Scope & controller
This Privacy Policy describes how Dear Jane (Dear Jane, we, us) handles personal information when you use dearjane.me, our mobile experience, and any related services (together, the Service).
For data-protection purposes, Dear Jane acts as the data controller for personal information you submit to the Service. The third parties listed in Section 13 act either as our processors under written contract, or as independent controllers for the services they directly provide to you (notably Stripe for payments and Auth0 for authentication).
This Policy applies to everyone who uses the Service. Where additional regional rights apply — under the EU GDPR, the UK GDPR, the Swiss FADP, the Cyprus Personal Data (Processing) Law of 2018 (Law 125(I)/2018), the California CCPA/CPRA, or any other local regime — those rights are described in dedicated sections below.
Definitions
- Personal information / personal data
- Any information that identifies or could reasonably identify a specific person, directly or together with other information.
- Processing
- Any operation performed on personal data — collecting, storing, using, sharing, deleting.
- Controller
- The party that decides why and how personal data is processed (us, for most purposes).
- Processor / subprocessor
- A third party that processes personal data on the controller's behalf, under contract.
- Sensitive / special-category data
- Data revealing racial or ethnic origin, religious or philosophical beliefs, trade-union membership, genetic or biometric data, data concerning health, or data concerning sexual life or sexual orientation.
- Member
- A natural person who has registered for the Service.
What we collect
We collect only what we actually need to run the Service:
3.1 Account & identity
- Email address;
- Authentication identifier issued by Auth0 (the opaque
subtoken; not your password — we never see it); - The provider you signed up with (Google, email/password, etc.) and the timestamps of sign-ins;
- Display name, gender, the gender(s) you are looking for, date of birth (used to derive your age — we don't display the raw DOB), country and city.
3.2 Profile content
- Photos and videos in your public profile and Private Gallery;
- Free-text profile fields: "About me", "What I find irresistible", relationship status, lifestyle, languages, occupation, education, height, weight, body type, ethnicity, smoke / drink / workout preferences, travel destinations, and similar attributes;
- Visibility preferences you set per field (who sees your phone, Instagram, LinkedIn, etc.);
- Personality-quiz responses and the resulting 4-letter type and score vector;
- Anything you choose to put into a chat message.
3.3 Activity
- Profiles you've liked, saved, passed, matched with, blocked or reported;
- Messages, voice notes, and attachments you send and receive in the in-app chat (we store them so the recipient can read them);
- Search filters, sorting choices, and the times you've used them;
- Push-notification opt-ins, email-marketing opt-ins, language preference.
3.4 Device & technical
- IP address;
- City-level geolocation derived from the IP, returned by an IP-geolocation API. We never collect a precise GPS coordinate from your device;
- Browser type and version, operating system, language, screen size, device type;
- The referring URL (the page that linked you to Dear Jane);
- Performance logs, error reports, anti-abuse signals (page-load timings, JS exceptions, the fact that a request was rate-limited, etc.).
3.5 Payment
- The membership tier you bought, amount, currency, dates, country;
- Last four digits and brand of the card, or masked wallet identifier;
- Stripe's payment-method token for renewals.
We do not see, store or process your full card number, security code, or any banking credential. Stripe does.
3.6 Verification
- The boolean fact that your selfie verification passed (
selfie_verified = yes) and the timestamp it happened; - The boolean fact that you completed the personality quiz, and the resulting type / scores.
Important: the actual photo frames captured during the selfie / liveness check never leave your device. See Section 10 for the technical detail.
3.7 Communications
- Emails you exchange with support, safety or security;
- Bug reports, feature requests, survey answers you voluntarily submit;
- Records of consents you've given or withdrawn (and when).
How we collect it
- Directly from you — when you sign up, fill in a field, upload a photo, send a message, complete the personality quiz, set travel destinations, change a setting, or pay for a Membership.
- Automatically — when your browser connects to our servers (HTTP headers, cookies, session tokens) or interacts with the app (the buttons you click, the matches you opened, the searches you ran).
- From third parties — Auth0 hands us your sign-in profile and any consents you gave it; Stripe tells us when a payment succeeded, failed, was refunded or charged back; the geolocation API converts your IP into a city.
