Effective date: August 4, 2026
Last updated: August 4, 2026
Data controller: Passn LLC, 8 The Green, Suite 23215, Dover, DE 19901, United States.
Contact: privacy@passn.app.
1. Summary
Passn is a dating / social-discovery service for adults. To run it we process the information you provide, the photos you upload, your approximate location — including, with your permission, coarse readings taken while the app is closed — and metadata about the messages and calls you exchange with matches. Your exact real-time location is never shown to other users. You can delete your account and the data we hold about you at any time from Settings → Delete account.
This page explains what we collect, why, and how to exercise your rights. If you want to skip to a specific topic:
- Data we collect
- Why we use it
- Who we share it with
- How long we keep it
- Your rights
- How to delete your account
- Children
2. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account identifiers | email, optional phone, Apple/Google subject id | You, your sign-in provider |
| Profile information | display name, date of birth, gender, sexual orientation (interested in), looking-for intent, bio, height, job, education, lifestyle, zodiac, country/city, social handles | You |
| Profile photos | up to 6 images | You |
| Discovery preferences | preferred genders, age range, distance, visibility | You |
| Approximate location | latitude/longitude, indexed into an H3 cell (resolution 9, ~174m edge) for matching | Device GPS, with your permission |
| Encounter records | approximate centre (midpoint of the two people, randomly offset by up to 50m), distance, time when two users crossed paths | Derived server-side |
| Likes / matches | who you liked, mutual matches | You + other users' actions |
| Messages and call metadata | text, image storage keys, voice-note storage keys, message timestamps, read receipts; for calls: caller, callee, type (audio/video), state, duration | You + your conversation peers |
| Subscription information | platform (Apple/Google), product id, transaction id, state, expiry, auto-renew flag | Apple / Google in-app purchase APIs |
| Device & technical data | device model, OS version, app version, push token, language, network type, IP address | Your device |
| Safety & moderation data | reports you filed or received, blocks, moderation case decisions | You + our moderation team |
| Audit log | privileged actions, security-relevant events | System |
We do not record call audio or video; calls are routed peer-to-peer via Agora's real-time infrastructure.
We do not sell personal data and we do not share data with third-party data brokers.
3. Why we use it — lawful basis
| Purpose | Categories used | Lawful basis (GDPR / equivalent) |
|---|---|---|
| Create and operate your account | Account identifiers, profile, device | Performance of contract (Art. 6(1)(b)) |
| Match you with nearby users | Approximate location, encounters, preferences, profile | Performance of contract |
| Enable messaging and calls between matches | Message + call metadata | Performance of contract |
| Keep the service safe (block, report, moderation) | Safety & moderation data, audit log, IP | Legitimate interests (Art. 6(1)(f)) and legal obligation where applicable |
| Verify and grant subscription entitlements | Subscription information | Performance of contract |
| Deliver push notifications | Device id, push token | Consent + performance of contract |
| Comply with law (e.g. CSAM reporting) | Whatever the order requires | Legal obligation (Art. 6(1)(c)) |
Where consent is the lawful basis (e.g. precise location, push notifications), you can withdraw consent at any time from your device settings — withdrawal does not affect the lawfulness of processing performed before withdrawal.
4. Who we share it with
We share personal data with the following categories of recipients, each bound by a written processing agreement and only to the extent needed:
| Recipient | Purpose | Where | Mechanism |
|---|---|---|---|
| Amazon Web Services (AWS) | Application hosting, database, object storage for photos and chat media, and the face-verification check | eu-central-1 (Frankfurt, European Union) | Processor; standard contractual clauses where data leaves the EU |
| Apple App Store & Google Play | Subscription validation | Global | Joint controllers for the purchase, processors for app distribution |
| Agora | Real-time voice/video transport | Global (multi-region edge) | Processor; media not recorded |
| Apple Maps (MapKit) | Rendering the crossing map on your device | Apple infrastructure | Independent controller for map requests; we send no profile data with them |
| Giphy | GIF search inside chat | Global | Processor; searches are not linked to your profile |
| Firebase Cloud Messaging + Apple Push Notification Service | Push delivery | Global | Processor |
| Transactional email provider | Verification, password-reset and notification email | European Union | Processor |
| Crash and error reporting | Diagnostics, when enabled on a build | European Union | Processor |
| Sign-in providers (Apple, Google) | Federated authentication | Global | Independent controller for the auth handshake |
| Law enforcement | Where legally compelled (warrant, court order) | Depends | Legal obligation |
| Acquirers / successors | Corporate transaction | Depends | Notice will be given |
Other users see only the information you choose to make visible: your display name, photos, profile fields, and shared messages within an active match. They never see your email, phone, or exact location.
