Legal · last updated August 5, 2026

Privacy Policy

This Privacy Policy explains how Raft Ventures, Inc. (“Raft,” “we,” “us,” or “our”) collects, uses, shares, and protects information about you when you use the Raft mobile application, website, and related services (collectively, the “Services”). Raft is a community-first social network for organizing real-world activities, meeting people, and forming genuine connections. Your use of the Services is also governed by our Terms of Service.

01

The Short Version

Three things about Raft that are worth knowing before you read the rest.

  • We keep a permanent safety record. Reports, blocks, enforcement decisions, meeting history, and the message versions you edit or unsend are retained forever and survive account deletion. This is deliberate — see Section 10.
  • Not everything is permanent. The sensitive things you share about yourself — orientation, religion, politics, substance use — are never part of that record and are deleted when you delete your account. Your wider message history expires after a retention period unless a safety concern has attached to it.
  • We do not sell your data and we do not profile you for ads. Advertising on Raft is a Boosted Ping — a local invitation to a real activity.
02

Who This Policy Applies To

The Services are intended only for adults aged 18 and older. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us at hello@raft.social and we will take appropriate steps to delete it.

People who are not members. We also hold limited information about people who do not have a Raft account: someone invited with a guest pass, someone described in a report, and business contacts we have reached out to about hosting or partnering. We process that information on the basis of our legitimate interest in operating a safe service and in reaching businesses, we do not use it to build a profile, and every outreach message carries an unsubscribe link. Write to us to see or remove what we hold about you.

03

Information We Collect

We collect the following categories of information:

  • Account & profile information — your name, email address, date of birth, gender, photos, voice intro, bio, city, languages, employment role and company, height, interests, and the profile statements you write. We do not ask for or store your phone number.
  • Sensitive personal information — where you choose to provide it: your sexual orientation, religion, political views, family intentions, and whether you drink, smoke, vape, or use marijuana or other drugs. This is optional, it is collected with your explicit consent, you can remove it at any time, and it is deleted when you delete your account. See Section 5.
  • Identity & age verification information — a government-issued photo ID and a live selfie used to confirm your identity and that you are 18+, along with the verification result. See Section 4.
  • Location information — precise and/or approximate location used to surface and create Pings, perform venue check-ins (by QR code or geolocation), establish proof of presence, and suggest relevant nearby activity, where you have granted the necessary permissions.
  • Activity & social information — the Pings you create or join, your check-ins and attendance, the Harbors and Rafts you belong to, friends, matches and unmatches, and your activity and date history.
  • Content — photos, notes, voice messages, and messages you share, including short-lived post-activity recaps, and every version of a message that you edit or unsend.
  • Calls, and their content when transcription is on — we keep call records such as who called whom, when, and for how long. When live transcription is enabled for a call, the speech of everyone on that call is processed into text, and translated where you speak different languages. Voice messages can be transcribed on request. See Section 7.
  • Safety & moderation records — reports you file or that are filed about you, blocks, moderation decisions, attendance and no-show history, and enforcement actions on your account.
  • Support correspondence — messages you send us and our replies.
  • Payment information — handled by our third-party payment processors; we receive limited billing details (such as confirmation of payment) and do not store full payment card numbers.
  • Information collected automatically — device identifiers and model, operating system, app version, locale, timezone, IP address, app interactions and screens viewed, and diagnostics and crash data.
  • Information from others — for example, when a member invites you with a guest pass, reports you, or includes you in content or a check-in.
04

Identity & Biometric Verification

To confirm identity and age, our verification provider — currently Sumsub — compares your selfie against your government-issued ID, which involves processing facial-geometry information. Where this constitutes biometric information under applicable law, it is processed only with your consent and only for identity and age verification, fraud prevention, and safety. We do not use it for advertising, and we do not sell biometric information.

Raft does not receive or store your face template, your ID image, or your selfie. Those stay with Sumsub, under Sumsub’s retention policy, and are destroyed on Sumsub’s schedule. What Raft keeps is the result of the check and an irreversible fingerprint derived from your identity document, which lets us recognize a previously banned person attempting to return. That fingerprint cannot be turned back into your document and is not biometric information.

Before verification, the app may show limited public Ping information using a coarse area and strongly blurred, low-resolution profile-photo derivatives. It does not disclose member profiles, attendee identities, or exact meeting addresses in that preview. The original profile photo and precise venue remain restricted to verified members.

05

Sensitive Information & Consumer Health Data

Some of what a profile can hold is sensitive: sexual orientation, religion, political views, and information about drinking, smoking, vaping, and drug use. Under U.S. state law, substance use and sexual orientation can also be “consumer health data.”

