A dating app built on where people actually go. Approximate crossings, verified profiles, human moderation — never live location.

EN TR

Write to us

Privacy Policy

Effective August 4, 2026 Passn LLC All legal documents Questions? Contact support

Effective date: August 4, 2026

Last updated: August 4, 2026

Data controller: Passn LLC, 8 The Green, Suite 23215, Dover, DE 19901, United States.

Contact: privacy@passn.app.

1. Summary

Passn is a dating / social-discovery service for adults. To run it we process the information you provide, the photos you upload, your approximate location — including, with your permission, coarse readings taken while the app is closed — and metadata about the messages and calls you exchange with matches. Your exact real-time location is never shown to other users. You can delete your account and the data we hold about you at any time from Settings → Delete account.

This page explains what we collect, why, and how to exercise your rights. If you want to skip to a specific topic:

2. Data we collect

CategoryExamplesSource
Account identifiersemail, optional phone, Apple/Google subject idYou, your sign-in provider
Profile informationdisplay name, date of birth, gender, sexual orientation (interested in), looking-for intent, bio, height, job, education, lifestyle, zodiac, country/city, social handlesYou
Profile photosup to 6 imagesYou
Discovery preferencespreferred genders, age range, distance, visibilityYou
Approximate locationlatitude/longitude, indexed into an H3 cell (resolution 9, ~174m edge) for matchingDevice GPS, with your permission
Encounter recordsapproximate centre (midpoint of the two people, randomly offset by up to 50m), distance, time when two users crossed pathsDerived server-side
Likes / matcheswho you liked, mutual matchesYou + other users' actions
Messages and call metadatatext, image storage keys, voice-note storage keys, message timestamps, read receipts; for calls: caller, callee, type (audio/video), state, durationYou + your conversation peers
Subscription informationplatform (Apple/Google), product id, transaction id, state, expiry, auto-renew flagApple / Google in-app purchase APIs
Device & technical datadevice model, OS version, app version, push token, language, network type, IP addressYour device
Safety & moderation datareports you filed or received, blocks, moderation case decisionsYou + our moderation team
Audit logprivileged actions, security-relevant eventsSystem

We do not record call audio or video; calls are routed peer-to-peer via Agora's real-time infrastructure.

We do not sell personal data and we do not share data with third-party data brokers.

3. Why we use it — lawful basis

PurposeCategories usedLawful basis (GDPR / equivalent)
Create and operate your accountAccount identifiers, profile, devicePerformance of contract (Art. 6(1)(b))
Match you with nearby usersApproximate location, encounters, preferences, profilePerformance of contract
Enable messaging and calls between matchesMessage + call metadataPerformance of contract
Keep the service safe (block, report, moderation)Safety & moderation data, audit log, IPLegitimate interests (Art. 6(1)(f)) and legal obligation where applicable
Verify and grant subscription entitlementsSubscription informationPerformance of contract
Deliver push notificationsDevice id, push tokenConsent + performance of contract
Comply with law (e.g. CSAM reporting)Whatever the order requiresLegal obligation (Art. 6(1)(c))

Where consent is the lawful basis (e.g. precise location, push notifications), you can withdraw consent at any time from your device settings — withdrawal does not affect the lawfulness of processing performed before withdrawal.

4. Who we share it with

We share personal data with the following categories of recipients, each bound by a written processing agreement and only to the extent needed:

RecipientPurposeWhereMechanism
Amazon Web Services (AWS)Application hosting, database, object storage for photos and chat media, and the face-verification checkeu-central-1 (Frankfurt, European Union)Processor; standard contractual clauses where data leaves the EU
Apple App Store & Google PlaySubscription validationGlobalJoint controllers for the purchase, processors for app distribution
AgoraReal-time voice/video transportGlobal (multi-region edge)Processor; media not recorded
Apple Maps (MapKit)Rendering the crossing map on your deviceApple infrastructureIndependent controller for map requests; we send no profile data with them
GiphyGIF search inside chatGlobalProcessor; searches are not linked to your profile
Firebase Cloud Messaging + Apple Push Notification ServicePush deliveryGlobalProcessor
Transactional email providerVerification, password-reset and notification emailEuropean UnionProcessor
Crash and error reportingDiagnostics, when enabled on a buildEuropean UnionProcessor
Sign-in providers (Apple, Google)Federated authenticationGlobalIndependent controller for the auth handshake
Law enforcementWhere legally compelled (warrant, court order)DependsLegal obligation
Acquirers / successorsCorporate transactionDependsNotice will be given

