Privacy Policy
Effective Date: January 1, 2026
Last Updated: Dec 30, 2025
1. Introduction
Call Me JOSH LLC ("JOSH," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use the JOSH friendship matching service, including our website at callmejosh.ai, SMS messaging service, and all related features (collectively, the "Service").
By creating an account or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not access or use the Service.
This Privacy Policy is incorporated into and is subject to our Terms of Service. Capitalized terms not defined herein have the meanings set forth in the Terms of Service.
2. Information We Collect
We collect several types of information from and about users of our Service.
2.1 Information You Provide Directly
Account Registration Information
- Phone number (immediately hashed and never stored in plaintext)
- Verification codes sent via SMS
Conversational Interview Data
During your conversational interview with JOSH's AI system, you provide information through natural conversation, including:
- Personal characteristics: Name, age, gender, location (city/state)
- Lifestyle information: Work situation, living situation, daily routines, schedules
- Social preferences: Communication style, social energy levels, interaction preferences
- Interests and activities: Hobbies, passions, how you spend free time
- Values and priorities: What matters to you in friendships, life goals, personal values
- Behavioral patterns: How you handle stress, conflict, decision-making
- Relationship history: Past friendship experiences, what works/doesn't work for you
- Emotional tendencies: How you process emotions, what you need in friendships
- Conversation style: Examples of how you communicate and connect with others
This information is used to build your psychological profile for matching purposes.
Photos
- Profile photos you upload (minimum 2, maximum 6)
- Photos are stored securely and shared only as part of the matching process
Contact Information
- Email address (optional, for account recovery and notifications)
- Real phone number (hashed for privacy, used for SMS communications)
Communications
- Messages you send through SafeChat anonymous messaging
- Messages exchanged during the onboarding conversational interview
- Communications with JOSH support staff
Payment Information
- Billing information is processed and stored by Stripe, our payment processor
- We do not store complete credit card numbers
- We retain transaction history, purchase dates, and amounts paid
2.2 Information Collected Automatically
Usage Data
- Features you use within the Service
- Time and duration of your activities
- Introduction responses (accept, decline, pass)
- SafeChat engagement (message frequency, session duration)
- Reveal decisions and timing
Device Information
- Mobile device type and operating system
- Browser type and version
- IP address (anonymized for analytics)
- Device identifiers
- Time zone settings
SMS Metadata
- Message delivery status
- Timestamp of messages sent and received
- Message routing information (not message content)
Analytics Data
- Aggregated, anonymized usage patterns
- Feature adoption rates
- Service performance metrics
- Error logs and crash reports
2.3 Information from Third Parties
Service Providers
- Twilio: SMS delivery status and metadata
- Stripe: Payment processing information and transaction status
- Anthropic: AI processing results (no storage of your data by Anthropic)
We do not purchase or receive personal information about you from data brokers or other third-party sources.
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Core Service Operations
Friendship Matching
- Building your psychological profile through conversational interview analysis
- Identifying compatible matches using AI-powered compatibility algorithms
- Creating introduction previews with compatibility reasoning
- Generating match recommendations based on multi-dimensional compatibility scoring
Account Management
- Creating and maintaining your account
- Verifying your identity and phone number
- Processing your registration and onboarding
- Authenticating your access to the Service
Communications
- Sending SMS messages as part of the conversational interview
- Delivering introduction previews and notifications
- Facilitating SafeChat anonymous messaging
- Sending important Service updates and security alerts
- Responding to your inquiries and support requests
- Sending Day 9 reminders for SafeChat sessions
Payment Processing
- Processing Sprint Pass purchases through Stripe
- Managing your billing information
- Maintaining transaction records
- Handling refund requests (in limited circumstances)
3.2 Service Improvement and Development
- Analyzing how users interact with the Service to improve functionality
- Identifying and fixing technical issues and bugs
- Testing new features and improvements
- Conducting research to enhance matching algorithms
- Understanding user preferences and behavior patterns
- Optimizing the conversational interview experience
3.3 Safety and Security
- Detecting and preventing fraud, abuse, and violations of our Terms of Service
- Monitoring for safety concerns including harassment, scams, and crisis situations
- Responding to safety incidents and user reports
- Protecting against unauthorized access or use of the Service
- Complying with legal obligations and law enforcement requests
- Enforcing our Terms of Service and other policies
3.4 Analytics and Aggregated Data
- Creating anonymized, aggregated statistics about Service usage
- Understanding demographic trends and user preferences
- Measuring the effectiveness of our matching algorithms
- Reporting on business metrics and service performance
Important: We only use aggregated and anonymized data for analytics. Individual user data is never sold or shared for advertising purposes.
