Last updated: 2026-07-17
Effective from: 2026-05-28
This Privacy Policy explains what personal data JWith collects from you, how we use it, who we share it with, how long we keep it, and what your rights are. It is written to be readable and to reflect what actually happens in our infrastructure — without unnecessary legalese.
It applies to your use of the JWith mobile app (iOS and Android), the website jwith.app, and all related services, regardless of where you are located.
Voluntarily provided by you during onboarding or profile editing:
Visible only to people you explicitly authorized via the "private profile share" flow:
Private photo: your real photo, uploaded during onboarding. Used as the reference for generating your public photo and as proof of existence (automated validation described in section 9). Stored in a private bucket, encrypted at rest, accessible only via short-lived signed URLs.
Public photo (AI): an image automatically generated from your private photo by an image diffusion model (Flux), with features altered to preserve your privacy. This is the image other users see in the feed. You control the level of modification in the photo editor.
Shared private photo: if you accept a private-photo-share request from another user, that user can see your original (unmodified) photo during the chat. Blocking the user suspends that access for as long as the block lasts (unblocking restores it); deleting your account removes it permanently.
To earn the "verified" badge, you record a short video (15–30 seconds) answering a randomly generated question shown on screen. The video:
This is the only biometric data collected by JWith. Verification is optional — you can use the app without the badge.
What we collect. Your private photo (section 2.4) and your verification video (above) contain your face as ordinary images — that is the only face data JWith collects. We do not perform facial recognition, and we do not extract, generate, or store face geometry, facial landmarks, faceprints, or any other biometric template — from the photo, the video, or anything else.
How we use it and who receives it. Face data is used only to operate the features you invoke, never for advertising, profiling, or training our own models:
fal.ai and Sightengine process the image transiently, on our instruction, under Data Processing Agreements, and may not use it for any other purpose. Any third party that receives face data is contractually bound to provide the same or equal protection of that data as described in this policy.
How long we keep it. The verification video is deleted automatically as soon as its review finishes (approved or rejected). The private photo is kept for as long as your account exists, stored in a private bucket, encrypted at rest, accessible only via short-lived signed URLs (section 2.4). No other face data exists to retain (no templates — see above). Full retention table: section 6.
How to delete it and revoke consent. You can replace your private photo at any time in the app (the previous one is deleted). Verification is optional — you can simply not record a video, and an unreviewed attempt can be cancelled in the app. Because the private photo is required to operate a profile, fully revoking consent to face-data processing means deleting your account: Settings → Delete account removes your photo, any pending verification video, and every derived record (permanent erasure within 30 days — section 6). You can also write to privacy@jwith.app (section 8).
When the app encounters an unexpected error, we send a technical report to an observability service (Sentry):
IP addresses are not sent.
To notify you of important events (new invitation, photo verified, etc.), we store your device's push token (provided by Apple Push Notification Service or Google Firebase Cloud Messaging, via Expo Push Service).
The table below maps each data category to its purpose and the legal basis under which we process it. The terms used map to the equivalent bases under GDPR, LGPD, CCPA, and other data-protection laws.
| Data category | Purpose | Legal basis |
|---|---|---|
| Email, password, device | Create and secure your account | Performance of contract |
| Public profile | Display your profile to other users | Performance of contract + Consent |
| Gender identity, exact age, selected location (neighborhood-level) | Match you with compatible people | Performance of contract + Consent |
| Religious data (pioneer status, congregational role) | Optional display on your private profile | Explicit consent |
| Private photo | Generate public AI photo + verify identity | Consent + Performance of contract |
| Verification video | Earn the "verified" badge | Explicit consent + Legitimate interest (community safety) |
| Messages, invitations | Operate the chat | Performance of contract |
| Usage history (views, quotas) | Order the feed, prevent abuse | Legitimate interest |
| Diagnostics | Identify and fix bugs | Legitimate interest |
| Rewarded ads | Earn additional credits | Consent |
| Phone number | Verify a reachable, real person; anti-fraud | Consent + Legitimate interest (community safety) |
| Device-integrity attestation | Block automated abuse / scraping | Legitimate interest |
You can withdraw any consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. Where we rely on legitimate interest, you can object — see section 8.
