Legal
Privacy Policy
Effective from: August 17, 2026 · Version 2.1.0
Subsets is a product of Workwind, Inc. (“Workwind,” “we,” “us,” or “our”), a company incorporated in Delaware, USA. This Privacy Policy explains how we collect, use, store, and protect your personal information when you use the Subsets mobile applications and website (collectively, the “Service”).
By creating an account or using Subsets, you agree to this Privacy Policy. If you do not agree, do not use the Service.
1. Who This Policy Applies To
This policy applies to all users of Subsets worldwide, including users in:
- The United States (COPPA, CCPA/CPRA apply)
- The European Economic Area and United Kingdom (GDPR and UK GDPR apply)
- All other jurisdictions
Where regional laws impose additional requirements, those are addressed in the relevant sections below.
2. Information We Collect
2.1 Account Data
Information you provide when creating or updating your account:
- Name
- Username
- Email address, mobile telephone number, or both
- Date of birth (used to verify you meet our minimum age requirement)
- Gender
- Profile photo and cover photo (optional)
- Biography and social media handles (optional)
Subsets is passwordless. We never ask you to create a password and we do not store user-chosen passwords. You sign in with a one-time code (OTP) delivered either to your email address or to your mobile telephone number. Where you register with a telephone number, an email address is optional and may never be collected. See Section 10 for how sign-in codes are protected.
2.2 Telephone Number
Where you provide a mobile telephone number, we retain the number in international (E.164) format, the country to which it belongs, and the date on which it was verified.
One-time codes sent to a telephone number are delivered and verified by Bird, our verification provider, over WhatsApp, SMS, or email according to the country concerned. Bird receives the telephone number for the sole purpose of delivering and verifying the code. Subsets neither generates nor stores those codes.
We additionally derive a keyed, non-reversible digest of your number. That digest is never disclosed to any party, and is used solely to match your account against the address books of users who have enabled contact discovery, as described in Section 2.9.
2.3 Content You Upload
- Photos, images and videos you upload to the Service
- Album names and descriptions
- Captions, comments and replies you write
- Locations you elect to attach to a post (see Section 2.8)
- Accounts you mention or tag in a post
2.4 Social Connections
Subsets operates a directed connection model. We record:
- The accounts you have added, and the accounts that have added you
- The accounts with which you hold a mutual connection
- Connection requests sent and received, and their outcome
- Invitations issued and accepted
- Accounts you have blocked
Adding an account permits you to view the content that account has made public. Viewing content that an account has not made public requires that account to add you in return.
2.5 Device and Technical Data
Information automatically collected when you use the Service:
- Device type, operating system version, and app version
- IP address
- Session identifiers and authentication tokens
- Error logs and crash reports (for service stability only — processed via Sentry, see Section 5.2)
2.6 Push Notification Tokens
If you grant permission, we collect a device push token to deliver notifications about activity on your account (new connection requests, activity from accounts you have added, and similar). You can revoke this permission at any time in your device settings.
2.7 Photo EXIF Data — Important
We do not store EXIF metadata from your photos. EXIF data (including any embedded GPS coordinates, camera details, or timestamps) is stripped from all photos at the point of upload before storage.
On the Subsets mobile app, EXIF data may be read locally on your device before upload solely to display contextual information to you (such as the photo’s capture date or location for your own reference). This data never leaves your device and is not transmitted to our servers.
2.8 Location Information
Subsets does not request, collect, or process continuous or background location data. The Service contains no facility for tracking the position of a device, and no location permission is required in order to use it.
Location information is processed in two circumstances only, each of which arises from an action you take:
(a) Selecting a place when publishing a post. Where you elect to tag a post with a location, the Service presents a place-search facility. If your device has a current position available and you have permitted the application to access it, the coordinates of that position may be transmitted to our mapping provider, Google Maps Platform, for the sole purpose of ordering search results by proximity. Transmission occurs only while the place-search facility is open. The provision of coordinates is optional; where none are supplied, results are returned without proximity ordering.
(b) Storing a location you have selected. Where you complete a location tag, we store the name of the place, the identifier assigned to it by the mapping provider, and its coordinates. That information is displayed together with the post and is therefore visible to the same audience as the post itself. Where the post is public, the location is public. A location tag may be removed at any time by editing or deleting the post.
