Privacy Policy
effective 26-june-2026
Quick Summary
This Privacy Policy explains what data 142 collects, how we use it, and what control you have over it. Here's a quick breakdown of the key points, but please read the whole thing:
- We collect what we need to run 142: your phone number, date of birth, name, email, your posts and messages, your connections, and (when you give us permission) your location, camera, microphone and photos.
- Your phone contacts stay on your device. We read them with your permission to power the invite screen, and we briefly check against our backend to identify which of your contacts already use 142. We don't store your contacts on our servers.
- We don't sell your data. Ever. To anyone.
- We don't show you ads, and we don't build advertising profiles about you.
- We don't share your data with data brokers, advertisers, or AI training companies.
- Most of your data is stored on Google Firebase in Belgium (the
europe-west1region). Your posts, photos, videos, voice notes and messages stay in the EU/UK area. A few Firebase services (such as authentication and analytics) process data in the US, with legal safeguards in place. - You have strong rights over your data under UK GDPR, including the right to access it, correct it, delete it, and take a copy with you.
- You can opt out of marketing emails at any time. Service messages (like sign-in codes) you can't opt out of, they're how the app works.
- Our regulator is the UK Information Commissioner's Office (ICO). You can complain to them at any time.
This summary simplifies the main points. The full Policy below is the official statement of what we do with your data.
142 Privacy Policy
Effective: 26-June-2026
1. Who We Are, and What This Policy Covers
This Privacy Policy explains how 142 Social Limited, a company registered in England and Wales with company number 16841957 and registered office at 4 Unstead Wood, Peasmarsh, Guildford, England, GU3 1NG ("142", "we" or "us"), handles your personal data when you use the 142 app or any of our related products and services (the "Services").
We are the "data controller" of your personal data. That means we are the company that decides what data is collected and how it's used. We are registered with the UK Information Commissioner's Office (ICO).
This Policy covers personal data we collect about:
- people who use the 142 app;
- people who sign up to our waitlist or other pre-launch lists; and
- people who contact us, including for support.
If you're a user of the Services, this Policy works alongside our Terms of Service, which set out the contract between us.
In summary: 142 Social Limited is the company that decides how your data is used. This Policy explains what we do with that data and what your rights are under UK law.
2. The Short Version of How 142 Handles Data
Before the detail, here's the simple version:
- No ads, no algorithms, no profiling. We don't make money from your data.
- We collect what's needed to run the Service. Phone number, date of birth, name, email, posts, messages, connections, and, when you grant permission, location, contacts, camera, and microphone.
- We use Google Firebase as our backend. This means Google processes data on our behalf to host, store and operate the Service. We don't share your data with Google for Google's own purposes. Our main databases and file storage are configured in Google's Belgium (
europe-west1) region. - Some Firebase services still process data in the US (notably authentication, push notifications and analytics). There are legal safeguards in place to protect your data when it leaves the UK or EU.
- You can request a copy of your data, correct it, or delete it at any time. Just ask us.
In summary: We collect what we need. We don't sell or trade your data. We give you real control over it.
3. The Data We Collect
We collect three kinds of data: data you give us directly, data the app generates while you use it, and data that other people give us.
3.1 Data You Give Us
When you create an account. When you sign up, we ask you for:
- your mobile phone number (used to sign you in via one-time-password SMS, and to identify your account);
- your email address (used for service communications, recovery, and, if you opt in, marketing);
- your first name (shown to your connections);
- your date of birth (used to confirm you are 18 or older); and
- optionally, a profile picture.
142 is an 18+ Service. We use a date-of-birth picker at sign-up that does not allow a date less than 18 years before the current date. We do not use a third-party age-verification service.
When you use the Service. When you use 142, you create content. We store this so that you and your connections can see it as part of the Service. This includes:
- Posts (text, photos, videos, voice notes, and location tags);
- Comments and marks (when you interact with posts);
- Direct messages and group messages;
- Calendar entries and events you create or join;
- Your list of connections ("friends"); and
- Circles you've created to organise your connections.
When you contact us. When you contact us by email or through the in-app support tool, we collect whatever you send us, your message, screenshots, and any information you give us to help us help you.
