Privacy Policy
Effective Date: August 4, 2026
This version supersedes all prior versions.
This Policy at a Glance
This summary is for convenience; the full sections below are authoritative.
- Who: Glambu Limited (UK) is the data controller for the Glambu app and website.
- What we collect: account and profile data you provide; messages on the Service; payment status (never full card numbers); optional ID/selfie verification data; and automatically, device, usage, IP, and approximate location data.
- Why: to run the matchmaking service, keep it safe (moderation, fraud and ban enforcement), improve it, and meet legal duties. Legal bases for each purpose are in Section 5.
- Sensitive data: anything revealing orientation, beliefs, or ethnicity is processed only with your explicit consent, only for matching. Biometric selfie checks require a separate consent and templates are deleted after each check.
- Sharing: we do not sell your data and do not share it with advertisers for behavioural advertising. We share it with service providers under contract, with other users per your profile settings, and where the law requires. Details in Section 8.
- Retention: specific periods per data category are in the table in Section 10.
- Your rights: access, correction, deletion, objection, portability, complaint to the ICO — Section 12.
- Your risks: other users can screenshot what you share; off-platform chats (WhatsApp, Telegram) are outside our protection; no online service is 100% secure — Sections 3 and 17.
- Contact: [email protected].
1. Who We Are
Glambu Limited («Glambu«, «we«, «us«, «our«) is a company incorporated in England and Wales (Company No. 16877178), registered office: 3rd Floor Suite 207, Regent Street, London, England, W1B 3HH. Contact: [email protected].
We are the Data Controller for personal data processed through our website at https://glambu.com (the «Website») and our mobile application (the «App») (together, the «Service»), within the meaning of the UK General Data Protection Regulation («UK GDPR»), the EU General Data Protection Regulation («EU GDPR») where applicable, and the Data Protection Act 2018.
2. Scope, Acceptance and Relationship to Our Terms
This Policy applies to all current and former users of the Service worldwide. Where we lawfully retain data after your account is closed or deleted (see Section 10), this Policy continues to govern that data. It forms part of, and must be read together with, our Terms of Service, including their limitations of liability, disclaimers, and dispute-resolution provisions, which apply equally to matters described in this Policy. By creating an account, accessing, or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree with this Policy, you must not use the Service.
This Policy describes our data-handling practices for transparency purposes. Except where mandatory law provides otherwise, it does not create contractual rights, warranties, or guarantees beyond those required by applicable data protection law, and it does not confer rights on any third party. Timeframes stated in this Policy (including retention and deletion periods) are good-faith operational targets pursued with reasonable diligence, not strict contractual deadlines, and may be affected by technical constraints, backups, investigations, and legal holds.
This Policy does not apply to third-party websites, apps, payment pages, or services linked from the Service, nor to communications you conduct outside the Service (see Section 17). We accept no responsibility or liability for the privacy practices, acts, or omissions of third parties.
3. Your Acknowledgment of Inherent Risks
You acknowledge and accept that:
- No online service is risk-free. Despite reasonable security measures, no method of electronic transmission or storage is completely secure, and the confidentiality of information transmitted over the internet can never be guaranteed.
- Criminal acts of third parties. Data security incidents may be caused by sophisticated, unlawful acts of third parties (including hacking, credential-stuffing, scraping, malware, and social engineering) that can occur despite security measures consistent with industry practice. To the maximum extent permitted by applicable law, we are not liable for loss or damage caused by such unlawful third-party acts where we have implemented appropriate technical and organisational measures.
- Other users are outside our control. Any information, photo, or message you share with or make visible to another user can be captured (e.g., screenshots, screen recording, photography of a screen), copied, stored, and redistributed by that user without our knowledge and in breach of our Terms. We have no technical means to prevent this and accept no responsibility or liability for the acts or omissions of other users, including their misuse, disclosure, or publication of content you shared with them.
- You decide what you upload. You are solely responsible for deciding which photos and information to upload or disclose. We strongly advise against uploading or sending intimate, explicit, financially sensitive, or otherwise highly sensitive content through any online service, including ours. If you nonetheless choose to share such content, you do so at your own risk and with awareness of the risks described in this Section.
