Privacy Policy
In force from 11 September 2026 · Version 2026-09-11
1. Who we are
DUDA is a matchmaking app that suggests compatible people and helps you decide who to meet.
- Controller: Duda Matchmaker LLC
- Registered address: Leo Kiacheli Street N15, Apartment N3, Mtatsminda District, Tbilisi, Georgia
- Company number: 404811502 (Georgian Public Registry)
- Privacy contact: privacy@dudamatchmaker.com
- Privacy representative (Art. 27 GDPR and Art. 27 UK GDPR): Prighter Group (see below)
Representative
We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:
- European Union (EU)
- United Kingdom (UK)
Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/15543778637
powered by
Prighter
We have not appointed a Data Protection Officer. Our founder currently handles privacy matters. For any question about your data, use the privacy contact above.
DUDA is for adults. You must be 18 or over to use it, and we ask you to confirm this when you sign up.
2. The short version
- We collect what you tell us about yourself, what you answer in the questionnaire, and how you use the app.
- Some of it is sensitive under data-protection law, and we ask for your explicit consent before using it. This covers your sexual orientation and sex life, health signals from fitness apps you connect, political or religious views in your questionnaire answers, your ethnicity if you add it, and a face scan if you verify your identity. See section 4.
- We do not sell your data.
- Matching is automated. It suggests; it does not decide for you.
- Two things are decided automatically: identity verification, and hiding an account that several people have reported, pending a person reviewing it within 72 hours. You can ask a person to review either.
- You can download a copy of your data, and delete your account at any time, from Settings.
3. What we collect and why
Your account
We collect:
- your email address;
- your password, stored hashed, so we never see it;
- or, instead of a password, a Sign in with Apple, Google or Facebook identifier;
- a phone number, if you give us one (we verify it separately);
- for security, the IP address and device details of security-relevant events;
- a coded fingerprint of the network you sign in from, so we can warn you about unfamiliar sign-ins.
Why: to create and secure your account and to detect fraud. Basis: our contract with you; our legitimate interest in preventing fraud and account takeover.
Your profile
Name, display name, date of birth, gender, who you are looking for, city and region, bio, occupation, education and employer if you add them, languages, height, interests, photos, your nationality and home or travel cities if you add them, your dealbreakers, and your favourite places and activities. Why: to build the profile others see and to find compatible matches. Basis: our contract with you.
Your questionnaire answers
Your answers and the personality profile we derive from them. Why: this is the core of how matching works. Basis: our contract with you, plus explicit consent for questions touching sensitive topics (see section 4).
How you use the app
Who you connect with, save, block or report; your messages; compatibility checks; invites you send or claim; and anything you type into the optional profile chat. Why: to run the features and keep people safe. Basis: our contract with you; our legitimate interest in safety.
Notifications
If you allow notifications, we store your device’s push token and send notifications through Apple (iOS) or Google (Android). Message notifications show the sender’s name and the start of the message. Turn this off in Settings or in your phone’s settings. Basis: our contract with you.
Location, when you use Nearby or the map
When you use Nearby or the map, we store your device’s position rounded to about 110 metres, and the venue or neighbourhood you are at. Other people never see the stored position; they see a blurred one. A Nearby session ends after at most two hours.
If you post a plan with your photo switched on, people who can see your plan see your photo, your first name, the activity, a rough time and the neighbourhood, but never the venue. This lasts until you switch the photo off.
Basis: providing the Nearby feature you switched on (our contract with you). Showing your photo on a plan relies on your consent, which you can withdraw for each plan.
Connected apps
If you connect Spotify, Strava, Pinterest, Google Calendar or Instagram, we receive the signals you authorise. Examples are music genres, activity types, board titles, or the rhythm of your calendar. We use them to adjust your lifestyle compatibility; they never exclude anyone. If you connect YouTube, we receive the channels you subscribe to and the videos you have liked; we do not turn them into interests or use them in matching. Basis: your consent, and explicit consent where an app reveals health data.
