Privacy notice
Effective August 21, 2026 · Contact: support@anonymouscrush.com
The short version
We run a service whose entire point is discretion, and the data practices follow from that. We collect only what the service needs to work. Crush entries are stored as one-way cryptographic fingerprints, not readable addresses. We never notify someone they were entered, never confirm whether an address has an account, and never sell or share data for advertising. There are no analytics trackers, no ad pixels, and no photos anywhere in the product. Anyone — member or not — can permanently exclude their email address from matching.
Who we are
AnonymousCrush (“we,” “us”) operates anonymouscrush.com, a private reciprocal-interest service for adults: you privately enter the email address of someone you like, and both of you are notified only if you have each entered the other. For anything in this notice, write to support@anonymouscrush.com.
What we collect, and why
Account data. Your email address(es), a display name, a password hash (never the password itself), and — if you sign in with Google — the name and email address Google provides. Optional profile fields you may fill in (first name, full name, short bio, general location, interests) exist solely so that you can choose to reveal them, field by field, to a mutual match; they are never public and never shown to anyone without your per-field consent.
Crush entries. When you enter someone's email address, we do not store that address in readable form. We store a keyed one-way cryptographic fingerprint (an HMAC) plus a short display mask (like a•••@g•••.com) so you can recognize your own entries. Your optional private nickname and private note are visible only to you. An optional “sealed note” is stored encrypted and is decrypted exactly once — if a mutual match forms and both people open messaging — and is destroyed unread on every other path.
Match and consent records. Which of your entries matched, each side's accept/decline choices, per-field reveal consents, and messaging consents.
Messages. Only after a mutual match where both people separately allow messaging. Messages may be reviewed by our safety staff if a participant reports the conversation.
Safety records. Blocks, reports, and moderation outcomes; the permanent opt-out list (below); and addresses our email provider tells us have bounced or complained, so we stop mailing them.
Operational data. Session cookies, short-lived rate-limit counters, notification records, problem reports you submit, server error logs (error message, stack trace, and route only — we never log request bodies, form contents, or conversation messages), and aggregate traffic counters: sitewide page views and unique visitors per day, and nothing per person. Uniqueness is derived from a one-way, daily-rotating code built from connection data — the codes cannot be linked across days, are deleted within two days, and involve no cookies and no stored addresses. We also process your IP address briefly for abuse prevention: it appears in short-lived rate-limit counters (deleted within about two days) and in our hosting provider's standard request logs. Beyond that we collect nothing else, and we do not buy, scrape, or enrich data about you or the people you enter.
What we deliberately don't have
No photos or images of people, anywhere in the product. No third-party analytics or advertising trackers. No ad networks. No social-media pixels. No cookies beyond those strictly necessary to keep you signed in and complete sign-in flows — which is why you don't see a cookie banner. No location tracking. No contact uploads or address-book access. No public profiles and no browsing: there is nothing on this service that lets anyone look anyone else up.
The promises that define the service
We never notify a person that they were entered as a crush. We never confirm or deny — to anyone, including the person asking — whether an email address has an account, was entered by someone, or was blocked. (One narrow, deliberate exception: an entry naming an address that has permanently opted out is refused without explanation — enforcing the opt-out requires refusing the entry.) Closed matches look the same regardless of why they closed, so nobody learns who declined. Every email template our system can send is published at /emails; all are deliberately uninformative on a lock screen, and none hints that “someone likes you.”
If you're not a member
Someone may have entered your email address as their crush. If so: we hold only the one-way fingerprint and display mask described above, we do not contact you about it, we never confirm to anyone (including you, including them) whether it happened, and nothing can ever come of it unless you independently join, verify that address, and enter that person yourself.
You can permanently exclude your address from matching — without creating an account — at /privacy/opt-out. Each opt-out request triggers a single confirmation email to that address (requests are rate-limited); confirming completes the exclusion and we send nothing further about it. To enforce the exclusion we retain a record derived from your address — its one-way fingerprint plus a masked form (like a•••@g•••.com) — and a log entry that the opt-out was confirmed; enforcing the exclusion is those records' only use.
Service providers
We use a small number of infrastructure providers who process data on our behalf under their own contractual and security obligations: Vercel (hosting), Neon (database), Resend (outbound email delivery), Cloudflare (Turnstile, the bot check on our registration and opt-out forms when enabled, which processes your IP address and browser signals), and ImprovMX (forwarding of email sent to our support address). Google processes your sign-in if you choose “Sign in with Google.” We share only what each provider needs to perform its function; none of them may use your data for their own purposes, and no provider ever stores a crush target in readable form — the address is converted to its one-way fingerprint during the request, and only the fingerprint and mask are kept. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
How long we keep things
Crush entries last for the seal length you choose (one month to one year) and end unless you renew them; you can withdraw an entry at any time and delete closed entries from your history. Sealed notes are destroyed whenever delivery becomes impossible — immediately on explicit closures, within about an hour otherwise. Notifications are deleted after 90 days, server error logs after 30 days, and expired session and token records shortly after they lapse. Messages in a matched conversation are kept while the match record exists, so the other person's copy of the conversation survives; problem reports (including any contact email you volunteer with one) and moderation and audit records are kept as long as we need them for safety and accountability.
If you delete your account: your active entries are withdrawn, live matches close neutrally, your profile details and password are erased, your email addresses are deleted outright, your unmatched entry history is deleted, matched entries are stripped of everything personal (nicknames, notes, the address mask), and messages you sent are erased — the other person sees “message removed.” What remains is a minimal anonymous account shell (needed so the other side's records stay coherent) plus the safety records above: the opt-out list, moderation records, the bounce list, and audit history.
Security
Crush targets are stored as keyed one-way fingerprints; sealed notes are encrypted at rest; passwords are stored as bcrypt hashes; all traffic is encrypted in transit (TLS); and administrative access to personal data is purpose-limited, with access to the most sensitive records — member accounts, report cases, and the problem-report queue — individually logged. No method of storage or transmission is perfectly secure, and we don't claim otherwise — our approach is to hold as little readable data as the service can function on, so there is less to lose.
Your rights and choices
You can read, change, or delete nearly everything yourself: profile fields and reveal choices in the app, entries on your crushes page, your account under Settings (pause or full deletion). For anything else — a copy of your data, a correction, or a deletion request — email support@anonymouscrush.com and a person will respond.
Depending on where you live (for example, the EU/EEA and UK under GDPR, or California under the CCPA/CPRA), you may have formal rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to not be discriminated against for exercising them. We honor these requests for everyone, wherever you live, subject to the narrow retention described above. We do not sell personal information, so there is nothing to opt out of selling. Where GDPR applies, our legal bases are performance of our contract with you (running the service), your consent (optional fields, sealed notes), and legitimate interests (safety, security, and abuse prevention). You may also lodge a complaint with your local data protection authority.
Age
AnonymousCrush is for adults 18 and over. We do not knowingly collect information from anyone under 18; if we learn an account belongs to a minor, we delete it. If you believe a minor is using the service, tell us at support@anonymouscrush.com.
Changes to this notice
If we change this notice in a way that matters, we'll update the date above and, for significant changes, tell members through the service. We will never quietly weaken the promises in “The promises that define the service.”
