Last updated: 31 March 2026
This Privacy Policy explains how Cuedo App ("Cuedo", "the App") and the Cuedo website ("Website") process your personal data. The App and Website are operated by Apmenta OÜ ("we", "us", "our"), a company registered in Estonia, acting as the data controller under the EU General Data Protection Regulation (GDPR).
If you have questions, contact: privacy@apmenta.com.
Apmenta OÜ
Tartu mnt 67/1-13b, 10115 Tallinn, Estonia
Email: privacy@apmenta.com
Account credentials: email address, encrypted password hash, phone number (optional)
Authentication tokens, session identifiers, and refresh tokens
Third-party authentication data from Apple/Google sign-in (name, email, provider identifiers)
Login history, IP addresses, and user agent strings
Multi-factor authentication settings and backup codes (when enabled)
Basic profile: display name, gender, bio, birthday (to calculate age)
Physical characteristics: height, photos you upload with metadata and cropping settings
Personal attributes: values, interests, dating intentions, dealbreakers, must-haves
Location data: geographic coordinates (when permission granted), city/area labels, timezone
Cultural preferences: favorite artists, songs, films, and books with associated metadata
Languages spoken and place of residence
Fun facts and photo prompts for conversation starters
Profile completion status and verification level
Interaction signals: how you use limited in-app indicators to express interest and prioritize interactions
Matching activity: mutual matches, signal level/strength, match status
Messaging: message content (up to 2000 characters), attachments, reactions, read receipts
Real-time interactions: typing indicators, presence status, conversation participation
Discovery behavior: profiles viewed, daily options shown, skipped profiles
User metrics: response rates, average response time, app usage duration, open match counts
Engagement patterns: time spent in conversations, feature usage statistics
Device information: model, operating system version, app version
Usage analytics: session duration, feature interactions, error reports
Push notification preferences and delivery status
Push notification tokens: device tokens for delivering push notifications
App settings: appearance theme, measurement units, notification preferences
User reports and feedback submissions with associated details
Block lists and reported users
Safety-related communications and support interactions
Instant match tokens and QR code sharing data
Reported Content: When you report another user, we store:
Information about the reported user (profile ID, display name)
Your reason for reporting and any additional description you provide
A limited portion of your conversation with them (default: 10 messages, adjustable up to 50), when reporting from a match context
Metadata about the report (timestamp, reporter information, match context)
The conversation context helps our moderation team evaluate patterns of harassment, spam, or impersonation rather than relying on isolated incidents.
Access & Retention:
Reported content is accessible only to authorized moderation staff
Used solely for safety, compliance, and community standards enforcement
Stored for up to 90 days after review completion
In exceptional cases requiring extended investigation, retention may be extended with documented justification
Your Rights:
Reported users are not notified of reports against them during investigation
False or malicious reports may result in account restrictions
You can optionally exclude conversation context when submitting a report
Sexual orientation: Inferred from gender and preferences
Precise location: GPS coordinates when location services are enabled
For special category data, we rely on your explicit consent under Art. 9(2)(a) GDPR. In the context of a dating app, you provide this consent when you use the App's matchmaking features and set or change your matching preferences (e.g., "Looking for"). If you choose not to set "Looking for", discovery will be limited to profiles from users who also have not set this preference. For precise location, your explicit consent is provided when you grant location permission at the system level. You can withdraw consent for precise location by disabling location access in your device settings. To withdraw consent for other special category data, you must delete your account.
Camera: Used to scan QR codes for Instant Match and to capture photos for your profile or messages (when enabled).
Photo Library: Used to select photos for your profile or to share in chats (when enabled).
Image Processing & Metadata: We may resize, crop, and compress images and may remove EXIF metadata where possible to protect your privacy. Uploaded images are stored in secure storage and are visible to you and, when shared in chats, to conversation participants.
Visibility: Profile photos you upload are displayed to other users in discovery and to your matches. Photos sent in chats are visible to conversation participants.
Our website and the web version of the App use LocalStorage and SessionStorage (or equivalent browser storage mechanisms) to store certain settings and preferences locally in your browser. This helps make the web experience more user‑friendly and restores your preferences (e.g., language and appearance) when you return.
