Privacy policy

Privacy, consent and control come before engagement. Always.

Last updated 8 August 2026

What we collect

  • Account details: email, password hash (held by our auth provider), date of birth for age checks.
  • Profile: name, KEMSTRY ID, photos, bio, interests, intents and the town or city you choose.
  • Activity: connections, messages, community posts, events, check-ins and reports.
  • Optional: contact matches (as irreversible hashes) and social accounts you link yourself.

Location

KEMSTRY stores an approximate area only — the town or city you enter. We never store or publish exact coordinates, never build a movement history, and never track you in the background. Other people see "in Cardiff" or a rough distance, never a live position.

Identity and biometric data

Verification captures a photo of your ID and a short liveness selfie. These are held as private, access-controlled records used only to confirm you are a real, unique adult and to check that your dating photos show that same person. They are never shown to other members, never returned to the app, and never used for advertising.

  • ID images are retained only for as long as the verification check and any dispute window require, then deleted.
  • The face reference used for photo matching is kept while your account is verified and deleted with your account.
  • Face matching runs server-side; results are stored as an outcome, not as a new biometric copy.
  • You can withdraw verification at any time, which deletes the reference and removes your verified badge.

Contacts

Contact discovery is opt-in. Phone numbers are converted to irreversible hashes on our server and matched against other hashes. We do not keep your address book, and you can delete all contact-matching data at any time from Connections & privacy.

Social accounts

We only ever use official sign-in and APIs. We never ask for a social password and never scrape private data. Every linked account has separate switches for showing it on your profile, using it for discovery and using it for verification — all off by default.

Who can see what

Row-level security rules in our database enforce your privacy settings server-side, not just in the app. Blocked people are excluded from discovery, search, messaging, communities and recommendations.

Your rights

  • Download a copy of your data from the Privacy centre.
  • Correct or delete individual items at any time.
  • Delete your entire account permanently, in-app, without contacting support.
  • Turn off discovery, search visibility, read receipts, online status and location sharing.

Retention

Check-ins expire automatically. Deleted accounts remove profiles, photos, messages you sent, listings, matches and contact-matching data. Limited safety records may be retained where we are legally required to keep them.

Contact

Privacy questions go to the help page — a named data controller and contact address will be published before launch.