inaff.sign up
legal · privacy

Privacy Policy

VERSION 1.1 · EFFECTIVE 15 SEPTEMBER 2026

What inaff collects, why, who it is shared with, how long it is kept, and what you can make us do about it. Where the honest answer is that we cannot read something or cannot recover it, that is stated rather than softened.

DRAFT — NOT THE FINAL PUBLISHED VERSION

The operating entity, the governing jurisdiction and the designated copyright agent are not filled in yet, so every place this document names one reads as unfinished. Fill in legal/entity.json and re-run node legal/sync.mjs before launch.

1Who is responsible for your data

The controller of the personal data described in this policy is Inaff Legal Department, at Your Real Address or Registered Agent Address. Where a data protection officer or a representative is required, the contact is dpu@inaff.app, and our representative in the European Union and the United Kingdom is N/A.

This policy covers the inaff mobile application, the website at inaff.app, and the inaff for business console. It does not cover anything that happens after you and another member leave the platform and meet in the world.

2The short version

We collect the least we can operate on, we do not sell it, and there is no advertising identity built from it. Advertisements shown inside the application are rewarded video that you choose to watch in exchange for something specific; they are not targeted using your profile, your answers or your matches.

Three things are designed so that we cannot see them even if we wanted to: the contents of your messages, the phone numbers in your address book, and your support passcode. Each is explained below, along with what that costs you.

We do not build a social graph. There is no people-you-may-know, no friend finder, and nobody in your phone book is ever told that you are here.

3What we collect, and why

Account data. An email address, a username and a passcode when you create an account. The passcode is stored only as a salted hash. We need this to give you an account and to let you get back into it.

A device identifier. Generated on your device when the application first runs. It is how a ban attaches to a device, how your address-book hashes are salted, and how your local state is kept consistent. It is not an advertising identifier and it is not shared with advertisers.

Age and verification data. Your date of birth or age, and — only if you choose to verify — a photograph of an identity document and a selfie, which are sent to our verification partner. No person at inaff looks at your document. We receive the outcome of the check and a small set of flags, not the document itself.

Profile photographs. Up to three, checked automatically as described in section 5. There is deliberately no free-text biography anywhere in the product, so there is no field in which to write personal information about yourself or anybody else.

Answers and derived traits. Your answers to the scenario questions, the personality axes computed from them, your chosen interests, and your stated preference about who you want to be matched with. This is the matching engine; without it there is no product.

Approximate location. Coarse location, and only when you grant it. It is used to work out whether there are enough members near you and to place quests. You control the precision shown to a match: district-level by default, exact only if you choose it.

Usage and diagnostic data. Quests accepted, completed and abandoned, cooldown state, crash and error reports. Used to keep the product working and to detect abuse.

Payment data. Handled by our payment provider or by Google Play. We receive a record that a subscription exists and when it ends. We never receive or store your card number.

Support data. What you write in a ticket, and the codes issued with it. Reports and appeals, including what the reporter wrote and what we did about it.

4What we cannot see

Message contents. Messages are encrypted in the application before they leave your device, using an ephemeral key agreement and authenticated encryption. The server stores ciphertext. Screening of message content for harm happens on your own device, not on ours. The consequence, stated plainly: we cannot read your conversations, we cannot hand them to you, and we cannot hand them to anybody else, including in response to a lawful request. What we can produce is metadata — that two accounts exchanged messages, and when.

Your address book. If you turn on hide-from-contacts, numbers are read, normalised and hashed on your device, salted with your device identifier, and the plaintext is discarded inside a single function call. Only the hashes leave the device. Because the salt is per-device, the same phone number produces a different digest on two different phones, so these values cannot be joined against each other, against a leaked table, or against a precomputed list of every number in a country. Turning the feature off deletes the hashes; it does not archive them.

Your support passcode. Stored only as a scrypt hash salted with the ticket's login code. A dump of that table does not let the holder read anybody's ticket — and it means we cannot recover your passcode for you either. That trade is the whole reason a person can appeal a ban on that page without telling us who they are.

5Automated processing

Profile photograph check. Every profile photograph is sent to a third-party vision model and asked two narrow questions: is this a real human face, and is this person a child. The model is never asked to judge, rank or describe anybody. There are four outcomes: approved; not a real photograph, which carries no penalty and can be retried freely; apparently a minor, which bans the device for eighteen years with an appeal opened immediately; and unavailable, which means the photograph was not checked and is not approved. A screening step that fails open does nothing on the one day it matters, so a missing key, a timeout or an unreadable response all mean not checked, never fine.

Matching. Filters and a compatibility score decide who you are shown. This has no legal effect on you and is not a decision within the meaning of Article 22 of the GDPR, but you can ask a person to look at it.

Support triage. A language model answers common questions from a fixed policy sheet and is not permitted past it. Anything about a bug, a payment, a ban, an appeal, safety or law goes to a person, and so does anything the model is unsure about. It fails closed: on any error the ticket is escalated rather than answered confidently with nothing behind it.

