AskedOut Privacy Policy
Version: 3.0 · Effective date: 25 July 2026
Plain-language summary (not a substitute for the full policy): AskedOut is a dating app for adults in France. To work, it needs your email address, date of birth, profile details and photos, and, each with your separate consent: your location, information that can reveal your sexual orientation (the genders you are interested in), and, if you choose to verify your profile, a one-time selfie that is compared to your photos and then deleted. Text messages are end-to-end encrypted: we cannot read them: the keys exist only on your device. Photos and voice messages in chat are not end-to-end encrypted, but only your match can access them. Your discovery location is deliberately blurred (snapped to a 500 m grid on our servers, distances rounded before display) so nobody can pinpoint you. We run the service on Amazon Web Services in the European Union (Ireland) and payments go exclusively through Apple; we never see your card details. There is no advertising, no third-party tracking or analytics SDK, and we never sell or rent your data. Matching is based only on the filters you set: no opaque algorithm, and no automated decisions with legal effects. You can export your data (JSON) and delete your account directly in the app; deletion takes effect after a 30-day grace period during which you can change your mind. Questions, requests and complaints: contact@askedout.com: and you can always complain to the CNIL.
Contents
- Who is responsible for your data (controller) and how to contact us
- Scope: who and what this policy covers
- The data we collect
- Why we process your data: purposes and legal bases
- Special-category data: sexual orientation and biometrics
- Automated processing, matching and Article 22
- How we share your data
- International transfers
- How long we keep your data (retention)
- Your rights
- How we protect your data (security)
- Guests: browsing without an account
- Non-users and reporters (Digital Services Act)
- Minors
- Push notifications, communications and your device
- Changes to this policy
- Contact and complaints
1. Who is responsible for your data (controller) and how to contact us
1.1 The controller
The controller of your personal data (the person who decides why and how your personal data is processed in connection with AskedOut) is:
Rohit Yasashwi Bonthalakoti, an individual established in France, acting as data controller 29 Rue des Faillettes, 95120 Paris, France Email (privacy, support, abuse and Digital Services Act contact, in one mailbox): contact@askedout.com Website: askedout.com
AskedOut is published by an individual entrepreneur, not a corporation. This does not change your rights in any way: the full GDPR (Regulation (EU) 2016/679) and the French Data Protection Act (Loi n° 78-17 du 6 janvier 1978, Loi Informatique et Libertés) apply to everything described in this policy.
1.2 Why there is no Data Protection Officer
We have not designated a Data Protection Officer (DPO). Article 37(1) GDPR makes a DPO mandatory only where (a) processing is carried out by a public authority, (b) the core activities require regular and systematic monitoring of data subjects on a large scale, or (c) the core activities consist of large-scale processing of special-category data. AskedOut does process special-category data (see Section 5), but at its current scale (a single-market app operated by an individual entrepreneur) that processing is not “large scale” within the meaning of Article 37(1)(c) as interpreted in the EDPB (formerly Article 29 Working Party) Guidelines on Data Protection Officers (WP243). We also do not track or monitor members’ behaviour beyond operating the features described in this policy.
We keep this assessment under review: if the service grows to a scale where Article 37 requires it, we will designate a DPO and update this policy. In the meantime, all data protection matters are handled directly by the controller at contact@askedout.com, with the same one-month response commitment as a DPO would provide (see Section 10.11).
1.3 One address for everything
We deliberately use a single contact point, contact@askedout.com, for privacy requests, support, abuse reports, notices of illegal content under the Digital Services Act, and communications from authorities. Communications are accepted in French and English. Postal mail can be sent to the address in Section 1.1.
2. Scope: who and what this policy covers
This policy explains how we process personal data in connection with the AskedOut mobile application and the associated services (API at api.askedout.com, transactional emails, push notifications, in-person events listings). It covers three groups of people:
- Members: people who have created an AskedOut account. Most of this policy is about you.
- Guests: people who browse nearby profiles in the app without creating an account. A dedicated section (Section 12) describes the very limited processing that applies to you.
- Non-users: people who have no account and don’t use the app but interact with us anyway: for example, someone who emails us to report content under the Digital Services Act, a person mentioned in a member’s report, or an authority contacting us. See Section 13.
What this policy does not cover. Apple processes your payment independently when you buy AskedOut+ (Apple is the merchant of record; see Section 7.3); Apple’s own privacy policy governs that payment. The informational website at askedout.com does not set tracking cookies and does not have member accounts. If we ever link to third-party sites or venues (for example, an event venue’s website), their policies govern what happens there.
AskedOut is strictly for adults aged 18 or over. See Section 14 (Minors).
3. The data we collect
This section is an exhaustive inventory. We collect data in three ways: data you give us (Sections 3.1 to 3.5, 3.8), data generated when you use the service (Sections 3.6, 3.7, 3.9, 3.10, 3.11), and data other people provide about you (Section 3.12). We do not buy data about you, we do not receive data about you from data brokers or social networks, and there is no “sign in with” any third-party identity provider. We also never request access to your phone’s contact list or address book; nothing in this inventory comes from your contacts, and referrals work through an invite code you choose to share, never through contact upload.
3.1 Account data
When you sign up we collect:
- Your email address, verified with a one-time code (OTP) we email to you. Your email is your login identifier and how we send you service messages.
- A password. It is stored only as an argon2 hash, a one-way transformation, so we never see or store the password itself. Passwords must be at least 10 characters with upper-case, lower-case and digit characters.
- Your date of birth, used to enforce the strict 18+ rule and to display your age (you can hide the age display; see Section 3.2). Your exact birth date is retained, not just an over-18 flag, because age-range filtering and ongoing age enforcement require it.
- A referral code, if you enter one, so both you and the person who invited you can receive the referral benefit (bonus AskedOut+ days when the conditions are met).
- Your acceptance of the Terms of Service and this Privacy Policy, recorded in the consent ledger (Section 3.10).
Phone-number sign-in is not offered at launch (the capability exists in our software but is disabled). If it is ever introduced, this policy will be updated first and you will be asked to review the change (Section 16).
