Back

VOCAL DATING

Privacy Policy

Last updated: August 5, 2026

This notice explains what data VOCAL DATING collects, why, how long we keep it, and the rights you have. It is written to meet the UK GDPR and the Data Protection Act 2018.

Data controller: VOCAL DATING, trading name of [registered company name], company number [number], registered office [registered address, United Kingdom]. ICO registration [registration number]. Privacy contact: privacy@vocaldating.app.

Data we collect

  • Account: email, password (hashed), name, date confirmed 18+.
  • Profile: age, tags/interests, general area, photos, voice intro, bio, voice vibes, selected prompts.
  • Voice data: recordings you create (intro, voice messages) and a derived numeric "voice embedding" used to find vocal matches and detect duplicate accounts.
  • Verification data: photos or video frames captured during liveness checks, processed for identity verification only.
  • Usage: swipes, matches, messages, rooms joined, listens, reports, and app events used to improve the product.
  • Device & connection: IP, browser, device type, approximate location from IP and GPS, crash logs.
  • Payments: handled by our payment partner; we receive subscription status, not card numbers.

Special category data

Voice embeddings and liveness images are used to identify you uniquely, so we treat them as biometric special category data under Article 9 UK GDPR. We rely on your explicit consent (Article 9(2)(a)), collected separately during onboarding, and we have completed a Data Protection Impact Assessment for this processing. You may withdraw consent at any time by emailing us or deleting your account; we will delete the biometric data, though you will lose access to verified-only features. Your dating profile can also reveal information about your sex life or sexual orientation — you choose what to publish, and we process it on the basis of your explicit consent given when you complete your profile.

Why we use it (legal bases)

  • Provide the service, match you with people, deliver messages, host rooms — Art 6(1)(b) contract.
  • Detect fake or duplicate accounts, enforce rules, keep users safe, comply with the Online Safety Act 2023 — Art 6(1)(f) legitimate interests and Art 6(1)(c) legal obligation. We have carried out legitimate interests assessments and you may object at any time.
  • Voice biometrics, liveness verification and precise location — Art 6(1)(a) and Art 9(2)(a) consent.
  • Transactional emails — contract. Marketing emails and push notifications — consent under PECR, withdrawable at any time via the unsubscribe link or Settings.
  • Keeping tax and billing records — legal obligation.

Automated decisions & AI moderation

  • We use AI to transcribe and assess reported content and to rank potential matches. Match ranking has no legal or similarly significant effect on you.
  • No account suspension or permanent ban is applied by automation alone: a person reviews the case before a restriction is confirmed, in line with Article 22 UK GDPR.
  • You can ask for an explanation of a decision, contest it, and request human review at support@vocaldating.app.

Sharing

We do not sell your data and we do not use it for third-party advertising. We share it only with processors needed to run VOCAL DATING: cloud hosting and database, our payment partner, email delivery, push notifications, AI moderation, and product analytics. Each is bound by a written data-processing agreement meeting Article 28 UK GDPR. We disclose data to police, regulators or courts only where we are legally required to, or where it is necessary to protect someone's life.

Retention

  • Active account data: kept while your account is active.
  • Voice recordings & embeddings: deleted within 30 days of account deletion.
  • Messages: kept while either party has an account; deleted on account deletion.
  • Reports & moderation evidence: up to 12 months for safety enforcement.
  • Billing records: kept as required by tax law (typically 7 years).
  • Records of banned accounts (email hash and device identifiers only): up to 3 years to stop ban evasion.

Your rights under UK GDPR

  • Access a copy of your data, and have it corrected or erased.
  • Restrict or object to processing, including profiling based on legitimate interests.
  • Data portability for data you provided under consent or contract.
  • Withdraw consent at any time (biometrics, location, marketing).
  • Not be subject to solely automated decisions with significant effects.

Delete your account in Settings → Delete account. For any other request email privacy@vocaldating.app; we respond free of charge within one month (extendable by two months for complex requests, and we will tell you if that happens). If you are unhappy with how we handle your data you can complain to the Information Commissioner's Office: ico.org.uk/make-a-complaint, 0303 123 1113, Wycliffe House, Water Lane, Wilmslow SK9 5AF.

Security

Data is encrypted in transit (TLS) and at rest. Access is role-based, least-privilege and logged, and row-level security keeps your private data (phone number, precise location) accessible only to you. We test regularly and keep an incident-response plan. Where a personal data breach is likely to risk your rights we report it to the ICO within 72 hours and tell affected users without undue delay. No system is 100% secure — please use a strong unique password and report anything suspicious.

Children

VOCAL DATING is strictly 18+ and is not directed at children, so the ICO's Age Appropriate Design Code does not apply to intended users. We do not knowingly collect data from anyone under 18 and we delete such accounts and their data as soon as we become aware. If you believe a minor created an account, email privacy@vocaldating.app and we will act immediately.

Cookies & similar technologies (PECR)

Under the Privacy and Electronic Communications Regulations 2003 we only set storage that is strictly necessary for the service you asked for: sign-in tokens, session continuity, and a local cache of your own content so the app loads quickly. These are exempt from consent. We do not use advertising, tracking or third-party profiling cookies, and no consent banner is required. Product analytics are first-party, aggregated, and contain no cross-site tracking. You can clear this storage in your browser or by signing out.

International transfers

Your data is hosted in the UK/EEA where possible. Where a processor is outside the UK we rely on UK adequacy regulations or, failing that, the ICO International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with a transfer risk assessment. You can ask us for details of the safeguards used.

Changes

We will tell you about material changes by email or in-app before they take effect, and we will ask for fresh consent where the law requires it.