GLEAP PRIVACY POLICY

Effective Date: February 22, 2026
Last Updated: February 22, 2026

This Privacy Policy explains how Gleap (“we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you use the Gleap mobile application and related services (collectively, the “Service”).

Gleap is operated by:

Gleap Limited
Company Number: 3219068
Registered Address: Unit 1103, 11/F, Mow Hing Industrial Building, No. 205 Wai Yip Street, Kwun Tong, Kowloon, Hong Kong

Data Protection Officer Contact:
Email: dpo@gleap.club

TABLE OF CONTENTS

  1. Information We Collect
  2. How We Collect Information
  3. How We Use Your Information
  4. How We Share Your Information
  5. Health Information and Verification
  6. Cookies and Tracking Technologies
  7. International Data Transfers
  8. Data Security
  9. Your Privacy Rights
  10. Data Retention
  11. Third-Party Links and Services
  12. Children's Privacy
  13. Changes to This Privacy Policy
  14. Contact Us
  15. Jurisdiction-Specific Provisions

1. INFORMATION WE COLLECT

1.1 Personal Data

“Personal Data” refers to information with personal identifiers that can be used separately or collectively to identify an individual.

1.2 Anonymized Data

“Anonymized Data” refers to information that is not associated with or linked to your Personal Data and cannot be used to identify individual persons.

Important: We only collect Personal Data that is necessary to provide the Service to you. Not all types of data specified below will be collected from every user.

1.3 Categories of Data We Collect

A. Account Registration Data

When you create an account, we collect:

B. Profile Information

When you complete your profile, you provide:

Note: Some of this information (such as sexual orientation and health-related lifestyle choices) may be considered sensitive or special category data in certain jurisdictions. By providing this information, you consent to our processing it as described in this Privacy Policy.

C. Health Documents (Optional)

You may voluntarily upload:

Important: We only accept and store documents showing negative test results. Documents showing positive results are automatically rejected and not stored.

D. Content You Create

E. Location Data

You can control location sharing in your device settings.

F. Usage Data

G. Device and Technical Data

H. Payment and Transaction Data (When Available)

When our paid features become available and you make purchases:

Note: All features are currently free. Payment processing will only apply when we introduce paid subscriptions in the future.

I. Customer Support Data


2. HOW WE COLLECT INFORMATION

2.1 Information You Provide Directly

2.2 Information Collected Automatically

When you use the Service, we automatically collect:

2.3 Mobile Device Identifiers

What are Mobile Device IDs? Mobile Device IDs are unique identifiers assigned to your device by the manufacturer (e.g., Apple's IDFA, Google's Advertising ID).

How we use them:

Important: Unlike cookies, Mobile Device IDs cannot be deleted. However, you can:

2.4 Information from Third Parties

2.5 Cookies and Similar Technologies

See Section 6 for detailed information about cookies.


3. HOW WE USE YOUR INFORMATION

3.1 Purpose-Based Data Processing

We process your information for the following purposes:

PurposeLegal BasisData Categories Used
To provide and maintain the Service
Create and maintain your account, enable profile browsing and discovery, facilitate messaging, process location sharing, enable rating and review features
Performance of our contract with youAccount Data, Profile Data, Content, Location Data, Usage Data, Technical Data
To process payments and subscriptions (when available)
Process transactions, manage subscriptions, apply promotional codes
Performance of our contract with youAccount Data, Payment Data, Transaction History
To verify health information
Review uploaded health documents, display verification badges, store health documents securely
Your explicit consentHealth Documents, Account Data, Profile Data
To keep you and others safe
Detect and prevent violations of Terms, investigate reports of abuse, verify user identity and age, monitor rating system integrity, prevent banned users from rejoining, respond to legal requests
Our legitimate interest in keeping users safe; Performance of our contract with you; Protection of vital interests; Legal obligationsAccount Data, Profile Data, Content, Rating Data, Location Data, Technical Data, Usage Data, Reports, Device Data
To improve and develop the Service
Analyze usage patterns, develop new features, test and optimize performance, conduct research
Our legitimate interest in improving the Service; Your consent (for sensitive data analysis)Usage Data, Technical Data, Anonymized Aggregate Data
To communicate with you
Send service notifications, respond to support requests, send rating prompts, share updates about the Service
Performance of our contract with you; Our legitimate interestAccount Data, Customer Support Data, Usage Data
To personalize your experience
Show relevant profiles, customize your experience
Performance of our contract with you; Our legitimate interestProfile Data, Usage Data, Preferences, Location Data
To comply with legal obligations
Respond to law enforcement requests, comply with court orders, preserve evidence for legal proceedings, comply with financial regulations
Legal obligations; Our legitimate interest in defending legal claimsAll data categories as necessary depending on the legal requirement

