Privacy Policy for Gennety
Last Updated: 26 September 2026 · Version 4.2
This Privacy Policy explains how Gennety ("Gennety", "we", "us", or "our") collects, uses, shares, and protects your personal data when you use the Gennety matchmaking service through our Telegram bot (@gennetybot), our Telegram Mini Apps, our native mobile application, and our website at gennety.com (together, the "Service").
Gennety is an AI-first matchmaking service. By design we process more context about you than a traditional dating app — psychological context, biometric data used for identity verification, and preferences you state for a date. Some of what we process is special-category data under GDPR Article 9 (biometric data; and, if you state them, dietary requirements that can reveal religion or accessibility needs that can reveal health). We process those only with your explicit consent — see Section 6.
Please read this Policy carefully. Related documents: Terms of Service and Cookie Policy.
1. Quick Summary
This summary is for orientation only — it does not replace the full Policy below.
| Question | Short answer |
|---|---|
| Who is responsible? | Gennety, operated from Kyiv, Ukraine. Contact: [email protected] (Section 2). |
| What do you collect? | Account and contact-verification data (email or phone), profile answers, photos and optional video, a liveness selfie, location for your dating city and date logistics, your messages with our AI, payment records, and technical data (Section 4). |
| Do you use AI on my data? | Yes. AI builds your psychological summary, an embedding, an attractiveness/"league" rating, icebreakers, and venue choices (Sections 7 and 8). |
| Do you use biometrics? | Yes — a liveness selfie and face comparison against your photos, only with your explicit consent. The selfie is deleted after 90 days (Sections 6 and 10). |
| Do you sell my data? | No. We never sell personal data and we do not run advertising profiling. |
| Do you show my data to other users? | Only to the one person you are matched with, in a forward/save-protected form (Section 12). |
| Does a human see my data? | Yes — the operator of the service, through an internal administration interface and a private operations feed (Section 12.2 and 12.3). |
| Can I delete everything? | Yes — freeze (reversible) or delete (irreversible cascading erasure), with one disclosed exception: an internal operational notification (Section 12.2). |
| Who do I complain to? | Us first at [email protected]; then your data-protection authority (Section 22). |
2. Data Controller
The data controller responsible for your personal data is:
- Gennety, a service operated by Gleb Gosha, an individual established in Kyiv, Ukraine. There is no separate legal entity; the operator is the data controller personally.
- Privacy contact: [email protected]
Article 27 GDPR representative: not yet appointed. Because we offer the Service in German and Polish and therefore target users in the EEA, a representative in the Union is required, and one will be appointed and named here. Until then, you can reach us directly at [email protected] and we will handle your request under the GDPR exactly as set out in Section 18.
Although Gennety is established in Ukraine, where we offer the Service to users located in the European Economic Area (EEA) or the United Kingdom, we apply the EU General Data Protection Regulation (GDPR) and the UK GDPR to that processing.
3. Scope
This Policy applies to all personal data we process about:
- users and prospective users of the Service, including during onboarding and before an account is fully created (for example, a phone number or email you submit to receive a verification code, even if you never finish sign-up);
- visitors to
gennety.com.
It does not cover:
- third-party services you reach through our links or embeds — for example the Telegram app itself, the Apple App Store, or the Spotify player embedded on our website. Those services process data under their own privacy policies;
- what another user does with information you choose to share with them.
Note on the website. Since 19 July 2026, the website runs no part of onboarding. It does not verify emails, does not create accounts, and does not hand any pre-filled data to the bot or the app. Its sign-up buttons only send you to Telegram or the App Store, where onboarding happens natively. The only personal data the website itself records is your cookie-consent choice (Section 5.4 and the Cookie Policy).
4. The Data We Collect
We collect data in three ways: data you give us, data generated by your use of the Service, and data we derive or generate to power matchmaking.