The native app (iOS/Android) does not use browser storage. Instead, it uses secure device storage:
SecureStore (iOS/Android) to store the encryption key for session data.
Encrypted app storage backed by AsyncStorage (React Native) to store session data and certain sensitive local app data, such as onboarding/profile draft data, push-notification tokens, and temporary signed image cache entries, in encrypted form.
AsyncStorage (React Native) may still be used for lower-sensitivity local app state and preferences, such as appearance or measurement-unit settings.
We do not intentionally persist sensitive profile, discovery, or message-preview caches locally for convenience caching.
This data is stored locally on your device or in your browser. It is not transmitted to our servers for other purposes; authentication sessions are only used to sign you in.
To protect our website and in particular our forms from abuse (e.g., automated requests, spam, fraud attempts), we use security mechanisms provided by Cloudflare. Depending on the risk assessment performed by the security services, Cloudflare may set strictly necessary cookies (e.g., as part of bot management, rate limiting, challenge/protection mechanisms, and Turnstile verification used on website forms and certain public authentication flows such as sign in, sign up, OTP requests, and password reset). These cookies are not used for marketing or tracking purposes; they are used solely to ensure security and stability of the website and related public authentication entry points.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in IT security and abuse prevention).
Storage period: Depending on the cookie, typically session-based or short-term.
Right to object: These cookies are required for secure operation. You can delete or block cookies in your browser; however, this may restrict functionality (e.g., forms).
Purpose: Account creation, profile management, discovery, interaction signals, matching, and messaging Legal Basis: Art. 6(1)(b) GDPR (performance of contract) Data Involved: Identity, profile, behavioral interaction data
Purpose: Safety measures, abuse prevention, troubleshooting, fraud detection, and legal compliance Legal Basis: Art. 6(1)(f) GDPR (legitimate interests) and Art. 6(1)(c) GDPR (legal obligations) Data Involved: User reports, moderation data, technical logs, behavioral patterns Legitimate Interest: Protecting user safety and maintaining platform integrity
Purpose: Preventing use of compromised passwords through HaveIBeenPwned integration Legal Basis: Art. 6(1)(f) GDPR (legitimate interests) Data Involved: Password hash prefixes (k-anonymity protocol) Legitimate Interest: Protecting user accounts from security breaches
Purpose: Important service notices, terms changes, safety alerts Legal Basis: Art. 6(1)(c) GDPR (legal obligations) and Art. 6(1)(f) GDPR (legitimate interests) Data Involved: Contact information, communication preferences
Purpose: App performance optimization, user experience enhancement, feature development Legal Basis: Art. 6(1)(f) GDPR (legitimate interests) Data Involved: Usage metrics, technical data, aggregated behavioral patterns Legitimate Interest: Improving service quality and user experience
Purpose: Sexual orientation inferences for matching, precise location for distance features Legal Basis: Art. 9(2)(a) GDPR (explicit consent) Data Involved: Gender preferences, location coordinates Consent Management: You can withdraw consent for precise location by disabling location access in your device settings. Changing "Looking for" preferences does not withdraw consent. To withdraw consent for other special category data, you must delete your account - this may impact the options you will see in discovery.
