Draft version 0.1 — last updated for this prototype build.
Merj ("we", "us") operates the Merj dating platform. For the purposes of GDPR, Merj is the data controller for account, profile, and matching data. Contact our Data Protection contact at [privacy@merj.app — placeholder]. [If you appoint a formal Data Protection Officer, name them here; required once you process biometric data at scale under Art. 37.]
| Category | Examples | Why |
|---|---|---|
| Account | Username, email, phone number, date of birth | Create your account, verify you're 18+, let you log in |
| Profile | Photos, bio, reasons for using Merj, interests, linked social handles | Show your profile to potential matches |
| Location | Live or fixed location, distance to other users | Sort and filter Discover by proximity |
| Verification | Phone OTP confirmation, optional ID document, optional face-scan age result | Confirm you're a real, unique, 18+ person |
| Activity | Swipes, matches, messages, call logs (participants & duration, not content or recordings) | Run the core matching & chat features, show your own activity history back to you |
| Safety signals | Reports filed/received, device & IP metadata, behavioural signals (see §12) | Detect fake, bot, and scam accounts |
| Contacts (opt-in only) | Hashed phone numbers from your device contacts, only if you turn this on | Suggest or exclude people you already know |
| Communications | Notification preferences, delivery logs | Send match/message/like/call alerts via the channels you choose |
Where you choose to age-verify using a face scan, that scan is processed to produce a single yes/no age estimate and is not retained once that result is produced. We do not build a facial recognition template, we do not use the scan to identify you against other people, and we do not share the raw image with anyone outside the verification process itself. Because this is biometric data under GDPR Art. 9, we only process it with your explicit, separate consent, collected at the moment you choose to verify — never bundled into general account sign-up consent. [If you use a third-party age-assurance vendor, name them here along with a link to their own privacy policy, since they will be a sub-processor of biometric data.]
ID documents submitted for optional ID verification are handled the same way: used only to confirm identity and immediately discarded or securely deleted after that one-time check, not stored as part of your ongoing profile.
We do not sell your personal data. We share limited data with: infrastructure and hosting providers, SMS/email delivery providers (for the notifications you opt into), an age/ID verification vendor (if used), and payment/ad providers (for the "watch an ad for more swipes" feature) — each bound by a data processing agreement. [List actual named sub-processors here before going live — this is a required GDPR disclosure, not optional boilerplate.]
Where data is processed outside your country (e.g. a cloud region, or a verification vendor based elsewhere), we rely on Standard Contractual Clauses or an equivalent adequacy mechanism. [Confirm actual hosting regions once infrastructure is finalised.]
| Data | Retention |
|---|---|
| Active account & profile | For as long as your account is active |
| Paused account | Retained; not shown to others until unpaused |
| Deleted account | Deleted or irreversibly anonymised within 30 days, except where we must retain records for fraud/legal reasons |
| Biometric scan (raw) | Not retained beyond the verification check itself |
| Messages after account deletion | Removed from your side; a copy may persist in a former match's thread for a limited window unless also deleted |
| Reports & safety signals | Retained longer than normal activity data specifically to detect repeat-offender patterns across accounts |
Subject to local law, you can: access the data we hold on you, correct it, request deletion, export it (portability), object to or restrict certain processing, and withdraw consent at any time without affecting processing already carried out. Most of these are also available directly in-app: Settings → pause, visibility, delete account. For anything else, contact us at the address in §1. You also have the right to lodge a complaint with your local data protection authority.
We apply encryption in transit, access controls limiting who can view verification data, and monitoring for unauthorised access. No system is perfectly secure; see §13 for what happens if that fails.
Merj is strictly for people 18 and older. We do not knowingly collect data from anyone under 18; accounts found to belong to a minor are removed and the associated data deleted. Reports flagging a suspected minor are treated as high priority.
We use strictly necessary cookies/local storage to keep you logged in and remember preferences (e.g. your notification choices, username-change cooldown). [Add an analytics/ads cookie table here once those providers are chosen, with a consent banner offering reject/accept before anything non-essential loads.]
We use an automated scoring system that combines signals — such as location/phone consistency, image duplication, account age, messaging behaviour, and report history — to flag accounts that may be fake, bot, or scam profiles. This scoring can reduce a profile's visibility or temporarily restrict messaging pending human review; it does not, on its own, permanently ban an account without a person reviewing the case first above a defined severity threshold. You can request a human review of any automated restriction placed on your account.
If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify affected users without undue delay where the risk to them is high.
We'll post material changes here with an updated date, and seek fresh consent where a change affects processing you previously consented to (e.g. biometric data use).
Questions about this policy: [privacy@merj.app — placeholder]