- Your own security conduct matters. You are responsible for using a strong, unique password, keeping your credentials confidential, securing your own device and email account, and promptly reporting suspected unauthorised access. To the maximum extent permitted by law, we are not liable for loss arising from your failure to do so or from unauthorised access attributable to compromise of your own device, email, or credentials.
Nothing in this Section excludes or limits any liability that cannot be excluded or limited under applicable law.
4. Information We Collect
4.1 Data You Provide Directly
- Account Information: Email address, password (stored only in salted, hashed form), username, date of birth, gender, and search preferences (age range, location range).
- Profile Data: Photos, biography, education, occupation, lifestyle details, physical attributes, languages, and relationship goals. You control what you publish. Anything you place in your profile is disclosed by your own choice and at your own discretion to other users in accordance with the Service’s visibility model.
- Special Category Data: You may voluntarily provide data revealing your sexual orientation, religious or philosophical beliefs, ethnicity, or political opinions (e.g., in your bio or filters). We process this data only on the basis of your explicit consent (Article 9(2)(a) UK GDPR), given when you enter such data. You may withdraw this consent at any time by removing the data or deleting your account; withdrawal does not affect the lawfulness of prior processing. If you do not wish this data to be processed, do not include it in your profile or filters.
- Communications: The content of messages and interactions with other users on the Service, and your correspondence with our support team.
- Payment Data: Billing details necessary to process subscriptions and purchases. We never receive or store full payment card numbers. All transactions are processed by PCI-DSS compliant third-party payment processors and, where applicable, by the app store through which you purchased (e.g., Google Play). Their own privacy policies govern their processing, and we are not responsible for their acts or omissions.
- Verification Data: Government-issued ID, selfie photos, or proof of address, where required for age verification, identity verification, fraud investigation, or compliance with law (including the UK Online Safety Act 2023).
- Survey, Contest, and Feedback Data you choose to submit.
4.2 Data Collected Automatically
- Usage Data: IP address, device type and model, operating system and version, app version, browser type, language settings, pages/screens viewed, features used, session duration, interaction events (invitations sent/accepted/declined, matches, blocks, reports), crash logs, diagnostic data, and login history. We may combine data collected from the different sources described in this Policy for the purposes set out in Section 5.
- Location Data: We determine your approximate location (city/region/country) to operate core features such as showing you nearby profiles, applying your distance preferences, localising content, and detecting fraud (e.g., VPN/proxy use, implausible logins). We derive this from: (a) your IP address; and/or (b) device GPS coordinates, only if you grant location permission via your device settings (revocable at any time). To convert coordinates or IP addresses into place names («reverse geocoding» and «IP geolocation»), we use specialised third-party geolocation providers acting as our data processors. We apply data minimisation: requests are made from our servers wherever technically feasible, coordinates are truncated to the precision needed for the feature (approximately city level), and requests do not include your name, username, email address, profile content, or any advertising identifier. Geolocation providers are contractually prohibited from retaining, reusing, selling, or enriching the data and act only on our documented instructions under a Data Processing Agreement. We do not disclose your precise location to other users. Other users see only the approximate distance or city, per your settings.
- Device Identifiers and Fingerprinting: Technical attributes (e.g., device identifiers, screen characteristics, OS build data) used to generate a stable device identifier. We use this strictly for security, fraud prevention, bot detection, prevention of multi-account abuse, and enforcement of bans, which constitutes a strictly necessary purpose under the Privacy and Electronic Communications Regulations (PECR) and our legitimate interests.
- Derived Data and Inferences: Using the Service generates insights and inferences we derive from your activity and the content you provide (e.g., inferred preferences and compatibility signals used by our recommendation and safety systems). We treat this derived data as personal data under this Policy.
- Third-Party SDKs Embedded in the App: Like most mobile apps, the App includes software development kits (SDKs) from third-party providers for functions such as crash reporting, performance monitoring, analytics, push notifications, and payment processing. These SDKs may automatically collect device and usage data (e.g., device model, OS version, app version, crash traces, event timestamps) and transmit it to their providers, who act as our processors under Data Processing Agreements. We configure SDKs so that message content, sexual orientation, and other special category data are not transmitted to analytics or advertising platforms, and we do not permit any SDK to use your data for its own behavioural advertising purposes. We review SDK data flows before integration and periodically thereafter.
- Cookies and Similar Technologies: See Section 15.
