Kind

Privacy Policy

Effective August 19, 2026 · Version 2.1

Kind exists because people living with HSV deserve somewhere private to date. Privacy is the product, not an afterthought, and this policy is written to be read rather than skimmed past.

The short version: we never sell your data, we never use it for advertising, your HSV information is encrypted before it is stored, your verification photos are never saved at all, and you can delete everything from inside the app.

1. Overview and Scope

This Privacy Policy explains how Subtxt LLC, doing business as Kind ("Kind", "we", "us"), collects, uses, shares, and protects personal information when you use the Kind mobile app, the kind.date website, and related services (the "Service"). Subtxt LLC is the controller of that information.

Kind is a dating app for adults living with HSV. That means some of what you choose to tell us is health-related and legally sensitive, and we treat it accordingly. Two companion documents form part of this policy and go into more detail: the Biometric Data Policy, which covers photo verification, and the Consumer Health Data Privacy Policy, which covers health information and the specific rights of residents of Washington, Nevada, and Connecticut.

This policy does not cover the practices of third parties we do not control, including Apple, Google, and any website or service you reach through a link on the Service.

2. Information We Collect

We collect information you give us, information generated as you use the Service, and limited information from the providers that help us run it. We collect only what the Service needs.

Information you provide

  • Account and authentication: your phone number, account identifiers, sign-in status, one-time passcode events, and session metadata.
  • Recovery email (optional): an email address you may add during signup or in Settings. We use it for exactly two things — verifying it is you so we can restore your account if you lose access to your phone number, and delivering legally required notices. Never for marketing, and you can remove it at any time in Settings.
  • Profile: display name, date of birth and age, gender and the genders you want to see, height, body type, ethnicity, relationship status and intent, religion, children, education, occupation, interests, prompts, biography, and social links you choose to add.
  • Health-related: HSV type, which signup asks for because it drives matching (choosing "Not sure" discloses nothing specific), and diagnosis year, which is entirely optional. Both are encrypted by our backend with application-layer encryption before they are written to the database.
  • Photos and media: profile photos, private album photos, and the reference and live capture images used for verification.
  • Voice notes: an optional recording of up to 90 seconds answering a profile prompt.
  • Communications: messages, message requests, likes and the openers attached to them, reactions, reports, support requests, Kind+ application answers, and exit survey responses.
  • Payment-adjacent: we never receive or store your card details. Apple and Google process payments; we receive entitlement and transaction status.

Information collected automatically

  • Location: with your permission, an approximate device location used to derive your city and to calculate distance between members. We request balanced, not high, accuracy, and we store a coarse location for matching. You can decline and enter a location manually.
  • Usage and interaction: profiles viewed, likes, passes, matches, messages sent, sessions, screens visited, features used, and time stamps. These drive matching, ranking, and abuse detection.
  • Device and technical: device and OS version, app version, device model, language, time zone, push notification token, crash reports, diagnostic logs, IP address, and security signals such as rate-limit and anti-fraud events.
  • Cookies and similar technologies on the kind.date website only — see Section 13. The Kind mobile app uses no cookies, no advertising identifiers, no advertising SDKs, and no third-party analytics. Nothing you do inside the app — profiles viewed, messages, HSV information — is visible to any analytics or advertising provider.

Information from other sources

  • Device contacts, only if you turn on contact blocking. Your device hashes each phone number with SHA-256 before it leaves your phone. We receive only the hashes and never plaintext contact numbers, names, or any other contact detail.
  • Apple, Google, and RevenueCat: subscription and entitlement status, product identifiers, purchase, renewal, billing-issue, refund, and cancellation events.
  • Other members: reports and safety information about you submitted by other users.

What we do not collect

We do not collect your payment card details, your government identification, your precise continuous location, your device contact list in readable form, your browsing activity on other apps or websites, or data from advertising networks or data brokers. We do not buy personal information about you.

3. Photo Verification and Biometric Information

To reduce catfishing, Kind offers an automated photo verification check. You select a private reference photo and take a live camera capture. Software detects a face in each image, converts each into a numeric facial geometry template, and compares the two.

Nothing from verification is stored

The reference photo, the live capture, and both facial templates exist only in server memory for the few seconds the comparison takes, and are then deleted. None of them is written to disk, to a database, or to object storage, and no human reviews them. We keep only the outcome: pass or fail, a similarity score, and a time stamp, retained as a security and anti-fraud record.

