OtherHalf ("we," "us," or "our") operates the OtherHalf mobile application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App. Please read this Privacy Policy carefully. By using the App, you agree to the collection and use of information in accordance with this policy.
Section 01Information We Collect
Information You Provide
- Account Information: Phone number — used as the primary identifier for your account and required to create one. Optional recovery email address. Authentication tokens issued by our authentication provider (Supabase Auth) for session management. The app language you have chosen, so that notifications and text messages we send you (for example, your sign-in code) arrive in that language; it is stored with your account and deleted with it.
- OAuth Sign-In: If you sign in via Google, we receive your email address, name, and profile picture URL from Google. The picture URL is used only during the sign-up onboarding step and is not stored on our servers. If you sign in via Apple, we receive your email address (or Apple's Hide My Email relay address, if you choose to use it) and name. We do not receive your profile picture from Apple.
- Profile Information: First name, date of birth, gender, gender preference (who you'd like to match with), bio text, custom catchphrase, city, country, ethnicity, languages spoken, religion, how important faith or spirituality is to you, job title, education level, parent status, family plans (whether you want children), pet parent status, drinking habit, smoking habit, dietary preference, preferred home setting, activity style, activity level, life values, lifestyle tags, and interest tags.
- Story Time (optional): Up to three stories you choose to add to your profile. Each story is a photo, which may carry an optional short title and an optional voice recording (up to 2 minutes) you make in the app. (Video stories were retired on September 7, 2026; a video story posted before then stays on your profile until you delete it.) Stories are visible to people who can view your profile, are stored on our cloud storage infrastructure, and are deleted when you remove them or delete your account.
- Replies to profiles you haven't matched with (optional): If you reply to someone's story or song before you have matched, we hold that reply — your message and any reaction — so it can be delivered if the two of you match later. Held replies are encrypted at rest, are never shown to the other person unless you match, and are limited to three per person. They are deleted when they are delivered, when either of you blocks the other, or when you delete your account. If you never match, the reply is never delivered.
- Support Tickets (optional): If you file a support ticket in the App, we collect the ticket's title and description (encrypted at rest in our database), an optional image attachment, and a snapshot of your recovery email address at the time of filing so we can reply to you. Our replies appear in the App and are also sent to that email address.
- Account Recovery Requests (optional): If you lose access to your phone number and ask us to move your account to a new number, we collect the details you provide to prove the account is yours — your old and new phone numbers, your first name, date of birth, and recovery email, and your answers to a short set of questions about the account — together with a truncated network identifier. These requests are reviewed by a human; see Section 5 for how long they are kept.
- Bug Reports & Suggestions (optional): If you report a bug or share a suggestion (for example, by shaking your device), we collect your message, an optional automatically captured screenshot of the screen you were on (shown to you before you submit), and basic technical context — device model, operating system, app version, and the screen you reported from.
- Photos: Profile photos you upload (up to 6), plus any photos you sent in chat before photo messaging was retired in September 2026 (those remain part of their conversations), stored on our cloud storage infrastructure.
- Biometric Data (Photo Verification): When you verify your profile photos, we extract mathematical representations of facial features (face descriptors) from your verification selfie, from a small number of pose snapshots captured during the liveness check (for example, smiling or with your eyes closed — used to confirm a live person is taking the photos), and from your profile photos to confirm they all depict the same person. This processing runs on our backend servers using an open-source library; we do not use any third-party biometric service. The selfie, the pose snapshots, and the descriptors are processed in memory for the verification only — they are not stored after the comparison completes, sold, or shared with any third party.
- Personality Assessment: Your responses to our personality assessment questions and the resulting trait scores across five axes.
- Chat Messages: Messages you send to your matches — text and voice recordings you choose to send. (Sending photos in chat was retired in September 2026; photos sent before then remain part of the conversation they belong to.) Messages are encrypted at rest in our database using AES-256-GCM; voice attachments, and any earlier photo attachments, are stored on our cloud storage infrastructure and follow the same retention rules as the conversation they belong to.
- Favorite Songs: Songs you save as favorites from the iTunes catalog (song title, artist, preview URL).
- Purchase Information: Records of in-app purchases you make. Payment processing for in-app purchases — including tips from the "tip jar" — is handled by Apple (App Store) or Google (Play Store) through RevenueCat. We do not directly collect or store your payment card information; Apple and Google process payment details directly.
