Privacy Policy
Effective date: July 27, 2026
Dateagent ("Dateagent," "we," "us") is a date-planning and invitation service operated from the United States. This Privacy Policy explains what personal information we collect, how we use and share it, and the choices and rights you have.
This policy covers: the Dateagent iOS app, the Dateagent App Clip, the Dateagent iMessage extension, our websites (dateagent.com and dateagent.app, including invitation pages and the waitlist), and Apple Wallet passes created with Dateagent (together, the "Service").
Who this policy is written for:
- Hosts — people with a Dateagent account who plan dates and send invitations.
- Guests — people who receive an invitation and view or respond to it, usually without creating an account. If you're a Guest, Section 4 and our short Guest Privacy Notice are written for you.
- Contacts — people a Host adds to their private contact list. If someone has added information about you, Section 4 explains your options.
The short version:
- We collect what you give us (profile, date plans, contacts, feedback) plus limited technical data. We don't buy data about you, and we don't use data brokers.
- We do not sell your personal information, and we do not share it for advertising. There are no ads in Dateagent. We have never sold or shared personal information as those terms are defined in California law.
- Who you date and how it's going is nobody's business but yours. Your contacts' details, notes, date history, and feedback are private to your account — never visible to other users or Guests, and never used to build profiles of the people you date. (Photos you upload, including contact photos, pass an automated safety screen before storage — see Section 5.)
- Dateagent doesn't publish anything. There is no feed, no search, and no browsing of profiles. Your profile and date ideas are visible only to the people you share an invitation or your datemenu link with — and you can deactivate links or hide your datemenu at any time.
- You can delete your account — and the data that goes with it — inside the app, any time.
- Before content you've chosen to share (photos, profile text, date ideas) becomes visible to your Guests, an AI model run by Anthropic screens it for prohibited material. Nothing you write privately is sent. Section 5 explains exactly what is screened.
1. Information You Provide to Us
In short: your account and profile, your date plans and availability, the contacts you add, your RSVPs and feedback, and messages you send us.
Account and profile. When you sign up we collect your phone number (used for sign-in codes) and the profile you build: name, username, profile photo, short bio lines, and any social links you add. You may optionally add an email address.
Date plans. Date options you create (venue names, addresses, photos, descriptions, hours, cost notes, time slots), your weekly availability, invitations and invite links you create, and dates you schedule.
Contacts you add. You can add people to your private contact list — manually or by importing from your phone's contacts (with your permission, and only the contacts you select). A contact entry can include name, photo, phone number, email, social handles, and details you choose to record such as birthday, job, school, interests, and free-text notes, plus your date history with them. This is information about other people; Section 4 covers how we handle it and your responsibilities.
Your private date feedback. After a date you can privately record ratings and notes (for example, how it went, whether you'd do it again, and an optional safety rating and safety comments). This feedback is for you — it is not shown to your date or to other users.
Guest RSVP information (if you respond to an invitation as a Guest): the name on the RSVP and the date options and times you pick, plus — optionally — a phone number or email so your Host can reach you, an Instagram handle, and a short message. If you respond to a personal invitation addressed to you (rather than a public datecard page), we collect only your time picks and optional message. If you provide a phone number and tick the "text me" box, we send you a confirmation text about that RSVP (see Section 3).
Waitlist and support. If you join our web waitlist we collect your email address. If you contact support we receive your message and email address.
What we do NOT collect. We do not collect financial or payment information (Dateagent is free), government IDs, precise background/identity-verification data, health records, or biometric identifiers. Face ID / Touch ID unlock happens entirely on your device through Apple's APIs — we never receive your biometric data. We do not use advertising identifiers (IDFA) or any cross-app tracking, and we do not purchase data about you from data brokers.
2. Information Collected Automatically
In short: device basics, first-party usage analytics, crash reports, push tokens, and limited IP-address use for security. No ad tracking of any kind.
- Device and app information: device model, OS version, app version, and language/timezone settings.
- Websites: our web pages run no analytics scripts and set no cookies — visibility into web traffic comes from hosting-provider server logs only (see the Website Notice).
- Usage analytics (first-party): screens viewed, buttons tapped, feature usage, and session length, tied to your account so the app can show you your own stats (e.g., your response rates). We use our own analytics system on our own backend — no third-party advertising or marketing analytics SDKs.
- Crash and performance data: if the app crashes or errors, a report (stack trace, device context, and recent in-app activity) is sent to our crash-reporting provider (Sentry) so we can investigate and fix the problem. We don't attach your name, phone number, or profile to crash reports.
- Push notification tokens: if you enable notifications, we store your device push token and device name to deliver them.
