Legal

Privacy Policy

What we collect, why, and the choices you have — in plain English. We ask for as little as we can, we are blunt about the sensitive parts, and we never sell what you share.

DraftVersion 1.0 · 16 June 2026

This notice explains what personal data mindate collects, why we collect it, and the rights and choices you have. mindate is built on one idea — minds meet before faces do — and that shapes everything here: we ask for as little as we can, we are honest about the sensitive parts (your photos and your face), and we never sell what you share.

The Short Version

If you read nothing else, read this. The rest of the notice is the detail behind these promises.

  • We never sell or rent your personal data to advertisers or data brokers.
  • Your photos stay blurred to a match until you have both earned the reveal — around twenty conversations in.
  • We verify that you are a real, live person and that your photos are you — but we store a one-way mathematical face-hash, not a browsable library of faces.
  • Chat is text only. No one can send you a photo or file in a conversation, ever.
  • You can export or permanently delete everything from inside the app, at any time.

Who We Are

mindate is operated by mindate Ltd (“mindate”, “we”, “us”), a company registered in England and Wales under company number 17202076 and the controller responsible for your personal data. Registered office [to be added]. We are registered with the UK Information Commissioner’s Office (ICO) under registration number [to be added]. For any privacy question, reach us at privacy@mindate.app.

Data We Collect

We collect only what the service needs to work and to stay safe. That falls into a few groups:

  • Account details — your email address, a securely hashed password, and your date of birth (used to confirm you are 18 or over).
  • Profile and personality — your answers across the wavelength axes, prompts, and any free text you add to your profile.
  • Photos you upload — shown blurred at first, then progressively to a match as you both earn the reveal.
  • Face and liveness data — a liveness capture at sign-up and a derived face-hash, used to confirm you are real and that your photos are you (see “Your Face, Specifically”).
  • Messages — the text of your conversations. We do not allow photo or file uploads in chat.
  • Usage and device data — how you use the app, your device model and operating system, app version, IP address, and diagnostic logs.
  • Approximate location — your city or region, if you choose to share it, to suggest people near you.
  • Purchases — your subscription tier and renewal status. Payments are handled by Apple; we receive confirmation of a purchase, never your card number.
  • Support correspondence — anything you send us when you ask for help.

Your Face, Specifically (Biometric Data)

This is the part most apps gloss over, so we will not. At sign-up we run a liveness check to confirm you are a real, present person, and we derive a face-hash — a mathematical representation of your face. We use it to confirm your photos are genuinely you, to enforce one real person per photo, and to stop duplicate or fake accounts. A face-hash is biometric data and counts as special category data under Article 9 of the UK GDPR, so we process it only with your explicit consent, given at sign-up. We do not keep a searchable gallery of identifiable faces, we do not use your face to identify you anywhere else, and we do not share it for that purpose. You can withdraw consent by closing your account — because verification is core to mindate, we cannot keep your account open without it. We keep your liveness data and face-hash only while your account is active and delete them when you delete your account, subject to any short legal hold.

Who We Share It With

We share personal data only where we need to, and only under contract or legal duty. We never sell it.

  • Service providers acting on our instructions — cloud hosting, our identity and liveness verification provider, analytics, email delivery, and payments via Apple [named sub-processors to be added].
  • Safety and legal — police, regulators, or others where we are lawfully required to, or where it is necessary to protect someone from serious harm.
  • Business transfers — if mindate is ever merged or acquired, your data may transfer with the service; we will tell you first.
  • Never — advertisers, data brokers, or anyone wanting to buy your data. That is not our model.

How Long We Keep It

We keep personal data only as long as we need it. While your account is open, we keep what the service needs. When you delete your account, we erase your personal data within [to be added] days, except for limited records we are legally required to keep (held only as long as the law requires) and anonymised statistics that can no longer identify you. Your face-hash and liveness data are deleted on account deletion, and backups cycle out within [to be added] days.

Your Rights

Under UK GDPR you have the right to:

  • Access — get a copy of the personal data we hold about you.
  • Rectification — correct anything inaccurate.
  • Erasure — ask us to delete your data (“the right to be forgotten”).
  • Restriction — ask us to pause how we use it.
  • Portability — receive your data in a portable format.
  • Object — object to processing based on our legitimate interests, including analytics.
  • Withdraw consent — at any time, where we rely on your consent.

How To Exercise Your Rights

Most of this you can do yourself inside the app — export or delete your data from your settings. For anything else, email privacy@mindate.app and we will respond within one month. If you are unhappy with how we have handled your data you can complain to the ICO at ico.org.uk, though we would genuinely appreciate the chance to put it right first.

Automated Decisions

We suggest matches using your wavelength answers, but we do not make decisions about you that have a legal or similarly significant effect without human involvement. A match suggestion is just that — a suggestion. You are never ranked, accepted, or rejected by an automated process that affects your legal rights.

International Transfers

We aim to keep your data in the UK or the European Economic Area. Where data is transferred elsewhere — for example to a service provider — we rely on a UK adequacy decision or appropriate safeguards such as the UK International Data Transfer Agreement, so your data keeps an equivalent level of protection. [Specific transfer mechanisms and regions to be added.]

How We Keep It Safe

We encrypt your data in transit and at rest, restrict who can access it, and design for privacy — the one-way face-hash is itself a safeguard. No system is perfectly secure, but if a breach occurs that is likely to put your rights at risk, we will notify you and the ICO as the law requires.

Children

mindate is strictly for adults aged 18 and over. We do not knowingly collect data from anyone under 18, and if we learn that we have, we delete it promptly.

Cookies And Similar Technologies

The app uses minimal local storage to keep you signed in and remember your preferences. The mindate website uses essential cookies and privacy-respecting analytics only — no advertising trackers.

Changes To This Notice

When we update this notice, we publish the new version here with its own version number and date, and the previous version moves into the document history shown alongside. For material changes we will also tell you in the app or by email before they take effect.

Contact

Questions, requests, or concerns: privacy@mindate.app, or write to mindate Ltd at [registered address to be added]. You can also contact the ICO at ico.org.uk or on 0303 123 1113.