Privacy Policy

Last updated: September 7, 2026

1. Who We Are

BeyondSwipe ("we", "us", or "our") is operated by 15748666 Canada Inc., a company incorporated in Canada. Our registered address is on file with Corporations Canada. For privacy inquiries, contact us at privacy@beyondswipe.app.

We are subject to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Act respecting the protection of personal information in the private sector (Law 25 / Bill 64).

2. Information We Collect

2.1 Information you provide directly

  • Account information: email address, first name, date of birth, gender, and sexual orientation.
  • Profile information: photos, video introduction, biography, height, job title, education level, and pronouns (all optional except photos).
  • Interest selections: the interests you choose during onboarding (used for compatibility matching).
  • Messages: the content of messages you send to other users.
  • Location: your city, chosen by you during onboarding. We do not collect precise GPS coordinates.

2.2 Identity verification and biometric information

We require all users to verify their real identity through Didit, our identity verification provider. During this process, Didit captures your government-issued photo ID and a live selfie, and processes biometric information (facial geometry) derived from both for the sole purpose of confirming that you are the person shown on the document.

Your identification document and selfie are transmitted directly to Didit. They are never received by, transmitted through, or stored on BeyondSwipe's systems. When we create the verification session, we send Didit the date of birth you entered so it can compare that exact date with the date printed on your document. Didit is capable of returning to us the images themselves and the personal details it reads from your document, such as your legal name, document number and address. Our verification is configured to return none of them. We request exactly one extracted value: the date of birth on your document, which we read transiently to confirm you are 18 or older and that it exactly matches your declared date. The extracted value is immediately discarded. It is not stored, not logged, and not linked to your profile. We retain only the date you entered, or the corrected date you submit after a mismatch. Beyond that check, what we receive is a session reference, warning codes needed to explain a refusal, and the verification result. Warning codes do not contain or retain the expected or extracted dates. If a date of birth cannot be read from your document, verification does not complete and you will need to contact support.

Deletion. Immediately after a verification resolves, whether it passed or failed, our system instructs Didit to delete the verification session and its associated document, selfie, and extracted feature data from active systems. Didit then hard-deletes the soft-deleted session record under the configured retention schedule. Because no image is ever returned to us in the first place, no BeyondSwipe personnel is able to retrieve or view your identity document at any point, before or after verification completes.

Biometric data. The biometric identifiers used to match your selfie to your document are never disclosed to us; we receive only the outcome of the match. Our Didit account is set to a one month retention period, the shortest the platform offers, and biometric templates are deleted together with the verification session rather than kept for later matching. You may withdraw consent to that retention at any time by writing to privacy@beyondswipe.app, after which we will instruct Didit to delete it.

Consent. We give you written notice of this biometric processing, its specific purpose, and its retention period before any capture takes place, and we proceed only with your consent. You may decline, in which case you will not be able to complete verification. We do not sell, lease, trade, or otherwise profit from biometric information, and we do not disclose it to third parties.

What we retain. The complete record we hold in relation to your verification is: a verification session reference, the declared date used for that session, the verification outcome, non-identifying warning codes needed to explain that outcome, and the date it completed. We do not retain the date extracted from your document. Didit stores verification data in the European Union, and its own privacy practices are governed by the Didit Privacy Policy. See also our How Verification Works page.

2.3 Payment information

We do not store credit card numbers or payment details, and they are never transmitted through or held on our systems. Payment processing is handled entirely by our payment provider. We retain only a transaction reference, the amount, and the date, for billing and fraud prevention purposes.

2.4 Technical data collected automatically

  • Log data: IP address, browser type and version, pages visited, timestamps, and referring URLs.
  • Device information: operating system, screen resolution, and device type.
  • Cookies and similar technologies: session cookies for authentication and analytics cookies (see Section 6).

Video intros and voice recordings are screened before they are published. Still frames sampled from a video are checked by AWS Rekognition, the same service used for photographs. Voice recordings are transcribed by AWS Transcribe and the resulting text is checked for prohibited content by the Anthropic Claude API; this screens what is said and does not analyse non-speech sound. Recordings are held by the screening services only for the duration of the check and are deleted immediately afterwards, and an upload is refused entirely if screening cannot run.

2.5 Content moderation data

Photos you upload are automatically screened before they are published: by AWS Rekognition for prohibited content, and by Microsoft PhotoDNA against industry databases of known child sexual abuse material. Both run on our servers before an image is stored, and an upload is refused entirely if either check cannot run. PhotoDNA receives only a mathematical hash, which cannot be reversed into an image, so no photograph of any member is transmitted to it. The scan produces a classification result; the raw image is not retained by the screening services beyond the duration of the scan. Suspected child sexual abuse material is reported to the Canadian Centre for Child Protection through Cybertip.ca, the agency designated under Canadian law for a service operated from Canada, and to police where we have reasonable grounds to believe our service has been used to commit an offence.

3. How We Use Your Information

We use your personal information for the following purposes, each grounded in a lawful basis:

  • Providing the service (contract): Creating your account, showing your profile to potential matches, enabling messaging, and processing verification and payments.
  • Safety and fraud prevention (legitimate interest / legal obligation): Verifying real identity, detecting spam and fake accounts, screening content for abuse, and responding to reports of misconduct.
  • Improving the platform (legitimate interest): Analysing aggregate usage patterns to improve features and user experience. We use PostHog for privacy-friendly analytics.
  • Legal compliance (legal obligation): Retaining records as required by Canadian law, responding to lawful government requests, and cooperating with law enforcement investigations involving CSAM or other serious harm.
  • Communications (consent / contract): Sending transactional emails (account confirmations, match notifications) via Resend. We do not send marketing emails without your explicit opt-in.
  • Content screening (contract): We use the Anthropic Claude API to check the transcript of a voice recording for prohibited content before that recording is published. We send the transcript of that one recording and nothing else. We do not send your messages, and your data is not used to train AI models.

