likealityBack to Home

Privacy Policy

Last updated: September 1, 2026. This draft describes how the product actually works today. It was written by the operator, not by lawyers, and requires jurisdiction-specific legal review before launch.

1. Information we process

We process account and profile information, authentication records, settings, messages and posts you choose to send, reports, verification status, device/session data, and coarse H3 location cells. We do not store or expose exact GPS coordinates. We do not intentionally collect sensitive identity or sexual-preference details outside the fields and controls clearly presented in the product.

2. How we use information

We use information to authenticate members, provide discovery and messaging, enforce SFW/after-dark access controls, process reports, prevent abuse and fraud, conduct verification, provide support, secure infrastructure, measure reliability, and comply with law. We do not sell personal information. We do not use verification media or private messages to build advertising profiles.

3. Verification media

Verification submissions are restricted to authorized processing and review. We aim to minimize source media and model output; raw prompts, transcripts, biometric templates, and sensitive inferences are not product profile fields. A provider outage fails closed rather than silently approving a submission. Retention periods, providers, and regional processing will be published or disclosed before production launch.

4. Sensitive data and our legal basis

Some of what this product exists to hold — sexual orientation, relationship structure, and kink interests — is special category personal data under the UK/EU GDPR and comparable regimes. We process it only on the basis of your explicit consent, given by choosing to enter it. It is encrypted, hidden by default, excluded from analytics, and never written to logs. You can remove it at any time, and withdrawing it does not affect the lawfulness of processing before withdrawal.

For everything else our bases are: performing our contract with you (running your account, discovery, messaging, purchases); legitimate interests (security, abuse prevention, service reliability, defending claims), balanced against your rights; consent (optional features and notifications); and legal obligation (child-safety reporting, tax and accounting records, lawful requests).

5. Automated decisions in verification

Verification is assessed first by an automated model and then placed in a human review queue. An automated approval grants access provisionally; a member of staff reviews it afterwards and can revoke it, which requires you to verify again. An automated rejection never becomes final on its own.

Because this decision affects your access to the service, you have the right to obtain human intervention, to express your point of view, and to contest the outcome. Write to appeals@likeality.com. We do not use verification media for advertising, profiling, or training models on identifiable people.

6. Where your data is processed

Our database and authentication run in Supabase (AWS, Mumbai, India). Our application and media-processing services run on Google Cloud Run (Singapore). Uploaded media is stored in Cloudflare R2. Payments are handled by Razorpay (India) or PayPal (elsewhere), which receive only what they need to take a payment.

If you are in the UK, EEA, or another region with transfer restrictions, your data is transferred outside that region to the locations above. Where required we rely on Standard Contractual Clauses or the equivalent mechanism with each provider. Ask privacy@likeality.com for details of the safeguards in place.

7. Sharing

We share information with infrastructure, authentication, storage, moderation, security, and payment providers only as needed to provide the service; with moderators when review requires it; and with authorities, advisers, or successor entities when legally required or necessary to protect people, investigate abuse, or complete a corporate transaction. Providers must receive only the data needed for their role.

8. Location and visibility

Discovery uses coarse H3 cells and bucketed distance labels. Verification, after-dark settings, RLS policies, and content moderation affect who can see or contact whom. No privacy control can make an offline meeting risk-free; do not disclose an address or meet without your own safety plan.

9. Retention and deletion

You can delete your account from Settings. Personal profile content, messages, media, memberships, and verification submissions are removed through the account lifecycle workflow, subject to backups, fraud prevention, legal holds, unresolved disputes, and narrowly retained de-identified moderation evidence. We delete or de-identify data when its purpose and required retention period end.

10. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object, export, or complain about processing. Contact privacy@likeality.com. We may verify requests to protect accounts and may retain information required by law.

11. Breach notification

If a breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it where that obligation applies, and tell affected members without undue delay when the risk is high. We will say what happened, what data was involved, and what you should do.

12. India — Digital Personal Data Protection Act

If you are in India, you are a Data Principal and Likeality (operated by Foundational Creations) is the Data Fiduciary. You may access, correct, complete, update, and erase your personal data, nominate another person to exercise your rights, and raise a grievance. Contact our Grievance Officer at grievance@likeality.com; we aim to respond within the statutory period. If unsatisfied, you may complain to the Data Protection Board of India.

13. Security and changes

We use access controls, RLS, encryption in transit, private storage patterns, audit logging, and least-privilege service credentials, but no system is perfectly secure. We may update this policy as the product changes and will post the effective date.