AI Disclosures — JWith
Last updated: 2026-07-02
Effective from: 2026-05-28
About this document
This document explains how JWith uses artificial intelligence (AI) in the service: which systems we use, what decisions they make about you, what your rights are, and how we comply with the EU AI Act (Regulation (EU) 2024/1689), the GDPR Article 22 (automated decisions), and equivalent obligations under the LGPD (Brazil) and CCPA/CPRA (California).
This is a companion to the Privacy Policy. Where this document refers to legal bases, data categories, or sub-processors, the authoritative description lives there.
JWith is a small, independent operator. We do not train AI models ourselves. We integrate AI services provided by external companies and run a small ranking algorithm of our own. We list everything below.
1. The AI systems JWith uses
1.1 Description and nickname moderation — Anthropic Claude (Haiku)
- Purpose: review the free text you submit — your description (bio) and any custom nickname you type — and decide whether it violates our Community Guidelines (external contacts, advertising, sexual content, hostility, hookup language; for nicknames: profanity, reserved words, impersonation).
- What goes in: the text you wrote. No photo. No account identifier sent to Anthropic.
- What comes out: a structured verdict — accepted, or rejected with a standardized reason code.
- Effect: if rejected, the content is not published, and you see the standardized reason. You may edit and resubmit. Repeated rejections do not, by themselves, suspend your account.
- Model: Anthropic's Claude Haiku family. Anthropic publishes model cards at anthropic.com/news.
- Sub-processor location: United States. Anthropic does not train on inputs received via its API (per Anthropic's commercial terms).
1.2 Photo validation — Sightengine
- Purpose: review every photo you upload (private and any new private replacement) and decide whether it depicts a real adult, a single subject, and is not itself AI-generated.
- What goes in: the photo file. No name, no email, no account identifier sent to Sightengine.
- What comes out: a structured verdict — accepted, or rejected with one of a small number of reason codes (multiple people, minor detected, AI-generated, low quality, etc.).
- Effect: if rejected, the photo is not stored and is not published. You see the standardized reason. You may upload a different photo.
- Sub-processor location: France (EU). No data leaves the EEA for this step.
1.3 Public photo generation — Flux (via fal.ai)
- Purpose: generate the AI public photo that other users see, starting from your real private photo. The model uses image-to-image diffusion to apply a modification level you control during onboarding.
- What goes in: your private photo + a configuration that controls how much the output may differ from the source.
- What comes out: a synthetic image, derived from your private one. The image is AI-generated by design — that is the privacy feature, not a defect.
- Effect: the generated image is your public photo. The private original is never shown to other users; private-share grants reveal it only after you explicitly accept the grant.
- Model: Flux family by Black Forest Labs, hosted by fal.ai.
- Sub-processor location: United States. Standard Contractual Clauses apply for transfers originating in the EU/EEA. See Privacy Policy §5.
1.4 Feed ordering — in-house algorithm
- Purpose: when you open the meet/feed tab, decide the order in which other profiles are presented to you.
- What it uses: (1) geographic proximity (based on the city you set as approximate location), (2) recency of activity on the platform, (3) how many times you've already seen each profile (older repeats are penalized so the feed rotates).
- What it does not use: any "attractiveness" score, any opaque desirability ranking, any third-party data broker signal, any inference about your faith intensity, sexuality, or income.
- What comes out: an ordered list of profiles.
- Effect: ordering only. Nobody is hidden from you that wouldn't otherwise be matched on your declared preferences (gender, age range, location compatibility). You can scroll the full feed.
- Provider: JWith. The algorithm runs in our backend functions (Hetzner Cloud).
1.5 Writing and flow aids — Anthropic Claude (Haiku)
Three small generative aids use the same provider. All are assistive — you always see and control the result before it takes effect:
- Bio sample ("Suggest sample" in the description editor): generates an example bio you can adapt. What goes in: your selected interests and your app language. You are free to edit or discard the sample, and whatever you submit still passes moderation (1.1).
- Verification question: generates the open-ended question you answer on camera during identity verification (see Privacy Policy §2.5). What goes in: your app language only. You can regenerate the question before recording.
- Public location options: after you save your private city, generates the broader public labels you can choose from for your public profile (e.g. metro area, region). What goes in: the city, region, and country you saved — no other profile data.