4.3 Biometric Data (Selfie Verification)
If you use optional selfie verification, our processing partner analyses facial geometry solely to compare your selfie with your profile photos and/or ID document. The biometric template is used exclusively for that single verification event and is deleted promptly after the check completes. We do not build, maintain, or contribute to any facial recognition database, and we do not sell, share, or repurpose biometric data. This paragraph, together with the retention table in Section 10, constitutes our publicly available written retention and destruction schedule for biometric data: biometric identifiers and templates are used for the single verification event only and are permanently destroyed promptly upon completion of that check, and in any event no later than any shorter period required by applicable biometric privacy laws. Legal basis: explicit consent, which you give through a dedicated consent screen before initiating the verification. Verification data is subject to heightened, restricted access controls. Declining verification may limit access to verified-only features but does not prevent basic use of the Service.
Fraudulent accounts: if you create or attempt to create a fake, impersonating, or fraudulent account, we may retain and use the associated data (including verification data and device identifiers) for fraud prevention, enforcement, and ban enforcement, disclose it to law enforcement or affected third parties where lawful, and use it in de-identified form to improve our fraud-detection systems. The protections in this Policy that assume good-faith use of the Service do not restrict these anti-fraud uses.
4.4 Data From Third Parties
We may receive data about you from payment processors (transaction status, chargeback notices), app stores (purchase and refund notifications), fraud-prevention and sanctions-screening providers, and law enforcement or regulators where they contact us. We are entitled to rely in good faith on the accuracy of data received from such sources.
4.5 Data About Others
If you report another user or reference third parties in messages, we process that data as part of our safety obligations. You must not upload personal data of any third party without their permission; you are solely responsible, and liable to us and to affected persons, for any such unauthorised upload.
5. Purposes and Legal Bases
| Purpose | Legal Basis |
|---|---|
| Account creation, matchmaking, delivering messages, providing purchased features | Contractual necessity (Art. 6(1)(b)) |
| Payment processing, subscription management, refunds | Contractual necessity; Legal obligation |
| Age verification; identity verification | Legal obligation (incl. Online Safety Act 2023); Legitimate interests |
| Content moderation; detection of solicitation, harassment, scams, fraud, spam, and prohibited conduct | Legitimate interests; Legal obligation |
| Security, bot detection, multi-account prevention, ban enforcement | Legitimate interests (protecting users and the Service) |
| Deriving approximate location from IP/GPS for matching, localisation, and fraud prevention | Contractual necessity; Legitimate interests; Consent (for device GPS) |
| Analytics, service improvement, A/B testing, algorithm improvement | Legitimate interests |
| Profile recommendations and personalisation | Legitimate interests; Contractual necessity |
| Marketing communications | Consent, or the «soft opt-in» for our own similar services (PECR Reg. 22(3)), with opt-out in every message |
| Processing special category data for matching | Explicit consent (Art. 9(2)(a)) |
| Defence of legal claims, chargebacks, disputes, and regulatory proceedings | Legitimate interests (Art. 6(1)(f)); establishment, exercise or defence of legal claims (Art. 9(2)(f) where relevant) |
| Compliance with tax, accounting, AML, sanctions, court orders | Legal obligation |
| Vital interests (e.g., credible threat of imminent harm) | Vital interests (Art. 6(1)(d)) |
Where we rely on legitimate interests, we have conducted balancing assessments and concluded our interests are not overridden by your rights. You may request further information about these assessments.
6. Automated Processing and Profiling
The Service uses algorithms to suggest potentially compatible profiles based on your stated preferences and in-app activity. This is inherent to a matchmaking service and is performed under contractual necessity. Suggestions are recommendations only; we make no representation, warranty, or guarantee as to the accuracy, compatibility, identity, character, conduct, or intentions of any suggested or matched user.
We do not make solely automated decisions producing legal or similarly significant effects on you without human involvement, except automated safety systems that may temporarily restrict accounts pending human review (e.g., suspected fraud, underage indicators, or Terms violations). You may contest any such restriction and request human review via [email protected].
7. Content Moderation and Safety — No Guarantee
To keep the Service safe and comply with the Online Safety Act 2023 and equivalent laws, we may use automated tools and human moderators to scan profiles, photos, and messages on the Service for illegal content, solicitation, commercial activity, harassment, underage use, fraud, and other violations of our Terms of Service. By using the Service you acknowledge that user-to-user communications on the platform are subject to such moderation.
