Privacy Policy

Last Updated: 19 August 2026

Version: 2.5

Advertising Disclosure

Konnectors is ad-supported for free users. If you use the Service without a paid Premium or Dating subscription, you will see advertisements, including interstitial ads displayed periodically while you use the swipe, travel and dating features. These ads are delivered through Google AdMob and may use your device advertising identifier (Google Advertising ID on Android, IDFA on iOS), approximate location, and in-app activity to show relevant ads.

  • Free users: ads are shown as a condition of using the free tier.
  • Premium / Dating subscribers: ads are removed entirely while the subscription is active.
  • You can stop seeing ads at any time by upgrading to a Premium or Dating subscription, or by resetting / opting out of your device advertising identifier in your OS settings (Android: Settings → Privacy → Ads → Reset advertising ID; iOS: Settings → Privacy & Security → Apple Advertising).
  • We and our advertising partners (Google AdMob, and where consented, Meta and TikTok) may use the data listed in Section 2 to measure ad performance and attribution. We do not sell your personal data.
  • Custom & Lookalike Audiences: where you have consented to marketing, we may share your email address or other contact data with advertising platforms (such as Meta/Facebook and TikTok) to build Custom Audiences and Lookalike Audiences for our own marketing and prospecting. This lets us show ads to people similar to our users. You can opt out at any time via your cookie / ad-consent settings (see Section 14), by contacting us, or by using the platform's own audience-matching opt-out (Meta: Accounts Center → Ad preferences). We certify to these platforms that we have a valid legal basis to share this data, as required by their Custom Audience terms.

By continuing to use the free tier, you acknowledge and consent to the display of advertising as described in this disclosure.

AdMob App ID: ca-app-pub-9385347738738825~9490213872
Publisher ID: pub-9385347738738825

1. Who We Are (Data Controller)

Konnectors ("we", "us", "our") is the data controller responsible for the personal data processed in connection with the Konnectors mobile and web application (the "Service").

  • Operator: Boris Adzaip (individual operator)
  • Address: Leixlip, Kildare, Ireland
  • Email: info@konnectors.app

Under GDPR Article 37, a Data Protection Officer (DPO) is not required for individual operators processing personal data for this service, as we do not engage in large-scale, systematic monitoring or processing of special-category data. You may contact the operator directly at the email above with any privacy or data protection inquiries.

2. Information We Collect

A. Information you provide

  • Account details: full name, email address, date of birth, age, gender, email and profile settings
  • Profile content: bio, photos, intro/extra videos, avatar, interests, preferred activities, languages, travel plans and "looking for" information
  • Location: city, country and, if you enable device geolocation, precise latitude/longitude for nearby discovery and check-ins
  • Identity verification: a live selfie performing a randomly chosen gesture, analysed by AI for liveness only
  • User-generated content: hangouts, activities, trips, posts, stories, reviews, comments, live streams and messages
  • Reviews and ratings: star rating, trait scores (friendliness, reliability, communication, respect, vibe), optional comment, and optional photos/videos you submit about another user after a hangout or activity
  • Dating preferences: who you wish to see, age range, distance, intent, likes, passes, matches and dating visibility settings
  • AI-matching descriptions and tags, only if you opt in
  • Consent records: cookie preferences, ToS / Privacy Policy / Community Guidelines acceptance timestamps and consent withdrawals
  • Subscription metadata: Stripe, RevenueCat, Apple App Store or Google Play customer, purchase, receipt and subscription IDs; we never receive your full card number
  • Push-notification data: push tokens, device identifiers needed for notifications, badge counts and delivery status

B. Information collected automatically

  • Device and connection data (IP address, browser, OS) — used by our hosting provider for security and abuse prevention
  • Last-active timestamps, online status, daily-streaming counters
  • Engagement insights: profile views, story views, post impressions and similar interaction analytics used to power features such as "who viewed your profile" and to improve the service
  • Audit logs (administrative actions, security events)

