Privacy Policy
Effective August 19, 2026 · Version 2.1
Kind exists because people living with HSV deserve somewhere private to date. Privacy is the product, not an afterthought, and this policy is written to be read rather than skimmed past.
The short version: we never sell your data, we never use it for advertising, your HSV information is encrypted before it is stored, your verification photos are never saved at all, and you can delete everything from inside the app.
1. Overview and Scope
This Privacy Policy explains how Subtxt LLC, doing business as Kind ("Kind", "we", "us"), collects, uses, shares, and protects personal information when you use the Kind mobile app, the kind.date website, and related services (the "Service"). Subtxt LLC is the controller of that information.
Kind is a dating app for adults living with HSV. That means some of what you choose to tell us is health-related and legally sensitive, and we treat it accordingly. Two companion documents form part of this policy and go into more detail: the Biometric Data Policy, which covers photo verification, and the Consumer Health Data Privacy Policy, which covers health information and the specific rights of residents of Washington, Nevada, and Connecticut.
This policy does not cover the practices of third parties we do not control, including Apple, Google, and any website or service you reach through a link on the Service.
2. Information We Collect
We collect information you give us, information generated as you use the Service, and limited information from the providers that help us run it. We collect only what the Service needs.
Information you provide
- Account and authentication: your phone number, account identifiers, sign-in status, one-time passcode events, and session metadata.
- Recovery email (optional): an email address you may add during signup or in Settings. We use it for exactly two things — verifying it is you so we can restore your account if you lose access to your phone number, and delivering legally required notices. Never for marketing, and you can remove it at any time in Settings.
- Profile: display name, date of birth and age, gender and the genders you want to see, height, body type, ethnicity, relationship status and intent, religion, children, education, occupation, interests, prompts, biography, and social links you choose to add.
- Health-related: HSV type, which signup asks for because it drives matching (choosing "Not sure" discloses nothing specific), and diagnosis year, which is entirely optional. Both are encrypted by our backend with application-layer encryption before they are written to the database.
- Photos and media: profile photos, private album photos, and the reference and live capture images used for verification.
- Voice notes: an optional recording of up to 90 seconds answering a profile prompt.
- Communications: messages, message requests, likes and the openers attached to them, reactions, reports, support requests, Kind+ application answers, and exit survey responses.
- Payment-adjacent: we never receive or store your card details. Apple and Google process payments; we receive entitlement and transaction status.
Information collected automatically
- Location: with your permission, an approximate device location used to derive your city and to calculate distance between members. We request balanced, not high, accuracy, and we store a coarse location for matching. You can decline and enter a location manually.
- Usage and interaction: profiles viewed, likes, passes, matches, messages sent, sessions, screens visited, features used, and time stamps. These drive matching, ranking, and abuse detection.
- Device and technical: device and OS version, app version, device model, language, time zone, push notification token, crash reports, diagnostic logs, IP address, and security signals such as rate-limit and anti-fraud events.
- Cookies and similar technologies on the kind.date website only — see Section 13. The Kind mobile app uses no cookies, no advertising identifiers, no advertising SDKs, and no third-party analytics. Nothing you do inside the app — profiles viewed, messages, HSV information — is visible to any analytics or advertising provider.
Information from other sources
- Device contacts, only if you turn on contact blocking. Your device hashes each phone number with SHA-256 before it leaves your phone. We receive only the hashes and never plaintext contact numbers, names, or any other contact detail.
- Apple, Google, and RevenueCat: subscription and entitlement status, product identifiers, purchase, renewal, billing-issue, refund, and cancellation events.
- Other members: reports and safety information about you submitted by other users.
What we do not collect
We do not collect your payment card details, your government identification, your precise continuous location, your device contact list in readable form, your browsing activity on other apps or websites, or data from advertising networks or data brokers. We do not buy personal information about you.
3. Photo Verification and Biometric Information
To reduce catfishing, Kind offers an automated photo verification check. You select a private reference photo and take a live camera capture. Software detects a face in each image, converts each into a numeric facial geometry template, and compares the two.
Nothing from verification is stored
The reference photo, the live capture, and both facial templates exist only in server memory for the few seconds the comparison takes, and are then deleted. None of them is written to disk, to a database, or to object storage, and no human reviews them. We keep only the outcome: pass or fail, a similarity score, and a time stamp, retained as a security and anti-fraud record.
We ask for your separate, express consent in the app before any capture, and our servers refuse to process a capture without it. Verification is required to complete signup — every member verifies, which is what makes the badge meaningful. We never sell, lease, trade, or otherwise profit from biometric information, and we never disclose it to anyone. Full details, including our written retention and destruction schedule and the rights of Illinois, Texas, and Washington residents, are in the Kind Biometric Data Policy.
