Legal

Privacy Policy

This English version is the legally binding text. The other language versions are convenience translations; in case of conflict, the English version prevails. Status: v1.3 — last updated 2026-10-01.

1. Controller

The controller within the meaning of Art. 4(7) GDPR is:

Karussell Labs OÜ Tartu mnt 67/1-13b Tallinn Estonia

Email: contact@karusselllabs.com

Karussell Labs OÜ operates BigBro from its seat in Tallinn, Estonia. The person responsible for content is Kfir Yehuda (address as above).

Registry code (Registrikood): 17536456 VAT: Karussell Labs OÜ is not currently registered for VAT and has no VAT identification number.

2. Privacy contact

For all questions about the processing of your personal data and to exercise your rights:

Email: privacy@bigbro.men

A formal Data Protection Officer has not been appointed. Estonian law has no headcount-based DPO threshold; the need for a DPO is assessed solely under Art. 37 GDPR. The privacy contact handles all data-protection requests in accordance with the GDPR.

3. Scope

This Privacy Policy applies to the processing of personal data by the BigBro application ("the App"), including the website at https://www.bigbro.men and the iOS/Android apps.

BigBro is an age-restricted (18+) social platform for gay, bi and queer men. The focus is on friendship, shared activities, and self-organised events (e.g. regular meet-ups, watch-parties, game nights). Dating or relationships may emerge from connections made on BigBro — that's possible, but it's not the primary purpose of the app.

4. Categories of data we process

4.1 Account data

  • Email address (or Apple/Google sub-ID for SSO)
  • Password hash (bcrypt; the cleartext password is never stored)
  • Registration timestamp, last login

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

4.2 Profile data

  • Display name, handle (unique username)
  • Bio
  • Age at signup (age_at_signup)
  • City / approximate location
  • Pronouns, height, body type, tribes, relationship status, languages
  • Search preferences: age range, distance

Legal basis: Art. 6(1)(b) GDPR and, where the data implies sexual orientation, Art. 9(2)(a) GDPR (explicit consent) — which is inherent to creating a profile on a platform for gay, bi and queer men.

4.3 Special-category data (Art. 9 GDPR)

  • Secret hashtags / kinks (user_kinks) — sexual and relationship preferences
  • HIV status, HIV medication, last test date (optional, with explicit consent, only visible to users to whom you have granted an explicit "Interaction Setup" share)

Legal basis: Art. 9(2)(a) GDPR (explicit consent). You may withdraw consent at any time with effect for the future by clearing the relevant fields in your profile or deleting your account.

4.4 Location data

  • A one-time, foreground reading of your device location (via your browser or the OS location permission), taken only when you tap "Allow Location." We do not store raw or continuous GPS: we immediately snap the reading to a fixed ~110 m grid and keep only that single latest snapped point — never a street-level coordinate, and never a location history.
  • This snapped point is held only on our servers and is used solely to compute approximate distances to other members and events. It is never shown or sent to other users: other members only ever see a rounded distance — never your coordinates, never your grid point, never your exact spot.
  • You can turn on "Hide Distance" at any time, which keeps you in discovery but shows no distance figure to others.
  • An optional free-text city you may enter on your profile.
  • Optional: Plus-Code location shares ("Smart Address Share") that you send explicitly to individual members; these are generated on your device, encrypted, and shared as a code, not a street address.
  • We do not track your location in the background or continuously.

Legal basis: Art. 6(1)(b) GDPR (performance of contract) for the distance/discovery feature and the city display; Art. 9(2)(a) GDPR (explicit consent) for the location reading itself, since location on a platform for gay, bi and queer men can imply sexual orientation and warrants the special-category safeguard; Art. 6(1)(a) GDPR (consent) for each individual Smart Address share.

4.5 Messaging data

BigBro lets you exchange private one-to-one messages, and group messages within an event you have joined. In connection with messaging we process:

  • Message content — text, emoji reactions, images, shared locations, shared addresses and event invitations you send or receive
  • Metadata — sender and recipient identifiers, timestamps, read status, delivery status, and whether a message was edited or deleted
  • Conversation settings — mute status, archiving, and any disappearing-message setting you choose (after reading, after sending, or view-once)

No end-to-end encryption. Messages are stored on our infrastructure (see Section 6) and are protected by encryption in transit and at rest. They are not end-to-end encrypted, and their content is technically accessible to us and to the automated safety systems described in Section 4.7. You should not treat BigBro messages as a confidential or secure-messaging channel.

Photos in chat. Photos you send in a message can only be images from your own profile gallery that have already passed our image-moderation checks. You cannot attach arbitrary files.

