Privacy Policy
What we collect, why we collect it, who else sees it, how long we keep it, and how to get it back or get rid of it.
Last updated: August 10, 2026
1. Who we are
ValidMeet is a location-based app for meeting people nearby, for friendship or dating. We are based in Austin, Texas, and we are the controller of the personal data described here.
This policy covers the ValidMeet app and validmeet.com. It is written to be read, not to be survived. If anything here is unclear, ask us.
2. What we collect
Everything below is collected either because you gave it to us or because a feature cannot work without it. We do not buy personal data about you from data brokers.
| Category | What it includes | Why |
|---|---|---|
| Account | Phone number or email, and the Apple or Google identifier you signed in with. Date of birth. | To create your account, keep it secure, and confirm you are 18 or older. |
| Profile | Name, photos, bio, gender, interests, and who you are looking to meet. | This is what other members see. You choose what goes in it. |
| Face verification | A short video selfie and a mathematical representation of your face. See section 3. | To confirm you are a real, live person and that your photos are actually you. |
| Precise location | GPS coordinates from your device while the map is open, and every few seconds while you are travelling to a meetup. | To show who and what is nearby, place beacons, and confirm you arrived. |
| Messages | The content of messages you send other members, and who you sent them to. | To deliver them, and to investigate reports. |
| Activity | Beacons, groups, events, RSVPs, matches, meetups you attended or missed, streaks, and trust level. | To operate the features and to keep the community accountable. |
| Safety | Reports you file or that are filed about you, blocks, and safety share links you create. | To keep people safe and to enforce our rules. |
| Device | Device type, operating system, app version, and a push notification token. | To deliver notifications and to fix problems. |
| Purchases | Subscription status and transaction identifiers from Apple or Google. | To unlock paid features. We never see your card number. |
| Student status | Your .edu email address, if you choose to verify as a student. | To grant the student badge. Optional. |
3. Face verification and biometric data
To prove that accounts belong to real people, we ask you to complete a short face check when you create your profile. This is the single most effective thing we do against fake profiles, catfishing, and banned users coming back.
The check runs once. Amazon Rekognition, operating on our behalf, confirms that a live person is present and produces a mathematical representation of your face, called a face template. We store the template and delete the video and any still images taken during the check.
Every time you add a new photo to your profile, we compare that photo against your template to confirm it is you. The comparison happens on a template, not on a stored picture of your face.
A face template is a biometric identifier under Texas law. We ask for your explicit consent before the check runs, and you can decline. If you decline, you cannot complete verification, which limits what you can do in the app.
We do not sell, lease, or trade biometric data, and we do not use it for advertising, tracking, or anything other than verifying identity and detecting banned users returning under a new account.
4. Location
Location is the core of ValidMeet, so it gets its own page. Our Location Data Disclosure explains precisely what other members can see, when, and how to turn each part off. The summary:
- We do not track you in the background. Location is collected only while the app is open and on screen. Close the app and collection stops.
- Beacons show a real pin. When you place a beacon, members nearby see its actual location, because they need to know where to go. Members far away see an approximate area instead.
- Matches see a venue, not you. When you match with someone, you both get the location of a public meeting spot. They do not see your live position.
- Safety shares are exact and deliberate. If you send a safety share link, whoever holds that link sees your live location until you end the share or it expires, at most 48 hours.
5. How we use your data
We do not use your data to build advertising profiles, and we do not run third-party ads in the app.
- To run the app: showing nearby people and places, matching, messaging, beacons, groups, and events.
- To keep people safe: verifying identity, screening photos, reviewing reports, detecting scams and ban evasion, and responding to emergencies.
- To communicate with you: notifications about activity, messages about your account or these policies, and — only if you opt in — an email when ValidMeet opens in a city you requested.
- To handle payments and subscriptions.
- To understand and improve the product, using aggregated and coarse data rather than individual tracking.
- To comply with the law and to respond to valid legal process.
6. Who we share it with
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Under the CCPA, that means we have no "sale" or "sharing" to opt out of.
