Privacy Policy
Our Approach to Privacy
OpenDating is designed to minimize data collection and separate service responsibilities. Privacy depends on both architecture and operating policy; no system can honestly promise that surveillance or compromise is impossible.
What We Collect
The service does not require an email address or phone number. It does process a pseudonymous public account key plus the profile, relationship, safety, and service metadata needed to provide the product.
Information you provide
- Profile data — Display name, age range, gender, bio, interests, relationship intent, and photos. This is what you choose to share on your dating profile.
- Coarse location — A 5-character geohash prefix (~5 km precision). Your exact GPS coordinates are converted to this coarse representation entirely on your device and then discarded. We never receive your precise location.
- Messages — End-to-end encrypted before transmission and readable by the intended recipient, not the delivery service.
- Relationship and safety data — Likes, matches, blocks, unmatches, reports, moderation state, and deletion records are processed by their role-specific services.
- Operational metadata — Cloudflare and the relay may process IP address, request timing, device connection information, and random request identifiers for delivery, abuse prevention, and reliability.
Information we do NOT collect
- Email address or phone number as an account login
- Precise GPS coordinates in the service payload
- Contact lists or address books
- Browsing history
- Device advertising identifiers
- Full payment-card or bank-account details; Apple processes payment
- Any data from other apps on your device
How We Use Information
The limited information shared with the relay is used exclusively to provide the dating service:
- Your coarse location enables discovery of people in your general area
- Your profile is shown to other users in discovery (according to your visibility settings)
- Encrypted likes are routed to the matcher service to create matches
- Encrypted messages are routed between matched users
The app does not use advertising SDKs or product analytics. Billing is disabled on the web. RevenueCat processes an opaque billing identifier and Apple purchase-entitlement status only in native builds where the optional one-time Plus feature is enabled. Infrastructure security and operational logs may still be processed. Any future analytics or moderation vendor will require an updated notice and production approval.
Data Storage and Security
- Native devices use secure storage. On the web, the recovery key is encrypted before entering local storage and unlocked only with the browser-lock passphrase. The decrypted key exists temporarily in JavaScript memory while the app is unlocked.
- Messages are end-to-end encrypted. The delivery service stores only encrypted ciphertext.
- Likes are private and encrypted to the matching service.
- Blocks and reports are private — encrypted to their respective services.
- The relay operates on Cloudflare's infrastructure. Encrypted data may be cached at Cloudflare edge locations for performance.
Data Sharing
We do not sell or rent profile or relationship data and do not have advertising partners. Cloudflare processes service data as the current infrastructure provider. RevenueCat may process an opaque billing identifier and purchase-entitlement status; it does not receive profile text, photos, location, recovery keys, likes, matches, reports, or messages. Apple, Google, and Expo may process purchase, build, or distribution data. See the current subprocessors list.
Your Control
- Pause discovery — Hide your profile from new discovery at any time while keeping existing matches.
- Delete account — Requests deletion through the dedicated service and clears local app state after confirmation. See the deletion instructions.
- Export identity — After warning and authentication, you can explicitly copy the recovery key. Anything copied to a clipboard can be exposed to other software or synchronized devices.
- Lock browser — Removes the decrypted recovery key from the app's current in-memory session without deleting the encrypted browser copy.
- Location permission — You can deny or revoke at any time. Discovery requires coarse location.
Children's Privacy
OpenDating is only for adults 18 and older. The service does not currently verify every member's identity or age. Report suspected underage use immediately.
Changes to This Policy
We will update this notice when practices, providers, retention, or available countries change. Material production changes require a new policy version and acceptance record.
Contact
For privacy questions or data requests, use the confidential email channel: jonny2298@live.com.