What we hold about you, and what we do not.

The plain version

If you join the list on this website, we hold your first name, your email address, and the record of your consent. If you have the app, we also hold those three and — only if you choose to write them — four short things you say about yourself, shown only to a man seated in the same live circle as you, at that moment, and only when he taps your seat.

Everything else you write in the app stays on your phone: change phones or reinstall and it is gone. Circles are not recorded. What we will not claim is that we cannot see your data — we can, and what you write about yourself sits in a database we control, inside the EU.

To have all of it deleted, write to privacy@tembral.com with the word delete, or use the page that explains every way out. You do not have to say why.

Two things, and which one this page is about

This page describes two systems, and it names which one it means.

This website collects one thing: the list of people waiting for the app to open. The iPhone app is where accounts live, where what you write about yourself is held, and where circles happen — audio only, on a server we run ourselves inside the EU. The Sunday circle offered here is a third thing, a video call on Zoom; item 9 sets out what it receives.

Who is responsible, and how to reach us

The controller of this data is Frank Flores, trading as Tembral, a sole trader in the Netherlands, in Amsterdam, the Netherlands.

For anything about your data — a copy of it, a correction, deletion, a complaint — write to privacy@tembral.com. For anything else, write to frank@tembral.com. One person reads both.

A postal address is available on request. The full identification details are on the legal notice.

No data protection officer is appointed; Article 37 does not require one at this scale.

What is held, record by record

This is the whole of it.

On this website, if you join the list: your first name, your email address, and the record of your consent. No IP address, browser, referrer, timezone or device information is recorded with it.

In the app, if you have an account:

  • Your account: your email address — or Apple’s private relay address, if you sign in with Apple and hide yours — the sign-in method, and your session.
  • Your first name, and the record of your consent.
  • About you, if you fill it in — four fields, every one optional: where you are, what you’re here for, love and the lack of it, and a short piece you write yourself.
  • The schedule: for each sitting, its details, its host and its facilitator, and which accounts may put a circle on it. Nothing about who attended.
  • That one account blocked another, and when.

And on both: server logs recording whether a request succeeded or failed. No field value and no name is written into one.

If you write to us, we hold your email and our reply until you ask us to delete it.

What is not held, and what that costs you

Your reflections, your check-ins, the lines you keep and the people you choose are stored on your phone only.

Say this to yourself before you write anything: if you change phones, or delete and reinstall the app, all of that writing is gone. There is no backup of it, because there is no copy of it.

What is not collected at all:

  • No photograph in the app. It does not ask for one, and does not request your camera or your photo library.
  • No video. Circles in the app are audio only.
  • No location of any kind.
  • No advertising pixel, no advertising software kit, no cross-app identifier, and no prompt asking to track you across other apps.
  • Nothing about you is sold, ever.
  • No language model reads anything you write or say, and nothing is used to train one.

Two consents, and they are not the same one

Tembral asks for consent twice, and one does not stand in for the other.

At the door of a sitting.
Before your first circle, one tick confirms that you are eighteen or older and that you have read the terms and this notice. No tick, no circle.
For the four things you write about yourself.
Before a single character reaches the server, a separate line with its own tick says that you want the men in a circle with you to see what you put there, that it is kept with your account inside the EU, and that it stays until you change or delete it. It is unticked when the screen loads and is not bundled into the door consent or the terms; bundling it would make it invalid under Article 7(2).
How you take either one back.
Blank the field on your own screen. Blanking overwrites, and blank is a complete profile. Deleting your account removes them with everything else. Withdrawal stops any further use from that moment; it cannot un-say what another man already read.

Why Article 9 applies, said plainly

Being on this list says something about you — that you are a gay man looking for a room like this one — and European law puts that in the same category as your medical records. What you may write in the app goes further.

That is data revealing health, data revealing sexual orientation and data about a man’s sex life, stated by him outright rather than inferred. Under Article 9 it may not be processed at all unless one of a short list of conditions is met. The one Tembral uses is the first: your explicit consent, Article 9(2)(a). There is no other basis available here.

Who can read those fields is limited as narrowly as the product allows: one man at a time, only a man seated in the same live circle as you, at that moment, and only when he taps your seat. It is enforced on the server, not in the app.

They are not on the schedule, not searchable, and there is no browse and no directory.

Every purpose, and the basis it rests on

The list on this website.
Consent — Article 6(1)(a), and Article 9(2)(a) for what being on the list reveals. An address counts as consented only once you press the link in a confirmation email.
Your account, sign-in and first name.
Performance of a contract — Article 6(1)(b).
Running circles, and carrying their audio and chat.
Performance of a contract — Article 6(1)(b).
The four About-you fields.
Explicit consent — Article 9(2)(a), with Article 6(1)(a). Nothing else.
The block record, and refusing to seat a blocked pair.
Legitimate interests — Article 6(1)(f): the safety of the men in the room, weighed against two identifiers and a time.
Counting how the app is used.
Legitimate interests — Article 6(1)(f), on measurements that carry no name.
Counting how this website is used.
Legitimate interests — Article 6(1)(f). No cookie, no address, and nothing that survives to a second visit.
Answering a lawful legal demand.
Legal obligation — Article 6(1)(c).

No decision about you is made by a machine: there is no automated decision-making and no profiling.

Who else touches it

A small number of companies hold or move part of this on our instructions: the database and sign-in, this website, the server that carries a circle’s live audio, the sending of mail, anonymous usage counting in the app and on this website, the mailbox you write to, and a feedback board you only reach if you go to it. What each one does, and whether it is inside the EU, is on a page of its own, along with how to ask us for the names.