4.1 Data you provide
| Category | Examples |
|---|---|
| Account & identity | First name (and optionally surname), age, gender, gender preference, language, UI theme, your Telegram user ID and public @username (if you have one), and the platform you use (Telegram / mobile). |
| Sign-up track | Which registration track you chose — student (university email) or general (phone) — and the date you verified it. |
| University email (student track) | The email address you verify and its domain, used to confirm eligibility for the student community and its perks. A one-time passcode (OTP) is sent to verify it; the code is stored hashed, never in plain text. |
| Phone number (general track) | Your phone number in international format. On Telegram you share it in one tap, so we receive it directly from Telegram as trusted contact data; in the mobile app we send you a verification code by SMS (or, where configured, as a Telegram service message). One account per phone number. |
| Profile details | Height, hobbies/interests, a free-text description of the partner you are looking for, your preferred partner age range, the city where you want to receive matches, and free-text "vibe" answers (for example, your ideal Friday night, and whether the experience or the company matters more to you). We do not ask for, and do not store, your nationality or ethnic origin. |
| Photos & video | Profile photos (including the static frame of a Telegram "Live Photo") and an optional short profile video. Images you attach to a chat with our AI concierge, including any you choose to add to your profile. |
| Identity verification (biometric) | A liveness selfie captured by our verification provider, used to confirm you are a real person and that your profile photos are of you. See Section 10. |
| Follow-up questionnaire answers | Short optional questions we send after onboarding ("Profiler") to fuel icebreakers and date hints — you can skip any of them. |
| Visual type preference (optional feature) | Where we offer the visual "type" calibration step, the picks you make from a set of sample portraits, and the compiled preference this produces. |
| Location | The dating city you select and its coordinates; coordinates resolved from your browser/device geolocation or a place you pick on a map; the departure point you mark for a date, with its human-readable label if you selected it via search. |
| Explored areas (optional, off by default) | Only if you switch on map colouring: the approximate areas you have been in, stored as grid squares roughly 1.2 km across — never your exact position, and never a coordinate. Recorded only while the map screen is open, and only inside a city we operate in. |
| Date preferences ("venue intent") | What kind of date you want — experience, atmosphere, format — plus any requirements you explicitly confirm, including dietary requirements (e.g. vegan, vegetarian, halal, kosher, gluten-free), an alcohol-free requirement, and a step-free access requirement. See Section 6 — some of these can reveal special-category data. |
| Communications & feedback | Messages, images, and voice notes you send to our bot or AI concierge; post-date feedback (a chemistry rating, whether you want a second date, free text or a voice note); free-text reasons when you decline a match, cancel a date, or report a user; and messages you send through the optional pre-date anonymous relay chat. |
| Payments | Your purchase records for Date Tickets, ticket bundles, paid venue changes, and the Gennety Premium subscription. We never receive or store your full card number — see Section 14. |
| Subscription cancellation reason | If you cancel Gennety Premium in chat and choose to answer, the free-text reason you give. |
| Support correspondence | Anything you send us at our support handle or at [email protected]. |
4.2 Data generated automatically
| Category | Examples |
|---|---|
| Usage & interaction logs | Onboarding progress, actions in the bot, Mini Apps and app, match decisions (accept/decline), scheduling availability, venue likes, timestamps. |
| Onboarding funnel telemetry | For each onboarding step: which step it was, whether it was asked, answered or skipped, how long you spent on it, your language and platform. We never store your answer text in this telemetry — only the step key, its outcome, and timing. |
| Technical & device data | IP address, device and operating-system information, app version, and diagnostic logs. |
| Session data | For the mobile app, sign-in sessions and refresh tokens (stored hashed) so you stay logged in and we can revoke access. |
| Push tokens | Device push tokens for Apple push notifications and Live Activities (the live "date day" / "decision" widget), so we can notify you. |
| Voice & video transcripts | Text transcriptions of voice notes you send. The audio of a profile video is transcribed transiently for a safety check and is not retained. |
| Usage metering | Per-user counters for how many messages and how much AI processing you use, so we can enforce fair-use limits and stop abuse. These are held in memory and are not a long-term profile. |
| Chat timeline | A short-lived record of what happened in your Telegram chat — the messages we sent, the buttons you tapped (by their visible label), what you typed, and actions you took in a Mini App. It lets our assistant answer a follow-up like "why?" against the message directly above it instead of guessing. A verification code you type is masked before storage. Kept 30 days. |
| Promo attribution | If you arrive through a promo link, a short-lived, hashed device fingerprint (IP + browser + language) and the promo code, so the reward survives an App Store install. Held in memory only, for up to an hour, then discarded. |
| Website cookie-consent records | See Section 5.4. |
4.3 Data we derive or generate
| Category | Examples |
|---|---|
| Psychological summary | A free-text summary of your personality, values, and preferences, generated from your onboarding answers. |
| Vector embedding | A numeric representation (embedding) of your psychological summary, used to compute compatibility. It is derived from your prose and is not stored as readable text. |
| Vibe axes | Structured scores derived from your free-text vibe answers (a tempo axis, an experience-vs-connection axis, a social role, and short anchor tags). |
| Compatibility & rating signals | A "league"/attractiveness score (Elo) seeded from an automated visual assessment of your photos, match scores, standby/priority counters, and the frozen score breakdown of each match we create. |
| Appearance tags (optional feature) | Where the visual type feature is active, coarse descriptive tags derived from your photos by an automated vision pass, used only to score how well you fit another user's stated visual preference. |
| Face-match scores | Similarity scores between your verification selfie and each of your profile photos. |
| Safety signals | Strikes, reports about you, suspension/investigation status, and records of media we rejected at upload (reason and time only — never the rejected media itself). |
| Venue selection logs | A structured, raw-text-free record of how a venue was chosen for your date, used to debug and improve the concierge. |
| Life rhythm (Tempo Sync) — two labels: your usual activity level (calm / moderate / active) and when your day tends to be most active (earlier / middle / later, or unknown), plus how many days of data they are based on | Computed on your iPhone from the last 28 days of your step count in Apple Health, only if you connect it. Only the labels reach us — never step counts, sleep, workouts, heart rate or any other Health data |
We do not create per-message embeddings of your conversations. We do not sell your data, and we do not use your data for third-party advertising or ad-profiling.
