Privacy policy
Privacy, consent and control come before engagement. Always.
Last updated 8 August 2026
What we collect
- Account details: email, password hash (held by our auth provider), date of birth for age checks.
- Profile: name, KEMSTRY ID, photos, bio, interests, intents and the town or city you choose.
- Activity: connections, messages, community posts, events, check-ins and reports.
- Optional: contact matches (as irreversible hashes) and social accounts you link yourself.
Location
KEMSTRY stores an approximate area only — the town or city you enter. We never store or publish exact coordinates, never build a movement history, and never track you in the background. Other people see "in Cardiff" or a rough distance, never a live position.
Identity and biometric data
Verification captures a photo of your ID and a short liveness selfie. These are held as private, access-controlled records used only to confirm you are a real, unique adult and to check that your dating photos show that same person. They are never shown to other members, never returned to the app, and never used for advertising.
- ID images are retained only for as long as the verification check and any dispute window require, then deleted.
- The face reference used for photo matching is kept while your account is verified and deleted with your account.
- Face matching runs server-side; results are stored as an outcome, not as a new biometric copy.
- You can withdraw verification at any time, which deletes the reference and removes your verified badge.
Contacts
Contact discovery is opt-in. Phone numbers are converted to irreversible hashes on our server and matched against other hashes. We do not keep your address book, and you can delete all contact-matching data at any time from Connections & privacy.
Social accounts
We only ever use official sign-in and APIs. We never ask for a social password and never scrape private data. Every linked account has separate switches for showing it on your profile, using it for discovery and using it for verification — all off by default.
Who can see what
Row-level security rules in our database enforce your privacy settings server-side, not just in the app. Blocked people are excluded from discovery, search, messaging, communities and recommendations.
Your rights
- Download a copy of your data from the Privacy centre.
- Correct or delete individual items at any time.
- Delete your entire account permanently, in-app, without contacting support.
- Turn off discovery, search visibility, read receipts, online status and location sharing.
Retention
Check-ins expire automatically. Deleted accounts remove profiles, photos, messages you sent, listings, matches and contact-matching data. Limited safety records may be retained where we are legally required to keep them.
Contact
Privacy questions go to the help page — a named data controller and contact address will be published before launch.