Draft — not lawyer-reviewed. Entity name set to "Tyluna." Jurisdiction is still open (Canada, US, Asia, or Middle East are all on the table) — Section 10 below is left as a placeholder rather than guessed, since which region-specific rights apply (GDPR/CCPA/PIPEDA-style, or otherwise) depends entirely on where you actually operate and where your members are. Get real legal advice before collecting this data at scale.
Privacy Policy
Last updated: September 24, 2026
1. What We Collect
- Account info: email, password (stored as a salted hash, never in plain text), first name, date of birth
- Profile info: photos you upload, your prompt answers, city, gender, and who you're interested in meeting
- Verification photos: if you choose to get a Verified badge, a selfie with a pose prompt — stored separately from your profile photos, seen only by our moderation team, and never shown publicly
- Government ID photo: if you choose to get ID Verified (our strongest trust badge, optional and separate from the Verified badge above), a photo of a passport, driver's license, or national ID card — stored separately, seen only by our moderation team, never shown publicly or to other members, and deleted from our systems if you submit a new one to replace a rejected attempt
- Location: if you grant permission, your device's location — powers "near me" discovery. We round it to roughly a 1km/0.6mi area before it's ever saved, specifically so it can't pinpoint your exact address, and it's never shown to other members (only an approximate "X km away" on your profile once both of you have shared location). Declining this doesn't block you from using the Service — you're just shown to everyone rather than sorted by distance. Tyluna+ members can additionally set a "Passport" location to browse a different city; this only overrides what you're shown, not your real saved location.
- Live check-in location (optional, separate from the above): if you turn on live location sharing for a specific Safety Check-In, your device's exact, unrounded position is recorded periodically while that check-in stays active and the app is open, and is visible — via a private, unguessable link, no account needed — to the one emergency contact you named for that check-in. This is off by default and only ever applies to the single check-in you enable it for. These location points are automatically deleted a few days after that check-in ends (whether you confirmed you were safe, cancelled it, or it went unanswered).
- Activity: who you swipe on and message, reports you file or receive
- Payment info: if you buy an event ticket or subscribe to Tyluna+, Stripe processes your payment details directly — we receive confirmation that you paid, not your card number
- Technical: IP address (used for login rate-limiting/security), timestamps of activity
2. How We Use It
To show you to compatible members and show them to you, to operate matching and messaging, to process payments, to enforce our Terms (including investigating reports), and to send account-related emails (verification, password resets, receipts). We do not sell your personal data.
3. Who Can See What
Other members can see your first name, age, photos, prompt answers, and city. Your email, exact birthdate, verification photos, and message history are never shown to other members. Messages are only visible to the two people in that conversation (or, in a Double Date group chat, its four participants) and to our moderation team when reviewing a report. If you choose to share your WhatsApp number with a match, that number leaves our systems at that point and WhatsApp's own privacy policy governs it from there — sharing it is always your choice, never automatic.
4. Third-Party Services
We use Stripe to process payments — see Stripe's privacy policy for how they handle payment data. If a live Safety Check-In location is viewed, the map is drawn using free OpenStreetMap map tiles — loading them sends the viewer's IP address to OpenStreetMap's servers, standard for any site using their tiles; see OpenStreetMap Foundation's privacy policy. We do not use third-party advertising or analytics trackers.
5. Cookies
We use a single session cookie to keep you signed in. We don't use tracking or advertising cookies.
6. Data Retention
We keep your data while your account is active. Deactivating your account hides your profile from other members; contact us to request full deletion of your data.
7. Your Choices
You can edit or delete your profile info and photos at any time from your Profile page, block or report other members, and deactivate your account. To request a copy of your data or full deletion, contact us at support@tyluna.com — we'll respond within 30 days.
8. Security
Passwords are hashed, not stored in plain text. Uploaded photos are stored in a directory that cannot execute code. We use rate-limiting to slow down automated login attempts. No system is perfectly secure — report any suspected vulnerability to support@tyluna.com.
9. Children
The Service is not intended for anyone under 18. We do not knowingly collect data from minors.
10. International Users
[Placeholder — jurisdiction of incorporation is still open (Canada, US, Asia, or Middle East). Once decided, this section needs cross-border data transfer disclosures and the specific region-based rights that apply (e.g. GDPR-style access/erasure/portability rights for EU/UK members, PIPEDA for Canada, CCPA for California), finalized with legal counsel based on where you actually operate and where your members are.]
11. Changes to This Policy
We may update this Policy from time to time; continued use of the Service after a change constitutes acceptance.
12. Contact
Privacy questions: support@tyluna.com.