We do not derive location from the photographs you upload. As stated in Section 2.7, EXIF metadata, including any embedded GPS coordinates, is removed at the point of upload. You tell us where a post was taken; we do not infer it.
2.9 Address Book Synchronisation
Where you elect to enable contact discovery, the Subsets application transmits the telephone numbers held in your device’s address book to the Service, in order to identify which of your contacts already use Subsets and to inform you where a contact registers subsequently.
The following applies to that processing:
- Telephone numbers are not stored. Each number is converted to a keyed, non-reversible digest (HMAC-SHA256) before it is written to our systems. The number itself is discarded and is retained in no form.
- The key is held outside the database. The secret used to compute each digest is stored separately from the data it protects. A copy of our database alone therefore discloses neither the numbers held in your address book nor the identity of the persons to whom they belong.
- Digests of persons who are not users are retained. Where a number matches no existing account, its digest is retained so that, if the person to whom it belongs later registers, the Service is able to present them to you as a suggested connection. No other information concerning that person is held, no attempt is made to contact them, and the digest cannot be used to recover their number.
- The processing is optional and reversible. Contact synchronisation is not required in order to use the Service. You may delete every digest derived from your address book at any time from within the application. You may dismiss individual suggestions. You may also prevent your own account from being identified in any other person’s address book by disabling contact discovery in your settings; that setting takes effect immediately and across all address books.
The legal basis for this processing is your consent, which you may withdraw at any time by deleting your synchronised contacts and disabling contact discovery.
2.10 Automated Analysis of Public Content
Photographs and videos contained in publicly visible posts are analysed automatically in order to determine their subject matter. The analysis is performed by Amazon Rekognition operating within our own cloud environment, and produces a set of descriptive subject labels (for example, “mountain”, “cycling”, “architecture”). In the case of videos, a limited number of frames are sampled for this purpose.
The following limitations apply, and are enforced by the Service itself:
- Private content is never analysed. A post is submitted for analysis only where it is publicly visible. Posts belonging to a private account, and posts confined to a chosen audience, are excluded before dispatch, and their content is never transmitted to the analysis system.
- The analysis produces subject labels only. It is not used to identify individuals, to perform facial recognition, or to infer any characteristic of any person.
- The resulting labels are used solely to operate Explore. They determine the topics under which a public account may be recommended within the Explore surface, as described in Section 13. They are not displayed to other users, not published, not disclosed to any third party, and are not sold, licensed, or otherwise made available for any other purpose.
- No decision producing legal or similarly significant effects is taken. The analysis does not determine your access to the Service or to any feature of it. No automated decision-making within the meaning of Article 22 of the GDPR is carried out.
2.11 Records of Content You View
Where you view a post, the Service records that you have done so.
The author of a post is able to see who has viewed it. For stories shown in the feed and for posts published by public accounts, the application presents authors with both a count of views and a list of the accounts that viewed. Viewing a post should accordingly be treated as an act visible to its author.
Where you view an account within Explore, that activity is recorded as described in Section 13. Explore activity is visible only to you and is not disclosed to the account concerned.
3. What We Do Not Do
- We do not sell your personal data, and we do not disclose it to data brokers.
- We do not show advertisements.
- We do not use advertising SDKs, cross-application analytics services, or third-party analytics products (no Mixpanel, Amplitude, Firebase Analytics, Google Analytics, or similar).
- We do not collect advertising identifiers (IDFA, GAID).
- We do not use tracking pixels or cross-site tracking technologies, and we do not track you across other applications or websites.
- We do not use your photos, videos, or other content to train, fine-tune, or evaluate artificial intelligence or machine learning models.
- We do not collect payment information (Subsets is free to use).
- We do not make your profile or your posts publicly visible unless you elect to make your account public.
We do record how you interact with the Explore surface, in order to determine the order in which accounts are presented to you there. That processing is carried out by us rather than by any third party, is confined to Explore, and is described in full in Section 13.
