Last updated 2026. This describes how Fledge uses data in the customer app. There is no separate CMS privacy document on the API — this matches the product as shipped.
Account details you submit (name, email, college, profile), listings you favourite or express interest in, roommate and Need Now posts, chat messages, reports, and device session metadata used to keep you signed in.
To run discovery, matching, chat, ads selection on home/search/listing placements, and safety features (moderation of images that contain contact details, block/report). Analytics events are allowlisted — message bodies and raw contact values are not sent as tracking properties.
Sign-in uses an HttpOnly access cookie (`cp_access_token`, short-lived) plus a refresh cookie. The browser talks to our same-origin proxy; the proxy attaches the API token. You cannot set that cookie from JavaScript.
Phone numbers are revealed only after an approved, time-bounded access grant with a maximum view count. Revealed numbers are treated as sensitive: they are fetched no-store and should not be persisted in analytics.
Notification and marketing toggles live under Settings. You can export a copy of stored data or request erasure from Settings → Your data (signed in). Erasure requires typing a confirmation phrase so it cannot happen by accident.
Privacy questions: contact us.