- IP addresses, used narrowly: (a) transiently, to rate-limit our public endpoints and prevent abuse; (b) when anyone submits an abuse report, we log the reporting device's IP address to prevent misuse of the reporting system; and (c) when a Guest views an invitation page, we record a one-way hashed (pseudonymized) form of their IP address to count unique views — we do not store Guest viewing IPs in readable form.
- Invitation activity: when your invitation is viewed or responded to, we record that event (and show it to the Host who sent it).
Location. If you grant location permission, we read your device's approximate location in the foreground only to show weather forecasts for your planned dates. Coordinates are sent to our weather provider (Open-Meteo) without any account identifier attached. We do not track your location in the background, do not keep a history of your movements, and the feature works (with a default city) if you decline.
Cookies. Our iOS app does not use cookies. Our websites currently set no cookies and run no analytics scripts; see the Website Notice.
3. How We Use Information
In short: to run Dateagent, deliver your invitations and notifications, keep the Service safe, and improve it. Never for ads.
We use personal information to:
- Provide the Service — create your account, sync your data across your devices, display your datemenu and invitation pages to the Guests you share them with, record RSVPs, and sync dates to your calendar when you turn that on.
- Send messages you initiate or sign up for — sign-in code texts; and, only if a Guest ticks the "text me" box on the RSVP form, an RSVP confirmation text and one feedback follow-up to that Guest; plus push notifications you enable (such as new-RSVP alerts). Message frequency varies; message and data rates may apply; Guests and Hosts can reply STOP to opt out of texts or HELP for help. We do not send marketing texts, and we never text a number that was not opted in on an RSVP.
- Power optional features you choose to use — weather forecasts (location), calendar sync (calendar access), contact import (contacts access), and Apple Wallet passes.
- Keep the Service safe — screen shareable content before Guests can see it (Section 5), investigate abuse reports, act on blocks, rate-limit endpoints, secure accounts, and debug crashes.
- Understand and improve the Service — first-party analytics about how features are used.
- Comply with law — respond to lawful requests and enforce our Terms of Service.
We do not use your information for third-party advertising, and we do not train AI models on your data (see Section 5).
4. Data About People You Add (Contacts and Guests)
In short: your contacts and your Guests' RSVPs are information about people who may not have Dateagent accounts. We keep it private to you, we don't pool it, and non-users can contact us to access or delete it.
Dateagent is built around planning dates with real people, so Hosts necessarily record information about others — contact entries, invitation recipients, and Guests' RSVPs.
Our commitments for this data:
- Private to your account. Contact entries, notes, date history, and feedback are visible only to the Host who created them (enforced by row-level security on our database). We do not cross-link this information between accounts, aggregate it across Hosts, or use one Host's data about a person to populate anyone else's account. No "profile" of a Guest or Contact is assembled across users.
- Used only to provide the Service to you. We don't use contact or Guest data for marketing, enrichment, advertising, or model training.
- Contact photos are safety-screened, not analyzed. A photo you attach to a contact passes through the same automated content screening as your own profile photo (Section 5) before it is stored. The screening checks what the photo depicts; it does not identify the person, and no facial-recognition template or biometric identifier is created or stored. Contact names, phone numbers, and notes are never sent.
- Guests see a notice. Invitation and RSVP pages link to our Guest Privacy Notice describing what is collected when they view or respond.
- Deleted with your account — when a Host deletes their account, their contacts, invitations, Guest RSVPs, and related records are deleted (Section 7).
Host responsibilities. You should only add information about people you actually know, and only what's appropriate. Under our Terms of Service you confirm you have a lawful basis to provide another person's contact details and you agree not to use Dateagent to collect information about people who have asked you to stop, or to harass anyone.
If you're not a Dateagent user and believe a Host has stored your information: email [email protected]. Two situations, handled differently:
- Information you submitted yourself (such as a Guest RSVP): we will verify your request — normally by confirming control of the contact channel you used on the RSVP — and then locate and delete it, or provide you a copy, as applicable law requires.
- A Host's private contact entries and notes about you: we act as a provider of private storage to that Host. We do not access, search, or disclose those records except as described in Section 6 (legal and safety) — and they are deleted when the Host deletes their account. Where a privacy law gives you rights against us for this data, we will honor a verified request to the extent the law requires.
5. AI Content Screening
In short: before content you've chosen to share becomes visible to your Guests, an AI model checks it for prohibited material. That is the only thing we use AI for — there is no AI matchmaking, ranking, or messaging, and nothing you write privately is sent.
