Privacy Policy
This policy explains what ProjectHax LLC ("we") collects when you use Last Swipe, why, and what control you have. Short version: we collect only what the product needs, we don't run ads, we don't sell or share your data for advertising, and deleting your account erases it — everything you posted, permanently. (The one exception is for banned accounts, and it is spelled out under "Retention and deletion" rather than buried: we keep a ban record — a one-way hash of the account identifier, plus the reason and the evidence — so that a ban can't be undone simply by deleting the account, and so that we can review an appeal if we got it wrong. It is deleted if the ban is lifted.)
What we collect
- Account: your first name and a pseudonymous Apple identifier from Sign in with Apple (your email only if Apple shares it); your birthdate (for the 18+ requirement and age display).
- Profile: photos and captions, bio, prompts, job and education if you add them, gender and who you want to see, height and weight (used for the filters you and others set), interests and hobby skill levels, and what you're looking for.
- Optional details you may choose to share: kids (have/want), education level, religion, political leaning, smoking, drinking, fitness, body type, ethnicity, pets, and your answers to the in-app values quiz. Every one of these is optional, self-reported, can be left blank or cleared at any time, and is used only for the profile you show others, the filters you and other users configure, and the values-match percentage.
- Location: approximate location (roughly neighborhood-level; we request reduced accuracy from iOS) to show people within your chosen distance. Your coordinates are never shown to other users — only a rounded distance.
- Activity: swipes, matches, and messages you send; a device token if you enable notifications; purchase state from Apple (never your payment details).
- Verification selfies and faceprints (only if you choose to verify): if you start profile verification, we ask you to take three selfies and we compare them with your profile photos to confirm you're the same person. To do that we compute a faceprint — a numeric representation of facial geometry, which is biometric information. We do not collect this unless you tap to agree and take the selfies.
Face verification (optional)
Verification is entirely optional. You can use Last Swipe without it, and you can decline it at signup or any time after.
- What we do: the three selfies and your profile photos are analysed on our own servers to check the faces match. They are never sent to a third-party AI provider or face-recognition service, and they are never used to identify you anywhere outside your own account.
- What we keep: if verification succeeds, we delete the selfies immediately and keep only the faceprint, for as long as your profile stays verified. We use it to re-check verification when you change your photos — that's what stops someone verifying with their own face and then swapping in someone else's pictures.
- What we delete: the faceprint is deleted as soon as verification is revoked or you unverify, and when you delete your account. If verification fails, we keep the selfies for up to 7 days so a person can review an appeal, then delete them.
- Your selfies are never shown to anyone. They do not appear on your profile. Other users only ever see whether you're verified.
- We do not sell, lease, trade, or otherwise profit from biometric information, and we don't disclose it except as required by law.
Biometric information: our written retention and destruction policy
A faceprint is a biometric identifier under the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, and Washington's biometric privacy law. This section is the publicly available written policy those laws require.
- Consent. We collect and store a faceprint only with your express consent, which you give in the app before the first verification selfie is taken, after being told what we collect, why, and for how long. Verification is optional: you can decline, and Last Swipe works fully without it.
- Purpose. The only purpose is to confirm that the person in your profile photos is you, and to re-check that if you change those photos. We do not use a faceprint to identify you anywhere else, and we never use it for advertising.
- Retention schedule. Verification selfies are destroyed immediately once verification succeeds. If verification fails, they are held for up to 7 days so that a person can review an appeal, and are then destroyed. An abandoned attempt is destroyed within 24 hours. A faceprint is retained only while your verified badge is active, and is destroyed as soon as the badge is removed or revoked, when you unverify, or when you delete your account — and in every case no later than 3 years after your last interaction with us, whichever comes first. In practice this is far sooner: an account left unused for 30 days is deleted automatically.
- Destruction. Destruction is permanent. Selfies are deleted from object storage and faceprints are erased from the database; they are not archived, and backups holding them age out within 14 days.
- No sale, no disclosure. We do not sell, lease, trade, or otherwise profit from biometric information, and we do not disclose it to anyone except with your consent or where required by law or valid legal process.
How we use it
- Matching and discovery (filters, distance).
- Delivering chat and push notifications.
- Safety: automated screening of every uploaded photo for explicit content before it appears on the Service (a photo we cannot screen is not published), profanity filtering of text, and — when a user is reported — automated review of that user's messages, profile, and photos. These systems run on our own servers; your content is never sent to third-party AI providers.
- Enforcing our Terms, including suspensions and bans.
What we never do
- No advertising, tracking, or cross-app profiling.
- No selling or renting your personal information.
- No showing your exact location, birthdate, weight, or email to other users.
Who processes your data (subprocessors)
We use a small number of service providers to run Last Swipe. Each receives only what its function requires, and none receives your data for advertising:
- Apple Inc. (USA) — Sign in with Apple (authentication), In-App Purchases (billing), and the Apple Push Notification service (delivering your notifications). Receives your pseudonymous identifier, purchase state, device push tokens, and the notification payloads we send.
- Cloudflare, Inc. (USA) — network security and routing for all traffic to our servers, private encrypted object storage for your photos, and routing of email you send to our support, privacy, and legal addresses.
- Resend (USA) — delivering our replies when you email us. Receives your email address, the subject, and the text of our reply.
- Server hosting providers — the virtual servers and database that run Last Swipe. All matching, chat, and moderation processing happens on servers we control at these providers.
- Backup storage provider — a separate storage bucket holds compressed database backups, which age out within 14 days.
If we add or change a subprocessor we will update this policy; for the current list at any time, email [email protected].