3.5 Legal Compliance
- Complying with applicable laws, regulations, and legal processes
- Responding to lawful requests from government authorities
- Protecting our legal rights and interests
- Preventing illegal activity and enforcing our policies
5. SafeChat Privacy Protections
SafeChat is our privacy-protected anonymous messaging system. We implement multiple layers of protection to keep your identity private during the SafeChat phase.
5.1 Masked Phone Numbers
- All SafeChat messages are routed through Twilio proxy numbers
- Your real phone number is never visible to the other person
- The other person sees only a temporary masked number
- Both parties communicate through masks until mutual Reveal
5.2 Phone Number Hashing
- Real phone numbers are immediately hashed using HMAC-SHA256
- Plaintext phone numbers are never stored in our database
- Hashes are used only for message routing and cannot be reversed
- This prevents unauthorized access to your real phone number
5.3 Message Encryption
All SafeChat messages are encrypted at rest using AES-256-GCM:
- Each message is encrypted with a unique initialization vector (IV)
- Authentication tags ensure message integrity
- Encryption keys are stored separately from message data
- Messages are decrypted only during relay, never for storage or display
5.4 Number Pool Management
After a SafeChat session ends:
- The masked phone number enters a 72-hour cooldown period
- The number cannot be immediately reused for another session
- This prevents psychological association between different matches
- Numbers are rotated to maintain anonymity
5.5 Automatic Session Closure
- SafeChat sessions automatically close after 10 days
- Upon closure, masked numbers are released
- No further messages can be sent through the session
- Conversation history remains encrypted in our database
5.6 No Staff Access to Content
- JOSH staff cannot read your SafeChat messages without legal warrant
- Encrypted messages can only be decrypted by automated systems for relay
- Safety monitoring uses automated keyword detection, not human review
- In crisis situations, we may access encrypted content to ensure user safety
6. Data Security
We implement industry-standard security measures to protect your information.
6.1 Technical Security Measures
- Encryption in Transit: All data transmitted between your device and our servers uses HTTPS/TLS encryption
- Encryption at Rest: Sensitive data including SafeChat messages is encrypted in our database
- Phone Number Hashing: Real phone numbers are never stored in plaintext
- Secure Authentication: Magic links with HMAC signatures for identity verification
- Access Controls: Strict role-based access controls for staff and systems
- Regular Security Audits: Ongoing review of security practices and vulnerabilities
6.2 Organizational Security Measures
- Background checks for employees with access to user data
- Confidentiality agreements for all staff and contractors
- Security training for employees
- Incident response procedures for data breaches
- Regular backups with encryption
- Monitoring and logging of system access
6.3 Third-Party Security
Our service providers (Twilio, Stripe, Anthropic, Supabase, Vercel) maintain:
- SOC 2 Type II compliance (where applicable)
- GDPR compliance
- Industry-standard security certifications
- Regular third-party security audits
6.4 No Guarantee of Absolute Security
While we implement strong security measures, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information. You use the Service at your own risk.
6.5 Your Security Responsibilities
You are responsible for:
- Maintaining the security of your phone and any devices used to access the Service
- Not sharing your account access with others
- Reporting any suspected unauthorized access immediately
- Using secure passwords if you create web account credentials
- Logging out from shared devices
7. Data Retention
We retain your information for different periods depending on the type of data and purpose.
7.1 Active Account Data
While your account is active, we retain:
- Profile information and conversational interview data
- Photos and personal information needed for matching
- SafeChat message history (encrypted)
- Introduction history and match data
- Account settings and preferences
- Payment transaction records
7.2 After Account Deletion
When you delete your account, we handle data as follows:
Deleted Within 30 Days:
- Profile information (name, age, photos, location)
- Conversational interview data
- Unencrypted personal information
- Account preferences and settings
The 30-day period allows account recovery if you change your mind.
Deleted Immediately:
- Encrypted SafeChat messages
- Active SafeChat sessions (closed)
- Access to the Service
Retained for Legal/Financial Compliance:
- Transaction records and payment history: 7 years (IRS requirement)
- Legal hold data: Until legal matter is resolved
- Safety incident reports: As required by law
Retained Indefinitely (Anonymized):
- Aggregated analytics data with no personal identifiers
- Statistical information about Service usage patterns
- De-identified research data
7.3 Inactive Accounts
If your account is inactive for 24 consecutive months:
- We may send a reminder asking if you want to keep your account
- If no response after 30 days, we may delete your account
- Data retention follows the same schedule as user-initiated deletion
7.4 Legal Obligations
We may retain information longer if required by:
- Law or regulation
- Pending litigation or government investigation
- Terms of Service enforcement actions
- Fraud prevention and security purposes
8. Your Rights and Choices
You have certain rights regarding your personal information.
