Privacy Policy
Effective: March 31, 2026 · Last updated: March 31, 2026
1. Introduction
DatingRealPeople, Inc. ("we," "us," or "DatingRealPeople") operates the DatingRealPeople online dating platform accessible via web browser and mobile application (collectively, the "Service"). We are committed to protecting your privacy and handling your personal data with care and transparency.
This Privacy Policy describes what personal information we collect, how we use it, who we share it with, how long we retain it, and what rights you have over your data. It applies to all users of the Service, regardless of location.
Please read this policy carefully. By using the Service, you acknowledge that you have read and understood this Privacy Policy and our Terms of Service. If you do not agree with this policy, do not use the Service.
2. Information We Collect
We collect the following categories of personal information:
| Category | Examples | Retention |
|---|---|---|
| Account Data | Email address, hashed password, phone number, date of birth, gender, gender preferences | Until account deletion |
| Profile Data | Nickname, profile photos, bio, interests, "looking for" preferences, physical attributes (optional), city and approximate location | Until account deletion |
| Verification Data | Liveness check images, verification status (email, phone, liveness, government ID), trust score details | See Sections 3 & 8 |
| Communication Data | Direct messages (encrypted), audio/video call metadata (initiator, recipient, duration, timestamp — calls not recorded) | Until account deletion or message deletion |
| Trust & Safety Data | Trust score (0–100), date feedback ratings (1–5 stars), party feedback ratings, user reports filed and received, block list | Until account deletion |
| Device & Usage Data | IP address, device type, OS, browser (User-Agent), login timestamps, push notification tokens, app version | Up to 12 months; tokens until revoked |
| Location Data | City-level and coordinate-based distance data for discovery. We do not continuously track your precise GPS location in the background. | Until account deletion or location disabled |
| Payment Data | Subscription tier, billing cycle, transaction identifiers. Full payment card data is processed and stored by our payment processor — we do not store raw card numbers. | 7 years for tax/compliance purposes |
3. Identity Verification & Government ID
To enhance trust and safety, we offer optional identity verification via Sumsub, Inc. ("Sumsub"), an independent third-party verification provider.
When you choose to verify your identity, the following may be collected and processed:
- Images of your government-issued photo ID (front and back);
- A selfie or short liveness video for comparison with your ID photo;
- Biometric templates (facial geometry) derived from facial recognition, processed and stored by Sumsub under their privacy policy.
This information is used solely to verify that your profile photo matches your government-issued ID. It is not used for advertising, profiling, or any purpose other than identity verification.
Government-issued ID images and biometric data constitute sensitive personal information under applicable law (including the California Consumer Privacy Act and GDPR Article 9). We obtain your explicit consent before collecting this information, separate from general acceptance of our Terms.
Verification images are deleted by Sumsub within 30 days of verification. The fact that you have been verified (verification status: yes/no) is retained for the lifetime of your account. You may request deletion of your verification data at any time by contacting privacy@datingrealpeople.com. Note that deletion may result in loss of the identity-verified badge on your profile.
4. WebRTC & Communication Data
Calls are not recorded by DatingRealPeople. Recording or screenshotting a call by any user is strictly prohibited under our Terms of Service (§7) and may constitute a criminal offense. If you have been the victim of non-consensual recording or sextortion involving content from the Service, please contact us at safety@datingrealpeople.com.
The Service uses WebRTC peer-to-peer technology for real-time audio and video calls between users.
When you make or receive a WebRTC call:
- Audio/video streams are encrypted in transit using DTLS-SRTP and are not accessible to DatingRealPeople;
- Your IP address may be visible to the other participant during a peer-to-peer call;
- Call metadata (initiator, recipient, session start/end time, duration, connection quality indicators) is logged by our servers for safety, support, and billing purposes;
- Calls are not recorded by DatingRealPeople. Any user recording is prohibited under our Terms of Service;
- TURN server relay: if calls cannot connect peer-to-peer, they are relayed through our TURN infrastructure, which logs both parties' IP addresses for the duration of the relay session.
For direct messages: message content is encrypted at rest using AES-256 (TextCipher). Metadata (sender, recipient, timestamp, delivery status) is stored unencrypted. Messages are deleted when you or the recipient deletes them, or when your account is deleted.
Typing indicators and read receipts are transient and are not retained after the session ends.
5. How We Use Your Information
We use your personal information to:
- Create and maintain your account;
- Display your profile to other users and facilitate discovery and matchmaking;
- Deliver messages and establish audio/video calls;
- Calculate and display your Trust Score;
- Process payments and manage subscriptions;
- Send you notifications (messages, matches, date reminders) based on your preferences;
- Detect and prevent fraud, spam, impersonation, and other violations of our Terms of Service;
- Moderate user-generated content using automated systems (photos may be reviewed by AI-based content moderation before publication);
- Respond to legal requests from law enforcement and data protection authorities;
- Improve the Service and develop new features.