3.2 Legal Bases for Processing (GDPR/UK GDPR)

Where we process your personal data, we do so under one or more of the following legal bases:

You have the right to object to processing based on legitimate interest. See Section 9 for how to exercise this right.

3.3 No Automated Decision-Making

We do not use fully automated decision-making systems that produce legal or similarly significant effects on you. While we may use technology to assist with certain functions (such as showing you profiles based on your preferences or detecting potential Terms violations), all significant decisions involve human review.

3A. WHAT WE DON'T DO WITH YOUR DATA

We do not:

We never ask for:


4. HOW WE SHARE YOUR INFORMATION

4.1 Information Visible to Other Users

When you create a profile on Gleap, certain information is visible to other users:

What other users CANNOT see:

What other users CAN see about ratings:

4.2 Service Providers and Partners

We share your data with trusted third-party service providers who assist us in operating the Service:

CategoryPurposeData Shared
Cloud hosting and storageStoring your data securely (AWS S3 Sydney)All data categories
Payment processors (when available)Processing subscriptions and payments (Apple In-App Purchase, Google Play Billing)Payment Data, Account Data, Transaction Data
Customer support toolsProviding assistance and resolving issuesCustomer Support Data, Account Data
Identity verificationAge verification servicesAccount Data (date of birth), Device Data
Email/SMS providersSending notifications and updatesAccount Data (email/phone), Usage Data
Content moderationReviewing reported content for safetyContent, Reports, Profile Data
Security and fraud preventionDetecting fraud and abuseDevice Data, Technical Data, Usage patterns

Contractual protections: All service providers are bound by contracts requiring them to:

4.3 Legal and Safety Disclosures

We may disclose your information to:

Law Enforcement and Government Authorities:

Safety and Protection:

Legal Proceedings:

4.4 Business Transfers

If Gleap is involved in a merger, acquisition, sale of assets, bankruptcy, or other business transaction:

4.5 With Your Consent

We may share your information with other parties when you give us explicit consent to do so (e.g., if you choose to share your profile on social media).

4.6 Aggregated and Anonymized Data

We may publicly share aggregated or anonymized information that cannot identify you individually, such as:


5. HEALTH INFORMATION AND VERIFICATION

5.1 Health Document Uploads (Optional)

Gleap allows you to voluntarily upload STD/STI test results to verify your health status to potential matches.

What We Accept:

What We Do NOT Accept:

5.2 How Health Documents Are Processed

Review Process:

Storage and Security:

5.3 Health Verification Badge

Once your health document is verified:

5.4 Your Control Over Health Data

You cannot manually delete health documents. Instead:

5.5 Legal Basis for Processing Health Data

Health information is considered “special category” or “sensitive” personal data under GDPR, UK GDPR, and other privacy laws.

Legal Basis:

5.6 Health Data Retention

5.7 No Medical Advice

Important Disclaimer:

  • Gleap is NOT a medical service or healthcare provider
  • We do not provide medical advice, diagnosis, or treatment
  • Health verification is for informational purposes only
  • You should consult qualified healthcare professionals for medical advice
  • We are not liable for the accuracy of user-uploaded health documents
  • Health verification does not guarantee a user's current health status

6. COOKIES AND TRACKING TECHNOLOGIES

6.1 What Are Cookies?

Cookies are small text files stored on your device when you use the Service. They help us recognize your device and remember your preferences.

6.2 Types of Technologies We Use

In the Mobile App:

On Our Website (gleap.club):

6.3 Cookies We Use on Our Website

Cookie TypePurposeCan be Disabled?
Essential/Strictly NecessaryEnable core website functionality (login, account access)No (website won't work without them)
FunctionalRemember your preferences (language, region)Yes

Note: We do NOT use third-party analytics cookies or advertising cookies.