8.1 Access Your Information
You can:
- View your profile information in the Service
- Request a copy of your personal data by emailing help@callmejosh.ai
- We will provide your data in a portable format within 30 days
8.2 Correct Your Information
You can:
- Update your profile information at any time through account settings
- Contact us at help@callmejosh.ai to correct inaccurate information
- We will update your information within 15 business days
8.3 Delete Your Information
You can:
- Delete your account at any time through account settings
- Request deletion by emailing help@callmejosh.ai
- Deletion follows the retention schedule in Section 7
Note: Some information may be retained as required by law or for legitimate business purposes.
8.4 Opt Out of Communications
You can control communications:
Marketing Messages:
- Reply STOP to any marketing SMS to unsubscribe
- Click "unsubscribe" in marketing emails
- Update preferences in account settings
Service Communications:
- You cannot opt out of essential Service messages (introduction notifications, SafeChat messages, payment confirmations, security alerts)
- These are necessary for Service operations
Complete Opt-Out:
- Text STOP to opt out of all JOSH communications
- This will close your account and you cannot resume Service
8.5 Data Portability
Upon request, we will provide:
- Your profile information in JSON or CSV format
- Your conversational interview transcript
- Your match history and introduction data
- Information in a commonly used, machine-readable format
8.6 California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information we collect, use, disclose, and sell
- Right to request deletion of your personal information
- Right to opt out of the sale of personal information (note: we do not sell personal information)
- Right to non-discrimination for exercising your privacy rights
To exercise these rights, contact us at help@callmejosh.ai with "California Privacy Request" in the subject line.
8.7 Nevada Privacy Rights
Nevada residents who wish to exercise their sale opt-out rights may submit a request to help@callmejosh.ai. Note: We do not currently sell personal information as defined by Nevada law.
9. Children's Privacy
JOSH is not intended for individuals under 18 years of age. We do not knowingly collect personal information from anyone under 18.
If you are a parent or guardian and believe your child has provided personal information to JOSH:
- Contact us immediately at help@callmejosh.ai
- We will delete the information within 48 hours
- We will terminate the account
If we discover that we have collected information from someone under 18, we will:
- Immediately delete all associated information
- Terminate the account
- Block the phone number from future registration
10. International Users
JOSH is currently available only to residents of the United States. The Service is operated from the United States, and information is processed and stored in the United States.
If you access the Service from outside the United States, you acknowledge that:
- Your information will be transferred to and processed in the United States
- U.S. privacy laws may differ from those in your country
- By using the Service, you consent to transfer and processing of your information in the United States
We do not knowingly collect information from users outside the United States. If you are not a U.S. resident, please do not use the Service.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will:
- Update the "Last Updated" date at the top of this policy
- Notify you via SMS if the changes are material
- Post a prominent notice in the Service
- Send an email to the address associated with your account (if provided)
Material changes include:
- Changes to what information we collect
- Changes to how we use your information
- Changes to information sharing practices
- Reduction in your rights or protections
Your continued use of the Service after the effective date of the revised Privacy Policy constitutes your acceptance of the changes. If you do not agree to the revised policy, you must stop using the Service and may delete your account.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
12. Third-Party Links and Services
The Service may contain links to third-party websites, services, or resources that are not owned or controlled by JOSH. This Privacy Policy applies only to information collected by JOSH.
We are not responsible for:
- The privacy practices of third-party websites or services
- The content of external links
- Any information you provide to third parties
We encourage you to review the privacy policies of any third-party services before providing them with personal information.
13. Do Not Track Signals
Some web browsers include a "Do Not Track" (DNT) feature that signals to websites you visit that you do not want your online activity tracked. Currently, there is no established standard for how DNT signals should be interpreted. JOSH does not currently respond to DNT signals from browsers.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Call Me JOSH LLC
Email: help@callmejosh.ai
For Privacy-Specific Inquiries:
- Data access requests: Include "Data Access Request" in subject line
- Data deletion requests: Include "Data Deletion Request" in subject line
- California privacy rights: Include "California Privacy Request" in subject line
- General privacy questions: Include "Privacy Inquiry" in subject line
We will respond to all privacy inquiries within 30 days.
15. Effective Date and Acceptance
This Privacy Policy is effective as of the date listed at the top of this document. By creating an account or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.
Last Updated: Dec 30, 2025