← All policies

Privacy Policy

Last updated: August 30, 2026

Working draft, pending review by counsel. This document is provided for transparency and will be finalized with a qualified attorney before public launch. It is not yet a final agreement.

This policy explains, in plain language, what Pop Interactive LLC (“POPPED”) collects, why, who processes it, what happens when you delete your account, and the controls you have. It was written from a line-by-line audit of the product’s code, so it describes what the service actually does — including the uncomfortable details.

1. The short version

  • We collect what we need to run a safe, 18+, verified dating service — the full inventory is in the table below.
  • We never receive or store your ID image, selfie, or any biometric data. Identity checks run on Stripe’s systems; we get back only a pass/fail and an “18 or older” confirmation.
  • Your messages, photos, bio, and profile are never sent to any AI provider. The only AI we use writes generic icebreaker questions for live rooms — see section 5.
  • Profile photos are served from a public CDN. Anyone with a photo’s exact URL can view it without logging in — see section 3.
  • Messages are encrypted at rest on our servers, but not end-to-end — see section 3.
  • We do not sell your personal information, and there are no analytics trackers or ad pixels in the app today.
  • You can export, correct, hide, or delete your data from Settings at any time.

2. What we collect, why, and who can see it

DataWhat it includesWhy we collect itWho can see it
Account & loginYour email and a login identifier from our sign-in provider (Clerk), plus account status (verified, POPPED+, etc.) and a coarse “last active” timestamp.Signing you in and running your account.You and POPPED. Clerk holds your actual login credentials and sessions.
Date of birthEntered once during onboarding.Confirming you’re 18+ and showing your age.Other members see your age only — never your date of birth.
ProfileDisplay name, photos, bio, prompts, interests, city, and basics (height, work, education, drinking/smoking/exercise), plus your visibility setting.Showing your profile in Discover, search, rooms, and matching.Other signed-in members — unless you hide your profile with “Show me on POPPED”.
Sensitive attributes (optional, consent required)Sexual orientation, religion, politics, family plans, love languages, lifestyle. Saved only after you explicitly consent; each saved answer records the exact consent it was given under.Matching only: compatibility scoring and mutual dealbreaker filters, computed entirely on our servers.Never shown to other members. Matches see per-factor compatibility scores, not your answers. You can read yours back anytime.
Location (optional)A precise location point, saved only if you tap “Use my current location”. Your city is a separate field you type yourself.Computing the distance between you and potential matches.The coordinates are never sent back to anyone — not even to you. Other members see only a rounded distance in km. You can clear it anytime in Settings.
MessagesDirect-message text, read receipts, and reactions.Delivering your conversations.You and your match. Encrypted at rest on our servers — but not end-to-end (section 3).
Likes, matches & viewsLikes, passes, and superlikes; matches with a compatibility breakdown; who viewed your profile; post-room vibe picks.Making matches and showing activity.Matches see each other plus a plain-language match explanation. “Who liked you” and viewer identities are shown only to POPPED+ members; everyone else sees counts with no identifying data.
Pop Room activityAn append-only event log of joins, leaves, balloon states, votes, matches, and ejections. In-room text chat is not saved — it’s relayed live and discarded.Running live rooms, post-room matching, and safety.Room participants see your display name and first photo. Live audio/video travels through LiveKit (section 6).
NotificationsA push subscription per device, per-category preferences, quiet hours, and your timezone (captured automatically when you enable push).Sending only the notifications you asked for, at reasonable hours.You and POPPED. Delivery passes through your browser’s push service (section 6).
Verification outcomeVendor name, session id, pass/fail, an “18 or older” yes/no, and the document type (e.g. driver’s license). Deliberately absent: your selfie, ID image, face data, and the raw date of birth from the document.Age and identity assurance before live rooms.Your verified badge is visible to members. Admins can see the outcome — never the documents, which stay with Stripe.
Reports, blocks & moderationReports you file (category + description), your block list, and moderation actions. If an account is banned, we keep a one-way hash of its identity to prevent ban evasion.Safety and enforcement.Our safety team. People you block or report are not told who acted.
Billing statusA Stripe customer id and your subscription/Boost status.POPPED+ and Boost.Card and payment details stay with Stripe — we never see your full card number.
Security ledgerAn append-only audit log of privileged actions: consent grants, exports, deletion requests, room joins, verification outcomes, and every admin view. Today this log stores no IP addresses or browser details.Accountability — including holding ourselves accountable: every admin view writes its own audit row.Internal only.
Waitlist (marketing site)Email, city, and an optional referral code.Letting you know when POPPED opens up.Stored with our contact-list provider, Loops, when that integration is enabled.