Read receipts, typing and online status. Other participants in a conversation can see when you have read their messages, and may briefly see that you are currently typing (this indicator is transient and is not stored). Your profile may show an "online now" indicator to other members, derived from your recent activity; you can suppress it by enabling incognito mode, which makes you appear offline. Discovery lists may also be ordered by the day you were last active. Only the calendar day is used for this, never the time, and incognito mode removes you from these lists entirely. To provide both, we store only the time of your most recent activity, which is overwritten each time you use BigBro.

Legal basis: Art. 6(1)(b) GDPR (performance of contract).

4.6 Push notifications

If you enable notifications, we send push notifications about new messages and activity to your device via Apple's and Google's push services (see Section 6). For a new message, the notification may include a preview of the message — up to approximately the first 80 characters of the text, or a generic label such as "sent you a photo." This preview is transmitted to Apple and/or Google to deliver the alert. You can disable message previews or notifications entirely in your device settings.

Legal basis: Art. 6(1)(b) GDPR (performance of contract) and Art. 6(1)(f) GDPR (legitimate interest in a usable service).

4.7 Moderation and safety data

  • Content-moderation log (content_moderation_log): excerpt of flagged content, hit categories, verdict
  • Strikes ledger (user_strikes)
  • User reports (reports)
  • Security audit log (audit_log)
  • For suspected CSAM: entry in ncmec_queue for later transmission to the National Center for Missing & Exploited Children (NCMEC).

To keep the platform safe and lawful, the text of messages and other user-authored text (such as your bio and display name) is screened before it is published, both against our own prohibited-terms list and by a third-party moderation service (see Section 6). Message text may be transmitted to that service for this purpose. Images are screened by an automated image-moderation service before they can be used. Where content is flagged we may block it, log the event, apply account strikes, suspend the account, and — for suspected CSAM — report it to NCMEC as required by law.

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a safe platform and protection of third parties) and Art. 6(1)(c) GDPR (legal obligations under the DSA and child-protection law).

4.8 Device and connection data

  • IP address (transient — session management and abuse prevention)
  • User-agent / platform (web, iOS, Android)
  • Device push token and device identifiers (only as required to deliver notifications and maintain the app session; push tokens are pruned after prolonged inactivity)

Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure operation).

4.9 Cookies and similar technologies

We use cookies and similar local-storage techniques in three separate categories. Optional categories are activated only after your consent; you choose per category in our cookie banner, where "Reject all" is exactly as easy as "Accept all".

  • Strictly necessary (always on): session and authentication cookies (refresh/access tokens), security, and storing your consent choice. The platform cannot work without them.
  • Functional (optional): device-local preferences, e.g. remembering which prompts you have already seen.
  • Analytics & error monitoring (optional): anonymous diagnostics (Sentry) to detect and fix crashes. No advertising trackers, no profiling, no third-party advertising cookies.

Consent is voluntary and access to the platform does not depend on it. You can change or withdraw your choice at any time, with effect for the future, via the "Cookie settings" link in the footer.

Legal basis: Art. 5(3) of the EU ePrivacy Directive 2002/58/EC (as implemented in Estonia in the Electronic Communications Act — Elektroonilise side seadus) together with Art. 6(1)(f) GDPR for strictly necessary cookies (no consent required); the same provision together with Art. 6(1)(a) GDPR (consent — withdrawable at any time, Art. 7(3) GDPR) for the optional categories.

5. Purposes

  • Operating the App and performing the user contract
  • Authentication and session management
  • Displaying and matching profiles (discovery / matching)
  • User-to-user communication (messages, reactions, event chats)
  • Delivery of push notifications
  • Location-based features (only as explicitly used)
  • Content moderation, abuse prevention, child protection
  • Compliance with legal obligations (DSA, GDPR, Estonian and EU law)
  • Defence against legal claims

6. Recipients

6.1 Processors

We do not sell your personal data and we do not use a third-party messaging provider; messaging runs on our own infrastructure. Your data is processed on our behalf by:

  • Supabase Inc. (hosting, database, auth, realtime message delivery, storage). All BigBro data is stored exclusively in the EU region eu-central-1 (Frankfurt am Main, Germany). A Data Processing Agreement based on the EU Standard Contractual Clauses is in place.
  • OpenAI, L.L.C. (USA) — automated moderation of user-authored text (including message text) and images.
  • Microsoft Corporation — PhotoDNA Cloud Service, used to check uploaded images against databases of known child sexual abuse material. Images are processed in Microsoft's EU datacenter.
  • Resend, Inc. (USA) — delivery of internal child-safety alert emails to our own staff mailboxes. These alerts contain the identifier of the account that uploaded the content; they never contain the image itself.
  • Apple Inc. (USA / global) — delivery of push notifications to iOS devices (APNs; may include a message preview), and "Sign in with Apple".
  • Google LLC (USA / global) — delivery of push notifications to Android/web (Firebase Cloud Messaging; may include a message preview), and "Sign in with Google".
  • Sentry (Functional Software, Inc., USA) — anonymous crash and error diagnostics (optional; only with consent).