- Referrals & Invites (optional): If a new account is created through an invite link, QR code, or typed invite code, we record which existing account referred it — the two account identifiers, the share code used, the source of the attribution (Google Play install referrer, a typed code, or a tapped link), and timestamps. We use this solely to award the referrer's shop credit and to prevent abuse of the referral program; neither side sees more than aggregate counts (for example, how many friends have joined). On Android, the App reads Google Play's install-referrer value once on first launch to see whether you arrived through an invite link; this is a read from Google Play — nothing is sent to Google.
Information Collected Automatically
- Location Data: If you grant location permissions, we collect your device's GPS coordinates. We use coordinates to calculate distances between users and to display approximate (city-level) location. Coordinates are encrypted at rest using AES-256-GCM and are never shown to other users — only the city-level summary is. Turning your coordinates into a city name happens on your device — we do not send your coordinates to any third-party geocoding service. If your device cannot determine your city's name, you can type it in yourself; the name you enter is used only as your displayed city.
- Device Information: Device type, operating system, and app version for diagnostics and compatibility.
- Usage Data: Interactions within the App (swipes, matches, feature usage) for analytics and to improve our service.
- Push Notification Tokens: If you enable push notifications, we store your device token to deliver match and message notifications.
Section 02How We Use Your Information
We use the information we collect to:
- Provide the Service: Create and maintain your account, display your profile to potential matches, calculate compatibility scores, facilitate messaging between matches, and process purchases.
- Personalize Your Experience: Generate your match queue based on your personality assessment, preferences, and location.
- Communicate with You: Send push notifications for new matches, new messages, and other app events (if enabled). When you change your recovery email, our authentication provider may send a verification email to the new address to confirm the change. If you file a support ticket, we reply in the App and by email to the contact address on the ticket. We do not currently send marketing emails.
- Improve the App: Analyze usage patterns, diagnose technical issues, and develop new features.
- Ensure Safety: Enforce our Terms of Service, detect and prevent fraud, and respond to reports of inappropriate behavior. A report can reference the specific message, story, or photo being reported; we keep that reference with the report and hold the reported content back from routine deletion (including the media deletion that follows blocking a user) so our team can review what was actually sent. When a report is reviewed, a moderator can open the reported message or media together with a small window of the messages immediately around it in that conversation, so the report can be judged in context rather than as a single line taken out of it. Moderators cannot browse conversations freely: reported content opens only from a report, and every time a moderator opens it, that access is itself recorded — which staff member viewed which report, and when — and kept with our security logs.
Section 03How We Share Your Information
With Other Users
Your profile information that you mark as visible — including first name, age, photos, stories, bio, custom catchphrase, city, ethnicity, languages, religion, job title, education level, family and pet information, home setting, activity style, activity level, dietary preference, life values, lifestyle and interest tags, drinking and smoking habits, favorite songs, personality traits, compatibility scores, and lifestyle compatibility scores — is visible to other users in the matching and discovery features, and — for the fields listed under "Sharing a profile card" below — may be shared by them as an anonymised card.
Per-field visibility controls let you hide the following fields from other users; a hidden field also stops counting toward lifestyle compatibility and match filters: kids and parent status, pets and pet types, job title, education level, languages spoken, religion, drinking habit, smoking habit, ethnicity, home setting, activity style, activity level, and dietary preference. Other fields (first name, age, photos, stories, bio, custom catchphrase, city, lifestyle tags, interest tags, favorite songs, personality traits, compatibility scores, lifestyle compatibility scores, gender, gender preference) are always visible to other users when set. Note that some choices can imply others — for example, a dietary preference of halal or kosher can suggest a religious affiliation even if your religion field is hidden — so review which fields you leave visible.
Your chat messages are visible only to the specific match you are communicating with.
Public invite card: If you share your invite link (otherhalf.love/invite?c=…), anyone who opens it — including people without an account — can see your first name, your first profile photo, and your five Energy Prism axis positions. Sharing the link is your own action; the card is served only for a valid, unguessable code, is disabled while your profile is paused, hidden, or banned, and never shows contact details or account identifiers.
Sharing a profile card: Other members can use the App's share feature to create an image of your profile card as they saw it in the App, and send it outside the App (for example to a messaging app or a story). That image never includes your photos, your full name (only your first initial), your city, or your account identifiers. It can include your custom catchphrase, your bio, your life-facts pills (job title, education level, family and pet information, languages — never ethnicity), the titles of your favorite songs, your Energy Prism shape and archetype, and the compatibility percentage between the two of you. Fields you have hidden with the per-field visibility controls never appear on it. Because the image is created on the other member's phone and sent through third-party apps, we cannot recall it once shared.
