This English version is provided for convenience. In case of discrepancy, the Spanish version prevails. Read the Spanish version.

Privacy Policy

Effective date: March 1, 2026 — Last updated: October 5, 2026 — Version 2026-10-05-v1

1. Introduction and Data Controller

Privemeet ("we", "us", or "our") operates a premium dating platform that prioritizes privacy and discretion. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our website and progressive web application (collectively, the "Service").

We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Spanish Organic Law 3/2018 on Data Protection and Digital Rights ("LOPDGDD"). Because the Service may be used outside the EU, we also apply local data-protection rules that are mandatory in a particular case, including the UK GDPR, Brazil's LGPD, Canada's PIPEDA and US state privacy laws, when they fall within their scope.

Data Controller

Oink Tech Intelligence S.L. (operator of Privemeet)

CIF: B-75305177

C/ Virgen de los Peligros 11, planta 3, 28013 Madrid, España

Email: privemeet@oinktechno.com

Data Protection Officer (DPO)

External DPO: Kira Intelligence Labs, S.L.. Contact person: Rafael Yañez Salamanca. Appointment effective from October 1, 2026.

For data-protection questions and to exercise your rights, you can contact the DPO directly at dpd@oinktechno.com. This channel is separate from general customer support.

By using our Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use the Service.

The controller is established in Spain. This Policy applies regardless of the country from which you access the Service; technical accessibility does not mean that the Service has been commercially launched in every jurisdiction.

2. Types of Data We Collect

We collect the following categories of personal data:

2.1 Account and Identity Data

  • Phone number (used for OTP authentication via Twilio)
  • Display name and profile information you provide
  • Date of birth (to verify you are 18 or older)
  • Gender and dating preferences
  • User segment and relationship preferences
  • Language and locale preferences
  • Sensitive data you provide or that may be inferred from use of a dating service, including sex life or sexual orientation

2.2 Photos, Media, and Biometric Data

  • Profile photos you upload (stored in our AWS S3 object-storage service)
  • Verification selfies and facial geometry data — used to confirm your identity via facial recognition. This constitutes biometric data under GDPR Article 9 and is processed only with your explicit consent.
  • Face-blurred versions of photos, generated automatically by our AI face blur technology
  • Private photos and videos controlled by the profile owner

2.3 Location Data

  • GPS coordinates (only when you explicitly grant location permission)
  • IP-based geolocation (approximate location derived from your IP address)
  • Location data is used to show nearby users and is never displayed precisely to other users

2.4 Communications Data

  • Messages exchanged with other users through the Platform
  • Message metadata (timestamps, read receipts)
  • Support communications you send to us
  • Reports and feedback submitted through the Platform

2.5 Financial and Transaction Data

  • Subscription type and billing history
  • One-time plan purchase history
  • Payment details are processed and stored exclusively by Stripe; we do not store your full card number, CVV, or complete banking information

2.6 Device and Technical Data

  • Device type, operating system, browser type and version
  • IP address and session identifiers
  • Push notification tokens (for delivering push notifications)
  • Usage logs (pages visited, features used, timestamps, click patterns)
  • Screen resolution and viewport size
  • Referring URL and landing page

2.7 Optional Product Measurement

  • Registration events, discovery and profile visits, filters and interaction attempts
  • First message and first reply, distinguishing real-profile relationships from virtual-profile conversations
  • Paywall views and confirmed purchases, including billing mode and plan tier
  • A temporary account identifier or session pseudonym, date, source and schema version
  • These events exclude message text, phone numbers, photos, IP addresses and exact location

2.8 Data We Do Not Collect

  • We do not collect data from social media accounts (we have no social login)
  • We do not collect contacts from your phone's address book
  • We do not request health data, political opinions, or religious beliefs as profile fields. If you voluntarily include them in free text or messages, they are processed as part of that content

3. How We Use Your Data

We process your personal data for the following purposes:

  • Account creation and authentication — verifying your identity via phone OTP (Twilio) and selfie verification (facial recognition)
  • Providing the Service — matching you with other users, displaying profiles, enabling messaging, and managing private media access
  • Location-based features — showing users near you and calculating approximate distances between users
  • Privacy protection — applying face blur to photos, enabling app disguise and panic button features, preventing unauthorized content distribution
  • Payment processing — managing subscriptions and one-time plan purchases
  • Safety and moderation — detecting and preventing fraud, abuse, harassment, and violations of our Terms of Service using both automated and human review
  • AI-powered features — checking age, face and gesture, applying local moderation, translating messages, and operating virtual profiles disclosed in the Terms of Service
  • Push notifications — delivering real-time alerts for messages, matches, and account activity (with your opt-in consent)
  • Communications — sending SMS verification codes, account notifications, and service updates
  • Analytics and improvement — with your separate consent, measuring registration, navigation, interaction and purchase events to improve the Service; also diagnosing technical issues and producing irreversibly aggregated statistics
  • Legal compliance — fulfilling legal obligations, responding to legal requests, and enforcing our Terms

4. Legal Basis for Processing (GDPR)

We process your data under the following legal bases as defined by GDPR Article 6 (and Article 9 for special categories of data):

Contract Performance (Art. 6(1)(b))

Processing necessary to provide you with the Service you signed up for, including account management, profile display, matching, messaging, payment processing, and content delivery.

