Privacy Policy
Version 1.0 Β· Last updated 2026-08-04
Privacy Policy
iDeal DP β operated by Dynamic Dating Group, Inc.
Version 1.0 β Effective August 4, 2026
This American English version is the reference version. Translations are provided for convenience; in the event of any discrepancy, this version controls.
At a Glance
This summary does not replace the full policy, but covers the essentials.
| We cannot read your messages. | Messaging and calls are end-to-end encrypted. We relay encrypted data and do not hold the keys. |
| Your history lives on your device. | Messages and their media pass through our servers for no more than 30 days, only for delivery. |
| Your data is hosted in Europe. | Our application and storage servers are located in Germany (IONOS SE, Hetzner Online GmbH) and our transactional email in Switzerland (Infomaniak). |
| We do not sell your data. | We do not sell or "share" personal information as those terms are defined by the CCPA/CPRA, and we do not run behavioral advertising. |
| Biometrics are optional. | Identity Certification requires your separate, explicit consent. You may decline. |
| Location is optional. | All GPS features are opt-in; your profile location is intentionally approximate, about 5 km (3 miles). |
| You stay in control. | Access, correction, deletion, objection, portability, withdrawal of consent: see Section 12. |
1. Who Is Responsible for Your Data
iDeal DP is not a company. iDeal DP is a brand and service owned and operated exclusively by Dynamic Dating Group, Inc., the sole controller of your data (a "controller" under the GDPR, a "business" under the CCPA). The company maintains its sole corporate headquarters in the United States of America.
| Legal name | Dynamic Dating Group, Inc. |
| Entity type | Corporation organized under the laws of the State of Delaware, United States |
| Registered address | 1111B S Governors Ave #3153, Dover, Delaware 19904, United States |
| Delaware File Number | 36-5097806 |
| EIN | 36-5097806 |
| Telephone | +1 415 417-0755 |
| Privacy email | privacy@idealdp.com |
| Legal email | legal-eu@idealdp.com |
| General contact | contact-us@idealdp.com |
Representative in the European Union (Article 27 GDPR and Article 13 DSA): Inga Metra β Latvia β β contact-us@idealdp.com β +48 732 736 288
Any data subject and any supervisory authority may contact the representative, in addition to or instead of the company.
2. Scope
This policy covers the iDeal DP mobile app (iOS, Android), the web application (app.idealdp.com), the public website (idealdp.com), our APIs, our transactional communications, and our internal administration console.
It does not cover third-party services you access (Apple, Google, Stripe, carriers, linked sites), which are governed by their own policies.
3. What We Cannot See
By technical design:
- The content of your messages and calls is end-to-end encrypted (X25519/ECDH + AES-256-GCM; DTLS-SRTP for calls). We carry encrypted blobs that we cannot decrypt.
- Your conversation backup is encrypted on your device (AES-256-GCM) before any transmission to Google Drive, iCloud, or a local folder. The key is derived from a 12-word recovery phrase (BIP39) that we do not know and cannot recover.
- Your contact list is read locally so you can invite people you know. It is not uploaded to our servers.
- Message translation and the liveness face detection run on your device.
As a result, we cannot restore lost history, nor produce message content β including in response to a lawful order. We hold only encrypted data and metadata.