Dateagent doesn't publish your content anywhere on its own. There is no feed, no search, and no directory — your profile and date ideas become visible only through invitations you choose to share (links, QR codes, Wallet passes) or your datemenu page, which you can hide in Settings. But the people you share with can view those pages without accounts, so we screen shareable content before it becomes visible to them. When you upload a profile photo or a contact photo, or save your shareable profile (name, username, bio, social handles) or a date idea (title, venue, address, hours, wardrobe, cost, description), that content is sent to Anthropic, whose Claude model checks it against our Community Guidelines and returns an allow-or-block result.
- Screening is limited to content your Guests could see, plus uploaded photos. Private notes, date history, date feedback, contact names and phone numbers, and Guests' RSVPs are never sent to Anthropic. (Guest RSVP text is checked by a simple word filter on our own servers instead.)
- If a photo is blocked, we don't store it. If text is blocked, the save is rejected with a short explanation so you can edit and try again.
- The screening classifies content; it does not identify people, and no facial-recognition template or biometric identifier is created or stored.
- Under Anthropic's commercial API terms, screened content is not used to train Anthropic's models, and Anthropic retains API inputs only per those terms.
- Screening is a safety requirement of operating the Service and cannot be turned off; your control is choosing what you upload.
- Automated screening can be wrong. If something of yours was blocked and you believe it shouldn't have been, email [email protected] and a human will review it.
See the AI Transparency Notice for more detail.
6. How We Share Information
In short: with the people you choose to share with, with the service providers that run Dateagent, and when the law requires. Never sold, never shared for ads.
At your direction — and only at your direction. Dateagent never publishes your information on its own. When you share an invitation link, QR code, Wallet pass, or your datemenu link, the people you share with see what's on it (your name, photo, bio, date options, and available times). You control this: you can deactivate invite links and hide your datemenu in Settings. A Guest's RSVP is shared with the Host who invited them.
Service providers. We use a small set of providers to run Dateagent. Contracted providers process personal data on our behalf, only to deliver their function. Two recipients receive limited data without acting as contracted processors: Open-Meteo (a public weather API that receives only identifier-free coordinates) and Apple (operating-system services such as push delivery and Wallet, under Apple's own terms). Full, current list and details: Sub-processor List.
| Provider | Purpose | Personal data involved |
|---|---|---|
| Supabase | Backend: database, authentication, file storage, server functions | Account, profile, contacts, dates, invitations, RSVPs, feedback, analytics |
| Twilio | Sign-in code and RSVP-confirmation texts | Phone numbers, text message content |
| Sentry | Crash and error reporting | Crash/diagnostic data |
| Anthropic | AI safety screening of shareable content (Section 5) | Profile and contact photos; profile and date-idea text you share |
| Resend | Operational email (report and waitlist-signup notifications to our team) | Email addresses, report details |
| Expo | Push-notification delivery; app updates | Push tokens, device name |
| Upstash | Rate limiting on web endpoints | IP address (transient) |
| Open-Meteo | Weather forecasts | Approximate coordinates (no identifier) |
| Vercel | dateagent.app hosting (invitation pages, functions) | IP address, browser info (server logs) |
| Cloudflare + Opalstack | dateagent.com delivery and hosting; support mailboxes | IP address, server logs; support email content |
| Apple | Push notifications (APNs), Wallet passes, App Clip | Push payloads; pass contents you create |
Legal and safety. We may disclose information if we believe in good faith it's required by law (subpoena, court order, or other lawful process) or necessary to prevent serious harm, investigate fraud or abuse, or protect the rights and safety of users, Guests, the public, or Dateagent. Our Law Enforcement Guidelines describe how we handle government requests.
Business transfers. If Dateagent is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction. We will notify you (for example, in-app or by text/email) of any transaction that changes who is responsible for your information or materially changes this policy.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We have not done either in the preceding 12 months, and we won't without first updating this policy and obtaining any required consent.
7. Data Retention and Deletion
In short: we keep your data while your account is active. Delete your account in the app and it's deleted from our systems, with a short backup tail.
| Data | Retention |
|---|---|
| Account, profile, contacts, dates, invitations, RSVPs, feedback, analytics, push tokens | Until you delete your account |
| Account deletion | Available in Settings — delete your account any time. Deletion runs server-side and removes your records across our database tables, your uploaded profile photos, and your login credentials. |
| Residual backup copies | Encrypted database backups expire automatically on a short rolling cycle after deletion; backups are not kept indefinitely. |
| Guest RSVP data | Kept while the Host's account is active (it's part of the Host's records); deleted when the Host deletes their account. Guests may also request deletion (Section 4). |
| Content submitted for AI screening (Section 5) | Approved content is stored as ordinary app content; blocked photos are never stored; Anthropic's transient processing is governed by its API terms |
| On-device analytics | Pruned after ~7 days on your device |
| Abuse/moderation reports | May be retained after account deletion where needed for safety, security, or legal compliance |
| Waitlist emails | Until launch communications conclude or you ask us to remove you |
| Rate-limiting records | Minutes to hours (transient) |
8. Your Rights and Choices
In short: access, correct, or delete your data; control permissions; state-law rights honored for everyone.
