Last Updated: 19 August 2026
Version: 2.5
Konnectors is ad-supported for free users. If you use the Service without a paid Premium or Dating subscription, you will see advertisements, including interstitial ads displayed periodically while you use the swipe, travel and dating features. These ads are delivered through Google AdMob and may use your device advertising identifier (Google Advertising ID on Android, IDFA on iOS), approximate location, and in-app activity to show relevant ads.
By continuing to use the free tier, you acknowledge and consent to the display of advertising as described in this disclosure.
AdMob App ID: ca-app-pub-9385347738738825~9490213872
Publisher ID: pub-9385347738738825
Konnectors ("we", "us", "our") is the data controller responsible for the personal data processed in connection with the Konnectors mobile and web application (the "Service").
Under GDPR Article 37, a Data Protection Officer (DPO) is not required for individual operators processing personal data for this service, as we do not engage in large-scale, systematic monitoring or processing of special-category data. You may contact the operator directly at the email above with any privacy or data protection inquiries.
A. Information you provide
B. Information collected automatically
C. Authentication and security data
D. Sensitive and special-category data
Because Konnectors includes dating, travel, social profiles and optional verification, information you choose to provide may reveal special-category data such as racial or ethnic origin, religious or philosophical beliefs, health information, sexual orientation, sex life, biometric-related verification information or similar sensitive details. We do not require you to provide these details unless needed for a specific feature. Where GDPR Article 9 applies, we process this data only with your explicit consent, where you make it public yourself, or where another lawful exception applies, such as legal claims, safety or compliance obligations.
E. Mobile app and device data
F. Automated content moderation and AI analysis
To keep the community safe, all photos, videos and images you upload(profile pictures, profile photos, story media, post images, review media, verification selfies and live-stream content) are automatically analysed by AI-powered moderation tools to detect explicit, violent, hateful or otherwise prohibited content, and to perform basic quality checks. This scanning does not use facial recognition to identify you, does not compare your images against other people, and does not create biometric identifiers or templates. Flagged images may be reviewed by trained administrators under confidentiality obligations.
Text content you submit — including messages, activity and hangout descriptions, profile text, post text, comments and trip descriptions — may be automatically analysed by AI-assisted classifiers and keyword-based systems to detect harassment, spam, scams, sexual misuse, threats, illegal activity or other prohibited conduct. We do not routinely read private one-to-one messages; human review is generally limited to content that has been flagged, reported, or is necessary to investigate safety, security, legal or policy concerns.
We do not use your photos, videos, messages or verification selfies to train AI models. AI analysis is limited to safety, policy enforcement and the specific feature purposes described in this Policy (for example, identity-verification liveness checks and interest matching). Inputs processed by our AI sub-processors are used for inference only and are not used to train their models.
| Purpose | Legal basis |
|---|---|
| Provide the core service (profile, matching, hangouts, messaging, payments) | Contract — Art. 6(1)(b) |
| Send transactional emails (event reminders, security alerts, breach notifications) | Contract / Legal obligation — Art. 6(1)(b),(c) |
| Show nearby users and events using your geolocation | Consent — Art. 6(1)(a) |
| Identity verification using AI liveness analysis of a selfie | Consent + Legitimate interest in user safety — Art. 6(1)(a),(f) |
| AI interest-matching notifications | Consent (opt-in) — Art. 6(1)(a) |
| Special-category data you choose to provide in dating/profile content or optional verification | Explicit consent — Art. 9(2)(a), and where applicable data manifestly made public by you — Art. 9(2)(e) |
| Push notifications, unread badges and device delivery tokens | Consent / Contract — Art. 6(1)(a),(b) |
| Subscriptions, in-app purchases, refunds and entitlement checks | Contract / Legal obligation — Art. 6(1)(b),(c) |
| Display of advertising to free users (ad-supported tier) | Consent (ad-supported tier) + Legitimate interest in operating a free service — Art. 6(1)(a),(f) |
| Analytics, attribution and marketing cookies or pixels | Consent (per category) — Art. 6(1)(a) |
| Sharing your email / contact data with advertising platforms (Meta, TikTok) to build Custom Audiences and Lookalike Audiences for our own marketing | Consent (marketing) + Legitimate interest in promoting the service — Art. 6(1)(a),(f) |
| Fraud, abuse and security monitoring | Legitimate interest — Art. 6(1)(f) |
| Content moderation and safety enforcement | Legitimate interest + Legal obligation — Art. 6(1)(c),(f) |
| Compliance with legal/regulatory obligations (breach notification, audit) | Legal obligation — Art. 6(1)(c) |
We do not perform automated decisions producing legal or similarly significant effects on you (Art. 22). Verification rejections may be appealed by re-submitting; admins can override AI results.