Electronic messages (CASL). In compliance with Canada's Anti-Spam Legislation, we send commercial electronic messages only with your consent. Every marketing email identifies us and contains a working unsubscribe mechanism, and unsubscribe requests take effect within 10 business days. Transactional messages about your account, security, or purchases are sent as needed to operate the Service.

4. How We Share Your Information

We do not sell your personal information. We share data only in these circumstances:

  • Other users: Your profile (name, photos, bio, interests, city) is visible to other verified BeyondSwipe users. Your email address and date of birth are never shown publicly.
  • Service providers (processors): We share data with trusted vendors who process it on our behalf under contractual data processing agreements: Supabase (database, authentication and media storage), Didit (identity and age verification), AWS (image and video-frame moderation, and speech transcription), Microsoft (PhotoDNA hash matching, which receives a mathematical hash and never an image), Anthropic (checking the text of a transcribed voice recording), Resend (email delivery), PostHog (analytics), and RevenueCat with Apple and Google (purchases and subscriptions). Each provider processes only the data necessary for their function.
  • Legal requirements: We may disclose information when required by law, court order, or to protect the safety of users or the public.
  • Business transfers: If BeyondSwipe is acquired or merged, your data may be transferred to the successor entity. We will notify you 30 days before any such transfer takes effect.

5. Data Retention

We retain your personal information for as long as your account is active. If you delete your account:

  • Your profile, photos, and messages are permanently deleted within 30 days.
  • Identity verification tokens are deleted immediately.
  • Payment records are retained for 7 years as required by Canadian tax law.
  • Content moderation logs are retained for 2 years to comply with our legal obligations.

Backups containing your data are purged on a rolling 90-day cycle.

6. Cookies and Tracking

We use the following types of cookies:

  • Strictly necessary cookies: Authentication session cookies that keep you logged in. These cannot be disabled.
  • Analytics cookies: PostHog analytics to understand how users interact with BeyondSwipe. PostHog runs in cookieless mode: no analytics cookie is set, nothing is persisted in your browser between visits, automatic click and input capture is disabled, and session recording is off.

We do not use third-party advertising cookies or cross-site tracking.

7. Your Rights

Under PIPEDA and Quebec Law 25, you have the right to:

  • Access: Request a copy of the personal information we hold about you.
  • Rectification: Correct inaccurate or incomplete information.
  • Deletion: Request deletion of your account and personal data, subject to legal retention obligations.
  • Portability (Quebec Law 25): Receive a copy of your data in a structured, commonly used, machine-readable format.
  • Withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
  • Object to automated decisions: Our matching algorithm uses your interests to suggest potential matches. You may request human review of any significant automated decision.

To exercise any of these rights, email privacy@beyondswipe.app. We will respond within 30 days. Quebec residents may also file a complaint with the Commission d'accès à l'information (CAI) at cai.gouv.qc.ca. Federal complaints may be directed to the Office of the Privacy Commissioner of Canada at priv.gc.ca.

International users: If you are located in the European Economic Area or the United Kingdom, you have equivalent rights under the General Data Protection Regulation (GDPR / UK GDPR), including the rights of access, rectification, erasure, restriction of processing, data portability, and objection, and the right to lodge a complaint with your local supervisory authority. If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know, delete, and correct your personal information, and the right to opt out of the sale or sharing of personal information. BeyondSwipe does not sell your personal information. To exercise any of these rights, contact privacy@beyondswipe.app.

8. Privacy by Design (Quebec Law 25)

In accordance with Quebec Law 25's privacy by default requirements:

  • We conduct Privacy Impact Assessments (PIAs) before deploying new features that process personal data.
  • We apply data minimisation principles and collect only what is necessary for a specific, stated purpose.
  • We designate a Privacy Officer responsible for ensuring compliance. Contact: privacy@beyondswipe.app.
  • Any third-party technology that presents a material privacy risk is evaluated through a PIA before adoption.

9. International Transfers

Your data is stored on servers located in North America (Supabase, AWS). When data is processed by service providers outside Canada, we ensure appropriate contractual safeguards are in place, including standard contractual clauses or equivalent protections as required by PIPEDA and Quebec Law 25.

10. Children's Privacy

BeyondSwipe is strictly for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. Identity verification is mandatory and is performed by Didit, which reads the date of birth printed on your government-issued document. BeyondSwipe checks that date and refuses any account where it shows the holder is under 18. If we discover that a user is under 18, we will immediately terminate their account and delete all associated data.

11. Security

We implement technical and organisational measures to protect your data, including:

  • Encryption in transit (TLS 1.3) and at rest (AES-256).
  • Row-level security on all database tables.
  • Access controls limiting data access to staff with a need to know.
  • Regular security reviews and dependency audits.

No method of transmission over the internet is 100% secure. In the event of a data breach that creates a real risk of significant harm, we will notify affected users and the applicable privacy regulator within 72 hours of becoming aware of the breach.

12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email and display a prominent notice in the app at least 30 days before the changes take effect. Your continued use of BeyondSwipe after that date constitutes acceptance of the updated policy. The date at the top of this page always reflects when the policy was last revised.

13. Contact Us

For privacy questions, requests, or complaints:

Privacy Officer
BeyondSwipe / 15748666 Canada Inc.
Email: privacy@beyondswipe.app