4. Data We Process
4.1 Categories
| Category | Data | Source | Sensitivity |
|---|---|---|---|
| Identifiers | Email address, phone number (hashed, never stored in the clear), password (bcrypt hash), date of birth, display name | You | Standard |
| Profile | Photos (up to 12), bio, gender, sought orientation, intentions, interests, languages, occupation, height, weight, religion, smoking, children, relationship goal | You | Sensitive (religion, orientation, data revealing health) |
| Biometrics and identity | Liveness selfies, government ID (optional), 512-dimension facial templates used to detect duplicate accounts | You | Sensitive (Article 9 GDPR; "biometric identifier" under BIPA and CUBI) |
| Location | Approximate profile location (about 5 km), precise location for Safe Date, emergency alerts, and Crossings, sign-in and registration country | Device (opt-in) | Sensitive (precise geolocation, CPRA) |
| Communications | Encrypted message and media content (unreadable by us), conversation metadata (participants, timestamps), call metadata (duration, type, quality) | Service | Standard |
| Social interactions | Swipes, matches, likes received, follows, community memberships, RSVPs, outing participation, comments, hashtags | Service | Standard |
| Profiling and AI | Profile embeddings, Smart Search history and feedback, compatibility scores, quality and reputation signals | Service | Standard |
| Published content | Reels, stories, posts, comments, polls, events, outings, uploaded music and credits | You | Standard |
| Subscription and payment | Plan, status, cycle, opaque references to Stripe, Apple, Google, billing history. We store no payment card data | You and providers | Standard |
| Devices and technical | Device identifier, platform, app version, push token, public encryption keys, last activity, IP address, technical logs | Device | Standard |
| Safety and moderation | Reports sent and received, attached evidence, automated analyses, moderation decisions, appeals, block list, blocked name-search attempts, audit logs | You, third parties, Service | Standard to sensitive depending on content |
| Third-party contacts | Safe Date trusted contacts (name and phone number), provided by you | You | Third-party data |
| Support | Exchanges with support, complaints, rights requests | You | Standard |
4.2 What We Do Not Collect
We do not collect payment card data, the plaintext of your messages, your address book, advertising identifiers for third-party targeting, or data from data brokers.
4.3 Data About Third Parties
When you save a Safe Date trusted contact, you provide us a third party's name and phone number. You must inform them and confirm their agreement. That person may request deletion of their data at privacy@idealdp.com.
5. Purposes and Legal Bases
| Purpose | Data | Legal basis |
|---|---|---|
| Create and manage your account, authenticate you | Identifiers, devices | Performance of contract |
| Verify that you are an adult | Date of birth, Certification | Legal obligation and legitimate interest (child protection) |
| Display your profile and enable discovery | Profile, approximate location, interactions | Performance of contract |
| Compute compatibility and rank results | Profile, embeddings, search history | Performance of contract; legitimate interest for improvement (right to object, Section 12) |
| Deliver messages, media, and calls | Metadata, encrypted blobs | Performance of contract |
| Translate messages (server fallback) | The text concerned, occasionally | Consent |
| Certify your identity | Selfies, ID, facial templates | Explicit consent (Article 9(2)(a) GDPR; written release under BIPA) and legitimate interest in fraud prevention |
| Prevent fraud, fake accounts, and duplicates | Facial templates, hashed phone, logs, devices | Legitimate interest (service security) |
| Moderate, handle reports and appeals | Reports, evidence, decisions | Legal obligation (DSA) and legitimate interest |
| Safe Date features and emergency alerts | Precise location, trusted contacts | Consent; vital interests where applicable |
| Proximity Crossings | Location pings | Consent |
| Push notifications | Device token | Performance of contract or consent depending on platform |
| Coach Connect and proactive coaching | Profile excerpts, queries | Performance of contract; consent for proactive coaching |
| Process payments and subscriptions | Subscription data, opaque references | Performance of contract and legal obligation (accounting) |
| Transactional communications | Email, phone | Performance of contract |
| Marketing communications | Consent (opt-in; withdrawable at any time) | |
| Information security, logging, audit | Technical data, audit logs | Legitimate interest |
| Establish, exercise, or defend legal claims | As relevant to the matter | Legitimate interest and legal obligation |
| Analytics and product improvement | Aggregated or pseudonymized data | Legitimate interest |
Withdrawing consent. Where processing relies on your consent, you may withdraw it at any time, without retroactive effect, from the app settings or by writing to us.
6. Sensitive Data β Specific Commitments
6.1 Biometric data
What we process. Liveness selfies and digital facial templates (512-dimension vectors), used solely to: confirm that the person present is live and matches the document provided, and detect the creation of multiple accounts by the same person.
What we do not do. We do not sell, lease, trade, or otherwise profit from any biometric data. We do not use it for advertising, for facial recognition in public spaces, or to identify people outside the Service.