YouTube and Google Calendar
DUDA uses YouTube API Services. If you connect YouTube, you also agree to the YouTube Terms of Service. Google’s own use of your data is covered by the Google Privacy Policy.
- What we read. From YouTube, with read-only access: the channels you subscribe to (their names and descriptions) and the videos you have liked (their titles and the channel that published each one). We cannot see your watch history or search history, and we never post, like, subscribe or change anything. From Google Calendar, with read-only access: when your events happen and how many people each one invites. We do not keep event titles, descriptions, locations or guest names.
- What we do with it. From YouTube, we store the authorised channel names, descriptions and liked-video titles. We do not turn them into interests, and we do not use them in matching. We do not show them to other users. From Google Calendar, we turn the timing and invite counts into a summary of the rhythm of your week, and use that only to adjust your lifestyle compatibility with other people. We do not show it to other users.
- What we keep. The names, titles and descriptions above, the Google Calendar weekly-rhythm summary, and the access tokens Google issues us, which we encrypt. We refresh YouTube data every day, and delete it if we have not been able to refresh it for 30 days. Otherwise we keep it until you disconnect the app or delete your account.
- Who else gets it. Only Amazon Web Services, which stores it for us. It is not sent to OpenAI or to any other provider in section 6. We do not sell it, use it for advertising, or give it to advertisers or data brokers, and we do not use it to train AI or machine-learning models. Nobody at DUDA reads it unless you ask us to, or unless we need to for security or to comply with the law.
- Stopping it. Disconnect the app in Settings → Connected apps and we delete the tokens and the data straight away. Disconnecting YouTube or Google Calendar also removes DUDA’s access in your Google account. Because both use the same Google permission, that disconnects both. If you remove DUDA’s access in your Google account instead, we delete the data the next time we try to refresh it, within a day. To remove DUDA’s access from your Google account as well, use Google’s security settings at myaccount.google.com/permissions. If you delete your DUDA account, we also ask Google to revoke our access.
DUDA’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Contacts, if you use contact discovery
The app turns each phone number into a hash (a scrambled code) before sending it. We protect those codes with a secret key held on our servers, and compare them only against people who chose to be findable. We never store your contact list.
Hashes of phone numbers can in principle be reversed by guessing, which is why the key and the comparison stay on our servers.
Basis: your consent, for your own use of the feature. For your contacts’ numbers, which we use only for that comparison, our legitimate interest.
Identity verification, if you choose to verify
Verification is optional. It is needed to send or accept a Move in Nearby. The scan runs in our own Amazon Web Services account in Ireland: a short live video confirms that a real person is present, and a still frame is compared with your main profile photo.
We keep only the result, never the images or any biometric template. We tell you the result in a notification, and the notification never says why a check did not pass. Basis: your explicit consent, given before the scan starts.
What you have to give us. To create an account you need an email address, a password and your name, and you must confirm you are 18 or over. Without these there is no account.
To be shown to other people you also need a display name, your date of birth, your gender, who you are interested in, an age range, your location (a city, or your device’s position), a handle, and at least one photo. Without these your profile is not complete and is not shown.
Everything else in your profile is optional. Verification is optional too, except for sending or accepting Moves in Nearby. None of this is required by law; it is what the service needs to work.
Information we get from others
- From Apple, Google or Facebook: your name and email, if you sign in with them.
- From apps you connect: see above.
- From Firebase: confirmation that you control your phone number.
- From other users: reports about you, invites that name you, and their contact lists, if your verified number is in them.
If you join our waitlist
On this website you can join our waitlist. We collect your email address or phone number, your city and your age. If you choose to add them, we also collect your gender identity and who you are looking for, with your explicit consent for those two.
We use this to tell you when DUDA launches near you. We keep the contact details for 18 months, then delete them. Basis: your consent.
