Last Updated: 11.05.26
This Privacy Policy explains how IAO (“we,” “us,” or “our”) collects, uses, stores, and protects your personal data when you use our mobile application and website (useiao.com).
IAO is an anonymous structured debate platform. You are matched with another user to discuss a daily topic. Your profile is never shown to other users — only your messages are visible during a debate.
1. Data We Collect
We collect only the minimum data necessary to provide our service:
- Email address — required for account creation and login. Never shown to other users.
- Debate messages — text content you send during a debate session. Stored to enable real-time chat and to review reported conversations.
- Report and block records — if you report or block another user, we store the reason and the associated debate ID for moderation purposes.
- Account metadata — account creation date, last active timestamp, and account status (active / suspended).
- Device notifications token — only if you grant permission, used to notify you when a debate match is found.
We do not collect your name, phone number, location, photos, or any other personal identifiers.
2. How We Use Your Data
- Service delivery — to match you with another user, enable real-time messaging, and manage your account.
- Moderation — to review reports of harassment, hate speech, threats, or spam and take appropriate action (warnings, suspensions).
- Security — to detect abuse, enforce our block system, and protect users from previously blocked accounts.
- Notifications — to alert you when a debate match is found (only with your permission).
- Legal compliance — to respond to lawful requests from authorities when required.
We do not sell your data to third parties or use it to build behavioral profiles. We do not currently display ads within the app. If this changes in a future version, this policy will be updated and users will be notified in advance.
3. Third-Party Services
IAO uses the following third-party infrastructure providers. Each handles data under their own privacy policies:
- Supabase (database, authentication, real-time messaging) — Your email address, hashed password, and debate messages are stored on Supabase’s servers. Supabase is SOC 2 Type II certified. Supabase Privacy Policy →
- Apple Push Notification Service (APNs) — Used to send match notifications if you grant permission. Apple Privacy Policy →
No other third-party SDKs, analytics tools, or advertising networks are currently integrated into the app. If any are added in the future, this policy will be updated accordingly.
4. Data Retention
- Active accounts — your data is retained for as long as your account is active.
- Debate messages — stored for up to 90 days after the debate ends, then automatically deleted.
- Report and block records — retained for up to 2 years for moderation and safety purposes.
- Deleted accounts — upon account deletion, your email and account data are removed within 30 days. Debate messages may be retained in anonymized form for moderation review if a report is pending.
5. Account Deletion
You can permanently delete your account directly within the app:
- Open the app → tap the Settings icon → tap Delete Account.
- You will be shown a confirmation message. Upon confirming, your account and associated personal data will be scheduled for deletion.
Alternatively, you may request account deletion by emailing us at [email protected]. Requests are processed within 30 days.
6. Your Rights
Under GDPR and applicable data protection laws, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Correction — request that inaccurate data be corrected.
- Deletion — request deletion of your personal data (see Section 5).
- Portability — request your data in a machine-readable format.
- Objection — object to certain processing activities.
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
7. Security
- All data is transmitted over HTTPS / TLS encrypted connections.
- Passwords are hashed and never stored in plain text.
- Database access is restricted to authorized services only.
- We never display your identity to other users during debates.
8. Children’s Privacy
IAO is not intended for users under the age of 17. We do not knowingly collect personal data from anyone under 17. If we become aware that a user under 17 has created an account, we will delete the account and associated data promptly. If you believe a minor has registered, please contact us at [email protected].
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last Updated” date at the top of this page. For significant changes, we will notify users via the app or email. Continued use of IAO after changes are posted constitutes acceptance of the updated policy.
Contact Us
If you have any questions about this Privacy Policy or how we handle your data, please reach out:
[email protected]