3.2 Profile data
Your profile is what you choose to show other members. Each field, and whether it is visible to others, is listed below:
| Field | Required? | Visible to other members? |
|---|---|---|
| Display name | Yes | Yes |
| Gender (woman / man / non-binary, with optional self-description) | Yes | Yes |
| Gender(s) you are interested in meeting | Yes (for matching) | No: used only to build your feed and decide who sees you |
| Date of birth / age | Yes | Age only, and you can hide the age display |
| Bio (free text) | No | Yes |
| Occupation | No | Yes |
| Profile song (title/artist of an iTunes preview clip) | No | Yes |
| Lifestyle fields: relationship goal, drinking, smoking, position on children, workout frequency, height | No | Yes (the ones you fill in) |
| Hobbies (chosen from a fixed list) | No | Yes |
| City | No | Yes |
| Photos (up to 6, moderated) | Yes (at least one) | Yes, once approved |
| Optional free-text sexual-orientation field | No | Yes, if you fill it in |
Special-category data. The gender(s) you are interested in, and the optional free-text orientation field, can reveal your sexual orientation: special-category data under Article 9 GDPR. We process them only with your explicit consent, collected separately in the app before your profile becomes active, and only for matching. Section 5 explains this in full, including exactly what happens if you withdraw the consent.
The profile song feature uses preview clips from Apple’s iTunes Search API. When you search for a song, your search terms are sent to Apple’s public search service (without any AskedOut account identifier); we then store only the chosen track’s title, artist and preview reference. No Apple Music account is linked and no listening data is collected.
3.3 Photos and photo-moderation data
You can upload up to six profile photos. Photos go through a two-stage pipeline:
- On your device, before upload: the app checks that the photo contains a visible face, using the operating system’s on-device face detection (Apple Vision on iOS; Google ML Kit on Android, with a bundled model that makes no network calls). This check happens entirely on your phone; photos that fail it are never uploaded.
- On our servers, before the photo is shown to anyone: automated content-safety screening via Amazon Rekognition (detection of nudity and explicit content) in the EU (Ireland) region, plus a human review queue. Automated screening alone never rejects a photo; a flagged photo goes to a human moderator (see Section 6.3). Rejected photos are removed and you receive an in-app notification explaining that the photo was not approved.
We store: the photo files themselves (on access-controlled storage; see Section 7.2), each photo’s moderation status and history (pending / approved / rejected, moderation labels from the automated screening, and moderator decisions), and their display order. Approved photos are visible to other members and to guests browsing nearby profiles (Section 12); pending and rejected photos are never visible to anyone but you and our moderation staff.
3.4 Identity verification selfie (biometric processing)
“Get Verified” is an optional feature that adds a verified badge to your profile by confirming that your profile photos really show you.
- You take a live selfie in the app, front camera only; gallery photos cannot be submitted. The selfie is compared against your profile photos, either automatically using Amazon Rekognition face comparison (CompareFaces) in the EU (Ireland) region where that is enabled, or by a human moderator.
- This comparison is biometric processing for the purpose of uniquely identifying you: special-category data under Article 9 GDPR. It happens only with your separate, explicit consent, captured in the app before the camera opens (a dedicated “face verification” consent, distinct from every other consent, and revocable; see Section 5.3).
- The selfie is compute-and-discard: it is deleted immediately after the automated decision, or immediately after the human moderator’s decision in borderline cases. It never appears on your profile and is never visible to other members.
- What we keep: the verification outcome (verified / rejected / pending) and the numeric similarity score of the comparison. We do not keep the selfie, and we do not build or retain any biometric template usable outside this one check.
Verification is entirely optional. An unverified account keeps full access to the service. Verification on AskedOut is selfie-based only: we never ask you to submit a government identity document (passport, ID card, driving licence), and no ID document data is collected anywhere in the app. See Section 6.2 for the automated element of this decision and your right to human review.
3.5 Location data
With your separate location consent, captured in-app before any location use, we collect your device’s location to power the discovery feed (“people near you”) and distance display.
How this actually works, because dating-app location handling deserves a precise explanation:
- We collect a single position fix at medium accuracy each time you actively set or refresh your location. There is no continuous tracking and no background tracking: the app does not report your position as you move around.
- We store the coordinates and the derived city name (the coordinates-to-city conversion uses the operating system’s own geocoder on your device).
- Grid snapping (anti-trilateration): when any member’s discovery query runs, our server first snaps the query’s centre point to a 500-metre grid. Combined with server-side distance rounding, where distances shown to other members are rounded to a minimum granularity of about 1 km: this is a deliberate design to prevent anyone from reconstructing your exact position by repeatedly querying from different points (a known attack on dating apps called trilateration). No member, however determined, is served data precise enough to locate you beyond a rough area.
- Guests browsing without an account are never shown any distance to you at all.
- Withdrawing location consent in the app deletes your stored location immediately and pauses your presence in location-based discovery (Section 10.7).
3.6 Usage, swipe and match data
Using the service generates records that make its features work:
- Swipes: each like or pass you make, with its timestamp. Swipes are quota-limited (35 per 12 hours for free members; 100 per 12 hours with AskedOut+), so we also track your quota usage. If you use Rewind (AskedOut+ only), the undo of your last swipe is performed server-side and recorded.
- Matches: created when two members like each other; each match’s status, creation time and expiry. Matches expire after 24 hours if neither person sends a message (a message from either side saves the match); expired matches can be revived with the AskedOut+ Rematch feature, and revivals are recorded.
- “Likes you” data: the list of members who have liked you (shown blurred to free members, visible with AskedOut+). Note the mirror image: when you like someone, you appear in their “likes you” list.
- Discovery and filter settings: your chosen distance radius, age range, genders sought, and, with AskedOut+, advanced filters (lifestyle fields, height, verified-only, etc.).
- Blocks and unmatches you perform, and reports you file or that are filed about you, with their resolution (see Sections 3.12 and 7.6).
- Events: if you use the in-person events listing, your RSVPs (“Join”) and event likes. Your RSVP is never shown to other members individually: other members see only an anonymous aggregate attendee count, and a gender-ratio percentage that is deliberately suppressed below a minimum number of attendees so that it can never reveal any individual attendee’s gender.
- Referral activity: the link between referrer and invitee account identifiers and the granting of referral rewards.
We collect this data to run the features themselves, not to build behavioural or advertising profiles. Discovery ordering uses only your explicit filters and profile recency (Section 6.1).