6.4 How to Manage Cookies

Browser Settings: Most browsers allow you to block or delete cookies:

Mobile App Settings:

Impact of Disabling Cookies:

6.5 No Third-Party Tracking

We do not use:

Your activity on Gleap is not shared with or tracked by third-party analytics companies.

6.6 Do Not Track Signals

Some browsers have “Do Not Track” (DNT) settings. Currently, there is no industry standard for responding to DNT signals. We respect your privacy and minimize tracking to only what's necessary for Service functionality.


7. INTERNATIONAL DATA TRANSFERS

7.1 Where Your Data Is Stored

Gleap operates globally, and your data may be transferred to, stored in, and processed in countries other than your country of residence.

Primary Data Storage Location: AWS S3 servers located in Sydney, Australia

Data May Be Accessed From:

7.2 Cross-Border Transfer Protections

When we transfer your data outside of your country, we ensure appropriate safeguards are in place:

For EEA, UK, and Swiss Users:

For Australian Users:

For Singapore Users:

For All Users:

7.3 Your Rights Regarding Transfers

You have the right to:

To exercise these rights, contact dpo@gleap.club.


8. DATA SECURITY

8.1 How We Protect Your Data

We implement industry-standard security measures to protect your personal information from unauthorized access, use, alteration, and destruction.

Technical Safeguards:

Organizational Safeguards:

Physical Safeguards:

8.2 Your Role in Security

You can help protect your account by:

8.3 Data Breach Notification

Despite our best efforts, no system is 100% secure. In the unlikely event of a data breach affecting your personal information:

What we will do:

What you should do:

Our commitment: We take data security seriously and continuously invest in systems to detect, prevent, and respond to security incidents.

8.4 Limitations

While we implement robust security measures, we cannot guarantee absolute security. You acknowledge that:


9. YOUR PRIVACY RIGHTS

We want you to be in control of your data. Depending on where you live, you have the following rights. The specific rights available to you may vary based on your jurisdiction.

9.1 Universal Rights (Available to All Users)

RightDescriptionHow to Exercise
AccessRight to know what personal data we hold about youView profile data directly in the app; Request full data export: dpo@gleap.club; Response time: 30 days
Rectification (Correction)Right to correct inaccurate or incomplete dataUpdate profile directly in app settings; For other data: dpo@gleap.club
Deletion (Erasure)Right to delete your personal dataDelete account via app: Settings → Account → Delete Account; Email request: dpo@gleap.club; Some data retained for legal obligations (see Section 10)
PortabilityRight to receive your data in a machine-readable formatRequest data export: dpo@gleap.club; Format: JSON file; Includes: profile data, messages, ratings (aggregate), usage history
Object/Opt-OutRight to object to certain data processingOpt out of marketing emails: app settings or email unsubscribe link; Object to processing: dpo@gleap.club; Note: May limit Service functionality
Withdraw ConsentRight to withdraw consent for specific processingHealth documents: expire after 90 days or delete account; Location sharing: device settings; Marketing: app settings or unsubscribe link; Email for assistance: dpo@gleap.club
Lodge ComplaintRight to complain to a data protection authoritySee Section 9.8 for relevant authorities in your jurisdiction

9.2 Additional Rights for EEA, UK, and Swiss Users (GDPR/UK GDPR)

9.3 Additional Rights for California Users (CCPA/CPRA)

For California-specific requests: dpo@gleap.club with subject line “California Privacy Request”

9.4 How to Exercise Your Rights

Step 1: Verify Your Identity

For your protection, we must verify your identity before fulfilling requests. We may ask for:

Step 2: Submit Your Request

Step 3: We Respond

9.5 Requests We May Decline

We may decline requests if:

If we decline your request, we will explain why and inform you of your right to appeal or complain to a supervisory authority.

9.6 Appeals Process (For Certain US States)

If you are a resident of Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Kentucky, Rhode Island, Maryland, Tennessee, Minnesota, Delaware, Nebraska, New Hampshire, New Jersey, Texas, Oregon, or Montana, and we deny your privacy request:

9.7 Authorized Agents (California & Other States)

You may designate an authorized agent to submit requests on your behalf. The agent must provide:

We may still require you to verify your identity directly.

9.8 Data Protection Authorities

If you believe we've violated your privacy rights, you can lodge a complaint with the relevant supervisory authority:


10. DATA RETENTION

10.1 How Long We Keep Your Data

We retain your personal information only as long as necessary for the purposes outlined in this Privacy Policy and as required by law.

