Privacy Policy
Last updated: 5 October 2026 · Effective: 5 October 2026
This Privacy Policy explains how Twoman ("Twoman", "we", "us", or "our") collects, uses, shares, and protects information about you when you use the Twoman mobile app and this website (together, the "Service"). Twoman is a double-dating app: you and a friend form a twoman and match with other twomans.
The short version. We collect the profile and activity you give us to run a dating service. We do not sell your personal data, run third-party ads, or use your content to train AI. Wingman is optional: it sends only the request you choose to submit and limited screen context to our AI provider after you consent, and it cannot like, message, vote, or book for you. Photos are stripped of location data on your device before upload. Raw contact names, phone numbers, and email addresses stay on your device; if you choose contact matching, the app uploads one-way hashes so our server can find existing members. You can edit or request deletion of your account at any time.
1. Information we collect
Information you provide
- Account details: your email address or mobile phone number (whichever you sign up with), chosen username, and password if you set one. Passwords are stored only in hashed form by our authentication provider; we never see your plaintext password. If you sign up with a phone number, we send a one-time code by text message through Twilio to confirm the number is yours; Twilio receives your number to deliver that code, and we store the verified number as your sign-in identifier. A keyed hash of the number, never the number itself, is kept briefly to limit repeated code requests.
- Date of birth: used to confirm you are 18 or older, derive the age shown on your profile, and—if you choose identity verification—compare against the birth date verified by Stripe. We store the date you entered; we do not display it directly.
- Optional identity verification: Stripe captures and holds your government ID and selfie in its secure flow. Those images never reach TWOMAN. Stripe sends our server the verification result and verified birth date. We compare the date with the date you entered, enforce 18+, and retain the canonical verified birth date with the trust result so later profile changes cannot detach a badge from its proof. We also retain retry state and limited provider references needed to prevent replay, investigate abuse, and request vendor redaction.
- Optional contact matching: if you grant Contacts access and choose matching, the app normalizes email addresses and phone numbers on your device and uploads only SHA-256 hashes, never contact names or raw address-book values. We retain at most the current replaceable hash set and matching bookkeeping until you clear the feature or delete your account.
- Profile content: your gender, private personal starting preference for who you would like your future twoman to meet, up to six photos, personal videos, written and recorded voice prompt answers, optional contact phone number and social handles, and optional vitals such as height, city, job, and school.
- Twoman content: the shared twoman profile you and your friend build together, including your friendship story, approved photos or videos, written prompt answers and member-attributed voice answers, and the preferences you set for who your twoman wants to meet.
- Messages and interactions: the likes and comments you send, your matches, text messages and voice notes in four-person, partner, and friend chats, and the answers you submit in First Round chat games.
- Optional Wingman requests: when you explicitly enable Wingman and submit a request, we process the text you send and a limited label for the app area you are using (for example, Discover or Matches) to generate an answer. We store your consent version. One-line Wingman answers are not added to your profile or chat history. Wingman chat (a separate, optional consent) is different: those conversations are stored on our servers for 30 days so the conversation can continue, and are deleted immediately when you withdraw Wingman chat consent.
- Safety reports: if you block or report someone, we keep a record of the report and the related evidence so our safety team can act on it. Depending on where you report, that evidence may include limited shared-conversation content or the exact profile voice answer, personal video, and video poster you selected.
- Support messages: anything you send us by email, through our contact form, or through in-app feedback. In-app feedback includes your account identifier, selected category, message, and app version.
Waitlists and campus ambassador applications
If you join a campus or Android waitlist, we store your email address, selected list, consent version and a hashed leave token to send a launch notice. A campus ambassador application also stores your campus and an optional short note, so we can contact you about the campus program. We hash the requesting IP address and email address for a one-day rate-limit log. Use the leave link to delete your entry. Notified entries are deleted after 30 days. Unnotified entries for a campus that never opens expire after 365 days; entries for an opened campus stay until notice or deletion. Email delivery uses Resend; sending-domain verification is part of release setup.
Information collected automatically
- Usage and device data: basic technical information needed to operate the app reliably, such as your device type, operating system version, app version, and diagnostic or crash information.
- Subscription data: when you subscribe to Twoman+, our payments partner records the purchase, its status, and a device or transaction identifier so we can grant and verify your subscription.