5. Where the Data Comes From
5.1 From you
Most data comes directly from you — your answers, photos, messages, and choices.
5.2 From Telegram
If you use the Telegram bot or a Mini App, Telegram provides us with your Telegram user ID, first name, language code, and public @username (if any). If you use the one-tap phone sharing, Telegram provides your phone number as trusted contact data. Everything you send in the chat is also processed by Telegram under Telegram's own privacy policy, which we do not control.
5.3 From our providers
Our liveness provider (Amazon Rekognition Face Liveness) returns the verification selfie and the liveness result; our face-comparison provider (Amazon Rekognition) returns similarity scores and safety labels; our payment rails return payment confirmations and transaction identifiers.
5.4 From your browser (website only)
When you make a cookie choice on gennety.com, we store an append-only consent record: the action (accepted / rejected / partial / withdrawn), which categories you allowed, the version of the cookie policy in force, a random session identifier held in your browser's local storage, the page URL where you made the choice, your browser's user-agent string, and a salted hash of your IP address (we do not store the raw IP). This record exists to prove that a valid consent was given, as consent laws require. Details are in the Cookie Policy.
5.5 From Apple Health (iPhone app, optional)
If you connect Apple Health (Section 6), the iPhone app reads your step count for the last 28 days — including wheelchair pushes, if your iPhone records them — and turns it on the phone into the two life-rhythm labels described in Section 4.3. Only those labels are sent to us; the step counts never leave your device.
6. Special-Category Data (GDPR Article 9)
Some of what the Service processes falls into the "special categories" that receive extra protection. We rely on your explicit consent (Art. 9(2)(a)) for each of them, we ask for that consent at the moment the data is collected, and you can withdraw it at any time (Section 18).
| Special-category data | When it arises | What happens if you say no |
|---|---|---|
| Biometric data — a liveness selfie and face-comparison scores used to uniquely identify you | When you complete identity verification. Verification is mandatory to be matched. | You are not matched. You may delete your account instead. See Section 10. |
| Dietary requirements — if you confirm halal or kosher (which can reveal religious belief), or a medical requirement such as gluten-free | Only if you explicitly confirm one when telling the concierge what kind of date you want. | The concierge simply does not filter venues on that requirement. Nothing else changes. |
| Accessibility needs — a step-free venue requirement, which can reveal health data | Only if you explicitly confirm it in the same flow. | As above. |
| Life rhythm from Apple Health — derived from your step count, which can reveal health | Only if you tap "Connect Apple Health" and allow access in the iOS permission sheet. Refreshed when you open the iPhone app, at most once a day. | Nothing changes: you are matched and dates are planned exactly as for everyone else. |
| Free-text you write — you may voluntarily reveal special-category information in a vibe answer, a chat message, a report, or feedback | Only if you choose to write it. | We ask you not to share more than you need to. |
Dietary and accessibility requirements are used only to filter and rank date venues. They are never used to rank you, to score you, or to decide who you are matched with, and they are never shown to your match as a category — your match sees only the venue we chose.
Life rhythm is different, and we say so plainly. If you connect Apple Health, your two rhythm labels are used (a) to plan the date — for example preferring a venue close to the metro, or suggesting a park or café nearby for afterwards — and (b) as one small factor in matching: when both people have a rhythm, a similar rhythm raises the pair's score slightly and a very different one lowers it slightly, by at most a few percent. It never excludes anyone, it does nothing when either person has not connected Apple Health, and it is far weaker than the other factors (Section 8). Your match never sees your labels or learns that rhythm played any part. The labels are never sent to our AI provider, never used in any text written about you, and never shown to our staff one person at a time — only as statistics over many pairs. Disconnect in the app (Settings → Your tempo → Disconnect) erases them from our servers immediately; revoke Health access in iOS Settings → Health → Data Access & Devices → Gennety.
Racial and ethnic origin: not collected. Until 1 August 2026 onboarding asked an optional "nationality or ethnic background" question, and the answer formed part of the text we turned into your matching profile. That was a special category under Article 9 feeding an automated matching decision, and it was removed: the question is gone, the stored values were erased, and nothing in the product asks for or infers your ethnicity. The visual preference feature (Section 8) deliberately uses only hair, build, style and tattoos — never skin tone or any proxy for ethnicity.
