Back to site

Privacy Policy

What we collect, why we collect it, who else sees it, how long we keep it, and how to get it back or get rid of it.

Last updated: August 29, 2026

1. Who we are

ValidMeet is a location-based app for meeting people nearby, for friendship or dating. We are based in Austin, Texas, and we are the controller of the personal data described here.

This policy covers the ValidMeet app and validmeet.com. It is written to be read, not to be survived. If anything here is unclear, ask us.

2. What we collect

Everything below is collected either because you gave it to us or because a feature cannot work without it. We do not buy personal data about you from data brokers.

CategoryWhat it includesWhy
AccountPhone number or email, and the Apple or Google identifier you signed in with. Date of birth.To create your account, keep it secure, and confirm you are 18 or older.
ProfileName, photos, bio, occupation, gender, relationship status, interests, what you are looking for, student field of study, class year or graduation year, who you are looking to meet, and typical availability.To show your profile and improve recommendations. Exact availability times are shown only if you choose to share them.
Face verificationA short video selfie and a mathematical representation of your face. See section 3.To confirm you are a real, live person and that your photos are actually you.
Precise locationGPS coordinates from your device while the map is open, a short history of those points used to estimate where you usually are, every few seconds while you are travelling to a meetup, and a one-time snapshot if you file a safety report.To show who and what is nearby, place beacons, suggest introduction venues, confirm you arrived, and review safety reports.
MessagesThe content of messages you send other members, and who you sent them to.To deliver them, and to investigate reports.
ActivityBeacons, groups, events, RSVPs, matches, introductions, meetups you attended or missed, yes/no decisions used to rank later suggestions, streaks, trust level, which onboarding steps you completed, and which days you opened the app.To operate the features, improve them, and keep the community accountable.
SafetyReports you file or that are filed about you, including a one-time location snapshot stored with a report, blocks, and safety share links you create.To keep people safe and to enforce our rules.
DeviceDevice type, operating system, app version, push notification token, IP address, a pseudonymous sign-in device identifier, and crash or performance diagnostics.To deliver notifications, prevent automated sign-up abuse, secure accounts, and diagnose reliability problems.
PurchasesSubscription status and transaction identifiers from Apple or Google.To unlock paid features. We never see your card number.
Student statusYour .edu email address, if you choose to verify as a student. Field of study, class year, or graduation year, if you add them.To grant the student badge. Optional.
Support and legal correspondenceEmails and other information you send to our support, safety, privacy, legal, or copyright addresses. If you delete your account from the app, the reason and message you wrote.To answer you, handle requests and disputes, protect members, meet legal obligations, and improve the product after someone leaves.

Your contacts stay on your phone

When you pick someone to share a meetup with, the app reads your address book on the device to show you a list. Those contacts are never uploaded to our servers. They are stored only in the app on your phone, and the message goes out from your phone, not from us.

3. Face verification and biometric data

To prove that accounts belong to real people, we ask you to complete a short face check when you create your profile. This is the single most effective thing we do against fake profiles, catfishing, and banned users coming back.

The check runs once. Amazon Rekognition, operating on our behalf, confirms that a live person is present and produces a mathematical representation of your face, called a face template. We store the template and delete the video and any still images taken during the check.

Every time you add a new photo to your profile, we compare that photo against your template to confirm it is you. The comparison happens on a template, not on a stored picture of your face.

A face template is a biometric identifier under Texas law. We ask for your explicit consent before the check runs, and you can decline. If you decline, you cannot complete verification, which limits what you can do in the app.

We do not sell, lease, or trade biometric data, and we do not use it for advertising, tracking, or anything other than verifying identity. While we still hold a template, we may also use it to detect a banned member returning. That template is still destroyed no later than one year after last activity.

How long we keep it

We delete your face template when you delete your account, and in any case no later than 365 days after your last activity. You can withdraw consent by deleting your account or by writing to privacy@validmeet.com. Withdrawal deletes the template immediately and removes your verified status. You cannot add photos until you consent and complete the face check again.