Moderation is conducted on a reasonable-efforts basis. No moderation system — automated or human — detects all harmful content, fake profiles, or bad actors, and we do not warrant or guarantee that the Service is free of them. We do not conduct criminal background checks or identity vetting of users beyond the optional verification features described in this Policy, and «verification» confirms only what the specific check covers (e.g., photo-to-selfie similarity), not a user’s character, intentions, wealth, occupation, or trustworthiness.
We may preserve evidence of violations, suspend or terminate accounts, and report serious matters (including suspected child sexual exploitation, human trafficking, or credible threats of violence) to the National Crime Agency, law enforcement, or specialised NGOs, in any relevant jurisdiction. Our moderation and safety systems apply only to activity on the Service and cannot extend to communications conducted on third-party services (see Section 17).
8. How We Share Your Information
We do not sell your personal data, and we do not disclose your personal data to third parties for their own behavioural or targeted advertising purposes. Where we advertise our own Service on third-party platforms, we do so using aggregate or contextual methods and consented conversion measurement only, never by transmitting your profile content, message content, or special category data to advertising platforms. We share data only as follows:
- Other Users: Your profile content is visible to other users in accordance with the Service’s visibility model. Your email address, phone number, payment details, verification documents, and precise location are not shown to other users by us. Any information you yourself choose to reveal to another user (in your profile, in messages, or otherwise) is disclosed at your own risk (see Section 3).
- Service Providers (Processors): Hosting and infrastructure (e.g., Amazon Web Services), payment processing (including Google Play for in-app purchases), identity/age verification, content moderation, image processing, communications delivery, analytics, crash reporting, and customer support tooling; and geolocation providers, which receive only the minimum technical data required (truncated coordinates and/or IP address) without any identifying account information, solely to return place names and network-risk signals to us. All processors are bound by Data Processing Agreements meeting Article 28 UK GDPR requirements and may act only on our documented instructions. A current list of our sub-processors by category is available on request via [email protected]; the detailed list is proprietary and provided in confidence, and may not be redistributed or used for any other purpose. To the maximum extent permitted by law, we are not liable for damage caused by a processor acting outside or contrary to our documented instructions.
- Payment Dispute Defence: In the event of a chargeback, refund dispute, or fraud claim, we reserve the right to disclose strictly relevant evidence to banks, card schemes, payment processors, and app stores — including account registration data, IP and access logs, usage timestamps, purchase acknowledgments, and proof of service delivery — to demonstrate that the service was provided as agreed. This is a legitimate interest of which you are hereby informed.
- Legal and Safety Disclosures: We may disclose data where we believe in good faith that disclosure is required or permitted by law, regulation, legal process, or governmental request in any jurisdiction where we operate; or is reasonably necessary to enforce our Terms, detect or prevent fraud or security issues, protect the rights, property, or safety of Glambu, our users, or the public, or establish, exercise, or defend legal claims. We shall not be liable for any disclosure made in good faith under this paragraph.
- Safety Partners: Where legally permitted, we may share data about suspected or confirmed bad actors (e.g., fraud rings, scammers, individuals banned for endangering users) with, and receive such data from, other platforms, industry safety coalitions, fraud-prevention services, and companies facing similar threats, solely to protect the safety, security, and integrity of our Service and our users.
- Report Outcomes: If another user submits a report involving you (for example, an alleged violation of our Terms), we may inform the reporter of the action we took, if any; the same applies to reports you submit about others.
- Data Requests by Other Users: If another user exercises their right to a copy of their personal data, their export may include messages you sent them, since those messages form part of their conversation data.
- Group Companies: With any current or future parent, subsidiary, or affiliate under common control, for purposes consistent with this Policy.
- Business Transfers: In connection with any merger, acquisition, financing, reorganisation, insolvency, or sale of assets, your data may be disclosed to counterparties under confidentiality obligations and transferred to a successor entity. The successor will be bound by this Policy or will notify you of material changes.
- Aggregated / Anonymised Data: We may create and freely use, retain, and share data that no longer identifies you (e.g., aggregate statistics, derived insights), including to develop and improve our features, safety systems, and technologies, such as through machine learning. Such data is not personal data, is not subject to this Policy, and is our property.
