ValuePair

Legal

Privacy Policy

Last updated: August 11, 2026

This Privacy Policy explains how ValuePair ("ValuePair," "we," "us") collects, uses, discloses, and protects your personal information when you use ValuePair, and the choices and rights you have. ValuePair is a values-based friendship and connection service intended for adults (18+).

This is a pre-launch beta.

ValuePair is currently a free, privately operated, non-commercial test. It accepts no payments and carries no advertising. Features may change and data created during the beta may be reset before public launch. You can export or permanently delete your data at any time from Settings.

Who is responsible (controller)

The controller responsible for your data under the EU General Data Protection Regulation (GDPR) is:

Marcel Hanfc/o flexdienst – #21549Kurt-Schumacher-Straße 7667663 KaiserslauternDeutschland

You can also reach us through the contact form.

Information we collect

We collect the following categories of personal information:

  • Account details. Your name or chosen display name, unique @handle, email address, and password (stored only as a salted hash). We record whether your email has been verified.
  • Profile & identity. Your date of birth (used to confirm you are 18+ and is not shown to other users as a raw date), gender identity (including any self-description), the genders you are looking to connect with, and your approximate location: a city you select, resolved to a coarse city-center coordinate and country. We never collect or store your precise street address or live GPS location.
  • Values answers. Your responses to the onboarding values questionnaire (including how important each topic is to you), your answers and optional free-text notes in the 14-question conversation deck, and answers to any shared question sets you play with a match.
  • Messages & connections. Chat messages you send, connection and photo-reveal consents, and interaction signals such as meet intents and check-in nudges.
  • Photos. Photos you upload. We re-encode them and strip embedded metadata (including any EXIF/GPS data) on upload, and we keep them private: they are only revealed to a match after a full conversation and only with mutual consent.
  • Preferences. Your match filters (including blocked countries), preferred check-in pace, and notification/email preferences, including your product-email consent choice and its change history.
  • Safety data. Blocks you create and reports you submit (including the category and any details you provide).
  • Technical & usage data. IP address, browser/user agent, session information, a native-app push registration token if you enable push notifications, and in-product analytics events about how the service is used.

Sensitive personal information

Some information you provide is special-category data under Article 9 of the GDPR: information reflecting your worldview or beliefs and information revealing your sexual orientation (such as your gender and the genders you seek), including what can be inferred from your answers. We process it only with your explicit consent (Art. 9(2)(a) GDPR).

You give this consent during onboarding, and we use the data only to operate the core matching and connection service: to find compatible people and show you where your values align. We do not use it for advertising, and we do not sell it. You can withdraw this consent at any time in Settings, which removes you from matching; we keep an internal record of when consent was given or withdrawn.

US state privacy laws likewise treat this information as sensitive and restrict its use.

How we use your information

  • To create and secure your account and authenticate you.
  • To build your values portrait and automatically match you with one compatible person at a time.
  • To run the answer-then-reveal conversation, connected chats, and shared question sets.
  • To deliver notifications and transactional or service emails you have not opted out of.
  • To send occasional product news, beta invitations, and feedback requests only when you have actively opted in to those emails.
  • To keep the community safe: handling blocks and abuse reports, and preventing re-matching people who have parted.
  • To understand and improve how the product is used, using aggregate and event-level analytics.
  • To comply with legal obligations and enforce our Terms.

Legal bases (GDPR)

We process your personal data on these legal bases:

  • Art. 6(1)(b): to provide the service you signed up for (your account, matching, conversations, and service emails such as password reset).
  • Art. 6(1)(a) together with Art. 9(2)(a): your explicit consent for the values, worldview, and orientation data described above, including what can be inferred from your answers. You can withdraw it anytime in Settings.
  • Art. 6(1)(f): our legitimate interest in keeping the service secure and abuse-free (your session IP address and browser data, transient rate limiting, blocks and reports, and the optional notification emails you can turn off).
  • Art. 6(1)(a): your consent to native push notifications, given only when you enable them. You can withdraw it in the app or your device settings.
  • Art. 6(1)(a): your optional consent to product news, beta invitations, and feedback requests by email. It is separate from service emails and you can withdraw it at any time in Settings or through the signed unsubscribe link.
  • Art. 6(1)(a) and § 25(1) TDDDG: for analytics cookies, only after you accept the cookie banner.