4. How We Use Your Information
We use the information we collect for the following purposes:
| Purpose | Data Used | Legal Basis (GDPR) |
|---|---|---|
| Provide and maintain your account | Account data, content | Performance of contract |
| Deliver your content to the audience you have chosen | Content, connections | Performance of contract |
| Authenticate your identity and secure your session | Account data, telephone number, device data | Performance of contract |
| Identify which of your contacts use Subsets | Address book digests | Consent |
| Determine the subject matter of publicly visible posts | Public content | Legitimate interests |
| Rank the accounts presented to you in Explore | Explore activity, declared preferences, content labels | Legitimate interests |
| Display a location you have attached to a post | Location tag | Performance of contract |
| Show authors who has viewed their posts | View records | Performance of contract |
| Send push notifications you have opted into | Push token | Consent |
| Prevent fraud, abuse, and violations of our Terms | All categories | Legitimate interests |
| Diagnose technical errors and maintain service stability | Device/technical data, crash logs | Legitimate interests |
| Comply with legal obligations | All categories as required | Legal obligation |
| Enforce our Terms of Service | All categories as required | Legitimate interests |
We do not use your data for advertising, and we do not sell it or disclose it to data brokers.
We do construct an inferred record of the subjects that appear to interest you, derived from your activity on the Explore surface. That record exists for one purpose: to determine the order in which public accounts are presented to you within Explore. It is not used for advertising, is not applied anywhere else in the Service, and is not disclosed to anyone. Section 13 sets out in full what is recorded, what is not recorded, how long it is kept, and how you may change or disable it.
5. How We Share Your Information
We do not sell your personal data. We do not share your data with third parties for their marketing purposes.
We share data only in the following limited circumstances:
5.1 With Other Users
Your account is private by default, and no content is publicly visible by default. Content becomes publicly visible only if you elect to make your account public.
While your account is private, your posts are visible only to the accounts you have added in return, together with any narrower audience you select when publishing.
If you elect to make your account public, your profile, your posts other than those confined to a private folder, and your public statistics become visible to any signed-in Subsets user, and your account becomes eligible to be recommended within Explore. You may return your account to private at any time, after which the content ceases to be publicly visible.
In neither case is any content accessible from the open internet. Every profile and every post is served only to authenticated Subsets users. Content that is public in the sense described above is not reachable by a person who is not signed in to Subsets, is not indexed by search engines, and cannot be crawled.
5.2 With Service Providers (Sub-processors)
We use trusted infrastructure providers to operate the Service. These providers process data only on our instructions and under strict data processing agreements:
| Provider | Role | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, storage | USA (and applicable regions) |
| Cloudflare | CDN, DDoS protection, network security | USA / global edge network |
| Postmark (ActiveCampaign) | Transactional email (e.g., account confirmations) | USA |
| Bird (Bird B.V.) | Delivery and verification of one-time sign-in codes sent to a telephone number, by WhatsApp, SMS, or email | Netherlands (EU) |
| Sentry (Functional Software, Inc.) | Error and crash reporting | USA |
5.3 Legal Requirements
We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
5.4 Business Transfers
If Workwind is involved in a merger, acquisition, or asset sale, your data may be transferred as part of that transaction. We will notify you before your data is transferred and becomes subject to a different privacy policy.
6. International Data Transfers
Workwind is based in the United States. If you use the Service from the European Economic Area (EEA), United Kingdom, or other regions with laws governing data collection and use, your data will be transferred to and processed in the United States and other countries where our service providers operate.
For transfers of personal data from the EEA or UK to the USA, we rely on the following safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our agreements with AWS, Cloudflare, Postmark, and Sentry.
- UK International Data Transfer Addendum (IDTA) for UK-to-USA transfers.
Bird, which delivers one-time sign-in codes to telephone numbers, is established in the Netherlands and processes that data within the European Economic Area. No transfer safeguard is required for EEA users in respect of that processing.
You may request a copy of the applicable transfer safeguards by contacting [email protected].
7. Data Retention
We retain your personal data for as long as your account is active.
| Data Category | Retention Period |
|---|---|
| Account data and content | Until account deletion |
| Active session tokens | Until logout or session expiry |
| Crash logs and error reports | 90 days |
| Backup copies | Purged within 30 days of account deletion |
| Email delivery logs (Postmark) | 45 days |
When you delete your account:
- Your content and account data — including your photos, albums, connections, device tokens, and active sessions — are deleted from our active systems immediately.
- Residual copies in encrypted backups are purged within 30 days.
- Some data may be retained longer if required by law or to resolve active disputes.
Deletion initiated from within the application takes effect immediately. Where you instead ask us to delete your account by email, the same outcome applies, but deletion begins once we have verified that the request comes from the account holder. Section 8.4 describes that route.