- From other Members — when they report you, block you, or include you in a conversation.
How we use it
- Run the Service. Authenticate you, show your profile to other Members, deliver messages, surface candidates that match your filters, process payments and unlock Membership features.
- Make matches feel real. Use profile attributes (age, location, lifestyle, personality, travel intentions) and behavioural signals (who you liked, who liked you back, how recently you were active) to rank who shows up in your feed and to help compatible people find each other.
- Keep the platform safe. Detect inauthentic accounts, harassment, scams, financial fraud and child-safety violations; investigate reports; enforce these Terms.
- Communicate with you. Send transactional emails (welcome, password resets, billing receipts, important product notices) and — with separate opt-in — marketing.
- Improve the Service. Measure aggregate usage, run A/B tests on UI variants, debug errors, train internal heuristics. We do not train external language models on your messages.
- Power AI-assisted features. Send the minimum text necessary to our LLM provider to produce a suggested rewrite or opener. The provider's terms prohibit them from using it to train their own models.
- Comply with the law. Tax accounting, regulatory reporting, lawful requests from authorities, responding to court orders.
- Defend our rights. Establish, exercise and defend legal claims that involve us.
Legal bases (GDPR)
If you are in the EEA, the UK or Switzerland, our legal basis for each kind of processing is:
- Contract (Art. 6(1)(b))
- Creating your account, providing the Service you signed up for, processing your Membership, delivering your messages.
- Legitimate interest (Art. 6(1)(f))
- Preventing abuse, debugging the product, defending our rights, running aggregated analytics, keeping the platform working and growing it carefully. You may object — see Section 19.
- Consent (Art. 6(1)(a))
- Marketing emails, optional analytics or advertising cookies (where used), and any "special category" data you voluntarily put in your profile (see Section 7). You may withdraw at any time.
- Legal obligation (Art. 6(1)(c))
- Tax and accounting records, responding to lawful regulatory and law-enforcement requests, complying with child-safety reporting duties.
- Vital interest (Art. 6(1)(d))
- Where necessary to protect someone's life or physical integrity — for example, sharing safety information with emergency services in a credible imminent-harm scenario.
Special-category data
Dating profiles sometimes reveal special-category data — sexual orientation in particular, and occasionally religion, ethnicity or health information. We rely on your explicit consent (GDPR Art. 9(2)(a)) to process this kind of data, and on the fact that you have manifestly made the data public on a profile that other Members can see (Art. 9(2)(e)).
Don't put anything into your profile that you wouldn't want other Members to see. You can edit or remove these fields at any time from your settings, and withdraw consent by deleting your account.
We do not use special-category data for advertising or share it with advertising networks, ever.
Profile visibility — who sees what
What other Members see depends on the field:
- Public
- Display name, headline photo, age, gender, gender(s) you're looking for, country, city, "About me", lifestyle, personality type, declared travel destinations. Visible to any signed-in Member.
- Per-field visibility
- Phone, email, Facebook, Instagram, LinkedIn, Telegram, Twitter and your Private Gallery. Each has a "who can see this" picker — Everyone, Matches only, After first message, Specific Member, or Nobody. Default is "Matches only" or "Nobody", depending on the field.
- Private to you
- Email address, date of birth, IP address, billing information, fraud-prevention signals, and the boolean of whether you passed selfie verification. Other Members never see any of these directly.
Your profile is not indexed by general search engines (we send the
noindex header on member pages). Other Members may
still see a cached or screenshotted copy outside the Service — once
someone has seen something, we cannot un-see it on their device.
Marketing & profiling
We send transactional and safety emails to anyone with an active account — these are part of running the Service and cannot be switched off without closing the account.
Marketing emails are sent only to Members who have opted in. Every marketing email contains a one-click unsubscribe link. Unsubscribing applies only to the marketing category — you'll still receive transactional and safety emails.
We do not sell ad space on the Service, do not target ads to you based on the contents of your messages, and do not let advertisers pixel your account. We may run small, non-personalised promotional banners for our own product (e.g., a banner advertising the Elite tier).