All of it is optional. We collect it only if you choose to fill it in, only with your explicit consent, and only to show it on your profile and to help match and surface people and activities you are more likely to want. We do not use it for advertising, we do not sell or share it, and we do not use it in moderation or enforcement decisions.

You can remove any of it from your profile at any time, and it is deleted when you delete your account — it is never part of the permanent safety record. If you are in a state with a consumer health data law, you also have the specific rights that law gives you, including the right to withdraw consent and to have the data deleted; write to privacy@raft.social.

06

How We Use Information

We use information to:

  • provide, operate, and maintain the Services, including Pings, check-ins, and dating;
  • verify your identity and confirm you meet the 18+ requirement;
  • protect safety and trust — preventing fraud, detecting duplicate or banned accounts, enforcing our Terms, and maintaining the safety record;
  • review and moderate content and conduct, including automated and human review, and apply enforcement actions;
  • translate messages, profiles, and other content when you or the person you are speaking with uses translation;
  • transcribe calls and voice messages where transcription is enabled;
  • personalize your experience and surface relevant communities and activities;
  • process payments and provide customer support;
  • communicate with you about the Services, including service and security notices;
  • comply with legal obligations and respond to lawful requests; and
  • improve, secure, and develop the Services.
07

Calls, Voice & Transcription

When live transcription is turned on for a call, the audio of everyone on that call is streamed to a third-party speech-recognition provider (Deepgram), converted to text, and — if the two of you speak different languages — translated by a machine translation model so each of you can read the other. Voice messages can be transcribed the same way, when someone asks for a transcript.

Both people are told before a call is transcribed, and either can decline. Declining ends transcription for that call, not the call. We do it this way because recording and transcription law varies and many places require everyone’s consent — and because nobody should find out afterwards that their voice was transcribed.

When transcription is off, we keep only call metadata: who called whom, when, and for how long. We do not record call audio.

08

Automated Systems, AI & Enforcement

Some parts of the Services run automatically. We use automated systems, sometimes combined with human review, to detect duplicate or banned accounts, to screen and prioritize reports, to limit the reach of content, to decide when dating access is admitted or queued, and to apply penalties for conduct such as not showing up to an activity you committed to attend.

We use AI models to help moderate. When you create or edit a Ping, its text is sent to a large language model (Anthropic’s Claude) to categorize the activity and flag content that breaks our rules. The model sees the activity text, not your profile or your messages. It is not used to train anyone else’s models.

These decisions affect what you can see and do on Raft, not your legal rights. You can always ask for a human to look again, tell us why you think a decision is wrong, and get an answer with reasons — write to hello@raft.social.

09

How We Share Information

We share information only as described here.

Service providers, who process information only on our instructions and only to run the Services:

  • Sumsub — identity and age verification
  • Apple, Google, RevenueCat, Stripe — payments and subscriptions
  • Deepgram — speech-to-text for calls and voice messages
  • DeepL — machine translation of messages and profiles
  • Anthropic — AI classification and moderation of activity text
  • LiveKit — real-time voice and video, and translation of live transcripts
  • Google Maps Platform — places, geocoding, and maps
  • PostHog — product analytics and crash reporting, and website analytics and session replay
  • Expo, Apple, Google — push notification delivery
  • Resend — transactional email
  • Amazon Web Services — media storage; and our hosting and database providers
  • Vercel — website hosting and cookieless site analytics

Other members — your profile and activity are shared with other members according to your settings and the nature of the feature (for example, a potential match sees your profile, and attendees of the same activity see a shared recap).

WithCoach — if you use the coaching experience offered with our partner WithCoach, we pass a pseudonymous identifier unique to that partner, confirmation that you are a verified adult, and your email address once, so an existing account can be linked. WithCoach never receives your Raft user id.

Safety & legal — to protect the rights, property, or safety of members or the public, to comply with the law, to respond to lawful requests, and to enforce our Terms. We report apparent child sexual abuse material to the National Center for Missing & Exploited Children as required by 18 U.S.C. § 2258A.

Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.

We do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not run engagement-based advertising that profiles you.

10

Retention: What We Keep, and For How Long

Raft retains more than most consumer apps, deliberately, and it is easier to explain in tiers than in paragraphs. The reasoning is in our Terms, Section 6.

Kept permanently — survives account deletion and ban. This is the safety record:

  • an irreversible fingerprint of your verified identity, your verification result, and any enforcement decision, so a banned person cannot return under a new account;
  • reports you filed and reports about you, blocks, and the moderation decisions and reasons attached to them;
  • your meeting history — gatherings created and attended, check-ins, matches and unmatches, and call metadata;
  • every version of a message you edited or unsent, in a record we cannot alter or delete;
  • a minimal account tombstone, including your email address, so the account cannot be re-created.

