Ttoblues
Privacy Policy

Your conversations deserve clear rules.

Effective: July 27, 2026 · Last updated: July 28, 2026

This Policy describes the information handled by toblues, a verified university-student matching and communications service operated from Ontario, Canada. It explains what is collected, why, who can access it, how long it is kept, and the choices available to you.

1. Scope and accountability

This Policy applies to the toblues website, verification process, text and video matching features, moderation tools, and related communications. “toblues,” “we,” “us,” and “our” refer to the operator of this service. “You” means a visitor or verified user.

We are responsible for personal information under our control, including information processed for us by infrastructure and email providers. Questions, access requests, complaints, and consent withdrawals may be sent to toblues@noonmatches.com.

2. Key points you should understand

  • You must be at least 18 and verify an eligible email address from a supported university.
  • Ordinary text content and optional profile details from the newest 100 completed chats are retained for safety review, subject to technical message and size ceilings.
  • Text entered during a video chat is treated like other chat text.
  • Video and audio currently travel peer-to-peer and are not recorded by toblues.
  • Authorized administrators can review retained chats and reports. They may export information when reasonably required for safety, legal compliance, incident response, or preservation of evidence.
  • We do not currently sell conversation content, use it for targeted advertising, or train commercial AI models with it.
  • Any future AI-training, data-sale, commercial profiling, or platform recording program involving personal information will require a separate, prominent explanation and express opt-in where required by law. It will not be activated merely because this Policy changes.

3. Information we collect

Verification and account-session data

  • Your selected university and submitted university email address while a verification code is pending. Successful verification converts the address to a one-way truncated cryptographic hash used to recognize the verified user; the address itself is not placed in the verified-session table.
  • Hashed session tokens, session creation and expiry times, verification-code hashes, attempt counts, and request times.
  • A hash derived from network address and browser user-agent for abuse prevention. Standard server logs may separately contain IP addresses, request paths, timestamps, response status, referrer, and user-agent.

Profile and matching information

Optional campus, year, gender, program/major, and matching preferences. Your browser saves these settings locally. They are transmitted to our server when you seek a match and may be included with a retained completed-chat record.

Communications and moderation information

  • Chat messages, message timestamps, chat mode, start/end times, pseudonymous participant labels, optional profiles, and cryptographic participant hashes.
  • Reports, selected reason, reporter and reported-user hashes, associated room identifier, mode, timestamp, and available transcript context.
  • WebRTC signaling data needed to establish video connections. Video peers may learn each other’s network address as part of peer-to-peer connectivity.
  • We do not intentionally collect payment, government identifier, precise location, contact list, or device-file data.

Local device storage

Your browser stores your selected university, a verification token, verified email display value, profile, preferences, and age/terms acknowledgement in local storage. Clearing site data removes these local values and may require re-verification.

4. Why we use information

  • Verify eligibility and prevent unauthorized access.
  • Provide optional preference-based matching and avoid immediate repeat matches.
  • Relay messages and WebRTC signaling.
  • Maintain safety archives, investigate reports, identify coordinated abuse, and preserve evidence of suspected exploitation, child-safety threats, violence, fraud, harassment, or other unlawful conduct.
  • Rate-limit traffic, prevent spam, diagnose failures, secure accounts and infrastructure, and measure capacity.
  • Generate aggregate operational statistics, such as verified-user counts, queue sizes, chat modes, duration, message counts, and aggregate optional-profile distributions.
  • Comply with lawful requests, enforce our Terms, establish or defend legal claims, and protect users or the public.
  • Communicate about verification, service operation, material policy changes, or a security incident.

We limit collection, use, and disclosure to purposes a reasonable person would consider appropriate in the circumstances and to additional purposes for which valid consent or other lawful authority exists.

6. When information may be disclosed

We do not publish private chat archives. Information may be available to:

  • Authorized administrators who need access for moderation, security, support, legal compliance, or incident investigation.
  • Infrastructure providers, including Microsoft Azure for hosting in the United States, Zoho for verification email processing in its European infrastructure, certificate authorities, content-delivery providers, and other processors necessary to operate or secure the service.
  • Law enforcement, emergency services, regulators, courts, or affected persons when disclosure is required or permitted by law, necessary to respond to an imminent safety risk, or appropriate to investigate suspected exploitation or serious abuse.
  • Professional advisers and transaction participants under confidentiality obligations for legal, security, insurance, financing, merger, acquisition, restructuring, or asset-transfer diligence. Any successor remains subject to applicable law and disclosed commitments.