3.2 Data Generated by Your Device, with Your Permission
Some features of 142 only work if you give the app permission to use parts of your device. You can grant or revoke these permissions in your device settings at any time. Where you grant permission, we collect:
- Location data. When you choose to tag a post with a location, or use the meet-spot search feature, we collect your location at the time you use that feature. We use the Google Maps Platform (including the Places API) and standard geolocation and geocoding services to power location search and to convert location coordinates to readable place names. When you tag a post or event with a location, the resulting location text and coordinates are stored with that post or event. We do not track your location in the background, and we do not maintain a continuous location history about you.
- Camera, microphone and photo library. When you take a photo or video, record a voice note, or attach a photo from your library, we collect the resulting content so we can post or send it.
Phone contacts: how we use them. When you tap "Invite Friends" (or open the Add Friends screen), we ask your permission to access your phone contacts. We treat your contacts carefully:
- Your contacts list stays on your device. The phone book itself is read on your device and shown to you on the invite screen. We don't copy your contacts list to our servers or store it in our database.
- We check which of your contacts already use 142. To show you which contacts to "Add" (existing 142 users) and which to "Invite" (people not on 142), the app sends each contact's phone number to our backend, which performs a real-time lookup against our user database. The number is used only to find whether a matching 142 account exists; it is not stored, logged, cached or otherwise retained after the lookup.
- Invites are sent through your own phone. When you tap "Invite" on a contact who isn't on 142, the app opens your phone's native share sheet so you can send the invite via whichever messaging app you choose (SMS, WhatsApp, email, etc.). The invite goes from your phone to theirs, it does not pass through our servers. The recipient's contact details are not sent to us.
- Add requests stay inside 142. When you tap "Add" on a contact who's already a 142 user, we send them a connection request inside the app.
A note for non-users. If you don't have a 142 account but someone has invited you, your contact details were used by the inviter's own phone to send you a message, they did not pass through our servers. If you've signed up to 142 since being invited, your data is then handled as set out elsewhere in this Policy. If you have any questions, contact privacy@142.social.
3.3 Data the App Generates Automatically
When you use 142, the app and our backend generate some data automatically:
- Device and technical data: device type, operating system version, app version, device language, time zone, and a device-specific identifier used by Firebase to deliver push notifications and analytics.
- Usage data: which screens you visit, which features you use, how often you open the app, and similar product-usage information. We use this to understand how 142 is being used so we can make it better. Our analytics are tied to an internal, randomly generated account identifier, not to your phone number or any other directly identifying detail. Firebase Analytics is configured with default retention (currently 14 months for user-level data).
- IP address: collected automatically when your device connects to our backend. We use it for security (to detect suspicious sign-in attempts), for fraud prevention, and to approximate which country you're in for legal compliance purposes.
3.4 Data Others Give Us
We may receive data about you from other people in limited circumstances:
- From other 142 users who add you as a connection, message you, add you to a group, or tag you in content;
- From law enforcement or regulators, where they share data about misuse of the Service.
We do not receive bulk data about you from data brokers, marketing networks, or other commercial third parties.
3.5 Waitlist Data
If you signed up to the 142 waitlist before launch, we collected your email address (and any other information you chose to provide). We use that information to notify you about launch, send you product updates, and, once you've created an account, link your waitlist signup to your account. You can ask us to delete your waitlist data at any time by emailing privacy@142.social.
In summary: We collect your account details, the content you make on 142, what you ask the app to handle (location, contacts, photos), and some standard technical data. We try to keep the list short.
4. How We Use Your Data, and Why It's Lawful
UK GDPR requires us to have a "lawful basis" for everything we do with your personal data. Here's the full list of how we use your data, and the lawful basis we rely on for each use.