Sexual orientation. Your gender and the gender you want to be matched with are, together, capable of revealing sexual orientation. We collect them because matchmaking is impossible without them, we use them only to match you, and we never share them outside the match itself.
Withdrawing consent for biometric verification does not undo processing that was already lawful, but it stops further processing, removes you from matching, and lets you request erasure of the biometric material we still hold.
7. How We Use Your Data and Our Legal Bases
"Legal basis" refers to GDPR Article 6 (and Article 9 for special-category data).
| Purpose | Data used | Legal basis |
|---|---|---|
| Create and operate your account; deliver onboarding | Account, profile, contact rail | Contract (Art. 6(1)(b)) |
| Verify your contact rail (university email OTP, or phone code / Telegram one-tap) | Email or phone, OTP, delivery metadata | Contract; legitimate interests (Art. 6(1)(f)) in preventing duplicate and fake accounts |
| Confirm eligibility for the student community and its perks | University email domain | Contract |
| Identity & anti-impersonation verification (biometric) | Liveness selfie, profile photos, face-match scores | Explicit consent (Art. 9(2)(a)); Art. 6(1)(f) for fraud prevention |
| Validate uploaded photos and video for safety and duplicates | Photos, video frames, audio transcript (transient), perceptual hashes | Legitimate interests in a safe platform; legal obligation for illegal content |
| Match you with compatible people | Profile, psychological summary, embedding, vibe axes, location, rating signals, age-band preference | Contract; legitimate interests in effective matchmaking |
| Score how well a candidate fits your stated visual preference (where offered) | Your type-preference picks | Consent — the step is optional and skippable |
| Derive coarse appearance tags (hair, build, style, tattoos) from your photos so you can be scored against another user's stated visual preference | Your profile photos | Legitimate interests in effective matchmaking. Unlike the picks above this runs for everyone, is not skippable, and produces no special-category data — see Section 8 |
| Generate pitches, icebreakers, date hints, and venue choices | Profile, follow-up answers, location, vibe, date preferences | Contract; legitimate interests |
| Arrange and confirm dates; select and change venues | Availability, departure point, date preferences, agreed time | Contract |
| Filter venues on dietary / alcohol-free / step-free requirements | The requirement you confirmed | Explicit consent (Art. 9(2)(a)) where the requirement is special-category; otherwise contract |
| Process purchases (tickets, bundles, paid venue changes) and manage the Premium subscription | Purchase records, ledger entries, processor confirmations, entitlement dates | Contract; legal obligation for accounting |
| Handle cancellations and understand why people leave | Subscription records, the cancellation reason if you give one | Contract; consent for the free-text reason |
| Trust & safety: moderation, reports, strikes, suspensions, investigations | Reports, photos/video safety scans, relay-chat logs, strikes | Legitimate interests in user safety; legal obligation |
| Send service messages, reminders, push notifications and Live Activities | Account, usage, push tokens | Contract; legitimate interests |
| Operate an internal founder/operations feed (Section 12.2) | Profile card, photos, match and date summaries | Legitimate interests in operating and quality-checking a small, early-stage service |
| Measure onboarding drop-off and product health | Step telemetry, aggregate counters | Legitimate interests in improving the Service |
| Improve and develop the Service using anonymised data | Aggregated / anonymised data | Consent (the optional research opt-in). We record your choice at sign-up; today we act on it only by counting how many people opted in, and we will not start any research use of your data without it |
| Enforce fair-use limits and prevent abuse | Usage counters, IP, technical data | Legitimate interests in service availability and cost control |
| Comply with law and respond to lawful requests | As required | Legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms; you can object at any time (Section 18) and we will stop unless we have compelling legitimate grounds.
You can withdraw any consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
8. Automated Decision-Making and Profiling
Matchmaking is automated. We use algorithms and AI to:
- build a psychological profile and an embedding of you;
- extract structured "vibe" axes from your free-text answers;
- estimate an attractiveness / "league" rating from your photos, which strongly influences who you are considered compatible with;
- where the feature is active, derive coarse appearance tags from your photos (hair colour and length, build, style, tattoos — never skin tone, ethnicity, or any proxy for either) and score them against another user's stated visual preference;
- decide which person (if any) you are matched with in each weekly round, and in what priority order;
- bucket each of your photos as pass / borderline / fail / no-face during identity verification, which routes your account to verified, manual review, or rejected;
- triage a report about you into a severity tier, which can produce a warning, a suspension, or an investigation;
- where you have connected Apple Health, compare your two life-rhythm labels with another person's as a minor factor in the match score, and use the calmer of the two to lean the venue choice (Section 6);
- select the venue for your date.
These automated steps can affect whether and with whom you are matched, and whether your account stays open. We consider that no automated decision here produces a legal or similarly significant effect that you cannot question, and we build in the following safeguards:
- Human intervention on request. You may ask us to review any verification outcome, moderation decision, or account restriction, express your point of view, and contest the result. Write to [email protected].
