Privacy policy
The short version
- We collect what a dating app needs to work, and we have tried hard not to collect anything else
- We do not sell your data. We do not share it for advertising. There is no advertising in this app
- Your verification selfie is looked at by a person and then deleted. We do not make a faceprint of you
- We never know exactly where you are. We store a postal code and a rounded centre point for it
- You can delete your account yourself, from inside the app, and we mean it when we delete it
- Your messages are private between you and the other person, and staff can read them only when one of you reports the conversation, which is written down with the name of the person who read it
This policy covers the Chai for Two app, run by Semper Labs LLC, a New Jersey company. It applies to members in the United States and Canada.
1. What you give us
- Your email address, to sign in. We use a code sent to your email rather than a password
- Your first name, date of birth, gender, and who you would like to meet
- A postal code, and the country it is in
- Photographs of yourself, at least four
- A verification selfie, in a pose we choose at random
- Your answers to profile prompts, a tagline, and anything you choose to write about yourself
- Optional details such as heritage, languages, faith, education, career, height, orientation, where you were raised, and the other profile questions we ask. Every one of these can be left blank
- An Instagram or Snapchat handle, if you add one. These are shown only to someone you have matched with, never on a profile you are browsing
- Messages you send to people you have matched with
- Reports you make about other members, and anything you tell us by email
Some of that is sensitive: faith, and in some places heritage and orientation. Those fields are optional, they are marked optional where we ask for them, and you can clear them at any time from Edit profile. If you fill them in, other members can see them on your profile.
2. What we collect on our own
- When you were last active, which decides whether your profile is still shown to people
- Who you sent chai to, who you passed on, and who you blocked or reported
- How many profiles you have seen today, to enforce the daily limit
- Which of three ways you ran out of profiles on a given day, as a count with a date and no time of day, so we can tell whether the daily limit is the right number. Once the day is over this becomes a total for everybody with nothing about you in it, and the row tied to you is deleted after 180 days
- Ordinary technical logs from our hosting provider, which include an IP address, needed to run the service and to deal with abuse
We do not use advertising identifiers. There are no third party trackers, no analytics SDK, and no advertising SDK in this app.
Some things are kept on your device rather than sent to us: what keeps you signed in, your travel setting and whether you have already seen a particular notice. Deleting the app removes all of it. The app does not use cookies, because it is not a web page.
3. Location, and how little of it we hold
Distance matters in a dating app, so we need a rough idea of where you are. We do it with the least precision that works.
- You type a postal code, or you tap Use my location and your phone gives us one coarse reading
- If you use the reading, it is turned into a postal code on your phone, against a table already inside the app. It is not sent to Apple, Google, or anybody else
- Before it goes anywhere it is rounded to a grid of about 1.4 miles
- What we store is a postal code and the centre point of that area. Not your address, not your street, and not where your phone is now
- You can always type a postal code instead. Location permission is never required
Because your home postal code decides which people you are shown to, it can only be changed once every 90 days.
4. What other members can see
Your first name, age, photographs, tagline, prompt answers, roughly how far away you are, and whichever optional fields you filled in. Your exact date of birth, your postal code, your email address and your last active time are never shown to another member.
5. Your verification selfie
This is the most sensitive thing we ask for, so it gets its own section.
- It is stored separately from your profile photographs, in a place other members cannot reach at all
- A person on our team looks at it beside your profile photographs and decides whether it is the same person
- It is deleted as soon as that decision is made. The staff screen says so to the reviewer: deciding is the last moment it can be seen
- Every look at it is recorded, with the name of the person who looked
We do not run face recognition on it. We do not compute a faceprint, a face template, a face geometry measurement, or any other biometric identifier, and we do not keep one. The comparison is made by a human being with their eyes. If that ever changes we will ask you first, separately, and this section will change before it does.
6. Your messages
Messages between matched members are stored so the app can show them to you both. They are not encrypted in a way that stops us reading them, and we will not pretend otherwise.