8. Your Privacy Rights
8.1 Rights for All Users
Regardless of location, you may:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your data or account
- Export your data in a portable format (photos, account data)
You can request a data export directly in the app from your account settings and download the resulting archive when it is ready. For any of these rights you can also email [email protected]. We will respond within 5-7 business days. You are never required to install or reinstall the application in order to exercise any of these rights — see Section 8.4.
8.2 Additional Rights for EEA and UK Users (GDPR / UK GDPR)
You also have the right to:
- Restrict processing of your data in certain circumstances
- Object to processing based on legitimate interests
- Withdraw consent at any time where processing is based on consent (e.g., push notifications)
- Lodge a complaint with your local data protection supervisory authority
Relevant authorities include:
- EU: Your country’s national DPA (e.g., CNIL in France, BfDI in Germany)
- UK: Information Commissioner’s Office (ICO) — ico.org.uk
8.3 Rights for California Residents (CCPA/CPRA)
California residents have the right to:
- Know what categories of personal information we collect and how it is used
- Delete personal information we hold about you
- Correct inaccurate personal information
- Opt out of sale or sharing — We do not sell or share your personal information for cross-context behavioral advertising.
- Non-discrimination — we will not deny, charge more, or provide a lesser service because you exercised your privacy rights
To submit a verifiable consumer request, email [email protected]. We will respond within 5-7 business days, and in any event within the period required by applicable law.
Categories of personal information collected in the past 12 months:
- Identifiers (name, email address, telephone number, username, IP address)
- Characteristics of protected classifications (date of birth, gender)
- Photos, videos, and other user-generated content
- Geolocation data, limited to locations you have expressly attached to a post
- Internet or other network activity (device and session data, Explore activity, records of posts viewed)
- Non-reversible digests derived from your device address book
- Push notification tokens
We do not sell or share any of these categories.
8.4 Deleting Your Account Without the Application
You do not need the application installed, and you do not need to reinstall it, in order to delete your account or your data. A request may be submitted from the account deletion request page on our website, which composes an email to [email protected] containing the information we need to identify your account. You may equally write to that address yourself.
To allow us to act on such a request, please include:
- Your full name;
- The email address associated with your Subsets account;
- Your username, if you know it;
- Whether you are asking us to delete the entire account or only specified data; and
- Your reason for the request, which helps us route it correctly. You are not obliged to give a reason, and we will not refuse or delay a deletion request because none was given.
We acknowledge deletion requests within 1-2 business days and complete verified deletions within 30 days, and sooner where practicable. Because deletion is permanent and cannot be reversed, we verify that the request comes from the account holder before acting on it — ordinarily by confirming that the request was sent from the email address registered to the account, and where that is not possible, by another proportionate means. We do not charge for this, and exercising this right will not result in any lesser service. The effect of deletion is described in Section 7.
The web request page submits nothing to us on its own: it only prepares an email for you to send, and stores no information you type into it.
9. Children’s Privacy
9.1 Minimum Age
- Global: Subsets is not intended for users under 13 years of age.
- European Economic Area and United Kingdom: Users must be at least 16 years of age in accordance with GDPR Article 8 and the UK Age Appropriate Design Code.
9.2 COPPA Compliance (USA)
We do not knowingly collect personal information from children under 13 in the United States. If we discover that a user is under 13, we will promptly delete their account and all associated data.
If you believe a child under 13 has created an account on Subsets, please contact us immediately at [email protected].
9.3 EU/UK Minor Users (Ages 16–17)
For users aged 16–17 in the EEA or UK, we process data based on their own consent as permitted under applicable law. We do not process data for profiling, behavioral advertising, or any purpose beyond operating the Service.
10. Security
We implement technical and organizational measures to protect your personal data, including:
- Encryption in transit: All data transmitted between your device and our servers uses TLS 1.2 or higher.
- Encryption at rest: Stored data is encrypted using AES-256.
- Passwordless sign-in: One-time sign-in codes issued to an email address are stored only as bcrypt hashes, expire after 5 minutes, and can be used exactly once. Codes issued to a telephone number are generated, delivered, and verified by our verification provider; Subsets neither stores nor has access to them.
- Address book protection: Telephone numbers synchronised from your address book are stored only as keyed, non-reversible digests, computed with a secret held outside the database (see Section 2.9).
- Session protection: Access tokens are short-lived, and refresh tokens are single-use and rotated on every refresh. If a stolen token is ever replayed, all related sessions are automatically revoked.
