CIPHER Back
Log inCreate a free account

Privacy Policy

This document is provided in English. The English text is the legally binding version.

Last updated: 15 August 2026 · Version 2

1. Who is responsible

The controller of your personal data is AITailor OÜ, a company established in Estonia, which operates CIPHER at cipherdate.me. For anything in this policy, including exercising your rights, write to contact@cipherdate.me.

2. The short version

CIPHER is built so that you can look for a partner without exposing who you are. Other members see a handle you choose, not your name; your photos stay blurred to a new match, opening progressively as your mutual conversation builds trust; and the most sensitive things you write are encrypted at rest, never shown to anyone, and used for one purpose only: finding you compatible people. We run no advertising trackers and no third-party analytics, we set no third-party cookies, and we never sell your data. If you reached us by clicking one of our ads, we do record the click identifier from that link so we can tell the ad network the sign-up happened — that is described in section 3 and is the only advertising data we hold.

3. What we collect

  • Account: your email address, a hashed password (we cannot read it), your consent history (terms version, age confirmation, timestamps) and account status.
  • Profile: your handle, age, gender identity, who you want to meet, the approximate location and search radius you set, an age range, a short bio and your profile photo (plus a blurred version we generate from it).
  • Private preferences (your “Vault”): what you desire and your hard and soft limits. This is data about your sex life and sexual orientation — a special category under Article 9 GDPR. It is encrypted at rest, is never displayed to other members or to staff interfaces, and is processed only as described in section 4.
  • Content and activity: photos and posts you publish, comments, hearts, pins, your chats with matches, personal adverts and responses to them (including when you last published an advert, kept to apply the posting interval for free accounts), members you have blocked, your per-match choice about viewing flagged media, notifications, and reports you file or that are filed about your content. Live rooms are an exception by design: we process who is present, but what is said in a room is not stored at all.
  • Payments: your membership tier, subscription periods and a ledger of transactions and credit grants. Payment itself happens at our payment provider; we never receive your card number.
  • Technical: your IP address, processed transiently for security and rate limiting, and — on your first visit only — looked up against a country database on our own servers to suggest a language. Your browser stores your login tokens; the site language you pick is also saved with your account, so the service (including the AI-written conversation openers) can use it.
  • Advertising attribution: if you arrived by clicking one of our ads, the link carries a click identifier generated by the ad network. Your browser keeps it for up to 90 days and sends it once, when you sign up, so that we can report back that the click led to a registration. We store it against your account and report the click identifier and the time — never your email address, profile or anything you write. We do not use it to build a profile of you, we do not receive anything about you from the ad network in return, and it is deleted with your account. Arriving any other way stores nothing at all.

4. How matching works, and your explicit consent

Matching is the service, so this is the processing that matters most. The preferences you save — including your Vault text — and your profile choices are converted by automated means into numerical representations that can be compared for similarity. Those similarity scores decide which members we suggest to you, whom your posts and personal adverts are visible to, and who is considered for a live room. The people we suggest never see your Vault — they see the fact that you are compatible, and a short AI-generated conversation hint derived from both members’ Vault text, produced under instructions not to reveal either member’s answers. A plain-language walkthrough of this processing is at cipherdate.me/privacy-ai.

Because this involves data about your sex life and orientation, we process it on the basis of your explicit consent (Article 9(2)(a) GDPR), which you give when you create your account and fill in these fields. Filling them in is voluntary — the more you share, the better the matching — and you can withdraw consent at any time by clearing the fields or deleting your account. No decision with legal or similarly significant effect is made about you this way; matching only ranks suggestions inside the service.

5. Automated screening

To keep the service lawful and safe we screen content automatically before it is shown: images are classified for illegal and adult material (an image flagged as child sexual abuse material is blocked on upload, sealed as evidence and escalated to a designated staff reviewer who reports confirmed cases to the competent authorities after human verification; other adult material gets an audience rating), and text is screened too — personal adverts and profile bios for contact details, commercial solicitation and illegal asks, and opening responses to adverts and comments on posts additionally for abusive language. Content that fails text screening is not shown; adverts, responses and comments that fail go to a human moderator for the final decision, and the screening verdict is stored with them. We count blocked attempts per account to spot repeat abuse. Access to flagged material is restricted and every access is recorded. Details of the moderation process are in the Terms of Service, section 10.