We collect personal data from the following sources:
Direct from you: Information you provide when creating your profile, using app features, communicating with us, submitting website forms, or setting website preferences (e.g., theme, language)
Your device: Technical information, usage patterns, and device interactions
Other users: Messages, reactions, and interactions you have with other users
Third-party authentication providers: Apple and Google when using social sign-in
Location services: GPS coordinates when location access is granted
External APIs: Cultural content metadata from services like Wikidata
We work with trusted service providers who act as data processors under GDPR-compliant agreements:
Supabase Inc.: Database hosting, authentication, file storage, and real-time services
Data processed: All user data categories
Location: Central EU (Frankfurt, Germany; eu-central-1)
Purpose: Core app infrastructure and functionality
Apple Inc.: Apple Sign-In authentication services
Data processed: Apple ID, email, name (when provided)
Purpose: Simplified account creation and authentication
Google LLC: Google Sign-In authentication services
Data processed: Google account ID, email, profile information
Purpose: Simplified account creation and authentication
HaveIBeenPwned (via Supabase): Password security validation
Data processed: SHA-1 password hash prefixes (first 5 characters only)
Purpose: Preventing use of compromised passwords
Privacy protection: k-Anonymity protocol ensures no plaintext passwords are transmitted
Cloudflare, Inc.: Website security and abuse prevention
Data processed: IP addresses, request metadata, security cookies (strictly necessary for bot management, rate limiting, challenge mechanisms, and Turnstile verification on website forms and certain public authentication flows)
Location: Global (with EU data processing options)
Purpose: Protecting website, forms, and certain public authentication entry points from abuse, automated requests, spam, and fraud attempts
Privacy policy: https://www.cloudflare.com/privacypolicy/
Wikidata/Wikimedia: Cultural content metadata for music, films, books, and artists
Data processed: Content identifiers and metadata
Purpose: Enriching user cultural preferences
GIPHY, Inc.: GIF search and content delivery for chat features
Data processed: GIF search queries you enter; selected GIF CDN URLs stored in message attachments
Location: United States
Purpose: Enabling GIF search and sending in conversations
Privacy policy: https://support.giphy.com/hc/en-us/articles/360032872931
Expo Notifications (APNs/FCM): Delivery of push notifications
Data processed: Device tokens, notification payloads
Purpose: Delivering notifications
Brevo (Sendinblue) SAS: Email delivery and communication management for website and service messages
Data processed: Email address, message content, and delivery metadata
Location: EU (primary), with vetted sub-processors
Purpose: Sending transactional emails, contact form responses, newsletters, and launch or product updates (if you sign up or subscribe)
Data Processing Agreements: All processors operate under GDPR-compliant data processing agreements that ensure appropriate technical and organizational security measures.
No Data Sales: We never sell, rent, or trade your personal data to third parties for commercial purposes.
Some of our service providers may process your data outside the European Economic Area (EEA):
Apple/Google: Authentication data may be processed globally according to their infrastructure
Cloudflare (global, including Turnstile): Website security, bot management, Turnstile verification, and abuse-prevention processing may occur across Cloudflare's global network.
Expo Notifications (APNs/FCM): Push notification delivery may involve processing outside the EEA
GIPHY (United States): When you use GIF features, your search queries are sent to GIPHY's API in the US and selected GIFs are stored as CDN URLs in our database. GIPHY may collect usage data according to their privacy policy.
Brevo (EU): Primary processing in the EU; if sub-processors outside the EEA are used, transfers are based on SCCs.
Transfers to GIPHY Inc. are based on Standard Contractual Clauses approved by the European Commission.
Legal basis for transfers: Adequacy decisions (Art. 45 GDPR) or appropriate safeguards (Art. 46 GDPR, e.g., SCCs) as set out in the providers' data processing terms
Documentation: You can request copies of safeguards by contacting us at info@apmenta.com
We retain personal data only as long as necessary for the stated purposes:
Profile information: Retained while your account is active
Messages and matches: Retained while your account is active and for safety investigations
Photos and attachments: Retained while your account is active
Cultural preferences: Retained while your account is active
Account deactivation: Profile hidden from discovery but data retained for 30 days to allow reactivation
Inactive accounts: After 24 months of inactivity, we may delete your account and associated data
User reports and moderation data: Retained for 2 years for pattern detection and legal compliance
Security logs: 6-12 months unless needed for ongoing investigations
Legal hold data: Retained as required by law or valid legal process
Usage analytics: Aggregated data retained indefinitely; individual data deleted after 2 years
Error logs and diagnostics: 90-180 days
Authentication logs: 12 months
Account deletion: All personal data (profile, photos, messages, matches) permanently deleted immediately
Audit records: A lightweight, anonymized audit record (deletion timestamp, account age, match count, optional reason) is retained for 30 days for compliance purposes. This record contains NO identifiable information and uses a one-way hash that cannot be reversed to identify you.