C. Authentication and security data

  • Email OTP codes (stored only as SHA-256 hashes; expire after a few minutes)
  • Optional TOTP authenticator secret (server-side only)
  • Hashed trusted-device tokens (30-day expiry)

D. Sensitive and special-category data

Because Konnectors includes dating, travel, social profiles and optional verification, information you choose to provide may reveal special-category data such as racial or ethnic origin, religious or philosophical beliefs, health information, sexual orientation, sex life, biometric-related verification information or similar sensitive details. We do not require you to provide these details unless needed for a specific feature. Where GDPR Article 9 applies, we process this data only with your explicit consent, where you make it public yourself, or where another lawful exception applies, such as legal claims, safety or compliance obligations.

E. Mobile app and device data

  • Camera and photo-library access, only when you upload profile media, stories, verification selfies, posts or stream content
  • Push notification permission and device push tokens for alerts, reminders and unread badges
  • Device, OS, app version, browser/WebView, IP address, crash/security logs and basic technical diagnostics
  • StoreKit, Google Play Billing and RevenueCat subscription/receipt data for in-app purchases
  • Advertising identifiers — the Google Advertising ID (GAID / AAID) on Android and the Identifier for Advertisers (IDFA) on iOS — collected by our mobile app for attribution and advertising measurement, only where you consent or where the app store / platform permits the processing
  • Mobile attribution data collected via the Tenjin SDK: install and in-app events, device advertising identifier, IP address, device model, OS version and campaign/referrer information, used to measure which advertising campaigns drive installs and activity

F. Automated content moderation and AI analysis

To keep the community safe, all photos, videos and images you upload(profile pictures, profile photos, story media, post images, review media, verification selfies and live-stream content) are automatically analysed by AI-powered moderation tools to detect explicit, violent, hateful or otherwise prohibited content, and to perform basic quality checks. This scanning does not use facial recognition to identify you, does not compare your images against other people, and does not create biometric identifiers or templates. Flagged images may be reviewed by trained administrators under confidentiality obligations.

Text content you submit — including messages, activity and hangout descriptions, profile text, post text, comments and trip descriptions — may be automatically analysed by AI-assisted classifiers and keyword-based systems to detect harassment, spam, scams, sexual misuse, threats, illegal activity or other prohibited conduct. We do not routinely read private one-to-one messages; human review is generally limited to content that has been flagged, reported, or is necessary to investigate safety, security, legal or policy concerns.

We do not use your photos, videos, messages or verification selfies to train AI models. AI analysis is limited to safety, policy enforcement and the specific feature purposes described in this Policy (for example, identity-verification liveness checks and interest matching). Inputs processed by our AI sub-processors are used for inference only and are not used to train their models.

3. Why We Process Your Data and the Legal Basis (GDPR Art. 6)

PurposeLegal basis
Provide the core service (profile, matching, hangouts, messaging, payments)Contract — Art. 6(1)(b)
Send transactional emails (event reminders, security alerts, breach notifications)Contract / Legal obligation — Art. 6(1)(b),(c)
Show nearby users and events using your geolocationConsent — Art. 6(1)(a)
Identity verification using AI liveness analysis of a selfieConsent + Legitimate interest in user safety — Art. 6(1)(a),(f)
AI interest-matching notificationsConsent (opt-in) — Art. 6(1)(a)
Special-category data you choose to provide in dating/profile content or optional verificationExplicit consent — Art. 9(2)(a), and where applicable data manifestly made public by you — Art. 9(2)(e)
Push notifications, unread badges and device delivery tokensConsent / Contract — Art. 6(1)(a),(b)
Subscriptions, in-app purchases, refunds and entitlement checksContract / Legal obligation — Art. 6(1)(b),(c)
Display of advertising to free users (ad-supported tier)Consent (ad-supported tier) + Legitimate interest in operating a free service — Art. 6(1)(a),(f)
Analytics, attribution and marketing cookies or pixelsConsent (per category) — Art. 6(1)(a)
Sharing your email / contact data with advertising platforms (Meta, TikTok) to build Custom Audiences and Lookalike Audiences for our own marketingConsent (marketing) + Legitimate interest in promoting the service — Art. 6(1)(a),(f)
Fraud, abuse and security monitoringLegitimate interest — Art. 6(1)(f)
Content moderation and safety enforcementLegitimate interest + Legal obligation — Art. 6(1)(c),(f)
Compliance with legal/regulatory obligations (breach notification, audit)Legal obligation — Art. 6(1)(c)