| What we use your data for | Lawful basis (UK GDPR) |
|---|---|
| To run the Service: sign you in, show your content to your connections, deliver messages, store your Activity, send push notifications you've enabled. | Contract (Article 6(1)(b)): necessary to perform our contract with you. |
| To power the invite and add-friends screens: read your contacts on your device (with permission), match them against our user database to show Add/Invite options. | Consent (Article 6(1)(a)): you grant device-level contacts permission, and you can revoke it at any time in your device settings. |
| To enable location features: location tagging on posts, meet-spot search. | Consent: you grant device-level location permission, and you can revoke it at any time. |
| To keep the Service running: detect fraud, prevent abuse, protect accounts, fix bugs, monitor uptime. | Legitimate interests (Article 6(1)(f)): keeping our Service secure and working. |
| To improve the Service: understand which features are used, identify problems, plan changes. | Legitimate interests: improving the Service we offer. |
| To moderate chat content: apply an automated profanity filter to chat text to reduce abuse. | Legitimate interests: keeping the Service safe and protecting users from harassment. |
| To send you service messages: sign-in codes, security alerts, important account updates. | Contract and legitimate interests. |
| To send you marketing emails about 142: once you've signed up to the waitlist, created an account, or otherwise opted in. | Legitimate interests under the UK PECR "soft opt-in" for existing users, with the right to opt out at any time. For new prospects, we rely on consent (Article 6(1)(a)). |
| To respond to your support requests: when you contact us. | Contract and legitimate interests. |
| To enforce our Terms and Community Guidelines: investigate reports, take action on rule-breaking. | Legitimate interests and legal obligation (Article 6(1)(c)). |
| To comply with the law: respond to court orders, regulatory requests, and our duties under the UK Online Safety Act. | Legal obligation. |
If we ever need to use your data for a new purpose that's not on this list, we will tell you in advance and ask for your consent where the law requires it.
Automated processing of chat content. We apply an automated profanity filter to chat text to reduce abuse and protect users. This is a simple word-list check, not an AI system; it does not make decisions that have legal or similarly significant effects on you. The filter blocks specific words; it does not restrict your account.
We do not use your data for:
- targeted advertising;
- building advertising profiles about you;
- training general-purpose AI models;
- selling or licensing your data to third parties.
In summary: We use your data to run the Service, keep it safe, and stay legal. Marketing is opt-in (and opt-out-able). We don't do ads, profiling, or AI training on your content.
5. Who We Share Your Data With
We share your data only with the parties listed below, and only for the purposes listed.
5.1 Your Connections on 142
The whole point of 142 is to share things with your connections. When you post, comment, mark, or message, the people you've shared with can see what you've shared. See our Terms of Service (section 12) for full details of how content moves between the feed and the Activity section.
5.2 Service Providers (Data Processors)
We use a small number of trusted service providers to help us run the Service. These providers process your data on our behalf and only for the purposes we tell them to. They can't use your data for their own purposes.
| Provider | What they do for us | Where they're based / data location |
|---|---|---|
| Google (Firebase Authentication) | Signs you in via SMS one-time-password. Sends OTP SMS via Google's own SMS infrastructure. | Authentication services process globally, including in the US. Google is certified under the UK Extension to the EU-US Data Privacy Framework. |
| Google (Cloud Firestore) | Our main database, which stores account data, posts, messages, connections, calendar entries and other content. | Belgium (europe-west1). Data stays in the EU/UK region. |
| Google (Firebase Cloud Storage) | Stores media: photos, videos, voice notes and profile pictures. | Belgium (europe-west1). Data stays in the EU/UK region. |
| Google (Firebase Cloud Functions) | Runs our backend logic: push-notification dispatch, email queueing, admin tasks and scheduled cleanup. | Belgium (europe-west1). |
| Google (Firebase Cloud Messaging) | Delivers push notifications to your device. | Processes globally, including in the US. Covered by the UK Extension to the EU-US Data Privacy Framework. |
| Google (Firebase Analytics) | Provides product usage analytics. | Processes globally, including in the US. Covered by the UK Extension to the EU-US Data Privacy Framework. |
| Google (Maps Platform, Places API and geocoding) | Powers location search ("meet spots") and converts coordinates to readable place names when you tag a post or event with a location. | Processes globally, including in the US. Covered by the UK Extension to the EU-US Data Privacy Framework. |
| Apple App Store | Distributes the iOS app. | United States, with UK data residency commitments. |
| Google Play Store | Distributes the Android app. | Same as above. |
We will keep this list up to date. If we add or change a service provider in a way that affects your data, we'll update this Policy.
