Back to XoSeen

Privacy Policy

Last updated August 30, 2026

XoSeen verifies that people are who they say they are, which means we handle sensitive information — including biometric information. This policy explains what we collect, why, how long we keep it, and how you get rid of it.

Pre-launch draft. XoSeen has not launched and is not yet collecting data from members. This document describes the practices we are building toward and has not yet been reviewed by counsel. It will be finalised before the app ships. Questions in the meantime: privacy@xoseen.com.

1. Who we are

XoSeen (“XoSeen”, “we”, “us”) operates the XoSeen mobile application and this website. For privacy questions, including any request to access or delete your data, contact privacy@xoseen.com. Our full legal entity name and registered address will appear here before launch.

2. Biometric information — the short version

This is the section most people came for, so it goes first and in plain language.

  • What we capture. A full-body photograph you submit, and a short live camera capture used to confirm the person on camera is the person in that photograph.
  • What we derive. A facial similarity measurement between the two. This is biometric information under laws such as the Illinois Biometric Information Privacy Act (BIPA) and Texas CUBI, and special category data under the GDPR.
  • Why. One purpose only: to decide whether to grant your verified badge, and to keep unverified accounts out of other members’ discovery feeds.
  • What we never do. We do not sell biometric information. We do not disclose it to advertisers, data brokers or marketing partners. We do not use it to train models for third parties, and we do not use it for surveillance, tracking or identification outside verification.
  • Consent. Verification is opt-in and we ask for your explicit consent before the capture. You can decline; you simply will not receive a verified badge, and unverified accounts cannot enter discovery.
  • Retention. We keep the verification decision (verified / not verified) and an audit record for as long as your account exists. Raw captures and derived biometric measurements are retained only as long as needed to complete and defend that decision, and in no case longer than three years after your last interaction with us — after which they are permanently destroyed.

3. Information we collect

You give us: your email address; at signup, your date of birth, gender and the preferences that shape your matches; your profile — photos, bio, interests; the full-body photo and live capture described above; a government-issued ID if you choose the ID-based verification path; the content of the messages you send; and anything you include in a report or support request.

We collect automatically: device and app version, IP address, crash and performance diagnostics, and how you use the app (screens opened, features used) so we can fix what is broken and improve matching.

Location: if you allow it, we use your location to show you people nearby. We convert it to a coarse geographic cell and a derived distance for ranking — we do not store or display your precise coordinates, and other members never see your exact location.

On this website: if you join the waitlist we store the email address you enter and the time you entered it. That is all.

4. How we use it

  • To create and operate your account, and to authenticate you.
  • To run verification and issue or withhold the verified badge.
  • To show you potential matches, and to show you to them.
  • To deliver messages between you and your matches.
  • To keep the platform safe: detecting fraud, fake accounts, harassment and abuse, and acting on reports.
  • To send you service messages (verification codes, match and message notifications, security notices) and — only if you asked for them — product and early-access emails, which every message lets you unsubscribe from.
  • To comply with legal obligations and to enforce our Terms.

We do not sell your personal information, and we do not share it with third parties for cross-context behavioural advertising.

5. Legal bases (EEA and UK)

We process your data to perform our contract with you (operating the service); on the basis of your explicit consent (biometric information and precise location, each of which you can withdraw); for our legitimate interests (safety, fraud prevention and service improvement, balanced against your rights); and to comply with legal obligations.

6. Who we share it with

Service providers who process data on our instructions and nothing else: cloud hosting and storage (Amazon Web Services, in the United States), email delivery (Amazon SES), push notification delivery, and error and diagnostics tooling. Each is bound by contract to use the data only to provide its service to us.

We also share data where the law requires it — in response to a valid legal request — or where it is necessary to protect someone’s safety, and with an acquirer if XoSeen is ever involved in a merger or sale, in which case we will tell you before your data becomes subject to a different policy.

7. How we protect it

  • Data is encrypted in transit (TLS) and at rest.
  • Identity documents are stored in a separate, encrypted vault from profile data, so browsing profiles never puts anyone a step away from your documents.
  • Chat is designed to be end-to-end encrypted, so message content is readable by you and your match rather than by us.
  • Verification state is enforced on our servers, not in the app, so it cannot be unlocked by modifying a device.
  • Access to production data is limited to the staff who need it, and is logged.

No system is perfectly secure. If a breach affects your personal information we will notify you and the relevant regulators as required by law.

8. Your rights

Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, or stop using it for a particular purpose — and you can withdraw consent for biometric processing or location at any time. Depending on where you live you may also have the right to object to processing, to data portability, to opt out of “sale” or “sharing” (we do neither), and to be free from discrimination for exercising any of these rights.

Deleting your account removes your profile from discovery immediately and erases your data on the schedule in section 2, except where we must retain something to comply with the law or to resolve a safety matter. Email privacy@xoseen.com and we will respond within the period your local law requires (45 days in California, one month in the EEA and UK).

9. Children

XoSeen is strictly for adults. You must be 18 or older to create an account. We do not knowingly collect data from anyone under 18, and we delete such accounts and their data as soon as we identify them.

10. International transfers

We operate from the United States, and your data is processed there. Where we receive data from the EEA or UK we rely on Standard Contractual Clauses and apply additional safeguards to protect it.

11. Changes

If we make a material change to this policy we will update the date at the top and notify you in the app or by email before the change takes effect. Continuing to use XoSeen after that means you accept the updated policy.

See also Privacy Policy · Terms of Service

© 2026 XoSeen. All rights reserved.