Consent. Biometric processing occurs only after explicit, separate, written consent, obtained on a dedicated screen before capture, with information on the purpose, retention period, and destruction method.
Retention and destruction schedule (published in accordance with the Illinois Biometric Information Privacy Act, the Texas Capture or Use of Biometric Identifier Act, and Chapter 19.375 RCW of the State of Washington):
| Data | Retention |
|---|---|
| Liveness selfies | Destroyed within 30 days of the certification decision |
| Government ID | Destroyed within 90 days of the decision, unless a dispute is pending |
| Facial template (512 dimensions) | Destroyed no later than one (1) year after certification expires, and in any event within one year of the date the initial purpose for collection has been satisfied |
| Proof of biometric consent | Duration of processing plus the applicable limitations period |
Biometric consent may be withdrawn at any time; withdrawal triggers destruction within the periods above and loss of certified status.
6.2 Data revealing sexual orientation, religion, or health
The "sought orientation," "intentions," "religion," "smoking," "children," "height," and "weight" fields may reveal sensitive data. These fields are optional and have per-field visibility controls (public, private, or certified members only). Completing them constitutes explicit consent to their publication at the visibility level you choose.
6.3 Precise location
Used only for Safe Date, emergency alerts, and Crossings, always opt-in. Precise coordinates are masked when the sharing session expires (24-hour cap). The public tracking link is token-based and expires automatically.
6.4 Minors
The Service is prohibited to anyone under 18. We do not knowingly collect data from minors. Any account identified as belonging to a minor is deleted and its data erased. Reports: safety@idealdp.com.
7. Artificial Intelligence and Profiling
7.1 Processing involved
| Feature | Data sent to the model | Output |
|---|---|---|
| Smart Search | Your query, criteria, excerpts of candidate profiles | Rephrasing and ranking |
| Bio writing assistance | Profile elements you provide | Suggested text |
| Coach Connect | Your questions, profile context | Guidance |
| Compatibility score | Profile embeddings | Score |
| Preliminary moderation analysis | Reported content and report context | Proposed classification, non-decisional |
Encrypted private messages are never transmitted to an AI provider.
7.2 Providers
We use a multi-provider gateway that may rely on Anthropic, Mistral, and OpenAI, along with self-hosted models (fallback translation, internal facial comparison service). Each provider is bound by a data processing agreement and by a contractual commitment not to use your data to train its models.
7.3 No automated decisions with legal effect
No suspension, ban, or certification denial is issued solely on the basis of automated processing: human review always occurs (Article 22 GDPR). You may obtain human intervention, express your point of view, and contest the decision.
7.4 Recommender system transparency
Profile ranking relies primarily on: your stated criteria, distance, semantic similarity between profiles, activity and mutual interest, and quality and safety signals. The main parameters are disclosed in accordance with Article 27 of the Digital Services Act. You can influence ranking through your filters and preferences.
8. Recipients and Service Providers
We do not sell your data. We disclose it only as follows:
| Recipient | Role | Data shared | Location |
|---|---|---|---|
| IONOS SE β Elgendorfer Str. 57, 56410 Montabaur, Germany (HRB 24498 Montabaur) | Application and database hosting | All server-side data | Germany (EU) β ISO/IEC 27001 |
| Hetzner Online GmbH β Industriestr. 25, 91710 Gunzenhausen, Germany (HRB 6089 Ansbach) | Media object storage | Photos, media, encrypted media | Germany (EU) |
| Infomaniak Network SA, Geneva | Transactional email (one-time codes, notifications) | Email address and message content | Switzerland |
| Stripe | Web payments | Email, amount, customer reference (no card data held by us) | EU and United States |
| Apple (App Store, in-app purchases) | iOS in-app purchases | Purchase receipts, Apple identifiers | EU and United States |
| Google Play Billing | Android in-app purchases | Purchase tokens | EU and United States |
| Google Firebase (FCM) | Push notifications | Device tokens, generic notification payloads (never message text) | EU and United States |
| Anthropic, Mistral, OpenAI | AI features | Profile excerpts, queries, reported content | EU and United States |
| Identity verification provider (where applicable) | External KYC verification | Selfie, government ID | EU |
| Google ML Kit | On-device translation and face detection | Nothing leaves the device | β |
| Google Drive / iCloud | Backup encrypted by you | Unreadable encrypted file | EU and United States |
| Pexels / Pixabay | Stock images, music catalog | No outbound user data | β |
We may also disclose data:
- to judicial or administrative authorities upon a lawfully grounded request; we review each request and, where the law permits, notify you;
- to our advisors, auditors, and insurers, bound by confidentiality;
- in connection with a merger, acquisition, or asset sale, subject to prior notice and continuity of protection;
- where necessary to protect the life or physical safety of a person.
