DRAFT — not yet reviewed by a lawyer. This page is a working draft for attorney review. App stores require a live, accurate privacy policy that matches your App Privacy / Data Safety disclosures before submission.
Treat — Privacy Policy
DRAFT FOR ATTORNEY REVIEW — DO NOT PUBLISH AS-IS
Not legal advice. This is a structured first draft so an attorney can finalise it efficiently. Sections marked ⚠️ carry real regulatory risk and need professional review.
A privacy policy is mandatory — Apple and Google both require a live policy URL before they will accept your app, and you must also complete Apple's App Privacy questionnaire and Google's Data Safety form. Those disclosures must match this document. Mismatches are a common cause of app rejection.
Fill in every [BRACKETED] item before review.
Effective date: [DATE]
Company: [LEGAL ENTITY NAME] ("Treat," "we," "us")
Contact: [PRIVACY EMAIL]
1. Who this applies to
This policy explains how we collect, use, share, and protect personal information when you use the Treat app or website (the "Service"). Treat is only for people aged 18 and over.
A note on sensitive data. Because Treat is a dating service, information you provide — including your gender, who you are looking for, and your photos — may reveal or imply your sexual orientation. In the EU, UK, and some other jurisdictions this is treated as a special category of personal data with heightened legal protection. ⚠️ If you have any EU or UK users, this materially changes your obligations. Discuss with counsel before launching there.
2. Information we collect
You give us directly
- Account information: email address or phone number, password, date of birth.
- Profile information: name or display name, age, gender, who you are looking for, photos, bio, your selected date activities, and your who-pays preference.
- Verification data: if you verify your identity, a selfie or short video used to compare against your profile photos. ⚠️ Facial-recognition and biometric data is separately regulated — Illinois (BIPA), Texas, and Washington impose strict consent and retention rules with statutory damages. Confirm with counsel how long you may keep verification selfies and what consent language you must show. This is a genuine litigation risk area.
- Communications: messages you send to other users, and anything you send our support team.
- Reports: information you provide when reporting another user.
Collected automatically
- Usage data: profiles viewed, swipes, matches, features used, session times.
- Device data: device model, operating system, app version, language, device identifiers, IP address.
- Approximate location: derived from your device or IP address, used to show you people nearby. You can control precise location permission in your device settings, though core matching may not work without approximate location.
- Cookies and similar technologies on our website.
From third parties
- Sign-in providers (Apple, Google, Facebook) if you use them to register — typically name, email, and profile photo.
- App stores: confirmation of purchases and subscription status (we do not receive your payment card number).
- Advertising and analytics partners: limited data as described in Section 5.
3. How we use your information
- To create and operate your account and profile.
- To show you potential matches and to show your profile to others.
- To enable messaging between matched users.
- To verify identity and reduce impersonation, fraud, and spam.
- To provide customer support and respond to your requests.
- To detect, investigate, and prevent fraud, abuse, harassment, and violations of our Terms, and to protect the safety of our users.
- To process subscriptions and purchases.
- To personalise and improve the Service, including measuring which features are used.
- To send you service messages (matches, messages, security alerts) and, with your consent where required, marketing messages. You can opt out of marketing at any time.
- To display advertising, as described in Section 5.
- To comply with legal obligations and enforce our Terms.
Legal bases (EU/UK users) ⚠️
Where GDPR applies, we rely on: contract (operating your account and matching), legitimate interests (safety, fraud prevention, product improvement), consent (marketing, precise location, personalised advertising, and processing of special-category data), and legal obligation. Consent may be withdrawn at any time.
4. What we share — and what we never do
Your profile is visible to other users. Your photos, display name, age, activity selections, approximate distance, and — once verified — your who-pays preference are shown to other users of the Service. Do not put anything in your profile you would not want a stranger to see.
We share personal information with:
- Service providers who process data on our behalf under contract: cloud hosting, database, analytics, content moderation, identity verification, customer support, and crash reporting.
- Advertising partners, as described in Section 5.
- Law enforcement or other parties where we believe in good faith it is required by law, or necessary to investigate fraud, prevent harm, or protect the rights and safety of our users or the public.
- A successor entity in connection with a merger, acquisition, financing, or sale of assets. We will notify you of any such change.
