Privacy Policy
Effective 28 August 2026 · Last updated: 29 September 2026
This platform is built on trust, and that begins with how we handle the most personal information you will ever put into an app. We do not sell your personal data, and we never will.
1. Who we are
Date to Marry is a marriage-first matchmaking platform owned and operated by Pila Studio UG (haftungsbeschränkt), a company with limited liability registered in Germany. For the purposes of the EU General Data Protection Regulation (GDPR) and equivalent laws, Pila Studio UG (haftungsbeschränkt) is the data controller for your personal data.
Contact: hello@datetomarry.app. Full company details are on our Impressum.
2. What we collect
2.1 What you give us
| Category | Examples | Why |
|---|---|---|
| Identity | Legal name, date of birth, sex, city | Account creation, age checks, matching |
| Contact | Email address | Account management, transactional email |
| Identity verification | A photo of your government-issued ID and a live selfie, captured and checked by Didit, including a biometric comparison of your face with the photo on the document, and afterwards of each new profile photograph with that selfie | Mandatory identity and age verification, and confirming that your profile photographs are of you |
| Profile media | Photographs, voice introduction (or an intro video recorded before voice introductions replaced it), voice notes | Shown to the people you are introduced to, each new photograph only once it has been checked (see section 9) |
| Onboarding answers | Life Architecture (children, faith, location, timeline, finances), faith tradition, character prompts, your bio | Compatibility matching |
| Values answers | Your answers to the values questions, including any you choose to give about religion, sexual ethics and politics, and which of them you share | Compatibility matching, and showing shared values to the people you are introduced to |
| Absolutes | Self-declared lifestyle facts, and the dealbreakers you choose | Excluding pairings neither side would accept |
| Preferences | Age range, distance, travel countries | Deciding who you can be matched with |
| Decisions | Whether you said yes or no to an introduction, and any note you chose to write when passing | Matching, and improving how we choose introductions |
| Conversations | Messages, voice notes, guided prompt responses | Communication with your match |
| Companion data | Partner journal entries, relationship check-ins, milestones | Your own coaching features. Never shown to your partner. |
| People who vouch for you | The email address and relationship of anyone you invite to vouch for you, and the reference they write | Sending them your invitation, and showing their reference on your profile |
| Payments | What you bought and when, the store and storefront country, and a confirmation of any request to begin at once. Card details are held by Stripe, Apple or Google, never by us | Taking the search fee and couple’s purchases, and keeping the records the law requires |
| Reports and support | Reports, complaints, support messages | Safety moderation and support |
2.2 What we collect automatically
- Device information: device type, operating system, app version, timezone, and locale.
- Usage data: which features and screens you use, and when you were last active.
- Log data: IP address, timestamps, and error logs.
- Crash and performance reports: diagnostic data via Firebase Crashlytics and Firebase Performance Monitoring.
- Session recordings: recordings of how the app’s screens are used, sent to PostHog so we can find and fix problems. Passwords, messages, voice notes, your journal, identity verification, reports, references and every photograph are hidden in these recordings; see section 18.
- Push tokens: the device token used to deliver notifications.
2.3 What we get from others
- Didit: the result of your verification, the details read from your document (such as your name, date of birth, document type and number, issuing country and expiry date), and the scores of its authenticity, liveness and face-match checks; and, for each new profile photograph, a similarity score from comparing it with the selfie from your verification. Didit keeps the document and selfie images, and the biometric data made from them, for us for up to one year after your verification, so that new profile photographs can be compared with your selfie, and then destroys them; we do not store them ourselves.
- OpenAI: for each new profile photograph, an assessment of what it shows: whether it is a photograph of a person, how clearly the face can be seen, and whether it looks generated, heavily edited, or unsuitable for a profile.
- Apple and Google sign-in: if you sign in with Apple or Google, your name and email address (or Apple’s private relay address) and an account identifier.
- Apple, Google, Stripe and RevenueCat: confirmation that a purchase is valid, its product, date, price and store country. We never receive your card details.
3. How we use your data
- Running your account: creating it, securing it, and authenticating you.
- Verifying identity and age: confirming through Didit that members are real adults.
- Checking profile photographs: before anyone else can see a new profile photograph, checking that it is a real, current photograph of you. See section 9.
- Matching: applying your absolutes and preferences, scoring compatibility from your answers and profile, asking an AI model to read the two profiles of a possible pair side by side, and showing you one introduction at a time. See section 9.