Conversation history: Your messages are permanently deleted; conversation partners will see that messages from a deleted account are no longer available
Safety exceptions: In rare cases, minimal data may be retained for ongoing legal proceedings or fraud investigations as required by law
Retention: Database backups are performed daily and retained for up to 7 days
Scope: Backups include database records and metadata; they do not include files stored via the Storage API
Deletion timing: Data deleted from the live database may persist in backups until they are overwritten (up to 7 days)
As a data subject, you have the following rights:
What: Request a copy of all personal data we process about you
How: Contact us at info@apmenta.com
Timeline: We respond within 30 days
What: Correct inaccurate or incomplete personal data
How: Update information directly in-app or contact us
Timeline: Corrections made immediately when technically feasible
What: Request deletion of your personal data
How: Use "Delete Account" button in Settings → Account section, or contact us at info@apmenta.com
Effect: All personal data is immediately and permanently deleted (profile, photos, messages, matches, preferences)
Audit Record: A minimal, anonymized audit record (30-day retention) is created for compliance but contains zero identifiable information
Limitations: In rare cases, we may retain minimal data for ongoing legal proceedings or fraud investigations as required by law
What: Temporarily limit how we process your data
How: Contact us with specific restriction requests
Effect: Data stored but not actively processed
What: Receive your data in a machine-readable format
How:
In-App: Use "Download My Data" in Settings → Account to instantly export all your data as an HTML file
By Email: Contact us at info@apmenta.com for a data export
Scope: Data processed based on consent or contract
Export Includes: Profile information, matches, messages, interaction signals, cultural preferences, app settings, and all other personal data
What: Object to processing based on legitimate interests
How: Contact us with objection details
Effect: We stop processing unless compelling legitimate grounds exist
What: Withdraw consent for voluntary processing
How: Disable location access in your device settings (withdraws consent for precise location) or delete your account (withdraws consent for other special category data)
Effect: Processing stops; does not affect lawfulness of previous processing
What: File complaints with supervisory authorities
Where: Your local data-protection authority or our lead supervisory authority in the EU:
Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Website: https://www.aki.ee/en
Email: info@aki.ee
Address: Tatari 39, 10134 Tallinn, Estonia
When: If you believe we've violated your privacy rights
Exercising Your Rights: Contact info@apmenta.com with identification and specific requests.
Special category data processing (sexual orientation, precise location)
Optional features like cultural preference matching
For preferences (e.g., "Looking for"), you provide explicit consent by setting or changing these preferences as part of using the App's matchmaking features.
For precise location, you provide consent when you grant location permission at the system level.
Changing preferences does not require re-consent.
Disable location access in your device settings (withdraws consent for precise location)
Delete your account (withdraws consent for other special category data)
Changing preferences does not withdraw consent.
Effect is immediate for future processing
What: Automated systems rank and suggest potential matches
Logic: Based on preferences, location, engagement patterns, and compatibility factors
Significance: Affects who you see and who sees you in discovery
What: Automated detection of inappropriate content and behavior
Logic: Pattern recognition, content analysis, and behavioral signals
Significance: May result in content warnings or account restrictions
We implement comprehensive security measures:
Encryption in transit (TLS 1.3) and at rest
Private storage buckets with signed URLs
Multi-factor authentication support
Regular security audits and updates
Row-level security (RLS) policies on all user data
Least-privilege access controls
Staff training on data protection
Incident response procedures
Collect only necessary data
Automatic deletion of expired logs
Anonymization where possible
Regular data audits
If a personal data breach occurs, we assess the risk to your rights and freedoms
Where required under Art. 33 GDPR, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware (unless the breach is unlikely to result in a risk to your rights and freedoms)
Where required under Art. 34 GDPR, we inform affected users without undue delay when the breach is likely to result in a high risk to their rights and freedoms
We document personal data breaches as required by Art. 33(5) GDPR
Important: No security system is perfect. While we implement industry-standard protections, we cannot guarantee absolute security.
