핵심 안내: 프로필 등록·수정 시 별도 동의를 받은 뒤 현재 프로필의 모든 사진·배경 이미지와 공개 프로필 문구를
Google Cloud Vertex AI(Gemini)의 일본 도쿄 리전으로 보내 안전 심사를 수행할 수 있습니다. 안전한 결과는 자동
승인될 수 있고, 위험하거나 불확실한 결과는 공개하지 않은 채 운영자가 확인합니다. 이 기능은 얼굴을 다른 사진과
대조하거나 신원을 확인하는 생체인식 기능이 아닙니다.
1. 개인정보처리자와 적용 범위
이 방침은 Blurry 모바일 앱, 관련 웹페이지, 고객지원 및 운영 서비스에 적용됩니다.
- 개인정보처리자: 주식회사 하이퍼리티(Hyperity Corp. Inc.)
- 대표자 및 개인정보 보호책임자: 전광하
- 사업자등록번호: 598-81-00904
- 주소: 경기도 성남시 분당구 운중로 124, 8층 804호 C-49(운중동)
- 개인정보 문의: support@hyperitycorp.com
Blurry는 성인용 데이팅 서비스이며 만 18세 미만을 대상으로 하지 않습니다. 만 18세 미만의 정보가 수집된 사실을
알게 되면 확인 후 삭제 조치합니다.
2. 처리하는 개인정보, 목적 및 보유 기준
| 범주 | 구체적인 항목 | 처리 목적 | 보유 기준 |
| 계정·인증 |
Firebase 사용자 ID, 전화번호 또는 이메일, Apple/Google 로그인 식별자, 표시 이름, 가입·최근 로그인 시각,
언어·국가, 계정 상태 |
가입, 로그인, 본인 계정 식별, 중복·부정 이용 방지, 고객지원 |
회원 기간 동안. 앱에서 계정 삭제를 확정하면 인증 계정과 계정에 연결된 서비스 데이터를 삭제하거나
익명화합니다. 앱을 사용할 수 없는 경우의 삭제 요청 및 법정 보관 예외는
계정 삭제 안내에 따릅니다. |
| 프로필·민감할 수 있는 정보 |
생년월일·연령, 성별 및 데이팅 선호, 국가·도시, 기기 또는 지도에서 선택한 좌표, IP로 추정한 대략적 위치,
키·체형, 직업, MBTI·성격, 결혼·자녀, 음주·흡연·운동 등 생활정보, 자산 수준, 종교·정치 성향 등 선택 답변,
가치관·Q&A·자기소개 |
성인 여부 확인, 프로필 구성, 매칭·추천·필터, 개인화, 안전 심사 |
계정 또는 해당 프로필 항목이 삭제될 때까지. 사용자가 편집한 값은 새 값으로 대체됩니다. |
| 사진·음성 |
프로필 사진·프로필 배경 이미지와 그 안의 보이는 글자, 인증·문의 첨부 이미지, 선택한 음성 프로필 녹음 |
프로필 표시·블러 공개, 프로필 안전 심사, 고객지원, 음성 프로필 제공 |
사용자가 교체·삭제하거나 계정을 완전 삭제할 때까지. 실시간 음성 통화는 회사가 녹음 파일로 저장하지
않지만 통화 연결 사업자가 통화 중 미디어를 전송 처리합니다. |
| 서비스 활동·이용자 콘텐츠 |
좋아요·매치·차단·신고, 차단 목적으로 직접 입력한 전화번호·메모, 채팅 메시지와 선택한 번역·AI 상담 입력,
통화 방 ID·참여·시각 등 메타데이터, 게시물·댓글·투표, 문의 내용·첨부, AI 기능의 입력과 결과 |
채팅·통화·커뮤니티 기능, 번역·AI 기능, 신고·분쟁 처리, 서비스 안전 |
서비스 제공과 분쟁 처리를 위해 필요한 동안. 다른 이용자에게 이미 전달된 콘텐츠는 상대방의 대화 기록이나
법적 보존 대상에 남을 수 있으며, 계정 식별자는 가능한 범위에서 삭제 또는 익명화합니다. |
| 결제·구독 |
상품 ID, 주문·거래·영수증 식별자, 구매 시각, 통화·금액, 구독 상태·만료일, 지급된 권리 |
App Store·Google Play 결제 검증, 상품 지급, 복원·환불·부정 결제 방지, 회계 |
전자상거래 관련 법령에 따라 계약·결제·공급 기록은 5년, 소비자 불만·분쟁 기록은 3년 보관할 수 있습니다.