3.7 Messages (chat)
Chat is available between matched members only. The privacy design differs by message type, and we want to be precise about it:
- Text messages are end-to-end encrypted (E2EE). Encryption uses an X25519 key exchange with AES-256-GCM message encryption; the private keys are generated and stored only on your device (in the operating system’s secure keychain). Our servers store and relay only ciphertext. We cannot read your text messages: not for moderation, not for support, not at the request of anyone. The app provides a safety-number (security code) screen so you and your match can verify your encryption keys against each other, and warns you in the conversation if your match’s key changes (for example after they reinstall on a new device). Honest limits of this design are described in Section 11.2.
- Photo and voice messages in chat are not end-to-end encrypted. They are stored on our infrastructure with access restricted to the two participants of the match, served only through access-controlled endpoints. Voice messages are limited to 120 seconds.
- Message metadata is stored in clear form so chat can function: sender, match, timestamps, read status, and, for media, duration and a file reference. Typing indicators and read receipts are exchanged live; typing indicators are transient and never stored.
- Reporting a message shares its content with us. If you report a text message (long-press → report), the app attaches the decrypted text of that message, decrypted on your device, by your action, so our moderators can assess it. This is the only way message text ever becomes readable to us. Report evidence has its own limited retention (Section 9).
- Messages removed for safety reasons display as “[deleted]” in the conversation.
- On-device only, never sent to us: (a) incoming chat photos are screened on your device for nudity and blurred until you tap to reveal; (b) your outgoing messages are checked on your device for personal information such as a street address, so the app can warn you before you share it. Both checks run entirely on your phone; nothing about them leaves the device.
- Chat history survives logout and login on the same device (keys are stored per account on that device). Screenshot and screen-recording blocking applies app-wide on a best-effort basis (Section 11.4).
3.8 Purchase data (AskedOut+)
AskedOut+ is an auto-renewing subscription (1, 6 or 12 months, EUR pricing displayed by Apple’s StoreKit) purchased exclusively through Apple In-App Purchase. Apple is the merchant of record for the payment transaction and an independent controller for it. Consequently:
- We never receive, see or store your card number, bank details or billing address. No payment instrument data ever touches our systems.
- What we do store: your subscription plan, status, period end, and the Apple transaction identifiers we need to activate, renew, restore (“Restore purchases”) and manage your subscription entitlements (extra swipes, advanced filters, “likes you” visibility, Rematch, Rewind).
- Subscription management and cancellation happen only through your Apple ID subscription settings; we could not charge or refund you ourselves even if asked.
3.9 Device and technical data
- Session data: for each sign-in we store your IP address and device/user-agent string. You can view your active sessions in the app (with IP and device info) and revoke any of them; revocation forces that session to log out.
- Authentication tokens: short-lived access tokens (about 15 minutes) and rotating refresh tokens (see Section 11.3). These are credentials, not tracking identifiers.
- Push token (iOS): with your OS-level permission, your device’s APNs push token, used solely to deliver notifications (Section 15). We use Apple’s push service directly (relayed via AWS SNS); there is no Firebase and no third-party push SDK.
- Crash/error reports: the app sends error type, message, stack trace and a small context tag to our own servers (no third-party crash SDK in the app). Backend errors are additionally monitored via Sentry (Section 7.4). Error logs have fixed retention (Section 9).
- Audit log: security-relevant actions (logins, consent changes, administrative/moderation actions) with timestamp and IP address.
- Email deliverability data: if an email to you bounces or you mark our email as spam, we record that on a suppression list so we stop sending to that address.
- Rate-limiting and abuse-prevention counters tied to IP addresses and accounts.
3.10 Consent and audit records
Every consent you give or withdraw (Terms of Service, Privacy Policy, marketing emails, location processing, special-category orientation data, face verification) is recorded in an append-only consent ledger with the exact document version, timestamp, IP address and user agent. This ledger is our legal proof that consent was validly obtained (Article 7(1) GDPR) and is retained even after account deletion, for as long as legal limitation periods require (Section 9). Withdrawing a consent adds a withdrawal record; it does not erase the historical proof that the consent existed, because we must be able to demonstrate the lawfulness of past processing.
3.11 Guest-mode data
If you browse without an account, the app asks you who you want to see (genders), an age range and a distance, and, with your OS permission, uses your device location only as a query parameter to fetch nearby profiles. We do not store the guest’s location, create no guest profile and assign no persistent guest identifier. Section 12 covers guests in full.
3.12 Data other people provide about you
- Reports: another member (or a non-user; see Section 13) may report your profile or a message you sent, choosing a reason category and optionally adding context. If they report one of your text messages, the report includes that message’s text, decrypted on the reporter’s device. Reports about you, their handling and their resolution become part of your account’s moderation record.
- Blocks: if someone blocks you, we record the block so the app can keep you apart. You are not notified and cannot see who blocked you.
- Referrals: if someone invited you with a referral code, the link between your account identifiers is recorded to grant the reward.
We treat report contents carefully: they are visible only to moderation staff, retained for a limited time (Section 9), and reporters are protected: we do not reveal a reporter’s identity to the person reported.
4. Why we process your data: purposes and legal bases
The GDPR requires a legal basis for every processing purpose. The table below maps each purpose to its basis; prose explanations follow, because a table row is not enough to genuinely understand what “legitimate interest” or “contract” means in practice.