4. Location

Location is the core of ValidMeet, so it gets its own page. Our Location Data Disclosure explains precisely what other members can see, when, and how to turn each part off. The summary:

  • We do not track you in the background. Ordinary map location is collected only while the app is open. The one exception is an active Share My Meetup link: then location can continue in the background until you stop sharing, 5 minutes after the meetup ends if you do not stop it, or 48 hours, like a navigation session. We do not use Always location to wake the app after you force-quit it.
  • Beacons show a real pin. When you place a beacon, members nearby see its actual location, because they need to know where to go. Members far away see an approximate area instead.
  • Matches and introductions see a venue, not you. When you match or receive an introduction, you both get the location of a public meeting spot. They do not see your live position, your route, your usual-location samples, or whether you are moving.
  • Safety shares are exact and deliberate. If you send a safety share link, whoever holds that link sees your live location until you end the share, 5 minutes after the meetup ends if you do not stop it, or it expires, at most 48 hours. The person you matched with cannot turn your share off.
  • A report stores a snapshot, not a trail. If you file a report, we keep one snapshot of your position and the meetup venue with that report. Other members cannot see it. It is deleted with the report.

5. How we use your data

We do not use your data to build advertising profiles, and we do not run third-party ads in the app.

  • To run the app: showing nearby people and places, matching, introductions, messaging, beacons, groups, and events.
  • To keep people safe: verifying identity, screening photos, reviewing reports, detecting scams and ban evasion, and responding to emergencies.
  • To communicate with you: notifications about activity, messages about your account or these policies, and — only if you opt in — an email when ValidMeet opens in a city you requested.
  • To handle payments and subscriptions.
  • To understand and improve the product, using aggregated and coarse data rather than individual tracking.
  • To rank relevant matches, introductions, groups, notifications, and zone times using typical availability and your recent yes/no decisions. This never activates live matching for you.
  • To comply with the law and to respond to valid legal process.

6. Who we share it with

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Under the CCPA, that means we have no "sale" or "sharing" to opt out of.

We use the following service providers, each of which is contractually limited to processing data on our instructions:

ProviderWhat they receiveWhy
Google FirebaseSign-in identifiers, phone number or email, photos, push tokensAuthentication, photo storage, and push notification delivery
TwilioPhone number and verification delivery statusSending and validating one-time phone sign-in codes
Amazon Web ServicesFace video during the check, then only the face template; encrypted database backupsLiveness detection, photo matching, and disaster recovery
Google Maps PlatformCoordinates and place searchesFinding and displaying real venues
Google Cloud VisionProfile, group cover, and chat photosAutomatically screening for explicit imagery
MapboxCoordinatesMap display, geocoding, and directions
Apple and GooglePurchase informationProcessing in-app purchases. We never receive card details
ResendYour .edu address if you verify as a student; support and legal email contentSending verification codes and delivering inbound support mail to our servers
SlackSupport, safety, privacy, legal, and copyright thread content, and in-app report summariesSo our team can answer mail and act on reports. Slack processes this on our instructions
RailwayAll app data, as our hosting providerRunning our servers and database
SentryCrash reports and performance diagnostics, which may include device, app, and technical request contextFinding crashes, server errors, and reliability problems. Default personal-information collection is disabled

We also share data with other members, as described in section 7, and with law enforcement or regulators when legally required or when someone is in danger. If we are ever acquired, your data may transfer as part of that transaction, and we will tell you before it does.

7. What other members can see

This is the part people most often get wrong about apps like ours, so here it is plainly.

Visible to other membersNever visible to other members
Your name, age, photos, bio, occupation, what you are looking for, relationship status, interests, student year, major, or graduation year, and badgesYour phone number and email address
Whether you are verifiedYour date of birth
A general typical-availability summary, and exact times only if you enable sharingYour exact typical schedule when exact sharing is off
Your trust level and meetup reliabilityYour face template or verification imagery
Beacons, groups, and events you create or joinYour exact position, except as described in the Location Data Disclosure
Messages you send themYour .edu address, if you verified as a student
That you are onlineReports you have filed, and who you have blocked

When you report someone, we never tell them who reported them. A location snapshot stored with a report is visible only to ValidMeet, and to law enforcement when legally required. When you block someone, they are not notified.

8. How long we keep it

We keep data only as long as it is useful for the purpose we collected it, and we run automated jobs that delete it on the schedule below.