General Retention Principles:

10.2 Safety Retention Period

After you close your account or are banned, we retain certain data for a reasonable period to:

Data retained during safety period:

Data NOT retained:

10.3 Legal Data Retention

We retain certain data to comply with legal obligations:

10.4 Data Retention After Specific Actions

If you let health documents expire (90 days):

If you delete your account:

If you delete specific messages:

If you delete profile photos:

10.5 Anonymized and Aggregate Data

What is Anonymized Data? Anonymized Data is information that has been processed to remove all personal identifiers, so it cannot be used to identify you individually.

Examples:

How we use it:

Retention: Anonymized and aggregate data may be retained indefinitely because it cannot identify you personally.

Your rights: Because anonymized data cannot identify you, data subject rights (access, deletion, etc.) do not apply to anonymized data under most privacy laws (GDPR, CCPA, etc.).

10.6 Data Deletion Process

When data is scheduled for deletion:

Note: Data deleted from our systems may remain in backups temporarily during normal backup rotation cycles.


11. THIRD-PARTY LINKS AND SERVICES

11.1 External Links

The Service may contain links to third-party websites, apps, or services (e.g., health clinics, testing centers, social media platforms).

Important:

  • These third parties are not governed by this Privacy Policy
  • We are not responsible for their privacy practices or content
  • We do not control how they collect or use your information
  • Linking does not imply endorsement

Before using external services:

11.2 Third-Party Payment Processors (When Available)

When we introduce paid features, we will use third-party payment processors to handle transactions:

What they will collect: Payment card information, billing address, transaction details

What we will receive: Transaction confirmation, subscription status, transaction ID (no full card numbers)

Their privacy policies:

11.3 Social Media Platforms

If you share content from Gleap to social media (e.g., “Check out my profile”), the social media platform may collect information about your activity.

We do not:

11.4 Health Testing Providers

We may provide links to STD/STI testing clinics or services for your convenience.

Important:

  • We are not affiliated with these providers
  • We do not receive your test results from them
  • You must manually upload results to Gleap (if you choose)
  • We are not responsible for the accuracy of their tests
  • Review their privacy policies before using their services

11.5 No Liability

You agree that Gleap is not liable for:

Use third-party services at your own risk.


12. CHILDREN'S PRIVACY

12.1 Age Requirement

Gleap is restricted to individuals who are 18 years of age or older.

We do not knowingly collect personal information from anyone under 18 years of age. If you are under 18, do not use the Service, do not create an account, and do not provide any information to us.

12.2 If You Are a Parent or Guardian

If you believe your child under 18 has created an account or provided us with personal information:

Step 1: Contact Us Immediately

Step 2: Provide the Following Information

Step 3: We Will Take Action

12.3 Reporting Underage Users

If you suspect another user is under 18:

In-App Reporting:

Email Reporting:

We will investigate all reports promptly, request age verification if necessary, suspend and delete accounts confirmed to be underage, and ban users who misrepresent their age.

12.4 Age Verification

To enforce our age requirement:

12.5 No Liability for Misrepresentation

While we take age verification seriously:

12.6 Educational Purpose

If you are a parent, please:


13. CHANGES TO THIS PRIVACY POLICY

13.1 Updates

We may update this Privacy Policy from time to time to reflect:

Current Version:

13.2 Notice of Material Changes

Before any material changes take effect (e.g., changes to how we use sensitive data, new data sharing practices, reduced rights), we will:

Notify You:

Advance Notice:

13.3 Non-Material Changes

For minor changes (e.g., clarifications, typos, formatting), we will:

13.4 Your Continued Use

By continuing to use the Service after changes take effect, you accept the updated Privacy Policy.

If you don't agree with changes:

13.5 Archived Versions

Previous versions of this Privacy Policy are available upon request:


14. CONTACT US

14.1 General Inquiries

For questions about this Privacy Policy, our data practices, or the Service:

Data Protection Officer:
Email: dpo@gleap.club
Response Time: Within 5 business days

Customer Support:
Email: support@gleap.club
In-App: Settings → Help & Support
Response Time: Within 24-48 hours

14.2 Privacy Requests

To exercise your privacy rights (access, deletion, correction, etc.):

14.3 Security Concerns

To report security vulnerabilities or data breaches:

14.4 Mailing Address

Gleap Limited
Unit 1103, 11/F
Mow Hing Industrial Building
No. 205 Wai Yip Street
Kwun Tong, Kowloon
Hong Kong

Company Number: 3219068

14.5 Response Times


15. JURISDICTION-SPECIFIC PROVISIONS

15.1 European Economic Area (EEA), United Kingdom, and Switzerland

Legal Basis for Processing: See Section 3.2 for detailed legal bases under GDPR/UK GDPR.