| # | Purpose | Main data used | Legal basis |
|---|---|---|---|
| 1 | Providing the service: account, profile, discovery, matching, chat, events, service notifications | Account, profile, photos, usage data, messages, push token | Contract: Art. 6(1)(b) GDPR |
| 2 | Showing you people matching the genders you seek / showing your profile to compatible members | “Interested in” field, optional orientation field | Explicit consent: Art. 9(2)(a), with Art. 6(1)(a) |
| 3 | Location-based discovery and distance display | Location (grid-snapped) | Consent: Art. 6(1)(a) |
| 4 | Optional profile verification (selfie comparison) | Selfie (transient), similarity score, outcome | Explicit consent: Art. 9(2)(a), with Art. 6(1)(a) |
| 5 | Safety: photo and content moderation, handling reports, enforcing the Terms, protecting members | Photos, reports (incl. voluntarily disclosed message text), moderation records, account status | Legitimate interests: Art. 6(1)(f); legal obligation (Digital Services Act), Art. 6(1)(c) |
| 6 | Age enforcement (18+) | Date of birth | Legal obligation / legitimate interests: Art. 6(1)(c), (f) |
| 7 | Payments and subscription management | Subscription and Apple transaction data | Contract: Art. 6(1)(b) |
| 8 | Security: sessions, authentication, rate limiting, lockout, audit, fraud and abuse prevention | Technical/security data, audit log | Legitimate interests: Art. 6(1)(f) |
| 9 | Reliability: fixing bugs and errors | Crash/error reports | Legitimate interests: Art. 6(1)(f) |
| 10 | Service emails (verification codes, security notices, deletion confirmations) | Email address | Contract: Art. 6(1)(b) |
| 11 | Marketing emails (news and offers) | Email address | Consent: Art. 6(1)(a), optional and withdrawable |
| 12 | Proof of consent; establishment, exercise or defence of legal claims | Consent ledger, audit log | Legal obligation / legitimate interests: Art. 6(1)(c), (f) |
| 13 | Responding to legally binding requests from authorities | The data specified in a valid request | Legal obligation: Art. 6(1)(c) |
Purpose 1, running the service (contract). When you create an account you enter into a contract with us (the Terms of Service). Everything indispensable to delivering what you signed up for (storing your profile, showing it to others, computing matches, relaying your encrypted messages, sending a “new match” notification) is processed on that contractual basis. If we could not process this data, the service simply could not exist for you.
Purposes 2 to 4, the consents. Three processing operations rest on your consent, each collected separately, each before the processing starts, and each withdrawable at any time in the app: matching by the genders you seek (explicit consent, because the data can reveal sexual orientation), location-based discovery, and biometric selfie verification (explicit consent). We never bundle these consents with the Terms, never pre-tick them, and using AskedOut+ or any paid feature is never conditioned on the marketing consent. Section 5 details the special-category consents and Section 10.7 the withdrawal paths and consequences.
Purpose 5, safety (legitimate interest + legal obligation). Keeping a dating community safe (screening photos, reviewing reports, restricting abusive accounts) is our legitimate interest and, above all, that of our members. We have balanced this interest against members’ rights: moderation uses the least data necessary, automated screening never rejects content on its own, E2EE text is structurally excluded from any scanning, and report evidence is retained only briefly (Section 9). Parts of this processing are also a legal obligation under the EU Digital Services Act (Regulation (EU) 2022/2065): operating a notice-and-action mechanism, giving statements of reasons, and notifying authorities of threats to life or safety (Art. 18 DSA). You can object to legitimate-interest processing (Section 10.6).
Purpose 6, age enforcement. Offering an adult dating service to adults only is both a legal necessity and a legitimate interest of every member. Your date of birth is checked at signup and enforced server-side; underage reports get priority handling (Section 14).
Purposes 8 to 9, security and reliability. Protecting accounts from takeover, detecting brute-force attempts, revoking stolen tokens, and fixing crashes are classic legitimate interests recognised by Recital 49 GDPR. The data involved is technical, minimal and short-lived (Section 9).
Purpose 11, marketing. The only marketing we do is email to members who opted in via an optional, unticked checkbox at signup. Every marketing email contains an unsubscribe link. We do not run ads, retargeting, audience sharing or any other marketing processing.
Purposes 12 to 13, legal. French law requires us to be able to prove consent and to respond to valid judicial requisitions; general limitation periods require retaining minimal evidence for the defence of legal claims. This is the narrowest possible processing: an append-only ledger and audit trail, never used for any other purpose.
What is deliberately not on this list. We do not process your data for advertising, do not build advertising or behavioural profiles, do not perform analytics beyond first-party operational metrics, do not train AI models on your content, and do not sell or rent personal data to anyone. There is no legal-basis row for those activities because they do not happen.
5. Special-category data: sexual orientation and biometrics
Dating apps inevitably touch the most protected categories of personal data. Article 9(1) GDPR prohibits processing data revealing sexual orientation, or biometric data for uniquely identifying a person, unless an exception applies. For AskedOut, the only exception we rely on is your explicit consent (Article 9(2)(a)). This section explains each processing operation, its consent, and precisely what happens when you withdraw.
5.1 Sexual orientation (the “interested in” field)
What reveals it: the gender(s) you say you are interested in meeting, combined with your own gender, can reveal your sexual orientation. The optional free-text orientation field reveals it directly if you use it.
The consent: at profile creation, a separate, explicit consent checkbox, distinct from the Terms acceptance, covers this processing. Without it, preference-based matching cannot run.
What we use it for, and nothing else: building your discovery feed (showing you profiles of the genders you seek) and deciding whose feeds your profile appears in. The “interested in” field itself is never displayed to other members; other members see only what your visible profile shows. We never use orientation data for advertising, never share it outside the matching function, and never infer anything further from it.
Withdrawal and its exact consequence: you can withdraw this consent at any time in the app. Withdrawal immediately nulls the orientation field (including removing the free-text orientation field from your profile) and pauses your presence in discovery: matching cannot operate without knowing whom to show you. Your existing matches and conversations are unaffected. You can re-consent later to resume discovery.
5.2 Biometric verification (the selfie)
What it is: the optional “Get Verified” face comparison described in Section 3.4, biometric processing for unique identification under Article 9(1).
The consent: a dedicated, explicit face-verification consent, captured in-app before the camera opens, separate from every other consent. Declining it simply means you do not get verified; nothing else changes.
Minimisation by design: the selfie is used for the single comparison and then deleted immediately (“compute-and-discard”). No biometric template is retained for future use; only the outcome and similarity score persist (Section 3.4).
Withdrawal and its exact consequence: withdrawing the face-verification consent in the app prevents any further verification attempt. There is no stored selfie to delete; it was already deleted at decision time by design. If you also want the stored verification outcome and similarity score erased (which removes the verified badge), ask via the in-app deletion tools or contact@askedout.com (Section 10.3).
