Ghosted – Privacy Policy
Effective 14 September 2026. This Policy replaces every earlier version.
The short version
(a convenience summary; the full text below is what counts)
- Disket France, Paris, is the company responsible for your data (the “controller” under the GDPR).
- We collect what a dating app needs: your profile, photos, approximate location, messages, and how you use the app. We do not sell your data.
- Photos are checked by automated tools and humans to keep filters and AI out. Everyone's photos, including yours.
- Your data is hosted in the European Union and the United States by providers bound by contract. Transfers are protected by EU standard clauses or the EU-US Data Privacy Framework.
- Delete your account in the app and your profile, photos and messages are gone within 30 days.
- Questions or requests: hello@ghosted.co.
1 - Who is responsible
The controller of your personal data is Disket France, SAS, RCS Paris 944 134 329, 67 rue d'Aboukir, 75002 Paris, France. You can reach the person in charge of privacy at hello@ghosted.co or at the postal address above.
This Policy covers the Ghosted mobile app (iOS and Android), the ghosted.co website and our support channels. It is written for adults: Ghosted is 18+ and we do not knowingly process data about minors (see section 10).
2 - What we collect
2.1 What you give us
- Account: sign-in method (Apple, Google, phone number or email), the identifier and email or phone number it returns, your date of birth, your first name, your gender and who you want to meet.
- Profile: your photos, your bio, and optional details you choose to add (height, job, education, interests, lifestyle, zodiac sign, prompts and answers). Some of these can reveal sensitive information, such as religion, sexual orientation or ethnicity. You choose whether to share them; by adding them to your profile you agree that we show them to other members and use them as described here.
- Messages: the texts, photos, voice notes and other content you exchange with matches.
- Purchases: the subscription or items you bought, the price, the date and a store transaction identifier. We never receive your card number.
- Support: what you write to us, and reports you make about other members.
2.2 What we collect when you use the app
- Location: with your permission, your device's approximate location, used to show you people nearby and your distance to them. You can turn it off in your phone settings; some features then stop working.
- Activity: swipes, likes, matches, roses sent, profiles viewed, features used, screens seen, time and frequency of use.
- Device and technical data: device model, operating system, language, app version, IP address, time zone, push token, crash logs, and identifiers such as the advertising identifier (IDFA on iOS, only if you allow tracking; GAID on Android) and a random app-instance identifier.
- Photo analysis results: the output of our moderation tools on each photo (for example a score for filters, edits or AI generation, and face detection to check that the photo shows a person). We do not create biometric templates to identify you across the web.
2.3 What we get from others
- Apple and Google when you sign in or buy something (identifier, email, purchase status).
- Our attribution partner when you install the app after seeing an ad (which campaign brought you, on which network), so we know which advertising works.
- Other members, when they report you or mention you in a report.
3 - Why we use it, and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Create and run your account, show your profile to others, make matches, deliver messages and notifications | Account, profile, activity, location, device | Performance of our contract with you (art. 6.1.b) |
| Check that photos are real and unedited, detect fake profiles, minors, scams and behaviour that breaks our rules | Photos and analysis results, profile, messages when reported, activity, device | Legitimate interest in a safe and honest service (art. 6.1.f); legal obligations under the Digital Services Act and child-protection laws (art. 6.1.c) |
| Process purchases, subscriptions and roses, prevent fraud | Purchases, account | Contract (art. 6.1.b); legal obligations in accounting and tax (art. 6.1.c) |
| Understand how the app is used and improve it, fix crashes | Activity, device, crash logs | Legitimate interest (art. 6.1.f) |
| Measure our advertising campaigns | Device identifiers, install and purchase events | Consent where the law requires it (the iOS tracking prompt, art. 6.1.a); otherwise legitimate interest |
| Send you service emails and push notifications (matches, messages, security) | Account, push token | Contract (art. 6.1.b). Marketing notifications rely on consent and can be switched off in the app |
| Answer your requests, handle reports and appeals | Support data, related account data | Contract and legitimate interest |
| Comply with the law, respond to authorities, defend our rights | Any of the above, as needed | Legal obligation (art. 6.1.c); legitimate interest |
Sensitive data you choose to put on your profile (section 2.1) is processed on the basis of your explicit consent (art. 9.2.a), which you withdraw by removing the information or deleting your account.
4 - Automated decisions and photo moderation
We use automated tools to score photos for filters, retouching and AI generation and to flag suspicious accounts. A high score can lead to a photo being rejected or blurred automatically. Decisions that close an account, or that affect a paid feature, are reviewed by a person before or promptly after they take effect. You can always ask for a human review and explain your case at hello@ghosted.co. Our matching shows you profiles based on your preferences, your distance, your activity and the activity of others; it does not use sensitive data as a ranking factor.
5 - Who sees your data
5.1 Other members
Your profile (photos, first name, age, distance, bio and the details you added) is visible to members whose preferences you match. Your messages are visible only to the match you sent them to. Members can report or screenshot what they see; the Community Guidelines forbid sharing it, but we cannot technically prevent it.