With Service Providers
We use the following third-party services to operate the App:
- Supabase — Database hosting and authentication
- Twilio — Delivery of one-time verification codes by SMS. We share your phone number with Twilio so it can send your sign-in code; Twilio processes it under its own privacy policy and does not use it for other purposes.
- Cloudflare R2 — Photo and media storage
- Backblaze B2 — Independent backup storage for photos and media. Copies of the media stored on our primary storage are mirrored daily to Backblaze B2 so that user content cannot be lost to a single storage failure. When media is deleted from primary storage, the backup copy stops being part of the backup on the next daily run and is permanently removed within 30 days after that (see Media Backups in Section 5). Backup copies are used for nothing except restoring lost data.
- Upstash — Redis caching, rate-limit storage, and WebSocket coordination
- Railway — Backend hosting
- RevenueCat — In-app purchase management and entitlement tracking
- Expo Application Services — Push notification delivery and over-the-air app updates. Push notifications are sent through Expo's servers to Apple and Google; the notification text (for example a new-message preview and the sender's first name) passes through Expo for delivery.
- Apple Push Notification Service / Firebase Cloud Messaging — Push notification delivery
- iTunes Search API — Song search and preview URLs
- Mixpanel — Product analytics. We share anonymized usage events (such as feature interactions and screen views) along with your account identifier so we can understand feature usage and retention. Before you create an account, we generate a random device identifier (not your phone number or any hardware identifier) to measure how many people complete sign-up; if you create an account, this identifier is linked to your account's analytics record. Some events carry a small set of profile attributes so we can see whether the App works equally well for everyone: for example, a swipe event records your gender and the gender of the profile you acted on, and events may carry your assessment level, age, and city. We do not share your name, photos, bio, messages, contact details, or biometric data with Mixpanel.
- Sentry — Crash and error reporting. When the App or our backend encounters an error, technical details of the failure — the error type and where in our code it happened, app version, device model and operating-system version, and the internal sequence of events leading up to the failure — are sent to Sentry so we can find and fix the problem. Crash reports do not include your profile content, photos, or messages.
- PostHog — Website analytics and session replay (our website only, not the App). When you visit otherhalf.love we collect usage events (pages viewed, buttons clicked), technical data (browser type, approximate location from IP), and session replays of how visitors move through the page. Replays mask everything typed into forms; the waitlist email you submit is not shared with PostHog; the personality assessment is never recorded, and individual answers are never sent to PostHog — completion events carry only the resulting archetype name and time taken. Session replays may be recorded for any visit. PostHog stores its analytics identifier in a cookie / local storage on your device, which can persist for up to a year unless you clear it.
- Formspark — Waitlist form processing (our website only). The email address you submit to join the launch list is delivered to and stored by Formspark so we can contact you when the app launches. We use it for no other purpose.
- Google and Apple OAuth — If you sign in via Google or Apple, we exchange data with those providers as required to complete sign-in (your email address is returned to us — Apple may relay it through a private address; your sign-in activity is visible to those providers per their own privacy policies).
- Google Cloud Vision (Google LLC) — Automated screening of profile and story photos for nudity and violence. The photo is sent to Google as image data only — no name, account identifier, file name, or link — and Google returns a likelihood rating for each category. A photo rated at or above our refusal threshold is not saved and is not shown to anyone. A photo rated below it is published, and may additionally be flagged for review by our team. The ratings, and a reference to the image, are kept as a moderation record (see Section 5).
- Google Workspace (Gmail) — Support email delivery. Operational notifications to our own support team — user reports, account-recovery tickets, and enforcement appeals — are delivered as email through Google Workspace, and can include the account identifiers and message text needed to handle the request (for account recovery, this includes the phone numbers involved). Replies to support tickets you file are also sent to your ticket's contact email through Google Workspace.
These providers process data on our behalf and are bound by their own privacy policies.
As Required by Law
We may disclose your information if required to do so by law, or in response to valid legal requests by public authorities (e.g., a court order or government agency).
Section 04Data Security
We take the security of your data seriously:
- Encryption at Rest: Chat messages, location coordinates, and personality trait data are encrypted in our database using AES-256-GCM authenticated encryption.
