Privacy Policy

Effective: May 24, 2026 · Version 1.0

This privacy policy describes how Verified Only ("we", "our", or "the app") collects, uses, and protects your personal information. By using this app you agree to the practices described here.

1. Account & Profile Data

When you create an account we collect: your email address, display name, and any profile content you provide (bio, photos, interests, location, age).

Profile data you submit — including photos, bio, and preferences — is stored on our servers and may be shown to other verified members of the platform.

You can edit or delete most profile data at any time from your settings.

2. Verification Data (Selfies, Videos, Biometric)

To verify your identity, you may be asked to submit a live selfie and/or a short video. This data is used solely to confirm that you are a real person and that submitted photos match your appearance.

Facial verification data: Your selfie and liveness check data may be processed using facial recognition technology (including AWS Rekognition) to compare faces. This is used for fraud prevention and identity verification only.

Verification media (selfies, videos) is stored securely and is not sold, shared with advertisers, or used for any purpose other than verification and fraud prevention.

You provide explicit consent to biometric data collection and processing during onboarding, before identity verification begins. Users who completed onboarding before this consolidated consent flow may be asked to consent again at the start of verification. You may request deletion of your verification data by contacting us (see Section 12).

Biometric Consent: By submitting verification photos or videos, you expressly consent to the collection and processing of biometric identifiers. These identifiers are retained only as long as necessary for verification and fraud prevention, or until you request deletion via Settings or by contacting privacy@verifiedonly.app.

3. Liveness Checks

Liveness checks are used to confirm that you are physically present during verification (not a photo or video replay attack). Liveness data is processed in real time and not retained beyond what is necessary for verification.

Liveness verification data is retained for up to 90 days after account deletion for fraud prevention purposes, then permanently deleted.

4. Location Data

We may collect your approximate city or GPS location to show you people nearby. Location data is used only for matchmaking and is never sold.

You can revoke location permissions in your device settings at any time. Some features may not work without location access.

GPS coordinates are stored with 2-decimal precision (approximately 1km accuracy) and retained for 30 days after last use. City-level location is retained while your account is active.

5. Messages & Communications

Messages you send through the app are stored on our servers and may be reviewed by our moderation team if reported for abuse or safety violations.

We do not read or analyze your messages for advertising purposes.

Moderation access is limited to reported content only. Our team reviews messages solely to investigate violations of our Terms of Service and Safety Guidelines.

6. Notifications & Device Data

If you enable push notifications, we collect your device push token (FCM/APNS) to deliver notifications. You can opt out of notifications in Settings.

We may collect device identifiers and fingerprints for security and fraud prevention.

7. Analytics & Usage Data

We collect anonymous usage data to improve the app — such as which features are used, error rates, and performance metrics. This data does not identify you personally.

Analytics data is retained for 12 months and used solely for product improvement. You can opt out of analytics tracking by contacting privacy@verifiedonly.app.

8. Third-Party Service Providers

We use third-party service providers to operate the platform. These may include:

  • Cloud hosting and storage (Base44, AWS)
  • Facial recognition (AWS Rekognition)
  • Email delivery (Resend)
  • SMS / phone verification (Twilio)
  • Push notifications (Firebase FCM, Apple APNS)
  • Maps and geocoding (Google Maps)
  • Music metadata (Spotify)

These providers have access only to data necessary to perform their services and are contractually bound to protect your data.

All providers are GDPR-compliant and maintain appropriate data protection agreements.

9. Data Retention

Active account data is retained while your account is open. When you delete your account, most data is removed within 30 days.

Verification records (selfies, liveness data, audit logs) may be retained for up to 90 days after account deletion for fraud prevention and legal compliance.

Retention periods by category:

  • Profile data: Deleted within 30 days of account deletion
  • Messages: Deleted within 30 days of account deletion
  • Verification photos/videos: Retained up to 90 days for fraud prevention
  • Audit logs: Retained up to 1 year for security compliance
  • Analytics data: Retained up to 12 months

10. Your Rights & Data Deletion

You may request access to, correction of, or deletion of your personal data at any time. You can delete your account directly in Settings → Delete Account.

For other data requests (export, correction, or erasure of verification data), contact: privacy@verifiedonly.app

We respond to all data requests within 30 days as required by GDPR and CCPA. Verification data may be retained beyond deletion requests only as necessary for fraud prevention or legal compliance.

11. Children's Privacy

This app is intended only for adults 18 years of age or older. We do not knowingly collect data from users under 18. If we discover an underage account it will be permanently deleted.

If you believe a user is under 18, please report them immediately via the in-app Report button or contact safety@verifiedonly.app.

12. Contact & Privacy Requests

For privacy questions, data requests, or to report a concern:

Verified Only · Attn: Privacy Officer

13. Changes to This Policy

We may update this Privacy Policy from time to time. Significant changes will be communicated via in-app notice or email at least 30 days before they take effect.

Material changes require your renewed consent. You can review the current version at any time in Settings → Privacy Policy.