계정 삭제 시 서비스 사용자 식별자는 삭제 토큰으로 익명화할 수 있습니다. |
| 기기·로그·분석·광고 |
IP 주소, Firebase 설치 ID, 기기·광고 식별자(IDFA/GAID 등, 허용된 경우), FCM 토큰, OS·기기·앱 버전,
언어·시간대·네트워크, 설치 경로·캠페인, 화면·버튼 등 이용 이벤트, 충돌 스택·진단·성능 정보 |
보안, 푸시 알림, 오류 해결, 품질·퍼널 분석, 광고 게재·빈도 관리·성과 측정·귀속 |
서비스별 설정과 제공자 기준에 따릅니다. 예: Firebase Crashlytics 충돌 정보는 90일 후 삭제 절차가 시작되고,
AppsFlyer 집계 데이터는 최대 25개월, AdMob 보고서는 종류에 따라 90일 또는 2,555일 보관될 수 있습니다.
회사가 만든 비식별 집계 통계는 개인을 식별하지 않는 형태로 계속 보유할 수 있습니다. |
사진·카메라, 마이크, 알림, 위치 및 iOS 앱 추적 투명성 권한은 해당 기능을 사용할 때 운영체제를 통해 요청합니다.
위치 권한을 허용하거나 지도에서 지점을 고르면 해당 좌표를 매칭 거리와 지역 기능을 위해 저장할 수 있습니다. 기본
지역에는 사용자가 고른 도시 또는 IP로 추정한 대략적 지역을 사용할 수 있습니다. 주소록 전체를 읽어 Blurry 서버에
업로드하지는 않지만, 이용자가 차단을 위해 직접 입력한 전화번호와 메모는 저장될 수 있습니다.
3. 수집 방법
- 가입, 프로필 작성, 메시지·통화·신고·문의·구매 등 이용자가 직접 기능을 사용할 때
- 앱, Firebase 및 통합 SDK가 기기·이용·진단 정보를 자동 생성할 때
- Apple, Google, 앱 스토어, 결제 검증 또는 로그인 제공자로부터 필요한 결과를 받을 때
- 운영자가 신고·이의신청·고객지원 사건을 처리할 때
4. AI 기능과 프로필 안전 심사
4.1 프로필 심사에 전송되는 정보
별도 동의 후 현재 프로필의 모든 사진과 배경 이미지(보이는 글자 포함), 공개 프로필 문구(MBTI·직업, 성격, 자기소개, 공개 Q&A와
가치관 답변)를 Firebase App Check와 인증으로 보호되는 회사 서버를 거쳐 Google Cloud Vertex AI의
gemini-3.5-flash 모델로
전송합니다. 사진 파일은 전송 전에 EXIF 메타데이터를 제거하고 크기를 제한합니다. 이 흐름에는 전화번호, 이메일,
채팅 내역 또는 정확한 위치를 넣지 않습니다. 인증 사용자 ID는 접근 통제와 호출 한도에 사용하지만 모델 입력에는
포함하지 않습니다.
4.2 자동 판단과 사람의 검토
모델은 성인 데이팅 프로필에 부적절하거나 위험한 콘텐츠가 있는지 분류합니다. 안전한 결과는 프로필을 자동 승인할
수 있습니다. 위험하거나 불확실한 결과는 프로필을 공개하지 않고 운영자 검토 대기 상태로 둡니다. 운영자는 결과를
확인해 승인 또는 거절할 수 있습니다. 이용자는 고객지원으로 결과에
이의를 제기하고 사람의 재검토를 요청할 수 있습니다.
이 심사는 얼굴을 다른 사진과 비교하거나 얼굴 템플릿을 만들거나 신원을 확인하지 않습니다. 프로필 심사 입력은
광고 개인화에 사용하지 않습니다.
4.3 다른 선택형 AI 기능
이용자가 채팅 도우미, 번역, 타로·상담, 소개 문구 제안 또는 AI 큐레이션을 실행하면 해당 요청을 수행하는 데 필요한
입력(예: 선택한 메시지, 최근 대화 일부, 공개 프로필, 작성 중인 문구)이 Vertex AI로 전송될 수 있습니다. 스팸 차단
이의신청을 제출하면 신고된 메시지 내용이 Google Gemini API로 분석될 수 있으며, 자동 해제되지 않은 사건은 운영자가
확인합니다.