Enforcement. Bans and suspensions may be initiated automatically. Every one of them can be appealed to a person, and the appeal route does not require an account.

6Why we are allowed to process it

Where the GDPR or a comparable law applies, we rely on: performance of a contract, for everything needed to run your account, match you and deliver quests; legitimate interests, for security, abuse prevention, and keeping the product working, balanced against your rights; consent, for optional things you switch on yourself — location, contacts, notifications, and identity verification — each of which you can withdraw at any time without losing the rest of the product; and legal obligation, for accounting records and for responses to lawful requests.

Verification data and anything revealing about your identity document is treated as sensitive and is processed on the basis of your explicit consent, for the single purpose of confirming that you are an adult.

7Who we share it with

We do not sell personal data and we do not share it for cross-context behavioural advertising. We share it with processors who run parts of the Service on our behalf, each bound by contract to use it only for what we ask: our hosting and database provider; our payment provider, and Google Play for purchases made through that store; our identity verification partner; the provider of the vision, language and quest-writing models; and our voice-call provider.

We may disclose data where the law requires it, where it is necessary to establish or defend a legal claim, or where we believe in good faith that disclosure is necessary to prevent imminent serious harm to a person. Where we are permitted to tell you that this has happened, we will.

If the business is ever sold or merged, personal data may transfer with it. You would be told before that took effect, and the buyer would be bound by this policy until you were asked to accept a new one.

8International transfers

Our providers operate in several countries, including the United States. Where personal data leaves the European Economic Area or the United Kingdom, the transfer is covered by the European Commission's standard contractual clauses and the UK addendum, together with whatever additional measures the circumstances require.

You can ask us which provider holds which category of data and where, and we will tell you.

9How long we keep it

Account data is kept while your account exists and is deleted when you delete it.

Identity documents are not kept by us at all. Our verification partner holds them under its own retention schedule; we keep only the outcome and the date.

Message ciphertext is deleted with the account. Because we never held the keys, deleting it is the end of it in every practical sense.

Ban records, appeal records and the reports that led to them are kept for as long as the ban lasts, so that a banned device cannot be cleared by reinstalling the application, and so that an appeal can be reviewed against what actually happened. For an eighteen-year minor ban, that is eighteen years, and that is the longest retention period in this product.

Support tickets are kept for two years from the last message. Accounting records are kept for the period the applicable tax law requires, typically between five and ten years.

Aggregate counts that cannot be linked back to a person — how many people are active in an area, how many quests ran this week — are kept indefinitely.

10Your rights

Depending on where you live, you have some or all of the following rights: to know what we hold about you and get a copy of it; to correct it; to delete it; to restrict or object to certain processing; to portability; to withdraw a consent you gave; and not to be discriminated against for exercising any of them.

In-app deletion is the fastest route and needs no request: it removes your profile, matches, answers and local data. For everything else, open a ticket and mark it as a data request. We will ask for enough to be confident that we are answering the right person and no more than that, and we will respond within thirty days or the shorter period your law requires.

If you are not satisfied, you may complain to your local data protection authority. If you are in the EU or the UK, that is the supervisory authority where you live or work.

We do not use your data to profile you for advertising, so there is nothing to opt out of there.

11Children

The Service is for adults of 18 and over. We do not knowingly collect personal data from a child, and we do not offer any child-directed feature.

If we learn that a child has created an account, the account is closed and the device is banned as described in the Terms. If you believe a child is using the Service, open a ticket and mark it as a safety matter; it goes to a person immediately.

12Security

Data is encrypted in transit. Messages are additionally encrypted end to end. Passcodes are stored only as salted hashes, using a memory-hard function. Access to production data is limited to the people who need it and is logged.

No system is perfectly secure, and we do not claim otherwise. If a breach occurs that is likely to put you at risk, we will tell you and the relevant regulator within the time the law allows, and we will say what actually happened rather than issue a paragraph that avoids saying it.

13The website

The website sets cookies that are strictly necessary: a session cookie if you sign in, and a preference cookie for the light or dark ground. There is no analytics cookie, no advertising pixel, and no third-party tracker, which is why you are not asked to dismiss a consent banner to read this page.

Server logs record IP address, user agent and the page requested, are used for security and debugging, and are deleted after thirty days.

All four policies are readable on the website without an account, without signing in, and without accepting anything.

14Changes to this policy

If we change this policy materially we will tell you in the application before the change takes effect and ask you to accept the new version. The version number and effective date at the top of this document identify the version you accepted.

15Contact

There is no support email address. Open a ticket at inaff.app/support and mark it as a data or legal matter, and it goes straight to a person — the automated first line is not permitted to touch data-access requests.

Postal notices: Inaff App, Your Real Address or Registered Agent Address.

QUESTIONS

Open a ticket at /support and say it is a legal matter. It goes straight to a person — the automatic first line is not allowed to touch legal, press, safety or data-access requests. There is no email address, for us or for you: a legal question sent by mail arrives with no case file and no way to prove later what was asked or when.

BUNDLE 1.1 · THE SAME TEXT IS IN THE APP, GENERATED FROM ONE SOURCE