Legal
Privacy policy
Effective 6 July 2026
1:1 is a dating app built on a simple idea: one person at a time, chosen by an AI matchmaker that pays attention. Paying attention requires data — so this policy is written to be read, not skimmed. It explains exactly what we collect, why, where it goes, and how to take it back.
01Who we are
The 1:1 app and this website are operated by Foways (“we”, “us”), reachable at [email protected]. Foways is the data controller for the personal data described in this policy.
02What we collect
Things you give us
- Account & profile — your phone number (used for sign-in via a one-time WhatsApp code), first name, date of birth, gender, city, country and line of work.
- Photos — the three profile photos you choose to show a match.
- Verification selfie — a selfie captured during onboarding, used only for identity verification (see section 3).
- Conversations — your chats with your AI matchmaker and with your match, including voice notes you record.
- Reports — anything you send us when you report or block another member.
Things the app derives
- Personality profile — a five-dimension (Big-Five) personality estimate inferred from your conversations with the matchmaker.
- Learnings — short, structured notes about your preferences and values (for example, “prefers slow mornings”), extracted from what you tell the matchmaker and used to choose and describe your matches.
- Voice transcripts — text versions of your voice notes, produced by a speech-to-text processor.
- Translations — translated versions of messages and app text when you use the app in a language other than English.
Things collected automatically
- Usage analytics — screens visited and product events, collected via PostHog to understand how the app is used.
- Crash & error data — diagnostic reports via Sentry when something breaks.
- Push token — a device token so we can send you notifications, if you allow them.
- Operational traces — internal logs of app operations and AI calls, kept briefly for reliability, cost accounting and abuse prevention (see section 7).
This website itself sets no analytics or advertising cookies. The only thing it stores on your device is your light/dark theme preference, kept locally in your browser.
03Face verification & biometric data
In plain words
We check that every profile belongs to one real, living person. To do that, we process face geometry from your selfie and photos — biometric information — with your explicit consent, given in the app before the check runs.
During onboarding (and if you later change your photos), we:
- run a liveness check to confirm the selfie is a live capture, not a photo of a photo;
- compare the selfie against your profile photos to confirm they show the same person;
- search the face against verified accounts to enforce one person, one profile and estimate gender consistency with your stated profile.
This processing is performed by Amazon Web Services (AWS Rekognition) in the AWS Mumbai region (ap-south-1) acting as our processor. A mathematical representation of your face (a “face vector” — not a photo) is stored in our private verification index for as long as your account exists, solely to prevent duplicate and impersonated accounts. It is never used for advertising, never sold, and never shared with other members. When your account is deleted, the face vector is deleted with it.
If you decline face verification you can still edit your profile and photos, but you cannot complete onboarding, meet your matchmaker, or be matched — verification is what keeps 1:1 free of bots and impersonation.
04How AI uses your data
The AI is the product, so we are precise about what it sees. Your conversations, profile details, photos (as short written captions), personality profile and learnings are processed by large language models to:
- hold the matchmaker conversation with you (persona “Sam” or “Sky”);
- infer and refine your personality profile;
- choose and explain your match, and write compatibility deep-dives;
- stand in for you when you are away — always visibly labelled to the other person by name (your “Sam” or “Sky”), never pretending to be human;
- transcribe and translate what you say.
Model requests are routed through OpenRouter to AI providers (including Anthropic, DeepSeek and xAI), configured so that your data is not used to train their models. Each request carries only what that task needs. Match selection is automated by design — that is the product you sign up for — but it only ever decides introductions, never punitive outcomes. If you believe an automated decision affected you unfairly, write to [email protected] and a human will review it.
05Why we process data
| Purpose | Examples | Legal basis |
|---|---|---|
| Providing the service | Accounts, matching, chat, notifications, translations | Contract |
| Identity verification | Liveness, face match, duplicate prevention | Explicit consent |
| Safety & integrity | Report handling, blocks, abuse prevention, fraud detection | Legitimate interest / legal obligation |
| Improving the product | Analytics, crash reports, AI quality evaluation | Legitimate interest |
| Communications | Service messages, match notifications | Contract / consent (push) |
06Who we share it with
We do not sell personal data, and we do not share it with advertisers. Data goes to three places only:
- Your match — sees your three photos, first name, age, work, city and what you say to them (including what your matchmaker says on your behalf when you are away).
- Processors — services that run 1:1 under our instructions: Convex (application backend, EU West), Cloudflare (media storage & delivery), AWS Rekognition (face verification, Mumbai), OpenRouter and its underlying AI providers (matchmaking intelligence), Deepgram (speech-to-text), Google Firebase Cloud Messaging (push), Authkey (WhatsApp one-time codes), PostHog (analytics) and Sentry (crash reporting).
- Authorities — if required by law, or where necessary to protect the safety of our members (see our child safety standards).
07Retention
- Messages — moved from live storage into a private archive after 30 days; deleted with your account.
- Operational traces — deleted after 30 days (90 days for error traces).
- Account data, photos, personality profile, learnings, face vector — kept while your account exists; deleted when you delete your account (see below).
- Safety records — reports and enforcement records may be retained after account deletion where we have a legal obligation or a live safety need.
Deleting your account (how to) removes your profile, photos, conversations, personality data, learnings and biometric verification data within 30 days of the request, except where law requires longer.
08Your rights
Depending on where you live (including under the EU/UK GDPR and India's Digital Personal Data Protection Act), you can:
- access a copy of your data;
- correct it — profile fields are editable in the app;
- delete it — in the app or by request;
- withdraw consent (including for face verification and push) at any time;
- object to or restrict certain processing;
- complain to your data-protection authority.
To exercise any of these, use the in-app controls on the Me tab (Delete account at the bottom; chat and profile data controls under Data) or email [email protected] — include the phone number your account is registered to so we can verify it's you. We respond within 30 days.
09Security
All traffic is encrypted in transit (TLS). Media lives in private object storage and is served only through short-lived signed links. Sessions use scoped tokens stored in your device's secure storage. Internal logs are redacted of personal identifiers where feasible, access to production systems is restricted, and every AI call is traced so unusual behaviour is noticed. No system is perfectly secure — if we learn of a breach that affects you, we will notify you as the law requires.
10Children
1:1 is strictly for adults 18 and over. We do not knowingly collect data from anyone under 18. Every member declares a date of birth showing they are 18 or older, live face verification deters fake and impersonated accounts, and accounts suspected of belonging to minors are prioritised for human review and removed. If you believe a minor is using 1:1, report it in-app or write to [email protected] — see our child safety standards.
11International transfers
Our backend runs in the EU (eu-west-1); face verification runs in India (ap-south-1); some processors (AI providers, analytics, crash reporting, push) operate in the United States. Where data crosses borders we rely on the processor's applicable transfer safeguards, such as standard contractual clauses.
12Changes & contact
If we change this policy in a way that matters, we will tell you in the app before it takes effect. The effective date at the top always reflects the current version.
Questions, requests, complaints: [email protected]. For India's Digital Personal Data Protection Act, grievances go to the same address — mark the subject “Grievance” and it is routed to our grievance officer.