privacy policy.
This Privacy Policy explains how Polari Group, a New Mexico limited liability company (“Polari Group,” “we,” “us,” “our”) collects, uses, shares, and protects information when you use Ojalá — our website at ojaladating.com, our iOS and Android mobile applications, and every related service (collectively, the “Service”).
This Privacy Policy is part of, and incorporated into, our Terms of Service. Capitalised terms that aren't defined here have the meanings given in the Terms.
For the purposes of the GDPR and UK GDPR, Polari Group is the data controller of the personal data described here.
1. Scope and definitions
This Policy covers personal information about identified or identifiable individuals who use the Service. It does not cover: (a) third-party websites or services we link to (subject to their own privacy policies); (b) information you publish into public surfaces of the Service intending for other users to see it (in which case you have already shared it with those users — but we still protect what we hold of it); or (c) data that is fully aggregated or de-identified.
2. What we collect
Account & identity
- Email address and an argon2id-hashed password (we never store your plaintext password). For anonymous accounts, a server-issued visitor token + a browser fingerprint (see “Device identifiers” below) anchor the account.
- Server-issued authentication tokens stored as HttpOnly cookies (a short-lived access token, a 30-day refresh token bound to Redis).
- Display name and date of birth.
Profile content (what you choose to share)
- Profile photos (your main photo + additional slots), bio, headline, height, gender, pronouns, ethnicity, relationship status, languages, the genders you ask to be shown (“Show me”), what you are looking for, and other profile fields.
- Sensitive information — anything you choose to put in a profile field that reveals health information, sexual orientation, or gender identity. By placing this on your profile, you are choosing to share it with the other users who view your profile. See § 6.
Location
- Your device sends precise GPS coordinates to our servers when you publish a location. On receipt we fuzz the coordinates by ~150 metres (configurable up to a wider radius in Settings → Location precision). The fuzzed coordinates are what we store, and the distance other people see is derived from them. The original precise coordinates are kept on the server only long enough to produce the fuzz and to compute distance for your own view; they are not exposed to any other user's device.
- Timestamps of location updates, used for the “active now” chip and for safety / legal-process response.
Communications
- Direct messages between matched users — text and photos — including their content, timestamps, delivery status, and reactions.
Behavioural signals
- Who viewed your profile, who waved at you or sent you a Flare, the profiles you liked or passed on, your matches, and who blocked whom.
- Conversation metadata (last-read timestamps, message reactions).
- Push notification preferences and delivery state.
Device identifiers
- Browser / device fingerprint via FingerprintJS Pro, used to anchor anonymous accounts and to detect ban evasion and account abuse. Illinois residents: see the BIPA notice in our Terms (§ 25).
- APNs / FCM device tokens used to deliver push notifications.
- IP address and user-agent string captured at signup, sign in, password reset, waitlist signup, report filing, and other sensitive events.
Moderation and safety
- Reports you file or that are filed about you, including category, free-text description, and resolution.
- Enforcement actions taken (warnings, suspensions, bans), recorded in an internal
moderation_actionsaudit table. - Photo-moderation signals from Amazon Rekognition (labels, confidence scores).
- Support chat transcripts. When you open a chat with Nico, our AI support assistant, we store the text of that conversation — your messages and Nico’s replies — so we can act on it and keep a record of what was promised. Retained for up to 24 months. See our AI Use Policy.
- CSAM hash-matching state from Microsoft PhotoDNA and Thorn Safer (a binary “hit / no hit”, plus the matched hash where a hit occurs). On a hit we report under 18 U.S.C. § 2258A.
Subscriptions and purchases
- Tier (free or Pro), tier expiry, tier source (in-app purchase via Apple or Google, Founding Member grant, admin promo).
- App Store / Google Play transaction identifiers and receipts. We never receive or store your payment-card details — Apple and Google handle that.
- Consumable-credit balances (Boosts, Flares).
Waitlist
- Email address, signup timestamp, signup index (your number in the queue), IP address and user-agent at signup, and whether your email qualifies for the Founding Member benefit.
3. How we use it
- Operating the Service — authenticating you, showing you people nearby to match with, delivering messages, sending push notifications you've opted into.