If our business changes hands
If ProjectHax is acquired or merges, or the Service or its assets are sold or transferred, your data may be transferred to the successor, which remains bound by this policy. We will announce any such change in-app before your data becomes subject to a materially different policy, so you can delete your account first if you object.
Retention and deletion
While your account is active, we keep data only as long as it has a job to do:
- Profile, photos, and filters: as long as your account exists. Photos you remove and fields you clear are deleted right away, not archived.
- Matches and messages: until either participant's account is deleted. Unmatching ends the conversation for both sides immediately; its record is removed when either account is deleted.
- Swipes: as long as your account exists; recycling deletes your passes so you can see those people again. Daily swipe counters expire automatically within a day.
- Blocks, reports, and moderation records: as long as the accounts involved exist, so blocks and bans stay effective. When an account is deleted these go with it — except for the hashed ban record described below, if one applies.
- Device push tokens: until you turn off notifications or delete your account.
- Email you send us: if you write to our support, privacy, or legal addresses, we keep the message, anything you attach, and our replies, so that we have a record of what was asked and what we said. We keep it for 2 years after the conversation ends, and then delete it. This is kept separately from your account and is not deleted when your account is — otherwise deleting your account would erase our record of an appeal you are in the middle of making.
Deletion works like this:
- Delete your account in Settings at any time: all profile data, photos, matches, messages, purchase records, and device tokens are permanently deleted, and we revoke our connection to your Apple account.
- Accounts inactive for 30 days are deleted automatically the same way (we send a warning notification a week before).
- Database backups age out within 14 days.
- If we ever shut down the Service, all remaining accounts and their data are permanently deleted the same way, after the advance notice described in our Terms of Service.
What outlives a deleted account: the ban record. If an account is banned, or is deleted while our systems have confirmed a violation on it, we keep a ban record after everything else is erased. It contains:
- a one-way cryptographic hash of the pseudonymous Apple identifier for that account. It cannot be turned back into an identifier, and it cannot be linked to your name, your photos, or your profile;
- a reference code, which we show you if you are ever turned away, so that you can appeal;
- the reason for the ban and the evidence behind it — the reports made about the account, what those reports said, what our automated checks concluded and how confident they were, and the specific content that triggered them, which may include messages you sent.
We do not keep your name, your photos, your profile, your matches, or the identities of the people who reported you. Those are erased exactly as described above.
The record has two jobs. The first is to answer one question when someone signs in — "is this identity banned?" — so that a banned user cannot simply delete their account and immediately create a new one. Without it, deletion would be a way to erase a moderation record, and every ban could be undone by the person it was applied to.
The second is so that we can be wrong. Moderation is partly automatic, so some bans will be mistakes. If we destroyed the evidence along with the account, an appeal would be undecidable — we could not review a decision whose reasons we had thrown away, and every ban would be final by accident. Keeping the case for the ban is what makes it possible for us to overturn it.
We keep it only for as long as the ban stands. If the ban is lifted, the whole record — hash, reason and evidence — is deleted.
If you believe a ban was wrong, email [email protected], quoting the reference code we showed you, and we will review it.
Your rights
Regardless of where you live: deletion, correction, and export are all built into the app. Settings → "Export my data" gives you a machine-readable JSON file with your profile, photos, matches, the messages you sent, and your swipes — instantly, whenever you like. For anything else, email [email protected] and we'll respond within 30 days. Depending on where you live you may have additional rights; see the sections below.
California residents (CCPA/CPRA)
In the preceding 12 months we collected the categories of personal information listed in "What we collect": identifiers (name, Apple identifier, email if shared); characteristics of protected classifications you choose to share (age, gender, sexual orientation, ethnicity, religion); photos; commercial information (purchase state); approximate geolocation; internet activity (swipes, matches, messages); and inferences (your values-match percentage). We collect it from you, your device, and Apple, for the purposes listed in "How we use it." We do not sell personal information, do not share it for cross-context behavioral advertising, and offer no financial incentives for it. Sensitive personal information (such as ethnicity, religion, or sexual orientation you add to your profile) is used only to provide the Service you request, never to infer characteristics about you. You have the right to know, access, correct, delete, and port your information, and to be free from discrimination for exercising those rights. Access, correction, deletion, and export are all built into the app; for anything else email [email protected] — we verify requests through your signed-in account, and you may use an authorized agent with written permission.
European users (GDPR)
Last Swipe is offered only in the United States and is not directed to residents of the EEA, the United Kingdom, or Switzerland. If you use the Service from a place where the GDPR or UK GDPR nonetheless applies to you, ProjectHax LLC is the data controller and processes your data: to perform our contract with you (providing matching, chat, and the rest of the Service); with your consent for the optional details listed above — including special-category data such as ethnicity, religion, political leaning, and sexual orientation, which you provide voluntarily and can clear at any time; for our legitimate interests in keeping the Service safe, secure, and free of abuse; and to comply with legal obligations. Your data is processed in the United States, which may not provide the same level of data protection as your home jurisdiction. You may access, correct, export, restrict, object to, or delete your data, withdraw consent at any time (clear the optional fields, or delete your account), and lodge a complaint with your local supervisory authority.
Security
Data is encrypted in transit; photos are stored in private buckets accessible only through short-lived signed URLs; Apple session tokens are encrypted at rest. No system is perfectly secure — please use the report and block tools if anything feels wrong. If we learn of a security breach affecting your personal data, we will notify you without undue delay — in-app, by push notification, or by email where we have one — tell you what was involved and what we have done about it, and notify regulators where the law requires.
Children
Last Swipe is strictly 18+. We do not knowingly collect data from minors; suspected underage accounts are deleted.
Changes and contact
Material changes will be announced in-app with a new version date. Questions: [email protected] · ProjectHax LLC, Pennsylvania, USA.