We do not sell your personal information for money. ⚠️ Note that "sale" and "sharing" are defined broadly under the California Consumer Privacy Act and similar state laws — using certain advertising SDKs can qualify as "sharing for cross-context behavioural advertising" even with no money changing hands. If you use ad networks, you likely must offer a "Do Not Sell or Share My Personal Information" link and honour Global Privacy Control signals. Confirm with counsel and update this line accordingly — getting it wrong is a frequent enforcement target.
We never publish your verification selfie, your exact location, or your private messages to other users.
5. Advertising and analytics ⚠️
Treat may display advertising provided by third-party ad networks such as [e.g. Google AdMob]. These partners may collect device identifiers and usage information to serve and measure ads, including personalised ads.
- On iOS, we will request your permission through Apple's App Tracking Transparency prompt before tracking you across apps and websites. If you decline, you will still see ads, but they will be less relevant.
- On Android, you can reset or delete your advertising ID in device settings.
- You may opt out of personalised advertising in the app settings where offered.
We also use analytics tools to understand how the Service is used. ⚠️ List every SDK you actually ship — ad networks, analytics, crash reporting — and confirm each one's disclosures match your App Store and Play Store privacy forms.
6. Your rights and choices
Depending on where you live, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Delete your account and personal information.
- Object to or restrict certain processing.
- Port your data to another service.
- Withdraw consent at any time, where processing is based on consent.
- Opt out of the sale or sharing of personal information and of targeted advertising.
- Be free from discrimination for exercising these rights.
How to exercise them: delete your account directly in the app settings, or contact [PRIVACY EMAIL]. We will respond within the timeframe required by applicable law. We may need to verify your identity before acting on a request.
⚠️ Response deadlines and required disclosures differ across GDPR, CCPA/CPRA, and other state laws. If you have EU or UK users you may also need an EU/UK representative and a Data Protection Officer. Confirm with counsel.
7. Data retention
We keep your information for as long as your account is active. When you delete your account:
- Your profile stops being visible to other users promptly.
- We delete or anonymise your personal information within [e.g. 30 days], except where we must retain it longer.
- We may retain limited information longer where necessary to comply with legal obligations, resolve disputes, enforce our agreements, or — importantly — to prevent a user who was banned for safety violations from simply creating a new account.
- Messages you sent may remain visible to the recipient.
- Verification selfies are deleted within [SPECIFY — keep this short] of verification completing. ⚠️ Biometric retention limits are legally mandated in several states. Set this deliberately with counsel, then make sure your system actually enforces it.
8. Security
We use technical and organisational measures — including encryption in transit, access controls, and secure hosting — to protect your information. No system is completely secure, and we cannot guarantee absolute security. Please use a strong, unique password and notify us immediately at [SUPPORT EMAIL] if you suspect unauthorised access.
⚠️ Have a written data breach response plan before launch. Most jurisdictions require notification within a defined window — 72 hours under GDPR.
9. Children
Treat is strictly for adults aged 18 and over. We do not knowingly collect information from anyone under 18. If we learn that a minor has created an account, we will delete it and their information promptly. If you believe a minor is using Treat, contact us immediately at [SAFETY EMAIL].
10. International transfers
Your information may be transferred to, stored in, and processed in [COUNTRY, e.g. the United States], which may have different data protection laws than your country. ⚠️ If you serve EU or UK users, you need a valid transfer mechanism such as Standard Contractual Clauses. Do not launch in the EU without confirming this.
11. Changes to this policy
We may update this policy. If changes are material, we will notify you in the app or by email before they take effect. The "Effective date" above shows when it was last revised. We keep prior versions available at [ARCHIVE URL].
12. Contact us
Privacy questions: [PRIVACY EMAIL]
Safety concerns: [SAFETY EMAIL]
[LEGAL ENTITY NAME], [MAILING ADDRESS]
Checklist before you publish
- [ ] Host this at a public URL that works without logging in — both app stores require it
- [ ] Complete Apple's App Privacy questionnaire and Google's Data Safety form so they match this document exactly
- [ ] List every third-party SDK you actually ship
- [ ] Build the account-deletion flow in-app — Apple requires in-app account deletion if you allow account creation
- [ ] Decide and document your verification-selfie retention period, then enforce it technically
- [ ] Add the CCPA "Do Not Sell or Share" link if you use ad networks
- [ ] Implement the App Tracking Transparency prompt on iOS before any cross-app tracking
- [ ] Write a data breach response plan
- [ ] Have a licensed attorney review — prioritise the biometric, advertising, and international sections
- [ ] Re-review before launching in any new country