Privacy Policy
The short version. We collect the profile you write, who you like, and what you send. We never ask for a photo. We do not sell your data and we do not run ads. Your face - if you verify - is never stored or published; only a non-reversible signature is. You can export or delete everything from Settings, at any time.
1. Who we are
The data controller is Tim Veles, Haus 26, Technologie- und Gewerbepark Eberswalde, Alfred-Nobel-Straße 1, 16225 Eberswalde, Germany. Contact: [email protected].
No Data Protection Officer has been appointed, as Art. 37 GDPR does not require one at this size. Data-protection questions go to the address above.
If Without. is ever taken over by a company, the controller changes. You will be told before that happens, not after.
2. What we collect
| Category | What it is | Why |
|---|---|---|
| Account | Email address; optional phone number or Telegram handle if you choose those notifications | To create your account, sign you in and reach you |
| Profile | First name, age, city, your card line, your story, prompts, interests, and optional details you choose (gender, orientation, height, lifestyle, etc.) | To show you to other people and to match you |
| Voice | Your optional voice intro and voice notes (max 30 seconds) | To let people hear you if you want them to |
| Activity | Likes, passes, matches, messages, reports and blocks | To run the service and keep it safe |
| Verification | A non-reversible mathematical signature derived from a liveness check | To confirm you are a real person and detect duplicates and fraud |
| Location | The city you type in, and its approximate coordinates | To show people near you. We do not track your live GPS location. |
| Technical | Device type, browser, IP address, crash and security logs | To keep the service working and to detect abuse |
What we never collect
- Photos of you - the product does not have a photo upload. Photos exist only if a future feature adds them, and only with your explicit, mutual consent.
- Your face. Verification video is processed for liveness and deleted immediately. We keep only an irreversible signature that cannot be turned back into an image.
- Your contacts. If you use "Block contacts", the entries stay on your device. We only ever receive a one-way hash for matching, never your address book.
- Continuous location. No background GPS, ever.
3. Legal bases (GDPR Art. 6)
- Contract - to provide the service you signed up for: your profile, matching, messaging.
- Consent - special-category data you volunteer (sexual orientation, religion, health-adjacent lifestyle answers) under Art. 9(2)(a); voice recordings; verification. You may withdraw consent at any time by removing the data or deleting your account.
- Legitimate interests - safety, fraud and spam prevention, moderation, service security and improvement.
- Legal obligation - responding to lawful requests and keeping records we must keep.
Some profile fields are special-category data. They are always optional, always marked, and we ask for them only because a dating service is useless without them. You can leave every one blank.
4. Who sees what
- Other members see your profile as you wrote it, and your match score with them. They do not see your email, phone, exact location, or who else you liked.
- A guest, if a member asks a friend for advice about you - but only a reduced version of your profile, and only if you allow it. See §5 below. You can switch this off in Settings.
- Nobody sees a photo unless you both actively choose to reveal.
- Calls. Voice only - never video. A call can only ring once you and your match have both switched calls on for that conversation, and it connects only if the other person picks up. The audio always runs through a relay operated by Cloudflare, so neither of you learns the other's IP address. Calls are not recorded. To set a call up, your devices exchange connection details through our database for a few seconds; they are deleted after ten minutes. Legal basis: Art. 6(1)(a) - your consent, which you withdraw by switching calls off.
- Events. If you join an event, other members going to the same event may be shown to you, and you to them, in the Events view. If you create an event, every member can see its title, city, date and description - but not who created it. You can cancel it at any time; past events disappear by themselves.
- Processors who work strictly on our instructions: website hosting and the test-phase login (Cloudflare), hosting and database (Supabase), identity verification (only if you verify), text moderation, email delivery, and payment processing (Apple, Google or Stripe). All are bound by data processing agreements.
- The test-phase login. During the closed test the app itself sits behind a login run by Cloudflare Access. You enter your email address, Cloudflare emails you a one-time code, and only addresses we have invited receive one. To do this Cloudflare processes your email address, your IP address and the time of each login, and sets a cookie that keeps you signed in. The homepage, the waiting list and these legal pages are not behind the login. Legal basis: Art. 6(1)(b), because the login is how you take part in the test you joined.
- Nobody else. We do not sell, rent or share your data with advertisers or data brokers. There is no ad network in this product.
