Blue Rush

Privacy Policy

Last updated: August 22, 2026

1. Scope

This policy describes what Blue Rush collects, why, who can see it, how long it is kept, and how to remove it. It applies to the Blue Rush website and to the same site installed on a phone. Blue Rush is for university students and is not affiliated with any University. Blue Rush does not sell personal data and does not share it with advertisers or data brokers.

2. What is collected

Everything below is given by you, or produced by your use of the site.

  • Account. Your campus email address, the time you created the account, your last sign-in time, and the time you accepted the Terms. Sign-in codes are sent to your email and checked once; they are not part of your profile.
  • Identity. First name, last name, username, birth date, gender (Man, Woman, or a description you type), campus, major, and class year. Your birth date is used to derive your age group (under 18, or 18 and older) and your campus is derived from your email domain. Both are permanent.
  • Red Rush preferences. The genders you seek, asked only if you enter Red Rush.
  • Profile. A bio of up to 280 characters and up to four photos.
  • Survey answers. Your answers in the two files of each rush describe you. Only in Red Rush, and only in a small number of questions, may you also state what you look for and how much it matters. Each answer is stored as its own record. From your answers we compute a sealed matching signature that is never readable by any user, including you, and a short public file code built only from harmless answers (your music, your dorm zone, your gym meter, your social battery). Where you heard about Blue Rush is stored separately and never used for matching.
  • Red Tick submission. For Red Rush, a photo of a government identity document and a live selfie. See section 5.
  • Matches. Each daily batch, the people shown to you, the compatibility percentages by domain, the short descriptive lines on each match, whether you passed, and a history of who was shown to whom, consulted for 30 days so nobody repeats.
  • Conversations. Each thread, its text messages, when each message was read, and which threads you have left.
  • Safety records. Blocks you make and reports you file or receive, with the reason and any details written.
  • Notifications. In-app notification rows for four events: your three are ready, a new message, a thread opened with you, and a Red Tick decision. If you turn on push notifications, the browser's push endpoint, its keys, and your browser's user agent string are stored so that the 5 PM notice can reach that browser.
  • Preferences. Two email switches (your three are ready, new messages), both on by default.
  • Queued email notices. When an email switch is on, a record that a notice was due is written to an outbox. See section 7.

On your device, Blue Rush stores the sign-in session cookie, a cookie holding the rush colour you last chose, your sign-up answers in the browser's session storage until the account exists (they are discarded if the tab closes first), and two local settings: whether sound is on and whether the install prompt has been answered. Blue Rush contains no advertising, no analytics scripts, and no tracking pixels.

3. Why it is collected

  • To admit only holders of an active campus email and to sign you in.
  • To place you in the right pool: your campus, your age group, and each rush you hold.
  • To compute compatibility percentages and deliver up to three matches per rush per day (two per rush for members of both rooms).
  • To carry text conversations between matched people in real time.
  • To act on blocks and reports, to review Red Tick submissions, and to keep a record of enforcement.
  • To notify you in the app and, if you turn it on, on your phone.

Blue Rush uses no automated profiling beyond the compatibility computation described in the Terms, and no data from third parties.

4. Who can see what

  • Your matches and conversation partners can see your first name, username, gender, bio, major, class year, photos, whether you hold the Red Tick, and the compatibility percentages computed between the two of you. Photos are shown through links that expire after one hour. They cannot see your last name, birth date, email address, the genders you seek, your survey answers, or anyone else's matches.
  • People you have blocked, and people who have blocked you, can see nothing of you. The database refuses the read.
  • People in the other age group, or at another campus can see nothing of you. This is a database rule applied to every read, every match, and every conversation.
  • Nobody can browse. There is no directory, search, or feed. The only people who ever see your profile are your daily matches and the people you are already talking to.
  • Administrators review reports and Red Tick submissions and keep the service safe. An administrator can open an account's file: email, profile record, photos, survey answers, Red Tick status, match history with percentages, counts of messages, blocks, and reports in both directions. Administrators are never shown the text of messages. A Red Tick document and selfie are viewable only by the reviewer, through links that expire after 30 minutes, and only until the decision.