We ask for your separate, express consent in the app before any capture, and our servers refuse to process a capture without it. Verification is required to complete signup — every member verifies, which is what makes the badge meaningful. We never sell, lease, trade, or otherwise profit from biometric information, and we never disclose it to anyone. Full details, including our written retention and destruction schedule and the rights of Illinois, Texas, and Washington residents, are in the Kind Biometric Data Policy.

4. How and Why We Use Information

PurposeInformation usedLegal basis (UK/EU)
Create and secure your account, authenticate you, prevent unauthorised accessAccount, authentication, device, security signalsPerformance of a contract; legitimate interests in security
Operate your profile, Discovery, Spotlight, matching, likes, and messagingProfile, health-related, photos, voice notes, usage, locationPerformance of a contract; explicit consent for health data
Rank and recommend profiles, including compatibility and quality scoringProfile, usage, interaction historyPerformance of a contract; legitimate interests in a useful service
Verify photos to reduce impersonationReference photo, live capture, facial templates (transient)Explicit consent
Trust and safety: moderation, nudity and hate-speech detection, fraud and bot detection, risk scoring, blocking, reports, suspensionsContent, messages, usage, device, security signals, reportsLegitimate interests in protecting members; legal obligation; substantial public interest
Contact blocking (hide people you know)Hashed contact phone numbersConsent
Process subscriptions and entitlements, restore purchases, handle refundsPurchase and entitlement data, account identifiersPerformance of a contract; legal obligation
Send service, match, message, safety, and account notificationsAccount, push token, usagePerformance of a contract; legitimate interests
Diagnose crashes, monitor performance, debug and improve the ServiceDevice, diagnostic logs, crash reports, aggregate usageLegitimate interests in a working service
Comply with law, respond to lawful requests, establish or defend legal claims, enforce our TermsAny category, as strictly necessaryLegal obligation; legitimate interests; establishment or defence of legal claims

We do not use your personal information for third-party advertising, cross-context behavioural advertising, or profiling for advertising. We do not use health-related information, private messages, or biometric information to train general-purpose artificial intelligence models.

5. Sensitive and Health-Related Information

The fact that you use Kind, along with HSV type and diagnosis year, is health-related information. Depending on where you live it may also be "sensitive personal information", "sensitive data", a "special category of personal data", or "consumer health data" under law. We treat all of it as sensitive.

  • We collect it only with your consent, given separately from your acceptance of our Terms, and only what the Service needs.
  • We use it only to operate the features you ask for — profile display, matching, filtering — and for safety, support, legal compliance, and your own deletion or export requests.
  • HSV fields are encrypted at the application layer before storage, with keys managed separately from the data they protect, so the raw database rows do not hold readable values.
  • We never sell it, never share it for advertising, and never disclose it to data brokers, advertisers, insurers, or employers.
  • Access inside Kind is limited to authorised systems and the small number of people with a genuine operational need.
  • We use sensitive information only for the purposes permitted by California Civil Code § 1798.121, and we do not use or disclose it to infer characteristics about you.

What you choose to show other members

Anything you put on your profile — including HSV type, photos, voice notes, and social links — is visible to other members of Kind, and messages you send are visible to the person you send them to. We cannot control what another member does with information you share with them, including taking a screenshot. Share only what you are comfortable with another person seeing.

Residents of Washington, Nevada, and Connecticut have additional rights over consumer health data, including a right to have it deleted. Those rights, and how to use them, are set out in our Consumer Health Data Privacy Policy.

6. Automated Decision-Making and Profiling

Kind uses automated systems, without a human reviewing every case, to:

  • Rank and recommend profiles in Discovery and Spotlight based on your activity and stated preferences.
  • Compare a verification capture against a reference photo and set your verified status.
  • Scan uploaded photos for nudity and prohibited imagery, and scan message text for spam, scams, hate speech, and exploitation patterns.
  • Calculate a trust score from behavioural and abuse signals, which can limit your visibility or automatically suspend your account pending human review.

Automated suspension and automated verification refusal can significantly affect you. Where the law gives you the right, you may ask for human review of such a decision, express your point of view, and contest the outcome. Email us at the address below and a person will look at it. We do not use automated decision-making to make decisions about you that produce legal effects except as described here.

7. How We Share Information

We do not sell your data

Kind does not sell personal information, and does not share it for cross-context behavioural advertising, as those terms are defined under California and other state privacy laws. We have not done so in the preceding 12 months, including for anyone we know to be under 16.

