Privacy Policy

Last Updated: July 12, 2026

1. Introduction

Welcome to Together. We value the trust you place in us to safeguard your focus and co-working environments. We recognize that virtual body doubling requires sharing focus spaces, and we are committed to ensuring your personal data remains private and protected.

This Privacy Policy explains how Together collects, processes, and stores your information. Our core philosophy is data minimization: we only request permissions necessary to deliver our body doubling matches and Focus Spaces, and we do not monitor or save your focus interactions.

2. Cloud Database & Row-Level Security (RLS)

For signed-in Supabase users, restrictions, blocks, reports, friends, profile/history/settings, and friend visibility settings are cloud-backed using Supabase database tables protected by strict Row-Level Security (RLS). Local profile state no longer decides restriction or friend truth.

Active account restrictions are checked directly from Supabase before enabling or initiating partner sessions.

3. Native Screenshot Protection

Partner sessions activate native operating system screen protection to guard visual privacy:

  • iOS Protection: Detects screenshot attempts during active partner sessions.
  • Android Protection: Natively blocks screenshot capture and listens for Android 14+ screen capture callbacks where available.
  • Automated Restriction: Repeated screenshot attempts automatically create a 4-hour partner-session restriction to prevent privacy violations.

4. Structured Safety Reports & Evidence Storage

Together provides a structured safety reporting system. Reports include typed reasons: under 18, harassment, sexual content, threats, spam/scam, or other safety concern.

Submitting a report immediately leaves the media room first so the partner is notified, submits the report, and restricts the reported user.

Evidence handling: For camera-session reports, Together captures a short proof clip that is uploaded securely to Supabase storage. Local temporary evidence files are deleted immediately after the upload attempt, and local file paths are never stored in database report rows. Report restrictions are executed via constrained database Remote Procedure Calls (RPCs) rather than broad client write privileges.

5. Explicit Blocking & Friend Visibility Controls

Explicit Blocking: Choosing "Block User" creates an explicit database block row. Matchmakers query active block rows at session initiation and exclude blocked users from pairing. Reporting no longer creates hidden block rows.

Friend & Streak Controls: Friend requests and accepted friends are fetched from Supabase RLS tables. Users can disable receiving friend requests and choose to publicly hide their focus streak.

6. Media Permissions & Account Cleanup (Right to Erasure)

Authenticated Media Access: Camera and voice sessions require explicit device hardware permissions and cloud user sign-in. LiveKit media identity tokens are validated before voice or camera partner sessions begin.

Account Cleanup & Erasure: Account deletion purges all local device profile data and permanently deletes the Supabase authentication user along with associated cloud data cleanup paths.

7. Infrastructure & Data Processors

We work with trusted infrastructure providers to deliver reliable, safe co-working:

  • Supabase: Cloud database, authentication, and encrypted storage provider enforcing Row-Level Security (RLS) and constrained RPC safety functions.
  • LiveKit: Real-time, low-latency audio/video routing. Media streams are processed ephemerally in memory with DTLS-SRTP encryption and are never written to disk.
  • RevenueCat: Handles premium subscription licensing by validating transaction tokens without collecting direct financial details.

8. Contact Information

If you have any questions about this Privacy Policy, your data permissions, or our body doubling infrastructure, feel free to submit a support ticket via our Support Center or email us directly at:

[email protected]