Tism Privacy Policy

Effective Date: December 7, 2025 | Last Updated: December 7, 2025

Welcome to the Tism Privacy Policy. Tism App LLC, a limited liability company organized and existing under the laws of the State of Florida, United States of America, Planet Earth (“we”, “us”, “our”, or “Tism”) is a specialized dating and social-connection platform designed exclusively for autistic and neurodivergent adults aged 18 and over. We recognize the unique sensitivities and vulnerabilities within our community, including the potential for heightened risks related to data privacy, such as doxxing, harassment, or misuse of sensitive health-related information. This policy is crafted with transparency, clarity, and respect in mind, avoiding dense legalese to ensure it's accessible to all users, including those who may prefer straightforward language.

This Privacy Policy details how we collect, use, store, protect, disclose, and manage your personal data. It ensures full compliance with key global privacy laws, including but not limited to:

We are committed to the principles of data minimization, purpose limitation, accuracy, storage limitation, integrity and confidentiality, and accountability. If you are a resident of California, please refer to our supplemental California Privacy Notice at the end of this policy. For residents of other U.S. states with comprehensive privacy laws (e.g., Virginia, Colorado, Connecticut, Utah), your rights are outlined in Section 8.

Good to Know: This policy applies to all interactions with Tism, including our waitlist sign-up, future app usage, websites, emails, and any related services. If you do not agree with this policy, please do not access or use our services.

1. Data Controller and Contact Information

Tism operates as a sole proprietorship. Depending on your location, the data controller responsible for your personal data is:

Contact us for any privacy-related inquiries:

If you believe your data rights have been violated, you may lodge a complaint with your local supervisory authority (e.g., CNIL in France, ICO in the UK, or the California Attorney General for CCPA issues).

2. Categories of Personal Data We Process

We collect only the data necessary to provide, improve, and secure our services. Data collection is minimized to respect your privacy, especially given the sensitive nature of neurodivergence-related information. Below is a comprehensive breakdown of data categories, examples, sources, purposes, and whether the data is mandatory or optional.

CategoryExamples (Non-Exhaustive)SourcePurpose(s)Mandatory/OptionalSensitive/Special Category?
IdentifiersEmail address, IP address, device ID, username, hashed passwordsDirectly from you (e.g., sign-up form); automatically (e.g., server logs)Account creation, authentication, waitlist management, communications, fraud prevention, personalized service deliveryMandatory for core servicesNo, unless linked to sensitive data
Internet/Network ActivityUser-Agent string, browser type, timestamps, session duration, pages viewed, referral URLsAutomatically via cookies, pixels, or logsSecurity monitoring, abuse prevention, analytics for service improvement, debuggingAutomatic (opt-out via cookie settings)No
Geolocation (Approximate)IP-derived country, region, or city; no precise GPS unless consentedAutomatically from IP; device if location services enabledFraud detection, regional compliance (e.g., age verification laws), future matching features based on broad locationOptional (can be disabled)No
Future Profile Data (Post-2026 Launch)Photos, bio, preferences (e.g., interests, relationship goals), neurodivergence details (e.g., autism spectrum level if shared), gender identity, sexual orientationVoluntarily provided by you during profile setup or updatesCore app functionality like matching, profile display, community building; ensuring neurodivergent-only environmentOptional (basic profile mandatory for use)Yes (special category under GDPR: health, sexual orientation; sensitive under CCPA)
Payment/Financial DataTransaction IDs, payment method type (no full card details stored), billing addressDirectly from you or payment processorsProcessing subscriptions or premium features (if implemented), refunds, fraud preventionMandatory for paid servicesNo
Customer Support DataInquiries, complaints, feedback, attached filesDirectly from you via support channelsResolving issues, improving service, compliance with reportsOptionalPossibly (if includes sensitive details)
InferencesDerived preferences from interactions (e.g., inferred interests from profile views)Generated from other dataPersonalization, matching algorithmsAutomaticPossibly sensitive

We do not collect or process precise geolocation, audio/video recordings, genetic data, or any data unrelated to our core mission. At the waitlist stage, we limit collection to essentials (email, IP, User-Agent). For future app features, any sensitive data (e.g., neurodivergence specifics) is processed only with explicit consent and for the purpose of community verification and matching. We do not use facial recognition or biometrics at this time but may introduce optional verification in 2026 with separate consent.

Good to Know: If you link social media accounts (e.g., for profile import), we receive limited data like profile photos or contacts, but only with your permission. You can revoke access anytime via the third-party platform.

3. Legal Bases for Processing (GDPR Art. 6 & 9; CCPA Equivalent Notices)

We process data only where we have a valid legal basis. For special category data (e.g., health/neurodivergence info), we require explicit consent. Below is a detailed mapping:

Processing ActivityLegal BasisExplanation & Examples
Account creation and waitlist managementPerformance of a contract (Art. 6(1)(b))To fulfill our agreement to add you to the waitlist and notify you upon launch. Example: Using your email to send confirmation and updates.
Fraud prevention and securityLegitimate interests (Art. 6(1)(f))Our interest in maintaining a safe, neurodivergent-only space outweighs risks. We conduct balancing tests and DPIAs for high-risk activities.
Processing sensitive data (e.g., neurodivergence details)Explicit consent (Art. 9(2)(a))You must affirmatively opt-in; consent is granular, informed, and revocable without detriment.
Marketing communicationsConsent (Art. 6(1)(a))Optional; you can unsubscribe anytime via email links or settings.
Compliance with legal obligationsLegal obligation (Art. 6(1)(c))E.g., responding to law enforcement requests or tax audits.

