Privacy
Privacy policy
This privacy policy explains how we process personal data in connection with this website and its app. The Swiss Data Protection Act (revDSG) and the EU General Data Protection Regulation (GDPR) apply where relevant.
Responsible entity
The party responsible for processing your personal data is:
Which data we process
- Account data: name, email address, password hash, profile name.
- Profile data: profile picture, header image, gender, age, sexual orientation, interests, links and visibility settings.
- Particularly sensitive data: voluntary information about sex life or sexual orientation as well as intimate content, interactions and preferences that may be inferred from them.
- Verification data: selfie, identity document image, verification status and AgeVerif results. Depending on the verification method used, biometric characteristics may be technically processed.
- Content data: uploads, image captions, comments, stories, chats, reports or other content you provide.
- Location data: if you provide a location or use the map feature.
- Usage and device data: IP address, date/time, visited pages, browser/OS, log files.
- Communication data: contents of contact requests or support communications.
- Cookie and storage data: login cookies and local settings (e.g. discreet mode).
Legal bases and explicit consent
- Contract and pre-contractual measures: account, profile, Club functions, support and enforcement of the Terms of Use.
- Explicit consent: processing voluntary information about sex life, sexual orientation, intimate content and verification data where legally required.
- Consent: optional analytics and marketing services and location access.
- Legitimate interests: IT security, fraud prevention, abuse prevention, moderation and secure development of the platform where your rights do not override those interests.
- Legal obligations and legal claims: handling illegal content, authority requests, preservation of evidence and defence of claims.
You may withdraw consent at any time for the future. Withdrawal does not affect the lawfulness of earlier processing. If sensitive information is necessary for a core function you requested, that function may no longer be available after withdrawal.
Purposes of processing
- Provision, operation, and security of the platform.
- Creation and management of user accounts and profiles.
- Providing uploads, feeds, maps, and community features.
- Communication with you (e.g. service messages, support).
- Analysis and optimization of usage (e.g. via Hotjar).
- Compliance with legal obligations and enforcement of our terms of use.
Data sharing and processors
We only share personal data when it is necessary to operate the platform, when you have consented, or when there is a legal obligation. Typical recipients include:
- Hosting & infrastructure: cyon & Cloudflare.
- Email delivery: cyon (E-Mail-Server).
- Age verification: AgeVerif for external age checks and internal manual review for selfie + identity document.
- Media delivery: Cloudinary where content is stored or delivered through this service.
- Communications: Twilio where SMS or communications functions are used.
- Analytics: Hotjar (usage analysis, session insights).
- Analytics and marketing after consent: Google Analytics / Google Ads and Meta Pixel.
- Maps: OpenStreetMap (map tiles), Leaflet (map library).
We contractually review service providers and limit access to the necessary purpose. If the providers used change materially, we update this page.
International data transfers
Some service providers may process data in countries outside Switzerland and the EEA. We ensure that appropriate safeguards are in place (e.g. adequacy decisions, standard contractual clauses, or comparable measures).
Cookies, local storage, and tracking
We use necessary cookies and similar technologies to log you in, store settings and secure our services. Analytics and marketing services are blocked server-side and load only after your active choice.
- Necessary cookies: login, security features, session management.
- Local storage: e.g. your discreet mode in
localStorage. - Analytics cookies: to improve the user experience (see Hotjar section).
You can change your choice at any time through “Privacy settings” in the footer. After withdrawal, optional services no longer load and identifiable first-party tracking cookies are removed. Necessary cookies cannot be disabled while required for login and security.
Hotjar (usage analytics)
We use Hotjar to understand and improve website usage. Hotjar can capture clicks, scrolls, device type, browser information, and technical data. The specific data collected depends on our Hotjar settings.
Hotjar loads only if you explicitly allow analytics. You can withdraw your choice at any time through the privacy settings.
Maps & location
For the map view we load map tiles from OpenStreetMap. Your IP address may be transmitted to this provider. If you use the Bij mij in de buurt feature, your browser asks for your location. The location is only processed if you consent.
Public content and visibility
Content you publish (e.g. uploads, descriptions, profile details) can be public or visible to other users depending on your visibility settings. Please do not share sensitive data if you do not want others to see it.
Retention period
- Account, profile and content data: until the account or content is deleted; active systems are generally cleared within 30 days.
- Selfie and identity document: deleted immediately after successful approval; pending or rejected manual checks are automatically cleared after no more than 14 days.
- AgeVerif result: status and necessary evidence data until the account ends; short-term technical verification data for no more than two days.
- Server and security logs: generally up to 30 days, exceptionally longer for a security incident or legal claim.
- Illegal-content notices and moderation records: generally three years after closure unless a longer legal duty or ongoing claim applies.
- Security backups: overwritten according to the regular backup cycle and used only for disaster recovery.
Automated checks and moderation
Safety rules may automatically flag, hide or prioritise content. Age verification may include automated checks. Decisions with significant effects can be reviewed by an authorised person on request. We do not use sensitive data for fully automated advertising decisions.
Minors
The platform is intended exclusively for people aged 18 or older. If we learn that data relating to a minor is being processed, we block access, preserve required evidence and delete the data according to applicable law.
Data security
We take appropriate technical and organizational measures to protect personal data against loss, misuse, and unauthorized access. This includes access restrictions, encryption, and regular security updates.
Your rights
Under the Swiss DPA and, where applicable, the EU GDPR, you have in particular the right to access, rectify, erase, and receive or transfer your data, provided the legal requirements are met.
To exercise your rights, please contact us using the contact details below.
Contact for privacy requests
Email: [email protected]
You can also contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where applicable, a competent data protection supervisory authority in the EU/EEA.
Changes to this privacy policy
We update this privacy policy when our processing changes or new legal requirements apply. The current version is always available on this page.