We do not perform automated decisions producing legal or similarly significant effects on you (Art. 22). Verification rejections may be appealed by re-submitting; admins can override AI results.

4. How Long We Keep Your Data (Retention Periods)

  • Account and profile data: for as long as the account is active
  • Identity-verification selfies: 180 days after approval / rejection, then deleted; only the verification status flag is retained
  • Stories: 24 hours, then auto-deleted
  • Uploaded short videos: 7 days, then auto-deleted
  • Live-stream recordings: 24 hours by default, longer only if explicitly saved by the user
  • Notifications: 90 days
  • Push tokens: until you disable notifications, log out, uninstall, or the token is replaced or invalidated
  • Subscription and payment records: for the life of the subscription and then as required for tax, accounting, fraud prevention and dispute handling
  • Reports (resolved/dismissed): 180 days
  • Admin audit logs: 12 months
  • Resolved data-breach records: 24 months (then deleted; required for accountability under Art. 33(5))
  • Cookie consent records: for as long as the consent is valid (re-prompted if withdrawn)
  • After account deletion (Right to Erasure): personal data is deleted or anonymised within 30 days, except where retention is required by law (e.g. tax records — 6 years)

5. Who We Share Your Data With (Sub-processors)

We share the minimum data necessary with the following sub-processors to operate the Service. Each is bound by a Data Processing Agreement and processes data only on our documented instructions.

Sub-processorPurpose / Data processedRegion
Base44Application hosting platform: database, authentication (email OTP, sessions), backend function runtime, transactional email delivery, AI inference proxy, public file-storage proxyEU
IONOS Cloud (1&1 IONOS SE)Underlying cloud infrastructure used by Base44 (compute, storage, network). Receives encrypted data at rest and IP/connection logs for security.EU (Germany)
Cloudflare R2 (Cloudflare, Inc.)Object storage for profile photos, intro/extra videos, story media, live-stream recordings, verification selfies, banners and uploaded short videosGlobal (EU edge)
LiveKit Cloud (LiveKit, Inc.)WebRTC live-streaming infrastructure: real-time audio/video transport, room signalling, server-side recording (egress). Receives stream media, room name, participant identity and IP for media transport.EU / US (SCCs)
Stripe Payments Europe LtdPayment processing for Premium subscriptions: checkout sessions, customer & subscription IDs, webhook signatures. Card data is collected directly by Stripe and never reaches our servers.EU (Ireland)
RevenueCat, Inc.Mobile subscription entitlement management: app-user ID, receipt identifiers, purchase status, renewal/cancellation events and subscription metadata.US (SCCs)
Apple App Store / StoreKit (Apple Distribution International Ltd.)iOS in-app purchase processing: transaction identifiers, receipt data, refund/cancellation status and subscription status.EU (Ireland)
Google Play Billing (Google Ireland Ltd.)Android in-app purchase processing: purchase tokens, subscription status, refund/cancellation status and Google Play billing metadata.EU (Ireland)
Firebase Cloud Messaging / GooglePush notifications: device push tokens, delivery metadata and notification routing for Android/web push where enabled.EU / US (SCCs)
Tenjin, Inc.Mobile install & event attribution and analytics (SDK): install/in-app events, device advertising ID (GAID/IDFA), IP address, device model, OS version and campaign/referrer data, used to attribute installs to advertising campaigns.US (SCCs)
TikTokMarketing attribution and campaign measurement where enabled and consented: event identifiers, advertising ID, device/browser data and conversion metadata.Global (SCCs where required)
Meta Platforms Ireland Ltd.Meta Pixel / Meta Ads marketing attribution where enabled and consented: event identifiers, advertising ID, browser/device data and conversion metadata.EU / US (SCCs where required)
OpenAI (via Base44 InvokeLLM)AI vision model for identity-verification liveness analysis (selfie + gesture check), AI interest-matching scoring, and content-moderation assistance. Inputs are processed for inference only and not used to train models.US (sub-processed by Base44 under SCCs)
OpenStreetMap Foundation — NominatimReverse geocoding: latitude/longitude → city/country. Coordinates are sent server-side; we do not echo raw coordinates back to other users.EU (UK / DE)
OpenStreetMap tile serversMap basemap tiles for hangouts map, world map, online-users map and location pickers. Receives IP, User-Agent and tile coordinates.EU
Google Fonts (Google Ireland Ltd.)Delivery of the 'Inter' and 'Space Grotesk' web fonts. Receives IP address, User-Agent and Referer when the font is loaded.EU (Ireland)