Support, security and operations
Support tickets, bug reports you choose to send (with your email and device details), audit logs of security-relevant actions, system logs, and backups. Basis: our contract with you; our legitimate interest in security, investigating problems and keeping the service running.
4. Sensitive data
Some information is special-category data under Article 9 GDPR and gets stricter treatment:
| What | Where it comes from |
|---|---|
| Sexual orientation | who you say you are looking for, and your relationship-structure preference |
| Sex life | some questionnaire answers, and the optional profile chat |
| Health information | fitness and health apps you connect (Strava) |
| Political opinions, religious or philosophical beliefs | some questionnaire answers |
| Racial or ethnic origin | your own ethnicity if you add it (shown only to you), and the ethnicities you want to see |
| Biometric data | the face scan, if you verify your identity |
We ask for your explicit consent before we use these, separately from signing up. There are two exceptions. Reports that mention sensitive matters are processed to keep people safe. And anything you choose to write in a bio, a message or a support ticket is processed as you wrote it. For identity verification, consent must exist before the scan; our systems refuse to start a verification without it.
If you set an ethnicity preference, people whose stated ethnicity is outside it are not shown to you. Your own stated ethnicity is used the same way when other people set a preference.
You can withdraw any of these consents at any time in Settings → Privacy & data. Withdrawal stops future use and removes that data from matching; it does not undo processing that already lawfully happened. Withdrawing consent about who you are looking for means we can no longer match you with anyone.
5. Automated decisions
Matching: automated, but it does not decide for you
We rank and suggest people automatically. You choose who to connect with. The system surfaces candidates; it does not accept, reject or match on your behalf.
How it works:
- Your answers and profile are scored for compatibility across the questionnaire’s areas and for overall similarity.
- The results are then adjusted so the same few people are not shown to everyone.
- People outside your age range, distance, gender preferences or dealbreakers are never shown to you. The same applies to your ethnicity preference, if you set one.
- A language model (OpenAI) writes the short explanation of why you might match.
- The result decides who appears in your suggestions, and in what order.
Identity verification: a solely automated decision you can contest
If you verify your identity, the outcome is decided entirely automatically, with no human involved. A refusal means you cannot send or accept Moves in Nearby.
You have the right to a human review. If the check refuses you, you can ask a person to look at it again from within the app; a member of our team can review the decision and verify you manually. You can also tell us why you think the decision was wrong. This right does not depend on anything else about your account.
Safety suspensions
If three different people report your account within seven days, it is hidden from other people automatically, before any person has looked at the reports. You can still use the app (read, not send) while a person reviews the reports, within 72 hours. You can ask for that review through Support and tell us your side.
6. Who we share it with
We do not sell your data. We share it only with the providers below, for the purposes listed:
| Who | What for |
|---|---|
| Amazon Web Services | hosting, databases, file storage, and the identity check itself, which runs inside our own AWS account |
| Cloudflare | serving and protecting our sites, including the identity-check page |
| OpenAI (US) | turning your profile and answers into a compatibility representation; writing match explanations and conversation starters from both people’s profiles; running the optional profile chat, including what you type in it |
| Resend | account emails (verification, password reset, export links) |
| Google (Firebase) and Apple | push notifications; phone verification; sign-in if you use it |
| Google Firebase Crashlytics | crash reports from the app, linked to your account ID |
| Meta | Facebook sign-in, if you use it |
| Mapbox | maps and place search. The app sends your approximate position and what you search for |
| KLIPY | GIF search and display. Your device contacts KLIPY directly, so KLIPY sees its IP address |
| Apps you connect | exchanging the data you authorise |
| Notion | bug reports you choose to send, including your email and device details |
| Telegram | alerting our support staff that a ticket exists. The alert carries a short subject line and category, never your message |
| Prighter | our representative, if you contact us through them |
Other users see only what your profile and privacy settings expose. We also share information where the law requires it, or where it is necessary to investigate abuse or protect someone’s safety.