5.3 Other Users (Limited Circumstances)
Other users may see your data in limited circumstances:
- Your connections see your posts, comments, marks, messages, calendar entries you share with them, and your profile information.
- Connections of your connections may see you in a group conversation if a mutual contact adds you to the group, even if you aren't directly connected to them.
- A user who marked or commented on your post will retain that post in their Activity section, even after it leaves the live feed (see ToS section 12).
- A user who has you in their phone contacts will see you as an "Add" option (rather than "Invite") on their add-friends screen, if they've granted contacts permission. This is the result of a real-time lookup; we don't tell that user anything about you beyond the fact that the number they already have in their phone is a 142 account.
5.4 Authorities, Law Enforcement and Regulators
We may share your data with authorities, law enforcement, regulators, and others where we are required by law, or where we reasonably believe it's necessary to:
- comply with a court order, subpoena, or other legal process;
- respond to a request from UK law enforcement, including under the Online Safety Act;
- protect the rights, property or safety of 142, our users, or anyone else;
- investigate fraud, security, or abuse.
We push back on overly broad requests and only share what we have to.
5.5 Business Transfers
If 142 is acquired, merged, or its assets are sold, your data may be transferred as part of that transaction. If that happens, we'll let you know in advance, and the new owner will be bound by this Policy or one that's at least as protective.
5.6 What We Don't Do
We do not share your data with:
- advertisers or ad networks;
- data brokers;
- AI training companies;
- any other third party for their own marketing or profiling purposes.
In summary: Your data goes to your connections (because that's the point), to a small number of trusted service providers (mainly Google Firebase, plus Google Maps for location features), and to authorities only where we have to. Nobody else.
6. International Data Transfers
Most of your content, your account, posts, photos, videos, voice notes, messages and calendar entries, is stored in Google's Belgium data centre (europe-west1) and stays within the EU/UK region.
Some Firebase services, notably Firebase Authentication (which handles sign-in), Firebase Cloud Messaging (which delivers push notifications), Firebase Analytics, and Google Maps Platform, process data globally, which includes the United States.
Where we transfer data outside the UK, we put legal safeguards in place to protect it:
- Google is certified under the UK Extension to the EU-US Data Privacy Framework. This is a recognised mechanism under UK data protection law for lawful transfers to the US.
- For any transfers to providers not covered by a recognised certification, we use the UK International Data Transfer Addendum to the European Commission's Standard Contractual Clauses.
- We also assess each transfer to make sure your data is protected to a standard equivalent to UK law.
If you'd like more information about the specific safeguards we use, please email privacy@142.social.
In summary: Your content stays in Belgium. A few Firebase services and Google Maps process some data in the US, with legal safeguards in place.
7. How Long We Keep Your Data
We keep your data only for as long as we need it. The Terms of Service (section 12) explain the user-visible side of this. Below is the full picture from the data-protection side.
| Data | How long we keep it |
|---|---|
| Account details (phone, email, name, profile picture, DOB) | For as long as your account is active. Deleted immediately when you close your account from inside the app. |
| Posts and content in your Activity | For as long as you keep them. Deleted immediately when you delete them or close your account. Attached media is deleted with the post. |
| Direct messages | Until you or the other party deletes them, or your account is closed. |
| Event chat messages | Kept like other messages (until you or another participant deletes them, or the account is closed). The chat becomes read-only 48 hours after the event ends. |
| Calendar entries | Until you delete them or close your account. |
| Phone contacts (from the invite screen) | Not stored on our servers. Used in real time for the Add/Invite lookup, then discarded. |
| Crash and analytics data | Held at Firebase Analytics defaults (currently 14 months for user-level data). |
| Server / Cloud Functions logs | Held at Firebase / Google Cloud defaults. |
| Backups | Held automatically by Google Cloud (we do not run separate backups). |
| Marketing email lists | Until you unsubscribe. |
| Support and complaint records | 2 years after the matter is closed, or longer where we need it for a legal claim. |
| Moderation and safety records (for accounts we've actioned) | 12 months after the action, or longer where there's a legal need to keep them. |
If the law requires us to keep certain data for longer, we will, and only for as long as required.
