Who we are
[COMPANY LEGAL NAME] ("we", "us") is the data controller for personal information processed through MayaDating. Registered office: [REGISTERED OFFICE]. Company number: [COMPANY NUMBER].
Privacy contact: [PRIVACY EMAIL]
Information we collect
Account information
- Name and email address
- Password (stored as a secure hash — we do not store plain-text passwords)
- Authentication session data (via NextAuth)
Profile and dating information (collected during onboarding and use)
- Date of birth / age-related information
- Gender
- Location and occupation
- Personality description, strengths, insecurities
- Relationship goals and current relationship status
- Dating experience and communication style
- Dating apps used and coaching goals
- Current dating focus
- Sexual orientation and/or who you are interested in dating (if you choose to provide this — see Special-category information)
Photos and uploads
- Dating profile photos you upload for review
- Screenshots of dating profiles or conversations
- Other images submitted for analysis
Coaching and analysis information
- Messages you send to Maya (AI coach)
- Date debriefs, ratings and reflections
- Notes about people you are dating ("people" records)
- Conversation analyses and profile review results
- Generated insights and coaching memories derived from your use
- Practice conversation messages (simulator)
Third-party information
If you upload screenshots or conversations, those may contain another person's messages, name or image. We process this only to provide the analysis you request.
Technical information
- IP address and browser/device information (standard server logs)
- Authentication and security session cookies
- Usage records for plan limits (e.g. free message counts)
- AI generation metadata (feature, provider, status — not full prompts)
Payment information
If you subscribe, payment card details are processed by our payment provider (Stripe, when configured). We store subscription status, plan type and billing-related identifiers — not full card numbers.
Why we use information
| Purpose | Data involved | Lawful basis (UK GDPR) |
|---|---|---|
| Creating and managing your account | Name, email, password hash, session data | [LEGAL BASIS TO BE CONFIRMED WITH COUNSEL] — likely contract / legitimate interests |
| Providing profile analysis and coaching | Profile, photos, chats, debriefs, preferences | [LEGAL BASIS TO BE CONFIRMED WITH COUNSEL] — likely contract |
| Personalising coaching using sensitive dating information | Sexual orientation, interested-in preferences (if provided) | Explicit consent (Art. 9(2)(a)) — [CONFIRM WITH COUNSEL] |
| Subscriptions and billing | Email, subscription status, Stripe identifiers | [LEGAL BASIS TO BE CONFIRMED WITH COUNSEL] — likely contract |
| Security and fraud prevention | IP, logs, usage patterns | [LEGAL BASIS TO BE CONFIRMED WITH COUNSEL] — likely legitimate interests |
| Marketing emails (if you opt in) | Email, marketing consent record | Consent |
| Legal and regulatory compliance | As required | Legal obligation / legitimate interests — [CONFIRM WITH COUNSEL] |
Special-category information
Information about your sexual orientation, and potentially information about your sex life or dating preferences, may constitute special-category personal data under UK GDPR Article 9.
Where we process this information for personalisation, we intend to rely on your explicit consent. We will:
- ask separately from Terms acceptance
- explain what information and purpose the consent covers
- allow you to skip optional fields where the product supports it
- let you withdraw consent from account privacy settings
Withdrawing consent does not affect the lawfulness of processing before withdrawal. After withdrawal, we will stop future processing that relies on that consent and handle stored information in line with our retention approach and counsel advice.
For legal review: final Article 9 condition, wording and withdrawal handling must be approved by UK privacy counsel.
How we use artificial intelligence
We use AI to analyse information you submit and generate coaching feedback, summaries and suggestions. Depending on configuration, this may include profile text, uploaded images, coach messages, date debriefs and conversation content.
When AI_PROVIDER=gemini is enabled, relevant content may be sent to Google (Gemini API) for inference. When mock mode is used (default in development), processing stays on our servers without an external AI call.
[AI PROVIDER DATA PROCESSING TERMS TO BE CONFIRMED BEFORE PRODUCTION] — including whether inputs may be used for model training, retention periods, and applicable data processing terms for your account tier.
AI outputs may be inaccurate. They should not be treated as objective facts about you or anyone else.
See AI & your data.
Automated decision-making
The Service uses AI to generate personalised analysis and suggestions. These outputs do not, by themselves, produce legal or similarly significant effects (such as credit decisions or employment outcomes). You are always responsible for how you act on coaching suggestions.
For legal review: confirm whether any feature constitutes solely automated decision-making under UK GDPR Article 22.
International transfers
Some providers may process data outside the UK. Where this occurs, we aim to use appropriate safeguards such as UK IDTA / UK Addendum to EU SCCs or adequacy regulations — [INTERNATIONAL TRANSFER MECHANISM TO BE CONFIRMED] for each processor before production launch.
How long we keep information
| Category | Retention |
|---|---|
| Account data | [RETENTION PERIOD TO CONFIRM] |
| Coach conversations | [RETENTION PERIOD TO CONFIRM] |
| Uploaded images | [RETENTION PERIOD TO CONFIRM] — deleted on account deletion where implemented |
| AI analysis results | [RETENTION PERIOD TO CONFIRM] |
| Consent records | Retained to demonstrate consent/withdrawal — [PERIOD TO CONFIRM] |
| Billing records | [RETENTION PERIOD TO CONFIRM] — may be longer for accounting/legal obligations |
| Security logs | [RETENTION PERIOD TO CONFIRM] |
| Import sessions (profile/message) | ~1 hour in-memory TTL |
See our internal retention draft at docs/legal/RETENTION-POLICY-DRAFT.md (internal).
Security
We use measures appropriate to the risk, including where implemented:
- HTTPS for data in transit
- Password hashing (bcrypt)
- Authenticated access to app features
- Server-side storage of secrets and API keys
- User-scoped file storage paths
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
Known gap: uploaded files may currently be accessible via URL without authentication — see implementation gaps documentation.
Your rights
Under UK GDPR you may have rights to access, rectify, erase, restrict, object, data portability, and withdraw consent where processing is based on consent.
Submit requests via privacy requests or email [PRIVACY EMAIL].
Delete data and your account
You can delete specific categories of data and your entire account from account settings where available. Account deletion removes your user record and cascades related database records, and deletes uploaded files from our storage provider where implemented.
Automated data export is not yet available — contact us for portability requests.
Complaints
Contact us first at [PRIVACY EMAIL]. You also have the right to complain to the UK Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint.
Children
The Service is not intended for anyone under 18. We do not knowingly collect personal information from children.
Changes
We may update this Notice. The version and effective date at the top will change when we do. Material changes will be communicated where appropriate.