We profile you internally for two reasons: ranking who shows up in your feed (so the Service is useful to you), and detecting fraud (so the platform is safe). This profiling is described in detail in Section 11.
Selfie verification — technical detail
We take the privacy of selfie verification seriously, so the implementation is worth describing precisely.
- Your browser prompts you for camera permission. If you decline, verification stops there.
- If you accept, the page opens a media stream from the front camera and renders the live preview inside a circular HTML overlay so you can position your face.
- A hidden HTML canvas reads a frame from the stream roughly five times per second. For each frame, we run a face-and-motion detector locally — using the browser's native
FaceDetectorAPI where available, or a skin-tone + motion heuristic where it is not. - The frames remain inside the running browser tab. They are not uploaded over the network, not written to
localStorageorIndexedDB, and not written to any other persistent storage on your device. - If liveness is confirmed within a few seconds, the page closes the camera stream and posts a single JSON body
{"verified": true}to our server. That POST contains no image bytes. - The server flips the boolean field
selfie_verifiedon your profile to"yes"and records the timestamp. - If you close the tab, navigate away, or cancel mid-flight, the camera shuts off immediately.
You can ask us to reset your verification flag at any time by writing to privacy@dearjane.me. We will do so within 30 days; you can re-verify later if you choose.
Plain English: we never see your selfie. The only thing that touches our database is the boolean "this account passed the local liveness check".
AI & automated decisions
Parts of the Service use automated systems — including AI models — to do the following:
- Rank profiles in your discover feed, based on your filters, your behaviour, and signals about how the candidate profile has been engaged with;
- Suggest text — opening messages, "About me" rewrites, profile-completion prompts;
- Moderate content — flag photos and messages that may break the rules so a human reviewer can take a look;
- Score trust signals — payment-fraud likelihood, account-takeover likelihood, fake-profile likelihood;
- Power Sophie, our automated agent that may send opening messages and surface platform updates.
Where AI-generated text is involved, the third-party provider (currently OpenAI) receives only the minimum text necessary to produce the result. Their contract with us prohibits using that text to train their own models. We do not send selfies, identity documents, payment information or other sensitive fields to any third-party AI provider.
We do not use automated decision-making to produce legal or similarly significant effects within the meaning of GDPR Art. 22. Outcomes that materially affect your account — suspension, ban, refund denial, restoration after a false positive — are always reviewed by a human before taking effect.
You can ask how a particular automated decision was made, or request human re-review of a moderation outcome you believe to be wrong, by writing to privacy@dearjane.me.
Subprocessor register
Current subprocessors and the role each plays:
- Auth0 / Okta, Inc. — USA
- Authentication, multi-factor, session management. Privacy.
- Stripe, Inc. — USA / Ireland
- Card processing, subscription billing, fraud screening. Privacy.
- Amazon Web Services, Inc. — EU / USA
- Cloud hosting, storage, CDN. Privacy.
- OpenAI, L.L.C. — USA
- Large-language-model inference for AI-assisted text features.
- ip-api.com — EU
- IP-to-city geolocation for the "near me" filter.
- Transactional email provider
- Delivery of authentication emails, billing receipts, safety notices.
- Error-monitoring provider
- Aggregated crash and performance logs from the running app.
We will update this list when we add, remove or change a subprocessor. Material changes are announced under Section 26.
International data transfers
The Service is operated from the Republic of Cyprus (a European Union member state). The primary application database and uploaded media live in AWS infrastructure inside the European Union. Some subprocessors operate from the United States and other jurisdictions (notably Stripe, Auth0 and OpenAI).
Where data leaves the EEA, the UK or Switzerland, we rely on the following safeguards to keep the level of protection consistent with EU law:
- European Commission's Standard Contractual Clauses (SCCs) with each subprocessor that does not benefit from an adequacy decision;
- UK International Data Transfer Addendum, where applicable;
- The Swiss FADP-compliant version of the SCCs, where applicable;
- As an EU member state, Cyprus applies the GDPR directly, so intra-EU transfers of your data do not require additional safeguards.
A copy of the SCCs used with any subprocessor is available on request to privacy@dearjane.me.