2. AI Act risk classification
The EU AI Act classifies AI systems into four tiers: prohibited, high-risk, limited-risk, and minimal-risk. JWith's systems fall as follows:
| System | AI Act tier | Why |
|---|
| 1.1 Description and nickname moderation | Limited-risk | Content-moderation system acting on user-submitted text. Subject to transparency under Article 50 (users informed they interact with AI). |
| 1.2 Photo validation | Limited-risk | Biometric categorisation in the narrow sense of "adult / not-adult", "single person / multiple people", "real / synthetic". Not biometric identification — we do not match faces to known individuals. We do not deploy facial recognition for surveillance. |
| 1.3 Public photo generation | Limited-risk + Article 50(2) disclosure | Generates synthetic image content. Article 50(2) requires that AI-generated or manipulated image content be marked as such in a machine-readable way and disclosed to the viewer. JWith complies via the on-photo "AI" badge (see §4) and this document. |
| 1.4 Feed ordering | Minimal-risk | Ordering of public profiles by proximity and recency. No profiling of sensitive traits, no decision affecting access to a service, contract, or right. |
| 1.5 Writing and flow aids | Minimal-risk | Text suggestions with the user in the loop — a bio sample you edit, a verification question you answer, location labels you pick. No synthetic media, no autonomous decision. |
No JWith system is high-risk under Annex III. We do not deploy AI for:
- biometric identification of natural persons,
- credit scoring, employment decisions, education admission, or essential public services,
- emotion recognition in the workplace or education,
- predictive policing, border control, or migration management,
- assessing eligibility for public benefits, insurance, or housing.
No JWith system is prohibited under Article 5. We do not deploy subliminal techniques, exploit vulnerabilities of minors or persons with disabilities, score social behavior, or scrape facial images from the internet or CCTV.
3. Your rights regarding automated decisions
3.1 Right to human review (GDPR Art. 22, LGPD Art. 20, AI Act Art. 86)
When an automated decision (description rejected, photo rejected) significantly affects you, you may request that a person at JWith review the decision.
To request review, email privacy@jwith.app with:
- the rejected content (or a description of it),
- the standardized reason we returned,
- why you believe the rejection was wrong.
We respond within the timeframe required by applicable law. If the human reviewer agrees with you, we accept the content and apologize for the friction. If the reviewer confirms the rejection, we explain the specific point of conflict so you can adjust.
3.2 Right to information about the logic
You may request a description of the logic used by any of the systems above, beyond the summary in §1. We provide what we can without disclosing sub-processor trade secrets — that means: the categories of input, the categories of output, the role of the decision in our flow, and the recourse available to you.
3.3 Right to opt out of certain processing
- Description moderation and photo validation are required — they protect minors and the broader community. You cannot opt out and continue to use the service.
- Public photo generation is required as well, because public profiles must not expose unmodified private photos. There is no "use my private photo as public" path by design.
- Feed ordering can be partially controlled by your declared filters (gender, age range, location radius). There is no way to receive an unordered feed.
If these constraints are unacceptable to you, you may delete your account at Settings → Delete account.
3.4 Right to contest profiling
The feed ordering algorithm does not produce a legal or similarly significant effect within the meaning of GDPR Art. 22(1) — it orders public profiles, it does not deny you access to anyone. If you disagree with this assessment, you may write to privacy@jwith.app and we will provide our reasoning in writing.
4. Transparency markings (AI Act Art. 50)
4.1 In-app
- The AI-generated public photo carries a visible "AI" badge in the upper-left corner of the photo on every profile screen. The badge disappears only when the viewer is looking at the original private photo (visible to the owner and to people who hold an accepted private-share grant).
- Feed thumbnails are not individually badged. Every photo in the feed is an AI public photo by design — there is no non-AI photo a feed image could be confused with — and the badge appears as soon as the profile is opened.
- Description moderation displays a notice during onboarding stating that submissions are reviewed by an AI moderator before publication.
4.2 Machine-readable provenance
The AI Act Article 50(2) requires synthetic content to be detectable by automated means. Public photos generated by JWith embed standard image metadata indicating AI generation. We will adopt the C2PA Content Credentials standard for public photos when fal.ai's Flux endpoint supports it natively or when our generation pipeline can sign credentials directly. Status of this work is tracked in our internal roadmap; until then, the visible badge plus this document are the operative disclosures.