- Staff do not read conversations as a matter of routine and have no way to browse them
- A conversation can be opened only when one of the two people reports it
- Opening a reported conversation writes a line naming the member of staff who opened it, which cannot be edited or deleted
- The chat is text only, by design. You cannot send a photograph in a message, which is why an unwanted explicit image is not possible here
7. Why we hold any of it
- To run the service: to make your profile, show you people, and let you talk to them
- To keep the pool honest: verification, and taking inactive accounts out of rotation
- To keep people safe: reports, blocks, moderation and suspensions
- To meet legal obligations, and to establish or defend legal claims
- To decide product questions with a measurement rather than a guess, using counts that do not name anybody
We do not use your information to build an advertising profile, and there is nothing in this app that would let us.
8. Who else touches it
A short list, and it is the whole list. Each of these processes data on our instructions and for nothing else.
- Supabase, which hosts our database and stores photographs
- Cloudflare, which serves our web addresses and protects them
- Brevo and Zoho, which send the sign-in code and any email we write to you
- Apple and Google, if you buy a membership. They bill you, not us, and we never see your card
- RevenueCat, which confirms with Apple or Google that a membership has been paid for and tells us. They see your account id and which plan you bought, never your card
We also share information where the law requires it, or where it is necessary to deal with a serious safety matter, and we would tell you about it unless we are prohibited from doing so.
We do not sell personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in United States privacy law. We never have.
9. Where it is kept
On servers in the United States. If you are in Canada, your information is transferred to and stored in the United States, and may be accessible to United States authorities under their law. By using the app you understand that. We apply the same standard to everybody wherever they live, rather than a weaker one for people whose local law asks for less.
10. How long we keep things
These are the actual periods, and they are enforced by the system rather than by somebody remembering.
- Your verification selfie: deleted as soon as a reviewer decides on it
- A photograph you remove from your profile: deleted 21 days later. The delay exists so that a photograph somebody reports is still there to be looked at
- Your account after you ask us to delete it: 21 days, in which signing back in cancels the deletion, then it is purged
- An account nobody has opened for about eighteen months: we email twice, at a month and at a week, then close it and delete it. Opening the app at any point stops the countdown, and we never close an account that is paying
- A match where neither of you ever spoke: ended after 14 days, and you both go back into each other’s pool
- A conversation that goes quiet: archived after 30 days, and closed after about six months
- Messages: deleted 30 days after a match ends
- Your profile stops being shown to anybody after 30 days without opening the app, and comes straight back when you return
- Counts of how you ran out of profiles: the rows tied to you are deleted after 180 days. A daily total with no member id in it is kept, so we can see how the app is doing over years without keeping anything about you over years
- Reports, and the record of what staff did about them: kept while they are needed for safety and for legal claims. An accountability log that could be emptied would not be one
11. Your choices
- See and change nearly everything about your profile, from Edit profile
- Take a break, which hides your profile and is reversible
- Delete your account from inside the app, without emailing anybody or explaining why
- Ask us for a copy of what we hold about you, or ask us to correct it, by writing to [email protected]
- Block anybody, at any time. It takes effect at once and they are not told
- Leave every optional field blank, including all of the sensitive ones
We will not treat you differently for exercising any of these. If we refuse a request we will tell you why, and you can ask us to look again.
Depending on where you live you may also have the right to know what we collect and why, to have it deleted, to correct it, to limit how we use sensitive information, and to appeal a refusal. Residents of California, Colorado, Connecticut, Virginia and other states with a privacy statute have these rights, and residents of Canada have similar rights under federal and provincial law. Use the same address and we will handle it the same way.
12. Keeping it safe
Access to member data is restricted to the people who need it for a job, and each of them holds only the specific permissions that job needs rather than a single master switch. Staff actions are written to a log that cannot be edited. Verification selfies sit in storage that no member can reach and that most staff cannot reach either.
No system is perfectly secure, and anybody who says otherwise is selling something. If a breach affects you we will tell you, and the authorities, as quickly as the law requires and as clearly as we can.
13. Children
Chai for Two is for adults. It is not for anyone under 18 and we do not knowingly collect anything from anyone under 18. If we find such an account we close it and delete what it held. If you believe a child is using the app, tell us at [email protected].
14. Changes to this policy
If we change something that matters, we will tell you in the app before it takes effect and change the date at the top of this page. If a change means collecting something new or using something for a new purpose, we will ask you rather than assume.
15. Asking us anything
Write to [email protected]. A person reads it and a person answers. That address also reaches whoever is responsible for privacy at Semper Labs LLC.
By post: Semper Labs LLC, 971 US Highway 202N, Ste N, Branchburg, NJ 08876, United States.