Privacy Policy
Last updated: September 2026
This Privacy Policy describes what information sugarFRUIT collects, why, and the choices you have about it. It's written in plain English rather than dense legal language — if anything here is unclear, that's a gap in the policy, not a trap in the wording.
This policy covers sugarFRUIT's website and community features. It should be read together with our Terms of Use and Community Guidelines.
1. Information you give us
Account information: when you sign up, we collect your email address, a password (stored securely by our authentication provider, never visible to us as plain text), and your date of birth, which we use to confirm you meet the 18+ minimum age for sugarFRUIT.
Profile information: nickname, photos, About Me text, prompt answers, and other details you choose to add to your profile.
Content you create: messages you send, Group posts and replies, Event submissions, and reports you file about other content or members.
Settings and preferences: things like your Who's Online visibility, Discover visibility, profile-gesture preference, and light/dark theme choice.
2. Information collected automatically
Like most web services, our hosting and security infrastructure processes ordinary technical information as part of serving each request — things like IP address, browser/device type, and request timestamps, in standard server logs. We don't use this to build advertising profiles.
If you accept optional analytics cookies (see Section 4), we also receive aggregated, privacy-conscious usage information through Google Analytics, described below.
Separately from Analytics, and regardless of your cookie choice, we keep a basic record on your account of when you were last active on sugarFRUIT. This is first-party operational information our team uses internally to understand overall site usage — it's never shared, and never used for advertising.
3. Necessary cookies
sugarFRUIT uses one category of cookie that's always on: authentication/session cookies set by our authentication provider (Supabase), which keep you signed in and let the site tell your browser apart from an anonymous visitor's. These are required for login and any signed-in feature to work at all, so they aren't something you can opt out of while remaining signed in — declining optional analytics (below) never affects them.
We don't set any other necessary cookie today — no separate preferences cookie, no first-party tracking cookie. Your theme (light/dark) choice, if you're signed in, is stored on your account, not in a cookie.
4. Optional analytics: Google Analytics
We'd like to use Google Analytics to understand, in aggregate, how sugarFRUIT is used — which pages get visited, how often, and roughly how — so we can improve the site. This is entirely optional and off by default.
Google Analytics does not load, and no Analytics cookie is set, until you choose "Accept analytics" in the cookie banner or in Cookie settings (footer link, any page). Choosing "Necessary only" means Analytics never loads for you.
Choosing "Necessary only" does not reduce your access to sugarFRUIT in any way — every feature works identically either way.
We've configured Analytics conservatively, for basic site-usage analytics only:
- We don't use Analytics for advertising or remarketing. Google Signals and ad-personalization features are turned off, and we don't run any advertising or cross-site marketing tracking on sugarFRUIT.
- We don't intentionally send names, nicknames, email addresses, account identifiers, profile content, Message or Group/Thread content, report or moderation content, or any other member-generated or private data to Analytics.
- Analytics never sees a pageview for private or member-only areas at all — Messages, Groups, Discover, Who's Online, Profile, Account, Admin, your own Event submissions, and the sign-up/login/password flows are excluded outright, not just hidden from search engines.
- For the public pages Analytics does see, we send a simplified page path and a fixed page label rather than the exact URL or page title your browser shows. An Event or Local/Organization detail page, for example, is reported as "an Event detail page in this region" or "an Organization detail page," not which specific Event or Organization you viewed.
- We never send URL query strings or fragments (search terms, filters, redirect targets, tokens) to Analytics — only the simplified page path described above.
You can change your analytics choice at any time from Cookie settings in the site footer. Switching from "Accept analytics" to "Necessary only" stops future Analytics collection and clears Google Analytics cookies in your current browser where we're able to, without affecting your sign-in session.
5. How we use information
We use the information above to:
- operate sugarFRUIT — accounts, profiles, messaging, Groups, Events, Local;
- keep the community safer — reviewing reports, enforcing our Community Guidelines and Terms, and blocking/moderation tooling;
- communicate with you about your account (verification, password resets, and similar service messages); and
- understand and improve the site, using aggregate analytics if you've opted in.
6. Who we share information with
We don't sell your information, and we don't share it with advertisers. We use a small number of service providers to run sugarFRUIT:
- Supabase — our database, authentication, file storage, and real-time (Who's Online) infrastructure. Nearly everything described above is processed and stored through Supabase.
- Netlify — hosts and serves the sugarFRUIT website.
- Resend — delivers transactional account email on Supabase Auth's behalf, such as verification and password-reset emails. Resend only receives what a given email needs — the recipient address, the email's own content, and ordinary delivery metadata — not your profile, messages, Groups, or any other sugarFRUIT content or database access.
- Google Analytics — only if you've accepted optional analytics, as described in Section 4.
Other members can see whatever your profile, settings, and participation choices make visible to them (for example, a message you send is visible to its recipient). That's the normal operation of a community platform, not third-party sharing.
We may also disclose information where reasonably necessary to comply with the law, or to protect the safety of members or the service.
7. International processing
sugarFRUIT's pilot community is based on Vancouver Island, British Columbia, Canada, but our service providers (Supabase, Netlify, Resend, and, if you've opted in, Google) operate infrastructure in multiple countries. As a result, your information may be processed or stored outside Canada, including in the United States. We haven't made any specific certifications about international data-transfer frameworks, and this policy doesn't claim compliance with any particular country's data protection law.
8. How long we keep information
We generally keep account and profile information for as long as your account is active. We don't currently offer a self-serve way to delete your account or data — if that changes, this policy will be updated to describe it.
Some information — including reports, moderation records, and content connected to a safety or Terms investigation — may be retained for longer than the rest of an account's data where reasonably necessary for community safety, fraud prevention, or legal obligations, consistent with our Terms of Use. We don't commit to a specific retention period beyond that, because we don't currently enforce one mechanically.
9. Your choices
Analytics: accept or decline at any time via Cookie settings in the footer.
Profile and visibility: Account settings let you control whether you appear in Who's Online and Discover, and whether profile gestures are enabled.
Blocking and reporting: you can block another member or report content/accounts that violate our Community Guidelines directly from the relevant profile, message, Group, or content.
If you have a request about your information that isn't covered by an existing setting, use the contact method described in Section 11 once one is published.
10. Children's privacy
sugarFRUIT is not directed at, and does not knowingly collect information from, anyone under 18. Account creation requires confirming you meet that minimum age.
11. Contact
A public contact method has not yet been published for sugarFRUIT; this section will be updated once one is available.
12. Changes to this policy
We may update this Privacy Policy as sugarFRUIT evolves — especially as we add or change service providers, like introducing Google Analytics itself. The date at the top of this page shows when it was last updated. For significant changes (for example, a new required cookie, or a new category of data we collect), we'll take reasonable steps to make that visible rather than relying solely on this page's date.