What you write about yourself is held on a database inside the EU. For the hour a sitting runs, its audio is relayed by a server we operate ourselves, also inside the EU, and nothing from it is kept.

What the live circle carries, and does not keep

The app’s circles run on a server we operate ourselves, on a machine in the EU. It carries live audio, plus the chat lines and reactions sent during a sitting, encrypted between your phone and that server.

It is not end-to-end encrypted, and that matters enough to say rather than to imply.

For the moment it is being relayed, the audio passes in readable form through a machine we run. Nothing is written down there — no recording, no transcript, no summary — and nothing from a sitting is retained.

What Zoom receives, for the Sunday circle

The Sunday circle offered on this website is a video call on Zoom.

Zoom receives the display name you type when you join, your IP address, and the audio and video of the call as it happens. It does not receive your email address, your first name from the list, or anything you have written.

Nothing is recorded.

What the usage measurements carry

The app counts how it is used, in events that carry no name.

The identifier attached to them is created at random on your device and cannot be matched to your account. That cuts both ways: if you object to the measurements, we cannot find yours and remove them, because we cannot tell which ones are yours.

The company that receives them is named on the subprocessors page.

Data leaving the EU

Almost nothing does.

The database, the circle server, the mailbox and the usage counting are all inside the EU, and so is this website.

Mail is the transfer that actually happens. Every message we send — the code that signs you in, and the link that confirms your address on this website — is relayed by a company in the United States. Your address and the message leave the EU each time.

Two of the companies holding EU data are American companies. Their machines are in Europe and the companies are not. Data residency in Europe and a European company are not the same thing, and it would be easy to print only the flattering half of that.

You may ask for a copy of the safeguard covering any of these at the privacy address.

How long each record is kept

Account, first name, consent stamps.
Until you delete your account in the app.
The four About-you fields.
Until you blank a field, or delete your account.
Block records.
Until either of the two accounts is deleted.
Live audio, chat lines and reactions.
Not retained at all.
A list row you never confirmed.
30 days from the earlier of when the row was made and when you gave the address.
A list row you confirmed.
Until you unsubscribe, or ask us to remove it.
A list row after you unsubscribe.
The row is marked so the list cannot mail you again, and it stays. Ask, and we delete it outright — that is your right and not a favour.
The Sunday circle list, if you never took a seat.
Deleted 90 days after you joined.
Mail already sent.
The sending provider holds a message’s content for 45 days, and that cannot be shortened.
Usage measurements and server logs.
Under each provider’s own schedule. Ask, and we will tell you the current figure.

Deleting it, and what deletion really reaches

Every way out is set out on its own page.

Deleting the row from the live database does not delete it from the provider’s backups.

So the row is gone from the live system at once, and gone from everywhere once the provider’s backup window has passed. Ask us what that window is and we will tell you. We will not write “deleted immediately”, because it would not be true.

Your rights, and exactly how to use each one

Write to privacy@tembral.com for any of these, unless a faster way is named.

See what we hold.
Ask, and we send back every row we hold about you.
Correct something.
Change your first name and the four About-you fields yourself, in the app. Otherwise, write and say what is wrong.
Delete it.
In the app: your own screen, then delete your account. For the list: the unsubscribe link, or write to us.
Take it with you.
Ask, and we send a machine-readable file of those rows.
Freeze it while something is disputed.
Ask, and we suspend the account and stop the About-you fields being served to any room.
Object to anything done on legitimate interests.
The block record and the usage measurements. Ask, and we stop what we can, with the limit in item 10.
Change your mind, without giving a reason.
For About you: blank the fields. For the list: the unsubscribe link or one email.
Complain.
To us, or to the Dutch supervisory authority, or to the authority where you live. Item 15 has the addresses.

The law gives us one month, and one month is the promise.

A complicated request may take two further months, and we will tell you inside the first month if it does. It is free unless clearly unfounded or excessive, and we may ask you to confirm who you are first.

If you want to complain

To us: write to privacy@tembral.com and say what we got wrong.

About us: the Dutch data protection regulator is the Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, autoriteitpersoonsgegevens.nl. If you live elsewhere in the European Union you can complain to your own country’s regulator instead. You do not have to speak to us first.

Security, and what happens if there is a breach

Everything travels encrypted, the database is encrypted where it rests, and access to it is restricted. No system is perfectly secure, and saying otherwise would be the first lie in this document.

If a breach happens, we notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of it, as Article 33 requires. Where it is likely to put you at high risk we tell you as well, without undue delay and in plain words: what happened, what was in it, and what you can do.

Cookies, and what this website counts

This website sets no cookies at all, and there is no consent banner because nothing is stored on your device to consent to.

One page view is counted, by a company in the Netherlands, with no cookie and without your address. It cannot tell you apart from anyone else, or recognise you on a second visit.

That, and what two pages ask your browser to remember for the length of a tab, is set out on the cookies page.

Adults only

Tembral is for adults, eighteen and over. The consent screen asks you to confirm your age, and we do not verify it — we rely on what you tell us. We do not knowingly hold data about anyone under eighteen; if we learn that we do, we delete it and close the account. If you think a minor has given us data, write to privacy@tembral.com.

Changes, and when this was last one

This page was last changed on 6 September 2026.

If a change is material — if it changes what is held, who can read it, where it goes or how long it is kept — you are told in the app and by email before it takes effect, and asked to agree again. Continued use is not an answer.

One version, one date, no archive.