1+1=1 — Privacy Policy

Version 1.0 · effective from 1 October 2026 · earlier versions · English translation; in case of doubt the Slovak version prevails.

1. Who we are

Data controller: Rastislav Janek, operator and developer of the 1+1=1 app. Contact for personal data matters: support@oneplusoneisone.eu.

2. Age

The app is intended exclusively for people aged 18 and over. If you are under 18, do not use the app and do not create an account.

3. What data we process

E-mail and sign-in identifier (Sign in with Apple / Google) — creating and managing the account.

Date of birth (day, month, year) — to verify 18+ (your age is worked out exactly from the date) and to wish you a happy birthday on the day (a notification in the morning and a card in Today; with notifications off, just the card). Other users only see your age, never the date or when your birthday is. Gender (man or woman) and who you are looking for (a man, a woman or both) — the basis for choosing Today's people; we only show you someone who is also looking for you (both ways).

Who was shown to you in Today and how you reacted (Interested / Not interested), the time of your last activity and what you have in your profile (including fields you saved but did not publish) — for ordering Today's people. The server computes the order and shows it to no one; unpublished fields are not seen by anyone else. The order in Today also takes into account whether people respond in conversations: someone who repeatedly stops replying is offered to others somewhat less often — never disappears entirely, and it evens out over time. This is profiling (Art. 4(4) GDPR) for the purpose of a fair offer for everyone, based on legitimate interest; it has no legal or similarly significant effects (it doesn't change whom you see, nor your messages or meetings) and you can object (section 7).

The meeting place and time you write in the meeting detail — stored readably (not encrypted) so both of you see them; deleted when an account is deleted.

Phone number — a CONTACT detail, OPTIONAL: the app asks for it only the first time you share your contact after a mutually confirmed meeting, and it is shared only then. You can change or delete it at any time. The app does NOT verify it and claims nothing about it — it is not proof of identity nor a guarantee of “one account per person”. It is never public.

Nickname and an optional short description.

Optionally, a few words from you with a photo (caption) and a city name — the city is added only at your explicit choice and ONLY the city/region name is stored, never coordinates or a street. Others see the caption and city together with the photo, and both go through the same content check.

Result of face verification (yes/no, time, how many degrees the head turned to each side, and an approximate age estimated from the frontal frames) — the frames used for the check are not stored on the server or on the phone. The age estimate is used to verify 18+: when it reaches the threshold (21 years by default), the age is verified automatically; otherwise a person from the operator's team checks the age (they see the nickname, profile photo, age estimate and entered date of birth) and, when in doubt, asks for ID document verification with a short face check at the processor Didit (a processor under Art. 28 GDPR, processing in the EU; Didit processes the document and images and deletes the session after the result). From that verification we keep ONLY the result — 18+ yes/no, the date of birth and issuing country from the document, the day of verification and Didit's verification reference; the date from the document replaces the entered one. We never store a copy of the document or the photo. Until the age is verified, the profile is not shown to others in Today and you cannot send interest, accept a request or write messages. The estimate never blocks anyone on its own and other users do not see it. The check is performed by our own server (api.joinfamiglia.com), not by a third party.

Result of the 18+ gate: whether you are 18 according to your date of birth. When you sign in, the app checks your sign-in identity (Apple/Google) and stores only a one-way fingerprint (hash) of it, never the account identifier itself — used solely so that a block (under 18 or exclusion) also applies to a new account with the same account. With a date under 18 the account is blocked until the day of the 18th birthday; until then we keep the date of birth, the unblock date, the approximate age from the face scan (deleted when the operator rejects a correction request, or at unblocking) and the fingerprint of the account and sign-in identity. If you send a date correction request, the date from the request, your note and the operator's decision are stored. On the 18th birthday the block is lifted by itself. For accounts from the period when the 18+ gate ran through Apple (until 27 September 2026), also Apple's answer (age range 18–29, 30–44 or 45+ and its source) — the date of birth from the Apple account was neither transferred nor stored. Gender is not estimated from photos.

Confirmation from Apple that the app runs on a genuine device and has not been modified (App Attest and DeviceCheck). It is not an identifier of your phone — Apple guarantees the device cannot be determined from it; it serves to prevent a new account from being created on a device from which we blocked someone, and — if the 18+ gate via Apple is switched on — to let the server verify that Apple's answer was sent by the genuine app (we store only the public key the app creates for this on the phone and a count of its uses).