Explicit Consent (Art. 6(1)(a) / Art. 9(2)(a))

For sensitive data inherent in a dating service and biometric processing (selfie verification and facial recognition), GPS location data, push notifications, optional analytics cookies and internal product measurement. You may withdraw consent at any time without affecting the lawfulness of processing performed prior to withdrawal.

Legitimate Interests (Art. 6(1)(f))

For fraud prevention, platform security, content moderation and abuse detection. Statistics that are already irreversibly anonymous are not personal data. We have conducted balancing tests to ensure these interests do not override your fundamental rights and freedoms.

Legal Obligation (Art. 6(1)(c))

Where we are required by law to retain, process, or disclose data, including tax record keeping, responding to lawful court orders, and mandatory reporting of CSAM.

5. AI and Automated Processing

Privemeet uses artificial intelligence and automated processing in several aspects of the Service. We are committed to transparency about how AI is used:

Face Blur Technology

When you upload a photo, our AI automatically detects faces and generates a blurred version. This processing happens on our servers. The original unblurred photo is stored securely and only revealed to users you explicitly authorize.

Legal basis: Contract performance (essential feature of the Service)

Selfie Verification (Facial Recognition)

Our verification system uses facial recognition to compare your live selfie with your profile photos, confirming you are a real person and that your photos are genuine. AWS Rekognition analyses the face, estimates an age range and compares similarity; OpenAI checks whether the requested gesture is being performed. The selfie and assessment results are retained while the account is active. You may request a manual-review alternative before sending the selfie.

Legal basis: Explicit consent (Art. 9(2)(a) GDPR — biometric data)

Message Translation (Anthropic Claude with OpenAI fallback)

Messages are checked by local rules for abusive, threatening, or illegal content. In conversations with virtual profiles, message text may be sent to Anthropic or, if the primary service fails, OpenAI for translation between the user's language and Spanish. Authorized Privemeet operators can read those conversations and write a Spanish response that is translated before delivery. The AI translates text but does not generate the operator's reply.

Legal basis: Contract performance and legitimate interest (service delivery and user safety)

Virtual Profiles

We use synthetic virtual profiles for entertainment, quality assurance and improvement of the Service. They do not represent real individuals. Users who voluntarily accept the separate checkbox may see and contact them. They are visibly identified as virtual before and during the chat. Replies are written by a restricted group of authorized operators and may be translated automatically. Operator identity, Spanish source text, translated text, target locale and provider are recorded for security and accountability.

Legal basis: consent to this interaction, contract performance and service security

Under GDPR Article 22, you have the right not to be subject to decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. If any automated processing results in account suspension or content removal, you may request human review by contacting privemeet@oinktechno.com.

6. Third-Party Data Sharing

We share your personal data only with trusted third-party service providers who assist us in operating the Service. We do not sell your personal data to third parties. We do not share your data with advertisers.

Stripe (Payment Processing)

Receives your payment information (card details, billing address) to process subscriptions and one-time plan purchases. Stripe is PCI DSS Level 1 certified. See Stripe's Privacy Policy.

Data shared: payment details, billing address, transaction history, email

Twilio (SMS Delivery)

Receives your phone number to send OTP verification codes and account notifications. See Twilio's Privacy Policy.

Data shared: phone number, SMS message content

Amazon Web Services (Infrastructure)

Our Service is hosted on AWS infrastructure. All data stored on AWS is encrypted at rest and in transit. AWS acts as a data processor under our instructions and does not access your data for its own purposes. See AWS Privacy Policy.

Data shared: all data is hosted on AWS (EU region by default)

Anthropic (AI Message Translation)

In virtual-profile conversations, message text may be sent to Anthropic's Claude AI for translation between the user's language and Spanish. Authorized operators access the conversation within Privemeet. Processing and retention follow the applicable provider configuration and agreement. See Anthropic's Privacy Policy.

Data shared: message text content (no user identifiers)

Google Analytics (Optional Analytics)

Only if you authorize it in cookie settings, Google may receive analytics identifiers and technical browsing data to produce usage statistics. This consent is separate from our optional internal measurement and can be withdrawn at any time. See Google's Privacy Policy.

Data shared: analytics identifiers, device, browser and page interaction data

OpenAI (Gesture Verification and Translation Fallback)

The verification selfie is sent to OpenAI solely to check that one person is performing the requested gesture. OpenAI may also receive virtual-profile message text if the primary translator fails. It is not asked to identify the person or infer sensitive attributes. See OpenAI's Privacy Policy.