4. How and Why We Use Information
| Purpose | Information used | Legal basis (UK/EU) |
|---|---|---|
| Create and secure your account, authenticate you, prevent unauthorised access | Account, authentication, device, security signals | Performance of a contract; legitimate interests in security |
| Operate your profile, Discovery, Spotlight, matching, likes, and messaging | Profile, health-related, photos, voice notes, usage, location | Performance of a contract; explicit consent for health data |
| Rank and recommend profiles, including compatibility and quality scoring | Profile, usage, interaction history | Performance of a contract; legitimate interests in a useful service |
| Verify photos to reduce impersonation | Reference photo, live capture, facial templates (transient) | Explicit consent |
| Trust and safety: moderation, nudity and hate-speech detection, fraud and bot detection, risk scoring, blocking, reports, suspensions | Content, messages, usage, device, security signals, reports | Legitimate interests in protecting members; legal obligation; substantial public interest |
| Contact blocking (hide people you know) | Hashed contact phone numbers | Consent |
| Process subscriptions and entitlements, restore purchases, handle refunds | Purchase and entitlement data, account identifiers | Performance of a contract; legal obligation |
| Send service, match, message, safety, and account notifications | Account, push token, usage | Performance of a contract; legitimate interests |
| Diagnose crashes, monitor performance, debug and improve the Service | Device, diagnostic logs, crash reports, aggregate usage | Legitimate interests in a working service |
| Comply with law, respond to lawful requests, establish or defend legal claims, enforce our Terms | Any category, as strictly necessary | Legal obligation; legitimate interests; establishment or defence of legal claims |
We do not use your personal information for third-party advertising, cross-context behavioural advertising, or profiling for advertising. We do not use health-related information, private messages, or biometric information to train general-purpose artificial intelligence models.
5. Sensitive and Health-Related Information
The fact that you use Kind, along with HSV type and diagnosis year, is health-related information. Depending on where you live it may also be "sensitive personal information", "sensitive data", a "special category of personal data", or "consumer health data" under law. We treat all of it as sensitive.
- We collect it only with your consent, given separately from your acceptance of our Terms, and only what the Service needs.
- We use it only to operate the features you ask for — profile display, matching, filtering — and for safety, support, legal compliance, and your own deletion or export requests.
- HSV fields are encrypted at the application layer before storage, with keys managed separately from the data they protect, so the raw database rows do not hold readable values.
- We never sell it, never share it for advertising, and never disclose it to data brokers, advertisers, insurers, or employers.
- Access inside Kind is limited to authorised systems and the small number of people with a genuine operational need.
- We use sensitive information only for the purposes permitted by California Civil Code § 1798.121, and we do not use or disclose it to infer characteristics about you.
What you choose to show other members
Anything you put on your profile — including HSV type, photos, voice notes, and social links — is visible to other members of Kind, and messages you send are visible to the person you send them to. We cannot control what another member does with information you share with them, including taking a screenshot. Share only what you are comfortable with another person seeing.
Residents of Washington, Nevada, and Connecticut have additional rights over consumer health data, including a right to have it deleted. Those rights, and how to use them, are set out in our Consumer Health Data Privacy Policy.
6. Automated Decision-Making and Profiling
Kind uses automated systems, without a human reviewing every case, to:
- Rank and recommend profiles in Discovery and Spotlight based on your activity and stated preferences.
- Compare a verification capture against a reference photo and set your verified status.
- Scan uploaded photos for nudity and prohibited imagery, and scan message text for spam, scams, hate speech, and exploitation patterns.
- Calculate a trust score from behavioural and abuse signals, which can limit your visibility or automatically suspend your account pending human review.
Automated suspension and automated verification refusal can significantly affect you. Where the law gives you the right, you may ask for human review of such a decision, express your point of view, and contest the outcome. Email us at the address below and a person will look at it. We do not use automated decision-making to make decisions about you that produce legal effects except as described here.
8. How Long We Keep Information
| Data | Retention |
|---|---|
| Verification photos and facial templates | Never stored — deleted from memory within seconds of the comparison |
| Verification outcome (pass/fail, score, time stamp) | Life of the account, then up to 12 months as an anti-fraud record |
| Active account, profile, photos, health-related fields | Until you delete your account |
| Deleted account | 30-day grace period during which you can restore, then permanent deletion |
| Messages | Until you or the other member deletes the account, or the conversation is removed |
| Hashed contact numbers | Until you turn contact blocking off or clear them in Privacy settings |
| Recovery email | Until you remove it in Settings or your account is permanently deleted, whichever comes first |
| Crash and diagnostic logs | Up to 90 days |
| Security, abuse, and moderation records | Up to 24 months after the event, or longer where needed for an ongoing investigation or legal claim |
| Deletion ledger entry | Created when you request deletion, holding display name, gender, city, join date, and any exit-survey reason — never HSV or other health information. Your display name is erased at the end of the grace period when permanent deletion runs; the remaining anonymised entry is kept indefinitely as proof we honoured the deletion. |
| Transaction and tax records | As required by law, typically 7 years |
After the 30-day grace period we permanently delete profile records, photos, private albums, voice notes, messages, matches, likes, contact hashes, push tokens, recovery email, Kind+ application records, and related app data. We keep only limited records where the law requires it or where they are necessary to defend a legal claim, prevent fraud, or enforce a ban — and we anonymise those wherever we can. Backups are overwritten on a rolling cycle and any residual copy is deleted within 90 days.