Other Members. Your profile information, published content, reels, stories, posts, comments, and participation are visible according to the visibility settings you choose. What you make public can be copied or captured by third parties; we cannot prevent this.
9. Data Location and International Transfers
9.1 Where your data is hosted
| Processing | Provider | Location |
|---|---|---|
| Application, APIs, databases | IONOS SE | Germany (EU) |
| Media storage | Hetzner Online GmbH | Germany (EU) |
| Transactional email | Infomaniak Network SA | Switzerland |
| Push notifications | Google (Firebase) | EU and United States |
| Payments | Stripe, Apple, Google | EU and United States |
| AI features | Anthropic, Mistral, OpenAI | EU and United States |
The Service's hosting foundation is located in the European Union (Germany) and Switzerland, a country covered by a European Commission adequacy decision. Data of European Members therefore does not leave the European Economic Area for hosting, storage, or backup.
9.2 Access from the United States
Because Dynamic Dating Group, Inc. is established in the United States, its teams access systems hosted in Europe to operate, support, secure, and moderate the Service. That access legally constitutes a transfer under Chapter V of the GDPR.
It is governed by Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), supplemented by a transfer impact assessment and by technical measures: end-to-end encryption of communications, logged and role-limited administrative access, and minimization of the data consulted.
9.3 Other jurisdictions
Swiss Members: Standard Contractual Clauses recognized by the Federal Data Protection and Information Commissioner. Canadian Members: contractual measures consistent with PIPEDA and, in Quebec, Law 25.
A copy of the applicable safeguards is available on request at privacy@idealdp.com.
10. Retention Periods
| Data | Retention |
|---|---|
| Encrypted messages in the server queue | 30 days maximum |
| Encrypted chat media (relay) | 30 days maximum |
| Stories | 24 hours |
| Reels | 7 to 30 days as you choose, or until deleted |
| One-time codes (OTP) | 5 minutes |
| Safe Date sessions | Coordinates masked at expiry; 24-hour cap |
| Account, profile, photos | Duration of the account, then anonymization |
| Certification | 1-year validity |
| Liveness selfies | 30 days after the decision |
| Government IDs | 90 days after the decision |
| Facial templates | 1 year after certification expires |
| Swipes, matches, likes | Rolling 24 months |
| Profile embeddings, Smart Search history | 12 months |
| Call metadata | 12 months |
| Reports, moderation decisions, appeals | 3 years after closure; 5 years for serious matters |
| Administrative audit logs | 12 months |
| Technical and security logs | 12 months |
| Billing records | 10 years (accounting obligations) |
After account deletion: your user record is anonymized (email, phone, and password erased); devices and profile are deleted. Retained, attached to an anonymized record: collective contributions (posts, events created), and safety, moderation, and billing data for the periods above.
11. Security
Technical and organizational measures in place:
- end-to-end encryption of messages, media, and calls;
- encryption in transit (HTTPS/TLS) and at rest; private storage buckets with signed access;
- hashed phone numbers (SHA-256 with pepper), bcrypt passwords, hashed one-time codes (HMAC) with a 5-minute lifetime and a 5-attempt limit;
- short-lived access tokens (15 minutes) and refresh tokens (30 days); role-based access control;
- isolated administration console protected by two-factor authentication and fully logged;
- brute-force protection and payment webhook signature verification;
- encrypted local database on the device; keys in the Keychain or Keystore;
- hosting in European data centers certified to ISO/IEC 27001.
