Privacy
Your data, on purpose.
Effective 27 August 2026 · getrizzed.app · 18+ only
This policy explains what rizzed (“we”, “us”) collects when you use getrizzed.app, the API, and the iOS/Android apps, why we collect it, who processes it, and how long we keep it. It reflects how the product is built today — including that chats are not end-to-end encrypted because safety systems read content.
Controller contact: [email protected]. Safety: [email protected]. Launch city in product config is London; we treat UK GDPR as the baseline and honour equivalent rights where they apply.
1. Children
rizzed is 18+ only. We do not knowingly collect data from anyone under 18. Age check is required before a profile is visible. Estimated 25+ may pass liveness; 18–24 requires ID; under 18 is rejected and the account is closed. If we learn a user is under 18, we ban, delete, and report as required by law.
2. What we collect
- Account. Email and/or phone (keyed hash for lookup; envelope-encrypted identifier), Google or Apple subject IDs, passwordless OTP, session tokens.
- Profile. Name, date of birth (encrypted), gender, who you want to see, intent, bio, prompts, tags, height, city, photos, video, voice prompts.
- Location. Precise lat/lng for Nearby, dropped after 24 hours. City and H3 cell stay for discovery.
- Matching & chat. Likes, passes, intros, matches, messages (text, image, video, voice), reports, blocks, appeals. Messages persist while a match exists, then 30 days after unmatch for investigations.
- Device. Device id, platform (web / iOS / Android), push endpoint or token. Optional Play Integrity / App Attest results.
- Safety & billing. Moderation decisions, strikes, verification status (over-18, age band, face-match score, Sumsub applicant id — not the ID images). Entitlements and payment events from Stripe or RevenueCat.
- Product analytics. First-party events in our Postgres (screen views, likes, settings saves). No advertising SDKs.
3. Why we use it
- Run the service: auth, discovery, chat, billing.
- Keep the product 18+ and reduce catfishing (age assurance, optional ID + face match).
- Moderate content and enforce the Terms — including automated screening of photos, video, voice, and chat.
- Send OTP codes, match/message push (no message body in the notification), and enforcement email.
- Comply with law, including CSAM reporting to NCMEC.
Legal bases (UK GDPR): contract (providing the app), legitimate interests (safety, fraud, product improvement), consent (precise location, optional marketing we do not currently send), legal obligation (CSAM, lawful requests).
4. Encryption and who can read chat
Transport is TLS. Data at rest is encrypted on Railway disks and with application-level envelope encryption for identifiers. Messages are not end-to-end encrypted. Moderators, automated classifiers (OpenAI), and hash-matching (PhotoDNA or Google Content Safety when enabled) can access content. That is intentional. Do not send anything you would not want a safety system to see.
Web push payloads carry who and where, not the message text.
5. Processors and other services
We use the following services as configured in our environment. Some are optional until the matching API key is set; if a row is enabled, that processor may receive the data needed for that job.
Hosts the website, API, worker, Postgres, Redis, and private media bucket. (US or EU (project region))
Builds and distributes the iOS and Android apps. May process Expo push tokens and crash/build metadata. (US (Expo cloud; iOS compiles on Expo Macs))
Sign in with Google; optional Play Integrity device attestation; webfonts; optional Google Content Safety CSAM hashing. (Global / US)
Android push delivery when FCM is configured (FCM_SERVER_KEY). (Global / US)
Sign in with Apple; APNs push; optional App Attest. (US / global)
SMS and WhatsApp one-time passcodes (Verify and/or Messages API). (US / global)
Transactional email: sign-in codes and enforcement notices. (US)
Optional alternate transactional email if configured. (US)
Age estimation, liveness, and ID + face match. Identity documents stay with Sumsub. (EU / global)
Automated moderation of text, images, video frames, and voice (transcription + classifier). Not used for ads. (US)
Error and crash reporting (no message bodies in push payloads; keep PII out of breadcrumbs where possible). (US)
Web billing for Plus / Premium if you pay on getrizzed.app. (US / global)
In-app purchase entitlements on iOS/Android if you pay in the stores. (US)
Optional push relay if ONESIGNAL_* is set. (US)
Optional object storage if media is not on the Railway bucket. (per bucket)
Optional CSAM hash matching when CSAM_PROVIDER=photodna. (US)
Mandatory reports of apparent child sexual abuse material. Not a vendor we choose for convenience. (US)
Google Fonts (Fraunces, Plus Jakarta Sans) load in the browser from Google’s CDN. Unsplash URLs appear only in demo seed photos, not as a live user-upload pipeline.
Railway, Expo, Google, and Apple are named because the product is hosted and built there even when a given optional key (Firebase FCM, Play Integrity, etc.) is still empty.
6. Sharing
- Other users see what you put on a live profile, and messages you send after a match.
- Processors above, under contract, only for the listed purpose.
- Law enforcement or NCMEC when required, including apparent CSAM.
- A buyer of the business, with the same promises.
We do not sell personal data. We do not run third-party ad networks.
7. Retention
- Account and profile: until you delete, plus up to 30 days to complete hard-delete unless a legal hold applies.
- Precise location: 24 hours.
- Chat after unmatch: 30 days for safety, then delete.
- OTP codes: minutes (TTL), not kept as a history.
- Moderation / report / ban records: as long as needed to protect users and meet legal duties.
- Sumsub: documents live with Sumsub per their retention; we keep applicant id, over-18, age band, face-match score.
8. Your rights
You can access, correct, export, and delete your account in Settings (hard-delete within 30 days unless legally held). You may object or restrict processing where the law allows. UK users may complain to the ICO. Email [email protected].
9. International transfers
If the Railway project is in the US, UK/EEA data is transferred there. Processors in the US (OpenAI, Expo, Google, Apple, SendGrid, Stripe, and others) likewise. We rely on UK GDPR transfer tools (adequacy, SCCs, or equivalent) as applicable. You accept this when you create an account.
10. Changes
We will update this page and the “Effective” date. Material safety changes (for example turning on PhotoDNA) stay listed here. Keep using the app after an update means you accept the new policy.
Questions: [email protected] · [email protected]