3. Things we want to be extra clear about

Profile photos live on a public CDN

Photos upload directly from your browser to Vercel’s blob storage with public access. The URLs contain a long random suffix, so they can’t be guessed — but they are not access-controlled: anyone who has a photo’s exact URL can view it without logging in. Don’t put anything in a profile photo you wouldn’t want seen outside the app.

Messages are encrypted at rest — but not end-to-end

Each message body is encrypted with its own random key before being stored, which protects it against database-level exposure. But POPPED holds the keys — our servers decrypt messages to deliver your chat history, so this is not end-to-end encryption, and POPPED can technically access message content. Every outgoing message also passes through an in-house, rule-based filter (fixed patterns, not AI, not a third party) that blocks solicitation and warns recipients about likely scams.

Your exact location never leaves our servers

If you share location, the coordinates are stored but never returned by any API — to anyone, including you. Only a rounded distance in km is ever shown.

Rooms are live, not recorded

Pop Rooms are not recorded today, and in-room text chat is not stored. (The pre-join screen includes a recording-consent step for a possible future feature; if we ever add recording, we will update this policy first.)

4. How we use information

  • To operate the service: your profile, Discover, Pop Rooms, matching, and messaging.
  • To keep POPPED safe: age verification, blocks, reports, moderation, rate limiting, and our Community Guidelines.
  • To process POPPED+ payments and provide support.
  • To send the notifications you’ve opted into, respecting your category choices and quiet hours.
  • To comply with legal obligations.

5. Automated processing & third-party AI

Being specific here matters, so here is the complete picture:

  • Identity verification (Stripe Identity) — the only third-party automated analysis of your personal content. During verification you provide your government ID and a live selfie directly to Stripe, in Stripe’s flow, and Stripe’s systems run the automated ID-to-selfie comparison. This happens only after your explicit biometric-verification consent. POPPED receives back a pass/fail and an “18 or older” flag — never the images or any biometric data. See our Identity & Verification Notice.
  • POPPY icebreakers (third-party AI, no personal data). When enabled, we call an AI provider (Groq and/or NVIDIA, running Llama models) to write generic icebreaker questions for a room round. The request contains only the round’s theme label and how many questions to write — no names, no messages, no profile data.
  • Scam & solicitation filter (in-house, rule-based — not AI). Outgoing messages are checked against fixed patterns; solicitation blocks the send, and scam patterns show the recipient a fraud warning.
  • Compatibility scoring (in-house, deterministic — not AI). A weighted formula over factors like shared interests, distance, goals, and (if you consented to share them) values alignment. Both matched people see the per-factor breakdown and a plain-language explanation. Race and ethnicity are not inputs — we don’t even store them.

Bottom line: no member content or personal data — no messages, photos, bios, or profiles — is sent to any AI provider, and no AI system makes moderation or account decisions about you.

6. Who we share information with

We share personal information only with the service providers that run POPPED:

  • Clerk — sign-in and authentication. Holds your email, login credentials or OAuth identities, and sessions; sends its own sign-in emails. Clerk’s privacy policy
  • Stripe — POPPED+ billing and Boost, plus identity/age verification (Stripe Identity). Your card details — and, during verification, your ID photo and selfie — go directly to Stripe and stay there; Stripe sends its own receipts. Stripe’s retention of verification media is governed by Stripe. Stripe’s privacy policy
  • LiveKit Cloud — live audio/video for Pop Rooms. Your device connects directly; your room token carries your user id and display name so participants can identify and report each other. LiveKit’s privacy policy
  • Neon — our production database, holding the data in the table above. Neon’s privacy policy
  • Railway — hosts our API and realtime servers, and keeps standard platform request logs (including IP addresses). Railway’s privacy policy
  • Vercel — hosts the web app and the public photo CDN, and keeps standard request logs. Vercel’s privacy policy
  • Your browser’s push service (Google, Mozilla, or Apple, depending on your browser) — relays web push notifications. Payloads are encrypted to keys held by your device, so the relay can’t read them. The content we compose can include another member’s display name or a room title — never message bodies.
  • Loops (when enabled) — stores waitlist contacts from the marketing site. Loops’ privacy policy
  • Groq / NVIDIA (when enabled) — generate the generic icebreaker questions described in section 5; they receive no personal data. Groq’s privacy policy, NVIDIA’s privacy policy
  • AWS KMS (when enabled) — holds the master key that wraps our message-encryption keys; it never sees message content. AWS’s privacy notice

Just as important is what’s not there: no analytics or tracking SDKs, no advertising pixels, no data brokers, no marketing-email service, and no SMS. POPPED itself sends no email today — Clerk and Stripe send their own transactional emails. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We may disclose information where the law requires it, to enforce our Terms, or to protect the safety of members and the public.

