Legal

Privacy Policy

What Uneven collects, why, where it lives, and how to make it go away.

Template prepared for launch review — have counsel review before publication.

This document was drafted to describe the Uneven app as actually built. It is not legal advice and has not been reviewed by a qualified lawyer in any jurisdiction. Do not rely on it as a final published policy until counsel has reviewed it and the governing-law, controller-identity and representative details have been completed.

1. Who we are and what this covers

Uneven ("Uneven", "we", "us") operates the Uneven mobile dating app and the website at unevenapp.com. This policy covers both. It explains what personal data we handle when you create an account, build a profile, swipe, match and message, and what your choices are.

For users in the European Economic Area and the United Kingdom, Uneven is the data controller for the personal data described here. The controller's registered legal entity name and address, and any EU/UK representative required under Article 27 GDPR, are to be inserted before publication.

2. You must be 18 or older

Uneven is an adult service. You must be at least 18 to create an account. We do not knowingly collect personal data from anyone under 18. If we learn that an account belongs to a minor, we delete it and its content. If you believe a minor is using Uneven, report the profile in the app or email support@unevenapp.com and we will act on it.

3. What we collect

Account data

You sign up with an email address and a password. Authentication is handled by Amazon Cognito: Cognito stores your email, a salted hash of your password, your account status and the verification code we send you when you sign up or reset your password. We never see or store your password. Cognito also holds a display name and, if provided, a birthdate, so support staff can identify an account without reading your app data.

Profile content

What a profile contains depends on which side of the app you are on. That asymmetry is the product.

If you are on her side
The photos you upload, their order, and their moderation status. No bio, no prompts, no free-text fields exist on her side.
If you are on his side
Your voice intro (an audio recording, maximum 60 seconds), its automatically generated transcript, its audio-amplitude envelope (the numbers that draw the waveform), your 140-character opener, your prompt answers, your fact chips, the animal avatar you chose and your card colour. No photographs are collected on his side — the app has no photo upload for men.
Both sides
Your first name (as you type it), your age, and your answers to the five "basics" questions: smoking, drinking, kids, pets and what you are looking for.

Approximate location

Discovery is local, so the app needs a rough idea of where you are. If you grant location permission, your device works out your coordinates and the app converts them on your device into a geohash cell — a rectangle roughly 5 km across — before anything is sent to us. Only that cell is transmitted and stored. We do not store latitude and longitude at all. There is no coordinate column in our database, so no query, log or breach can produce a point on a map for you. If you decline location permission, discovery is limited or unavailable, and everything else still works.

Activity data

When you use the app we store: your swipes (like or pass), your matches, your conversations and the messages in them (text messages, voice messages with their transcripts and waveform data), read and played timestamps, the accounts you have blocked, and any reports you file. Swipes are write-only from the app — nobody can read them back, including you, so a like never leaks before it is mutual.

Device and technical data

If you turn on notifications, we store an Expo push token for your device so we can send match and message alerts. We also process ordinary technical data that any app on any network produces: IP address, app version, operating system and device model, timestamps and error traces, recorded in our AWS service logs and used for security, abuse prevention and debugging.

Support correspondence

If you email us, we keep the message, your address, and our reply, so we can answer you and keep a record of what was decided.

4. What we deliberately do not collect

  • No social logins. There is no Facebook, Google or Apple sign-in, so we import nothing from those accounts.
  • No phone number, no contacts, no calendar, no photo-library scanning. The app reads only the photos you explicitly pick.
  • No precise coordinates in storage. See §3 — cells only.
  • No advertising identifiers, no third-party ad SDKs, no cross-app tracking. Uneven does not run advertising.
  • No payment data. Nothing in the app is for sale at launch, so there is no card data to hold.
  • No special-category data by design. We do not ask for your race, religion, health, politics or sexual orientation. If you volunteer such information inside a voice note or a prompt answer, it becomes part of your profile content and is visible to other users.

5. How we use it

We use personal data to:

  • create and secure your account, and let you sign in;
  • build and display your profile to other users of the app;
  • show you nearby profiles and record swipes, matches and messages;
  • send push notifications you have asked for;
  • screen photos and review reports, to keep the service usable and lawful;
  • investigate abuse, fraud, ban evasion and threats to safety;
  • fix bugs, monitor availability and improve the product;
  • answer your support requests and comply with legal obligations.

For EEA/UK users, our legal bases are: performance of a contract (running the service you signed up for — account, profile, discovery, matching, messaging); legitimate interests (security, abuse prevention, moderation, debugging, defending legal claims); consent (device location, push notifications, microphone and photo access — each of which you can withdraw in your device settings at any time); and legal obligation (responding to lawful requests, keeping records we are required to keep).

6. Photo screening and moderation

Every photo uploaded to Uneven is screened automatically by Amazon Rekognition before it is visible to anyone else. Rekognition returns content-moderation labels; if any label is returned above our confidence threshold, the photo and the profile it belongs to are flagged, the profile leaves discovery, and the case goes to a human review queue. If the screening service itself fails, the photo stays pending rather than going live — the system fails closed.