- Fail-safe routing. If our own infrastructure or a provider fails during verification, you are routed to manual review — never auto-rejected.
- Rehabilitation. Verification re-runs automatically whenever you change your photos, so a bad outcome is not permanent.
- Safety decisions are reviewable. Suspensions for repeated breaches expire automatically; investigations are reviewed by a person.
9. AI Processing
To generate your psychological summary and matchmaking signals, we send relevant profile text to our AI provider for analysis, embedding, transcription, moderation, and visual scoring.
- Your psychological summary is built from your ordinary onboarding answers — your hobbies, what you want in a partner, and your free-text "vibe" answers.
- The summary and its embedding are treated as your personal data, are used only to build your profile and your matches, and are never shown to another user.
- We use AI providers on terms that do not permit them to train their public models on our API data.
- AI outputs can be wrong. Nothing our AI produces is advice; see the Terms of Service.
Retired: the personal AI export. Earlier versions of the Service invited you to paste in a psychological analysis produced by your own AI assistant (the "Magic Prompt"). That feature is no longer offered and we no longer accept such an export. If you provided one while it was available, the raw text was never retained — only the redacted signal summary and its embedding, which are erased with your account like everything else.
10. Photos, Video, and Biometric Data
Identity verification and face-matching involve biometric data — a special category under GDPR Article 9. We process it only with your explicit consent, which we ask for on a dedicated screen before the check starts. That screen tells you what is captured, who processes it (Amazon Web Services, in the EU), how long it is kept, and what happens if you say no.
- Verification is mandatory to be matched. You cannot be shown to other users, or see them, without passing it. (A small legacy group of users who skipped verification before it became mandatory, and accepted a rating penalty, remain matchable under the terms they agreed to.)
- Liveness selfie. Your device streams a short liveness video directly to Amazon Rekognition Face Liveness — it does not pass through our servers. AWS returns a single still frame, which we store privately as your verification reference and compare against your profile photos. The AWS session and everything in it expires three minutes after it is created.
- Face-match scores. A similarity score is stored per profile photo to decide the verification outcome. Photos where no face is detected (group shots, scenery) do not count against you.
- Selfie retention. Your verification selfie is automatically deleted 90 days after verification (Article 9 data minimisation). You remain verified; only the reference image is erased. If you verify again later, a new selfie is captured.
- Re-verification on photo changes. Every time you add, replace, or delete a profile photo, the verification pipeline re-runs against your current photos.
- Photo safety, face presence, and duplicates. Uploaded photos are checked for prohibited content, for the presence of a usable face, and for duplicates (using a perceptual hash). Rejections are logged as a minimal audit record (reason, media type, time) — the rejected media and any biometric material from it are not retained.
- Profile video. An optional profile video is scanned for safety only: a small number of frames and the audio are analysed transiently for prohibited content. The extracted frames, the audio, and the transcript are not retained — only a validation timestamp and version. The video itself is display-only and carries no identity check.
- Partner photo protection. When you are matched, your photos are shown to your match in a forward/save-protected form, and a shareable date card blurs the partner's face before it can leave the platform. If the blur cannot be produced, we refuse to send the shareable copy rather than send a clear one. (Note: operating-system screenshots cannot be technically blocked in a normal chat — this is a platform limit, not a choice.)
11. Location Data
We use location data for three narrow purposes. The first two are part of the service; the third is an optional feature that does nothing unless you turn it on:
- Your dating city. The city you select — and its coordinates — determines your match pool. You can search for a city or let us resolve it from your browser/device geolocation. A raw coordinate alone does not make you eligible for matching; you must set a city.
- Date logistics. For a confirmed date, the departure point you mark (and any raw location pin you choose to share) is used to compute a fair meeting area and to find a venue that is convenient for both of you. Your match is never shown your departure point — only the agreed venue.
- Colouring in the map you have explored (optional). If — and only if — you switch this on, we note the approximate area you are in while the map screen is open, so the map can show the parts of the city you have actually been to. We store it as a grid square roughly 1.2 km across, which is about a neighbourhood: it can record that you have been around a district, and it cannot record which street or which building. Your exact position is never stored for this, and the areas are yours alone — they are never shown to a match or to anyone else. You can switch it off at any time; switching it off stops the recording and keeps the map you have already uncovered. To erase the areas themselves, delete your account (Section 15).
We do not continuously track your location, and we do not run background location collection — including for the optional feature above, which records only while you have the map screen open in front of you, and which is off until you switch it on. Map tiles shown in our Mini Apps are proxied through our own servers, so the map provider does not receive your IP address.
12. Who We Share Data With
We do not sell your personal data. We share it in the following situations only.