5. Retention
| Data | Default retention | Notes |
|---|---|---|
users (account row) | Lifetime of the account, then 30 days post-deletion | After deletion grace period the row is hard-deleted; cascades remove dependents |
profile_photos | Until you delete them or your account | Object storage purged on delete |
location_points (raw GPS) | 72 hours | Hourly BullMQ retention job |
encounters (approximate centres) | 90 days | Daily BullMQ retention job |
chat_messages | Lifetime of the match (or until you delete) | Soft-delete; hard delete 30d after account deletion |
calls (metadata only) | 12 months | Retained for safety/abuse investigations |
audit_logs | 365 days | Append-only; admin-only access |
subscriptions + purchase_receipts | 7 years | Required for tax/financial audit |
legal_acceptances | Lifetime of the account, then 7 years | Proof of consent |
reports + moderation_cases | Lifetime of the account, then 2 years | Recurrence prevention |
| Banned-account PII | Hashed and minimised after 30 days | Identifiers retained to prevent re-registration |
6. Your rights
Depending on where you live you have the following rights regarding your personal data:
- Access: receive a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure: ask us to delete your account and the associated data.
- Restriction: ask us to limit processing in specific cases.
- Portability: receive your data in a machine-readable format.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: for any processing where consent is the basis.
- Lodge a complaint with your supervisory authority.
To exercise any of these rights, email privacy@passn.app. We respond within one month (or sooner where required by law); we may extend by two further months for complex requests.
7. Account deletion
From the app: Settings → Delete account. The deletion is scheduled 14 days in the future ("grace period"). During grace you can cancel by signing in. After grace, the account is hard-deleted and dependent records are removed via cascade. Some data is retained for the periods listed in Section 5 when required by law or for safety or financial reasons.
8. Children
Passn is 18+ only. We do not knowingly collect personal data from children. We enforce this through a registration age gate, a database CHECK constraint, and a moderation queue that escalates suspected minors to suspension and, where applicable, NCMEC/local authorities. If you believe a child is using the Service, email abuse@passn.app.
9. International transfers
Personal data may be transferred to and processed in countries other than the one you live in. Where required, we use Standard Contractual Clauses (SCCs), adequacy decisions, or other approved safeguards. You can request a copy of the relevant transfer mechanism.
10. Security
Industry-standard controls protect your data:
- Encryption in transit: HTTPS / WSS only; TLS 1.2+.
- Encryption at rest: managed-storage default-encryption.
- Tokens: Argon2id-hashed passwords; JWT access tokens (15 min); rotating refresh tokens with reuse detection.
- Secrets: loaded from environment, never logged.
- Audit: every privileged action recorded in
audit_logs. - Moderation: photo review queue; report flow; ban/suspend.
No system is perfectly secure. If you suspect your account has been compromised, contact security@passn.app.
11. Cookies and SDK technologies
The mobile app uses persistent local storage (Keychain / encrypted shared preferences) for session tokens and a Hive KV store for non-sensitive preferences. No third-party advertising SDKs are embedded. Third-party SDKs in use are listed in docs/compliance/google-play-data-safety.md.
12. Changes to this policy
We may update this policy. Material changes will be announced in-app and via email at least 14 days before they take effect.
13. Contact
- General privacy questions: privacy@passn.app
- Safety reports: abuse@passn.app
- Security disclosures: security@passn.app
- Postal address: 8 The Green, Suite 23215, Dover, DE 19901, United States
Privacy Policy · Passn LLC, 8 The Green, Suite 23215, Dover, DE 19901, United States · legal@passn.app