WingvoyAI matchmaker

Privacy Policy (draft)

Draft: a first version that no lawyer has reviewed.

Drafted 2026-10-07

A first draft that no lawyer has reviewed. It lists what the service really collects, sends and deletes; legal bases and country-specific requirements are added after review. Items in [brackets] are not decided yet.

1. Who is responsible

[operator name: not set]

[address: not set]

Privacy requests: [support email: not set]

2. What we collect

  • Account: your email address and when you signed up.
  • Profile: nickname, matchmaker's name, the country you live in (state or province for the US and Canada), time zone, languages you can talk in.
  • Conditions (which can be sensitive information): your gender, the genders you would like to meet, year of birth, the age range and regions you want, smoking, drinking and what you are looking for, answers to the taste questions.
  • Cards: the short texts you confirmed (public cards, and private judgment cards only you and your matchmaker use).
  • Drafts your AI app sends (cards and taste answers): kept only as drafts, and not used for matching, until you confirm them in Wingvoy; deleted after 48 hours if you do not. We do not receive your conversations with your AI app.
  • Missions and conversations: the length of a mission and how many conversations it used, the conversations between AI matchmakers (shown by alias only), each matchmaker's assessment, introduction reports, your acceptance or refusal and the nickname and contact detail you wrote.
  • Photo (optional): one photo you took with the camera in the Wingvoy screen (encrypted). It is stored only if you agree to the photo consent, and shown only to a member you are introduced to who has added a photo too, while the two of you decide on the introduction. The purpose is to let each of you see the other before deciding whether to accept. It is never part of a conversation, report or summary, and is never sent to the AI model provider or to an AI app. No AI looks at it, there is no face recognition, and it plays no part in matching. It is deleted 30 days after it was taken, when you delete it, or with your account. While a report that may concern it is open, it is shown to nobody until a person has settled the report. If you have a photo when such a report comes in, a copy of the photo as it was then (encrypted) is kept with that report, apart from your photo, to handle the report. Only the person handling the report can see the copy, after giving a reason, and each view is recorded; it stays until the report is settled even if you delete or retake your photo, its own period ends, or you delete your account. It is deleted when the report is dismissed, or kept with the settled report for 365 days if action was taken. The copy of your data says whether you have a photo and its dates, without the image.
  • Consent records: which wording you agreed to and when (you are identified only by a keyed hash).
  • Age check: when it was confirmed and a keyed hash of the identifier the provider gave for you. We do not receive your name, number or documents.
  • Invite: if you joined with an invite code, that fact and when (the code only as a keyed hash), and the circle of everyone who joined with the same code.
  • Country check: the country your browser connected from (a country code), when it was last seen, and a keyed hash of that address. The address itself is not stored, and the sign-in record (session) holds no address or browser details either.
  • Reports and blocks, what you wrote in a report, for an automatic safety stop the matchmaker line or card the check saw (encrypted), and your answer a week after a connection (yes, not yet, no).
  • Logs: the path, result and time of a request, and the name and kind of error of a feature that failed. No content, query, token or address. Counts of use and model cost (members only as keyed hashes).
  • The text of mails we send is not kept on our servers; sign-in and confirmation codes are kept only as keyed hashes.

3. What we use it for

  • Providing the service: matchmakers talk using your cards, then introduce and connect.
  • Safety: age checks, handling reports, preventing abuse, spending limits.
  • Keeping the service to the countries where it is open: no mission can start while your browser's country differs from the one you chose, and an account that has started nothing is deleted on the spot if it is opened from a country that is closed.
  • Telling you things: an introduction has arrived, a reminder before it ends, a connection, the evening summary (only if you turn it on), a new AI app connected (a security alert you cannot turn off).
  • Statistics to improve the service: how much each feature is used (counts that do not point to a member).

4. Sensitive information

Your gender and the genders you want to meet can suggest sexual orientation. They are stored encrypted and saved as conditions only after you agree separately. You can withdraw that agreement at any time by deleting your conditions in Settings, which also ends a running mission.

Your conditions are never shown to other members, the matchmakers are told to speak without gender words, and a card that holds one is sent back to be rewritten. But conversations and introductions open only between members whose conditions match both ways, so a member whose matchmaker talks with yours or who is introduced to you can tell that you are open to meeting their gender, and if they look for only one gender they can infer yours. The full list of genders you look for is never shown to anyone. We cannot promise more than that.

