Privacy Policy
Last updated: July 4, 2026 — Template, not legal advice.
1. Who we are
Datemaxxing ("we", "us") operates the Datemaxxing dating application (the "Service") at datemaxxing.eu. Contact: privacy@datemaxxing.eu. [Insert legal entity name, registered address, and — if required under GDPR Art. 27 — your EU representative.]
2. Data we collect
- Account data: email address, hashed password (managed by our authentication provider, Supabase Auth).
- Profile data: username, date of birth, gender, gender(s) you're interested in, bio, city.
- Photos: images you upload to your profile.
- Activity data: swipes, matches, messages you send.
- Cookie/consent data: your cookie preferences (see Section 8).
- Technical data: IP address, device/browser type, and log data collected automatically by our hosting provider for security and abuse prevention.
- Age assurance data: your self-attested date of birth and an explicit, timestamped confirmation that you are 18 or older, recorded at signup and re-confirmed periodically (Section 11).
- Location data (optional): if you opt in to distance-based discovery, an approximate latitude/longitude used only to rank and show distance in the Discover feed. Off by default; you can disable it at any time, which deletes the stored coordinates. We never show your exact coordinates or address to other members.
- Payment data: if you subscribe to a paid plan, our payment processor (Stripe) collects your payment card details directly — we never receive or store your full card number. We retain only the subscription status, plan, and Stripe customer/subscription identifiers.
- Profile prompts (optional): up to three question-and-answer prompts you choose to fill in, shown on your card the same way your bio is.
- Compatibility embedding (optional): if your bio and/or prompts are long enough to be meaningful, we generate a numeric "text embedding" from that combined text to compute a Compatibility Score with other members who have also done so (Section 3). This is derived only from text you already chose to make visible to other members — never your photos.
- Verification selfie (optional, not stored): if you use Photo Verification (Section 3), a live selfie you capture in-app is sent to our AI vision provider to compare against your existing profile photo and is never written to our database or storage — it exists only for the duration of that one request.
- Safewalk check-ins (optional): if you use the Safewalk safety feature, we store your trusted contact's name and email address (which you provide — please only add someone who has agreed to this), an optional destination label, an optional location snapshot, and the check-in timer. We use this solely to email that contact if you don't confirm you're safe in time. Note: your trusted contact is not a Datemaxxing user, and their email is used only for this safety alert, never for marketing.
We do not collect government-issued ID or biometric identity documents in the MVP version of the Service.
3. Photos and the optional "PSL Score" feature
Photographs of your face can be considered sensitive/biometric-adjacent personal data in some jurisdictions (e.g. "special category data" under GDPR Article 9, or a "biometric identifier" under laws such as the U.S. Illinois Biometric Information Privacy Act). We designed this feature to minimize that risk and to always keep it under your control:
- The PSL Score is entirely optional and off by default. Core features (profile, swiping, matching, chat) work without ever using it.
- We only enable it after your explicit, separate opt-in consent, recorded with a timestamp. You can withdraw consent at any time in your Profile settings; withdrawal immediately stops any further scoring.
- When you request a score, your photo is sent to a third-party AI vision provider (currently OpenAI) solely to generate a numeric rating (0-100) and a short comment. We do not request, extract, or store facial geometry, facial embeddings, or any other biometric template — only the resulting score and comment are saved to your profile.
- The score is presented as a subjective, AI-generated opinion for entertainment purposes. It is not a scientific, psychological, or medical assessment, and is not used to make any automated decision that produces legal or similarly significant effects about you.
- If you opt in and have a completed score, it may also be used to order the Discover feed, showing you people with a similar score first if they have also opted in. This never excludes anyone from being shown to you or you to them — members who haven't opted in appear normally, just without score-based ordering.
- You can delete any generated score, delete the underlying photo, or delete your account at any time (Section 9).
Separately from the optional PSL Score, every photo you upload is automatically screened immediately upon upload — before it becomes visible anywhere in the Service — for content that suggests nudity/sexual content or that the subject may be a minor. This automated screening is not optional; it is a safety measure necessary to operate the Service and protect other members, similar to spam/abuse filtering. Photos flagged by this process are deleted immediately and never appear on your profile, Discover, or anywhere else; we do not keep a copy of a rejected image, only a short machine-generated reason code.