5.2 Our providers (processors)
We rely on companies that process data on our behalf, under contracts that limit what they can do with it:
| Provider | What for | Where |
|---|---|---|
| Supabase | Database, authentication and file storage for the app | European Union |
| Stream (Stream.io) | Real-time chat infrastructure | EU / US |
| OneSignal | Push notifications | US |
| RevenueCat | Subscription and purchase management | US |
| Adjust | Advertising attribution and campaign measurement | European Union |
| PostHog | Product analytics | European Union |
| Sentry | Crash and error reporting | EU / US |
| Amazon Web Services, Cloudflare, Vercel | Hosting, content delivery, website | EU / US |
| Photo and content moderation services | Detection of filters, AI generation, nudity and unsafe content | EU / US |
| Apple, Google | Sign-in, payments, app distribution | Worldwide, under their own policies |
The list changes as we change providers; the current version is always the one on this page.
5.3 Advertising partners
When we advertise Ghosted on networks such as Apple Search Ads, Meta, TikTok or Google, our attribution partner matches installs to campaigns using device identifiers. On iOS this only happens if you accept the tracking prompt. We do not show other members' data to advertisers, and we do not sell personal data.
5.4 Authorities and legal requests
We disclose data to police, courts or regulators when we are legally required to, or when we believe in good faith that it is necessary to protect someone's safety, in particular in cases involving minors, violence or fraud. We report apparent child sexual abuse material to the competent authorities.
5.5 Change of ownership
If Disket France is acquired, merges or sells the Ghosted business, your data may be transferred to the new owner under this Policy; we will tell you before that happens.
6 - Transfers outside the European Union
Some providers are in the United States or process data there. For those transfers we rely on the European Commission's adequacy decision for companies certified under the EU-US Data Privacy Framework, and otherwise on the Commission's Standard Contractual Clauses with additional safeguards. You can ask us for a copy of the relevant safeguards at hello@ghosted.co.
7 - How long we keep it
| Data | Kept |
|---|---|
| Profile, photos, matches, messages | While your account exists, then deleted within 30 days of deletion (backups are overwritten within 90 days) |
| Purchase records | 10 years, as required by French accounting law |
| Reports, moderation decisions and bans | Up to 3 years after the decision, to handle appeals and stop banned people from coming back; kept longer if a legal case is open |
| Data about apparent child sexual abuse material | As required by the reporting laws that apply (typically 12 months after the report) |
| Technical logs and analytics | 12 months, then deleted or anonymised |
| Support conversations | 3 years after the last exchange |
| Inactive accounts | Deleted after 24 months without a sign-in, after a warning |
8 - Your rights
Wherever you live, you can:
- access the data we hold about you and get a copy (in the app, or by asking us);
- correct it (most of it directly in your profile);
- delete it, by deleting your account in the app or by asking us;
- object to processing based on our legitimate interests, and to marketing at any time;
- restrict processing in the situations the GDPR provides for;
- receive the data you gave us in a portable format;
- withdraw a consent at any time, without affecting what was done before (tracking in your phone's settings, notifications in the app, sensitive profile details by removing them);
- tell us how you want your data handled after your death (French law).
Write to hello@ghosted.co from the email linked to your account, or from the app. We answer within one month, extended by two months for complex requests, and we may ask you to confirm your identity. You can also complain to the French data protection authority, the CNIL (3 place de Fontenoy, 75007 Paris, cnil.fr), or to the authority of the country where you live.
Members in the United Kingdom have equivalent rights under the UK GDPR and can complain to the ICO. Members in California and other US states with privacy laws can exercise the rights of access, deletion, correction and portability described above; we do not sell or share personal data for cross-context behavioural advertising as those laws define it, and we do not discriminate against members who exercise their rights.
9 - Security
Data is encrypted in transit and at rest with our providers. Access inside Disket France is limited to the people who need it for moderation, support and engineering, under confidentiality obligations. Photos in chats are stored in private storage and served through expiring links. No system is perfectly secure: if we learn of a breach that puts you at risk, we tell you and the CNIL as the law requires.
10 - Minors
Ghosted is strictly for adults aged 18 and over. We ask for your date of birth at sign-up, use automated signals to detect underage members, and close any account we reasonably believe belongs to a minor, deleting its data. If you know of a minor using Ghosted, report the profile in the app or write to hello@ghosted.co. Our commitments against child sexual abuse and exploitation are set out on the Child Safety page.
11 - Cookies and the website
The app does not use cookies. The ghosted.co website uses only the technical storage needed to serve pages and, if we enable analytics, privacy-preserving measurement without cross-site tracking; we will ask for your consent before setting any non-essential cookie. Links to the App Store and Google Play take you to Apple's and Google's sites, under their policies.
12 - Changes
We may update this Policy when the app, our providers or the law change. For significant changes we notify you in the app or by email at least 30 days before they apply. The date at the top always tells you which version you are reading.
13 - Contact
Disket France, 67 rue d'Aboukir, 75002 Paris, France. Email: hello@ghosted.co.