Region and city — we store only your main region (and, for a photo, the city name if you add it). The app evaluates your location (approximate, once) only on your phone; the coordinates never leave the phone and we don't store them anywhere.

Chat content — messages are end-to-end encrypted directly on the sender's phone and stored on the server only in encrypted form. Encryption keys exist only on users' devices; the operator does not have them and CANNOT read message content. The server can see only who communicated with whom and when (metadata), how many messages were exchanged and their approximate length (the length of the encrypted text). The app evaluates the rhythm of a conversation only from the number and timing of messages (how much you wrote and over how many days), never from their content; it sends only message counts to the server, never text.

Conversation history — after a conversation ends (including by blocking) it stays read-only for both people, together with the other person's name, whether you ended it (the other person only sees “The conversation ended”, without the name of whoever ended it), and a copy of the other person's profile photo from the time it ended (no other photos or later changes). Blocking looks exactly like an ordinary ending to the other person. Only the person who gave a reason for ending sees it. An ended conversation, including the profile photo copy, is deleted for both people 90 days after it ended (the operator may change this value, never below 7 or above 365 days); a reported conversation stays as long as the moderation rules require. When the other person deletes their account, the copy of their profile photo disappears immediately.

The private key is only on your devices — your iPhone and your iCloud Keychain (automatic backup: on a new iPhone with the same Apple ID your history comes back by itself); each account has its own key. The server additionally holds an ENCRYPTED copy that only your 12-character recovery code can open — the code is stored only on your phone and in iCloud Keychain (shown after Face ID) and is never sent to the server in readable form, so the operator cannot open the copy. The server also remembers your public keys and, with each message, the public keys of both sides (public keys aren't secret), so older messages can still be read after someone changes phones. Without iCloud Keychain and without the recovery code, your older messages can't be opened on a new phone (the other person still sees them). When you delete your account, the app also deletes the key, the code and the history on the phone.

Conversation excerpt when reporting — when you report someone, your device attaches the last 20 messages of that conversation in readable form so the report can be assessed. This happens only at your initiative, the app explicitly tells you so on the report screen, and nothing is decrypted without a report. The report and the excerpt remain even after the reporter deletes their account — for safety reasons, since the reported person may really be dangerous — but without the reporter's identifier or name (the sides in the excerpt are labelled only “Me” and “The other person”). The excerpt (including the reporter's own messages) is deleted automatically at the latest 6 months after the case is closed, the report itself after at most 12 months.

Reports and moderation — on a report “Looks like a minor”, the reported account is temporarily suspended right away and we only record that it is suspended and since when (the record disappears with the decision); to prevent abuse we count how many accounts reported this way the team confirmed as adults — someone with a set number of them (3 by default) no longer suspends accounts with further such reports. a report is reviewed by a person from our team: a moderator (a trusted user appointed by the operator) or the operator. A moderator sees the reason and text of the report, the conversation excerpt attached by the reporter (never the whole chat — it is encrypted and they cannot read it), the reporter's nickname, the reported person's nickname, profile photo and year of birth and their previous reports and actions; for a photo review the photo itself. They do not see the phone number, e-mail, location or message content, and they do not handle cases of people they have been in contact with in the app. Every action they take (who, when, what and why) is written to a record that only the operator sees and that the moderator cannot change or delete. Who decided about you is not shown to you.

Messages from the team — when the 1+1=1 team writes to you about an age check, a photo or a report, the conversation with the team (its messages and your replies) is not end-to-end encrypted: it is read by the admin and the moderator handling the case. You see the sender as “1+1=1 Team”, never the name of the team member. We keep it with the case under the moderation rules, for at most 12 months; if you delete your account it is deleted immediately. The notification about a new message doesn't contain its content.

Push notification token — only if you allow notifications on your phone. It serves solely to deliver notifications about events concerning you (request, message, connection, meeting, a reviewed report, a verified age, a message from the team, a birthday greeting; the greeting is sent in the language of the app on your phone, so the app remembers the device language for notifications). A notification sent to your lock screen (push) never contains the other person's name, and the server does not store a name in the notification. In the app's Notifications list you do see the name — the app fills it in from that person's profile on your phone; after account deletion it is no longer shown (after a block it stays, as in History — a block has to look like an ordinary ending). When you turn notifications off or the device stops accepting the token, the app deletes it. Your phone's time zone (for example Europe/Bratislava) and your quiet hours — so notifications at night wait until morning in your time. The app sends the time zone when it starts; you set quiet hours yourself in Settings → Notifications.