How we share information

We do not sell your personal information. We share it only:

  • With people you are matched or connected with: the parts of your profile, values answers, and (once mutually unlocked) photos that the product is designed to reveal.
  • With service providers who host and operate the service on our behalf (for example, our hosting/database provider, our email and push-notification delivery providers, and (only if enabled and you consent) an analytics provider). They may process your information only to provide services to us.
  • For legal and safety reasons: to comply with law, respond to lawful requests, or protect the rights, safety, and security of our users, the public, or ValuePair.
  • In a business transfer: if we are involved in a merger, acquisition, or sale of assets, subject to this Policy.

Hosting

ValuePair runs on servers of Hetzner Online GmbH, Industriestraße 25, 91710 Gunzenhausen, Deutschland (a processor under an Art. 28 data processing agreement). All servers are located in Germany. Our web server keeps no persistent access logs; IP addresses are processed transiently to protect against attacks and abuse (rate limiting) and are stored together with your sign-in session. The legal basis is Art. 6(1)(f).

Email delivery

Transactional and service email (password reset, notifications) is sent through Amazon SES (Amazon Simple Email Service), provided by Amazon Web Services EMEA SARL, 38 Avenue John F. Kennedy, L-1855 Luxembourg, an EU processor under an Art. 28 data processing agreement. Email is processed in Amazon’s Europe (Stockholm) region. As AWS belongs to a group with a US parent, some data may be transferred to Amazon Web Services, Inc. in the USA under the EU-US Data Privacy Framework, under which AWS is certified (an adequacy decision, Art. 45 GDPR). We send occasional product news, beta invitations, and feedback requests only if you actively opt in. This choice is separate from activity and service emails. We record when, where, and under which notice version you granted, declined, or withdrew consent. You can withdraw in Settings or through the signed marketing unsubscribe link. Activity emails have their own setting and unsubscribe link.

Native push notifications

If you enable native push notifications, we use Firebase Cloud Messaging (FCM), provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Google acts as our processor under the Firebase Data Processing and Security Terms. We send FCM a pseudonymous device registration token and the notification payload: the ValuePair title, a short status message that may include your match’s display name, an app-relative destination, the event type, and a random delivery identifier. We do not send chat-message bodies, question answers, email addresses, or profile answers in a push.

FCM uses an app-installation identifier to route the notification and operates on Google’s global infrastructure, so processing may occur outside the EEA. Restricted transfers are covered by the safeguards in Google’s Firebase Data Processing and Security Terms, including applicable standard contractual clauses. The legal basis is your consent (Art. 6(1)(a) GDPR). You can turn push off in the app or your device settings. We remove stale registration tokens from our server after 60 days and logical delivery/open records after 90 days; account deletion removes both immediately from ValuePair.

Signing in with Google or Apple

You can choose to create your account or sign in using Google or Apple. If you do, that provider authenticates you and sends us your basic profile information: your name, email address, and whether that email is verified (and, for Google, your profile picture). We use it only to create and secure your account, exactly as we would with an email and password. Using a social sign-in is optional; you can always register with an email address and password instead.

With Apple, you can use “Hide My Email” so that Apple shares only a private relay address instead of your real one; email we send to it is forwarded to you by Apple. Sign in with Apple is provided by Apple Inc. (One Apple Park Way, Cupertino, CA 95014, USA).

When you use one of these options, the provider processes your data as an independent controller for the sign-in itself, under its own privacy policy: Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) for Google, and Apple for Apple. Data may be transferred to the USA (Google LLC, and Apple) under the EU-US Data Privacy Framework (an adequacy decision, Art. 45 GDPR). The legal basis for our processing of the profile data we receive is Art. 6(1)(b) GDPR (to provide the login you asked for). You can disconnect either connection at any time from your Google or Apple account settings.