- Safety and moderation — running CSAM hash matching, photo moderation, report triage, ban-evasion detection, and account preservation for law enforcement.
- Subscription management — unlocking Pro features, honouring cancellations and refunds from Apple or Google, applying server-managed grants.
- Customer support when you contact us, including appeals.
- Communications from us about the Service (account verification, security alerts, safety announcements, material changes to these policies, Founding Member welcome emails). Promotional emails are opt-in, opt-out at any time, and never required to use the Service.
- Advertising on the free tier only — see § 5 and § 13 of the Terms. We do not let ad partners retarget based on what you do inside the Service.
- Improving the Service — aggregated, de-identified analytics. We do not sell personal information.
- Legal compliance — responding to subpoenas, court orders, NCMEC and law enforcement requests, and protecting our rights and the rights of others.
4. Legal bases — for residents of the EU, EEA, UK, and Switzerland
We rely on the following legal bases under the GDPR / UK GDPR:
- Contract (Art. 6(1)(b)) — to provide the Service you signed up for.
- Legal obligation (Art. 6(1)(c)) — for NCMEC reporting, tax records, and response to lawful process.
- Legitimate interests (Art. 6(1)(f)) — for security, fraud prevention, abuse detection, and product analytics. We balance these interests against your rights; you may object at any time.
- Consent (Art. 6(1)(a) and 9(2)(a)) — for processing of special-category personal data (health status, sexual orientation, biometric identifiers where applicable), for opt-in marketing, and for cookies that require consent under applicable e-privacy law. You can withdraw consent at any time.
5. Who we share with
We share personal information only with the parties below, in the categories of data needed for the purposes listed. Each service provider is bound by a written data-processing agreement; none are licensed to use your data for their own purposes.
Infrastructure
- Amazon Web Services (AWS) — S3 (photo storage), RDS Aurora PostgreSQL (relational data), ElastiCache Redis (sessions, tokens, rate limits), CloudFront (signed-URL delivery), ECS Fargate (the API), Lambda (background jobs), SQS / EventBridge (job queues), CloudWatch (logs / metrics), Secrets Manager (credentials).
- Bunny.net — CDN edge cache for photo delivery.
- Cloudflare — DNS, web application firewall, bot management (Turnstile), Worker edge logic.
- Vercel — web hosting for the Site and BotID for signup bot detection.
Safety and moderation
- Amazon Rekognition — on-upload public-photo moderation (no facial-recognition features used).
- Amazon Bedrock + Amazon Nova — report-triage assistance.
- Amazon Bedrock (Claude) — powers Nico, the AI support assistant in the Help Hub. Receives the text of your support conversation and nothing else: no profile, no messages with other users, no location, no purchase history. Inputs and outputs are not used to train the underlying model.
- Microsoft PhotoDNA + Thorn Safer — CSAM hash matching on every uploaded image.
- NCMEC — receives reports of suspected CSAM, as required by 18 U.S.C. § 2258A.
- FingerprintJS Pro — browser-fingerprint computation for anonymous account anchoring and ban-evasion detection. The fingerprint is a non-reversible identifier; the underlying signals are not shared with third parties.
Payments and communications
- Apple App Store and Google Play — process all paid subscriptions and consumable in-app purchases. They see your transaction; we never see your card. They are governed by their own privacy policies.
- RevenueCat — subscription entitlement management. Receives a subset of subscription metadata (purchase event, plan, renewal status, store identifier) — no payment details, no chat content, no location.
- Resend — sends transactional email (verification, password reset, waitlist welcome, safety notices) on our behalf.
- Apple Push Notification Service (APNs) and Firebase Cloud Messaging (FCM) — deliver push notifications to your device using the device token you provide.
- LiveKit (self-hosted). The media server that relays video calls. We run it ourselves on our own AWS infrastructure instead of using a calling vendor, so call audio and video never go to a third party, and calls are not recorded.
Diagnostics and analytics
- Sentry — receives application error traces. We configure Sentry to scrub request bodies, message content, and PII before transmission; stack traces and breadcrumbs may include sanitised metadata (timestamps, route names, error types).