Data retention
We hold personal information only as long as we need it:
- Active accounts
- For as long as your account is open. You can edit or delete most fields yourself at any time.
- Closed accounts (grace window)
- Up to 30 days after closure, to allow you to undo accidental deletion. After that, identifying data is purged from production.
- Messages
- For as long as both participants still have an account. When either side deletes their account or a conversation, the messages become inaccessible from the Service.
- Payment records
- Up to seven years after the transaction, as required by tax and accounting law in the operating jurisdiction.
- Abuse, safety & ban records
- Up to two years after the closure of an account, to enforce a ban, prevent re-registration, defend against legal claims, or respond to regulators.
- Fraud signals
- Hashed device, IP and email signals associated with confirmed fraud may be retained indefinitely as part of an anti-fraud blocklist.
- Backups
- Encrypted backups roll off on a 30-day cycle. Deleted data is fully purged from the backup chain by the end of that cycle.
- Logs & analytics
- Raw application logs: up to 90 days. Aggregated analytics: indefinite, in non-identifying form.
Where the law requires us to retain a record for longer than the periods above, we will. Where you ask us to delete data and law prevents us from doing so, we will tell you why.
Security
We protect personal information with:
- Transport encryption — HTTPS only, modern TLS, HSTS;
- Storage encryption — disk-level encryption for media, database and backups;
- Authentication — handled by Auth0, with optional multi-factor authentication;
- Access control — least-privilege roles for engineering and support staff; audited admin actions;
- Payment isolation — your card details are entered into Stripe's iframe and never touch our servers;
- Hardening — automated dependency patching, vulnerability scanning, web-application firewall, rate limiting, anti-bot protection;
- Monitoring — anomaly detection, abuse heuristics, log review.
No security measure is perfect. If you believe your account has been compromised, write to security@dearjane.me immediately.
Your rights (everywhere)
The following rights apply to every Member, regardless of where you live, as a matter of our internal policy:
- Access the personal information we hold about you;
- Correct anything that's inaccurate;
- Delete your account and the personal information attached to it (see Section 16 for the limited retention windows);
- Export a portable copy of your data;
- Withdraw consent to marketing or optional analytics at any time;
- Object to processing carried out under our legitimate interest;
- Complain to a data-protection authority (we list how below).
See Section 22 for how to exercise them.
Rights under the GDPR & UK GDPR
If you are in the EEA, the UK, or Switzerland, you have specific rights:
- Article 15 — Right of access: get a copy of your data, plus information about how we process it.
- Article 16 — Right to rectification: correct inaccurate data.
- Article 17 — Right to erasure: have your data deleted, subject to legal exceptions.
- Article 18 — Right to restriction: limit processing while a dispute is being resolved.
- Article 20 — Right to data portability: receive your data in a portable, machine-readable format.
- Article 21 — Right to object: object to processing based on legitimate interest. We will stop, unless we can demonstrate compelling legitimate grounds that override your rights.
- Article 7(3) — Withdraw consent: withdraw any consent at any time; this does not affect processing already carried out.
- Article 77 — Right to lodge a complaint: with your local supervisory authority. The full list is at edpb.europa.eu; the UK ICO is at ico.org.uk.
Our EU representative under GDPR Art. 27 will be appointed before we offer the Service to EEA users. Until that happens, write to dpo@dearjane.me.
Rights under Cypriot data-protection law
If you are resident in the Republic of Cyprus, you benefit from the GDPR (which applies directly in Cyprus) together with the Cyprus Personal Data (Processing) Law of 2018 (Law 125(I)/2018). In particular you may:
- exercise every right listed in Section 18 (access, rectification, erasure, restriction, portability, objection, and the right not to be subject to solely automated decisions);
- refuse to receive direct-marketing communications at any time;
- lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (dataprotection.gov.cy) if you believe your rights have been violated.
Direct-marketing communications from us include an opt-out link. You can also write to privacy@dearjane.me at any time to opt out of direct marketing.
California residents (CCPA & CPRA)
If you are a California resident, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, gives you additional rights:
- Right to know: which categories of personal information we have collected, the sources, the purposes, and the categories of recipients.