5.3 General consent guarantees
For both special-category consents (and the location and marketing consents): consent is requested in clear language, separately from other matters (Article 7(2) GDPR); it is as easy to withdraw as to give (Article 7(3)); the withdrawal switches are in the app’s privacy settings; withdrawal never affects the lawfulness of processing already carried out; and refusing or withdrawing a consent never blocks the parts of the service that do not depend on it. Every grant and withdrawal is recorded in the consent ledger (Section 3.10).
6. Automated processing, matching and Article 22
Members of dating apps rightly ask whether an opaque algorithm decides their romantic prospects. Here is exactly how AskedOut works.
6.1 Matching is deterministic, with no profiling-based ranking
Your discovery feed is built from deterministic filters only: the distance radius, age range and genders you (and the other member) have set, premium filters where applicable (lifestyle fields, height, verified-only), and profile recency. There is no machine-learning ranking, no “desirability score”, no engagement-optimising algorithm, and no behavioural profiling deciding who you see or who sees you. Two members whose filters mutually match will appear in each other’s feeds, ordered by the stated criteria. That is the entire system.
Consequently, no processing on AskedOut constitutes profiling-based automated decision-making producing legal effects or similarly significant effects on you within the meaning of Article 22(1) GDPR. Nobody is invisibly downranked, excluded or scored.
6.2 The one automated decision: optional selfie verification
Where automated face comparison is enabled, verification works like this: a clearly matching selfie is auto-approved; a clearly non-matching selfie is auto-rejected; everything in between goes to a human moderator. Because verification is optional and an unverified account keeps full access to every feature, we consider that even an auto-rejection does not produce legal or similarly significant effects under Article 22(1). Nevertheless, we voluntarily provide the full Article 22(3) safeguards: if your verification is auto-rejected you can (a) retry with a new selfie at any time, (b) request human review of the decision at contact@askedout.com, and (c) express your point of view and contest the decision.
6.3 Automated screening never acts alone in moderation
Profile photos are screened automatically for policy violations (Section 3.3), but automated screening alone never rejects a photo or sanctions an account: flagged content goes to human review, and account restrictions (suspension, limitation, ban) are decided by humans and come with a statement of reasons (see the Terms of Service and, for EU notice-and-action rights, Section 13). Your encrypted text messages are structurally outside any scanning: we hold only ciphertext (Section 3.7).
7. How we share your data
Short version: your data goes to other members (only what your profile shows), to a small set of processors (AWS, Apple’s push and search services, Sentry) bound by contracts, to Apple as an independent controller for payments, and to authorities only under valid legal process. We never sell it and never share it for advertising. Details per recipient:
7.1 Other members and guests
What other members can see: your approved photos, display name, age (unless you hide it), gender, bio, occupation, profile song, lifestyle fields, hobbies, city, verified badge if you have one, and an approximate distance (rounded; see Section 3.5). If you like someone, you appear in their “likes you” list (blurred until they have AskedOut+). Once matched, your match sees your messages and any chat media you send them.
What other members can never see: your email address, exact date of birth, phone data, precise location or coordinates, the “interested in” field, your verification selfie or similarity score, your swipe history, who else you matched with, your reports or blocks, your subscription and purchase details, and your consent or security records.
Guests (Section 12) see approved photos and public profile fields of active members near their queried area, with no distance shown: unless the member has paused discovery in Settings.
Remember that anything you put in your public profile or send to a match is disclosed by you to another person; despite app-wide best-effort screenshot blocking (Section 11.4), we cannot technically guarantee another person will never capture or repeat what you show them.
7.2 Processors: Amazon Web Services (sub-processor detail)
Our infrastructure runs on Amazon Web Services (AWS EMEA SARL, 38 avenue John F. Kennedy, L-1855 Luxembourg), a processor under Article 28 GDPR bound by data-processing terms, with all primary processing in the EU (eu-west-1, Ireland) region:
| AWS service | What it does for AskedOut | Data involved | Region |
|---|---|---|---|
| Compute & database hosting | Runs the API and stores the database | All server-side data described in Section 3 | EU (Ireland) |
| S3 (storage) | Stores files | Profile photos, chat media, transient verification selfies, data-export files | EU (Ireland) |
| SES (email) | Sends transactional email | Email address, message content (OTP codes, security notices), deliverability events | EU (Ireland) |
| SNS (push relay) | Relays push notifications to Apple APNs | Push token, notification payload (generic text only; see Section 15) | EU (Ireland) |
| Rekognition (image analysis) | Content-safety screening of profile photos; face comparison for optional verification | Photo being screened; selfie + profile photos during comparison (transient) | EU (Ireland) |
7.3 Apple
Apple (Apple Distribution International Ltd., Hollyhill Industrial Estate, Cork, Ireland) touches your data in four distinct ways:
- Payments: Apple is the merchant of record and an independent controller for AskedOut+ purchases. Your payment relationship for the transaction itself is with Apple, under Apple’s terms and privacy policy. We receive only transaction identifiers and subscription status, and never payment instruments (Section 3.8).
- Push delivery: notifications reach your device through Apple’s APNs (Section 15).
- Song search: the profile-song picker queries Apple’s public iTunes Search API with your search terms, without any AskedOut credentials or identifiers (Section 3.2).
- App distribution: the App Store’s own analytics and crash reporting between you and Apple are governed by Apple’s policies and your Apple device settings, not by us.
7.4 Sentry
Backend (server-side) errors are monitored via Sentry (Functional Software, Inc.), a processor bound by data-processing terms. Sentry receives error type, message, stack traces and technical context from our servers: the app itself contains no Sentry or other third-party crash SDK; client errors go to our own backend only (Section 3.9). Transfers, where they occur, are safeguarded as described in Section 8.
7.5 Our staff
AskedOut moderators and administrators access personal data only as needed for content moderation, report handling and support. Access is role-restricted and logged. Staff can never read your end-to-end encrypted text messages; the architecture makes it impossible, not merely forbidden (Section 3.7).
7.6 Authorities and legal requests
We disclose personal data to public authorities only where legally required: a valid judicial requisition (réquisition judiciaire) or equivalent binding order under French or EU law, or our own obligation under Article 18 of the Digital Services Act to inform authorities of information giving rise to a suspicion of a criminal offence involving a threat to life or safety. We review every request for legal validity, jurisdiction and scope, disclose only the data the request lawfully covers, and cannot disclose the content of end-to-end encrypted text messages, because we do not possess the keys. Where the law permits, we will inform you of a request concerning you.
