Back to App

Privacy Policy

Last updated: February 13, 2026

Introduction

Marco Polo is a privacy-first connection app designed for intimate, meaningful connections. We collect minimal data and use end-to-end encryption to protect your privacy.

1. Data We Collect

Phone Numbers

We store your phone number in hashed form (SHA-256) for user identification and connection matching. Your actual phone number is never shared with other users.

Custom Messages

Your custom "Marco" and "Polo" messages are encrypted using AES-256-GCM before storage. Only you can decrypt them.

Recovery Email (Optional)

If you choose to add a recovery email, it is stored securely and only used for account recovery.

Connection Data

We store your connections (up to 3) and their current status (waiting, responded, etc.).

2. How We Use Your Data

  • Enable real-time connections between you and your chosen contacts
  • Send notifications when someone signals you
  • Facilitate friend requests and invitations
  • Improve the service and fix bugs

We never: Sell your data, share it with third parties, use it for advertising, or analyze it for marketing purposes.

3. Your Rights (GDPR)

Right to Access

You can export all your data at any time from the Settings menu. This includes your profile, connections, and invitation history.

Right to Deletion

You can delete your account and all associated data at any time from the Settings menu. This action is immediate and irreversible.

Right to Withdraw Consent

You can revoke invitations and remove connections at any time.

4. Data Retention

  • Active accounts: Data is retained indefinitely while your account is active
  • Deleted accounts: All data is immediately and permanently deleted
  • Expired invitations: Automatically deleted after 7 days
  • Inactive accounts: We do not delete inactive accounts automatically

5. Security

End-to-End Encryption: Custom messages are encrypted using AES-256-GCM with keys stored only on your device.

Phone Number Hashing: Phone numbers are hashed using SHA-256 with a salt before storage.

Secure Tokens: Invitation tokens are generated using cryptographically secure random number generation (256-bit).

Firebase Security: All data is stored in Firebase with strict security rules ensuring users can only access their own data.

6. Data Sharing

We do not share your data with third parties except:

  • Firebase (Google): Our infrastructure provider, subject to their privacy policy
  • Legal requirements: If required by law or to protect our rights

7. Children's Privacy

Marco Polo is not intended for users under 13 years of age. We do not knowingly collect data from children under 13.

8. Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any changes by updating the "Last updated" date at the top of this policy.

9. Contact Us

If you have questions about this privacy policy or your data, please contact us at:

Email: privacy@marcopolo.app