Privacy Policy
Last updated September 19, 2026
DatePic is a private-first date diary. This is the plain list of what leaves your phone, who touches it, and how to get rid of it.
What we collect
- Account: your email (or your Apple/Google sign-in identity), username, display name, and optional bio and city.
- What you make: date logs, plans, memories, ratings, photos, invites, comments, likes, and bucket-list items.
- Your home area, if you set one: a coarse coordinate saved to your account so we can suggest date spots near you.
- Device and app data: a push token if you turn notifications on, anonymous product analytics, and crash and performance diagnostics.
Who processes it
- Supabase: our database and photo storage.
- Google: Places for venue search, Gemini for the AI concierge.
- Google Sign-In: only if you choose that route to sign in.
- Apple: MapKit for address lookup, APNs for notifications.
- OpenFreeMap / OpenStreetMap: the map tiles
behind Your Map. Opening the map asks
tiles.openfreemap.orgfor the squares of map you are looking at, which tells them the rough area on your screen and your IP address. No account data, no photos and nothing you have written goes with them. We plan to move these tiles onto our own storage, and this line goes away when we do. - TelemetryDeck: anonymous product analytics.
That is the whole list. There is no ad network on it. Settings → What leaves your phone shows the same list inside the app, one section per destination, with what goes, what never goes, how long it is kept and how to get rid of it.
Photos
EXIF and GPS are stripped from every photo on your device before it uploads, so the location your camera writes into a file never reaches our servers. Diary photos are private to your account. Photos on a post you share to Discover are served over short-lived links to people allowed to see that post. Profile pictures are served from a public URL.
Location
Two separate things, and it is worth keeping them apart:
- The spot you're at. When you tap the location button, iOS gives us a coarse fix, roughly 100 metres. We use it for that one venue search.
- Your home area. If you set one, we save that coarse coordinate to your account and send it to Google Places as a search bias, so results are near you instead of nowhere. Change or clear it any time in Settings.
There is no background location. The app never asks for “Always” permission and contains no code that could use it.
Calendar
If you allow it, DatePic writes dates you've accepted to your calendar and keeps them current when a plan moves or gets called off. It reads back only the events it created. The seam it uses exposes no way to list or read anything else in your calendar.
The AI concierge
When you chat with the concierge, or write free-text notes on a plan, that text goes through our server to Google Gemini together with the plan's context (city, date, stops, vibes, budget) to generate suggestions. We don't keep the conversation on our servers, only a per-day request count so we can cap usage, and we don't train any model on it. Google processes it under its Gemini API terms. Treat it like any third-party service: don't type anything in there you wouldn't want processed off your phone.
Before anything reaches Gemini for the first time, DatePic asks. The answer is kept on this phone, per account, and never on a server, so a second device asks again. Until it is answered nothing is sent.
The concierge is an AI run by DatePic. It says so at the top of every conversation, it says so again in a conversation that runs for three hours, and it says so plainly if you ask it.
On your iPhone, and nowhere else
Two things are written by a model that never leaves this device: three suggested titles for a night you logged, and a short story of that night. They are written from that night's own details: its stops, the city, who was there, what you wrote afterwards. None of that is sent anywhere to do it. A story the model wrote carries a “Written by a model” mark until you edit it; a title you picked out of three is yours and carries none. On an iPhone that cannot run the model, neither offer appears.
Dictation
If you tap the microphone in the log form, what you say is turned into text on this iPhone and dropped into the story field for you to edit. Nothing is recorded, nothing is uploaded, and nothing is posted until you post it.
Notifications
If you turn on push, we store an Apple push token against your account so we can reach this device. Signing out removes it; deleting your account removes it.
Analytics and diagnostics
- Product analytics (TelemetryDeck) tell us which screens and flows get used. They're keyed to an anonymous install id, not your account and not your email, and that id is gone when you delete the app. No ads, no cross-app or cross-site tracking, nothing sold.
- Crash and performance diagnostics come from Apple's MetricKit: stack frames, counters, app version, OS version, device model. They upload with that same anonymous install id and are stored with no account column at all, and we don't correlate them back to you.
Things that stay on the device
Links you share into DatePic from other apps are read on the device. The share sheet contains no networking code at all; it hands the link to the app, which does the rest. The widgets cache a few photos in a shared app container so they can draw without waking the app; that container never leaves your phone.
Worth being plain about what those photos can be: a home-screen widget can show a picture from a date you shared, and on a shared date the photographer may be your partner rather than you. So a photo your partner took may be written into that shared container on your phone, shrunk down and one file at a time, because the widget runs in its own sandbox and cannot fetch anything itself. Only DatePic and its widget can read that container, nothing there is uploaded, and it is emptied when you sign out or delete your account.
What we don't do
We don't sell your data. We don't upload your contacts. There is no address-book code in the app. We don't run ad trackers, and we don't track you across other apps or websites.
Your controls
- Sharing is opt-in per date, and you can unshare.
- Block users and report content from anywhere in the app.
- Set, change, or clear your home area in Settings.
- Export your diary from Settings.
- Turn any category of notification off in Settings.
Deleting your account
Settings → Delete account. We remove your profile, posts, diary, comments, the plans and live dates nobody else joined, and the photo files behind all of it, and we delete your sign-in record. If a stored file resists deletion on the first pass, that failure is recorded and swept up afterwards rather than quietly left behind.
A plan or live date you shared with someone else is not deleted. It was their night too, so it is handed over instead of destroyed. One of the other people on it becomes its owner: your partner if it was the two of you, otherwise the first person who joined. They inherit the control you had over it: from that moment they can edit it, call it off, or delete it themselves.
One consequence of that is worth knowing before you tap the button: if you were keeping a plan a surprise, the handover ends the secret. Whoever inherits it reads it as its owner, which means the real title and the full itinerary, not the placeholder you set for them. Deleting your account is not a way to keep a surprise. Anything still cached on this device is cleared when you delete the app.
Changes
When what we collect changes, this page changes with it and the date at the top moves.
Contact
Questions or data requests: kanishka.sundar@gmail.com or Settings → Send feedback in the app.