12.1 With your match
When a match is created, the other person sees: your first name, age, photos (and profile video, if you added one), a verification indicator, and AI-generated text about you (a pitch, icebreakers, a hint). They do not see your contact details, your email or phone, your exact location or departure point, your psychological summary, your ratings or scores, or your safety history. Telegram contact details are exchanged only if you both explicitly choose to, through the pre-date coordination flow (Section 13).
Your match never receives your life-rhythm labels, or any statement that rhythm influenced the match, the venue or an after-date suggestion. An after-date suggestion, when there is one, is shown to both of you with the same neutral wording.
12.2 Internal operations feed
Because Gennety is an early-stage service operated by a very small team, our founder receives an internal notification feed through a separate, private Telegram bot. It carries:
- On a new activated profile: a profile card (first name, age, gender, preference, city, height, hobbies, partner preferences, language, sign-up track, verification status, attractiveness score, Telegram
@usernameif any) and your profile photos. It deliberately excludes your psychological summary. - After each weekly matching round: a link to a private, unlisted, search-engine-excluded report page showing that week's pairs with the same kind of profile cards and photos. Access to that page is controlled by an unguessable token in the URL, and the link stops working after 90 days.
- When a date is confirmed: the two date cards and the venue.
- When an account is frozen or deleted: the profile card described above, your phone number, and your profile photos, so the operator can see who left and, where appropriate, follow up personally. It still excludes your psychological summary. This goes to the same single, private, founder-only Telegram bot as every other item on this list — it is not published, not shared onward, and not held anywhere beyond that one operator's own chat with their own bot.
Please read this part carefully, because it is the one place where deleting your account does not erase everything. When you delete your account we erase your data from every Gennety-operated system — the database, our file storage, and any stored weekly-report snapshot containing you. The operational notification above is the exception: it is sent at the moment of deletion and remains in the operator's private chat afterwards.
We disclose this plainly rather than bury it, because it is a real limit on your right to erasure. Two things follow from that:
- You can ask for it to be removed too. Write to [email protected] and the corresponding messages will be deleted from that chat. We treat that as part of an erasure request, not as a separate favour.
- It is a deliberate, time-limited choice. Gennety is at an early stage and run by one person, for whom understanding exactly who leaves is currently the main way the service improves. We have recorded this internally as an accepted risk with a named tradeoff, and we review it as the service grows — it is not intended to be permanent.
12.3 Staff and administrative access
The operator of the Service can access an internal administration interface that includes user profiles, conversation transcripts, photos, and verification state, for support, moderation, and investigating abuse. It runs on a separate, key-protected, rate-limited interface, and images are streamed through an authenticated proxy rather than published.
Being straightforward about the scale: Gennety is run by one person, and that interface is protected by a single shared key rather than per-person accounts, so it does not currently produce a per-person audit trail of who viewed what. We treat that as a limitation to fix as the team grows, not as a feature.
12.4 Processors (sub-processors)
We share personal data with the following service providers strictly to operate the Service. Each acts as our processor under a data-processing agreement and may process data outside Ukraine or your country (see Section 15).
| Processor | Purpose | Data shared |
|---|---|---|
| Amazon Web Services (Rekognition Face Liveness) | Identity / liveness verification. Your device streams the liveness video directly to AWS; it never passes through our servers | Liveness video and the reference selfie it produces |
| Amazon Web Services (Rekognition) | Face comparison, face detection, and content-safety analysis of photos and video frames | Profile photos, verification selfie, transient video frames |
| OpenAI | Psychological analysis, embeddings, conversational agents, voice and video-audio transcription, content moderation, visual attractiveness scoring and (where active) appearance tagging | Profile text, voice/video transcripts, chat messages, photos |
| Supabase | PostgreSQL database hosting and private file storage (verification selfies, mobile profile photos, chat images) | Account, profile, photos, embeddings, all relational data |
| Resend | Delivering university-email verification codes | Email address, one-time code |
| Twilio | Delivering phone verification codes by SMS to mobile-app users (primary rail) | Phone number, verification status |
| Telegram Gateway | Optional secondary rail for delivering a phone verification code as an official Telegram service message | Phone number, verification code |
| Telegram | The messaging platform the bot and Mini Apps run on; also the Telegram Stars payment rail | Everything you exchange with the bot, processed by Telegram under its own policy; payment amount and confirmation |
| Apple | Push notifications and Live Activities (APNs); App Store purchases and subscriptions (App Store Server API) | Device push token and notification content; transaction identifiers and subscription status |
| Google (Places) | Venue search, venue details and venue photos for arranging dates | Approximate meeting-area coordinates of a matched pair (never your identity) |
| CARTO | Base map tiles for the map pickers, proxied through our servers | Tile coordinates only — not your IP address |
| Open-Meteo | Weather forecast for the date's city and hour, so an outdoor venue is not suggested into a thunderstorm | Approximate city coordinates and a date — never your identity |
| DigitalOcean | Hosting our application servers | Technical data, all data processed by the application |
| Vercel | Hosting the marketing website | Technical data, website request logs |
We update this list as our providers change. A current list is available on request at [email protected].
