rizzed

Law enforcement

Bring a lawful order.

Effective 1 September 2026 · getrizzed.app · 18+ only

These protocols explain how Tweed Tyne Technologies Ltd (“we”, “us”) handles requests from law enforcement and other competent authorities about rizzed (getrizzed.app, the API, and the iOS/Android apps). They are published at https://getrizzed.app/law-enforcement. They sit next to the Terms of Use (EULA) and the Privacy Policy. They are not a shortcut around a lawful order.

We cooperate with valid legal process. We do not hand over user data because someone asked nicely, flashed a badge in an email, or wants a fishing trip. Chats are not end-to-end encrypted, so if we still have a message we can produce it when the law requires it.

1. Who we are

  • Company. Tweed Tyne Technologies Ltd, registered in Scotland (SC874131). Launch city in product config is London. We treat UK GDPR as the baseline.
  • Product. rizzed — a dating service for verified adults. Controller contact: [email protected].
  • Legal process inbox. [email protected]. Put the case reference in the subject. This is the same address we publish to NCMEC as our legal-process contact.

2. This is not 999

If someone is in immediate danger, call local emergency services first. In the UK that is 999. rizzed is not emergency response and we do not have a 24/7 duty desk. After people are safe, send the request to [email protected].

3. What we will not do

  • No informal “just send the chats” requests. No civil discovery dressed up as a police email.
  • No bulk dumps, keyword trawls, or “everyone in this postcode” asks without specific lawful process.
  • No live tracking. We do not stream a user’s location to anyone.
  • No access to ID images or biometric captures we do not hold — those live with Didit.
  • We will not install spyware, keep a silent extra copy of a user’s camera, or leave a backdoor in the apps.

4. How to send a request

Email [email protected] from an official agency address. Include:

  • Agency name, officer name, rank, and a callback number we can verify.
  • The lawful instrument (UK court order, production order, warrant, or equivalent). Attach a copy.
  • The account you mean, as specifically as you can: user id (UUID), email, phone in international format, display name plus city, or a message/media id.
  • The offence, the date range, and exactly which records you need.
  • Any non-disclosure order, and when it expires.
  • A response deadline that is real, not theatrical.

We may refuse, narrow, or ask you to come back with a better instrument if the request is invalid, overbroad, or does not identify an account we can find.

5. UK and everyone else

We are a UK company. Valid process from a UK court or a UK competent authority is the default path. Courts of England and Wales have exclusive jurisdiction under our Terms, except that we may seek injunctive relief anywhere.

Authorities outside the UK should use mutual legal assistance, a letter of request, or another recognised international channel — unless section 6 (emergency) applies. We may preserve records while that process is underway. We do not treat a foreign subpoena emailed to us as automatically binding.

6. Emergencies

If there is a specific, imminent risk of death or serious bodily harm, email [email protected] with the subject line EMERGENCY. Say who is at risk, why the risk is imminent, which account you need, and what minimum data would help. We may disclose the least we reasonably need, then require formal process to go further. A vague “could be serious” is not enough.

7. What we can produce — if we still have it

See the Privacy Policy for the full picture. In short:

  • Account. Email and/or phone (stored as a keyed hash plus an envelope-encrypted identifier), Google or Apple subject IDs, account status, created-at.
  • Profile. Display name, date of birth (encrypted), gender, intent, bio, prompts, city, photos, video, voice prompts that are still on the account.
  • Location. Precise lat/lng for Nearby is dropped after 24 hours. City and H3 cell can remain for discovery. We do not have a GPS history.
  • Matching and chat. Likes, passes, intros, matches, blocks, reports, appeals. Messages (text, image, video, voice) while a match exists, then up to 30 days after unmatch for safety investigations. We can read them. They are not end-to-end encrypted.
  • Device. Device id, platform (web / iOS / Android), push token metadata. Optional Play Integrity or App Attest results.
  • Safety and billing. Moderation decisions, strikes, verification outcome (over-18, age band, face-match score, Didit session id — not the ID images). Entitlements and payment events from Apple, Google Play, or Stripe. Card numbers live with the payment provider.

8. What we cannot produce

  • Data we already hard-deleted, unless a legal hold froze it first.
  • Identity-document images, selfies, and biometric captures held by Didit.
  • OTP codes after they expire. We do not keep a history of the codes themselves.
  • A live or historical trail of precise location beyond the 24-hour window.
  • Message bodies in push notifications — those payloads do not carry the chat text.
  • Other users’ records except as the order specifically requires.

9. Preservation and legal holds

Ask us to preserve a named account or conversation pending process. Give a case reference and a hold period. We will freeze hard-delete for that material where we still have it. A preservation request is not a production order — we will not release the data on the hold alone, except under section 6.

Ordinary retention: account and profile until the user deletes, plus up to 30 days to finish hard-delete unless a hold applies. Chat after unmatch: 30 days, then delete. CSAM filings and some moderation records stay as long as the law requires.

10. Notice to the user

We notify the account holder that we received legal process, unless the instrument forbids notice, notice would create a risk of harm, or it would reasonably interfere with an investigation. If a non-disclosure period expires, we may notify then.

11. Child sexual abuse material

Apparent CSAM is reported to the National Center for Missing & Exploited Children (CyberTipline). That is a statutory duty (including 18 U.S.C. § 2258A where it applies), not a request we negotiate. We may also terminate the account and device-ban. Underage and CSAM decisions are not ordinary appeal cases. NCMEC is listed as a processor in the Privacy Policy.

12. Costs and changes

We may charge for non-emergency production where the law allows. We can update these protocols; the Effective date at the top will change. Questions that are not legal process: [email protected].

Questions: [email protected] · [email protected]

Law enforcement protocols — rizzed