Advertising (free tier only)
- Advertising networks. We use a curated list of mainstream, brand-safe networks and name each one here as we onboard it. They receive only the minimum needed to display an ad (placement enum, app version, coarse country, a non-persistent request ID). They do not receive your email, messages, profile details, precise location, or any unique-to-you identifier.
Legal disclosures
We may disclose personal information in response to a valid subpoena, court order, search warrant, or other legal process, or where we believe disclosure is necessary to protect users, our infrastructure, or the public from imminent harm. See our Law Enforcement Guidelines for the procedural details.
Sale / sharing of personal information
We do not “sell” or “share” personal information for cross-context behavioural advertising as those terms are defined under the CCPA / CPRA. We do not work with data brokers or analytics resellers.
6. Sensitive data
The Service is for adults, and people often choose to share sensitive information about themselves — health information, sexual orientation, gender identity, and so on. We treat that information as special-category personal data under the GDPR and as “sensitive personal information” under the CCPA / CPRA.
- We never include sensitive data in ad-targeting signals.
- We do not sell sensitive data and do not allow third parties to use it for their own purposes.
- We do not use sensitive data to train any general-purpose machine-learning model. Targeted safety models (e.g., a scam-text classifier) may use moderation reports as labels, and those reports may incidentally include sensitive data; we treat the resulting models as confidential and do not release them.
- When you place sensitive information on your profile, other users who can see your profile will see the information. We protect what we hold, but we cannot prevent another user from screenshotting or redistributing what you have chosen to publish. Disclose only what you are comfortable other users seeing.
7. Location
Location is the most sensitive piece of data on the Service. We treat it with extra care:
- Your precise GPS coordinates are fuzzed by a random offset on receipt. Default fuzz is ~150 metres; you can widen it in Settings → Location precision.
- Other people see only a derived distance label (e.g., “420 ft”, “0.6 mi”). Precise coordinates are never transmitted to another user's device.
- We retain a brief history of fuzzed coordinates and update timestamps for the “active now” display and for safety / legal-process response. We do not sell your location history; we do not share it with advertisers.
9. Photo moderation
- Every photo you upload is hashed against Microsoft PhotoDNA and Thorn Safer databases before persistence. A match triggers immediate account termination, account preservation for law enforcement, and an NCMEC report.
- Every uploaded photo is additionally scanned by Amazon Rekognition for content that violates our display rules (no nudity, no sexual acts, nothing that would be flagged on a mainstream social platform). Content above our moderation threshold is rejected on upload before it reaches another user.
10. Photo moderation and display rules
Nudity and sexually explicit content are not allowed anywhere on the Service. This applies to your profile photos, photos shared in messages, and every other surface on which you can upload an image. The display rule is enforced through three layers:
- Pre-persist CSAM hash matching against Microsoft PhotoDNA and Thorn Safer. Matches trigger immediate ban, account preservation for law enforcement, and an NCMEC report under 18 U.S.C. § 2258A.
- Amazon Rekognition on every upload. Content above our threshold for nudity, sexual content, or other violations is rejected before it persists to S3 or reaches any other user.
- Human review on report. Photos that pass automated moderation but violate the display rule can be reported by any user; reports route into our moderation queue (see § 13).
10a. Automated decisions and AI
Automated systems help us review photos, detect scams, rank who you see, and answer support questions. Our AI Use Policy sets out exactly where they run, what they may decide, and what they may never decide alone.
Two commitments govern all of it:
- No automated permanent ban. A system may recommend one and may apply a temporary suspension with an audit trail, but only a human moderator can end an account permanently.
- Human review on request. If an automated decision affected you, you can ask a person to look at it, give your side, and contest the outcome — GDPR Article 22 rights, honoured for everyone rather than only where the law compels it. Write to appeals@ojaladating.com.
Nico is AI, not a person, is labelled as such wherever it appears, and sees only a summary of the account it is talking to — never your messages, your location, or anyone else’s account. See our AI Policy for exactly what it can read and the one thing it can change.