7. Where your data goes
Our servers are in the European Union: Frankfurt, and Ireland for the identity check. Some providers are outside the EU/EEA, including OpenAI, Mapbox, KLIPY, Google and Meta. Where that happens we rely on the safeguards the law allows, such as Standard Contractual Clauses (and the UK’s equivalent) or an adequacy decision. We are completing a per-provider list; ask us and we will tell you which safeguard applies to any provider.
DUDA itself is established in Georgia, outside the EU/EEA, and your data is stored on servers in the European Union. Because we are outside the EU but offer this service to people inside it, the GDPR applies to us directly, and we have appointed a representative in the EU and the UK (see section 1).
Whether our own staff accessing data from Georgia also counts as a “transfer” that needs a separate safeguard is a question we are still settling. We will say so here plainly once it is answered. We would rather tell you what is unresolved than imply a certainty we do not have.
8. How long we keep it
| What | How long |
|---|---|
| Your account and profile | while your account exists |
| Messages | while your account exists, except threads with someone you unmatched or blocked, which are archived immediately and deleted after 365 days |
| Match suggestions | 30 days |
| Match records | 180 days for finished ones; ongoing connections kept while they last |
| Security audit logs | 7 years |
| Routine audit logs, notifications | 90 days |
| Networks you sign in from | 180 days after you last used them |
| Data from YouTube and Google Calendar | until you disconnect the app or delete your account; disconnecting deletes it immediately; YouTube data we cannot refresh for 30 days is deleted |
| A deleted account | deleted immediately; anything left is purged within a day. Encrypted backups and system logs roll over within 30 days |
| Data-export files | deleted 7 days after we create them; the download link itself lasts 24 hours |
| Nearby history | 90 days |
| Onboarding and profile-chat transcripts | 12 months after you last used them |
| Finished invites | 30 days after they end |
| Reports about abuse | kept for safety investigations |
| Waitlist sign-ups | 18 months, then the contact details are deleted |
9. Your rights
- See your data. Download a copy of the data we hold about you from Settings; the link is valid for 24 hours. We leave out security codes, other people’s reports about you (to protect them), and some internal values.
- Take it elsewhere. The download is a machine-readable file.
- Correct it. Edit your profile and answers directly in the app.
- Delete it. Delete your account from Settings. This is immediate and irreversible. Reports other people made about you are kept (see section 8).
- Withdraw consent. Withdraw sensitive-data consents in Settings → Privacy & data. Notifications, contacts and location are controlled in your phone’s settings and in the app.
- Ask us to restrict processing. Contact us.
- Ask for a human to review an automated decision. See section 5.
- Complain to a supervisory authority. In the EU, complain to the data protection authority where you live or work. In the UK, complain to the Information Commissioner’s Office (ico.org.uk). You can also contact us through our representative (section 1).
We answer requests within one month.
Your right to object. Where we rely on our legitimate interests (section 3), you can object at any time on grounds relating to your situation. We will stop unless we have compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims. Email privacy@dudamatchmaker.com with “Objection” in the subject.
Being suspended does not take these rights away. If we suspend your account for breaking our rules, you can still export your data, delete your account, withdraw consent, contact support, and contest an automated verification decision.
10. Security
Our safeguards are:
- encryption in transit and at rest;
- passwords stored hashed;
- access to production data limited;
- security-relevant actions logged;
- re-authentication before dangerous account changes;
- secrets held in a managed secret store.
No system is perfectly secure, and we do not claim otherwise.
11. Children
DUDA is for adults only (18 or over). We do not knowingly collect data from anyone under 18. If you believe a minor is using DUDA, contact us and we will remove the account.
12. Changes
If we change this policy materially, we will tell you at least 30 days before the change takes effect, in the app and by email to the address on your account. Corrections, and changes required by law, may take effect sooner; we will still tell you. We keep every published version of this policy at this address, with its date. When you sign up we record which version you were shown.