Automated decision-making: Matchmaking recommendations are generated using automated algorithms based on your preferences, location, and behavioral signals. These decisions are not solely automated in a legally significant sense — human review is available for any decision you wish to contest. Contact privacy@datingrealpeople.com to request human review of a specific matchmaking decision.
6. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, we rely on the following lawful bases under GDPR Article 6 (and UK GDPR equivalents):
- Contract performance (Art. 6(1)(b)): Account creation, authentication, messaging, calls, subscription billing — processing necessary to provide the Service you signed up for.
- Legitimate interests (Art. 6(1)(f)): Trust Score calculation, fraud detection, safety moderation, abuse prevention, push notifications — where our legitimate interests are not overridden by your rights and freedoms.
- Consent (Art. 6(1)(a)): Marketing communications, optional identity verification, optional biometric processing — where you have given clear, affirmative consent.
- Legal obligation (Art. 6(1)(c)): Retaining certain data to comply with tax, consumer protection, and other legal obligations.
For special category data (biometric data from identity verification, processed under GDPR Article 9), we rely on your explicit consent as the lawful basis.
Where processing is based on consent, you may withdraw consent at any time via your account settings or by emailing privacy@datingrealpeople.com. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
7. Data Sharing
We do not sell your personal data to third parties for monetary consideration. We do not share your data with data brokers or advertising partners for targeted advertising purposes.
We may share your data with the following categories of recipients:
- Service providers who process data on our behalf under Data Processing Agreements (DPAs): Twilio (SMS verification codes), Firebase (push notifications), Sumsub (identity verification), Cloudflare (bot protection — see Section 9), our cloud hosting provider, and our payment processor. A current list of subprocessors is available on request;
- Other users, limited to the information you choose to display on your public profile (nickname, photos, bio, age, location, trust score, verification badges);
- Law enforcement and regulators, when required by valid legal process, court order, or applicable law, or when we believe in good faith that disclosure is necessary to prevent imminent harm;
- Legal successors, in connection with a merger, acquisition, or sale of assets, in which case your data would be transferred subject to the same privacy protections described in this Policy;
- Anonymized aggregate data shared with academic or research partners for safety research — data is anonymized and not identifiable to any individual.
8. Data Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, subject to legal retention obligations.
| Data Category | Retention Period |
|---|---|
| Account profile data | Until account deletion + 30-day grace period |
| Direct messages | Until deleted by sender/recipient or account closure |
| Audio/video call metadata | 90 days from session |
| Government ID / verification images | Deleted by Sumsub within 30 days of verification; verification status retained for account lifetime |
| Liveness check images | Deleted within 30 days of verification |
| Trust score history | Until account deletion (for historical integrity during account lifetime) |
| Device and usage analytics | 12 months; anonymized aggregate data retained longer for research |
| Payment/subscription records | 7 years (tax and consumer law compliance) |
| Activity log (IPs, logins) | 12 months |
Upon account deletion, we initiate a 30-day recovery grace period. After this period, your personal data is deleted or irreversibly anonymized within an additional 30 days, except as required by law or for active legal holds.
9. Security
We implement technical and organizational measures designed to protect your personal data, including:
- AES-256 encryption for messages at rest;
- TLS 1.2+ encryption for all data in transit;
- DTLS-SRTP encryption for audio/video streams;
- bcrypt hashing for passwords;
- Short-lived JWT tokens for session management;
- Rate limiting and progressive ban infrastructure to protect against abuse and brute-force attacks;
- Redis-based rate limiting for API endpoints;
- AI-based photo moderation before photo publication.
- Cloudflare Turnstile to distinguish real people from automated bots on sign-up, sign-in, and password-reset requests.
Bot protection (Cloudflare Turnstile)
To stop automated accounts, we use Cloudflare Turnstile on sign-up, sign-in, and password-reset. Turnstile runs invisibly — it does not ask you to solve a puzzle or identify images, and in most cases you will not notice it at all. To decide whether a request comes from a real person, Cloudflare processes technical signals from your device and browser: your IP address, TLS fingerprint, User-Agent header, and the site key together with its associated origin. Cloudflare states that these signals are used solely for bot detection, and not to build advertising profiles or to track you across other websites.
Cloudflare processes this data as our service provider. Its handling of that data is governed by the Cloudflare Turnstile Privacy Addendum and the Cloudflare Privacy Policy.