Kept while your account is live, then removed. Your messages, media, voice notes, transcripts, bio, and profile text are removed 24 months after you delete your account — unless a safety concern has attached to your record, in which case they are preserved. A safety concern attaches when someone reports you, when you report someone, when someone blocks you, when a child-safety flag is raised, when law enforcement asks us to preserve records, or when you delete your account while carrying a recent report or block.

Deleted when you delete your account. Your sensitive profile information — orientation, religion, politics, substance use, family intentions — and your device records.

Kept briefly. Screen views, session records, translation caches, analytics and crash telemetry, and server logs are kept only as long as needed to run and secure the Services, and are then removed on our normal schedules.

Kept because the law requires it. Billing and tax records for as long as tax and accounting law requires. Records subject to a law-enforcement preservation request or a litigation hold, for as long as that obligation lasts. Records relating to a report of child sexual abuse material, as required by 18 U.S.C. § 2258A.

Short-lived post-activity recaps are visible to attendees for roughly 24 hours and are then archived rather than shown.

11

Your Rights & Choices

Retaining a safety record does not suspend your rights. Whatever we keep, and whether or not your account still exists, you can:

  • Access — ask what we hold about you and get a copy;
  • Correct — have factual errors fixed;
  • Delete — have deleted everything outside the safety record, on the schedule in Section 10;
  • Port — receive your content in a portable format;
  • Object — object to how we use your information, and have the objection considered on its merits and answered with reasons;
  • Withdraw consent — for sensitive information and for verification, at any time, without affecting past processing;
  • Ask for a human — for any automated decision that gates your access; and
  • Complain — to your data protection authority or attorney general, without prejudice.

Where we refuse an erasure request in part, we will tell you exactly what we are keeping and on what ground. We will not discriminate against you for exercising any of these rights.

  • EEA / UK: we process your information under legal bases including performance of our contract with you, our legitimate interests (safety, security, and fraud prevention — including the retention described in Section 10, for which we have carried out and documented a balancing assessment), your explicit consent (for sensitive information and for identity verification), and compliance with law. You may lodge a complaint with your local supervisory authority.
  • California & other U.S. states: you have the right to know, access, correct, and delete personal information, to limit the use of sensitive personal information, and to opt out of the sale or sharing of personal information. As noted above, we do not sell or share your personal information. We retain each category for the periods, or on the criteria, described in Section 10.

To exercise any of these rights, contact privacy@raft.social. We may need to verify your identity before acting on a request, and we will respond within the time your law allows.

12

Cookies & Similar Technologies

The Raft app does not use advertising cookies or trackers, and does not track you across other companies’ apps or websites. It stores identifiers on your device to keep you signed in, remember your settings, and deliver push notifications, and it sends product analytics and crash diagnostics to PostHog.

The Raft website uses analytics cookies, provided by PostHog, to understand how the site is used: which pages you read, what referred you, and a replay of your visit that records your clicks, scrolling, and navigation. It also sets cookies strictly necessary to serve the site. We do not set advertising or profiling cookies, and we do not track you across other companies’ websites.

Where the law requires your consent before we may set analytics cookies — including the European Economic Area, the United Kingdom, Switzerland, Thailand, and China — we ask before setting them, and declining is exactly as easy as accepting. Elsewhere, analytics cookies are set when you arrive. Wherever you are, you can change your answer at any time: .

If you decline, we fall back to cookieless measurement: we count the visit using a privacy-preserving hash computed on PostHog’s servers, and set no cookies, record no replay, store no IP address, and keep nothing that identifies you or follows you between visits.

13

Security

We use administrative, technical, and physical safeguards designed to protect your information. Access to the safety record and to member data is limited to staff who need it, and the message archive cannot be altered or deleted by anyone — which protects you from quiet edits as much as it protects the record. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Please help protect your account by keeping your credentials confidential.

14

International Data Transfers

We are based in the United States and process information there, and our providers may process it elsewhere. Where we transfer personal information out of the EEA, the UK, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, and we assess the protections available in the destination country. Ask us for a copy of the relevant safeguards at privacy@raft.social.

15

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes — particularly to what we retain or who we share with — we will provide notice through the Services or by other reasonable means before they take effect, and update the date above.

16

Contact Us

For privacy questions and to exercise your rights: privacy@raft.social. For anything else: hello@raft.social.

Raft Ventures, Inc., a Delaware corporation, is the controller of your personal information.