No system is infallible. You contribute to your own security by using a unique password, protecting your device, and keeping your recovery phrase offline.
Vulnerability reports: security@idealdp.com.
12. Your Rights
12.1 European Union, EEA, United Kingdom, and Switzerland
You have the rights of access, rectification, erasure, restriction, objection (including to legitimate-interest processing and profiling), portability, withdrawal of consent, the right not to be subject to a solely automated decision, and the right to give post-mortem instructions (France, Article 85 of the Data Protection Act).
Response time: one (1) month, extendable by two months where the request is complex.
12.2 United States
Depending on your state of residence β California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island, and other states with laws now in effect β you may have the following rights:
- to know and access the categories and specific pieces of personal information collected;
- to correct inaccurate information;
- to delete your information;
- to obtain a portable copy;
- to opt out of sale, of "sharing" for cross-context behavioral advertising, and of profiling producing significant effects;
- to limit the use of sensitive personal information;
- to be free from discrimination for exercising these rights;
- to appeal a denial. In California, you may also complain to the California Privacy Protection Agency or the Attorney General.
Required disclosures (California, CCPA/CPRA): in the preceding 12 months, we have not sold and have not "shared" personal information. Because the Service is limited to persons 18 and over, we do not sell minors' data. We honor universal opt-out signals such as Global Privacy Control.
An authorized agent may act on your behalf upon presentation of a written authorization. We may request proportionate identity verification.
12.3 Canada and Quebec
Rights of access, correction, withdrawal of consent, portability, de-indexing or cessation of dissemination, and information about automated decisions. You may complain to the Office of the Privacy Commissioner of Canada or the Commission d'accès à l'information du Québec.
12.4 Self-service tools
| Action | Where |
|---|---|
| Edit your profile and preferences | Profile β Edit |
| Set per-field visibility | Settings β Privacy |
| Enable or disable location, incognito, AI coaching | Settings |
| Block a Member | Member's profile β Block |
| See what is stored on our servers versus your device | Settings β My Data |
| Delete your account | Settings β Account β Delete |
12.5 How to exercise your rights
Two methods are available:
- in the app: Settings β My Data;
- by email to privacy@idealdp.com, or by mail to the registered address (Section 1).
Members in the European Union may also contact our EU representative (contact-us@idealdp.com) or legal-eu@idealdp.com.
12.6 Complaints
- United States: your state Attorney General; in California, the California Privacy Protection Agency
- European Union: the supervisory authority of your habitual residence
- France: Commission nationale de l'informatique et des libertΓ©s (CNIL)
- Switzerland: Federal Data Protection and Information Commissioner
- United Kingdom: Information Commissioner's Office
- Canada: Office of the Privacy Commissioner; Quebec: Commission d'accès à l'information
13. Cookies
The public website and web application use cookies and similar technologies (local storage, device identifiers). Purposes, durations, and opt-out methods are detailed in our Cookie Policy.
Non-essential cookies are set only after your consent, obtained through a banner that makes refusing as easy as accepting, and withdrawable at any time.
14. Data Breaches
Where a breach is likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours (GDPR) and inform you without undue delay where the risk is high. Notification obligations under U.S. state laws and Canadian laws are applied in parallel.
15. Changes to This Policy
Any material change is notified at least 30 days before it takes effect, by email or in-app notification. Changes expanding the use of sensitive data require fresh consent. Prior versions are archived and available on request.
16. Contact Us
Dynamic Dating Group, Inc. 1111B S Governors Ave #3153, Dover, Delaware 19904, United States β +1 415 417-0755
| Purpose | Contact |
|---|---|
| Privacy and rights requests | privacy@idealdp.com |
| Legal and European Union matters | legal-eu@idealdp.com |
| General contact | contact-us@idealdp.com |
| European Union representative | Inga Metra β Latvia β contact-us@idealdp.com |
| Security and vulnerabilities | security@idealdp.com |
Privacy Policy β version 1.0, effective August 4, 2026. Reference version.