- Notification data: if you enable notifications, we store an app-specific push token, your notification choices, time zone, delivery status, and the app object needed to open the right screen. We do not put private message text in redacted notification categories.
- Product analytics (only if you turn it on): if you turn on product analytics under Me → Safety & privacy, we record which app steps you reach and complete — for example that onboarding finished, that a twoman went live, that a Move was locked — together with your app version, build, and a pseudonymous identifier linked to your TWOMAN account. Events carry counts and bucketed categories only: never your name, email, phone number, photos, prompt answers, message text, venue, address, or who you liked. With product analytics on, the app also sends a short report when it crashes or freezes: the kind of error and where in TWOMAN's own code it happened, never what was on screen. Product analytics is off until you turn it on, and nothing is recorded before then.
- Activity days for your twoman streak: to show the streak you and your two-man build together, we record the times you use the app, with no content, and keep them for up to 13 months or until you delete your account.
What we do not collect
- We do not collect your precise GPS location.
- We do not use third-party advertising trackers, and we do not run ads in the app.
- We do not use your photos, prompts, or messages to train artificial intelligence models.
- We do not upload or store contact names or raw address-book phone numbers or email addresses. Optional contact matching uploads one-way hashes as described above; the system picker and share sheet otherwise operate on your device.
2. How we use your information
- To create and operate your account and your twomans.
- To show your twoman to compatible twomans and to show you theirs.
- To deliver likes, matches, and real-time four-person chats.
- To confirm you meet the minimum age and to keep the community safe.
- To provide, verify, and manage Twoman+ subscriptions.
- To respond to your support requests.
- To detect, investigate, and prevent abuse, fraud, and violations of our rules.
- With your separate consent, to answer the Wingman request you choose to submit and provide a draft or suggestion for you to review.
- With your separate consent, to count which app steps members reach and complete, so we can find and fix the parts of the app that are broken. We never use product analytics for advertising or profiling.
- To deliver the notification categories you enable and route a notification tap to the relevant app screen.
- To meet our legal obligations.
3. How we share information
We share information only in the ways described here. We do not sell your personal information.
With other members
Your twoman profile, photos, and prompt answers are visible to other twomans in the matching feed. Once you match, your first name and profile are visible to the other three people in that chat. Anything you write in a chat is visible to all four members of that chat. Posts you publish to Activity are visible to people outside your twoman once they pass automated safety review.
With service providers
We rely on a small number of trusted providers who process data on our behalf under contract:
| Provider | Purpose |
|---|---|
| Convex | Secure backend, database, authentication, and real-time messaging |
| Twilio | Delivery of the one-time text message code that confirms a phone number at sign-up or sign-in |
| Stripe | Optional government-ID and selfie verification, verified birth-date confirmation, and redaction processing |
| Adapty | Subscription status delivery, lifecycle reconciliation, and paywall analytics for Twoman+ |
| Apple | App distribution, in-app purchase processing, and signed transaction verification |
| OpenRouter and the selected AI model provider | Process the Wingman request you explicitly submit after enabling the feature |
| OpenRouter and the selected AI model provider | Automated safety review of photos and videos you submit to the public Activity feed, before they become visible outside your twoman |
| PostHog | Product analytics, only for members who turn it on |
For safety and legal reasons
We may disclose information when we believe in good faith that it is necessary to comply with the law, respond to a valid legal request, enforce our Terms, or protect the safety, rights, or property of our members or the public.
Wingman AI
Wingman is optional and off until you turn it on. It receives the request you submit, your recent messages in that Wingman chat, the current feature area, a short situation card that can include the first names of the other people in the match, and instructions that prohibit autonomous social actions and hidden-field use. We do not send your contacts, block list, hidden profile fields, private chats, or another person's sensitive information as background context. You review every answer and remain responsible for anything you choose to send or do. You can withdraw Wingman consent from its menu at any time; withdrawing stops future AI requests unless you consent again.
4. Photos, likeness, and consent
Your photos belong to you. Before any photo leaves your device, the app removes embedded metadata such as GPS location and camera details, and downsizes the image. When a twoman photo shows your friend as well as you, that friend must approve the photo before it appears, and either of you can remove a photo you appear in at any time.