For CCPA/CPRA, we do not "sell" or "share" data for targeted advertising. Any sharing is for operational purposes only (see Section 5).

4. How We Use Your Data

4.1 Primary Uses

We use data to deliver, personalize, and secure our services. Examples:

4.2 Security and Fraud Prevention

We employ advanced measures to protect our community:

4.3 Marketing and Research

With consent, we may send promotional emails or conduct anonymized research on community trends. No targeted ads without opt-in.

Good to Know: We do not use automated decision-making that produces legal effects (GDPR Art. 22). All matching algorithms are overseen by humans.

5. Data Retention Schedule

We retain data only as long as necessary, with strict limits:

Data TypeRetention PeriodReasonDeletion Process
Waitlist Emails & IdentifiersUntil December 31, 2026 or consent withdrawalService fulfillmentSecure erasure; backups purged within 90 days
Security Logs (IP, User-Agent)180 days maxFraud investigationAutomatic anonymization or deletion
Sensitive Profile DataUntil account deletion + 30 daysUser controlIrreversible hashing or full wipe
Support Tickets6 yearsLegal defensePseudonymized after resolution

Upon deletion request, we confirm within 10 days and complete within 30 (GDPR) or 45 (CCPA) days.

6. Recipients & Sub-Processors

We share data only with trusted parties under strict contracts (GDPR Art. 28 DPAs). No sales or unrelated sharing.

Recipient TypeExamplesPurposeSafeguardsLocation
Hosting ProvidersContabo GmbH (Germany), AWS (US)Data storage and processingEU SCCs (2021/914), encryption, access controlsEU/US
Security/CDNCloudflare, Inc.DDoS protection, traffic managementSCCs, BCRs, regular auditsGlobal
Email ServicesSendGrid or equivalentTransactional emails (e.g., waitlist confirmations)DPA, SCCs, TLS encryptionUS
Payment ProcessorsStripe, PayPalFuture premium featuresPCI DSS compliance, pseudonymizationUS/EU
Legal/RegulatoryLaw enforcement, courtsCompliance with subpoenasOnly upon valid legal request; user notification where possibleVaries

We audit sub-processors annually and ensure they meet GDPR adequacy standards. For CCPA, these are "service providers" not involving sale/sharing.

7. International Transfers

Data may be transferred outside your jurisdiction. Primary storage: US (with EU mirrors for EEA users).

We conduct TIAs for all non-adequate transfers and make summaries available upon request.

8. Your Rights – Comprehensive List and Exercise Instructions

You have extensive rights over your data. Requests are free (unless excessive) and verified via email/IP checks.

  1. Access (GDPR Art. 15 / CCPA §1798.110): Receive a copy of your data, sources, purposes, recipients.
  2. Rectification (Art. 16): Correct inaccurate data.
  3. Erasure/Deletion ("Right to be Forgotten" - Art. 17 / CCPA §1798.105): Delete data when no longer needed or consent withdrawn.
  4. Restriction (Art. 18): Limit processing while disputes are resolved.
  5. Portability (Art. 20): Receive data in machine-readable format and transfer to another controller.
  6. Objection (Art. 21): Oppose processing based on legitimate interests or for marketing.
  7. Withdraw Consent (Art. 7): Revoke at any time; does not affect prior processing.
  8. Opt-Out of Sale/Sharing (CCPA §1798.120): Not applicable, but we honor "Do Not Sell My Personal Information" requests.
  9. Limit Sensitive Data Use (CPRA): Restrict use of sensitive data to necessary purposes.
  10. Non-Discrimination (CCPA §1798.125): No penalties for exercising rights.
  11. Complaint (Art. 77): Lodge with supervisory authority (list available on request).
  12. Automated Decisions (Art. 22): Request human review if applicable (none currently).

How to Exercise: Email chad@cummings.law with your request, including verification details. Response times: 30 days (GDPR), 45 days (CCPA, extendable). Appeals: If denied, appeal within 30 days; we respond within 60 days.

9. Security Measures

We implement robust technical and organizational measures (TOMs) per GDPR Art. 32 and CCPA requirements:

In case of a breach, we notify affected users and authorities as required.

10. Automated Decision-Making and Profiling

We do not engage in automated decision-making with legal or significant effects (GDPR Art. 22). Future matching algorithms may involve profiling for recommendations, but:

11. Children's Privacy

Tism is exclusively for adults 18+. We do not knowingly collect data from minors. If discovered:

We use age gates and verification to enforce this.

12. Cookies and Similar Technologies

We use cookies for essential functions, analytics, and (with consent) marketing. See our separate Cookie Policy for details:

13. Changes to This Policy

We may update this policy to reflect changes in practices or laws. Material changes (e.g., new data uses) will be notified via email at least 30 days in advance. Continued use constitutes acceptance. Non-material changes are effective immediately. Archived versions available upon request.

14. Supplemental Notice for California Residents (CCPA/CPRA)

This supplements the main policy for California residents:

15. Additional Notices for Other Jurisdictions

15.1 EU/UK/Switzerland

Data transfers protected as in Section 7. Supervisory authorities: EDPS (EU), ICO (UK), FDPIC (Switzerland).

15.2 Other U.S. States

Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA): Similar rights to CCPA; no material differences in our practices.

15.3 Global

We comply with PIPEDA (Canada), LGPD (Brazil), etc., via equivalent protections.

© 2025 Tism App LLC. All rights reserved.
This policy is comprehensive to empower our neurodivergent community with full knowledge and control over their data. If anything is unclear, contact us – we're here to help.