6. What other members can see

Your handle (or “Anonymous” if you have not set one), your age, an indication of compatibility, and the content you publish to the audience it is published to. Your photo is shown blurred to a new match and becomes visible progressively as your mutual conversation builds trust. Your email, location coordinates and Vault are never shown to anyone. Staff access to member data is limited by role and every administrative action is recorded in an audit log.

7. Processors and international transfers

  • OpenAI (USA) processes text you save and images you upload to compute the compatibility representations, content ratings and screening verdicts described above, under a data processing agreement. API content is not used by OpenAI to train models. Transfers rest on the EU–US Data Privacy Framework and standard contractual clauses.
  • Hosting and storage run on our own infrastructure in the EU, including media storage.
  • Payment provider: payments are processed by AS LHV Pank’s payment gateway (bank links and cards) as an independent controller under its own privacy terms. We receive confirmation that a payment succeeded and its reference — never your card number or bank credentials.
  • The language suggestion uses a GeoLite2 country database from MaxMind stored on our servers — your IP address is not sent to MaxMind or anyone else for this.

8. Legal bases

  • Contract (Art. 6(1)(b)): running your account, matching, chat, feed, personals, live rooms, memberships and payments.
  • Explicit consent (Art. 9(2)(a)): the special-category processing in section 4.
  • Legitimate interests (Art. 6(1)(f)): security, rate limiting, abuse prevention, content screening records and moderation audit trails — keeping the service safe for everyone; and measuring which of our own ads brought people here, which we keep to the single click identifier described in section 3 precisely so it stays proportionate to that interest.
  • Legal obligation (Art. 6(1)(c)): accounting records, mandatory reporting of illegal material, responding to lawful requests from authorities.

9. How long we keep data

Everything lives as long as your account does, and you can delete content yourself at any time. Deleting your account erases it immediately and irreversibly: profile, Vault, photos, posts, matches and conversations (including for the people you talked to), credits and notifications. Three things outlive deletion: an irreversible cryptographic hash of your email address (so we can recognise abusive re-registration — it cannot be turned back into your address), transaction records we must keep under accounting law (seven years in Estonia), and content removed by moderation or preserved as evidence of illegal activity, which is quarantined for as long as the law requires.

10. Your rights

You can access, correct and delete your data yourself: your profile and Vault are editable in place, “Your data” on the profile page downloads a machine-readable export (your account, profile, Vault, the messages you sent, your posts and your transaction ledger — messages other people sent you are their personal data, so they are not in your export), and the same page deletes your account. Beyond that, you have the GDPR rights of access, rectification, erasure, restriction, portability and objection, and the right to withdraw consent at any time without affecting past processing — write to contact@cipherdate.me. You can complain to your local supervisory authority or to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee).

11. Security

Vault content is encrypted at rest; passwords are stored only as strong hashes; connections are encrypted in transit; staff access is role-gated and audit-logged; and abuse is throttled by rate limiting. No system is perfectly secure — if a breach ever puts you at risk, we will notify you and the supervisory authority as the GDPR requires.

12. Cookies and local storage

We use no cookies for tracking or advertising. Your browser’s local storage holds only what the service needs to work: your login session and your chosen language. These are strictly necessary and set no consent banner in motion.

13. Minors

CIPHER is for adults only. We do not knowingly process data of anyone under 18; such accounts are deleted as soon as we learn of them.

14. Changes

If we change this policy in a way that matters, it gets a new version and you will be asked to review and accept it before continuing to use the service.

15. Contact

AITailor OÜ (Estonia) · CIPHER · cipherdate.me · contact@cipherdate.me. We answer in English or Estonian.

Create a free account
HomeAI Cupid at workFAQAbout usTerms of ServicePrivacy Policy