Reports filed by users are read and decided by a person. We do not run fully automated account terminations: an automated flag takes content out of circulation, and a human decides what happens to the account. If a decision goes against you, you can contest it by emailing support@unevenapp.com and a person will look again.

Voice notes are not machine-screened at present; they are reviewed by a person when reported.

7. Who can see what

Signed-in users of the app can see the profiles that discovery shows them: her photos, his voice intro, transcript, opener, prompts, facts, basics, first name, age and approximate distance. Your email address is never shown to another user. Your exact location is never shown to another user, because we do not have it.

Your messages are readable only by you and the person you matched with. Media (photos and voice notes) is stored in private storage and served through short-lived signed links, typically valid for about fifteen minutes; there is no public URL for your photos or recordings. Uneven has no public API and no anonymous access path.

Blocking is symmetric and permanent: a blocked person disappears from your discovery and you from theirs, and they are not told that it happened.

8. Who we share it with

We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We disclose data only to the service providers who run the app on our behalf, and only for that purpose:

  • Amazon Web Services — Cognito (accounts), AppSync and DynamoDB (data), S3 (photos and voice notes), Lambda (discovery, matching, screening), Rekognition (photo screening) and Amplify Hosting (this website).
  • Expo — delivery of push notifications to your device, via Apple and Google's push services.
  • Apple and Google — app distribution, and crash reporting where you have enabled it at the OS level.
  • Email delivery providers — sending verification codes and support replies.

We may also disclose data where we are legally required to, where it is necessary to protect someone's safety or our rights, or as part of a merger, acquisition or asset sale — in which case we will tell you before your data becomes subject to a different privacy policy.

9. Where your data is processed

Uneven runs on AWS in the us-east-1 region (Northern Virginia, United States). If you use the app from outside the United States, your personal data is transferred to and processed there. For transfers out of the EEA or the UK we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, together with our providers' supplementary safeguards.

10. How long we keep it

  • While your account exists: your account, profile, media, matches and messages are kept so the service works.
  • After you delete your account: profile data, photos, voice notes, matches and messages are deleted from live systems promptly, and purged from encrypted backups within 30 days.
  • Moderation and safety records — reports, blocks, and the outcome of a review — are kept for up to 12 months after the account is closed, so that a banned account cannot simply be re-created, and so we can answer a complaint or a legal claim. Where possible these records are reduced to the minimum needed for that purpose.
  • Service logs containing IP addresses and diagnostics are kept for up to 90 days.
  • Support correspondence is kept for up to 24 months.

Content another user has legitimately received — a message you sent them — remains in their copy of the conversation unless they delete it too.

11. Deleting your account

You can delete your account from inside the app: You → Delete account. Gone is gone: there is no archive and no cooling-off period. Full instructions, including what to do if you no longer have the app installed, are on the account deletion page.

12. Your rights

Depending on where you live, you have some or all of the following rights over your personal data:

  • Access — get a copy of what we hold about you.
  • Correction — have inaccurate data fixed. Most profile data you can edit yourself in the app.
  • Deletion — have your data erased. See §11.
  • Portability — receive your data in a structured, machine-readable format, or have it sent to another controller where technically feasible.
  • Objection and restriction — object to processing based on our legitimate interests, or ask us to restrict processing while a dispute is resolved.
  • Withdraw consent — turn off location, notifications, microphone or photo access at any time in your device settings, without affecting processing already carried out.
  • Complain — lodge a complaint with your local data protection authority. We would rather you came to us first.

If you are a California resident, the CCPA/CPRA gives you the right to know what we collect and why, to delete it, to correct it, to opt out of sale or sharing (we do neither), to limit the use of sensitive personal information (we do not use it for inference or advertising), and not to be discriminated against for exercising any of these rights. You may use an authorised agent; we will verify their authority.

To exercise any right, email privacy@unevenapp.com from the address on your account. We verify requests before acting on them and respond within 30 days (or the shorter period your law requires), and we will tell you if we need more time.

13. Security

Data is encrypted in transit and at rest. Access to your own data is enforced at the API layer by owner-based authorisation rules rather than by checks in app code; your photos and voice notes live under a storage prefix keyed to your identity, so another user physically cannot write into it. Media is served only through short-lived signed URLs. There is no anonymous API key and no public read path. No system is perfectly secure, and we will notify you and the relevant authority of a breach affecting your personal data where the law requires it.

14. Cookies and this website

This website sets no cookies, runs no analytics and embeds no trackers. It loads web fonts from Google Fonts, which means your browser makes a request to Google's font servers and Google receives your IP address for that request. The Uneven app itself contains no advertising or analytics SDKs.

15. Changes to this policy

If we change this policy we will update the version number and the date at the top of this page. For changes that materially affect your rights, we will notify you in the app or by email before they take effect. Previous versions are available on request.

16. Contact

Privacy questions and rights requests: privacy@unevenapp.com
Everything else: support@unevenapp.com

The postal address of the controller, and the contact details of any data protection officer or EU/UK representative, are to be inserted before publication.