The App is exclusively for adults aged 18 and over
We do not knowingly collect data from minors
Age verification through birthday field
If you become aware of underage use, report it immediately to info@apmenta.com
We will promptly delete accounts of verified minors
You can download all your personal data at any time:
In-App Export:
Go to Settings → Account
Tap "Download My Data"
A comprehensive HTML file with all your data will be generated
On Android: You choose a folder (e.g., Downloads); the HTML file and photos are saved there
On iOS: A share dialog appears; save to Files, email it, or share to another app
What's Included:
Identity and authentication data (email, sign-up date, last sign-in)
Complete profile information (bio, photos, preferences, dating intentions)
Cultural preferences (favorite artists, songs, films, books)
Matches and interaction signal history
Messages you've sent
App settings and preferences
Export Notes:
Android: Photos are saved as separate files; the HTML report lists photo filenames
iOS: Photos are embedded directly in the HTML file as base64 for easy sharing
Discovery history is excluded from the export
By Email: Alternatively, contact privacy@apmenta.com to request a data export
In-App Deletion (Recommended):
Go to Settings → Account
Tap "Delete Account"
Confirm deletion (you'll be asked twice to prevent accidents)
Optional: Provide feedback on why you're leaving (helps us improve)
Your account and all personal data is immediately and permanently deleted
By Email: Alternatively, contact delete-account@apmenta.com from your registered email address. We may request verification to ensure it's really you.
What Happens Immediately:
All personal data is permanently deleted (no recovery possible)
Profile completely removed from the app
All photos permanently deleted from our servers
Messages permanently deleted from all conversations
Matches and interaction signals removed
Cultural preferences and settings deleted
Backups: Database backups are retained for up to 7 days; deleted data may persist in backups until they are overwritten
Audit Record (Compliance Only): A lightweight audit log entry is created containing:
Deletion timestamp
Anonymized identifier (one-way hash that cannot identify you)
Optional deletion reason (if you provided feedback)
Basic metadata (account age, number of matches)
This audit record:
Contains NO identifiable information (no name, email, photos, or messages)
Is automatically deleted after 30 days
Is accessible only to authorized system administrators for compliance verification
Cannot be used to recover your account or identify you
Your profile: Immediately and permanently removed
Your messages: Permanently deleted from all conversations
Your photos: Immediately deleted from our servers (no copies retained)
Your matches: All match records permanently deleted
Analytics data: Personal analytics immediately deleted; aggregated anonymous data may be retained
Audit record: Anonymized metadata retained for 30 days only (compliance requirement)
We may update this policy to reflect changes in our practices or legal requirements
Material changes will be notified through:
In-app notifications
Email notifications (if provided)
App Store update notes
Continued use after changes indicates acceptance
Your options: If you disagree with changes, you may delete your account
Data Controller: Apmenta OÜ
Tartu mnt 67/1-13b, 10115 Tallinn, Estonia
Email: info@apmenta.com
For Privacy Concerns: Email: privacy@apmenta.com
EU Representative: Not applicable (EU-established controller)
Response Times:
General inquiries: 5 business days
Privacy rights requests: 30 calendar days
Urgent security matters: 24-48 hours
Camera: To scan QR codes and capture photos. You can disable camera access in your device settings; core app features continue to work.
Photos/Media Library: To select photos to upload for your profile or share in chats. You can disable library access in device settings; photo-related features will be limited.
Location: To show nearby profiles and set your timezone. We request "While Using the App" access only; we do not request background location or continuous foreground location services. You can change this in device settings.
Push Notifications: To deliver match, message, and safety notifications. You can opt out in OS settings and in app settings where available.
File Storage: To save your data export when you use "Download My Data" feature. On Android, you'll be prompted to select a folder where your data export and photos will be saved (requires storage permission). On iOS, files are automatically saved to the app's private Documents folder accessible through the Files app (no permission required). This is only requested when you initiate a data export.
Not requested: We do not request access to your microphone, contacts, calendars, or Bluetooth.
Last Updated: 31 March 2026
Version: 2.7
Previous Version: 2.6
Changes in 2.7: Updated the email-communications wording to remove outdated launch-phase references.