Your Rights: Enhanced rights under GDPR/UK GDPR as detailed in Section 9.2.

Data Controller: Gleap Limited (contact details in Section 14.4)

Data Protection Officer: dpo@gleap.club

Supervisory Authority: You have the right to lodge a complaint with your local data protection authority:

Data Transfers: We use Standard Contractual Clauses (SCCs) for transfers outside the EEA/UK/Switzerland (see Section 7).

15.2 Australia

Australian Privacy Principles (APPs): We comply with the Privacy Act 1988 (Cth) and APPs.

Your Rights:

Complaints: If you're not satisfied with our response to a privacy complaint:

Overseas Disclosure: Your data may be disclosed to overseas recipients (see Section 7). By using the Service, you consent to these disclosures.

15.3 Singapore

Personal Data Protection Act (PDPA): We comply with Singapore's PDPA 2012.

Your Rights:

Complaints: If you have concerns about our data practices:

Do Not Call (DNC) Registry: We respect Singapore's DNC Registry. If you've registered your number, we will not send marketing calls/SMS unless you've given explicit consent.

15.4 Hong Kong

Personal Data (Privacy) Ordinance: We comply with Hong Kong's PDPO.

Data User: Gleap Limited (Company Number: 3219068)

Your Rights:

Complaints: Contact the Office of the Privacy Commissioner for Personal Data:

15.5 New Zealand

Privacy Act 2020: We comply with New Zealand's Privacy Act.

Your Rights:

Complaints: Contact the Office of the Privacy Commissioner:

15.6 California, USA

California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA):

Your Rights:

Categories of Personal Information Collected: See Section 1.3 for detailed categories.

Business Purpose for Collection: See Section 3 for purposes.

Categories of Third Parties We Share With: See Section 4 for recipients.

Do Not Sell My Personal Information: We do not sell personal information. If this changes, we will provide an opt-out.

Shine the Light Law: California residents can request information about personal information disclosed to third parties for their direct marketing purposes (once per year, free of charge).

To Exercise Your Rights:

Authorized Agents: You may designate an authorized agent to make requests on your behalf (see Section 9.7).

Response Time: Within 45 days (may extend to 90 days for complex requests).

15.7 Other US States (Virginia, Colorado, Connecticut, Utah, etc.)

Many US states have enacted comprehensive privacy laws similar to California's CCPA. If you reside in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Iowa, Indiana, Kentucky, Rhode Island, Maryland, Tennessee, Minnesota, Delaware, Nebraska, New Hampshire, New Jersey, Texas, Oregon, or Montana:

Your Rights (generally include):

To Exercise Your Rights: Email dpo@gleap.club with subject “[Your State] Privacy Request”

Response time: Typically 45 days

Appeals: If we deny your request, you may appeal (see Section 9.6).

15.8 Canada

Personal Information Protection and Electronic Documents Act (PIPEDA):

Your Rights:

Complaints: Contact the Office of the Privacy Commissioner of Canada:

15.9 Brazil

Lei Geral de Proteção de Dados (LGPD):

Your Rights:

Data Controller: Gleap Limited

Data Protection Officer (Brazil): Email: dpobrazil@gleap.club

Complaints: Contact Autoridade Nacional de Proteção de Dados (ANPD):

15.10 Other Jurisdictions

If your jurisdiction is not specifically listed above, we will:

To inquire about your jurisdiction: Email dpo@gleap.club with your location and specific questions.


16. ACCEPTANCE OF THIS POLICY

By creating an account and using Gleap, you acknowledge that you have read, understood, and agree to this Privacy Policy.

This Privacy Policy is incorporated into and forms part of our Terms and Conditions.

If you do not agree with this Privacy Policy, you must not use the Service.


End of Privacy Policy

Last Updated: February 22, 2026 — Version: 1.0

Copyright © 2026. GLEAP LIMITED. All rights reserved.