Error diagnostics — when something fails or crashes in the app, a technical record is stored: app version, device type and iOS version, the screen and a technical description of the error. It never contains message content or anything you wrote. It is deleted after 90 days.

Usage statistics (analytics) — so we know whether the app does what it promises (where people drop out of sign-up, how many conversations lead to a meeting, who comes back to the app), we store events in our own database: what happened (e.g. “sign-up step shown”, “request sent”, “message sent” — only that it was sent, “meeting confirmed”, “notification opened”), when, your pseudonymous identifier, region, gender, age band (e.g. 25–34) and app version. NEVER message content, answer text, photos or location — the server rejects anything other than a number, yes/no or a short code. We use no third-party analytics tools (Firebase, Meta, etc.). Raw events are kept for at most 24 months, daily totals per region (without identifiers) without limit. Only the operator sees them. When you delete your account, your identifier is detached from the events — only anonymous ones remain (what, when, region, gender, age band) so the statistics stay truthful.

App version on your device — each time the app starts, it sends the app version (including the update number), device type and iOS version together with a random installation number (not a phone identifier), so the operator knows whether an update has arrived. It is deleted 90 days after the last start and immediately when the account is deleted.

Purchase record — if you pay the entry fee, the Apple transaction identifier is stored so the purchase can be verified. Payment details (card) are held only by Apple; the app does not see them.

Consent to the Terms and the Privacy Policy — which version of the document, the date and time, the language and the app version; for a new version of the Privacy Policy, also that the notice was shown to you. Every consent is a new record that cannot be changed or deleted — it is proof of consent. Only the operator sees it.

Codes — which code you redeemed and when; founding status (yes/no). For a wrong code, only the time of the attempt, the account and a fingerprint (hash) of the IP address — not the address itself nor the code tried — solely to protect codes from being guessed.

Test version (TestFlight): while you test the app via TestFlight, Apple sends the developer feedback (text and a screenshot) and crash reports — only those you send yourself, or crashes you allowed to be shared in TestFlight. We keep from them only what is needed to fix the bug, without the tester's e-mail: the screenshot in the app's private storage, which only the operator can access, and the crash log on our server — both for at most 90 days, then deleted.

Safe Date: the app has no access to your contacts. The Safe Date contact you pick or enter yourself stays only on your phone (the iPhone's secure storage, not a backup or the server) and is deleted when you sign out or delete your account. Neither the name, the number, nor the fact that you turned on Safe Date ever reaches us.

4. Legal basis

Providing the service (performance of a contract — Art. 6(1)(b) GDPR), age verification and user safety (legitimate interest — point (f); the app is an 18+ dating app with photos of real people), reports and their review by a moderator or the operator (legitimate interest — safety). Automated processing: the face age estimate can temporarily hide a profile from Today and pause sending interest and writing until a person reviews the case; unclear ages are always decided by a person, not an automated system (Art. 22 GDPR).

5. Who we share data with (processors)

Supabase — database, sign-in, storage. Didit (didit.me) — age verification with an ID document, only when the team asks for it; processing in the EU, deletes the session after the result.

Apple — sign-in (Sign in with Apple), payments through the App Store and delivery of notifications (Apple Push Notification service).

Google — sign-in (if you use it).

Expo — app updates and handing notifications over to Apple's service (Expo Push Service); it sees only the device token and the notification text without the other person's name.

Message text is stored on the server only encrypted and without the key; neither the operator nor Supabase can read it. It is not sent to any other third party.

Face check snapshots go to our own server (api.joinfamiglia.com), not to a third party, and are not stored.

Hetzner Online (Germany) — rental of our server (face check, photo moderation, backups).

Cloudflare — network connection to our server: requests including face check snapshots pass through its network.

Where data lives: the Supabase database in the EU (Stockholm), our server in Germany. Apple, Google, Expo and Cloudflare are US companies — with their services data may leave the EU, based on their contractual safeguards for data transfers.

6. How long we keep data

As long as you have an account. Unfinished sign-up: the data you entered is deleted automatically after 30 days of inactivity (the operator may change this value, never below 7 days); you can also delete it yourself with the “Delete account” link on every step of sign-up.

