Privacy policy
Version 2026-10-06
What we collect
- Account: email, password hash, optional phone number, country, language.
- Profile: everything you choose to enter, including sensitive categories such as ethnicity and relationship intent.
- Verification: documents you submit. These are encrypted at rest and visible only to the verification team.
- Safety: signup and login IP addresses, device fingerprints, report and moderation records, message spam-scan results.
- Billing: Stripe identifiers and payment amounts. Card numbers never reach our servers.
What other members can see
Only what your visibility settings allow. Each questionnaire answer is independently classified as public, members-only, matches-only, grant-only or private, and you can raise those restrictions at any time. Verification documents are never shown to another member - only the resulting badge is.
When you open someone's profile, members on the Curated and Select tiers can see that you visited (for 30 days). Visits are not recorded while a Select member browses in incognito. Your hide list, your hidden words, your date check-ins and your date suggestions are never shown to anyone else; date check-in details are encrypted at rest and visible only to people you send the private link to. Hide-list entries are stored only as a keyed hash, never as the email, phone number or name you typed.
AI portraits are optional. If you create one, your approved profile photo is re-encoded (removing location and device data) and sent to our image-generation provider solely to produce the portrait; we record your consent when you do. The portrait stays private until you publish it, is always labelled as an AI portrait, and is removed if you delete the photo it came from or take it down.
How long we keep it
Packets and grants expire automatically. Verification media is deleted after approval plus the retention window required to defend a decision. Safety records are retained while an account is open and for a limited period afterwards, because the entire purpose of a report is to remain resolving after the subject deletes their account.
Where it lives
Data is stored on infrastructure we operate, behind Cloudflare. Media for packets currently lives on our own encrypted-at-rest storage and is served only through authenticated, expiring links - never from a public bucket or CDN path.
Who we share it with
Processors only, and only as needed: Stripe for payments, Cloudflare for security and delivery, and our email provider for transactional mail. We do not sell personal data, and we do not use your private content to train advertising models.
Your rights
You can access, correct, export and delete your data from your settings, and you can withdraw any consent you previously gave. Deletion removes your profile, media and answers; the audit record of what you consented to, and of safety actions taken, is retained where we are legally required to keep it.
Contact
Data requests and privacy questions go to the address published in the footer of 6on7. We answer within 30 days, and usually much sooner.