- With Your Direction: Where you instruct or consent to a disclosure.
9. International Data Transfers
Your data is primarily stored in the UK/EEA. If you use the Service from outside the UK/EEA, you acknowledge that your data will be transferred to and processed in the UK/EEA and in the other locations described in this Section, where data protection laws may differ from those of your country. Where we transfer personal data outside the UK/EEA, we implement appropriate safeguards: UK adequacy regulations or EU adequacy decisions where available; otherwise the UK International Data Transfer Agreement (IDTA), the UK Addendum to the EU Standard Contractual Clauses, or the EU SCCs, supplemented by transfer risk assessments and technical measures (encryption in transit and at rest).
Certain technical service providers (including geolocation providers) may be located in jurisdictions without a UK or EU adequacy decision, such as Australia or the United States. In all such cases, transfers are protected by the UK IDTA or UK Addendum to the EU SCCs, together with contractual data-minimisation, retention-limitation, and no-reuse obligations, and supplementary technical measures (transmission of pseudonymised or truncated data only, TLS encryption). You may request a copy of the relevant safeguards (redacted for commercial confidentiality) via [email protected].
10. Data Retention
We retain personal data no longer than necessary for the purposes described, subject to legal, accounting, and reporting requirements. The periods below are operational targets (see Section 2):
| Category | Retention |
|---|---|
| Active account data | Duration of membership |
| Deleted accounts (profile data) | Profile no longer visible upon closure; data deleted or irreversibly anonymised within approximately 30 days, subject to the safety retention window and other exceptions below |
| Safety retention window | Following account closure, relevant data may be retained for up to 3 months — and following a ban, up to 12 months — to investigate unlawful or harmful conduct, protect potential victims, and enforce bans (legitimate interests of Glambu, our users, and third parties) |
| Data reasonably necessary in anticipation of potential litigation | Up to 12 months following account closure, for the establishment, exercise, or defence of legal claims |
| Records of consents you give us | 6 years, to evidence compliance with applicable law |
| Customer support and moderation correspondence | 6 years from the communication, to support our decisions and defend against claims |
| Inactive accounts | Deleted after 6–12 months of inactivity (no invitation sent, accepted, or declined for 6 months), following notice where feasible |
| Transaction and billing records | 6–7 years (UK tax/accounting law, HMRC) |
| Verification/ID documents | Deleted within approximately 30 days of verification completion, unless retained as evidence in an open investigation or dispute |
| Biometric verification templates | Deleted promptly upon completion of the individual verification check |
| Ban-enforcement data (device IDs, hashed email/phone identifiers, ban reason) | Retained indefinitely to prevent banned users from re-registering and endangering the community (legitimate interest in user safety) |
| Moderation and safety records, abuse reports | Up to 7 years, or longer where required as evidence |
| Data relevant to actual or reasonably anticipated legal claims, disputes, chargebacks, or regulatory proceedings | Until final resolution plus applicable limitation periods (generally 6 years in England and Wales) |
| Server logs, IP logs | Up to 24 months |
We may retain data beyond these periods where required by law, court order, or regulator, where reasonably necessary for the establishment, exercise, or defence of legal claims, or where deletion is technically infeasible in backups, in which case the data is isolated from further processing until backup expiry.
11. Security and Breach Notification
We implement technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, access controls on a need-to-know basis, media access restricted to authenticated, time-limited requests, logging, and staff confidentiality obligations. A limited number of authorised personnel may access account data, photos, and message content strictly where necessary for customer support, safety investigations, content moderation, fraud prevention, or legal compliance; such access is role-restricted, logged, and subject to confidentiality obligations, and is never used for curiosity or any purpose unrelated to those functions. However, as set out in Section 3, no method of transmission or storage is completely secure, and we do not warrant or guarantee absolute security. The existence of security measures is not a representation that incidents cannot occur.
In the event of a personal data breach, we will assess and, where legally required, notify the ICO and/or other competent supervisory authorities and affected users in accordance with Articles 33–34 UK GDPR and other applicable breach-notification laws. By using the Service, you agree that we may provide all notices under this Policy — including any security-incident notices — electronically (by email to your registered address and/or in-app or website notice). Where the law of your place of residence entitles you to written notice of a security breach, you may request written notice, or withdraw consent to electronic-only notice, via [email protected]. Our provision of notification, remediation, or support following an incident is not an admission of fault, negligence, or liability.