7.7 Business transfers
If the AskedOut business is ever transferred (for example a sale of the business, incorporation of the sole tradership into a company, merger or asset transfer), personal data may be transferred to the successor solely to continue operating the service, under confidentiality obligations. The successor would be bound by this policy or would have to notify you of changes and, where required, seek fresh consent (Section 16). You would retain every right in Section 10, including deletion.
7.8 What we never do
We do not sell or rent personal data. We do not share data with advertisers, ad networks, data brokers or “marketing partners”. There are no advertising SDKs, no third-party analytics SDKs and no tracking SDKs in the app. No social network receives anything about your AskedOut activity. These are not just policy choices; the code contains no such integrations.
Nor is there any corporate group behind AskedOut: the publisher is a single individual entrepreneur (Section 1.1), with no parent company, no affiliates and no “family of apps” with which your data could be pooled or shared. The recipients listed in Sections 7.1 to 7.6 are the complete list.
8. International transfers
Primary rule: your data stays in the European Union. AskedOut is hosted on AWS in the eu-west-1 (Ireland) region: database, photos, chat media, email sending, push relay and image analysis all run there (Section 7.2).
Residual transfers. Limited situations can involve access from outside the EU/EEA: a provider’s global support or sub-processing (e.g. AWS support access, Apple’s global push infrastructure) and Sentry’s error monitoring (a US company). For any such transfer we rely on the safeguards of Chapter V GDPR:
- the EU-US Data Privacy Framework (adequacy decision of 10 July 2023) for US providers certified under it, and/or
- the European Commission’s Standard Contractual Clauses (Decision 2021/914), with supplementary measures where needed, and/or
- an adequacy decision for the destination country (Article 45 GDPR).
Your rights regarding transfers: you can ask us at contact@askedout.com which safeguard applies to a given transfer and request a copy of the relevant Standard Contractual Clauses (redacted of commercial terms). If a safeguard we rely on is invalidated or a transfer can no longer be adequately protected, we will suspend it or switch providers.
9. How long we keep your data (retention)
We keep personal data only as long as the purpose requires, then delete or anonymize it. The full schedule:
| Data | Retention |
|---|---|
| Account and profile data | Life of the account, then the 30-day deletion grace period, then erasure/anonymization (Section 10.3) |
| Profile photos | Life of the account; deleted from storage upon account erasure |
| Verification selfie | Deleted immediately after the verification decision (automated or human), never stored beyond the check |
| Verification outcome + similarity score | Life of the account |
| Location | Until you refresh it, withdraw location consent (immediate deletion), or delete your account |
| Text messages (ciphertext) | Life of the match/account; on account erasure, message content is replaced with “[deleted]” |
| Chat media (photos, voice messages) | Life of the match/account; deleted from storage upon account erasure |
| Swipes, matches, blocks, discovery settings | Life of the account; anonymized on erasure (Section 10.3) |
| Report evidence (including reported message text) | Maximum 180 days after resolution of the report; 365-day hard cap if a report is never resolved |
| Data-export files | 48 hours, then deleted from storage |
| One-time codes (OTP) | 10 minutes, then purged |
| Sign-in sessions (refresh tokens) | 30 days, or until you revoke them or we revoke them for security |
| Audit logs | 90 days |
| Error logs | 90 days after resolution; 365-day hard cap regardless of status |
| Email suppression flags | As long as needed to honour the suppression |
| Subscription/transaction records | Life of the account + as required by French accounting and tax law |
| Consent ledger | Retained as proof of consent including after account deletion, for the duration of applicable legal limitation periods |
| Backups | Encrypted backups rotate automatically and expire within [BACKUP ROTATION PERIOD, confirm before publication]; data erased from live systems disappears from backups as the rotation completes and is never restored except for disaster recovery |
Why these periods. The account-life periods exist because the service cannot function without the data while you are a member. The 30-day grace period protects you against impulsive or coerced deletion, a real risk in the dating context, while removing you from discovery immediately. Report evidence is kept just long enough to handle appeals and detect repeat abuse, then destroyed. The consent ledger and minimal anonymized safety records outlive the account because French limitation periods may require us to prove past lawfulness or defend legal claims; they are never used for any other purpose. Exactly what survives account deletion is itemised in Section 10.3.
10. Your rights
Under the GDPR and the French Data Protection Act you have the rights below. Many work directly in the app with no email needed; everything else goes through contact@askedout.com. All rights are free of charge.
10.1 Right of access (Article 15 GDPR)
You can ask whether we process your data, obtain a copy of it, and receive the information in this policy tailored to your case (purposes, recipients, retention, safeguards for transfers). The fastest route is the in-app export (Section 10.5), which already contains the bulk of your data; for anything it does not cover, for example your photo files or moderation records concerning you, email contact@askedout.com. Where a request concerns records that also contain other people’s data (e.g. reports), we will provide your data while protecting theirs.
10.2 Right to rectification (Article 16 GDPR)
Almost everything about you is editable in the app: profile fields, photos, preferences, settings. If something is wrong that you cannot edit yourself, for example an error in your date of birth, contact us with the correction; we may ask for evidence where the field has legal significance (age).
10.3 Right to erasure (Article 17 GDPR), including the in-app path
In the app: Settings → Privacy & Data → “Delete my account”. The process:
- Immediately: your profile leaves discovery, and nobody new can find you.
- 30-day grace period: you can cancel the deletion simply by logging back in. This window exists to protect against hasty or pressured deletions.
- After the grace period, permanent erasure/anonymization: your photos and any residual verification files are deleted from storage; your message content is replaced with “[deleted]”; chat media is deleted; your email, name, bio, orientation data, location and all other identifying fields are erased.
Uninstalling is not deleting. Removing the app from your phone does not delete your account: your profile and server-side data remain, and your profile remains discoverable, until you run the deletion process above (or ask us by email at contact@askedout.com). If you want your data gone, delete the account; deleting the app alone is not enough.
What is retained after deletion, and why: anonymized message/match/report records (safety and legal-claims purposes, no longer linkable to you as a person), referral links between account identifiers, and the consent ledger and audit entries until their retention expires (Section 9). Backups purge on their rotation cycle (Section 9).