DataRetention
Profile, photos, and messagesUntil you delete your account
Face templateUntil you delete your account or withdraw consent, and no later than 365 days after your last activity
Search and matching locationDeleted within minutes of the search ending
Beacon locationsRemoved from the live map at expiry; deleted from our database within 30 days
Safety share locationDeleted when the share ends, and in any case within 48 hours
Last known positionOverwritten continuously; cleared after 30 days of inactivity
Usual-location samplesPrecise points collected about every 45 minutes while the app is open, kept 14 days, then deleted. Other members never see them
Introduction recordsUntil the introduction ends or you delete your account
Taste events (yes/no ranking signals)Up to 90 days, then deleted
Usage analyticsOnboarding-step and app-open day records, and search locations rounded to roughly one kilometre, kept up to 12 months
Typical availabilityYour profile choices remain until changed or your account is deleted; anonymous area and time aggregates may be kept up to 12 months
Phone verification security recordsHashed phone and device identifiers, IP address, timestamps, outcomes, and provider verification identifiers are deleted after 90 days
Reports, blocks, and any location snapshot stored with a reportDeleted with your account
Support, safety, privacy, and legal correspondenceNormally up to 24 months; longer only when needed for a legal claim, preservation duty, or litigation hold
Arbitration opt-out recordFor as long as needed to honor your opt-out and establish which dispute terms apply
Ban recordsIf we removed your account for a serious violation, we keep a minimal record of the ban. The face template is still destroyed no later than 365 days after your last activity
Transaction recordsAs long as tax and financial law requires, generally 7 years
Encrypted disaster-recovery backupsUp to 30 days; deleted data may remain in a backup until that backup expires and is used only for authorized disaster recovery

9. Your rights and choices

Wherever you live, you can do all of the following. We do not charge for any of it and we will not treat you differently for asking.

  • See your data. Request a copy of what we hold about you, or export it yourself from Settings.
  • Correct it. Edit your profile at any time, or write to us about anything you cannot change yourself.
  • Delete it. Delete your account from Settings, or from validmeet.com if you cannot get into the app.
  • Withdraw biometric consent. Delete your account, or write to privacy@validmeet.com. We delete the template immediately. Verified status ends, and you cannot add photos until you consent and complete the face check again.
  • Control location. Adjust what is shared in Settings, or revoke the permission entirely in your device settings.
  • Control notifications. Choose categories and quiet hours in Settings.
  • Object or complain. Tell us if you think we are handling your data wrongly, or complain to your local data protection authority.

To make a request, write to privacy@validmeet.com from the address or phone number on your account. We acknowledge requests within 10 business days and complete them within 45 calendar days. If we need longer, we will tell you why.

If you are in California, you have these rights under the CCPA, including the right not to be discriminated against for exercising them. As stated above, we do not sell or share personal information. If you are in the EEA or UK, our legal bases are performance of our contract with you, our legitimate interest in keeping the community safe, your consent for biometric data and precise location, and compliance with legal obligations.

10. Security

Data is encrypted in transit and at rest. Access to production systems is restricted and authenticated. Photos are served from managed cloud storage rather than our own servers, and face templates are stored as mathematical representations rather than images.

No system is perfectly secure. If a breach ever affects your personal data, we will notify you and the relevant authorities as the law requires.

11. Children

ValidMeet is strictly for people 18 and older. We do not knowingly collect data from anyone younger, and we verify age at sign-up. If we learn that an account belongs to a minor, we delete it and its data immediately.

If you believe a minor is using ValidMeet, tell us at safety@validmeet.com and we will act the same day.

12. Changes to this policy

When we change something material, we will notify you in the app before it takes effect, not quietly edit the page. The date at the top always reflects the current version.

13. Contact us

Privacy questions, data requests, and complaints: privacy@validmeet.com

Safety concerns: safety@validmeet.com

Everything else: support@validmeet.com

Account deletion takes effect immediately and finishes within 30 days. See our Data Deletion Policy for the details.

Other policies

Terms Location Guidelines Safety Safety Policy Copyright Delete Account

© 2026 ValidMeet · Austin, Texas

Terms Privacy Location Guidelines Safety Safety Policy Copyright Delete Account