9. Your Privacy Rights
Wherever you live, you can use these controls at any time:
- Edit or remove most profile information, photos, and your voice note in the app.
- Hide your profile, pause your account, or delete it from Me → Privacy.
- Turn contact blocking off and clear all uploaded contact hashes from Privacy settings.
- Block, hide, or report another member from any profile or conversation.
- Turn push notifications on or off by category in Notification settings, and in your device settings.
- Manage or cancel a subscription in your Apple or Google account settings.
Legal rights, depending on where you live
Subject to law and to verification of your identity, you may have the right to: know what personal information we hold and how we use it; access it or receive a portable copy; correct inaccurate information; delete it; restrict or object to certain processing; opt out of sale, sharing, targeted advertising, or profiling with significant effects (we do not sell, share, or advertise, so there is nothing to opt out of); limit the use of sensitive personal information; withdraw consent at any time without affecting processing already carried out; and not be discriminated against for exercising any of these rights.
To make a request, email info@kind.date from the email address on your account, or send the request from inside the app. We will verify your identity — usually by confirming control of the phone number or email on the account — before acting, and we may ask for more information if we cannot verify you. An authorised agent may submit a request on your behalf with written permission signed by you, and we may still ask you to confirm it directly.
We respond within 45 days for California, Colorado, Connecticut, Virginia, and similar state requests, extendable once by a further 45 days with notice, and within one month for UK and EU requests, extendable by two further months for complex requests. We do not charge for a request unless it is manifestly unfounded or excessive. If we refuse a request, we will tell you why and how to appeal; you may appeal free of charge by replying to our decision, and we will respond to an appeal within 45 days (or 60 days in Colorado and Connecticut).
If you are in the UK, the EU, or the EEA
You also have the right to lodge a complaint with your local data protection supervisory authority. In the UK that is the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concern first.
If you are in California
California’s "Shine the Light" law (Civil Code § 1798.83) lets you request details of personal information disclosed to third parties for their own direct marketing. We do not make such disclosures. California minors under 18 may request removal of content they posted; contact us and we will remove it from public view.
10. International Data Transfers
Kind is operated from the United States, and our servers and principal service providers are located there. If you use the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States and other countries whose data protection laws may differ from those of your own country.
Where we transfer personal information out of the UK, the EEA, or another jurisdiction that restricts transfers, we rely on an appropriate safeguard, normally the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, plus supplementary technical measures including encryption in transit and application-layer encryption of health-related fields. You may request a copy of the relevant safeguard by emailing us.
11. How We Protect Information
- All traffic is encrypted in transit with HTTPS/TLS, and data is encrypted at rest by our infrastructure providers.
- Health-related fields receive an additional layer of application-layer encryption before storage, with keys held separately from the database.
- Row-level security policies restrict which records an authenticated account can reach.
- Verification images and facial templates are never written to persistent storage.
- Access to production systems is limited to authorised personnel, protected by multi-factor authentication, and logged.
- We monitor for abuse and intrusion, rate-limit sensitive endpoints, and review security-relevant changes.
- The app offers an optional device biometric or passcode lock, and screenshot protection on sensitive screens where the platform supports it.
No system can be perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant regulators as required by law and without undue delay.
12. Children
Kind is strictly for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18, and the Service is not directed to children. If we learn that an account belongs to someone under 18, we remove the account and delete the associated information promptly. If you believe a minor has given us information, contact us immediately at the address below. See also our Child Safety Standards.
14. Do Not Track and Global Privacy Control
There is no common industry standard for responding to browser Do Not Track signals, so the kind.date website does not respond to them. Because we do not sell or share personal information or engage in targeted advertising, an opt-out preference signal such as Global Privacy Control has no data for us to act on; we nonetheless honour such signals as an opt-out of any sale or sharing.
15. Changes to This Policy
We may update this policy as the Service or the law changes. We will post the new version with an updated effective date and version number. For material changes — particularly any change to how we handle health-related or biometric information — we will give notice in the app or by email before the change takes effect and, where the law requires it, obtain your consent. We will not apply a materially different use to information already collected without your consent.
16. Contact Us
Questions, requests, or complaints about privacy: email info@kind.date. Subtxt LLC is a Wyoming limited liability company operating remotely, so email reaches us fastest. We aim to acknowledge every privacy enquiry within five business days.