4.3 Deepfake controls
Public photos are derived only from a real photo you uploaded, validated by Sightengine to depict a real adult. You cannot upload a public photo prepared elsewhere. You cannot upload a photo of someone other than yourself (it would fail private-photo validation and verification). This eliminates the deepfake-of-a-third-party scenario at the input layer.
5. Training, retention, and data flows
5.1 AI training on your data
- JWith does not train AI models. We do not collect a training set from your data.
- Anthropic does not train on inputs received via its commercial API. JWith uses the commercial API.
- Sightengine does not retain validated photos beyond the validation call.
- fal.ai does not train on user-submitted images by default; JWith uses the default.
- We do not consent to any sub-processor using your content for model improvement on our behalf.
5.2 Retention of AI artifacts
- Rejected content: deleted at the moment of rejection. No stored training signal.
- Generated public photo: stored as long as your account exists (per Privacy Policy §6).
- Photo validation verdicts: kept as a small audit record (decision, reason code, timestamp) for the lifetime of the account, so that contested decisions can be reviewed.
- Description and nickname moderation verdicts: same.
5.3 Cross-border transfers
Most AI systems are operated by US-based sub-processors (Anthropic, fal.ai). For EU/EEA-origin data, transfers are governed by Standard Contractual Clauses and the supplementary measures described in Privacy Policy §5. Sightengine is in France — no cross-border transfer for that step.
6. Risk management and incident response
We monitor our AI integrations for the following classes of failure:
- False positives in moderation (good content rejected): tracked via support tickets, manually reviewed weekly, escalated to Anthropic or Sightengine when patterns appear.
- False negatives in moderation (bad content accepted): tracked via user reports. Confirmed misses tighten our prompt or rule set.
- Public photo failures (generated image broken, distorted, or unsuitable): the user is informed and can regenerate within the daily quota; persistent failures escalate to fal.ai.
- Bias: we monitor rejection rates by language and locale. If a community sees a disproportionate rejection rate, we investigate the cause.
- Sub-processor incidents: we notify affected users and the relevant authorities as required by applicable law (e.g. GDPR Art. 33/34 and equivalents).
We do not maintain a formal AI risk management system in the sense of AI Act Article 9, because none of our systems are high-risk. We will add one if our classification changes.
7. Sub-processor list
The authoritative sub-processor list is in Privacy Policy §4.2. The AI-relevant entries:
| Sub-processor | Role | Location |
|---|
| Anthropic | Text moderation + writing/flow aids (Claude Haiku) | United States |
| Sightengine | Photo validation | France (EU) |
| fal.ai | Public photo generation (Flux model) | United States |
Changes to this list follow the notification procedure in Privacy Policy §12.
8. Children
JWith is for adults. The minimum age is 18, with stricter local thresholds where applicable. See Child Safety Standards. Our AI photo validation is one of the layers we use to keep minors off the platform — Sightengine rejects photos where the subject appears to be a minor, and accounts repeatedly submitting such photos are escalated to manual review. AI is not used to assess emotion, intent, or vulnerability of any user, minor or adult.
9. EU AI Act timeline relevant to JWith
The AI Act entered into force on 2 August 2024 and applies in phases:
- 2 February 2025: prohibitions (Article 5) and AI-literacy duties (Article 4) — applicable. JWith complies (no prohibited systems; operators of the service are AI-literate within the meaning of Art. 4).
- 2 August 2025: governance + GPAI rules — primarily affects model providers (Anthropic, Black Forest Labs), not JWith as deployer.
- 2 August 2026: transparency obligations under Article 50 become applicable to deployers — this is the date that binds JWith's public-photo disclosure and the AI badge. We are compliant ahead of the deadline.
- 2 August 2027: full applicability of remaining provisions — no impact on JWith's current systems unless we deploy something newly classified as high-risk.
10. Changes to this document
This document is reviewed and updated alongside the Privacy Policy. Material changes (a new AI sub-processor, a new AI system, a change of classification) follow the same notification procedure as the Privacy Policy — in-app + email notice in advance before the change takes effect.
11. Contact
For any AI-related question or to exercise the rights described above (including human review under GDPR Article 22 and AI Act Article 86), write to privacy@jwith.app.
We respond within the timeframe required by applicable law.