While we implement reasonable safeguards, no system can guarantee absolute security. If you become aware of a security vulnerability in the Service, please contact us at security@datingrealpeople.com.
10. Your Rights
To exercise any of these rights, email privacy@datingrealpeople.com with your request and the email address associated with your account. We will respond within 30 days (GDPR) or 45 days (CCPA) as required by applicable law. We may need to verify your identity before processing your request.
California Residents (CCPA / CPRA)
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected, the purposes for collection, and whether we have sold or shared your data.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: You may opt out of the sale or sharing of your personal information. We do not sell personal data for monetary consideration. Cross-context behavioral advertising is treated as "sharing" under CPRA.
- Right to Limit Use of Sensitive Personal Information: You may limit our use of sensitive PI (including biometric data and precise geolocation) to that which is necessary to provide the Service.
- No Retaliation: We will not discriminate against you for exercising your rights.
California residents may also use our in-app privacy settings to exercise certain rights. To submit a verifiable consumer request, contact privacy@datingrealpeople.com.
European Union / EEA Residents (GDPR)
- Right of Access (Art. 15) — Obtain a copy of your personal data.
- Right to Rectification (Art. 16) — Correct inaccurate data.
- Right to Erasure / "Right to be Forgotten" (Art. 17) — Request deletion of your data, subject to our legal retention obligations.
- Right to Restriction of Processing (Art. 18) — Restrict our use of your data in certain circumstances.
- Right to Data Portability (Art. 20) — Receive your data in a structured, machine-readable format.
- Right to Object (Art. 21) — Object to processing based on legitimate interests. We will cease processing unless we have compelling legitimate grounds that override your rights.
- Right to Withdraw Consent (Art. 7(3)) — Withdraw consent at any time where processing is based on consent.
- Right to Lodge a Complaint (Art. 77) — You have the right to file a complaint with your national Data Protection Authority (DPA).
Contact our EU/UK representative at privacy@datingrealpeople.com.
Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Nevada (NRS 603A)
Residents of these states have rights similar to CCPA/GDPR, including rights to access, delete, correct, and opt out of targeted advertising and sale of personal data. To exercise these rights, contact privacy@datingrealpeople.com. Nevada residents may request that we do not sell covered information; we do not sell covered information as defined under Nevada law.
11. International Data Transfers
DatingRealPeople is headquartered in the United States. Your data may be processed in the United States and, in limited circumstances, in the European Union.
For transfers from the EEA or UK to the United States, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the transfer mechanism, supplemented by transfer impact assessments where applicable.
For transfers to third-party subprocessors outside the EEA or UK, we ensure adequate protections are in place through DPAs incorporating SCCs or through other mechanisms recognized under applicable data protection law.
You acknowledge that U.S. law (including FISA 702 and Executive Order 12333) may enable U.S. intelligence authorities to access data transferred from the EU/EEA to the U.S. We take reasonable steps to limit such access in accordance with applicable law.
12. Children's Privacy
DatingRealPeople is not intended for persons under 18 years of age. We do not knowingly collect personal information from anyone under 18. If we discover that we have inadvertently collected personal information from someone under 18, we will immediately delete their account and associated data.
This is consistent with COPPA (13+), CCPA (13+ for consent, 16+ for data sale opt-out), and the UK Age Appropriate Design Code (18+). As a dating platform, our minimum age is set at 18 to align with the nature of the service.
13. Data Breach Notification
In the event of a data breach that affects your personal information, we will notify you via the email associated with your account, and/or via prominent in-app notice, as required by applicable law. Notification will be provided within the timeframe required by your jurisdiction (for example, 72 hours to the relevant supervisory authority under GDPR; 30–90 days depending on the U.S. state).
We maintain a written incident response procedure for data breaches and conduct tabletop exercises periodically to ensure our team is prepared.
14. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email and/or a prominent notice in the Service at least thirty (30) days before they take effect. Your continued use of the Service after such notice constitutes acceptance of the updated Policy.
A history of previous versions of this policy is maintained and available on request. We encourage you to review this Policy periodically.
15. Contact
For all privacy-related inquiries, data subject rights requests, or questions about this Policy:
- Privacy team: privacy@datingrealpeople.com
- DPO / EU Representative: dpo@datingrealpeople.com
- Security vulnerabilities: security@datingrealpeople.com
- Mailing address: DatingRealPeople, Inc., Austin, Texas, United States
If you are located in the European Economic Area or United Kingdom and wish to contact our EU/UK representative directly, please email privacy@datingrealpeople.com.
DatingRealPeople, Inc. · Austin, Texas, USA · Terms of Service