4.4 Google Cloud 보관과 회사 보관의 구분
- Google Cloud 처리: 프로필 안전 심사는 일본 도쿄(
asia-northeast1) 리전에서 처리합니다.
Google의 공개 기준상 Gemini 입력·출력·파생 데이터는 기본적으로 프로젝트별로 격리된 메모리 캐시에 최대 24시간
남을 수 있습니다. Google은 사전 허락이나 지시 없이 이 고객 데이터를 모델 학습·미세조정에 사용하지 않습니다.
Google Cloud 약관 적용 범위에서는 악용 탐지를 위해 프롬프트를 기록할 가능성이 있으며, 회사는 그러한 예외 적용
여부와 캐시 설정을 정기적으로 확인합니다.
- 회사 저장: 프로필 원본 사진과 문구는 프로필 제공을 위해 Firebase Storage·Firestore에 위 표의
기간 동안 보관됩니다. 현재 프로필 심사 동의 정책 버전은
2026-07-23이며, 인증 사용자 ID별 동의
버전·시각·철회 상태는 profile_moderation_consents/{authUid}에 기록합니다. 심사 상태·사유,
호출 횟수·날짜 같은 운영 메타데이터도 안전 운영과 이의신청 처리를 위해 보관됩니다. 회사 애플리케이션 로그에는
프로필 사진이나 원문 프롬프트를 별도 기록하지 않고 오류 종류와 요청 식별 정보만 기록하도록 운영합니다.
동의를 거부하면 해당 프로필 데이터는 AI 심사로 전송되지 않지만 새 프로필 또는 변경된 프로필을 공개할 수 없습니다.
동의 상태 조회·동의·철회는 인증 및 App Check로 보호되는 callable 함수
manageProfileModerationConsent의 status, grant, withdraw
작업으로 처리합니다. 철회 요청에는 서버 시각을 기록하고 이후 프로필 심사 전송을 차단합니다. 철회 전 처리는 유효하며,
새 등록·수정 내용을 공개하려면 버전 2026-07-23 또는 당시 적용되는 최신 버전에 다시 동의해야 할 수
있습니다.
5. 다른 이용자 제공 및 법적 공개
프로필 정보, 블러 처리된 사진, 음성 프로필, 좋아요·매치 상태와 메시지는 이용자가 선택한 서비스 기능에 따라 다른
이용자에게 표시됩니다. 신고 시 신고 대상 콘텐츠와 필요한 계정 정보가 신고 처리 담당자에게 제공됩니다. 법령, 적법한
수사·법원 명령, 생명·안전 보호 또는 권리 침해 방지를 위해 필요한 경우 관계 기관이나 권리자에게 최소한의 정보를
제공할 수 있습니다.
6. 처리위탁·통합 서비스
| 제공자/서비스 | 처리 내용과 목적 | 보유·통제 기준 |
| Google Cloud / Firebase | Auth, App Check, Firestore, Storage, Cloud Functions, Realtime Database,
FCM, Remote Config, Hosting, Crashlytics, Analytics, Vertex AI를 이용한 인증·저장·서버 처리·알림·진단·분석·AI |
회사의 삭제·보유 설정과 Google Cloud/Firebase 약관. Firestore 일일 내보내기 백업은 7일 이내 순환 삭제되도록
구성합니다. Crashlytics는 위 기준을 따릅니다. |
| Google AdMob | 광고 요청·게재·빈도 관리·성과 측정. 기기/광고 ID, IP 기반 대략적 위치, 광고·앱 상호작용,
진단 정보가 처리될 수 있습니다. | 운영체제 추적 권한과 지역별 동의 상태를 따르며, 사용 가능한 경우 비개인화
광고 또는 제한적 데이터 처리 설정을 적용할 수 있습니다. |
| AppsFlyer | 설치·캠페인 귀속과 구매 성과 측정. SDK가 실제로 시작된 빌드에서 AppsFlyer ID, 허용된
광고/기기 식별자, IP, 설치·앱 이벤트와 구매 이벤트가 처리될 수 있습니다. | AppsFlyer 설정과 제공자 정책.