11. Cookies and similar technologies
The Service uses a small set of cookies and storage technologies, all of them strictly necessary or security-related:
ojala_accessandojala_refresh— HttpOnly, Secure, SameSite=Lax authentication cookies. Strictly necessary.age_gate_passed— HttpOnly cookie recording your self-attested 18+ entry on the public Site. Strictly necessary for compliance.cf_bmand similar Cloudflare cookies — bot management. Strictly necessary security.- FingerprintJS Pro local-storage entries — anchor the anonymous-account identifier. See § 2 and the BIPA notice in the Terms.
We do not use third-party advertising cookies on the website.
12. Retention
- Account and profile data — retained for as long as the account is active. When you delete your account, you have a 48-hour reversible window during which you can cancel via the magic link we email. After the window, a moderator approves the deletion; once approved, your account row is anonymised, your profile is removed from the active product, and your S3 photo originals are hard-deleted within 90 days. Messages you sent to other users remain in those users' threads with your name replaced by “Deleted user.”
- Messages — retained for as long as both parties keep their accounts.
- Reports and moderation actions — retained as long as needed for safety, legal compliance, and the audit trail (typically 7 years).
- Support chat transcripts — retained for up to 24 months, then deleted. Ask us to delete yours sooner at privacy@ojaladating.com.
- Forensic logs (IP, user agent, login timestamps) — retained for 90 days in active storage. A separate, encrypted compliance archive of pre-deletion data is retained for six years for forensic and legal-process response (subject to extension only by valid legal hold), after which it is destroyed.
- CSAM and law-enforcement preservation — preserved separately from the normal retention schedule as required by 18 U.S.C. § 2258A and applicable law.
- Waitlist signups — retained until you create an account using the same email (at which point they become part of your account data) or until we close the waitlist program (at which point we delete the standalone waitlist row, retaining only an aggregated count for our records).
13. Your rights
For everyone
- Access and export your data from Get my data.
- Delete your account from Settings. One tap, 30-day reversible window, then permanent destruction.
- Correct profile fields at any time from the profile editor.
- Object to specific processing, withdraw consent, or restrict use by emailing privacy@ojaladating.com.
- Appeal a moderation action by emailing safety@ojaladating.com.
Residents of the EU, EEA, UK, and Switzerland (GDPR / UK GDPR)
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), portability (Art. 20), objection (Art. 21), and the right to withdraw consent for any consent-based processing. You have the right to lodge a complaint with your local supervisory authority. Our EU representative can be reached at privacy@ojaladating.com (we will appoint a named EU representative as required and publish the contact here).
California residents (CCPA / CPRA)
You have the right to:
- Know what personal information we collect, use, and disclose.
- Delete personal information.
- Correct inaccurate personal information.
- Limit the use of sensitive personal information (see § 6).
- Opt out of “sale” or “sharing” for cross-context behavioural advertising. We do not sell or share for that purpose, so there is nothing to opt out of — but you can confirm this at any time.
- Non-discrimination for exercising any of these rights.
To exercise these rights, email privacy@ojaladating.com. We will verify your identity by reference to information already on your account.
Other US states with comprehensive privacy laws (VA, CO, CT, UT, TX, OR, MT, IA, IN, TN, DE)
You have rights of access, deletion, correction, portability, and (where the law provides) opt-out of targeted advertising, sale, and profiling that produces legal or similarly significant effects. Email privacy@ojaladating.com to exercise any of them. We respond within 45 days (extendable once by 45 days for complex requests).
Washington residents — see § 19 (Consumer Health Data)
Washington's My Health My Data Act treats health information, sexual orientation, gender-identity information, and certain precise-location signals as “consumer health data.” § 19 below sets out the additional rights and disclosures required by that Act.
14. Children
The Service is for adults aged 18 or older. We do not knowingly collect personal information from anyone under 18. If you believe a minor is using the Service or that we have collected information about a minor, email safety@ojaladating.com immediately. We will review, ban any underage account, preserve the account for law enforcement, and report under 18 U.S.C. § 2258A where applicable.
15. Security
We protect personal information using TLS in transit, encrypted storage at rest (AWS-managed keys), argon2id password hashing, short-lived JWT access tokens in HttpOnly cookies, Redis-backed refresh tokens with a force-signout primitive (session_token_version), IP-allowlisted admin access via Cloudflare WAF, role-based access controls, and audit logs for every privileged action.