We share information only in these situations:

WhoWhat they receiveWhy
Other membersYour visible profile, photos, voice note, verification badge, Kind+ badge where applicable, approximate distance, likes and messages you sendTo provide the Service you signed up for
SupabaseAccount, profile, health-related (encrypted), content, mediaDatabase, authentication, and file storage
RailwayAll processed data in transit through our APIApplication hosting and background jobs
Apple, Google, RevenueCatAccount identifier, purchase and entitlement eventsPayments, subscriptions, entitlement management
Expo push notification service, Apple APNs, Google FCMPush token, notification contentDelivering notifications to your device
SentryCrash reports, error diagnostics, limited device and account identifiersDetecting and fixing faults
VercelWebsite request logs and aggregate analyticsHosting the kind.date website
Professional advisers, insurers, auditorsOnly what is strictly necessaryLegal, accounting, and insurance advice

Every service provider is bound by contract to protect the information, to use it only to provide services to Kind, and not to sell it or use it for their own purposes. They are service providers or processors, not independent controllers.

Legal and safety disclosures

We may disclose information when we reasonably believe it is necessary to comply with a law, subpoena, court order, or other lawful request; to enforce our Terms; to detect, prevent, or address fraud, security, or technical issues; to protect the rights, property, or safety of Kind, our members, or the public; or to report suspected child sexual abuse material to the National Center for Missing & Exploited Children and law enforcement. Where we are legally permitted, we will try to notify you of a legal request before responding.

Business transfers

If Kind is involved in a merger, acquisition, financing, reorganisation, bankruptcy, or sale of assets, information may be transferred as part of that transaction. We will require the recipient to honour this policy for information transferred, and we will notify you of any material change to how your information is handled before it takes effect.

8. How Long We Keep Information

DataRetention
Verification photos and facial templatesNever stored — deleted from memory within seconds of the comparison
Verification outcome (pass/fail, score, time stamp)Life of the account, then up to 12 months as an anti-fraud record
Active account, profile, photos, health-related fieldsUntil you delete your account
Deleted account30-day grace period during which you can restore, then permanent deletion
MessagesUntil you or the other member deletes the account, or the conversation is removed
Hashed contact numbersUntil you turn contact blocking off or clear them in Privacy settings
Recovery emailUntil you remove it in Settings or your account is permanently deleted, whichever comes first
Crash and diagnostic logsUp to 90 days
Security, abuse, and moderation recordsUp to 24 months after the event, or longer where needed for an ongoing investigation or legal claim
Deletion ledger entryCreated when you request deletion, holding display name, gender, city, join date, and any exit-survey reason — never HSV or other health information. Your display name is erased at the end of the grace period when permanent deletion runs; the remaining anonymised entry is kept indefinitely as proof we honoured the deletion.
Transaction and tax recordsAs required by law, typically 7 years

After the 30-day grace period we permanently delete profile records, photos, private albums, voice notes, messages, matches, likes, contact hashes, push tokens, recovery email, Kind+ application records, and related app data. We keep only limited records where the law requires it or where they are necessary to defend a legal claim, prevent fraud, or enforce a ban — and we anonymise those wherever we can. Backups are overwritten on a rolling cycle and any residual copy is deleted within 90 days.

9. Your Privacy Rights

Wherever you live, you can use these controls at any time:

  • Edit or remove most profile information, photos, and your voice note in the app.
  • Hide your profile, pause your account, or delete it from Me → Privacy.
  • Turn contact blocking off and clear all uploaded contact hashes from Privacy settings.
  • Block, hide, or report another member from any profile or conversation.
  • Turn push notifications on or off by category in Notification settings, and in your device settings.
  • Manage or cancel a subscription in your Apple or Google account settings.

Legal rights, depending on where you live

Subject to law and to verification of your identity, you may have the right to: know what personal information we hold and how we use it; access it or receive a portable copy; correct inaccurate information; delete it; restrict or object to certain processing; opt out of sale, sharing, targeted advertising, or profiling with significant effects (we do not sell, share, or advertise, so there is nothing to opt out of); limit the use of sensitive personal information; withdraw consent at any time without affecting processing already carried out; and not be discriminated against for exercising any of these rights.

To make a request, email info@kind.date from the email address on your account, or send the request from inside the app. We will verify your identity — usually by confirming control of the phone number or email on the account — before acting, and we may ask for more information if we cannot verify you. An authorised agent may submit a request on your behalf with written permission signed by you, and we may still ask you to confirm it directly.