이용자 수준 원시 데이터 기간은 연동·매체별로 다르고, 집계 데이터는 최대 25개월입니다. |
| Apple / Google Play | 로그인, 앱 배포, 인앱 구매·구독·영수증 검증·환불 | 각 스토어 계정과 결제
정책 및 법정 보존기간 |
| VideoSDK (Zujo Tech Pvt. Ltd.) | 이용자가 음성 통화를 시작한 동안 방 식별자, 참가·연결 정보,
IP·기기 정보와 실시간 오디오 전송 | 통화 제공에 필요한 기간과 VideoSDK 정책. 회사는 통화 오디오를 녹음
파일로 저장하지 않습니다. |
| APILayer ipstack | 가입 지역 기본값을 제안하기 위한 IP 기반 국가·도시·대략 좌표 조회 |
요청 시 전송되며 APILayer 처리 약관상 목적 달성 및 법적 필요 기간 |
| Google Maps Platform | 지역 선택 지도의 표시·좌표 확인과 상호작용. 선택하거나 기기에서 받은 좌표,
IP, 기기·SDK 정보, 지도 상호작용과 가명 SDK 식별자가 처리될 수 있습니다. | Google Maps 약관과 이용자 설정 |
7. 국외 처리·이전
국외 서비스는 전송 구간을 암호화해 이용합니다. 특정 제품이 고정 리전을 제공하는 경우 그 리전을 사용하고, 글로벌
운영 서비스는 제공자의 최신 하위처리자·인프라 목록에 따라 처리 국가가 달라질 수 있습니다.
| 수령자·연락처 | 국가 | 항목·목적 | 시기·방법 | 보유 |
계약상 Google Cloud 제공 법인 및 Google Cloud 하위처리자
Google Cloud 문의 |
일본(도쿄) |
동의한 전체 프로필 사진·배경 이미지·보이는 글자·공개 프로필 문구 / 안전 심사 |
가입·프로필 수정 시 동의 버튼을 누른 뒤 Firebase 보안 서버에서 암호화 통신 |
기본 프로젝트 격리 메모리 캐시 최대 24시간. 약관 적용 시 악용 탐지 로그가 생성될 수 있음. 사전 허락·지시 없는
모델 학습에는 사용하지 않음. |
Google LLC 및 Firebase/Google 하위처리자
Firebase Privacy |
싱가포르(Realtime Database), 미국 및
현행 하위처리자 소재국 |
계정·설치 ID, 접속·온라인 상태, 푸시 토큰, 분석·충돌·광고 데이터 / 인증·동기화·알림·분석·진단·광고 |
해당 기능 사용 및 이벤트 발생 시 암호화 통신 |
제품별 설정·약관. Firebase 설치 ID는 삭제 API 호출 후 라이브·백업 시스템에서 제거되는 데 최대 180일이 걸릴
수 있고, Crashlytics 데이터는 90일 후 삭제 절차가 시작됨. |
AppsFlyer Ltd. dpo@appsflyer.com |
미국, 이스라엘, 유럽경제지역 및 제공자 하위처리자 소재국 |
설치·기기/광고 식별자·IP·앱/구매 이벤트 / 광고 귀속·성과 측정 |
SDK가 시작된 빌드에서 설치·이벤트 발생 시 암호화 통신 |
매체·연동별 원시 데이터 보유기간, 집계 데이터 최대 25개월 |
Zujo Tech Pvt. Ltd. (VideoSDK) security@videosdk.live |
미국, 인도 및 통화 품질을 위해 선택되는 AWS 처리 리전 |
방·참가·연결 메타데이터, IP·기기 정보, 통화 중 오디오 / 실시간 음성 통화 |
이용자가 통화를 시작·참여하는 동안 암호화된 실시간 전송 |
통화 제공과 보안·법적 의무에 필요한 기간. 상세 기간은 VideoSDK 정책에 따름. |
apilayer Data Products GmbH (ipstack)
compliance@apilayer.com |
오스트리아 및 제공자 미국/EU 인프라 |
IP 주소 / 국가·도시 수준의 대략적 위치 제안 |
가입 지역 확인 시 암호화 API 호출 |
목적 달성과 제공자 법적 의무에 필요한 기간 |
Google LLC 및 Google Maps Platform 하위처리자
Google Maps Platform 약관 |
미국 및 제공자 하위처리자 소재국 |
선택하거나 기기에서 받은 좌표, IP, 기기·SDK 정보, 지도 상호작용 / 지역 선택·주소 확인 |
위치 선택·현재 위치 확인 시 암호화 통신 |
Google Maps Platform 설정과 제공자 정책에 따른 기간 |
| Apple Inc. / Google LLC |
미국 및 이용자의 스토어 계정·지역에 따른 처리국 |
로그인 토큰, 거래·영수증·구독 정보 / 로그인·결제·환불·부정 이용 방지 |
로그인·구매·복원·환불 시 암호화 통신 |
각 제공자 정책 및 회사의 법정 보존기간 |
프로필 AI 심사를 위한 일본 이전 동의를 거부하거나 철회하는 방법은 제4항과 같습니다. 다른 필수 처리의 국외 이전을
거부하면 로그인, 알림, 통화, 결제 검증 등 해당 기능 또는 서비스 이용이 제한될 수 있습니다. 광고 추적은 운영체제
설정 및 제공되는 개인정보 옵션에서 선택을 변경할 수 있습니다.
