LoveJan Privacy Policy
Last updated: July 22, 2026
LoveJan is a privacy-first dating app for the Persian-American diaspora and all who wish to join.
What we collect
- Account: an Apple-issued identifier via Sign in with Apple. We do not collect your name or email from Apple, and we do not collect phone numbers.
- Profile: display name, birth date (for 18+ verification and age display), gender, who you're interested in, a chosen home city (city-level only), optional languages, relationship intent, generation, bio, and photos.
- Coarse location only: we store the centroid of the city you select — never your precise device location. We never request location permission and never access GPS. Distance to others is shown only as rounded buckets (e.g., "Nearby", "~50 km").
- Activity: likes and passes, matches, and messages with your matches.
- Subscriptions: LoveJan is free to join, with optional Premium subscriptions purchased through Apple In-App Purchase. If you buy one, we store an Apple transaction reference and an expiry date (validated with Apple). We never see your card details.
- Verification: LoveJan is a verified community — before matching, each member completes a one-time selfie check used to derive a faceprint, described in full under Identity verification & biometric data below. We never store the selfie image itself. A human-review alternative is available that creates no biometric data.
- We use no third-party analytics or advertising SDKs.
Why (GDPR lawful bases)
- Contract: to operate the matching and messaging service you sign up for.
- Consent: optional profile fields (languages, intent, generation, Travel Mode) — provided only if you choose. Withdraw anytime by editing or clearing them.
- Legitimate interests: safety (block and report) and fraud or abuse prevention.
- We do not profile by ethnicity or religion, and we do not infer sensitive characteristics. Pricing is flat and identical for everyone (no gender-based or personalized pricing).
Your rights (GDPR / UK GDPR / CPRA / PIPEDA)
- Access, portability, correction: edit your profile in-app; contact us for a copy.
- Erasure: Settings → Delete account performs an immediate hard, cascading delete of your profile, photos (both blurred preview and original), your verification faceprint (removed from our verification processor), matches, messages, and your authentication record. This is irreversible and runs server-side.
- Objection, restriction, withdraw consent: clear optional fields or delete your account.
- California (CPRA): we do not "sell" or "share" personal information; no targeted ads.
- Canada (PIPEDA): Canadian users may contact us to access or correct their data and may escalate to the Office of the Privacy Commissioner of Canada.
International data transfers
LoveJan runs on Supabase infrastructure hosted on AWS (us-west-1, United States). If you use LoveJan from the EU, UK, Canada, or elsewhere, your data is transferred to and processed in the United States under appropriate safeguards (e.g., Standard Contractual Clauses with our processors). City centroids and bucketed distances are the only location-related data processed.
Photos
Your full-resolution photo is private until you match: it lives in a private bucket and is only retrievable by someone you've mutually matched with. The feed shows a blurred, downscaled preview.
Identity verification & biometric data
Verification is required to participate. To keep every profile a real person, each member completes a one-time selfie check before matching and messaging: it confirms your selfie matches your own profile photo, and that the same face is not already verified on another account. This is how we keep fake, stolen-photo, and duplicate accounts off LoveJan. If you can’t — or prefer not to — take the selfie check, you can ask for human review instead (“Have a real person verify me” on the verification screen): our team reviews your existing profile photos and can verify you without any biometric data being created. If you choose neither, you can’t participate in matching, and you may delete your account at any time — all data, including any faceprint, is erased.
- What the check captures. Using your front camera you take a selfie in the moment — not an upload. If the anti-spoofing “liveness” check is enabled, the camera also captures a brief sequence of frames used only to confirm a live person is present (not a photo or a screen). Your device runs an on-device face check (Apple Vision) to help ensure a clear, single face is in frame before anything is sent.
- How it is processed, and by whom. Your selfie (and any liveness frames) are sent over an encrypted connection to our verification service, which uses Amazon Web Services (AWS Rekognition) — our verification processor, located in the United States — to (1) when the anti-spoofing liveness step is enabled, confirm you are live, (2) compare your selfie to your own profile photo so we know it is you, and (3) check that the face is not already verified on another account. To do step (3), AWS derives a facial-geometry vector — a mathematical “faceprint” — from your selfie. This faceprint is a biometric identifier.
- What we keep — and what we don’t. We do not store your selfie image or your liveness frames. They are used only in the moment of the check and then discarded — never saved to your profile, never shown to anyone, never posted. The only thing we retain is the faceprint vector, held by AWS in a private collection tagged solely with your account identifier and used for a single, limited purpose: preventing the same person from verifying multiple accounts. It is never used to identify you to other members, to build a profile of you, or for advertising. We also record that your account is verified, and the date.
- We never sell it. We do not, and will not, sell, lease, trade, or otherwise profit from your biometric data, and we do not disclose it to anyone except AWS — solely to perform the checks above — or where strictly required by law.
- Retention and destruction. We keep your faceprint only while your account is active and verified. We permanently destroy it at the earliest of: when you delete your account; when you ask us to remove your verification; or within three (3) years of your last activity on LoveJan. Deleting your account (Settings → Delete account) runs a hard, cascading, server-side delete that removes your faceprint from the AWS collection together with your photos and all account data — irreversibly.
- Your consent and choices. Biometric processing happens only after you give your informed consent on the verification screen, before any capture — your consent, and the policy version you agreed to, is recorded. If you prefer not to consent, choose the human-review alternative (no biometric data is created) or delete your account. To withdraw consent and have your faceprint deleted, contact privacy@lovejan.app or delete your account.
If you live in a U.S. state with a biometric-privacy law — including Illinois (BIPA), Texas (CUBI), and Washington — those rights apply to you, and this section, together with the in-app consent, is our written policy governing the collection, use, safeguarding, retention, and destruction of biometric identifiers. Under the California CPRA, biometric information is “sensitive personal information”; we use it only for the limited verification purpose described here and do not sell or share it. Questions or requests: privacy@lovejan.app.
Retention
We keep your data while your account is active. On deletion it is removed immediately as described above. Backups, if any, are purged on our processor's rolling schedule.
Age
LoveJan is strictly 18+, enforced server-side at signup for all territories.