- EXIF stripping: Sensitive photo metadata is removed at upload.
- Access controls: Internal access to user data is restricted to authorized personnel on a need-to-know basis.
No security system is impenetrable. In the event of a data breach that affects your personal data, we will notify affected users and applicable supervisory authorities within the timeframes required by law (72 hours under GDPR).
11. Cookies and Tracking
Our website (subsetsapp.com) uses only essential cookies required for the site to function (e.g., session management). We do not use advertising cookies or third-party tracking cookies.
Our mobile apps do not use cookies. We do not use cross-app or cross-device tracking.
12. Push Notifications
If you grant permission, we send push notifications to your device for service-related events (for example, connection requests, shared albums, and activity on your posts). You can withdraw this permission at any time in your device settings (iOS: Settings → Notifications; Android: Settings → Apps → Subsets → Notifications). Withdrawing permission does not affect your ability to use the Service.
13. How Explore Decides What You See
Explore presents public accounts that you have not already added. The order in which those accounts appear is determined by an automated ranking process. This section describes that process, the information it uses, and the means by which you may direct or disable it.
13.1 What is recorded
Only the following actions are recorded, and only where they occur on the Explore surface itself:
| Signal | Meaning |
|---|---|
| Impression | An account’s card was visible on your screen |
| Tap | You opened an account’s card |
| Similar | You asked to see accounts similar to a given account |
| Not interested | You expressly dismissed an account |
| Watched | You viewed all of the posts an account had shown you |
An impression that is followed by no other action carries a small negative weight. An account you are shown repeatedly and pass over repeatedly is therefore presented to you less often.
13.2 What is not used
No location data, no device identifiers, no device fingerprinting, and no measurement of the time you spend viewing anything is used in ranking. No activity occurring elsewhere in the Service, and no activity occurring outside the Service, is used.
13.3 What is retained
The individual records described in Section 13.1 are deleted after 30 days. What persists thereafter is a set of numerical scores expressing your apparent degree of interest in each subject topic. Those scores decay with time, so that recent activity carries more weight than older activity.
13.4 Where topics come from
The topics attributed to an account are derived from the profile category its owner has selected and, where the account is public, from the automated analysis of its content described in Section 2.10.
13.5 The controls available to you
- Explore preferences. You may select the topics and categories you wish to see. Selections you make expressly are applied in addition to the inferred scores described above, and are not overwritten by them.
- Not interested. Dismissing an account both suppresses that account and informs subsequent ranking.
- Profile discovery. Disabling profile discovery removes your own account from Explore and from the suggestions presented to other users.
This section is provided in accordance with Article 27 of Regulation (EU) 2022/2065 (the Digital Services Act).
14. Your Privacy Controls
The following controls are available to you within the application:
| Control | Effect |
|---|---|
| Account type | Private (the default) or public. Determines whether your profile and posts are visible beyond the accounts you have added, and whether your account may appear in Explore. |
| Profile discovery | Removes your account from Explore and from suggestions shown to other users. |
| Contact discovery | Prevents your account from being identified in any other person’s address book. Takes effect immediately and across all address books, and is reversible. |
| Delete synchronised contacts | Erases every digest derived from your device address book. |
| Explore preferences | Selects the topics and categories you wish Explore to present. |
| Not interested | Suppresses an individual account and informs subsequent ranking. |
| Push notifications | Enables or disables notifications for your account, independently of your device permission. |
| Block | Prevents all interaction between your account and another, in both directions. |
| Devices | Lists the devices signed in to your account and allows you to sign any of them out remotely. |
| Data export | Produces a downloadable archive of your data, in machine-readable or human-readable form. |
| Delete account | Permanently deletes your account. Requires verification by one-time code. |
Where you no longer have the application installed, the same deletion and export rights may be exercised by email, or through the account deletion request page on our website. Section 8.4 describes that route.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
- Sending a push notification or in-app notice, and
- Emailing you at the address associated with your account
The updated policy will be effective upon posting. Continued use of the Service after notification constitutes acceptance of the updated policy.
16. Contact Us
For privacy questions, data requests, or concerns:
Subsets Team — Workwind, Inc. Email: [email protected] Address: 1111B S Governors Ave #47719, Dover, DE 19904
We aim to respond to all requests within 5-7 business days.
To delete your account or data without the application installed, use the account deletion request page. See also: Terms of Service | Support