12.5 Legal and safety disclosures
We may disclose personal data where we believe in good faith that it is necessary to comply with a law, regulation, legal process, or enforceable governmental request; to enforce our Terms; to detect, prevent, or address fraud, security, or technical issues; or to protect the rights, property, or safety of Gennety, our users, or the public — including reporting unlawful conduct to the authorities.
12.6 Business transfers
If Gennety is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction. We will notify you and, where required, give you a choice before your data becomes subject to a different privacy policy.
13. Communications and the No-Chat Model
Gennety does not provide open user-to-user chat. Your conversations are with our bot and AI concierge, plus the structured pitch, decision, scheduling, venue, safety, and report flows.
There are two narrow, optional exceptions, both after you are matched and scheduled:
- Contact exchange. Shortly before the date, you may choose to share your own Telegram handle with your match, or to ask for theirs. Sharing your own needs only your tap; receiving theirs needs their explicit approval.
- Anonymous pre-date relay chat. A time-boxed relay that passes text between you and your match so you can find each other. When it is used: it opens shortly before the date and closes automatically after it; it is text-only (media is rejected, which also prevents metadata leaks); every relayed message is logged to provide a moderation and safety trail and to support the in-line report control; and those logs are deleted when the related match is deleted.
14. Payments and Subscriptions
Paid features are optional. When you buy something:
- Payment is processed by the platform's own rail — Telegram Stars inside Telegram, or Apple's In-App Purchase in the iOS app. We never receive or store your card number or payment credentials. Telegram or Apple handles those under their own terms and privacy policies.
- We retain a record of the transaction — amount, currency, status, time, the provider's transaction identifier, and what it relates to (a match, a bundle, a venue change, or a subscription period). This append-only ledger is what makes a purchase count exactly once, makes a refund possible, and meets our accounting obligations.
- For the Gennety Premium subscription, we additionally store when your entitlement started and ends, whether auto-renewal is on, which rail it came from, and the recurring transaction identifier we use to recognise renewals.
- If you cancel in chat and choose to tell us why, that free-text reason is stored against the cancellation record and used to understand churn.
- Refunds and their conditions are described in the Terms of Service.
15. International Data Transfers
Some processors are located outside Ukraine, the EEA, or the UK (for example, in the United States). Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or an adequacy decision, as applicable. You can request a copy of the relevant safeguards at [email protected].
16. Data Retention
We keep personal data only as long as necessary for the purposes above.
| Data | Retention |
|---|---|
| Account & profile data | While your account exists; erased on account deletion |
| Frozen accounts (soft-delete) | Retained intact while frozen, so you can return instantly; erased on request or on deletion |
| Verification selfie | 90 days after verification, then automatically deleted |
| Face-match scores | While your account exists (they are scores, not images) |
| Profile video frames, audio, transcript | Not retained — transient safety validation only |
| Rejected-media records | Minimal audit record (reason, media type, time) — no media kept |
| Email / phone one-time codes | Short-lived; hashed, expire quickly, and are marked consumed after use |
| Mobile sign-in sessions / refresh tokens | Until they expire, you sign out, or the account is deleted; stored hashed |
| Push and Live Activity tokens | Until the device unregisters, the token is reported dead, or the account is deleted |
| Relay-chat message logs | 90 days, and in any case deleted with the match |
| Chat timeline | 30 days, then automatically deleted |
| Promo attribution fingerprint | Up to 1 hour, held in memory only |
| Explored areas (map colouring) | While your account exists; erased on account deletion. Switching the feature off stops new recording and keeps what you have uncovered |
| Life rhythm (Tempo Sync) | While connected. Replaced on every refresh; deleted 35 days after the last refresh, immediately on "Disconnect", and on account deletion |
| Match records, score breakdowns, venue selection logs | While your account exists; erased on account deletion |
| Onboarding funnel telemetry | While your account exists; erased on account deletion (it contains no answer text) |
| Payment and subscription ledger entries | As required by accounting and tax law, typically several years, even after account deletion — kept minimal and separated from your profile |
| Safety records after account deletion (moderation status, strikes, and reports and blocks made against the account) | Kept only if the deleted account had them, linked solely to keyed hashes of its Telegram ID, verified phone number and verified email — never the identifiers themselves — and used only to stop a restricted or blocked person from resetting them by registering again; 24 months after deletion, then deleted |
| Internal weekly-report snapshots | Deleted for your account when you delete your account |
| Website cookie-consent records | Kept as proof of consent for as long as required to demonstrate compliance (append-only; see the Cookie Policy) |
| Diagnostic / technical logs | Short-term, then rotated |
On account deletion we erase the storage objects we hold for you (verification selfies, profile media, chat attachments, voice recordings — everything stored under your account, not only what your profile currently shows), remove any internal report snapshot containing your account, and then delete your account and the data tied to it across our database. Two kinds of record remain afterwards: payment and subscription ledger entries, detached from your profile, and — only if your account had them — the safety records described in the retention table above. If a refund connected to your account is still being processed, deletion waits until it has gone through, so the money has somewhere to go; you can retry then. If storage erasure is temporarily unavailable, the deletion does not report success and you can retry — we never leave a half-deleted account. Some records may be retained where required by law (for example, financial records), where a processor keeps them under its own disclosed legal duties, or in anonymised form that can no longer identify you.