5. Who sees what

  • Other members: when you are introduced they see your alias and the introduction report (what fits, what to watch, topics for a first conversation). If both of you switched watching on, they can replay your matchmaker's lines (Terms, section 6). Only after both of you accept do they see the nickname and the one contact detail you wrote. They do not see your name, your email, or cards you did not share.
  • Your private judgment cards and your matchmaker's assessment of the other person are not shown to any other member; the AI model provider reads them to write the assessment (section 6). They are not part of any request made for the other matchmaker.
  • The operator: there is no tool for opening conversations. What a reporter wrote in a report opens only when someone gives a reason, and the opening is recorded. A legal request follows its own procedure, and for it the operator can read a decrypted copy of one member's data; each reading needs a stated reason and is recorded.

6. Who processes it for us, and transfers abroad

  • AI model provider Anthropic, PBC (United States): receives card texts, matchmaker conversations and what is needed to write assessments and reports. It does not receive names, emails, contact details or age-check information, and members are replaced by aliases. [Retention and training terms are written after the contract is checked.]
  • Hosting and database: [provider and region are written after the contract]. The encrypted columns (section 9) are stored as ciphertext.
  • Email delivery: [provider and region are written after the contract]. Every mail we send passes through it: your email address, sign-in and confirmation codes, the text of a notice (nothing about another member) and, when you ask for “a copy of my data”, that copy in the body of the mail as plain text.
  • Age-check provider: [written once one is used]. We receive only whether you are an adult and an identifier of the person.
  • The AI app you use (for example Claude) is a separate service you connect yourself.

7. How long we keep it

  • Card drafts and taste answer drafts you did not confirm: 48 hours.
  • Confirmed cards, conditions and profile: until you delete them or your account.
  • Conversations that did not become an introduction: 30 days after both missions closed. Conversations that did, and the introduction records: 90 days after the introduction ended.
  • Mission records: 90 days after they close.
  • Contact details: deleted the moment an introduction ends without a connection; 30 days after a connection.
  • The words of a practice conversation: 7 days.
  • Your photo: 30 days after it was taken (or when you delete it, if sooner). A copy kept to handle a report: until the report is dismissed, or 365 days after it was settled if action was taken.
  • That two members were introduced, or that either matchmaker judged them not to fit (a keyed hash): one year. Model cost records: one year.
  • Reports once they are settled: 365 days. Expired sign-in sessions: removed every hour.
  • Consent records (proof of which wording you agreed to, as a keyed hash): no end date has been set yet.
  • Job records: 7 days after they finish. Age-check tries and confirmation codes: 7 days.
  • When a member whose age was checked deletes their account, a keyed hash of that check and the numbers of their conversations are kept for 90 days, so that the same person cannot open a new account straight away. A report on one of those conversations in that time lengthens it to 365 days. Nothing else about them is kept.
  • Records of what the operator did (audit log): 2 years.
  • While a report is open or a legal hold is in place, the records concerned are not deleted.

8. Your rights and how to use them

  • Access and a copy: ask for “a copy of my data” in Settings; after you confirm a mailed code we email you your data. It does not hold what other members wrote, the conversations between matchmakers, introduction reports or your matchmaker's scores of other people, because they are mostly about other people; write to the address below for anything else.
  • Deletion: delete your account in Settings and your profile, cards, conditions and missions are deleted. What has already been given to another member stays with them for the periods above, and consent records and the operator's records (audit log) stay for the periods in section 7.
  • Withdrawing consent: delete your conditions, turn off watching, turn off keep looking, delete your photo, disconnect an app or turn off notices in Settings.
  • Explanations and objections: follow the procedure on the AI notice page.
  • Anything else: [support email: not set]. You also have the right to complain to a supervisory authority.

9. How we protect it

Stored encrypted: your gender and the genders you look for, answers to the taste questions, cards, conversations, reports, contact details, the nickname other members see and your photo. Your email, profile nickname, year of birth, age range and regions, and lifestyle answers such as smoking and drinking are not encrypted; access to them is restricted. The database account the service runs as cannot change the schema or alter the audit log, and the production server checks this when it starts and does not start otherwise. Logs hold no content. If a breach is suspected we establish its scope and notify within the required time.

10. Children

People under 19 (counted by year: this year minus the year of birth below 19) cannot use the service. If an age check shows a minor, the account and data are deleted at once; if a report or the automatic safety check suggests it, the account is stopped at once and deleted as soon as a person has confirmed it.

11. Cookies

One cookie that keeps you signed in. No advertising or tracking cookies.

12. Changes

Changes are posted on this page with a date; important ones are also mailed to you.