FREEZING the profile (Settings → Leave 1+1=1 → Freeze) deletes NOTHING — the profile just disappears from Today's people; the verification and conversations are kept for a possible return. After 12 months frozen, the account is deleted in the same way as a deletion below.

DELETING THE ACCOUNT (Settings → Leave 1+1=1 → Delete, or “Delete account” during sign-up) is real, not deactivation. RIGHT AWAY: the app signs you out on all devices, the profile disappears from Today's people, Connections and History for everyone, and the following are permanently deleted: photos (the row and the file — a cleanup process removes the file usually within a few minutes), all messages in your conversations on the server on both sides, encryption keys, answers, tags, relationship intent, regions, settings, the 18+ gate result, the age estimate, date of birth, phone number, notifications and push tokens. Ongoing conversations show the other person “Account deleted” with no name or photo, and the app also deletes the copy of the messages on their phone the next time it opens. Arranged meetings, their confirmations and ratings are deleted too — for both sides. If you later sign up again with the same sign-in, nothing from the old account comes back. On your phone the app also deletes the stash of unpublished photos and cached photo previews.

WITHIN 30 DAYS these empty conversations and the record of the deletion in progress are deleted too.

WHAT STAYS is only: an anonymised count of deleted accounts, without any ID; the records of consent to the Terms and the Privacy Policy (version, time, language, app version) without your identifier — as proof that the terms were accepted; anonymous statistics events without your identifier for at most 24 months; the reason for leaving, if you picked one in the survey (without an ID and without any text you wrote); reports you filed, without your ID, for at most 12 months — they are evidence when assessing the reported person (the attached conversation excerpt, including your messages, is deleted at the latest 6 months after the case is closed); and for a payment, Apple's transaction ID without a link to you, so the same purchase can't be used again. If the operator blocked you for breaking the rules, or our team decided that the account belongs to someone under 18, a one-way fingerprint (hash) of your sign-in identifier and the reports about you (reason, text and date, no photos) also stay for at most 12 months — so a new account can't be created right away. If the account was blocked because the date of birth is under 18, the fingerprint (hash) of the account and sign-in identity and the day the block ends (without the date of birth) remain until the 18th birthday — then they are deleted automatically. Otherwise you can create a new account from scratch with the same sign-in after deletion.

EMAIL AND SIGN-IN IDENTIFIER (Apple/Google) are deleted too — right when you delete the account, and if that isn't possible yet (conversations that stay with the other person as “Account deleted”), within 30 days at the latest. Exception: we currently share the sign-in system with the operator's other apps — if you use the same email in one of them, the sign-in record stays there (otherwise we would delete your account in that app too); 1+1=1 has nothing about you and the app tells you so after the deletion. If you signed in with Apple, the app also revokes the link with Apple when you delete the account; if that fails, it tells you how to remove it on your iPhone. For an unfinished sign-up that the app deletes by itself after inactivity, the sign-in record stays; we delete it at your request — write to support@oneplusoneisone.eu.

BACKUPS: our provider (Supabase) does not back up the database on our plan and photos are not backed up at all. Before larger database changes the operator makes a backup on its own server (Germany, operator access only); each one deletes itself after 30 days, so an account deletion within 30 days applies to it too.

MODERATION RECORDS: the record of a moderator's action (dismissing a report, a warning, a suspension, a removal proposal, a decision on age or on a photo) and a decided removal proposal are kept for 12 months, then the app deletes them itself. When an account is deleted, the record is unlinked from it. A suspension is lifted automatically when the period ends (within an hour at the latest).

UNPUBLISHED PHOTOS are deleted by the app itself after 7 days — the row and the file.

When you delete a photo, the app deletes the ROW AND THE FILE — it does not merely hide it. A cleanup process removes the file usually within a few minutes; until then it is already unreachable because no link to it can be created. We will not keep a photo you never published indefinitely just because you did not decide.

7. Your rights (GDPR)

You have the right of access, rectification, erasure, restriction of processing, portability and objection. Write to support@oneplusoneisone.eu. You also have the right to lodge a complaint with the Office for Personal Data Protection of the Slovak Republic (dataprotection.gov.sk).

Automatic hiding of a profile (section 9 of the Terms of Use) is a solely automated decision based on a count, not a human decision — you have the right not to be subject to such a decision (Art. 22 GDPR). The app always informs you about it directly in the app and offers to request a review by a human.

8. Changes

We may update this document; the new version will always be available in the app with the date of the last change.

Terms of Use · Slovenská verzia