12. Your Rights (UK / EU)
Subject to legal conditions and exemptions, you have the right to: access your data; rectify inaccurate data; erasure; restriction of processing; object to processing based on legitimate interests (including an absolute right to object to direct marketing); data portability; and withdraw consent at any time (without affecting prior processing). Withdrawal of consent essential to the Service (e.g., special category data used for matching) may result in loss of functionality or account closure.
How to exercise: Email [email protected] or use in-app controls. We verify the identity of all requesters and may request additional information to do so; we will not act on requests we cannot verify, to protect you from fraudulent requests, and we are not liable for declining to act on an unverifiable request. We respond within one month, extendable by two further months for complex or numerous requests. We may refuse, or charge a reasonable fee for, requests that are manifestly unfounded or excessive, including repetitive requests (Art. 12(5) UK GDPR). We may also decline a request, in whole or in part, where fulfilling it would be unlawful, would adversely affect the rights and freedoms of others (including their privacy), or would reveal trade secrets, security mechanisms, or intellectual property; where possible we will fulfil the remainder of the request. Requests concerning another person’s data must be made by that person.
Exceptions: We may retain data notwithstanding an erasure request where retention is necessary for compliance with legal obligations, the establishment, exercise, or defence of legal claims, fraud and ban enforcement, or freedom of expression — as permitted by Article 17(3) UK GDPR. Erasure applies to data under our control; we cannot erase copies of your content that other users or third parties captured or redistributed (see Section 3), and an erasure request does not oblige us to pursue such third parties.
13. Regional Provisions
13.1 United States (California and Other States)
We do not «sell» personal data or «share» it for cross-context behavioural advertising as defined by the CCPA/CPRA, and we do not engage in «targeted advertising» or profiling in furtherance of decisions that produce legal or similarly significant effects as defined under applicable US state privacy laws. Because we do not sell or share personal data, opt-out signals such as the Global Privacy Control (GPC) do not change our processing, but we will honour such signals to the extent required by applicable law. Do Not Track: there is no industry standard for responding to browser «Do Not Track» signals, and we do not respond to them.
California residents have rights under the CCPA/CPRA to know, access, delete, correct, opt out of sale/sharing, limit use of sensitive personal information, and non-discrimination. Residents of Colorado, Connecticut, Delaware, Iowa, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Texas, Utah, Virginia, and other states with comprehensive privacy laws have equivalent rights to confirm processing, access, correct, delete, obtain a copy, and opt out of sale, targeted advertising, and significant profiling. Under Nevada law (SB 220), Nevada consumers may opt out of the sale of covered information; we do not sell such information and will not do so without providing notice and an opt-out. Submit requests (directly or via an authorised agent with proof of authority) to [email protected]; requests are subject to identity verification, and we retain records of requests and our responses for at least 24 months as required by law.
Appeals: If we deny your privacy request and you reside in a state whose law provides an appeal right (including Colorado, Connecticut, Delaware, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, and Virginia), you may appeal by replying to our decision or emailing [email protected] with the subject «Privacy Request Appeal.» If you are dissatisfied with the outcome of your appeal, you may contact your state attorney general.
Consumer health data (Washington, Nevada, and similar laws): Certain information processed by a dating service — such as data revealing sexual orientation — may be treated as «consumer health data» under laws such as Washington’s My Health My Data Act and Nevada SB 370. We collect and process such data only with your consent, only for the purposes described in this Policy, and we do not sell it. You may exercise access, withdrawal, and deletion rights over such data via [email protected]. To the maximum extent permitted in your jurisdiction, any dispute relating to this Policy shall be resolved on an individual basis, and you waive participation in class or representative actions; this sentence does not apply where such waivers are unenforceable (including for UK and EU consumers).
13.2 Brazil (LGPD)
For users in Brazil, we process personal data in accordance with the Lei Geral de Proteção de Dados (Law 13.709/2018) on the legal bases of contract performance, legal obligation, legitimate interest, and consent (including specific consent for sensitive data). You may exercise LGPD rights (confirmation, access, correction, anonymisation, portability, deletion, information on sharing, and revocation of consent) via [email protected], and may lodge complaints with the ANPD (https://www.gov.br/anpd).
