v0.9 draft — legal review pending
Privacy Notice
Last updated 18 July 2026
This notice explains how Safeword handles personal data. The controller's final legal name, registered address, representative details, and supervisory authority must be inserted during legal review before version 1.0. Privacy requests can be sent to privacy@safeword.dating.
1. Data we collect
- Account and consent: email or phone authentication identifier, authentication records, account timestamps, adult confirmation, and versioned Terms, Privacy, and explicit Article 9 consent records.
- Private profile: pseudonym, birthdate, gender, optional self-description and bio, relationship and role identity, languages, country, and coordinates rounded to two decimal places (roughly one kilometre, depending on latitude).
- Special-category matching data: sexual and kink interests, preferred stance, hard limits, relationship intentions, gender preferences, age range, distance, and online or partnered preferences. Some profile fields may also reveal sexual orientation or sex-life information.
- Service activity: proposals and scores, your response, chats, messages, photos, read times, blocks, reports, contact-exchange state, and moderation decisions.
- Private operational data: encrypted contact channels; pose-selfie verification challenges, artifacts, status and review metadata; engagement aggregates; Telegram numeric account/chat identifiers if linked; web-push endpoints and protocol keys; notification preferences; and export or deletion requests.
- Essential device data: authentication cookies or browser session storage, IP address and request metadata processed by the web and API services, and information needed to deliver an installed PWA. The current application does not implement advertising or analytics trackers.
2. Why we use it and our legal bases
We use account, profile, messaging, and notification data to provide the service you ask for; security and moderation data to protect members, prevent abuse, establish or defend legal claims, and comply with law; and consent records to demonstrate your choices.
Kink, sexual-preference, and other sex-life data is GDPR Article 9 special-category data. Safeword relies on GDPR Article 9(2)(a) explicit consent for matching. Onboarding presents that choice separately from the Terms, Privacy acknowledgement, and adult confirmation, and records each against the current draft version. You may withdraw consent by requesting account deletion or contacting us. Withdrawal does not make earlier lawful processing unlawful, but matching cannot continue without this data.
We do not sell personal data or use special-category data for advertising.
3. Matching and visibility
The matching worker compares hard filters, complementary or shared interests, distance, and engagement signals, then allocates limited proposals above a score threshold. Profiles are not browseable. A counterpart receives only the proposal-card fields needed to assess a proposal; direct database policies prevent one member from reading another member's raw profile, photos, kink list, or hard limits. Chat starts only after mutual acceptance.
4. Recipients and international transfers
The live application, self-hosted Supabase services, and primary database run on one EU VPS. Service operators and infrastructure providers can process data only as needed to host, secure, back up, or support the service. If you link Telegram, Telegram receives bot messages and your Telegram identifiers under its own terms. If you enable web push, your browser's push service receives an endpoint-level delivery request; Safeword sends no notification payload or message content.
Restic encrypts off-site backups on the Safeword host before upload. Those encrypted backup objects are currently stored in a Backblaze B2 US-region bucket, so ciphertext—not readable database or photo plaintext—is transferred to the United States. The transfer mechanism, processor contracts, and final safeguards require legal review.
5. Security
Safeword separates sensitive worker-only tables from the public API schema, applies forced row-level security to member-facing tables, uses short-lived signed links for private stored objects, and keeps contact-channel values encrypted in PostgreSQL. Access controls reduce risk but no online service can promise absolute security. Push notifications always display only “Safeword: you have news.”
6. Retention
- Profile, preferences, interests, contact channels, notification links, photos, and engagement aggregates remain while the account is active, unless a shorter rule below applies.
- A chat closes after 14 days without a member-authored message. Closure stops new messages; it does not by itself delete the chat history.
- After an approved verification review, the pose-selfie artifact is deleted after 24 hours. After a rejected review, it is deleted after seven days. Review metadata remains with the account. An artifact awaiting a decision has no separate automatic deletion window yet and is deleted during account purge.
- Data-export JSON objects and their request rows expire and are deleted seven days after the request.
- Account deletion stops matching and starts a 14-day grace period. The purge then removes the authentication account, profile, private contact/engagement/Telegram records, photos, verification artifacts, and export objects. Authored messages are anonymized by removing the sender and replacing the body with “[deleted].” Reports can remain as tombstoned safety records with the deleted member's structured profile reference set to null.
- Local database dump files older than seven days are removed after successful backup runs. The encrypted restic retention policy keeps seven daily, four weekly, and three monthly snapshots. Erased data may therefore remain outside the live service in encrypted backups until those snapshots expire and are pruned. If an older snapshot is restored, completed erasure requests must be re-applied before normal service resumes.
- The system currently has no shorter automatic deletion window for ordinary proposal, message, or moderation records while an account remains active. Legal review must set any additional safety-record retention limits before version 1.0.
7. Your rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, objection, or withdrawal of consent, and complain to a competent supervisory authority. Use Settings → Privacy & data to request a JSON export or account deletion. The export includes your decrypted contact channels and sensitive preferences, so protect the downloaded file. Contact privacy@safeword.dating for other requests.
8. Children
Safeword is strictly for people aged 18 or older. If you believe a minor has used the service, report it immediately. Suspected child sexual abuse material must be escalated under a restricted incident process, but the preservation authority, reporting route, deadlines, and on-call ownership remain pending legal and operations review. Legal preservation duties may override ordinary deletion where applicable.
9. Changes and contact
We will update this notice when processing changes. Material changes will receive an appropriate notice and renewed explicit consent where required. Questions and rights requests: privacy@safeword.dating.