7. Retention and deletion — what really happens

  • Deleting your account (Settings → Delete account) takes effect immediately as a soft delete: your account is marked deleted, your profile disappears from Discover, search, and likes, and you can no longer sign in. Permanent erasure then runs automatically about 30 days later: an hourly automated process hard-erases accounts deleted more than 30 days ago — scrubbing your account and profile records, deleting your photo files from the CDN, and removing your messages, likes, profile views, room RSVPs and invites, and push subscriptions. Erasure is paused while your account is under an active legal hold, and resumes once the hold is lifted.
  • Kept after deletion, by design: ban-evasion hashes (one-way hashes only — no readable personal data) and our append-only ledgers (the audit log, consent history, and room event log), which the database itself forbids editing or deleting. That immutability is how we keep an honest record of consents and privileged actions.
  • Messages don’t expire automatically; they’re kept encrypted until account erasure. Unmatching or blocking closes a conversation but does not delete its messages.
  • Photos: removing a photo from your profile also deletes the underlying file from the CDN, and permanent erasure deletes all of your remaining photo files. If you ever spot a photo file that should be gone, email privacy@poppeddating.com.
  • Data-export requests are themselves logged, with a 45-day due date.

8. Your rights and controls

  • Export your data: Settings → Download my data returns a portable JSON copy (account, profile, sensitive attributes, consent history, verification outcome).
  • Delete your account: Settings — see section 7 for exactly what happens.
  • Correct: edit your profile anytime.
  • Visibility: hide your profile with the “Show me on POPPED” toggle.
  • Location: never turn it on, or clear it anytime in Settings.
  • Sensitive attributes: saved only after your explicit consent, and you can read back everything you’ve consented to.
  • Notifications: per-category toggles, quiet hours in your timezone (enforced on our servers before anything is sent), and per-device push on/off.
  • Blocks and reports: available from every profile, chat, and room.
  • Match explainability: every match shows the per-factor breakdown and a plain-language explanation of why you were matched.

Depending on where you live (e.g., EEA/UK under GDPR, California under CCPA/CPRA), you may have additional rights, including objection, restriction, non-discrimination for exercising rights, and lodging a complaint with a supervisory authority. Contact privacy@poppeddating.com.

9. Security

Data is encrypted in transit; message bodies are additionally envelope-encrypted at rest with per-message keys (section 3). Admin access is role-based, and every admin view of member data writes its own audit row to an append-only log. We rate-limit abusive traffic. No system is perfectly secure, but security and accountability are first-class parts of POPPED’s design.

10. Children

POPPED is strictly for adults 18 and older. We collect your date of birth at onboarding and require identity verification before live rooms. We do not knowingly collect data from anyone under 18, and we delete underage accounts when discovered.

11. Legal bases (EEA/UK)

Where GDPR applies, we rely on: contract (providing the service you signed up for), consent (sensitive attributes, biometric verification, location, notifications), legitimate interests (safety and anti-abuse), and legal obligation. You may withdraw consent at any time in Settings.

12. International transfers

We may process information in countries other than where you live. Where required, we use appropriate safeguards for such transfers.

13. Changes to this policy

When this policy changes, we update the “Last updated” date and ask you to acknowledge material changes in the app.

  • Version 2026-08-30 (this version) — full rewrite based on a code-level audit of the product: added the what-we-collect table, the named processor list, the third-party AI section, plain statements about public photo URLs and server-side message encryption, and an honest description of deletion. Strengthened within this version (no version bump — the change is strictly more protective): 30-day automatic permanent erasure, and CDN photo file deletion on removal and on erasure.
  • June 29, 2026 — first working draft.

14. Contact

Privacy questions, or exercising your rights: privacy@poppeddating.com.

Questions about this policy? legal@poppeddating.com