4a. Every outside service, and what it gets
This is the complete list. Nothing else is contacted by the website or the app: no analytics, no advertising, no content delivery network, no translation service. The program code we use from others (the Supabase library, and MediaPipe for the on-device liveness check) is served from without.photos itself, so no one else learns that you use Without.
| Service | What for | What it receives |
|---|---|---|
| Cloudflare, Inc. (USA; EU-US Data Privacy Framework) | Delivers the website; shows prices in the currency of your country; the test-phase login; the bot check on the forms (Turnstile); the relay that carries the audio of a call | IP address, browser type, the pages requested (from the IP address Cloudflare derives only the country, to pick the currency - it is not stored); your e-mail address for the login; the encrypted audio of a call, which it passes on but cannot store or read |
| Cloudflare DNS (cloudflare-dns.com) | Checks, when you type an e-mail address, that its domain can receive mail | Only the part after the @ (for example "gmail.com") and your IP address - never the address itself |
| Supabase, Inc. (servers in Frankfurt, EU) | Database, sign-in, stored voice notes, server functions | Everything you store with us, as described in section 2 |
| Resend (USA; standard contractual clauses) | Sends our e-mails: confirmations, the launch message | Your e-mail address and the text of that e-mail |
| Komoot GmbH, Potsdam, Germany (Photon) | Suggests places while you type your city | What you type into the city field, and your IP address |
| ALL-INKL.COM, Germany | Our mailbox, when you write to us | Your message and address |
5. "Ask a friend" - sharing and guests
A member can share your profile with a friend to ask their advice before writing to you. We'd rather explain this plainly than bury it.
Why it exists at all
People already do this. They screenshot a profile and send it to a friend captioned "thoughts??". That happens on every dating app, with no consent, no limit, no expiry and no way for you to opt out. We can't stop screenshots. We can offer a governed version alongside them - one you control.
What a guest can see
A reduced profile: your first name, age, city, your goal, your story, your prompts, interests, languages, what you're looking for, relationship and family answers, work, education, height, and whether you're verified.
A guest never receives:
- Your sexual orientation, religion, politics or ethnicity.
- Your intimacy answers.
- Your drinking, smoking, cannabis, drug or body/weight answers.
- Your voice intro. Your voice is not the sharer's to forward.
- Your coordinates, your email, or anything else.
This isn't hidden at the last moment by the app - those fields are not sent by the database at all, so no bug in the interface can reveal them. A friend doesn't need to know your cannabis use to say "yes, message her".
Your controls
- Switch it off. Settings → "Allow my profile to be shared". Off means no share of you can be created or opened - including links already sent.
- It expires. Every share link dies after 7 days, and the sharer can revoke it sooner.
- Blocks win. Blocking someone kills any share they made of you, instantly.
- You can see it happened. Settings shows how many times you were shared in the last 30 days. You won't see who asked or what the friend said - that conversation belongs to them, and telling you would make it a very different, much worse feature.
- Limits. Ten shares per member per day. This is a way to ask a friend, not a way to scrape a city.
What a guest account is
A guest signs in with an email and sees only the profiles explicitly shared with them. A guest cannot browse, search, swipe, message members, or be discovered. They can reply to the person who asked them, with a verdict and a comment. If a guest later wants to date, they make a normal account - the guest account is not a preview of the app.
Legal basis: consent under GDPR Art. 6(1)(a), which is why the switch exists and why turning it off retroactively closes live links. Special-category data is excluded from the share entirely, so no Art. 9 consent is sought or relied on for it.
5b. Printing your own profile
You can print your own profile on one sheet, for example to hand to someone at an event. The sheet is made by your browser on your device; nothing is sent to us to make it. There are two versions. "To pass on" carries your words and the basics and a QR code. "Complete" carries everything you filled in and no QR code - it is meant for you, not for handing out.
The QR code opens a print link: anyone holding the paper can read the same reduced view of your profile a friend would see through "Ask a friend" - never your orientation, faith, politics, ethnicity, intimacy or lifestyle answers, your location or your voice. The link works for 90 days, you can switch it off at any time in Settings, and it stops working at once if you hide your profile or delete your account. You can only ever print your own profile. Legal basis: Art. 6(1)(a) - you choose to print it.
5a. The waiting list, and asking for an invite (before you have an account)
Two things on this site collect data from people who are not members, and they are the only two. You can ask for an invite code at request-invite.html if you want in now, or join the waiting list on the home page if you only want to hear when it opens. Both write to the same list and are described together here.
