actually

Privacy

What we hold, why, and who can see it. The short version is at /terms — this is the long one.

What this is

This explains what we collect, why, and who can see it. The consent you actually give when you sign up is the short version at /terms — this is the long version, for anyone who wants it.

What we collect

Your account: email, password, name, birthdate, city.

What you contribute: photos, voice notes, written answers, and music picks, plus anything optional you fill in about yourself — bio, interests, and attributes like relationship style, kids, smoking, and (only if you choose to say) sexuality, religion, political view, disability, neurodivergence, and background.

What you do here: messages you send, who you ping or match with, who you pass on or block, and usage events like which profiles you open and which of someone's moments you were shown. That last part is the point of the test — it's how we find out whether an uncurated profile is actually more interesting.

The IP address you connect from, recorded at two moments only: when the account is created, and each time you sign in. Not on every request, and not as you move around the app.

The sensitive fields are opt-in, and only ever given by you

Sexuality, religion, political view, disability, neurodivergence, and background are never inferred from anything else — not your name, your photos, your city, or what you write. They're set by one thing only: you choosing an option on your own profile form. Leaving them unset is the default and is treated the same as any other answer — a blank on a profile.

There's no per-field privacy switch on these. If you set one, it's shown the same way the rest of your stated facts are — that's stated on the form itself, not just here.

Why we collect it

To run the product: match you with people, assemble what a visitor sees of your profile, deliver messages, and send the notifications you'd expect (a match, a reminder to check in). Nothing here is used for ads, and nothing is sold to anyone.

To keep it usable: reports are read by a person, and if someone is making this unpleasant for other people that person can pause or close their account. The IP address is part of the same job — it makes it harder for an account closed for behaviour to be replaced by a fresh one from the same connection. It is not used to locate you, and one address is often a whole household or a whole mobile network, so it is treated as the weak signal it is.

We also use it to learn whether the core idea works — a daily, system-curated profile instead of one you build yourself. That's what the usage events are for. It's a couple of weeks with a handful of people, not an ongoing analytics pipeline.

Encryption, and what it does and doesn't do

Sensitive fields — your email, bio, birthdate, messages, and the attributes above — are encrypted in the database, so a copy of the database or a leak shows unreadable data by default, not your information.

The person running this test can still deliberately access it through the app itself, same as the rest of what's described in this notice — encryption protects against a stolen copy of the database, not against the operator choosing to look.

Photos and voice notes sit as ordinary files on server storage, not encrypted, and aren't covered by the database backups.

Who can see what

The person running this test can see everything in the database, including messages — see /terms. Other users see only what the app's randomizer chooses to show them from what you've contributed, never your full history, and never anything you've deleted.

A report you file, or one filed about you, goes to that same person by email, and they can see it on a screen only their account can open. There's no wider moderation team, and nobody else reviews it.

Two outside services see a limited slice: your device's push notification provider (if you enable push) and, if a photo you took prompts a music search, Apple's iTunes Search API sees the search text — no account or identifying link is created with either.

How long we keep it

Until you delete it or close your account. Deleting a photo, voice note, or answer removes it immediately and for good — it can't be recovered, and it can never be shown to anyone again.

IP addresses are kept as long as the account is, and go when it goes. A blocked address is the one thing that outlives an account, because deleting it would undo the block it exists to be.

Closing your account removes your profile, every photo and voice note (including the underlying files), your messages, your matches, and the addresses recorded against it. Feedback you've left is the one exception: it stays, with your name removed from it, because it's about the product rather than about you.

Your rights

Ask, and you'll get a copy of everything we hold about you — profile, contributions, check-ins, matches, full conversation text, and a log of your activity. A few things about other people are left out: who passed on you, who viewed you, and anything reported or blocked, because handing those over would expose someone else.

If your account was ever paused or closed, you'll be told that it happened and when — but not the private note whoever did it wrote for themselves, which isn't something you gave us. Ask, and a person will explain in their own words.

You can correct anything by editing it yourself, or delete your account outright from Settings — both take effect immediately, whatever your account's standing.

Questions

Ask whoever invited you — they run this test and this is the only place your data lives.

Version 2026-08-24.1.