You can also request erasure of specific data (rather than the whole account), for example the verification outcome and score (Section 5.2), in-app where a control exists, otherwise by email. Erasure may be refused only on the narrow grounds of Article 17(3) (e.g. legal obligations, legal claims), and we will tell you if so.
10.4 Right to restriction (Article 18 GDPR)
You can require us to freeze (store but not otherwise process) specific data while a dispute about it is resolved, for example while we verify a rectification request or assess your objection. Email contact@askedout.com; we will confirm the restriction and inform you before lifting it.
10.5 Right to data portability (Article 20 GDPR), including the in-app export
In the app: Settings → Privacy & Data → “Export my data”. You receive a machine-readable JSON file, shareable from your device, containing your account, profile, consents, matches, messages, settings and more. Two honest notes: your text messages appear as ciphertext with an explanatory note, because we cannot decrypt them for you (they are readable in your own app, where your keys live); and photo files are not bundled into the JSON but can be requested via contact@askedout.com. Export files are deleted from our storage after 48 hours (Section 9). Portability covers data you provided under contract or consent; where technically feasible you may ask us to transmit it directly to another controller.
10.6 Right to object (Article 21 GDPR)
You can object, on grounds relating to your particular situation, to any processing based on legitimate interests (the rows marked Art. 6(1)(f) in Section 4: safety moderation, security, error logging, legal-claims retention). We will stop unless we demonstrate compelling legitimate grounds overriding your rights, or the processing is needed for legal claims. Since we do no direct marketing based on legitimate interest and no profiling, the absolute objection right for marketing has no application beyond the consent-based emails you can simply switch off (Section 10.7).
10.7 Right to withdraw consent (Article 7(3) GDPR), with per-consent paths
Each consent has its own switch and its own precise consequence:
| Consent | Where to withdraw | Exact consequence |
|---|---|---|
| Location processing | In-app privacy settings | Stored location deleted immediately; location-based discovery pauses until re-consent |
| Special-category (orientation / “interested in”) | In-app privacy settings | Orientation field nulled immediately (free-text field removed); discovery pauses, because matching cannot run without it |
| Face verification (biometric) | In-app privacy settings | No further verification attempts; the selfie was already deleted at decision time; outcome/score erasable on request (Section 5.2) |
| Marketing emails | Unsubscribe link in every email, or via contact@askedout.com (an in-app toggle is planned) | Marketing stops; service emails (OTP, security) continue as they are contractual |
| Terms/Privacy acceptance | Withdrawing acceptance of the Terms means closing the account (Section 10.3) | Account deletion flow |
Withdrawal is always as easy as giving consent, never affects the lawfulness of past processing, and never degrades the parts of the service that do not depend on the withdrawn consent.
10.8 Post-mortem directives (Article 85, Loi Informatique et Libertés)
French law gives you the right to set directives on the fate of your personal data after your death: general directives (registrable with a certified third party) or specific directives given to us. You may tell us at contact@askedout.com what should happen to your AskedOut data after your death and designate a person to execute those directives. Absent directives, your heirs may exercise the limited rights provided by Article 85 (closing the account, opposing further processing).
10.9 Right to complain to the CNIL (Article 77 GDPR)
You can lodge a complaint at any time, without going through us first (though we would appreciate the chance to fix things), with the French supervisory authority:
CNIL, Commission Nationale de l’Informatique et des Libertés 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France www.cnil.fr
If you live in another EU country, you may instead complain to your local supervisory authority.
10.10 How we verify requests
For in-app actions, you are already authenticated, so no further verification is needed. For email requests, we verify that the request comes from the account holder: requests sent from the account’s registered email address are normally sufficient; otherwise we will ask you to confirm control of that mailbox or provide matching account details. We ask for identity documents only as a last resort, where doubt remains and the request is sensitive (Article 12(6) GDPR), and delete them once verification is complete. Requests made on your behalf by an authorised third party must include proof of authority.
10.11 Timelines
We respond to rights requests within one month of receipt (Article 12(3) GDPR). For exceptionally complex or numerous requests the GDPR allows an extension of up to two further months; if we ever need it, we will tell you within the first month and explain why. If we refuse a request (on the narrow grounds the GDPR allows), we will state the reasons and remind you of your right to complain to the CNIL and to seek a judicial remedy.
11. How we protect your data (security)
11.1 Core measures
- TLS encryption for all transport: every connection between the app and our servers, and between our servers and processors.
- argon2 password hashing: the current state-of-the-art memory-hard algorithm; your password is never stored or transmitted in recoverable form.
- Token architecture: short-lived access tokens (about 15 minutes) plus rotating refresh tokens; reuse of a rotated refresh token (the signature of token theft) triggers automatic revocation of all of that account’s sessions. Per-account login lockout and rate limiting resist brute force.
- Encrypted secure storage on your device (iOS Keychain / Android Keystore) for tokens and encryption keys.
- Access-controlled media endpoints: chat media is served only to the two match participants; verification files only to you and vetted staff; uploads are validated and re-encoded.
- Anti-trilateration location design (500 m grid snapping + distance rounding; see Section 3.5).
- On-device processing for face pre-checks, nudity screening and personal-information warnings; this data never reaches our servers.
- Access-logged administration: staff actions on personal data are logged (Section 3.9).
- Our use of encryption has been declared to ANSSI (the French national cybersecurity agency), as French law requires for supply of cryptographic means.
11.2 End-to-end encryption, honestly scoped
E2EE for text messages (X25519 + AES-256-GCM, keys only on devices) means we genuinely cannot read your texts. But we owe you the limits as well as the promise:
- No forward secrecy: the current design does not rotate message keys per message. If your device’s private key is ever compromised, that conversation’s stored history could be exposed. Protect your device (passcode, OS updates).
- Device compromise defeats E2EE: encryption protects data in transit and on our servers, not against malware or a person with access to your unlocked phone.
- Endpoints are people: your match can always screenshot (despite blocking; see Section 11.4), photograph or repeat what you send.
- Media is not E2EE: chat photos and voice messages are protected by access control, not end-to-end encryption (Section 3.7).