8. 삭제, 보관 및 백업
- 프로필은 앱에서 편집할 수 있고, 계정 삭제는 앱 설정 또는
공개 삭제 요청 페이지를 통해 요청할 수 있습니다.
- 앱 내 계정 삭제를 확정하면 로그인 인증과 앱 무결성을 확인한 서버가 Firebase Auth, Storage 및 관련 컬렉션의
계정 연결 데이터를 즉시 삭제하거나 익명화하며, 앱은 성공 응답을 받은 뒤에만 완료로 표시합니다.
- 앱을 사용할 수 없으면 공개 삭제 요청 페이지의 이메일 절차로 같은 범위의 삭제를 요청할 수 있습니다.
- 삭제 시 계정·프로필·저장 사진·음성·푸시 토큰과 관련 서비스 데이터를 삭제하거나 익명화합니다. 거래·환불 및
신고·분쟁 자료는 법적 의무와 권리 보호에 필요한 최소 범위만 분리 보관할 수 있습니다.
- 운영 Firestore 일일 내보내기 백업은 7일 이내 순환 삭제되도록 구성되어 있어, 운영 데이터 삭제 뒤에도 그 기간
동안 암호화된 백업에 남을 수 있습니다.
9. 이용자의 권리와 행사 방법
이용자는 자신의 개인정보에 대한 열람, 정정, 삭제, 처리정지, 동의 철회, 국외 이전 관련 선택 및 자동 판단에 대한
설명·이의 제기를 요청할 수 있습니다. 앱의 프로필·설정 기능 또는
support@hyperitycorp.com으로 요청해 주세요. 회사는 계정 탈취를 막기
위해 합리적인 본인 확인을 요청할 수 있으며, 법령상 제한이 있으면 이유를 안내합니다.
대한민국 이용자는 개인정보 침해에 관하여 개인정보침해 신고센터(국번 없이 118), 개인정보분쟁조정위원회 또는
관계 기관에 상담·구제를 신청할 수 있습니다.
10. 안전조치
회사는 전송구간 암호화, Firebase Authentication·App Check, 최소권한 접근, 서버측 비밀 관리, 접근·오류 기록,
업로드 파일 제한, 관리자 권한 분리 및 정기 점검을 적용합니다. 다만 인터넷 전송이나 저장의 절대적 안전을 보장할 수는
없으므로 침해 사고가 확인되면 법령에 따라 조사·통지·완화 조치를 수행합니다.
11. 방침 변경
서비스, 제공자 또는 법령이 변경되면 이 방침을 갱신하고 중요한 변경은 앱 또는 웹페이지에서 시행 전에 알립니다.
상단의 시행일로 현재 버전을 확인할 수 있습니다.
Key notice: When you create or edit a profile, after obtaining separate consent we may send all photos and the
background image in your current profile, plus public profile text, to Google Cloud Vertex AI (Gemini) in the Tokyo, Japan region for a safety review.
Safe results may be approved automatically. Risky or uncertain profiles stay unpublished for human review. This is not a
biometric feature: it does not compare your face against other photos or verify your identity.
1. Controller and scope
This Policy applies to the Blurry mobile app, related web pages, customer support, and operations.