Data shared: verification selfie; message text for fallback translations

We may also disclose your data when required by law, in response to valid legal process (court orders, subpoenas), to protect the rights, property, or safety of Privemeet, our users, or the public, or in connection with a merger, acquisition, or sale of assets (in which case you will be notified).

7. International Data Transfers

Our primary infrastructure is hosted in the European Union (AWS EU region). However, your personal data may be transferred to and processed in countries outside the European Economic Area (EEA) when using our third-party service providers:

  • Stripe — United States (PCI DSS compliant, EU-US Data Privacy Framework)
  • Twilio — United States (Standard Contractual Clauses)
  • Anthropic — United States (Standard Contractual Clauses)
  • OpenAI — United States (Standard Contractual Clauses)
  • Google Analytics — United States (the transfer safeguard applicable to the contracted service)

Data provided directly by a person outside the EEA is received and processed primarily in the EU. When Privemeet or its providers make a subsequent transfer, the mechanism required by the law of origin is used. For EEA data we use GDPR Chapter V safeguards. Before a restricted transfer of UK data or data subject to Brazil's LGPD is made, the UK IDTA or Addendum and a valid ANPD-approved mechanism, respectively, must be put in place.

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions by the European Commission where applicable
  • Binding Corporate Rules where the service provider has adopted them
  • UK IDTA or Addendum and a transfer risk assessment where applicable
  • ANPD standard clauses or another valid LGPD transfer mechanism

You may request information about the safeguards in place for specific transfers by contacting our privacy contact.

8. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law:

Data CategoryRetention Period
Active account dataDuration of account activity
Profile, photos, and messagesDeleted from active systems when the account is deleted, unless a documented legal hold applies
Virtual-profile operator audit recordsWhile the conversation is retained; deleted with the associated account or conversation unless a documented legal hold applies
Read-only administrative access recordsRetained for up to 3 years for security, accountability and complaint handling, unless another legal period applies
Verification selfiesWhile the account remains active; deleted with the account
Facial geometry / biometric dataAWS templates are not stored; scores and review reasons are retained while the account is active
Financial / tax recordsFor applicable statutory periods; generally 4 years for Spanish tax duties and 6 years for commercial records
Detailed optional product-measurement eventsUp to 90 complete UTC days; deleted earlier when you delete your account. Only aggregated counts without identifiers remain afterwards
Usage and access logs12 months
Safety / abuse reportsUp to 3 years after resolution
Banned account identifiersUp to 3 years to prevent abuse, subject to periodic review and applicable limitation periods
Private media accessAccessible while access is granted. After revocation, an already issued signed URL may continue to work until its technical expiry, for no more than 15 minutes

When data is no longer needed, it is securely deleted or anonymized. Anonymized data (which cannot be linked back to you) may be retained indefinitely for statistical and analytical purposes.

9. Your Rights Under GDPR

Under the GDPR and other applicable data protection laws, you have the following rights regarding your personal data:

Right of Access (Art. 15)

You can request a copy of all personal data we hold about you, together with information about how it is processed. We will provide this in a commonly used electronic format.

Right to Rectification (Art. 16)

You can request correction of inaccurate or incomplete personal data. You can also update most of your profile information directly through the app.

Right to Erasure (Art. 17)

You can request deletion of your personal data ("right to be forgotten"). You can delete your account at any time from the Settings page. Certain data may be retained where required by law.

Right to Data Portability (Art. 20)

You can request your data in a structured, commonly used, and machine-readable format (e.g., JSON), and have it transmitted directly to another controller where technically feasible.

Right to Object (Art. 21)

You can object to processing of your personal data based on legitimate interests or for direct marketing. We will cease processing unless we have compelling legitimate grounds.

Right to Restrict Processing (Art. 18)

You can request limitation of processing in certain circumstances, such as when you contest the accuracy of data or when processing is unlawful but you oppose erasure.

Right to Withdraw Consent (Art. 7(3))

Where processing is based on consent (e.g., biometric data, location, AI photos), you can withdraw it at any time without affecting the lawfulness of processing performed prior to withdrawal.

Right Regarding Automated Decisions (Art. 22)

You have the right not to be subject to decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you. You can request human review of automated decisions.

How to exercise your rights

Contact our privacy team at privemeet@oinktechno.com. We will respond without undue delay and, in principle, within one month. If the complexity or number of requests requires it, we may extend that period by up to two additional months and will inform you within the first month. There is no fee for exercising your rights, unless requests are manifestly unfounded or excessive.

You also have the right to lodge a complaint with your local supervisory authority. In Spain, this is the Agencia Española de Protección de Datos (AEPD) at www.aepd.es.