5. Location
Twoman is city-based, not a precise-location tracker. You can search for a city or optionally use a one-time approximate location to find it. Before storage, coordinates from either path are rounded to city-scale precision; we use them for distance filters and fair midpoint venue suggestions. We do not collect background or precise location, and photos are stripped of location data before upload.
6. Purchases and subscriptions
Twoman is free to download. Twoman+ is an optional auto-renewing subscription sold through the Apple App Store. Apple processes your payment; we never receive or store your card number. Our payments partner records that a purchase happened and its status so we can unlock your benefits. See our Terms of Use for subscription details.
7. Age requirement
Twoman is only for adults aged 18 and older. We confirm your age at sign-up. If trusted verification shows that an account belongs to someone under 18, we immediately hide the profile and lock dating access. Account deletion remains available, and limited safety or legal records may be handled under the retention terms below. See section 12 on children below.
8. Retention and deletion
We keep your information for as long as your account is active. When you request deletion, we lock the account and begin removing or de-identifying your personal profile, contact hashes, photos, videos, messages, notification records, and Wingman consent record. Stripe identity redaction is an asynchronous vendor process that may take up to four days after submission; failed requests remain restricted for operator review and retry instead of being silently discarded. If Stripe has already placed a verification session in a state its redaction API does not accept, we keep its local linkage restricted while we resolve the provider-retention request. Wingman request text and answers are not stored in your Twoman profile or message history; an AI service provider may process them for the limited time needed to provide and secure its service. Wingman chat transcripts are stored for 30 days and deleted immediately when you withdraw Wingman chat consent; the automated Activity safety review keeps only its verdict, not a copy of your media.
Limited legal-retention exceptions. When someone submits a safety report, we may retain a restricted, pseudonymous record of the report and limited evidence for as long as needed to investigate the report, protect members, and meet legal obligations. That evidence may be the exact reported profile voice answer, personal video and poster, or content from the shared conversation. Because conversation evidence documents a shared interaction, evidence associated with either participant may remain restricted for those purposes if either person later deletes their account, including the person who submitted the report. Profile evidence selected in a report may likewise remain held after its owner deletes their account. A scheduled review date prompts a case-by-case decision; it does not automatically end a hold or authorize deletion. If the scope or evidence pointer is unclear, the record remains restricted for manual review. We may also retain pseudonymous purchase, refund, commission, tax, and accounting records for the period required by law. These records are not used to rebuild a deleted profile or market to anyone.
You can start account deletion from inside the app under Profile, or from our Delete your account page.
9. Your rights and choices
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to object to or restrict certain processing. You can exercise many of these directly in the app:
- Access and edit: view and change your profile at any time under Profile.
- AI choice: do not enable Wingman, or withdraw consent from Wingman's AI & privacy menu at any time.
- Notifications and contacts: change notification categories in the app and system permission choices in iOS Settings.
- Delete: delete your account in the app or from our deletion page.
- Other requests: use our monitored support and privacy form and we will respond within the time required by applicable law.
Withdrawing product-analytics consent. You can turn product analytics off at any time under Me → Safety & privacy. Turning it off stops new product-analytics events from this device and synchronizes your consent choice with our server. It does not automatically delete previously recorded events or the analytics profile linked to your account. Withdrawal does not affect anything recorded lawfully beforehand, and it never changes your access to the app or to Twoman+.
We will not discriminate against you for exercising any of these rights.
10. Security
We use encryption in transit, hashed passwords, and access controls to protect your information. No online service can promise perfect security, but we work to protect your data and to respond quickly if something goes wrong.
11. International transfers
Our providers may process and store data in countries other than yours. Where required, we use appropriate safeguards for those transfers.
Product analytics, if you turn it on, is processed by PostHog Inc. in the United States under a data processing agreement and the European Commission’s Standard Contractual Clauses. IP addresses are anonymised on receipt.
12. Children
Twoman is not directed to anyone under 18, and we do not knowingly collect information from children. If you believe a minor is using Twoman, use the Safety or reporting topic in our monitored support form and we will act promptly.
13. Changes to this policy
We may update this policy from time to time. If we make a material change, we will update the date above and, where appropriate, notify you in the app.
14. Contact us
For privacy or safety concerns, use our monitored support form and select the matching topic. In an emergency, contact local emergency services first.