We use the following service providers, each of which is contractually limited to processing data on our instructions:
| Provider | What they receive | Why |
|---|---|---|
| Google Firebase | Sign-in identifiers, phone number or email, photos, push tokens | Authentication, photo storage, and push notification delivery |
| Amazon Web Services | Face video during the check, then only the face template; support email content for triage | Liveness detection, photo matching, and automated support-inbox classification |
| Google Maps Platform | Coordinates and place searches | Finding and displaying real venues |
| Google Cloud Vision | Profile, group cover, and chat photos | Automatically screening for explicit imagery |
| Mapbox | Coordinates | Map display, geocoding, and directions |
| RevenueCat | Subscription and transaction identifiers | Managing subscriptions |
| Apple and Google | Purchase information | Processing in-app purchases. We never receive card details |
| Resend | Your .edu address if you verify as a student; support and legal email content | Sending verification codes and delivering inbound support mail to our servers |
| Railway | All app data, as our hosting provider | Running our servers and database |
We also share data with other members, as described in section 7, and with law enforcement or regulators when legally required or when someone is in danger. If we are ever acquired, your data may transfer as part of that transaction, and we will tell you before it does.
7. What other members can see
This is the part people most often get wrong about apps like ours, so here it is plainly.
| Visible to other members | Never visible to other members |
|---|---|
| Your name, age, photos, bio, interests, and badges | Your phone number and email address |
| Whether you are verified | Your date of birth |
| Your trust level and meetup reliability | Your face template or verification imagery |
| Beacons, groups, and events you create or join | Your exact position, except as described in the Location Data Disclosure |
| Messages you send them | Your .edu address, if you verified as a student |
| That you are online | Reports you have filed, and who you have blocked |
When you report someone, we never tell them who reported them. When you block someone, they are not notified.
8. How long we keep it
We keep data only as long as it is useful for the purpose we collected it, and we run automated jobs that delete it on the schedule below.
| Data | Retention |
|---|---|
| Profile, photos, and messages | Until you delete your account |
| Face template | Until you delete your account or withdraw consent, and no later than 365 days after your last activity |
| Search and matching location | Deleted within minutes of the search ending |
| Beacon locations | Deleted when the beacon expires |
| Safety share location | Deleted when the share ends, and in any case within 48 hours |
| Last known position | Overwritten continuously; cleared after 30 days of inactivity |
| Usage analytics | Coordinates rounded to roughly one kilometre, kept up to 12 months |
| Reports and blocks | Deleted with your account |
| Ban records | If we removed your account for a serious violation, we keep a minimal record and your face template so you cannot return under a new account |
| Transaction records | As long as tax and financial law requires, generally 7 years |
9. Your rights and choices
Wherever you live, you can do all of the following. We do not charge for any of it and we will not treat you differently for asking.
- See your data. Request a copy of what we hold about you, or export it yourself from Settings.
- Correct it. Edit your profile at any time, or write to us about anything you cannot change yourself.
- Delete it. Delete your account from Settings, or from validmeet.com if you cannot get into the app.
- Withdraw biometric consent. Turn off face verification in Settings. We delete the template immediately.
- Control location. Adjust what is shared in Settings, or revoke the permission entirely in your device settings.
- Control notifications. Choose categories and quiet hours in Settings.
- Object or complain. Tell us if you think we are handling your data wrongly, or complain to your local data protection authority.
To make a request, write to privacy@validmeet.com from the address or phone number on your account. We acknowledge requests within 10 days and complete them within 45 days. If we need longer, we will tell you why.
If you are in California, you have these rights under the CCPA, including the right not to be discriminated against for exercising them. As stated above, we do not sell or share personal information. If you are in the EEA or UK, our legal bases are performance of our contract with you, our legitimate interest in keeping the community safe, your consent for biometric data and precise location, and compliance with legal obligations.
10. Security
Data is encrypted in transit and at rest. Access to production systems is restricted and authenticated. Photos are served from managed cloud storage rather than our own servers, and face templates are stored as mathematical representations rather than images.
No system is perfectly secure. If a breach ever affects your personal data, we will notify you and the relevant authorities as the law requires.
11. Children
ValidMeet is strictly for people 18 and older. We do not knowingly collect data from anyone younger, and we verify age at sign-up. If we learn that an account belongs to a minor, we delete it and its data immediately.
If you believe a minor is using ValidMeet, tell us at safety@validmeet.com and we will act the same day.
12. Changes to this policy
When we change something material, we will notify you in the app before it takes effect, not quietly edit the page. The date at the top always reflects the current version.
13. Contact us
Privacy questions, data requests, and complaints: privacy@validmeet.com
Safety concerns: safety@validmeet.com
Everything else: support@validmeet.com
Account deletion takes effect immediately and finishes within 30 days. See our Data Deletion Policy for the details.