| What | Why | Legal basis |
|---|---|---|
| Your email address | To answer you: a code if a place opens up, or a plain no. On the waiting list, to tell you when it opens. | Art. 6(1)(b) - steps taken at your request before any contract |
| Your optional note | Only what you choose to write. Please do not put anything sensitive in it. | Art. 6(1)(b), same purpose |
| IP address and browser | Abuse prevention on a form that is open to the whole internet, checked by Cloudflare Turnstile (see §10) | Art. 6(1)(f) - our legitimate interest in not having the list filled by bots |
| Follow-up questions by email | Only if you tick that box. Lets us ask a question or two to judge whether you fit the current test group. | Art. 6(1)(a) - your consent, separate and optional |
| One message when we open | Only if you tick that box. A single email saying it is live, and then nothing further. | Art. 6(1)(a) - your consent, separate and optional |
| Our newsletter | Only if you tick that box. Occasional email about how the project is going. You can leave at any time from a link in every message. | Art. 6(1)(a) - your consent, separate and optional |
Every box is separate, and none of them is a condition. You can join the list and tick nothing: we then answer your request, or send you the one launch message if that is what you asked for, and that is all. Ticking one box never implies another. Nothing is pre-ticked.
We confirm your address before sending you anything (double opt-in). If you ask for the launch message or the newsletter, we send one email asking you to confirm it was really you. Until you click that link, we send you nothing else and the consent does not count. This protects you from being signed up by somebody typing your address into our form.
What we store as the record of your consent: the time you ticked, the time you confirmed, the IP address both times, and the exact sentence you agreed to in the language you actually read it in. We keep our own copy of that wording on the server, so the record cannot be quietly rewritten later - not by us and not by anyone filling in the form.
Leaving. Every newsletter carries a one-click unsubscribe link that works without logging in or replying to anything. You can also withdraw any consent by writing to [email protected]. It takes effect immediately and does not make anything we did beforehand unlawful.
What we still do not do with it. No profiling, no advertising, no passing it to anyone else, no selling it, and no automated decision about whether you get in - a person reads every request. We do not use the waiting list to work out anything about you beyond that you are interested. Joining is not signing up: it creates no account and grants no access.
How long. An invite request is kept until it is settled and then deleted: within 30 days of sending you a code, and within 30 days of a decline. Requests we never get to are deleted after 12 months at the latest. A waiting-list entry is deleted once we have sent the launch message, unless you also asked for the newsletter - then we keep the address until you unsubscribe. An address that never confirms is deleted after 30 days. If we cannot offer you a place we tell you and delete your address; we do not keep it quietly against a future round.
6. International transfers
Where a processor operates outside the EEA/UK, transfers are covered by Standard Contractual Clauses or an adequacy decision. We store data in the EU where we reasonably can.
7. How long we keep it
- Your account and profile: until you delete it.
- After deletion: removed or irreversibly anonymised within 30 days, except where we must keep something longer.
- Messages: deleted with your account; the other person's copy of a conversation may persist for their record.
- Safety records (blocks, reports, bans): retained up to 3 years so banned users cannot simply return.
- Verification signature: retained while your account exists, to prevent duplicate and fraudulent accounts.
- Billing records: as tax law requires, typically 7-10 years.
- Decisions about your profile and your objections (Digital Services Act): kept with the safety records, up to 3 years. You see every decision about you, with the reason, under Settings, and can object once within six months; a person reads every objection.
- Voice messages in a chat: 90 days, then the recording is deleted and the chat shows "voice message, expired". Only the two of you can play them, and only once you have both switched voice notes on.
- Print links (section 5b): 90 days after you create one, or when you switch it off; removed with your account.
- Invite requests (section 5a): 30 days after a code or a decline; 12 months at the latest if never settled.
- Beta test data: during the closed test, everything you have in Without. is deleted 90 days after you register unless you ask us to keep it - see the Beta Test Agreement, which takes precedence over this section for as long as the test runs.
8. Your rights
You can access, correct, export, restrict, object to processing, and delete your data. Two of these are one tap:
- Export: Settings → Privacy & safety → Download my data.
- Delete: Settings → Delete account. This is permanent.
For anything else, write to [email protected]; we respond within 30 days. You may also complain to your local data protection authority. California residents have equivalent rights under the CCPA/CPRA, including the right to know and to delete; we do not sell or share personal information as those terms are defined.
9. Security
- Encryption in transit (TLS) and at rest.
- Row-level security: the database itself refuses to return another member's private data, rather than relying on the app to behave.
- Free two-factor authentication (authenticator app or emailed code).
- Links are blocked in chat; messages are automatically moderated for abuse.
- Least-privilege staff access, audited. We will notify you and the regulator of a qualifying breach within 72 hours.
