sign-in security log (email and IP address)30 days. Your entries are deleted at once when you delete your account.
Server logs of our hosting providersUp to 30 days.
Crash reportsUp to 90 days.
Support and privacy request emailsUntil the request is resolved, then up to 2 years to handle follow-ups and legal claims.
Encrypted database backupsReplaced on a rolling basis, within 30 days. Deleted data can remain in a backup until that backup is replaced.

8. How your data is protected

  • All connections use TLS. The database and its backups are encrypted at rest.
  • Passwords are stored only as salted adaptive hashes.
  • Lookups by ID use a keyed digest, not the plain ID.
  • Every database table is closed to other users: the app can only read your own state through server functions.
  • On your phone, the session is kept in the operating system's secure storage.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the competent authority as the law requires.

9. Minimum age: 13

You must be at least 13 years old to use Tremi, and you confirm this at sign-up. We do not knowingly collect data from children under 13; accounts of users found to be under 13 are deleted. To report an underage account, use "Report current match" with the reason "Underage" in the app, or contact Support. If you are a parent and believe your child under 13 has an account, email us and we will delete it.

10. Your rights

Depending on where you live, you can ask to access your data or get a copy of it, have it corrected or deleted, restrict or object to its processing, receive it in a portable format, learn who we transfer it to, object to a result based solely on automated processing, and claim compensation for unlawful processing. Users in Turkey have these rights under Article 11 of the KVKK; see the KVKK Aydınlatma Metni.

Write to support@tremiapp.com from the email address of your account, so we can confirm it is you. We answer within 30 days at the latest and free of charge. You also have the right to complain to your data protection authority (in Turkey, the Personal Data Protection Board).

11. Deleting your account

In the app: Settings → Delete account (you confirm with your password). If you cannot use the app, see Delete account. Deletion ends your match, removes your account, ID, pending attempts, blocks, counters, poke records, push tokens and sessions, and holds your ID back for 30 days. The records listed above as kept after deletion (ended match records and reports, with internal account numbers only) are deleted when their period ends.

12. Changes

We may update this policy. We will change the date at the top of this page and, for significant changes, tell you in the app before they take effect.

13. Contact

support@tremiapp.com