5. The Red Tick files

The identity document and the live selfie are uploaded to a private storage area. The storage rules allow you to write your own files and allow no signed-in account to read them, including yours and including administrators signed in as users. The review happens server-side. The moment a decision is recorded, approved or declined, both files are deleted, before anything else; if deletion does not succeed, no decision is recorded. After the decision only the decision, its timestamps, and the reviewer's identity remain. A file path is never written to any log.

6. Where the data lives and who processes it

  • Supabase provides the database, sign-in, file storage, and the real-time channel for chat. Every table is protected by row-level rules that deny access by default; photos and Red Tick files are in private buckets with no public address.
  • Netlify hosts the website and runs its server code.
  • Push services. If you turn on push notifications, the notice travels through your browser maker's push service (for example Google, Apple, or Mozilla). The notice contains a title, a short line, and a link into the app, never message text.

Blue Rush may disclose data when the law requires it, or when needed to protect a user from serious harm.

7. Email

Today the only email Blue Rush sends is the sign-in code. Settings carries two switches, “Your three are ready” and “New messages”. While a switch is on, Blue Rush records a queued notice in its outbox at the relevant moment; no email is sent from that queue today. If Blue Rush begins sending these notices, it will send them only for those two purposes, only while the matching switch is on, and this policy will be updated first.

8. How long it is kept

  • Your account data is kept while your account exists.
  • Red Tick files are kept only until the decision, then deleted (section 5).
  • The shown history is consulted for 30 days and removed with your account.
  • Matches and conversations are kept while both accounts exist. When either person deletes their account, the conversation and its messages are removed for both.
  • Push subscriptions are removed when the browser's push service reports the subscription gone, or when your account is deleted.

9. Deleting your account

You can delete your account from Settings by typing DELETE. The deletion is immediate. Your photos and any pending Red Tick files are removed from storage first; then your sign-in identity is deleted and everything tied to it is removed by the database in the same step: profile, survey answers, memberships, batches, matches, shown history, conversations and messages on both sides, threads you left, blocks you made, notifications, push subscriptions, queued email notices, and Red Tick records.

Three things remain after deletion:

  • A dated row in a deletion log, recording only that an account was deleted and when. It carries no personal data.
  • Reports filed about you, kept for safety review, with your account identity removed. Reports you filed about others are deleted with your account.
  • If an administrator ever acted on your account, the action log keeps that action and the email address it concerned, because the log cannot be edited or deleted.

Messages you sent remain visible to their recipient only until either account is deleted.

10. Your controls

  • Edit your username, bio, photos, and survey answers from your Profile.
  • Your name, gender, major, and class year are set during sign-up and are not edited in the app today. To change one, write to the address below.
  • Turn each rush membership on or off from your Profile.
  • Turn the email switches on or off in Settings.
  • Turn push notifications on from the notifications prompt. Revoking the notification permission in your browser's site settings stops delivery to that browser.
  • Leave any conversation, block any person, report any person.
  • Delete your account from Settings.
  • Ask for a copy of your data, or for help with anything above, at hello@thebluerush.com.

11. Users under 18

Blue Rush accepts users aged 13 to 17 who hold an active campus email. They use Blue Rush only, are matched only with other users under 18, cannot enter Red Rush, and cannot submit a Red Tick. The interface never offers Red Rush to a minor, and the database refuses it regardless of the interface. The age wall and the campus wall are covered by automated tests in the Blue Rush codebase.

12. Security

  • Sign-in is by a code typed into the site. Blue Rush never sends a sign-in link and never stores a password.
  • Every database table denies access by default. What a signed-in person can read is decided row by row by their own identity, their campus, their age group, and their blocks.
  • Photos and Red Tick files live in private storage with no public address. Photos are served through links that expire after one hour.
  • Administrative reads go through functions that first verify the administrator's role; administrative actions are logged in a table that refuses edits and deletions.

13. Changes and contact

The date at the top of this page shows when it last changed. For any question about this policy, or to exercise a privacy right, write to hello@thebluerush.com. This policy is governed by the laws of the State of Oklahoma. See also the Terms of Service.

Get the app on your phone

Blue Rush installs from the browser and lives on your home screen like any app. The button explains the steps for your phone.

Questions about these pages: hello@thebluerush.com

For university students. No affiliation to any University.