We share the minimum data necessary with the following sub-processors to operate the Service. Each is bound by a Data Processing Agreement and processes data only on our documented instructions.
| Sub-processor | Purpose / Data processed | Region |
|---|---|---|
| Base44 | Application hosting platform: database, authentication (email OTP, sessions), backend function runtime, transactional email delivery, AI inference proxy, public file-storage proxy | EU |
| IONOS Cloud (1&1 IONOS SE) | Underlying cloud infrastructure used by Base44 (compute, storage, network). Receives encrypted data at rest and IP/connection logs for security. | EU (Germany) |
| Cloudflare R2 (Cloudflare, Inc.) | Object storage for profile photos, intro/extra videos, story media, live-stream recordings, verification selfies, banners and uploaded short videos | Global (EU edge) |
| LiveKit Cloud (LiveKit, Inc.) | WebRTC live-streaming infrastructure: real-time audio/video transport, room signalling, server-side recording (egress). Receives stream media, room name, participant identity and IP for media transport. | EU / US (SCCs) |
| Stripe Payments Europe Ltd | Payment processing for Premium subscriptions: checkout sessions, customer & subscription IDs, webhook signatures. Card data is collected directly by Stripe and never reaches our servers. | EU (Ireland) |
| RevenueCat, Inc. | Mobile subscription entitlement management: app-user ID, receipt identifiers, purchase status, renewal/cancellation events and subscription metadata. | US (SCCs) |
| Apple App Store / StoreKit (Apple Distribution International Ltd.) | iOS in-app purchase processing: transaction identifiers, receipt data, refund/cancellation status and subscription status. | EU (Ireland) |
| Google Play Billing (Google Ireland Ltd.) | Android in-app purchase processing: purchase tokens, subscription status, refund/cancellation status and Google Play billing metadata. | EU (Ireland) |
| Firebase Cloud Messaging / Google | Push notifications: device push tokens, delivery metadata and notification routing for Android/web push where enabled. | EU / US (SCCs) |
| Tenjin, Inc. | Mobile install & event attribution and analytics (SDK): install/in-app events, device advertising ID (GAID/IDFA), IP address, device model, OS version and campaign/referrer data, used to attribute installs to advertising campaigns. | US (SCCs) |
| TikTok | Marketing attribution and campaign measurement where enabled and consented: event identifiers, advertising ID, device/browser data and conversion metadata. | Global (SCCs where required) |
| Meta Platforms Ireland Ltd. | Meta Pixel / Meta Ads marketing attribution where enabled and consented: event identifiers, advertising ID, browser/device data and conversion metadata. | EU / US (SCCs where required) |
| OpenAI (via Base44 InvokeLLM) | AI vision model for identity-verification liveness analysis (selfie + gesture check), AI interest-matching scoring, and content-moderation assistance. Inputs are processed for inference only and not used to train models. | US (sub-processed by Base44 under SCCs) |
| OpenStreetMap Foundation — Nominatim | Reverse geocoding: latitude/longitude → city/country. Coordinates are sent server-side; we do not echo raw coordinates back to other users. | EU (UK / DE) |
| OpenStreetMap tile servers | Map basemap tiles for hangouts map, world map, online-users map and location pickers. Receives IP, User-Agent and tile coordinates. | EU |
| Google Fonts (Google Ireland Ltd.) | Delivery of the 'Inter' and 'Space Grotesk' web fonts. Receives IP address, User-Agent and Referer when the font is loaded. | EU (Ireland) |
Advertising, analytics and attribution
We use advertising attribution and analytics partners — specifically Tenjin (mobile install/event attribution), TikTok and Meta (campaign measurement) — to understand which advertising campaigns lead to installs and activity. To do this, our mobile app collects your device advertising identifier (Google Advertising ID on Android, IDFA on iOS) and shares install/event data with these partners, only where enabled and permitted by your cookie / app-tracking choices. We do not sell personal data. Where a law treats targeted advertising or cross-context sharing as a "sale" or "sharing", you may opt out using your cookie preferences, your device advertising-ID settings, or by contacting us.
Custom & Lookalike Audiences (sharing your email/contact data): where you have consented to marketing, we may share your email address or other contact data with advertising platforms such as Meta (Facebook) and TikTok to build Custom Audiences (matched lists of our users) and Lookalike Audiences (people similar to our users) for our own marketing and prospecting campaigns. This is a separate purpose from attribution measurement and involves sharing your personal data with these platforms. We rely on your marketing consent (Art. 6(1)(a)) and, where applicable, our legitimate interest in promoting the service (Art. 6(1)(f)) as the legal basis. We certify to these platforms that we have a valid legal basis to share this data, as required by their Custom Audience terms. You can opt out at any time via your cookie / ad-consent settings (see Section 14), by contacting us, or through the platform's own controls (e.g. Meta Accounts Center → Ad preferences). Opting out does not affect the lawfulness of processing that took place before you withdrew consent.