- Showing your profile: when you are introduced to another member, your first name, age, city, photographs, introduction, the answers on your profile and the values you chose to share are shown to them, and theirs to you.
- Conversations: delivering messages and voice notes between matched members.
- Companion features: your journal and check-ins power your own coaching, and nothing else.
- Payments: taking payment and keeping transaction records.
- Safety: investigating reports, enforcing the Terms, preventing fraud, and protecting members.
- Legal compliance: meeting our obligations and responding to lawful requests.
- Improving the service: analysing usage events and session recordings under a pseudonymous identifier to find and fix problems, and analysing aggregated, de-identified data to make matching better.
- Running the business: internal notifications to our team about sign-ups, introductions, purchases and safety reports, so a person can act on them.
- Communicating: transactional email, and optional informational email if you opted in.
4. What we never do
- We never sell your personal data.
- We never use it to serve you targeted advertising, or build an advertising profile of you.
- We never share your identifiable content with third parties for marketing.
- We never show your partner your journal entries or check-in answers.
- We never show anyone your exact location. See Location and distance.
5. Legal bases for processing
If you are in the EEA, the UK, or another jurisdiction with comparable law, we rely on the following (the article numbers are those of the GDPR):
| Purpose | Legal basis |
|---|---|
| Your account, matching, introductions, conversations, Companion features, payments | Performance of our contract with you (Art. 6(1)(b)) |
| Identity verification, including the biometric face comparison, and comparing new profile photographs with the selfie from it | Your explicit consent (Art. 6(1)(a) and 9(2)(a)), given with your release when you accept the Terms (section 5). Verification is required to be matched, so without it we cannot match you |
| Faith, values, sexual ethics, politics and health information you give | Your explicit consent (Art. 9(2)(a)), given when you accept the Terms (section 14) and each time you answer |
| Fraud prevention, security, safety moderation (including checking what new profile photographs show), internal team notifications, fixing problems | Our legitimate interests in a safe, working service (Art. 6(1)(f)), which we have weighed against your interests |
| Product analytics and session recordings in the app | Our legitimate interest in finding and fixing problems (Art. 6(1)(f)); see section 18 for what is recorded and your right to object |
| Child safety reporting, tax and accounting records, lawful requests | Legal obligation (Art. 6(1)(c)) |
| Optional email | Your consent (Art. 6(1)(a)) |
Where we rely on consent you may withdraw it at any time, in the app or by writing to us. Withdrawal does not affect processing already carried out. Where we rely on legitimate interests, you may object at any time for reasons relating to your situation.
7. Third-party processors
These providers process personal data on our behalf and on our instructions, under data processing agreements. Apple and Google also act for themselves when they sell you something through their stores or sign you in, under their own privacy policies.
| Provider | Purpose | What it receives |
|---|---|---|
| DigitalOcean | Hosting of our servers and database, and storage of photographs, voice and video | Everything stored in the Service |
| Didit | Identity and age verification, and comparing new profile photographs with the selfie from it | Your ID document images, a live selfie, and the biometric comparison of the two; your name and date of birth as read from the document; each new profile photograph, to compare with the selfie |
| OpenAI | Compatibility scoring, the pairwise reading of two profiles, Companion suggestions, and checking what new profile photographs show | The text of profile answers and bios, without names or contact details; each new profile photograph, the image only |
| Firebase (Google) | Push notification delivery, crash reporting, app performance monitoring | Device push token, diagnostics and performance data, a pseudonymous identifier |
| PostHog (EU cloud) | Product analytics and session recordings | A pseudonymous identifier, device information, usage events, and recordings of app screens with sensitive content hidden (section 18) |
| RevenueCat | Purchase and entitlement management | Purchase receipts, store country, a pseudonymous member identifier |
| Stripe | Payments taken on this website | Payment details, handled by Stripe |
| Apple / Google | In-app purchases, and sign-in if you choose it | Purchase records and receipts; sign-in identifiers |
| ForwardEmail | Transactional email delivery | Email address and message content |
| Slack | Internal notifications to our team | First names, ages and cities of members involved, introductions and purchases, and safety reports, so a person can act on them |
| Vercel | Hosting for this website and our internal tools | Standard web request logs |
From photo checks we keep only the results: what each check found in a photograph, the reasons for any decision, and, for the comparison with your selfie, a similarity score. We never store your verification selfie, or a template of your face, ourselves.
8. International transfers
We and our processors operate internationally, so your data may be transferred to, stored in, and processed in countries outside your own, including the United States, whose data protection laws differ from yours.