As described in section 2, certain data is visible to other app users:
We engage the following companies to process data on our behalf. Each has access to only what is needed to perform its function:
| Sub-processor | Location | Purpose |
|---|---|---|
| Hetzner Cloud | Germany (EU) | Database hosting, authentication, photo storage, backend functions |
| Cloudflare | United States / global | DNS, CDN, website hosting (Pages), API edge (Workers), email routing |
| Anthropic | United States | Automated content moderation (description text, interests, language, location text) |
| Sightengine | France (EU) | Automated photo validation: detects AI-generated photos, presence of minors, multiple people |
| fal.ai | United States | Public photo generation (image diffusion model) |
| Google AdMob | United States | Rewarded ads + transaction verification |
| Resend | United States | Transactional email delivery (auth: OTP, email confirmation, password recovery) |
| Twilio | United States | Phone verification — sending and checking the one-time SMS code (Twilio Verify) |
| Sentry | United States | Error diagnostics (stack traces, breadcrumbs, device info) |
| Apple (APNs; App Attest / DeviceCheck) | United States | Push notification delivery; app/device integrity & anti-fraud attestation |
| Google (FCM; Play Integrity API) | United States | Push notification delivery; app/device integrity & anti-fraud attestation |
| Expo (EAS) | United States | Push notification routing (relays to APNs / FCM) |
We maintain Data Processing Agreements with each sub-processor, binding them to standards equivalent to or stricter than GDPR/LGPD.
We may share data when legally required by a court order or valid request from a public authority. Whenever possible, we will notify you in advance — except when prohibited by law.
If JWith is sold, merged, or has assets transferred, your data may be transferred to the successor entity. You would be notified in advance to exercise your rights (including deleting your account before the transfer).
Several sub-processors store data outside your country of residence. We rely on the following safeguards for cross-border transfers:
The current list of safeguards per sub-processor is available upon request at privacy@jwith.app.
| Category | Retention period |
|---|---|
| Verification video | Deleted immediately after review (approved or rejected) |
| Private photo | As long as your account exists |
| Public AI photo | As long as your account exists |
| Chat messages | Until both accounts in the thread are deleted (messages you sent stay visible to the recipient after you delete your account) |
| Invitations | As long as your account exists |
| Usage history (profiles viewed) | Up to 60 days without interaction, then automatically deleted |
| Sentry diagnostics | 30 days |
| Soft-deleted account | 30 days retention to allow reactivation |
| Hard-deleted account | Removed within 30 days of request — except data we are legally required to retain (e.g. minimal records for legal defense) |
| Technical logs (auth, security) | 6 months |
| Phone number | As long as your account exists |
| Device-integrity attestation | While your account exists (only the latest check is kept) |
Despite all protections, no system is 100% secure. If you suspect your account has been compromised, change your password immediately and notify us at privacy@jwith.app.
You have the following rights regardless of where you are located. The specific legal basis differs by jurisdiction (GDPR Art. 15–22, LGPD Art. 18, CCPA/CPRA, and equivalents elsewhere), but the substance is equivalent.
JWith uses AI to automate certain decisions:
You have the right to request human review of any automated decision. To do so, email privacy@jwith.app with a description of the decision and your reasoning. We respond within the timeframe required by applicable law.
JWith's baseline minimum age is 18 years. Where the age of legal majority or the legal age to use online dating services in your jurisdiction is higher, that higher age applies. We do not allow use by anyone below the applicable legal age.
The complete description of how we prevent minors from accessing the service, how we detect suspected child-safety issues, and how to report concerns is in our Child Safety Standards.
If you are under 18 and created a JWith account, ask a parent or legal guardian to email privacy@jwith.app so the account can be deleted immediately.
The mobile app does not use cookies. We use:
The website jwith.app sets no cookies. When you pick a language or a light/dark theme, the choice is stored in your browser's localStorage — user-requested preferences, never used for tracking. We do not use third-party tracking cookies.
This policy may be updated. When there is a material change — a new sub-processor, a new category of data collected, a change of legal basis — we will notify you via in-app notification and via email (if you provided one), in advance before the change takes effect.
The current version is always available at jwith.app/legal/privacy and in Settings → Privacy Policy in the app.
For any question, request, or concern about your personal data — including the rights described in section 8 — write to privacy@jwith.app. This is the primary channel for all data-protection matters, regardless of where you are located.
We respond within the timeframe required by applicable law.
If you believe your rights have been violated, you may file a complaint with your local data-protection authority — your national DPA in the EU/EEA, the ICO (UK), the ANPD (Brazil), the California Attorney General, or the equivalent agency in your jurisdiction.