Outbound social-share links and third-party sites
When you click a "Share" button, your browser opens the destination platform (e.g. Facebook, X / Twitter, WhatsApp). No personal data is sent to those platforms by us automatically — only the URL you choose to share, and only when you click. These platforms are independent controllers; please review their own privacy policies.
Where data is transferred outside the EU/EEA, we rely on the European Commission's Standard Contractual Clauses (Art. 46) together with technical and organisational safeguards (encryption in transit and at rest, access controls, audit logging). We do not sell personal data. We share limited attribution data with the advertising/analytics partners named above only where you have consented.
Your profile and activity may be visible to other authenticated users depending on your settings and the feature you use. This can include your name, profile photos, avatar, bio, age, city/country, interests, languages, dating/travel preferences, posts, stories, reviews, comments, trips, hangouts, streams, check-ins and messages sent in shared/group areas. You can hide your profile from discovery / dating at any time in Settings. Public or shared content should not be treated as confidential.
Reviews and ratings: after a hangout or activity you may rate other participants and they may rate you. Your aggregate star rating is shown on your profile. Individual trait scores (friendliness, reliability, communication, respect, vibe) and comments are visible to the person being rated; low ratings are used internally for trust, safety and moderation and are not displayed on your profile to other users. A sustained pattern of negative feedback may flag an account for human review by our safety team.
We only collect precise location (latitude/longitude) when you grant explicit permission via your browser/device. Coordinates are reverse-geocoded to a city/country and we do not echo raw coordinates back to other users. You can revoke location permission at any time in your device settings; some discovery features will then be limited.
When you choose to verify your identity, we capture a live selfie in which you are asked to perform a randomly chosen gesture (e.g. a peace sign on the left or right side of the frame). The image is analysed by an AI vision model only to determine whether (i) it is a live human, (ii) the requested gesture is shown, and (iii) the gesture appears in the requested position. We store the AI's boolean result, a confidence score, and a short reason text. The selfie itself is deleted after 180 days. Verification is optional.
To exercise any of these rights, email info@konnectors.app. We will respond within 30 days (Art. 12(3)).
If you are located in a US state with a consumer privacy law, you may have rights to know/access, correct, delete, obtain a portable copy of your data, and opt out of targeted advertising, sale, sharing or certain profiling. We do not sell personal data for money. To exercise these rights, contact info@konnectors.app. We may verify your request through your account or email before acting on it.
If you believe we have not handled your personal data in accordance with the law, contact us first and we will aim to respond to privacy complaints within 30 days. You also have the right to lodge a complaint with the Irish Data Protection Commission, our lead supervisory authority:
We apply technical and organisational measures appropriate to the risk, including: row-level security on every database entity, file MIME-type and size validation, server-side authentication checks on every backend function, optional multi-factor authentication (email OTP + TOTP), hashed device-trust tokens, signed Stripe webhooks, automated brute-force / DoS detection, encrypted transport (TLS), and encryption at rest by our hosting provider. No system is perfectly secure; in the event of a personal-data breach, we will notify the DPC within 72 hours and affected users without undue delay where required by Articles 33 and 34.
The Service is restricted to users 18 and over. We verify age at sign-up via the date of birth you provide. We do not knowingly collect data from anyone under 18. If we discover an account belongs to a minor, we delete it immediately.
We classify cookies and similar technologies into three categories: essential (always on, required for log-in, security, fraud prevention and payments), analytics (off by default — only loaded after you opt in), and marketing/attribution (off by default — only loaded after you opt in). These technologies may include cookies, pixels, SDK identifiers, device IDs, advertising IDs and server-side event tracking. You can change or withdraw your preferences at any time via the in-app banner, in Account Settings → Privacy → Manage Cookie & Ad Consent, or your device/app tracking settings.
Your data is processed primarily in the European Economic Area. Where sub-processors operate outside the EEA, we rely on the European Commission's Standard Contractual Clauses (Art. 46) as the transfer mechanism, together with technical safeguards (encryption in transit and at rest).
We may update this Privacy Policy. Material changes will be communicated by in-app notice and/or email at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.
"Personal data" means information relating to an identified or identifiable person. "Processing" means any operation performed on personal data, such as collection, storage, use, disclosure, deletion or analysis. "Special-category data" means sensitive data under GDPR Article 9, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, health, biometric data used for identification, sex life or sexual orientation.
For privacy questions, data subject requests, or to exercise any GDPR right, contact our data-protection contact at info@konnectors.app.