- Controller: Hyperity Corp. Inc. (주식회사 하이퍼리티)
- Representative and privacy lead: Kwangha Jeon (전광하)
- Business registration number: 598-81-00904
- Address: 8F, Room 804 C-49, 124 Unjung-ro, Bundang-gu, Seongnam-si, Gyeonggi-do, Republic of Korea
- Privacy contact: support@hyperitycorp.com
Blurry is an adult dating service and is not intended for anyone under 18. If we learn that we collected a minor's data,
we will verify the circumstances and delete it.
2. Data, purposes, and retention
| Category | Examples | Purpose | Retention |
| Account and authentication | Firebase user ID, phone number or email, Apple/Google sign-in identifier,
display name, sign-up and last-login times, language, country, and account status | Registration, login, account
identification, abuse prevention, and support | For the life of the account. When you confirm in-app deletion,
we delete or anonymize the authentication account and account-linked service data. See
Account deletion for the request available when you cannot use the app
and for statutory-retention exceptions. |
| Profile and potentially sensitive data | Date of birth/age, gender and dating preferences, country/city,
coordinates obtained from the device or selected on a map, IP-derived approximate location, height/body type,
occupation, MBTI/personality, marriage/children, drinking/smoking/exercise and other lifestyle data, asset level,
optional religion/political views, values, public Q&A, and introduction | Age eligibility,
profile display, matching, recommendation, filters, personalization, and safety | Until the account or the
profile field is deleted. Edited values replace prior active values. |
| Photos and audio | Profile photos, profile background images and visible text, verification/support attachments, and optional voice
profile recordings | Profile display and gradual reveal, safety review, support, and voice profile | Until
replaced or deleted by you, or complete account deletion. We do not record live voice calls as audio files, although
the call provider processes media in transit during the call. |
| Activity and user content | Likes, matches, blocks, reports, phone numbers and notes manually entered for
blocking, chat messages and selected translation/AI inputs, call room/participation/time metadata, posts, comments,
votes, support requests and attachments, AI inputs and outputs | Messaging, calling, community, translation and
AI features, safety, disputes, and support | As
needed to provide the feature and resolve disputes. Content already delivered may remain in another user's conversation
record or a legally retained record; we remove or anonymize account identifiers where reasonably possible. |
| Purchases | Product, order, transaction and receipt identifiers, purchase time, currency and amount,
subscription status/expiry, and entitlements | App Store/Google Play validation, fulfillment, restoration,
refunds, fraud prevention, and accounting | Contract, payment, and supply records may be retained for five years,
and consumer complaint/dispute records for three years where Korean e-commerce law applies. User identifiers may be
replaced with a deletion token after account deletion. |
| Device, logs, analytics, and ads | IP address, Firebase installation ID, device/advertising identifiers
where permitted (such as IDFA/GAID), FCM token, OS/device/app version, language, time zone, network, install referrer
and campaign, interactions, crash stack traces, diagnostics, and performance | Security, notifications,
troubleshooting, analytics, advertising, frequency controls, measurement, and attribution | Product settings
and provider terms apply. For example, Firebase Crashlytics begins deleting crash data after 90 days, AppsFlyer may
retain aggregate data for up to 25 months, and AdMob report retention can be 90 or 2,555 days depending on the report.
We may retain statistics that no longer identify an individual. |
We request photo/camera, microphone, notifications, location, and iOS App Tracking Transparency permissions through the
operating system when relevant. If you allow location access or choose a point on the map, we may store its coordinates for
match-distance and regional features. A city you select or an IP-derived approximate region may provide a default. We do not
read and upload your whole address book, but we may store phone numbers and notes you manually enter for blocking.
3. How data is collected
- When you register, create a profile, message, call, report, contact support, or purchase;
- When the app, Firebase, or an integrated SDK creates device, usage, or diagnostic data;
- When Apple, Google, an app store, payment validator, or sign-in provider returns necessary results; and
- When our operations team handles a report, appeal, or support case.
4. AI features and profile safety review
4.1 Profile data sent for review
After separate consent, all photos and the background image in your current profile (including visible text), plus public profile text (MBTI and occupation,
personality, introduction, public Q&A, and values answers) are sent through our Firebase App Check- and authentication-protected
server to the gemini-3.5-flash model on Google Cloud Vertex AI. We strip EXIF metadata and limit the image size
before transfer. This flow
does not include your phone number, email, chat history, or precise location. Your authenticated user ID is used for access
controls and rate limits but is not included in the model input.