Where we transfer data outside the EEA or the UK, we rely on an adequacy decision where one exists (for United States providers certified under it, the EU-US Data Privacy Framework and the UK Extension to it), and otherwise on Standard Contractual Clauses approved by the European Commission or the UK authorities, together with additional safeguards where they are needed. You may ask us for a copy of the safeguards that apply.
9. Automated decision-making
Matching is automated, and it is profiling. It works in this order:
- Hard rules first. Two people are only introduced if both pass the other’s absolutes and dealbreakers, fall within each other’s age range and meeting area, and are identity-verified.
- Then a score. For pairs that pass, we calculate compatibility from your life plans, your written answers and bio, a reading of the two profiles side by side by an AI model (OpenAI), your values answers where both of you have enough of them, and what each of you says you want. Pairs below a minimum quality are not introduced.
- Then the order. Members who have waited longest are considered first. Among good fits, people who have been active recently come first, and a trust score moves each person up or down a little. That score starts in the middle and changes with the reviews other members leave after a match and with safety reports we uphold.
These decisions determine who you are introduced to and how often. They do not change your legal rights, but because the search fee buys introductions, we treat them as significant anyway: you may ask a person to review any matching decision, contest it and put your point of view, by writing to hello@datetomarry.app.
Profile photographs are checked automatically. Before anyone else can see a new profile photograph, we check that it is a real, current photograph of a person and, once you are verified, that the person is you, by comparing it with the selfie from your identity check. A photograph that clearly fails is not added, and you are told why. A photograph the check is unsure about is held for a person on our team to decide, and nobody else sees it in the meantime; if nobody has approved it within three days, it is declined and you are told why. A photograph that cannot be compared with your selfie, for example more than a year after your verification, waits for a person with no time limit. A photograph that fails after it was added, for example once your identity check is complete, is taken off your profile, and you are told in the app.
You can ask a person to look again at any decision about your photographs, from the app or by writing to hello@datetomarry.app. Photographs already on your profile before these checks began were not checked and have not been changed.
10. Sensitive data
Some of what we collect is “special category” data under the GDPR:
- Religious or philosophical belief: your faith answer, faith tradition, and values answers about faith.
- Political opinions: values answers about society and politics, if you choose to give them. They start private.
- Sex life: values answers about sexual ethics, if you choose to give them.
- Biometric data: the comparison of your selfie with your document photo during identity verification, and of each new profile photograph with that selfie, both carried out by Didit for us. It is used only to confirm that you are the person on the document and in your profile photographs, never sold, and kept by Didit for up to one year after your verification, so that new profile photographs can be compared with it, and then destroyed.
- Health information: where you disclose it in a character prompt, a self-declared fact, or Companion data.
We process it only with your explicit consent, which you give by accepting our Terms and, for your answers, by giving them: section 5 of the Terms covers the biometric checks and section 14 your answers about faith, intimacy and politics. The app does not ask for these consents separately. We use this data only for identity verification, confirming that your profile photographs are of you, compatibility matching, showing the answers you did not keep private to the people you are introduced to, and your own coaching features. It is never sold, never shared with advertisers, and never used to decide anything about you other than who you are introduced to and whether a profile photograph is accepted. You can withdraw consent at any time by deleting those answers in the app, by writing to us, or by deleting your account; the answers are then deleted and no longer used in matching.
11. Location and distance
Distance matters to matching, so we need to know roughly where you are. We do this from the city you tell us: the app does not request device location permission, and we do not collect GPS coordinates from your device.
From that city we store approximate coordinates, and use them to calculate the distance between you and potential matches, and to honour the radius you set.
Nobody is ever shown your exact distance. Members see a coarse band, never a precise figure. A precise distance, repeated across several matches, can be used to triangulate where someone lives, so we do not expose one.
12. Companion privacy
Partner journal entries, relationship health check-in answers, and private reflections belong to you alone. We do not show them to your partner, and we do not share them with any third party, except where the law requires it.
Behavioural reviews left about you after a match are used for safety and trust scoring. They are never shown verbatim to the person they describe.