- Right to delete: ask us to delete your personal information, subject to legal exceptions.
- Right to correct: ask us to correct inaccurate personal information.
- Right to opt out of "sale" or "sharing": we do neither, but if we ever did you would be able to opt out. We honour the Global Privacy Control signal as an opt-out request under California law.
- Right to limit the use of sensitive personal information: ask us to limit our use to what is necessary to provide the Service.
- Right to non-discrimination: we will not deny you the Service, charge you a different price, or provide a different quality of service because you exercised any of these rights.
Categories of personal information collected in the last 12 months (per Cal. Civ. Code §1798.140(v)):
- Identifiers (name, email, IP, user ID);
- Records described in Cal. Civ. Code §1798.80(e) (billing address, payment card last 4);
- Characteristics protected under California or US law (age, sex, marital status — only to the extent you provide them);
- Commercial information (Membership purchases);
- Internet/electronic activity (interactions with the Service);
- Geolocation data (city-level, derived from IP);
- Audio, electronic, visual information (photos, voice notes, messages you choose to send);
- Sensitive personal information: account credentials, contents of your communications, and any sexual-orientation information you choose to disclose on your profile;
- Inferences drawn from the above to rank your feed and prevent fraud.
You can authorise an agent to exercise these rights on your behalf by sending us a signed authorisation. We will verify your identity by matching the request to the account on file.
How to exercise your rights
For most rights, the fastest path is from inside your account: Settings → Privacy & data. For anything that isn't available there, write to privacy@dearjane.me from the email address on file and tell us which right you are exercising.
We respond within 30 days. If the request is complex or we have a high volume, we may extend this by up to another 60 days and will tell you in advance.
To protect against impersonation, we may ask you to confirm a piece of account-only information, complete a fresh login, or respond to a confirmation email. We don't ask for government ID for routine requests.
We do not charge a fee for handling a request unless it is manifestly unfounded or excessive — in which case the law allows us to charge a reasonable fee or refuse to act.
Data-breach notifications
If we suffer a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of it, in line with GDPR Art. 33 (which applies directly in Cyprus). If the risk is high, we will also notify you directly — by email and/or in-product notice — without undue delay.
Minors
Dear Jane is strictly an 18+ Service. We do not knowingly collect personal information from anyone under 18, and we do not target the Service to anyone under 18. Where US law applies, this includes compliance with the Children's Online Privacy Protection Act (COPPA) for under-13s.
If you believe a minor has created an account, write to safety@dearjane.me with any details you can share. We will remove the account and associated data promptly.
Do Not Track & Global Privacy Control
Many browsers send a Do Not Track (DNT) header or a Global Privacy Control (GPC) signal. We respect a GPC signal as an opt-out of any "sale" or "sharing" of personal information under California law (we don't currently do either, but the opt-out is honoured by default).
Browser DNT signals are still inconsistent across vendors; where we can interpret them, we treat them as an opt-out of optional analytics cookies.
Changes to this Policy
We may update this Policy from time to time. When changes are material — including any change in the categories of data we collect, the purposes we collect them for, the subprocessors we use, or your rights — we will tell you by email and/or in-product notice at least 14 days before they take effect. We will also keep the prior version linked here for transparency.
Continued use of the Service after the effective date constitutes your acceptance of the updated Policy.
Contact, DPO & EU representative
- Registered office
- Dear Jane — Griva Digeni 66, 6045 Larnaca, Cyprus
- Privacy & data requests
- privacy@dearjane.me
- Data Protection Officer
- dpo@dearjane.me
- EU representative (GDPR Art. 27)
- Not required — the controller is established in an EEA member state (Cyprus). Contact the DPO above for GDPR requests.
- UK representative (UK GDPR Art. 27)
- To be appointed prior to opening UK registration. Until then, contact the DPO above.
- Supervisory authority (lead)
- Office of the Commissioner for Personal Data Protection of the Republic of Cyprus — dataprotection.gov.cy
- Safety reports
- safety@dearjane.me
- Security disclosures
- security@dearjane.me
- General support
- support@dearjane.me