We document and limit disclosures where reasonably practicable. We do not promise secrecy where a credible child-safety concern, threat, or legal duty requires action.

7. Artificial intelligence, data sales, profiling, and commercial uses

Current practice: toblues does not currently sell messages, videos, or personal profiles; provide them to partners for their independent advertising; or train commercial AI models with them. Video/audio is not currently recorded by the platform.

We may use de-identified or aggregate operational statistics that do not reasonably identify an individual to improve matching, reliability, capacity, and safety. We will assess re-identification risk and avoid representing pseudonymous data as anonymous where linkage remains reasonably possible.

If we propose using identifiable or reasonably linkable messages, recordings, inferred traits, or profiles for AI development, model training, partner disclosure, sale, targeted marketing, research unrelated to safety, or another non-essential commercial purpose, we will first provide a separate notice describing the exact data, recipients or categories of recipients, purpose, consequences, retention, safeguards, compensation if any, and withdrawal mechanism. We will seek express opt-in consent where required. An email opt-out offered only after collection is not treated by this Policy as blanket authorization for such uses.

Requests or objections may be sent to toblues@noonmatches.com. If a future optional program is introduced, its dedicated controls and notice will govern in addition to this Policy.

8. Retention and deletion

CategoryGeneral retention
Completed chat archiveNewest 100 chats, up to 300 retained messages and 350,000 characters per chat. Older records are automatically removed.
Reports and associated evidenceMay be retained longer, including while required for investigation, safety, legal compliance, dispute resolution, or evidence preservation.
Verified sessionsGenerally expire after 30 days; no more than five active server sessions per verified-email hash are retained.
Pending verificationCodes expire after 10 minutes; expired records are periodically removed.
Server/security logsRetained according to operational logging and security needs, subject to storage rotation and legal holds.
Video/audio recordingsNot collected by the platform at present.

Deletion from active systems may not immediately remove securely rotated backups or records under legal hold. We securely delete or render information inaccessible when it is no longer required, subject to technical and legal constraints.

9. Safeguards and incident response

Safeguards include encrypted transport, restricted administrator endpoints, cryptographically random and hashed sessions, input and packet ceilings, rate limits, database and memory ceilings, automatic pruning, firewall rules, key-only administration, process isolation, security headers, and automatic operating-system security updates. Access is limited according to operational role.

No Internet service is perfectly secure. A peer may record a conversation using device or external tools beyond our control. Do not share information you cannot safely disclose to another student. If a breach creates a real risk of significant harm, we will investigate, preserve required records, notify appropriate authorities, and notify affected individuals as required by law.

10. Access, correction, deletion, and complaints

Subject to identity verification, applicable law, the rights of other participants, privilege, safety, and lawful exceptions, you may request:

  • information about whether we hold personal information about you;
  • access to and correction of that information;
  • withdrawal of consent for optional processing;
  • deletion or an explanation of why information must be retained;
  • information about service providers or significant disclosures; and
  • review of a privacy concern.

Email toblues@noonmatches.com from your verified address and describe your request. Because chats are pseudonymous, we may require session or timing information and may be unable to identify a record reliably. We will not disclose another participant’s personal information without lawful authority and may redact it.

11. International processing

The service is intended for students at supported Canadian universities, but infrastructure providers process information outside Canada, including the United States and European Economic Area. Information may therefore be subject to foreign laws and lawful access by foreign authorities. We use providers and safeguards appropriate to the sensitivity and function of the data, but cannot guarantee that foreign law is identical to Canadian law.

12. Age restriction and child safety

toblues is strictly for persons aged 18 or older. We do not knowingly permit minors. If we learn that a minor used the service, we may suspend access, preserve evidence when necessary for safety, delete information where appropriate, and notify guardians, platforms, or authorities as permitted or required. Report suspected grooming, exploitation, or child sexual abuse material immediately through the report tool and, where urgent, to law enforcement.

13. Changes to this Policy

We may update this Policy as the service, law, or providers change. The effective date will be revised. Material new uses or disclosures will receive prominent notice and renewed consent where required. Continued use does not create consent for a new sensitive or non-essential purpose where express consent is legally required.

14. Contact

Privacy questions, requests, complaints, and consent choices: toblues@noonmatches.com. Include “Privacy Request” in the subject line. You may also contact the Office of the Privacy Commissioner of Canada if you are dissatisfied with our response.