One further exception is disclosed in Section 12.2: the internal operational notification sent at the moment of deletion remains in the operator's private chat. You can ask for that to be removed as part of your erasure request.
17. Data Security
We apply technical and organisational measures appropriate to the sensitivity of the data, including:
- encrypted transport (TLS) everywhere;
- private storage buckets with short-lived signed access — media is never publicly addressable;
- cryptographic verification of requests from Telegram Mini Apps and signed tokens for the mobile API, with refresh-token rotation and revocation. Our liveness result is read server-to-server from AWS rather than accepted from the client, so a device cannot claim to have passed a check it did not;
- hashing of one-time codes and refresh tokens; salting and hashing of IP addresses in consent records; masking of any verification code you type before it is written to the chat timeline;
- separate, key-protected, rate-limited administrative interfaces;
- minimisation of biometric retention (90-day selfie deletion) and non-retention of transient media used for safety checks;
- rate limiting and abuse controls on messaging and code-delivery endpoints.
No system is perfectly secure. If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where the law requires, you.
18. Your Rights
Subject to applicable law (and in full where GDPR/UK GDPR applies), you have the right to:
- Access the personal data we hold about you and receive a copy;
- Rectify inaccurate or incomplete data (note: some identity fields such as first name, age, and your verified contact rail are fixed after onboarding — contact us to correct them);
- Erase your data ("right to be forgotten");
- Restrict processing, or object to it — including any processing based on legitimate interests, and including profiling;
- Data portability — receive the data you provided in a structured, commonly used, machine-readable format;
- Withdraw consent at any time — including biometric verification, the optional visual type step, dietary/accessibility requirements, and the research opt-in — without affecting processing already carried out;
- Not be subject to solely automated decisions that significantly affect you: you may request human intervention, express your view, and contest a decision (Section 8);
- Lodge a complaint with a supervisory authority (Section 22).
How to exercise them. Write to [email protected]. We respond within the time the law requires (generally one month under GDPR, extendable by two months for complex requests, in which case we will tell you). We may need to verify that the request comes from you.
Self-service. You can also:
- Pause matching at any time, from the menu or the app;
- Freeze your account (soft-delete) — you are removed from matching and your status is hidden, but your profile, photos, verification, and embedding are kept so you can return instantly. Any in-flight match is cancelled and your counterpart is told neutrally. You are silently reactivated the next time you open the bot or the app;
- Delete your account — permanent and irreversible erasure as described in Section 16.
Withdrawing biometric consent. There is no self-service button for this yet: write to [email protected] and we will erase the verification selfie and the face-match scores we hold. Because verification is what admits you to matching, withdrawing it removes you from the matching pool — you can keep the account and re-verify later, or delete it outright.
19. Children's Privacy
The Service is intended only for users who are at least 18 years old. We do not knowingly collect data from anyone under 18. If we learn that we have collected data from someone under 18, we will delete it and close the account. If you believe a minor is using the Service, contact [email protected].
20. Cookies and Similar Technologies
Our website uses cookies and local storage; our Mini Apps and mobile app use local storage only for things they need to work (such as your language, theme, and an unsent form draft). Inside the bot we operate a no-third-party-tracking model.
Full details — the categories, what each one enables, the optional Spotify embed, the consent record we keep, and how to change or withdraw your choice — are in the separate Cookie Policy.
21. Changes to This Policy
We may update this Policy as the Service evolves. When we make material changes we will update the "Last Updated" date and the version number and, where appropriate, notify you in the app or the bot. Where a change requires new consent under the law, we will ask for it rather than rely on continued use. Continued use after a non-material update means you accept the revised Policy.
Previous versions are available on request at [email protected].
22. Complaints and Contact
For any privacy question, request, or complaint, contact us at [email protected]. We would appreciate the chance to address your concern first.
If you are in the EEA or the UK and believe we have not handled your data lawfully, you may lodge a complaint with your local data-protection supervisory authority. If you are in Ukraine, you may contact the Ukrainian Parliament Commissioner for Human Rights (Ombudsman).