What the service processes
The private beta does not require precise device location, contact-book access, advertising identifiers, or payment data.
- Account data: email address, authentication records, and account identifiers.
- Adult eligibility and profile data: birth date, displayed age, name, biography, avatar, and discovery preferences. Exact birth dates are not shown to other members.
- User content: text, images, short videos, thumbnails, captions, and associated media metadata.
- Dating interactions: post passes and likes, reciprocal sparks, chat consent, messages, unread state, blocks, and connection history.
- Safety data: report categories and details, moderation status, moderator actions, and support correspondence.
- Operational data: request metadata and logs needed for security, abuse prevention, debugging, and reliability.
- First-party product events: bounded event names and coarse metadata such as media type, feed action, spark count, or report category. These payloads do not contain meme text, message bodies, report details, or email addresses.
Why data is processed
Data is used to authenticate members, establish adult eligibility, publish and deliver media, calculate reciprocal meme-based connections, open mutually consented chats, operate safety controls, prevent abuse, provide support, and maintain the service.
Service providers
Supabase provides authentication, database, private media storage, realtime delivery, and server functions. Resend provides transactional authentication email. These providers process data under their own contractual and security terms and may process it in different countries.
Sharing and sale
Profile and approved post data are shown only through member-facing product surfaces. Private reactions, reports, blocks, exact birth dates, and unopened chats are not made public. Personal data is not sold.
Data may be disclosed when required by law, to protect people from credible harm, or to investigate abuse and security incidents.
Retention and deletion
Members can delete individual posts and initiate permanent account deletion inside the app. Account deletion removes owned media and the authentication account, then cascades through profile, post, interaction, connection, and message data.
Reports submitted by a deleted member are removed. Reports about a deleted account or deleted content may remain in anonymized form for safety audit purposes. Limited security logs and encrypted backups follow the shortest operational expiry schedule available in the hosting plan and are not restored except for disaster recovery or security investigation.
First-party product events are kept for no more than 90 days and are anonymized when an account is deleted.
Choices and rights
Members can edit profile data, remove posts, block accounts, sign out, or delete the account in-app. Requests concerning access, correction, deletion, or an appeal can be sent to support@onlineunfortunately.com. Applicable rights depend on the member’s location.
Children
The service is for people aged 18 and older. Suspected underage accounts should be reported immediately and may be suspended while reviewed.
Security and changes
The service uses access controls, row-level authorization, private media storage, and server-side privileged operations. No system can guarantee absolute security. Material policy changes will be published here with an updated effective date.
Contact
For privacy questions or requests, email support@onlineunfortunately.com. Include the email associated with your account, but never send your password or authentication code.