4.2 Automated decisions and human review
The model classifies potentially inappropriate or unsafe content for an adult dating profile. Safe results may be approved
automatically. Risky or uncertain profiles remain unpublished and enter human review. Our team may approve or reject the
profile after review. You may email support to appeal and request human review.
This feature does not perform face matching, create face templates, or identify you. Profile moderation input is not used for
ad personalization.
4.3 Other optional AI features
If you invoke chat assistance, translation, tarot/counseling, profile-writing suggestions, or AI curation, the information
needed for that request—such as a selected message, a limited portion of recent conversation, public profile data, or draft
text—may be sent to Vertex AI. If you submit a spam-block appeal, the reported message may be analyzed by the Google Gemini API.
Cases that are not automatically released can be reviewed by our team.
4.4 Google Cloud retention versus Blurry retention
- Google Cloud processing: Profile safety reviews run in Tokyo, Japan
(
asia-northeast1). Under Google's published terms, Gemini inputs, outputs, and derived data can be cached by
default in project-isolated memory for up to 24 hours. Google does not train or fine-tune its AI/ML models on this Customer
Data without prior permission or instruction. Where the applicable Google Cloud terms permit it, Google may log prompts to
detect abuse. We periodically review whether an abuse-monitoring exception and cache setting apply to our project.
- Blurry storage: Original profile photos and text remain in Firebase Storage/Firestore under the profile
retention stated above. The current profile-moderation consent policy version is
2026-07-23. We record each
authenticated user's consent version, time, and withdrawal state in
profile_moderation_consents/{authUid}. We also retain operational metadata such as moderation status/reason and
request count/date for safety, abuse prevention, and appeals. Our application logs are designed not to separately record
profile photos or raw prompts; they record error classes and request identifiers.
If you decline profile-AI consent, that profile data is not transmitted for review, but you cannot publish a new or changed
profile. Consent status, grant, and withdrawal are handled by the authentication- and App Check-protected callable function
manageProfileModerationConsent using the status, grant, and withdraw
actions. A withdrawal records server time and blocks future profile-review transfers. It does not invalidate processing
completed before withdrawal, and you may need to accept version 2026-07-23 or the then-current version before
publishing a new or changed profile.
5. Disclosure to other users and legal disclosures
Your profile, blurred photos, voice profile, like/match state, and messages are shown to other users as directed by the
features you use. A report provides the relevant content and account details to authorized reviewers. We may disclose the
minimum necessary data to authorities or rights holders when required by law, valid legal process, safety needs, or to prevent
fraud and rights violations.
6. Processors and integrated services
| Provider | Processing | Retention/control |
| Google Cloud / Firebase | Auth, App Check, Firestore, Storage, Cloud Functions, Realtime Database,
FCM, Remote Config, Hosting, Crashlytics, Analytics, and Vertex AI for authentication, storage, server processing,
notifications, diagnostics, analytics, and AI | Our retention configuration and Google terms. Daily Firestore
export backups are configured to rotate within seven days. Crashlytics follows the period above. |
| Google AdMob | Ad requests, delivery, frequency control, and measurement. Device/advertising IDs, IP-derived
approximate location, ad/app interactions, and diagnostics may be processed. | Operating-system tracking permission
and regional consent choices apply; non-personalized ads or restricted data processing may be used where available. |
| AppsFlyer | Install/campaign attribution and purchase measurement. In builds where the SDK is started,
AppsFlyer ID, permitted advertising/device IDs, IP, app events, and purchase events may be processed. | AppsFlyer
configuration and policy. Raw user-level periods vary by integration/media source; aggregate data may remain up to 25 months. |
| Apple / Google Play | Sign-in, app distribution, in-app purchases, subscriptions, receipt validation, and refunds |
Store account/payment terms and legally required retention |
| VideoSDK (Zujo Tech Pvt. Ltd.) | Room, participant, connection, IP/device data, and live audio transport
while you initiate or join a voice call | As needed for the call and under VideoSDK policy. We do not record live
call audio as a stored audio file. |
| APILayer ipstack | IP-based country, city, and approximate-coordinate lookup to suggest a registration region |
At the time of request and as needed under APILayer terms |
| Google Maps Platform | Map display, coordinate lookup, and interaction for location selection. Coordinates
you select or obtain from the device, IP, device/SDK metadata, map interactions, and a pseudonymous SDK identifier may
be processed. | Google Maps terms and your settings |
7. International processing and transfers
We use encryption in transit for international services. We select a fixed region when the product supports it. For globally
operated services, processing locations may change under the provider's current infrastructure and subprocessor list.