10. Additional Rights Based on Your Location

In addition to the rights in section 9, local rights may apply when the relevant law covers Privemeet:

  • United Kingdom: UK GDPR and Data Protection Act 2018 rights and the right to complain to the Information Commissioner's Office (ICO).
  • Brazil: confirmation, access, correction, anonymisation, blocking or deletion, portability and information about sharing under the LGPD, plus the right to petition the ANPD.
  • Canada: access, correction and other rights under PIPEDA or applicable provincial law, including the ability to complain to the competent authority.
  • California and other US states: where Privemeet is subject to the relevant law, you may have rights to access or know, correct, delete and port data, limit certain uses of sensitive information, opt out of sale or sharing, and receive non-discriminatory treatment. Privemeet does not sell personal information for monetary consideration.

To exercise any local right, contact us at privemeet@oinktechno.com or use the account deletion feature in Settings. We may request the minimum information needed to verify your identity and residence. We will not discriminate against you for exercising a legal right.

11. Cookies and Tracking Technologies

We use the following cookies and similar technologies:

Strictly Necessary Cookies

Required for authentication, session management, CSRF protection, and security. These cannot be disabled as the Service cannot function without them.

Legal basis: Contract performance

Preference Cookies

Store your language selection, locale, display preferences, and theme settings. These improve your experience but are not essential.

Legal basis: Legitimate interest / Consent

Analytics Cookies

Help us understand how users interact with the Service so we can improve it (Google Analytics). Data is anonymized or pseudonymized where possible. They are only set if you accept them in the cookie banner; you can withdraw consent at any time from "Cookie settings" (your choice is stored for 12 months in the pm_consent cookie).

Legal basis: Consent

Optional Internal Product Measurement

With a separate choice, we measure limited registration, navigation, interaction and purchase events. The pm_product_analytics cookie stores your choice for 12 months; pm_product_session contains an HttpOnly pseudonym while permission remains in place. Accepting Google Analytics does not enable this measurement, and you can reject or withdraw it at any time from "Cookie settings".

Legal basis: Separate consent

We do not use third-party advertising cookies. We do not track you across other websites. We do not participate in any cross-site tracking or retargeting networks.

12. Children's Privacy

Privemeet is strictly for users aged 18 and older. We do not knowingly collect personal data from anyone under the age of 18. Age verification is performed during the registration process through date of birth confirmation and selfie verification.

If we become aware that we have collected personal data from a person under 18, we will take immediate steps to:

  • Delete all personal data associated with that account
  • Permanently terminate the account
  • Report the incident to relevant authorities where required by law

If you believe that a minor has created an account on our platform, please contact us immediately at privemeet@oinktechno.com so we can take appropriate action.

13. Security Measures

We implement robust technical and organizational measures to protect your personal data in accordance with GDPR Article 32:

Technical Measures

  • All data transmitted between your device and our servers is encrypted using TLS 1.2+ / HTTPS
  • Encryption-at-rest controls configured for our storage and infrastructure services
  • Private and original photos are served through access controls; blurred previews may be distributed through a CDN
  • Face-blurring technology protects your identity until you choose to reveal it
  • Phone numbers are used for authentication only and are never publicly displayed
  • The interface discourages downloading, although no website can completely prevent screenshots or external copies
  • Push notification tokens are stored securely and scoped to individual devices

Organizational Measures

  • Access to personal data is restricted to authorized personnel on a need-to-know basis
  • Internal access must be subject to documented confidentiality and data-protection instructions
  • Security controls and infrastructure monitoring are maintained
  • Providers processing data on our behalf must be subject to data processing agreements
  • Incident response procedures for security incidents

While we take all reasonable precautions, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of your data.

14. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:

  • Notify the competent supervisory authority (AEPD in Spain) without undue delay and, where feasible, within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
  • Notify affected users without undue delay if the breach is likely to result in a high risk to their rights and freedoms, as required by GDPR Article 34. Notification will be sent via SMS, email, or in-app notification.
  • Provide details of the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
  • Document the breach internally regardless of severity, including facts, effects, and remedial action taken.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or applicable law. When we make material changes:

  • We will update the "Last updated" date at the top of this page.
  • We will notify you through the Service, by SMS to your registered phone number, or by other appropriate means at least 14 days before the changes take effect.
  • Where changes affect processing based on consent, we will request renewed consent where required by law.

Your continued use of the Service after the effective date of any changes constitutes your acknowledgment of the updated policy. Previous versions of this policy are available upon request.

16. Contact Us

If you have questions about this Privacy Policy, wish to exercise your data protection rights, or have concerns about how we handle your personal data, please contact us:

Privemeet

Single email for privacy, safety, support and legal communications: privemeet@oinktechno.com

We will respond without undue delay and, in principle, within one month. If the complexity or number of requests requires it, we may extend the period by up to two additional months and will inform you within the first month.