Account data. An email address, a username and a passcode when you create an account. The passcode is stored only as a salted hash. We need this to give you an account and to let you get back into it.
A device identifier. Generated on your device when the application first runs. It is how a ban attaches to a device, how your address-book hashes are salted, and how your local state is kept consistent. It is not an advertising identifier and it is not shared with advertisers.
Age and verification data. Your date of birth or age, and — only if you choose to verify — a photograph of an identity document and a selfie, which are sent to our verification partner. No person at inaff looks at your document. We receive the outcome of the check and a small set of flags, not the document itself.
Profile photographs. Up to three, checked automatically as described in section 5. There is deliberately no free-text biography anywhere in the product, so there is no field in which to write personal information about yourself or anybody else.
Answers and derived traits. Your answers to the scenario questions, the personality axes computed from them, your chosen interests, and your stated preference about who you want to be matched with. This is the matching engine; without it there is no product.
Approximate location. Coarse location, and only when you grant it. It is used to work out whether there are enough members near you and to place quests. You control the precision shown to a match: district-level by default, exact only if you choose it.
Usage and diagnostic data. Quests accepted, completed and abandoned, cooldown state, crash and error reports. Used to keep the product working and to detect abuse.
Payment data. Handled by our payment provider or by Google Play. We receive a record that a subscription exists and when it ends. We never receive or store your card number.
Support data. What you write in a ticket, and the codes issued with it. Reports and appeals, including what the reporter wrote and what we did about it.