| Recipient/contact | Location | Data/purpose | Timing/method | Retention |
The Google entity in our Cloud agreement and Google Cloud subprocessors
Google Cloud contact | Tokyo, Japan |
Consented profile photos, profile background image, visible text, and public profile text / profile safety | Encrypted server transfer
after you tap the consent button during registration or profile editing | Default project-isolated in-memory cache
up to 24 hours; abuse-monitoring logs may apply under the applicable terms; no model training without prior permission/instruction |
Google LLC and Firebase/Google subprocessors Firebase Privacy |
Singapore (Realtime Database), United States, and locations in the
current subprocessor list | Account/installation IDs,
connection/presence state, push token, analytics, crash, and ad data / authentication, sync, notifications, analytics,
diagnostics, ads | Encrypted transfer when the feature or event occurs | Product settings/terms. Firebase
installation deletion can take up to 180 days across live and backup systems; Crashlytics begins deletion after 90 days. |
AppsFlyer Ltd. dpo@appsflyer.com | United States, Israel, EEA,
and provider-subprocessor locations | Install, device/advertising IDs, IP, app and purchase events / attribution
and measurement | Encrypted transfer on install/events in builds where the SDK is started | Raw period varies;
aggregate data up to 25 months |
Zujo Tech Pvt. Ltd. (VideoSDK) security@videosdk.live |
United States, India, and AWS regions selected for call quality | Room/participant/connection metadata,
IP/device information, and in-call audio / live voice call | Encrypted real-time transport while you initiate or join |
As needed for service, security, and law; details follow VideoSDK policy |
apilayer Data Products GmbH (ipstack) compliance@apilayer.com |
Austria and provider infrastructure in the United States/EU | IP address / approximate country-city suggestion |
Encrypted API request when checking registration region | As needed for purpose and provider legal obligations |
Google LLC and Google Maps Platform subprocessors
Google Maps Platform terms | United States and
provider-subprocessor locations | Coordinates selected or obtained from the device, IP, device/SDK information,
and map interactions / location selection and address lookup | Encrypted transfer when selecting or confirming a
location | Google Maps Platform settings and provider policy |
| Apple Inc. / Google LLC | United States and locations associated with your store account/region |
Sign-in token, transaction/receipt/subscription data / sign-in, payment, refund, fraud prevention | Encrypted
transfer on sign-in, purchase, restore, or refund | Provider policy and our statutory retention |
You can decline or withdraw the Japan transfer for profile AI as described in Section 4. Refusal of other transfers necessary
for a feature may prevent login, notifications, calling, payment validation, or the relevant service. You can change ad-tracking
choices in operating-system settings and any privacy options we provide.
8. Deletion, retention, and backups
- You can edit profile data in the app and request account deletion in Settings or on our public
account-deletion page.
- After you confirm in-app deletion, the server verifies the signed-in account and app integrity, then immediately deletes
or anonymizes account-linked data across Firebase Auth, Storage, and related collections. The app reports completion only
after the server confirms it.
- If you cannot use the app, you can request deletion with the same scope through the email process on the public page.
- On deletion, we delete or anonymize account, profile, stored photos/audio, push tokens, and related service data.
We may isolate the minimum transaction/refund and report/dispute record required by law or to protect rights.
- Daily operational Firestore export backups are configured to rotate within seven days, so deleted data may remain in an
encrypted backup during that period.
9. Your rights
You may request access, correction, deletion, restriction, withdrawal of consent, international-transfer choices, and an
explanation or appeal of an automated profile decision. Use in-app profile/settings controls or email
support@hyperitycorp.com. We may reasonably verify identity to prevent account
takeover. If law limits a request, we will explain why.
10. Security
We use encryption in transit, Firebase Authentication and App Check, least-privilege access, server-side secret management,
access/error logging, upload limits, separated administrator privileges, and periodic reviews. No internet transmission or
storage is guaranteed to be absolutely secure. If we confirm an incident, we investigate, notify, and mitigate as required by law.
11. Changes
We update this Policy when services, providers, or law change. We provide advance notice in the app or on this page for
material changes. The effective date above identifies the current version.