Privacy Policy

Last updated: April 28, 2026

Who we are

Date to Marry ("we", "us", "our") is a serious, marriage-first matchmaking platform available at datetomarry.app, owned and operated by Pila Studio UG (haftungsbeschränkt), a company with limited liability registered in Germany. Pila Studio UG (haftungsbeschränkt) is the data controller responsible for your personal data under applicable data protection law, including the EU General Data Protection Regulation (GDPR). We are committed to protecting your privacy and being transparent about what data we collect and why.

What we collect

When you use Date to Marry, we collect:

  • Account information: Email address, first and last name, date of birth, gender, and city.
  • Onboarding answers: Life Architecture responses (children, faith, location, timeline, finances) and Character & Values responses (up to 39 written, voice, or video prompts).
  • Identity verification: Government-issued ID documents and selfie images are submitted through our verified identity provider. These are used solely for verification and are not stored on our servers after verification is complete.
  • Photos and media: Profile photos and intro video you choose to upload, stored securely on DigitalOcean Spaces.
  • Voice messages: Audio recordings you send in conversations, stored with private access controls.
  • Conversation data: Messages, guided discovery responses, and match interactions.
  • Usage data: App activity, device type, operating system version, and crash reports (collected anonymously via Firebase Crashlytics).
  • Push notification tokens: Device tokens for delivering match and message notifications.

How we use your data

  • To match you with compatible members using our AI-assisted compatibility engine
  • To facilitate guided discovery conversations between matched members
  • To deliver push notifications for matches, messages, and important updates
  • To maintain community safety through behavioral review and reporting systems
  • To improve the product through anonymised, aggregated analytics (PostHog)
  • To communicate with you about your account, your matches, and platform updates

What we never do

  • We never sell your data to anyone. Ever.
  • We never share your personal information with advertisers.
  • We never use your data for targeted advertising.
  • We never display your profile or answers publicly, they are only visible to your assigned match.
  • We never store your identity verification documents after verification is complete.

Where your data is stored

Your account data is stored on PostgreSQL databases hosted on DigitalOcean, with encrypted connections and row-level security. Media files (photos, voice notes) are stored on DigitalOcean Spaces using private access controls, they are never publicly accessible. All data transmission uses HTTPS/TLS encryption.

Conversation privacy

Your guided discovery prompt responses and in-app messages are end-to-end encrypted in transit and stored with strict access controls. Match journal entries and monthly check-in responses are private to you and are never shared with your match or any third party. Voice notes are stored using private presigned URLs, only authenticated users with the relevant match can access them.

Behavioral review data

After a match concludes, members submit anonymous behavioral reviews. This data is used to maintain community safety, adjust trust scores, and improve matchmaking. Reviews are never shown to the person they describe. Safety-flagged reports are reviewed by our Trust & Safety team.

Analytics

We use PostHog to understand how members use the app. Analytics data is anonymised and aggregated. We use Firebase Crashlytics for crash reporting, crash logs contain device information and error traces but are not linked to your personal identity. Both tools operate under data processing agreements with us.

Money, and who we tell

The Pledge Agreement sets out what you pay and how the Guarantee returns it. Two parts of that process involve someone other than you, and you should know about both before you pledge rather than after.

Your vouchers are told when you claim. If you ask for your Pledge back, we notify the two people who vouched for you that a claim has been made, and invite them to confirm it. We ask for your consent to this separately when you pledge, and you can withdraw that consent at any time. Withdrawing it cannot cost you your claim — if your vouchers do not reply, or you have told us not to contact them, your claim proceeds on your own statement. We will not let another person's silence decide whether you get your money.

We check our own records against your claim. Because we introduce you to other members, we hold both sides of every match. When you claim, we look at whether anyone you were matched with has recorded a continuing relationship with you. Our basis for this is our legitimate interest in preventing fraud, and it is narrow by design: we never tell you what another member recorded, and we never tell them what you claimed. Where our records and your statement disagree, a person reviews it and you are told the outcome.

If you are engaged and choose to share your story with future members, we ask separately and use only what you approve.

Identity and where you live

Your membership price depends on the country that issued your identity document. We read that country from the verification result and store the two-letter code on your profile. We do this rather than asking you, or guessing from your location, because a price that anyone could change by moving a setting would not be a price at all. It is also used to match you with people nearby, and with people elsewhere if you turn on matching abroad.

Data retention

  • Active account data is retained while your account is active.
  • Behavioral review records are retained for 18 months for safety purposes.
  • When you delete your account, your personal data is permanently deleted within 30 days.
  • Identity verification documents are not retained after verification is complete.
  • Records of payments are the one exception. German commercial and tax law (§ 147 AO) requires us to keep them for up to ten years, so they survive account deletion. They contain what you paid and when, not your profile or your conversations. This does not affect your right to claim the Pledge Guarantee — keep your membership reference and write to us.

Your rights

You have the right to:

  • Access: Request a copy of all data we hold about you
  • Correction: Ask us to update or correct your information
  • Deletion: Delete your account and all associated data from within the app, or by emailing us
  • Portability: Request an export of your data in a machine-readable format
  • Opt out: Unsubscribe from communications at any time
  • Complain: Lodge a complaint with a data protection supervisory authority if you believe we have processed your data unlawfully

To exercise any of these rights, email us at hello@datetomarry.app or use the account deletion option in the app. We will respond within 30 days.

Children

Date to Marry is intended for adults aged 18 and older. We require identity verification to confirm age. We do not knowingly collect data from anyone under 18. If we learn that we have, we will delete it immediately.

Changes to this policy

We may update this policy as the platform evolves. If we make significant changes, we will notify you by email and in-app notification. The "last updated" date at the top of this page indicates when this policy was last revised.

Contact

Questions about this policy or your data? Contact us at hello@datetomarry.app.