Advertising, analytics and attribution

We use advertising attribution and analytics partners — specifically Tenjin (mobile install/event attribution), TikTok and Meta (campaign measurement) — to understand which advertising campaigns lead to installs and activity. To do this, our mobile app collects your device advertising identifier (Google Advertising ID on Android, IDFA on iOS) and shares install/event data with these partners, only where enabled and permitted by your cookie / app-tracking choices. We do not sell personal data. Where a law treats targeted advertising or cross-context sharing as a "sale" or "sharing", you may opt out using your cookie preferences, your device advertising-ID settings, or by contacting us.

Custom & Lookalike Audiences (sharing your email/contact data): where you have consented to marketing, we may share your email address or other contact data with advertising platforms such as Meta (Facebook) and TikTok to build Custom Audiences (matched lists of our users) and Lookalike Audiences (people similar to our users) for our own marketing and prospecting campaigns. This is a separate purpose from attribution measurement and involves sharing your personal data with these platforms. We rely on your marketing consent (Art. 6(1)(a)) and, where applicable, our legitimate interest in promoting the service (Art. 6(1)(f)) as the legal basis. We certify to these platforms that we have a valid legal basis to share this data, as required by their Custom Audience terms. You can opt out at any time via your cookie / ad-consent settings (see Section 14), by contacting us, or through the platform's own controls (e.g. Meta Accounts Center → Ad preferences). Opting out does not affect the lawfulness of processing that took place before you withdrew consent.

Outbound social-share links and third-party sites

When you click a "Share" button, your browser opens the destination platform (e.g. Facebook, X / Twitter, WhatsApp). No personal data is sent to those platforms by us automatically — only the URL you choose to share, and only when you click. These platforms are independent controllers; please review their own privacy policies.

Where data is transferred outside the EU/EEA, we rely on the European Commission's Standard Contractual Clauses (Art. 46) together with technical and organisational safeguards (encryption in transit and at rest, access controls, audit logging). We do not sell personal data. We share limited attribution data with the advertising/analytics partners named above only where you have consented.

6. Visibility to Other Users

Your profile and activity may be visible to other authenticated users depending on your settings and the feature you use. This can include your name, profile photos, avatar, bio, age, city/country, interests, languages, dating/travel preferences, posts, stories, reviews, comments, trips, hangouts, streams, check-ins and messages sent in shared/group areas. You can hide your profile from discovery / dating at any time in Settings. Public or shared content should not be treated as confidential.

Reviews and ratings: after a hangout or activity you may rate other participants and they may rate you. Your aggregate star rating is shown on your profile. Individual trait scores (friendliness, reliability, communication, respect, vibe) and comments are visible to the person being rated; low ratings are used internally for trust, safety and moderation and are not displayed on your profile to other users. A sustained pattern of negative feedback may flag an account for human review by our safety team.