Photo Verification is a separate, optional feature: you may capture a live selfie in-app, which our AI vision provider compares against your existing profile photo to produce a "verified" badge. This is an automated, approximate check intended to reduce catfishing — it is not a certified biometric identity or age-verification service, and we do not store, retain, or reuse the selfie image; it is discarded immediately after comparison.
Compatibility Score is a separate, optional signal computed from your bio and prompt answers (never your photos): we generate a numeric "text embedding" from that combined text, cached on your profile, and compare it mathematically to other members' embeddings to estimate how similar your written self-descriptions are. Like the PSL Score, this is never a hard filter — members without enough bio/prompt text simply don't get a Compatibility Score shown, and everyone remains visible in Discover regardless.
4. Legal bases for processing (GDPR)
- Contract: processing your account, profile, swipes, matches, and messages is necessary to provide the Service you signed up for.
- Consent: the PSL Score feature, and non-essential cookies (analytics/marketing), rely on your explicit consent, which you may withdraw at any time without affecting other processing.
- Legitimate interests: fraud prevention, abuse/report handling, and basic security logging, balanced against your rights.
- Legal obligation: where we must retain or disclose data to comply with law.
5. Who we share data with
We use a small number of processors to run the Service. We do not sell your personal data.
- Supabase (database, authentication, file storage, realtime messaging).
- OpenAI (or an equivalent AI provider) — receives a photo when you explicitly request a PSL Score; is used to screen every newly uploaded photo for prohibited content; receives a live selfie (never stored) if you use Photo Verification; and receives your bio/prompt text if you have enough of it to generate a Compatibility Score (Section 3).
- Stripe (payment processing and subscription billing) — receives your payment details directly; we only receive your subscription status and identifiers.
- Resend (transactional email) — only used to send Safewalk safety alerts to the trusted contact you designate, and account-related emails.
- Vercel (application hosting).
- Other members of the Service can see your public profile fields (username, age, city, bio, primary photo) and messages you send them after a match — that visibility is the core function of the app, not third-party sharing.
[Insert/confirm Data Processing Agreements (DPAs) with each processor above before launch.]
6. International data transfers
We serve users in the EU/EEA, UK, and USA. Where personal data is transferred outside the EU/EEA (e.g. to US-based processors), we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU-U.S. Data Privacy Framework. [Confirm current mechanism with each processor.]
7. Data retention
We retain your account and profile data for as long as your account is active. If you delete your account, we permanently delete your profile, photos, swipes, matches, and messages within 30 days, except where we must retain limited data (e.g. records of a safety report) to comply with legal obligations or to protect other users.
8. Cookies
- Essential — required for login sessions and security. Always on.
- Analytics — helps us understand aggregate usage. Only set with your consent.
- Marketing — used for promotional purposes. Only set with your consent.
9. Your rights
If you are in the EU/EEA or UK (GDPR/UK GDPR)
You have the right to: access your data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict or object to processing; data portability; and withdraw consent at any time. You can exercise deletion yourself from Profile → "Delete my account and all data", or contact us. You also have the right to lodge a complaint with your local data protection supervisory authority.
If you are a California resident (CCPA/CPRA)
You have the right to know what personal information we collect, request deletion, correct inaccurate information, and opt out of the "sale" or "sharing" of personal information (we do not sell or share personal information as those terms are defined by the CCPA). We will not discriminate against you for exercising these rights.
10. Security
Photos are stored in a private storage bucket, never publicly accessible, and served only via short-lived signed URLs to authenticated, authorized users. Access to user data is protected by row-level security policies at the database layer, in addition to application-level authentication.
11. Age restriction and age assurance
The Service is restricted to individuals 18 years of age or older. We do not knowingly collect data from anyone under 18. At signup you must enter your date of birth and explicitly self-certify that you are 18+; this is enforced both in the application and by a database-level constraint that rejects any profile with a date of birth under 18. We periodically (currently every 12 months) ask you to reconfirm this self-certification before you can continue using the Service, and we log the date of each confirmation. Providing false information about your age violates our Terms of Service and may result in immediate account termination. This is a self-attestation mechanism, not government-ID or biometric age verification; we may adopt stronger age-assurance methods in the future as regulation and available tooling evolve.
12. Changes to this policy
We may update this policy from time to time. Material changes will be notified in-app or by email before they take effect.
13. Contact
Questions or requests: privacy@datemaxxing.eu