6.2 Independent controllers

  • NCMEC (USA) for suspected CSAM transmissions.
  • Authorities (e.g. law enforcement) where we are legally required.

6.3 Other users

Profile information you make visible on your profile (display name, bio, city, tribes, etc.) is visible to other signed-in users. Special-category data (interaction_setup) is only visible if you grant an explicit share. The content of a message is visible to the other participant(s) in that conversation.

6.4 Map and address search

The events map and the address search on the event form are drawn and answered by third-party services that your device contacts directly. They are not processors acting on our behalf: we do not send them your data, your device does, so they necessarily receive your IP address and the request itself.

  • OpenFreeMap (openfreemap.org) — supplies the map tiles shown on the events map. It receives your IP address and the map area you are looking at. Map data is © OpenStreetMap contributors, licensed under the ODbL.
  • Photon, operated by komoot GmbH (Potsdam, Germany) — answers the address search when you create or edit an event. It receives your IP address and the text you type into that field. Do not type anything into it you do not want to send.

Neither service is used to identify you, and we do not receive any profile or tracking data back from them. The map is only loaded when you open the events map; the address search only when you type in that field.

7. International transfers

The BigBro database is in Frankfurt am Main (Germany). Transfers outside the EEA may occur in the following cases:

  • Supabase Inc. (US-based) — based on EU Standard Contractual Clauses (SCCs, Module 2) plus supplementary technical measures (in-transit and at-rest encryption).
  • OpenAI, L.L.C. (USA), for content moderation — based on EU Standard Contractual Clauses under OpenAI's data-processing terms.
  • Apple / Google, for push-notification delivery and SSO — based on the EU–US Data Privacy Framework and/or EU Standard Contractual Clauses.
  • NCMEC (USA) for CSAM reports — based on Art. 49(1)(d) GDPR (important reasons of public interest — child protection).

Microsoft's PhotoDNA image check runs in an EU datacenter, so it does not itself involve a transfer outside the EEA.

You may request a copy of the relevant safeguards by contacting privacy@bigbro.men.

8. Retention periods

Data categoryRetention
Active accountWhile the account exists
Time of most recent activity (online indicator)Overwritten on each use; deleted with the account
Messages (no disappear mode)While the conversation exists / both participants are active
Messages (disappear mode)Per the chosen setting, then hard-deleted
Conversation permanently deleted, or a participant blockedThe one-to-one conversation and its media are hard-deleted immediately, for both participants — irreversibly
Content connected to a CSAM reportPreserved for up to 180 days regardless of deletion, to comply with reporting obligations
Audit log12 months from entry
Content-moderation log24 months from entry (DSA obligations)
NCMEC queue entriesUntil transmission + 12 months
Account deleted30-day grace period, then pseudonymisation; certain identity and strike data may be retained up to 24 months to prevent post-ban re-entry. Messages you sent may remain in the recipient's copy of a conversation until they delete it.

9. Your rights

  • Right of access (Art. 15 GDPR)
  • Right to rectification (Art. 16 GDPR) — most profile data can be edited yourself at /me/edit
  • Right to erasure (Art. 17 GDPR) — you can delete your account at /me (pseudonymisation)
  • Right to restriction (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR) — JSON export via /me
  • Right to object (Art. 21 GDPR)
  • Right to withdraw consent (Art. 7(3) GDPR)
  • Right to lodge a complaint (Art. 77 GDPR) — as our main establishment is in Estonia, our lead supervisory authority (One-Stop-Shop, Art. 56 GDPR) is:

Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate) Tatari 39 10134 Tallinn, Estonia Email: info@aki.ee Web: https://www.aki.ee

You may also always lodge a complaint with the supervisory authority in your EU Member State of residence.

10. Obligation to provide data

Providing mandatory data (email, display name, handle, age confirmation) is required to create an account. All other data is voluntary.

11. Automated decision-making and profiling

We use automated pre-filters for content moderation, including the third-party services named in Section 6. No automated decision within the meaning of Art. 22 GDPR (legal or similarly significant effect from automation alone) is made: every consequential moderation decision is human-reviewed before becoming permanent.

Matching / discovery features ("In your tribe", "Online now", "Top of the top", "Nearby") are pure sort/filter functions with no legal or similarly significant effect.

12. Security

We implement technical and organisational measures pursuant to Art. 32 GDPR, including TLS in transit, encryption at rest, row-level security, Apple SIWA / Google OAuth / bcrypt-based auth, and audit logging.

13. Protection of minors

BigBro is for users aged 18 and over only. At registration you must explicitly confirm that you are at least 18. We have zero tolerance for minors. Suspected CSAM is reported to NCMEC without delay.

14. Changes to this Privacy Policy

We may update this Policy from time to time. For material changes we will notify you by email or via an in-app notice before the new version takes effect.

Last updated: 2026-10-01.