13. How long we keep things
| Data | Retention |
|---|---|
| Active account data | For as long as your account exists; after you delete it, see Account deletion |
| Identity verification records | The result and the details read from your document, for as long as your account exists, and afterwards only as long as needed to stop a banned person re-registering or as the law requires. The document and selfie images and the biometric data made from them: kept by Didit for up to one year after your verification, so that new profile photographs can be compared with your selfie, and then destroyed |
| Profile photographs you replace or remove | Deleted as soon as you save the change |
| Profile photographs refused or removed by the photo check | Deleted as soon as they are refused or removed; they cannot be put back |
| Photo check results (what each check found, the reasons, and any similarity score; never images) | For as long as the photograph is on your profile. For one that was refused or removed, a note of the decision is kept for seven days, then deleted |
| Conversations in a closed match | Message and voice note content deleted within 90 days of the match closing |
| Session recordings | 30 days |
| Usage events | Kept under a pseudonymous identifier for as long as they help us understand how the Service is used |
| Companion data (journal, check-ins) | Deleted when you delete it, or when you delete your account |
| Payment and tax records | Up to 10 years, as German commercial and tax law requires |
| Safety and moderation records | Up to 7 years where needed for an ongoing investigation or legal proceedings |
| Deleted accounts | Identifiable profile data is removed. Anonymised or aggregated data, and records we are legally required to keep, may remain as described above. |
14. Security
We use appropriate technical and organisational measures to protect your data, including encryption in transit using TLS, encryption at rest of our database and stored media by our hosting provider, access controls limiting who can see what, private storage for every uploaded photograph, voice note and document with short-lived links for viewing, and reputable infrastructure providers.
No system is perfectly secure. If you believe your account has been compromised, write to hello@datetomarry.app immediately. Where a breach is likely to result in a high risk to your rights, we will notify you and the relevant supervisory authority as the law requires.
15. Children
Date to Marry is strictly for adults aged 18 and over. We do not knowingly collect data from anyone under 18, and every member must pass government-issued identity verification confirming their age before they can be matched.
If we learn that we hold data from a person under 18, we delete it and terminate the account. If you believe a minor has created an account, report it to hello@datetomarry.app immediately. See also our Safety Standards.
16. Your rights
Depending on where you live, you may have the right to:
- Access a copy of the personal data we hold about you.
- Correct anything inaccurate or incomplete.
- Delete your data, in the app or by writing to us, subject to our legal retention obligations.
- Restrict processing in certain circumstances.
- Port the data you gave us, in a structured, machine-readable format.
- Object to processing based on legitimate interests.
- Withdraw consent where processing relies on it.
- Ask for human review of an automated decision. See section 9.
To exercise any of these, write to hello@datetomarry.app. We respond within 30 days, and may need to verify your identity first. Data export and account deletion are also available inside the app; see Account deletion.
United States residents. Depending on your state, you may have rights to know what we collect, to access, correct and delete it, to limit the use of sensitive personal information, and to opt out of its sale, sharing for targeted advertising, or profiling. We do not sell or share personal information for advertising, and we use sensitive information (such as your identity documents, religious beliefs, and views on sexual ethics or politics) only to provide the Service you asked for. To exercise any right, write to us as above; we will not treat you differently for doing so, and you may appeal a refusal by replying to our answer.
17. Notifications and email
We send push notifications for matches, messages, and reminders, delivered through Firebase Cloud Messaging. You can turn them off per type in the app, or entirely in your device settings.
We send transactional email — verification, password reset, match notifications — which is necessary to run your account and cannot be switched off while the account is open. Informational email is sent only if you opted in, and every one carries an unsubscribe link.
18. Analytics and cookies
In the app. The app does not use cookies. It sends product analytics events to PostHog, on its EU servers, under a pseudonymous identifier, so we can see which features are used and where people get stuck. It also records about half of all sessions longer than ten seconds, as a replay of the screens and taps, so we can see and fix what goes wrong. In those recordings every photograph is hidden, and so are passwords, messages and voice notes, your journal, identity verification, references, and reports. Recordings are kept for 30 days, IP addresses are anonymised, and nothing is shared with advertising networks.
You may object to analytics and recordings at any time by writing to hello@datetomarry.app, and we will stop them for your account.
On this website. This website uses PostHog together with Vercel Analytics and Speed Insights. These measure page views and performance and do not build an advertising profile of you.
19. Changes to this policy
We may update this policy to reflect changes in what we do, the technology we use, or the law. We post the updated version here and in the app, and for material changes we notify you by email or in-app notice. The date at the top shows when it last changed.
20. Contact and complaints
For any question or request about this policy or your data, write to hello@datetomarry.app. We aim to respond within 30 days.
You have the right to complain to a data protection supervisory authority, in particular the one where you live or work. Our lead supervisory authority is the Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59-61, 10555 Berlin, Germany (www.datenschutz-berlin.de).
Questions about this page? Write to hello@datetomarry.app.