No system is perfectly secure. If you suspect a security incident affecting your account, email safety@ojaladating.com immediately.
16. International transfers
We are based in the United States. Personal information you provide will be transferred to and processed in the United States and any other jurisdictions where our service providers operate.
For transfers from the European Economic Area, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, as applicable. Copies are available on request at privacy@ojaladating.com.
17. Changes
We may update this Policy. Material changes will be announced in-app and on the Site at least 14 days before they take effect, except where a shorter window is necessary to comply with the law or to protect users from imminent harm.
18. Contact
Privacy questions, requests, complaints, and notices: privacy@ojaladating.com.
Polari Group c/o Privacy 6300 Riverside Plaza Ln NW Ste 118 PMB 418129 Albuquerque, New Mexico 87120-2617 United States
19. Consumer Health Data Privacy Policy (Washington MHMD)
This § 19 is required by Washington's My Health My Data Act (RCW 19.373) and applies to Washington residents and to anyone whose consumer health data we process within Washington.
What “consumer health data” means
For purposes of this section, “consumer health data” means personal information linked or reasonably linkable to you that identifies your past, present, or future physical or mental health status. On the Service this includes, where present: any health information you choose to share on your profile or in a message; sexual orientation; gender-identity information; and any precise location that indicates an attempt to obtain reproductive or sexual-health services.
Categories collected and the purposes
- Health information you place on your profile — collected to display on your profile to the other users you choose to share it with.
- Sexual-orientation and gender-identity fields — collected to work out who you are shown and who is shown you, and to display on your profile.
- Precise location — collected only at the precision needed to fuzz it before storage and to compute distance. We do not use precise location to infer attempts to obtain reproductive- or sexual-health services, and we do not retain precise location for that purpose.
Sources
Directly from you (profile fields, location updates you push to the Service).
Categories shared
We do not sell consumer health data. We share consumer health data only as follows:
- With service providers strictly to operate the Service (the providers listed in § 5), bound by data-processing agreements that prohibit them from using your data for any other purpose.
- With other users — when you choose to publish a profile field, the users who view your profile see the field. That is the purpose of the field; the disclosure is to people you chose to share with.
- With law enforcement under valid legal process or under 18 U.S.C. § 2258A for CSAM.
Consent
By creating your profile and choosing to fill in a sensitive field (health information, gender identity), you are giving us your opt-in consent under RCW 19.373.030 to collect that data for the purposes above. We do not share consumer health data with third parties for purposes beyond providing the Service without your separate, explicit consent. You can withdraw consent at any time by removing the field from your profile or deleting your account.
Your rights under Washington MHMD
- Confirm whether we are collecting, sharing, or selling your consumer health data.
- Access your consumer health data, including a list of all third parties with whom we have shared it.
- Withdraw consent to our collection and sharing of your consumer health data, prospectively.
- Have your consumer health data deleted, including from our archives, with notification to our service providers and affiliates (subject to applicable legal-hold and 18 U.S.C. § 2258A obligations).
To exercise any of these rights, email privacy@ojaladating.com with the subject line “MHMD request.”
Appeals
If we deny a request, we will tell you why and how to appeal (within 45 days). If your appeal is also denied, you may contact the Washington Attorney General's Office: 1125 Washington Street SE, P.O. Box 40100, Olympia, WA 98504; (360) 753-6200; atg.wa.gov/file-complaint.
20. Notice of Financial Incentives (CCPA)
The Founding Member benefit (Ojalá Pro free for one year for the first 150 publicly-marketed and up to 500 operationally-permitted waitlist signups) is a financial incentive offered in exchange for collecting and retaining your email address on the waitlist. The reasonable estimated value of the benefit to you is the standard retail price of one year of Ojalá Pro (see App Store and Google Play listings for current pricing). Our estimated cost in providing the benefit is approximately equivalent; we do not profit from waitlist signups.
You may opt out of this incentive at any time before you create an account using the waitlist email — simply do not create the account, or contact privacy@ojaladating.com to delete your waitlist row. Opting out forfeits the benefit but is not otherwise penalised — you can still create a Free tier account on the same email at any time.