- Verify your keys: use the in-app safety-number screen and heed key-change warnings for sensitive conversations.
11.3 What a breach of our servers could and could not expose
Because of the architecture: text message content would remain unreadable (ciphertext only); passwords would remain unrecoverable (argon2); payment card data cannot leak from us because we never hold it. What a server breach could expose is the server-side data described in Section 3 (profiles, photos, metadata, chat media). This is why the measures in 11.1 exist and why we minimise what we store at all.
11.4 Screenshot blocking, on a best-effort basis
The app blocks screenshots and screen recording app-wide, but this is best-effort and operating-system-dependent: OS mechanisms differ, and no app can prevent, for example, photographing the screen with another device. Do not treat screenshot blocking as a guarantee.
11.5 If a breach happens
No system is perfectly secure. If a personal data breach occurs, we will assess it immediately, notify the CNIL within 72 hours where required (Article 33 GDPR), and notify you directly without undue delay if the breach is likely to result in a high risk to your rights and freedoms (Article 34 GDPR), telling you what happened, what data is affected and what you should do.
12. Guests: browsing without an account
You can browse nearby profiles without creating an account. The processing is deliberately minimal:
- You choose who you want to see (genders), an age range and a distance. With your OS-level permission, your device location is used only as a query parameter to fetch nearby profiles; it is not stored by us. If you deny location access, the app browses a default city area instead.
- No guest profile is created and no persistent guest identifier is assigned. No account data is stored server-side for guests beyond serving the query.
- Guests see only approved photos and public profile fields of active members, and are never shown distances to any member.
- Standard security-level technical logs (IP-level request logs, rate limiting) apply, on the legitimate-interest basis in Section 4 (row 8), with the short technical retention in Section 9.
If you are a member: your approved photos and public profile fields are visible to guests browsing near your area, unless you pause discovery in Settings. Guests can never see your distance, contact you, or access anything beyond the public profile.
13. Non-users and reporters (Digital Services Act)
Anyone, including people without an AskedOut account, can notify us of illegal content or policy violations at contact@askedout.com, our single point of contact under Articles 11 and 12 of the Digital Services Act (Regulation (EU) 2022/2065) for authorities, members and non-members alike. Communications are accepted in French and English. Members can also report in-app (profile reporting and per-message reporting).
If you submit a notice as a non-user, we process your contact details and the content of your notice to handle it, inform you of the outcome where the DSA requires, and defend against abusive notices, on the legal-obligation and legitimate-interest bases in Section 4. We do not reveal a reporter’s identity to the person reported. Notice-handling records follow the report-evidence retention in Section 9 (maximum 180 days after resolution, 365-day cap). If a member’s report or export mentions you as a non-user, we process that incidental data only for the safety purposes described, with the same retention. The mechanics of notice handling, statements of reasons and appeals are described in the Terms of Service.
14. Minors
AskedOut is exclusively for people aged 18 or over. Our layered enforcement:
- The sign-up flow makes it impossible to enter a date of birth under 18, and the limit is enforced server-side: a modified client cannot bypass it.
- “Underage user” is a dedicated report reason handled with priority and escalated for expedited review. Confirmed underage accounts are removed.
- Where legally required, underage cases are reported to the competent authorities.
- We do not knowingly process the data of minors. If, despite these measures, a minor’s data has been collected, we delete it as soon as we become aware.
If you believe a minor is using AskedOut, report the profile in-app or write to contact@askedout.com: these reports are treated with the highest priority.
15. Push notifications, communications and your device
15.1 Push notifications
- Notifications are delivered via Apple APNs directly (relayed through AWS SNS). There is no Firebase and no third-party push SDK.
- We send notifications for new matches, new messages and events. Each type has its own toggle in-app, and the OS-level permission is requested only after your first match: when a notification first becomes useful, not at first launch.
- Notification payloads never contain message content. Because your messages are end-to-end encrypted, our server cannot include their text even in principle; a new-message push carries only server-authored generic text such as “New message”.
- You can silence everything at any time via the in-app toggles or the OS notification settings.
15.2 Emails
Service emails (verification codes, security notices, deletion confirmations) are part of operating your account and cannot be opted out of while the account exists. Marketing emails are sent only with your opt-in consent and always contain an unsubscribe link (Section 10.7). Bounce and spam-complaint suppression is described in Section 3.9.
15.3 What the app stores on your device (ePrivacy / Article 82, Loi Informatique et Libertés)
The app stores on your device only what the service strictly requires: your login tokens and end-to-end encryption keys (in the operating system’s secure keychain), a few one-off flags (onboarding completed, push permission asked, review prompt shown), and image/audio caches so content doesn’t re-download. All of this is exempt from the consent requirement of Article 82 of the Loi Informatique et Libertés as strictly necessary for the service you request. No advertising identifiers are read, and no cross-site or cross-app tracking storage is used. The informational website at askedout.com sets no tracking cookies.
16. Changes to this policy
We may update this policy, for example for new features, legal developments or changes in providers. How changes work:
- Every version is numbered and dated; the current version is always available in-app and at askedout.com.
- Material changes trigger the in-app re-consent flow: the new version is published in-app and you are asked to review and re-accept it before continuing to use the service. Your re-acceptance is recorded in the consent ledger with the exact version (Section 3.10).
- Where a change involves a new consent-based processing (for example, a new special-category use), continuing under the old consent is never assumed; we ask for the new consent separately.
- Prior versions are archived and available on request at contact@askedout.com.
- We will never degrade your rights retroactively: processing already carried out remains governed by the version in force at the time.
17. Contact and complaints
All privacy matters, data subject requests, support, abuse reports and DSA notices: contact@askedout.com (French and English)
Postal address: Rohit Yasashwi Bonthalakoti, 29 Rue des Faillettes, 95120 Paris, France
Supervisory authority (complaints): CNIL, Commission Nationale de l’Informatique et des Libertés 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France (www.cnil.fr)
We answer rights requests within one month (Section 10.11). If you are unhappy with our answer, Section 10.9 explains the complaint route, and nothing in this policy limits any right you have under the GDPR or French law.
AskedOut Privacy Policy v3.0, effective 25 July 2026. This English version is provided for convenience; once the French version is published, the French version is the operative version for users in France.