Privacy Policy
How we handle your data.
Overview
This page explains what data we collect, why we collect it, who we share it with, and your rights. We've written it in plain English (with a French and Spanish translation that's just as plain). If anything here is unclear, email [email protected].
Last updated: June 2026.
Effective date: June 1, 2026.
The principles
- We don't sell your data. Not to advertisers. Not to data brokers. Not under any circumstances.
- We collect the minimum. Just what's needed to match you well, keep the service running, and keep you safe.
- You own it. Download or delete everything we have on you, anytime, from Settings → Privacy.
- We're transparent. We publish an annual transparency report covering law enforcement requests and content moderation actions.
What we collect
Account information
Phone number (for sign-in and account recovery), email address (optional, for password resets), name, date of birth, and the answers you provide during onboarding.
Profile content
Photos, bio, prompt answers, preferences (age range, distance, interests), and any other information you choose to add to your profile.
Interactions
Who you've matched with, message content (encrypted at rest), dates booked, and how you've used core features. We use this to improve matching and to investigate safety reports.
Device & connection
Device type, operating system version, app version, IP address (for fraud prevention), approximate location (city level — not precise location), and basic telemetry needed to deliver the service.
What we don't collect
Precise location, contacts (we don't ask for permission), microphone outside in-app calls, camera outside photo uploads, browsing history, or anything else you wouldn't expect.
Why we collect it
- To match you — preferences, location (city level), prompt answers
- To keep you safe — verification photos, message scanning for scam patterns, safety reports
- To run the service — payment info (handled by Apple/Google, we don't see card numbers), device telemetry
- To comply with law — age verification, retention requirements, lawful requests
Who we share with
Service providers
Hosted infrastructure (Supabase, Cloudflare), payment processing (Apple, Google for IAP), push notifications (Expo), analytics (Firebase Analytics — anonymized), crash reporting (Sentry), face verification (Google MediaPipe). All providers are bound by contracts requiring them to handle data only on our instructions.
Law enforcement
Only with proper legal process, and only what's required. See law enforcement page for the full process.
Other users
Profile content you've made public to matches. Nothing else.
What we never share
Your phone number, email, exact location, message content, or anything you haven't published yourself. Not with advertisers. Not with data brokers. Not for any reason that isn't legally required.
Your rights
Under GDPR (Europe), CNDP (Morocco), CCPA (California), LGPD (Brazil), POPI (South Africa), and equivalent laws worldwide, you have the right to:
- Access — download everything we have on you (Settings → Privacy → Download my data)
- Rectification — fix anything that's wrong
- Erasure — delete your account and have your data removed within 90 days
- Restriction — limit how we process your data while a complaint is being investigated
- Portability — receive your data in machine-readable format
- Object — opt out of any non-essential processing
To exercise any of these rights, email [email protected]. We respond within the legally required window (typically 30 days, often much faster).
Retention
- Active accounts — as long as you use the service
- Deleted accounts — hidden immediately, permanently removed within 90 days (subject to legal retention obligations like financial records)
- Verification photos — deleted within 24 hours of verification
- Message content — until you delete the conversation or your account; up to 90 days after deletion for safety review purposes
- Backups — encrypted, 30-day rolling window
International transfers
Our database is hosted by Supabase in EU and US regions. Content delivery uses Cloudflare's global network. Push notifications use Expo (US-based). All international transfers are protected by Standard Contractual Clauses (SCCs) as required by GDPR.
Children
LoverSpot is 18+ only. We do not knowingly collect data on anyone under 18. See child safety for our verification process and reporting channels.
Changes
If we materially change this policy, we'll notify you in-app at least 30 days before the new version takes effect. Minor non-material changes (clarifications, typo fixes) may be made without notice.
Contact
Privacy questions: [email protected]
EU representative (under GDPR Article 27): [email protected]
Data protection authority complaints (Morocco): CNDP. EU residents may also complain to their local supervisory authority.