Privacy Policy

Effective: July 13, 2026 · Version 2026-07-13

This policy explains what ProjectHax LLC ("we") collects when you use Last Swipe, why, and what control you have. Short version: we collect only what the product needs, we don't run ads, we don't sell or share your data for advertising, and deleting your account erases it — everything you posted, permanently. (The one exception is for banned accounts, and it is spelled out under "Retention and deletion" rather than buried: we keep a ban record — a one-way hash of the account identifier, plus the reason and the evidence — so that a ban can't be undone simply by deleting the account, and so that we can review an appeal if we got it wrong. It is deleted if the ban is lifted.)

What we collect

Face verification (optional)

Verification is entirely optional. You can use Last Swipe without it, and you can decline it at signup or any time after.

Biometric information: our written retention and destruction policy

A faceprint is a biometric identifier under the Illinois Biometric Information Privacy Act (740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act, and Washington's biometric privacy law. This section is the publicly available written policy those laws require.

How we use it

What we never do

Who processes your data (subprocessors)

We use a small number of service providers to run Last Swipe. Each receives only what its function requires, and none receives your data for advertising:

If we add or change a subprocessor we will update this policy; for the current list at any time, email [email protected].

If our business changes hands

If ProjectHax is acquired or merges, or the Service or its assets are sold or transferred, your data may be transferred to the successor, which remains bound by this policy. We will announce any such change in-app before your data becomes subject to a materially different policy, so you can delete your account first if you object.

Retention and deletion

While your account is active, we keep data only as long as it has a job to do:

Deletion works like this:

What outlives a deleted account: the ban record. If an account is banned, or is deleted while our systems have confirmed a violation on it, we keep a ban record after everything else is erased. It contains:

We do not keep your name, your photos, your profile, your matches, or the identities of the people who reported you. Those are erased exactly as described above.

The record has two jobs. The first is to answer one question when someone signs in — "is this identity banned?" — so that a banned user cannot simply delete their account and immediately create a new one. Without it, deletion would be a way to erase a moderation record, and every ban could be undone by the person it was applied to.

The second is so that we can be wrong. Moderation is partly automatic, so some bans will be mistakes. If we destroyed the evidence along with the account, an appeal would be undecidable — we could not review a decision whose reasons we had thrown away, and every ban would be final by accident. Keeping the case for the ban is what makes it possible for us to overturn it.

We keep it only for as long as the ban stands. If the ban is lifted, the whole record — hash, reason and evidence — is deleted.

If you believe a ban was wrong, email [email protected], quoting the reference code we showed you, and we will review it.

Your rights

Regardless of where you live: deletion, correction, and export are all built into the app. Settings → "Export my data" gives you a machine-readable JSON file with your profile, photos, matches, the messages you sent, and your swipes — instantly, whenever you like. For anything else, email [email protected] and we'll respond within 30 days. Depending on where you live you may have additional rights; see the sections below.

California residents (CCPA/CPRA)

In the preceding 12 months we collected the categories of personal information listed in "What we collect": identifiers (name, Apple identifier, email if shared); characteristics of protected classifications you choose to share (age, gender, sexual orientation, ethnicity, religion); photos; commercial information (purchase state); approximate geolocation; internet activity (swipes, matches, messages); and inferences (your values-match percentage). We collect it from you, your device, and Apple, for the purposes listed in "How we use it." We do not sell personal information, do not share it for cross-context behavioral advertising, and offer no financial incentives for it. Sensitive personal information (such as ethnicity, religion, or sexual orientation you add to your profile) is used only to provide the Service you request, never to infer characteristics about you. You have the right to know, access, correct, delete, and port your information, and to be free from discrimination for exercising those rights. Access, correction, deletion, and export are all built into the app; for anything else email [email protected] — we verify requests through your signed-in account, and you may use an authorized agent with written permission.

European users (GDPR)

Last Swipe is offered only in the United States and is not directed to residents of the EEA, the United Kingdom, or Switzerland. If you use the Service from a place where the GDPR or UK GDPR nonetheless applies to you, ProjectHax LLC is the data controller and processes your data: to perform our contract with you (providing matching, chat, and the rest of the Service); with your consent for the optional details listed above — including special-category data such as ethnicity, religion, political leaning, and sexual orientation, which you provide voluntarily and can clear at any time; for our legitimate interests in keeping the Service safe, secure, and free of abuse; and to comply with legal obligations. Your data is processed in the United States, which may not provide the same level of data protection as your home jurisdiction. You may access, correct, export, restrict, object to, or delete your data, withdraw consent at any time (clear the optional fields, or delete your account), and lodge a complaint with your local supervisory authority.

Security

Data is encrypted in transit; photos are stored in private buckets accessible only through short-lived signed URLs; Apple session tokens are encrypted at rest. No system is perfectly secure — please use the report and block tools if anything feels wrong. If we learn of a security breach affecting your personal data, we will notify you without undue delay — in-app, by push notification, or by email where we have one — tell you what was involved and what we have done about it, and notify regulators where the law requires.

Children

Last Swipe is strictly 18+. We do not knowingly collect data from minors; suspected underage accounts are deleted.

Changes and contact

Material changes will be announced in-app with a new version date. Questions: [email protected] · ProjectHax LLC, Pennsylvania, USA.