We respond within 45 days for California, Colorado, Connecticut, Virginia, and similar state requests, extendable once by a further 45 days with notice, and within one month for UK and EU requests, extendable by two further months for complex requests. We do not charge for a request unless it is manifestly unfounded or excessive. If we refuse a request, we will tell you why and how to appeal; you may appeal free of charge by replying to our decision, and we will respond to an appeal within 45 days (or 60 days in Colorado and Connecticut).

If you are in the UK, the EU, or the EEA

You also have the right to lodge a complaint with your local data protection supervisory authority. In the UK that is the Information Commissioner’s Office (ico.org.uk). We would appreciate the chance to address your concern first.

If you are in California

California’s "Shine the Light" law (Civil Code § 1798.83) lets you request details of personal information disclosed to third parties for their own direct marketing. We do not make such disclosures. California minors under 18 may request removal of content they posted; contact us and we will remove it from public view.

10. International Data Transfers

Kind is operated from the United States, and our servers and principal service providers are located there. If you use the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States and other countries whose data protection laws may differ from those of your own country.

Where we transfer personal information out of the UK, the EEA, or another jurisdiction that restricts transfers, we rely on an appropriate safeguard, normally the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, plus supplementary technical measures including encryption in transit and application-layer encryption of health-related fields. You may request a copy of the relevant safeguard by emailing us.

11. How We Protect Information

  • All traffic is encrypted in transit with HTTPS/TLS, and data is encrypted at rest by our infrastructure providers.
  • Health-related fields receive an additional layer of application-layer encryption before storage, with keys held separately from the database.
  • Row-level security policies restrict which records an authenticated account can reach.
  • Verification images and facial templates are never written to persistent storage.
  • Access to production systems is limited to authorised personnel, protected by multi-factor authentication, and logged.
  • We monitor for abuse and intrusion, rate-limit sensitive endpoints, and review security-relevant changes.
  • The app offers an optional device biometric or passcode lock, and screenshot protection on sensitive screens where the platform supports it.

No system can be perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant regulators as required by law and without undue delay.

12. Children

Kind is strictly for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18, and the Service is not directed to children. If we learn that an account belongs to someone under 18, we remove the account and delete the associated information promptly. If you believe a minor has given us information, contact us immediately at the address below. See also our Child Safety Standards.

13. Cookies and Website Analytics

The app and the website are different

This section is about kind.date, the public marketing website. The Kind mobile app — where your profile, messages, and HSV information live — contains no cookies, no analytics SDK, and no session recording of any kind.

No session recording, ever

Kind does not use Microsoft Clarity, Hotjar, FullStory, or any other session-recording, session-replay, or heatmap tool, on the website or in the app. Reading a page about herpes is nobody else’s business, and we will not reconstruct anyone’s browsing of this site. We also run no advertising pixels, no remarketing tags, no conversion tracking, and no social media tracking pixels of any kind.

The website uses strictly necessary cookies to serve pages and remember your preferences. Beyond those, this is the complete list of what the website can load:

TechnologyPurposeStatus
VercelHosting and request logs — IP address and request metadata, used to serve the site and spot abuseAlways on. Strictly necessary.
Google AnalyticsAggregate visitor counts and which pages are read. If it is ever switched on it runs with IP anonymisation, and with Google Signals, ad personalisation, and remarketing all disabled, so it cannot build an advertising profile.Currently switched off. No analytics runs on kind.date today.

Anything in that list runs only on the public marketing website, never inside the app, and never on a page that requires an account. If we ever switch aggregate analytics on, this section is what we update first.

You can block whatever you like using your browser’s cookie controls or private browsing, or by sending a Global Privacy Control signal, which we honour. Nothing on the website needs cookies beyond the strictly necessary ones, and blocking the rest changes nothing about what you can read or do.

14. Do Not Track and Global Privacy Control

There is no common industry standard for responding to browser Do Not Track signals, so the kind.date website does not respond to them. Because we do not sell or share personal information or engage in targeted advertising, an opt-out preference signal such as Global Privacy Control has no data for us to act on; we nonetheless honour such signals as an opt-out of any sale or sharing.

15. Changes to This Policy

We may update this policy as the Service or the law changes. We will post the new version with an updated effective date and version number. For material changes — particularly any change to how we handle health-related or biometric information — we will give notice in the app or by email before the change takes effect and, where the law requires it, obtain your consent. We will not apply a materially different use to information already collected without your consent.

16. Contact Us

Questions, requests, or complaints about privacy: email info@kind.date. Subtxt LLC is a Wyoming limited liability company operating remotely, so email reaches us fastest. We aim to acknowledge every privacy enquiry within five business days.