In-app controls. Edit your profile any time; delete your account in Settings; toggle notifications; deactivate invite links and hide your datemenu; and grant or revoke Contacts, Calendar, Location, and Photos permissions in iOS Settings at any time.
US state privacy rights. If you live in California, Colorado, Connecticut, Texas, Virginia, Utah, or another state with a comprehensive privacy law, you have rights to: know/access the personal information we hold about you; receive a portable copy; correct inaccurate information; delete your information; and opt out of "sales," "sharing"/targeted advertising, and certain profiling. Dateagent does not sell or share personal information or engage in profiling that produces legal or similarly significant effects, so there is nothing for an opt-out to switch off; if that ever changes, we will treat Global Privacy Control signals as valid opt-out requests.
Sensitive information. Some of what you store in Dateagent is sensitive by nature — your private notes and date feedback can concern your personal and romantic life. We collect it only because you enter it, and we use it solely to provide the features you ask for — never to infer characteristics about you for advertising, and never for sale or sharing. Because we use it only for these requested-service purposes (CPRA regs §7027(m)), a separate "Right to Limit" control is not required; if our uses ever change, we will provide one.
- How to exercise rights: in-app (deletion, correction) or by emailing [email protected] with the subject "Privacy Request." We will verify your request (usually by confirming control of the phone number or email on the account) and respond within 45 days, extendable once by 45 days where permitted.
- Authorized agents may submit requests on your behalf with proof of authorization; we may still verify directly with you.
- Appeals: if we decline a request, you may appeal by replying "Appeal" within 30 days; we'll respond within the period your state's law requires. If your appeal is denied you may contact your state Attorney General.
- Non-discrimination: we will never deny service, charge different prices, or degrade the Service because you exercised privacy rights.
- California "Shine the Light" (Civ. Code §1798.83): we do not disclose personal information to third parties for their direct marketing, so no such list exists to request.
Notice at Collection and categories disclosure (CCPA). This section, together with Sections 1–3 and 7, serves as our Notice at Collection. In the last 12 months we collected these categories: identifiers (name, phone, email, username, account/device IDs, IP addresses); user content (profile, date plans, contacts you add, notes, feedback, RSVPs); sensitive personal information (the contents of your private notes and feedback, which may concern your personal or romantic life — used only as described above); characteristics of protected classifications only insofar as content you enter contains them (for example, a contact's birthday); approximate geolocation (weather feature only); internet activity (first-party app usage, invitation views); and audio/visual (photos you upload). We do not collect or generate inferences about you. Sources: you, your device (with permission), and Guests who respond to your invitations. Business purposes: providing the Service and its requested features, security and debugging, and legal compliance (Section 3). Each category is disclosed only to the Section 6 service providers needed to deliver its function, and retained as described in Section 7. Sold or shared: none.
9. Security
We use industry-standard safeguards: encryption in transit (TLS) and at rest, row-level security policies that isolate each account's data, authentication tokens and sensitive account fields stored in the device Keychain, IP hashing for Guest view counting, and rate limiting on public endpoints. No system is 100% secure, and we can't guarantee against every unauthorized access — but if a breach affects your personal information, we will notify you and regulators as required by applicable law.
10. Children
Dateagent is for adults. You must be 18 or older to use the Service, and it is not directed to anyone under 18. We do not knowingly collect personal information from anyone under 18; if we learn we have, we will delete it and terminate the account. Contact [email protected] if you believe someone under 18 has provided us information.
11. Users Outside the United States
The Service is operated from the United States and is currently offered to users in the United States. If you access it from elsewhere, you understand your information will be processed and stored in the U.S.
12. Changes to This Policy
We'll update this policy as the Service evolves. For material changes we will notify you in the app (and by text or email where appropriate) before the change takes effect, and update the date at the top. If a change materially expands how we use previously collected personal information, we will obtain any consent required by law rather than relying on continued use alone.
13. Contact Us
Email: [email protected] (subject "Privacy")
We aim to acknowledge privacy inquiries promptly and to resolve them within the timelines described in Section 8.