10. Cookies and local storage
This website sets no cookies and does not track you. There are no analytics and no advertising. The one script that comes from elsewhere is Cloudflare's bot check (Turnstile), and only on the three forms: the waiting list, the invite request and the join page.
| What | Where and why | Consent? |
|---|---|---|
| Login cookie | Only in the app, and only once you log in: the Cloudflare Access cookie (CF_Authorization) keeps you signed in during the closed test. | Not required - strictly necessary for the login you asked for |
| App data on your device | Only in the app: your settings and draft profile, stored in your own browser so the app works. | Not required - strictly necessary |
| Language choice | Only if you pick a language on the invite or join page: that choice is remembered in your browser. It is never sent to us. | Not required - you asked for it |
| Cookie note closed | When you close the cookie note, your browser remembers that, so it does not show again. It is never sent to us. The fingerprint button in the corner of every page opens the note again and can erase this and the language choice. | Not required - you asked for it |
| Bot check on the forms | Only on the waiting list, the invite request and the join page: Cloudflare Turnstile checks that a person, not a script, is sending the form. It reads technical signals from your browser (such as IP address and browser type) for that one check, sets no cookie on this site, and does not follow you to other pages. | Not required - strictly necessary to keep an open form from being flooded; Art. 6(1)(f) |
| Security check, only if needed | Cloudflare, which delivers this site, may ask a connection it considers suspicious to pass a check. Only then does it set a security cookie (cf_clearance) so it does not ask again. Our bot-fighting settings that would set cookies for every visitor are switched off. | Not required - strictly necessary to protect the site; Art. 6(1)(f) |
| Analytics and advertising | None. | - |
11. Sensitive and consumer health data
A dating profile is unavoidably personal. Some of what you may choose to tell us is special category data under GDPR Art. 9, and some of it counts as regulated consumer health data under US state laws such as the Washington My Health My Data Act, the Nevada consumer health law, and comparable rules elsewhere.
In our case that can include:
- Sexual orientation, and who you ask to be shown.
- Health-adjacent lifestyle answers you opt into: drinking, smoking, cannabis, other drugs, and exercise.
- Intimacy preferences - how important intimacy is to you, and how often you'd want it.
- Religion, ethnicity and politics, if you add them.
- Liveness verification signals - a non-reversible signature confirming a live human. Never a face image; the video never leaves your device.
How we treat it:
- Every one of these fields is optional. Leave them blank, or set them to "Prefer not to say", and the app works exactly the same.
- Our legal basis is your explicit consent (GDPR Art. 9(2)(a)), given by choosing to fill the field in. You can withdraw it by clearing the field - that deletes the value, it does not merely hide it.
- We do not sell it, share it for cross-context advertising, or use it for ads. We do not run ads at all.
- We do not use it to infer anything you didn't tell us. Your match score is computed only from what you explicitly selected.
- It goes to other members only as part of your profile - the profile you wrote, shown to people in your discovery settings.
Where state law grants you a specific right to have consumer health data deleted, you can exercise it yourself in Settings → Download my data / Delete account, or by writing to [email protected]. We confirm deletion in writing.
12. Notice at collection
For California residents (CCPA/CPRA) and equivalents, a plain summary of what we take and why:
- Identifiers - email address. To create your account and sign you in. Kept until you delete the account.
- Profile content - everything you write, plus optional voice intros. To show you to other members. Kept until you delete it or the account.
- Sensitive personal information - as listed in §10 above, only where you volunteer it.
- Approximate location - the city you choose. To show you people nearby. We do not track precise GPS.
- Usage data - swipes, matches, messages. To run the service and enforce our rules.
We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we never have. We do not use sensitive personal information for any purpose beyond providing the service you asked for, so no limitation right is triggered - but you may still exercise every right below.
13. Your privacy choices
You do not need to email anyone or fill in a form to exercise these. They are buttons in the app.
- Access / export - Settings → Download my data. A complete file, immediately.
- Delete - Settings → Delete account. Removes your profile, messages, matches and swipes. Not recoverable.
- Correct - edit any field at any time.
- Withdraw consent - clear an optional field, or turn off voice.
- Opt out of sale/sharing - nothing to opt out of. We don't do it.
- Non-discrimination - using any of these changes nothing about your experience or price.
Authorised agents may act for you with written proof. We may need to confirm your identity via your registered email before acting on a request.
14. Children
Without. is strictly 18+. We do not knowingly collect data from anyone under 18. If we learn an account belongs to a minor we delete it immediately. Report a suspected minor to [email protected].
15. Automated decisions
Our match score ranks and explains suggestions. It is not a decision with legal effect, and it never restricts your access to the service. You can see exactly why a score is what it is on every profile, and change it by editing your interests.
16. Changes
If we change this policy materially we will tell you in the app before it takes effect. The date at the top always shows the current version.
17. Contact
Tim Veles, Haus 26, Technologie- und Gewerbepark Eberswalde, Alfred-Nobel-Straße 1, 16225 Eberswalde, Germany
Email: [email protected]