In summary: We keep your data while you're using 142, and delete it when you do. Some things (like safety records and support tickets) have to be kept longer.
8. Your Rights
Under UK GDPR, you have a strong set of rights over your personal data:
- The right to be informed: to know what we do with your data. That's what this Policy is for.
- The right of access: to ask us for a copy of the data we hold about you. We respond within one month, and there's no charge for a normal request.
- The right to rectification: to have inaccurate data corrected. You can update most account details inside the app; for anything else, email us.
- The right to erasure ("right to be forgotten"): to ask us to delete your data. You can close your account at any time in the app, which triggers deletion.
- The right to restrict processing: to ask us to pause processing your data in certain circumstances.
- The right to data portability: to ask us for a copy of your data in a portable format so you can take it elsewhere.
- The right to object: to object to certain uses of your data, including marketing.
- The right to withdraw consent: where we rely on your consent, you can withdraw it at any time. This doesn't affect anything we did before you withdrew it.
- Rights related to automated decision-making: we don't make any solely automated decisions about you that have a legal or similarly significant effect on you.
To exercise any of these rights, email us at privacy@142.social with details of your request.
The right to complain. If you're not happy with how we've handled your data, you have the right to complain to the Information Commissioner's Office (ICO) at https://ico.org.uk, or call 0303 123 1113.
You can also contact us first at privacy@142.social, and we'll do our best to put things right.
In summary: You have strong rights over your data. To use them, email privacy@142.social. If you're not happy with how we respond, you can complain to the ICO.
9. Cookies, SDKs and Similar Technologies
The 142 mobile app doesn't use traditional web cookies. But it does use software development kits (SDKs) from Google Firebase and the Google Maps Platform, which work similarly. These SDKs collect technical and usage data that helps us operate, secure, and improve the Service.
Our website uses Cloudflare Web Analytics, which Cloudflare states does not use cookies and does not collect personal data for tracking. Because of this, our website does not set a cookie consent banner. If we later add cookie-based tools to the website, we'll publish a separate Cookie Policy and ask for consent where the law requires it.
In summary: No traditional cookies in the app or on our website. The Firebase and Google Maps SDKs collect technical data on our behalf (covered in section 3.3), and our website uses cookieless Cloudflare analytics.
10. Children
142 is an 18+ Service. We do not knowingly collect data from anyone under 18. If we discover that someone under 18 has created an account, we'll close the account and delete any data we've collected. If you believe a 142 user is under 18, please contact us at support@142.social.
In summary: 142 is 18+. We don't knowingly collect data from anyone younger.
11. Security
We take security seriously. We use industry-standard technical and organisational measures to protect your data, including:
- encrypted connections between the 142 app and our backend (TLS);
- encryption of data at rest within Google Firebase;
- access controls limiting who at 142 (and at our service providers) can access your data;
- regular security reviews of our infrastructure; and
- monitoring for unusual activity and security threats.
No system is ever 100% secure. If we become aware of a personal data breach that's likely to result in a risk to your rights and freedoms, we'll notify the ICO within 72 hours (as required by UK GDPR), and we'll tell you if the risk is high.
In summary: We use industry-standard security to protect your data. If something goes wrong, we'll act fast and let you know.
12. Changes to This Policy
We may update this Privacy Policy from time to time, to reflect changes in the Service, in our practices, or in the law.
If we make material changes, we'll give you reasonable advance notice (by in-app notification, email, or both) and tell you when the changes take effect. For minor changes (like clarifying wording or adding a new service provider that doesn't affect you), we may just update the Policy and update the "Effective" date at the top.
We recommend checking back here from time to time.
In summary: We may update this Policy. We'll tell you about anything material in advance.
13. Contact Us
Questions about this Policy, or how 142 handles your data?
142 Social Limited 4 Unstead Wood, Peasmarsh, Guildford, England, GU3 1NG Registered in England and Wales, company number 16841957
| What for | |
|---|---|
| Privacy questions and data subject requests | privacy@142.social |
| General support | support@142.social |
| Content moderation appeals | appeals@142.social |
| Copyright and IP complaints | copyright@142.social |
| Legal / regulatory contact | legal@142.social |