- Encryption in Transit: All data transmitted between the App and our servers uses HTTPS/TLS encryption.
- Authentication Security: OtherHalf does not use passwords. We sign you in using a one-time code (OTP) sent to your phone number, or via Google or Apple OAuth. On subsequent sign-ins from the same device, the App uses a quick sign-in token stored in your device's secure storage (iOS Keychain or Android Keystore); you can optionally require Face ID, fingerprint, or your device passcode before this token is used ("Quick Sign-In Lock" in Settings). Quick sign-in tokens are single-use — each sign-in replaces the token with a new one — are valid for at most 90 days without use, and are stored on our servers only in irreversibly hashed form. If a replaced token is ever presented again, we treat it as a possible theft and immediately invalidate all of that account's sign-in tokens. One-time codes are likewise hashed at rest and compared in constant time to resist timing attacks.
- Access Controls: API endpoints require authentication; rate limiting prevents abuse.
- Breach Notification: If we become aware of a personal data breach that affects you, we will notify you and the relevant regulatory authorities without undue delay, and in any case within 72 hours where required by applicable law (including the EU General Data Protection Regulation).
While we implement reasonable security measures, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.
Section 05Data Retention
- Active Accounts: We retain your data for as long as your account is active.
- Automated Image Screening Records: Profile and story photos are automatically screened before they are saved (see Section 3). Photos that pass are not recorded. When a photo is refused, or is flagged for our team to review, we keep a moderation record: the category ratings, what the photo was for, a reference to the stored image file, and — where a refused image had to be preserved because a report or another part of your profile still pointed at it — a private copy of the image itself. Refusal records and completed reviews are deleted 730 days (two years) after they are created, together with any private copy; items still awaiting review are kept until they are reviewed. These records survive account deletion — the reference to the image file contains the deleted account's internal identifier, so the record is pseudonymous rather than anonymous. The lawful basis is our legitimate interest in keeping OtherHalf safe.
- Content Under Report: If you delete or replace a photo or a story while a report is pending against you or against that content, or while our team's review of that content is open, the file is not deleted at once: it is kept as a moderation record (moved to private storage where possible) so the report can still be acted on, and it is no longer shown on your profile. It is removed under the moderation-record rules above — no later than 730 days after the record is created, unless a report about it is still open.
- Deleted Accounts: When you delete your account, we delete your personal data — including profile, photos, stories, messages, swipes, matches, purchase history, personality assessment data, support tickets, bug reports (including their screenshots), and analytics records held by our analytics provider — typically within hours of your request, and in all cases within 30 days. The only exceptions are the security logs, the moderation and automated image-screening records described below (which can include a private copy of a refused image), and the time-limited media backup copies described below.
- Media Backups: Photos and media are additionally copied to an independent backup (Backblaze B2 — see Section 3) so your content cannot be lost to a storage failure. When media is deleted, the backup copy stops being part of the backup on the next daily run (normally within a day) and is permanently removed within 30 days after that. Backup copies are never used for anything except restoring lost data.
- Undelivered Profile Replies: A reply written to someone you have not matched with is kept until it is delivered (you match), until either account blocks the other, or until either account is deleted — whichever comes first.
- Support Tickets, Bug Reports & Suggestions: Kept while your account exists so we can act on them, and deleted — including any screenshot or attachment — when you delete your account. Replies already emailed to you naturally remain in your own mailbox.
- Unmatched Conversations: When you unmatch another user, the match and chat are hidden from both your view and theirs. The underlying messages remain in our database (encrypted at rest) until either party deletes their account, at which point all messages in that conversation are permanently removed from both users' accounts.
- Security and Audit Logs: We retain technical security logs (records of authentication events, sign-in attempts, account changes, and similar) for 180 days, after which they are automatically deleted. One exception: the single log record evidencing that an account-deletion request was received and honored is retained for 730 days (two years) after deletion, as compliance evidence that we carried out your request. These logs contain event metadata (timestamps, event types, and truncated network identifiers) — not your profile content, photos, or messages.
- Moderation and Enforcement Records: If your account is warned, restricted, suspended, or banned for violating our community guidelines, the record of that decision (the action taken, when, and the reason category) is kept even if the account is later deleted — deleting an account does not erase its moderation history. We keep these records so that enforcement decisions remain reviewable and appealable, and so that the deletion process cannot be used to erase them. The lawful basis is our legitimate interest in keeping OtherHalf safe.