7. Location Data

We only collect precise location (latitude/longitude) when you grant explicit permission via your browser/device. Coordinates are reverse-geocoded to a city/country and we do not echo raw coordinates back to other users. You can revoke location permission at any time in your device settings; some discovery features will then be limited.

8. Identity Verification (AI Liveness)

When you choose to verify your identity, we capture a live selfie in which you are asked to perform a randomly chosen gesture (e.g. a peace sign on the left or right side of the frame). The image is analysed by an AI vision model only to determine whether (i) it is a live human, (ii) the requested gesture is shown, and (iii) the gesture appears in the requested position. We store the AI's boolean result, a confidence score, and a short reason text. The selfie itself is deleted after 180 days. Verification is optional.

9. Your Rights Under GDPR

  • Right of access (Art. 15): request a copy of your personal data — available in-app via Settings → "Download my data"
  • Right to rectification (Art. 16): correct inaccurate data via Edit Profile
  • Right to erasure / "right to be forgotten" (Art. 17): delete your account in Settings → Account; we erase or anonymise your data within 30 days
  • Right to restrict processing (Art. 18)
  • Right to data portability (Art. 20): the data export is provided in machine-readable JSON
  • Right to object (Art. 21): object to processing based on legitimate interest
  • Right to withdraw consent at any time without affecting prior lawful processing
  • Right not to be subject to solely automated decision-making (Art. 22)

To exercise any of these rights, email info@konnectors.app. We will respond within 30 days (Art. 12(3)).

10. US State Privacy Rights

If you are located in a US state with a consumer privacy law, you may have rights to know/access, correct, delete, obtain a portable copy of your data, and opt out of targeted advertising, sale, sharing or certain profiling. We do not sell personal data for money. To exercise these rights, contact info@konnectors.app. We may verify your request through your account or email before acting on it.

11. Right to Lodge a Complaint

If you believe we have not handled your personal data in accordance with the law, contact us first and we will aim to respond to privacy complaints within 30 days. You also have the right to lodge a complaint with the Irish Data Protection Commission, our lead supervisory authority:

12. Security

We apply technical and organisational measures appropriate to the risk, including: row-level security on every database entity, file MIME-type and size validation, server-side authentication checks on every backend function, optional multi-factor authentication (email OTP + TOTP), hashed device-trust tokens, signed Stripe webhooks, automated brute-force / DoS detection, encrypted transport (TLS), and encryption at rest by our hosting provider. No system is perfectly secure; in the event of a personal-data breach, we will notify the DPC within 72 hours and affected users without undue delay where required by Articles 33 and 34.

13. Children

The Service is restricted to users 18 and over. We verify age at sign-up via the date of birth you provide. We do not knowingly collect data from anyone under 18. If we discover an account belongs to a minor, we delete it immediately.

14. Cookies

We classify cookies and similar technologies into three categories: essential (always on, required for log-in, security, fraud prevention and payments), analytics (off by default — only loaded after you opt in), and marketing/attribution (off by default — only loaded after you opt in). These technologies may include cookies, pixels, SDK identifiers, device IDs, advertising IDs and server-side event tracking. You can change or withdraw your preferences at any time via the in-app banner, in Account Settings → Privacy → Manage Cookie & Ad Consent, or your device/app tracking settings.

15. International Transfers

Your data is processed primarily in the European Economic Area. Where sub-processors operate outside the EEA, we rely on the European Commission's Standard Contractual Clauses (Art. 46) as the transfer mechanism, together with technical safeguards (encryption in transit and at rest).

16. Changes to This Policy

We may update this Privacy Policy. Material changes will be communicated by in-app notice and/or email at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.

17. Definitions and Contact

"Personal data" means information relating to an identified or identifiable person. "Processing" means any operation performed on personal data, such as collection, storage, use, disclosure, deletion or analysis. "Special-category data" means sensitive data under GDPR Article 9, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, health, biometric data used for identification, sex life or sexual orientation.

18. Contact

For privacy questions, data subject requests, or to exercise any GDPR right, contact our data-protection contact at info@konnectors.app.