Other users see only the information you choose to make visible: your display name, photos, profile fields, and shared messages within an active match. They never see your email, phone, or exact location.

5. Retention

DataDefault retentionNotes
users (account row)Lifetime of the account, then 30 days post-deletionAfter deletion grace period the row is hard-deleted; cascades remove dependents
profile_photosUntil you delete them or your accountObject storage purged on delete
location_points (raw GPS)72 hoursHourly BullMQ retention job
encounters (approximate centres)90 daysDaily BullMQ retention job
chat_messagesLifetime of the match (or until you delete)Soft-delete; hard delete 30d after account deletion
calls (metadata only)12 monthsRetained for safety/abuse investigations
audit_logs365 daysAppend-only; admin-only access
subscriptions + purchase_receipts7 yearsRequired for tax/financial audit
legal_acceptancesLifetime of the account, then 7 yearsProof of consent
reports + moderation_casesLifetime of the account, then 2 yearsRecurrence prevention
Banned-account PIIHashed and minimised after 30 daysIdentifiers retained to prevent re-registration

6. Your rights

Depending on where you live you have the following rights regarding your personal data:

  • Access: receive a copy of the personal data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: ask us to delete your account and the associated data.
  • Restriction: ask us to limit processing in specific cases.
  • Portability: receive your data in a machine-readable format.
  • Objection: object to processing based on legitimate interests.
  • Withdraw consent: for any processing where consent is the basis.
  • Lodge a complaint with your supervisory authority.

To exercise any of these rights, email privacy@passn.app. We respond within one month (or sooner where required by law); we may extend by two further months for complex requests.

7. Account deletion

From the app: Settings → Delete account. The deletion is scheduled 14 days in the future ("grace period"). During grace you can cancel by signing in. After grace, the account is hard-deleted and dependent records are removed via cascade. Some data is retained for the periods listed in Section 5 when required by law or for safety or financial reasons.

8. Children

Passn is 18+ only. We do not knowingly collect personal data from children. We enforce this through a registration age gate, a database CHECK constraint, and a moderation queue that escalates suspected minors to suspension and, where applicable, NCMEC/local authorities. If you believe a child is using the Service, email abuse@passn.app.

9. International transfers

Personal data may be transferred to and processed in countries other than the one you live in. Where required, we use Standard Contractual Clauses (SCCs), adequacy decisions, or other approved safeguards. You can request a copy of the relevant transfer mechanism.

10. Security

Industry-standard controls protect your data:

  • Encryption in transit: HTTPS / WSS only; TLS 1.2+.
  • Encryption at rest: managed-storage default-encryption.
  • Tokens: Argon2id-hashed passwords; JWT access tokens (15 min); rotating refresh tokens with reuse detection.
  • Secrets: loaded from environment, never logged.
  • Audit: every privileged action recorded in audit_logs.
  • Moderation: photo review queue; report flow; ban/suspend.

No system is perfectly secure. If you suspect your account has been compromised, contact security@passn.app.

11. Cookies and SDK technologies

The mobile app uses persistent local storage (Keychain / encrypted shared preferences) for session tokens and a Hive KV store for non-sensitive preferences. No third-party advertising SDKs are embedded. Third-party SDKs in use are listed in docs/compliance/google-play-data-safety.md.

12. Changes to this policy

We may update this policy. Material changes will be announced in-app and via email at least 14 days before they take effect.

13. Contact


Privacy Policy · Passn LLC, 8 The Green, Suite 23215, Dover, DE 19901, United States · legal@passn.app