- Reported Content: When something is reported, we keep the report and its reference to the reported message or media, and reported media is held back from routine deletion (including block-related deletion) while the report is on file, so our team can review it. Reviewing a report can include viewing the reported message or media and the messages immediately surrounding it in that conversation; each such viewing is logged (which staff member, which report, and when), and those access records follow the Security and Audit Logs retention rule above. Enforcement outcomes follow the Moderation and Enforcement Records rule above.
- Referral Records & Shop Credit: Referral attribution records and your credit ledger are kept for the life of the accounts involved and are deleted with the account; they are included in your data export.
- Blocked Phone Numbers: If an account is deleted while suspended or banned, we retain a one-way cryptographic code derived from its phone number and refuse new sign-ups from that number for as long as the block lasts — until the suspension would have ended for suspended accounts, or indefinitely for permanently banned accounts. The phone number itself is not stored in this list and cannot be recovered from the code. A successful appeal removes the block. The lawful basis is our legitimate interest in preventing banned users from returning.
- Appeals: If you appeal a suspension or ban, your appeal message and the enforcement record it concerns are delivered to our support team and kept in our audit trail for up to 730 days (two years) — an appeal must remain on file at least as long as the decision it contests. Appeal records survive account deletion.
- Account Recovery Requests: A request to move your account to a new phone number (see Section 1) is kept while it is pending. Once it is approved or denied, the request — including the identity details it contains — is automatically deleted 90 days after the decision. The separate minimal security-log record of the decision follows the Security and Audit Logs rule above. We keep decided requests for this period so recovery decisions can be reviewed and disputed; the lawful basis is our legitimate interest in preventing account takeover.
- One-Time Codes: Sign-in verification codes are stored only in hashed form and are automatically deleted within 24 hours of expiring.
- Quick Sign-In Tokens: Expired or invalidated quick sign-in tokens (see Section 4) are automatically deleted from our servers within 30 days of becoming unusable.
- Payment Webhook Records: Technical records of purchase and refund notifications from our payment providers are retained for 90 days to guard against duplicate processing, then automatically deleted. One exception: if a purchase notification cannot be matched to an account (for example, a payment that completed during a reinstall before sign-in finished), we keep its technical record until the purchase has been matched and delivered — so a completed payment is never lost to the deletion schedule — after which it follows the normal 90-day rule.
- Biometric Data: Face descriptors computed during photo verification are not retained at all — they exist only for the duration of the verification comparison and are discarded when it completes, and the verification selfie and liveness pose snapshots are likewise deleted immediately and never stored (see Section 1). The only thing we keep is the result: the verified checkmark and the date it was earned. Your biometric consent record (when you granted or withdrew consent, and which version of the consent notice you saw) is kept while your account exists and is deleted with your account.
Section 06Your Rights
Depending on your jurisdiction, you may have the following rights:
All Users
- Access: Request a copy of the personal data we hold about you. You can request a copy of your data in a machine-readable format (JSON) from within the App.
- Correction: Update or correct inaccurate information via your profile settings.
- Deletion: Delete your account and associated data through the App settings. Account deletion is typically completed within hours, and in all cases within 30 days.
- Notification Preferences: Control push notification settings on your device and within the App.
European Economic Area (EEA) Residents — GDPR
- Data Portability: Request your data in a machine-readable format (JSON) via the in-app export feature described above.
- Right to Object: Object to processing based on legitimate interests.
- Restriction of Processing: Request that we limit how we use your data.
- Withdraw Consent: Withdraw consent at any time where processing is based on consent, including consent to biometric processing for photo verification. Withdrawing biometric consent will disable the photo-verification feature on your account.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the data protection supervisory authority in your country of residence.
To exercise these rights, contact us at support@otherhalf.love.
California Residents — CCPA
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected.
- Right to Delete: Request deletion of your personal information.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
- We Do Not Sell Personal Information. We have not sold personal information in the preceding 12 months.
Section 07Age Restriction
OtherHalf is intended for users who are 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected data from a user under 18, we will delete that account and associated data promptly.
Section 08International Data Transfers
Your information may be transferred to and processed in countries other than your own. We take appropriate safeguards to ensure your data is protected in accordance with this Privacy Policy.
Section 09Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy in the App and updating the "Last Updated" date. Your continued use of the App after changes constitutes acceptance of the updated policy.
Section 10Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:
- Email: support@otherhalf.love
- Website: https://otherhalf.love