Cookies & analytics

We use a small number of strictly necessary cookies to keep you signed in and secure, and to remember a language you explicitly choose. If you select the browser-language option, we remove the language preference cookie.

If analytics are enabled, we use Google Analytics 4, provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Irland). It loads only after you accept the cookie banner; the legal basis is Art. 6(1)(a) GDPR and § 25 Abs. 1 TDDDG. Data may be transferred to Google LLC in the USA under the EU-US Data Privacy Framework (an adequacy decision, Art. 45 GDPR). You can decline, and you can withdraw consent later in Settings, which clears the analytics cookies. We do not use cookies for third-party advertising.

When you contact us

When you email us or use the contact form, we process your email address, your name if you give it, and your message, only to answer the enquiry (Art. 6(1)(b) if it concerns your account or contract, otherwise Art. 6(1)(f)). Enquiries are deleted once resolved unless a legal retention duty applies. Our contact inbox is hosted by Proton AG, Genf, Schweiz; the EU has an adequacy decision for Switzerland (Art. 45 GDPR).

Your privacy rights

Under the GDPR you have the right to access your data (Art. 15), rectify it (Art. 16), erase it (Art. 17), restrict its processing (Art. 18), receive a portable copy (Art. 20), and object to processing (Art. 21).

You can exercise the core rights directly in the product:

  • Access / portability: download a JSON copy of the account and service data available through our self-service export from Settings → Your data.
  • Deletion: permanently delete your account and associated data from the same Settings section.
  • Withdraw consent: withdraw sensitive-data consent or analytics consent in Settings.
  • Email opt-out: manage activity emails and optional product emails separately in Settings, or use the signed channel-specific unsubscribe link in any email.

For a full Article 15 access request, including personal data in retained safety reports where it can lawfully be disclosed, use the contact form or contact us at . We may redact only the parts necessary to protect the rights and freedoms of other people, including reporters and witnesses.

Right to object (Art. 21 GDPR): where we process data on the basis of legitimate interests, you can object at any time for reasons arising from your particular situation, and we will stop unless we have compelling legitimate grounds that override your interests.

You can also complain to a data protection supervisory authority at any time, in particular in the German state or EU member state where you live (Art. 77 GDPR).

If you live in the US, you may also have rights to access, correct, delete, and port your information, and to limit the use of sensitive data. We do not sell or share your personal information for cross-context behavioral advertising. You may make a request or appeal a decision by contacting us at .

Data retention

We keep your personal information for as long as your account is active and as needed to provide the service. When you delete your account, we delete your account data, including product-email consent records, and remove your uploaded photo files. An abuse report filed by someone else may be retained where necessary for safety review, legal compliance, or the establishment, exercise, or defense of legal claims. Account deletion removes the direct subject account ID, but reporter-written details may still contain identifying context. Removing that ID does not necessarily make free text anonymous.

We review ordinary new abuse reports within 30 days. Child-safety reports are escalated for prompt review. We re-review retained evidence at least every six months. We delete report evidence as soon as it is no longer necessary, and normally no later than 24 months after the report was filed. We keep it longer only while an active investigation, dispute, legal claim, or legal retention duty requires it, and we document that reason during review.

Contact enquiries are deleted once they are resolved, and our web server keeps no persistent access logs.

Security

We use technical and organizational measures to protect your information, including encrypted transport, hashed passwords, private photo storage separated from public assets, and access controls on the paths that touch other users’ data. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Children

ValuePair is for adults. You must be at least 18 years old to use it, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 has used the service, contact us at and we will take appropriate action.

Automated matching

Matching runs fully automatically based on your answers and preferences. It introduces people, and it produces no legal or similarly significant effects for you in the sense of Art. 22 GDPR. You can end any match yourself and leave the pool at any time.

Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. A policy update does not create consent for optional processing. Where consent is required, we will ask you separately.

Contact us

For any privacy question or request, use the contact form, email , or write to us at:

Marcel Hanfc/o flexdienst – #21549Kurt-Schumacher-Straße 7667663 KaiserslauternDeutschland

Back to top