13.3 India (DPDP Act 2023)
For users in India, we act as a Data Fiduciary under the Digital Personal Data Protection Act, 2023. We process personal data for the lawful purposes described in this Policy with your consent or for legitimate uses recognised by the Act. You have rights to access, correction, erasure, grievance redressal, and nomination. Grievances: [email protected] (Grievance Officer contact available on request). You may escalate to the Data Protection Board of India.
13.4 Latin America (Mexico, Argentina, Peru, Chile, Colombia)
We honour applicable rights of access, rectification, cancellation, and opposition («ARCO» rights and equivalents) under local data protection laws, exercisable via [email protected].
Where local law conflicts with this Policy, local mandatory law prevails for users in that jurisdiction; all other provisions remain in full force.
14. Children
The Service is strictly for adults aged 18+. We do not knowingly collect data from anyone under 18. We deploy age-assurance measures and moderation signals to detect underage use; no age-assurance method is infallible, and we are entitled to rely in good faith on the date of birth and identity information users provide. If we determine a user is under 18, we will terminate the account and delete the data, retaining only the minimum identifiers needed to prevent re-registration. Report suspected underage users to [email protected].
15. Cookies and Similar Technologies
We use strictly necessary cookies/SDK storage (authentication, security, fraud prevention, load balancing) without consent, as permitted by PECR; and analytics or preference cookies only with your consent where required, managed via our consent banner or device settings. Blocking strictly necessary cookies may render the Service unusable. Where we publish a separate Cookie Policy on our website, it provides further detail and forms part of this Policy.
16. Marketing Communications
We may send you service-related communications (transactional, security, and legal notices) which you cannot opt out of while you hold an account, as they are necessary to operate the Service. Marketing emails and push notifications are sent only with consent or under the soft opt-in, and every marketing message contains an unsubscribe mechanism. Opting out of marketing does not affect service communications.
17. Off-Platform Communications and Interactions
This Policy applies only to data processed through the Service. If you choose to move conversations to third-party services (e.g., WhatsApp, Telegram, phone, email, social media) or to meet another user in person, you do so entirely at your own risk and outside the scope of this Policy and our safety systems. We do not receive, monitor, moderate, or store off-platform communications, cannot enforce our content or safety rules there, and, to the maximum extent permitted by law, accept no responsibility or liability for any content exchanged, information disclosed, or harm arising outside the Service — including in-person meetings between users. We strongly recommend keeping conversations within the Service, where our safety and moderation measures apply, until you trust the other user, and following basic safety practices when meeting anyone in person.
18. Your Responsibilities and Warranties
You warrant that you are at least 18 years old, that all information you provide is accurate, and that content you upload is lawful and does not infringe the rights of any person. You are solely responsible for the content you upload, for information you choose to reveal to other users, and for your interactions with other users on and off the platform. To the maximum extent permitted by applicable law, you agree to indemnify us against claims by third parties arising from your content, your breach of this Policy or our Terms, or your unlawful conduct. (For consumers in jurisdictions where such indemnities are restricted, this applies only to the extent permitted.)
19. Limitations, Severability and Interpretation
- Limitation of liability: The exclusions and limitations of liability in our Terms of Service apply to all matters arising out of or in connection with this Policy and our processing of personal data, to the maximum extent permitted by applicable law. Nothing in this Policy or our Terms excludes or limits liability for death or personal injury caused by negligence, for fraud or fraudulent misrepresentation, or any statutory right or liability that cannot lawfully be excluded or limited (including your rights under Articles 77–82 UK/EU GDPR).
- Complaints first: Before initiating any claim relating to this Policy, you agree to first contact us at [email protected] with a description of the issue and allow us 30 days to respond and, where appropriate, remediate. This does not limit your right to complain to a supervisory authority at any time.
- Severability: If any provision of this Policy is held invalid or unenforceable in a given jurisdiction, that provision is deemed modified to the minimum extent necessary or, if incapable of modification, severed for that jurisdiction only, and all remaining provisions continue in full force.
- No waiver: Our failure to enforce any provision is not a waiver of it.
- Interpretation: Headings are for convenience only. «Including» means «including without limitation.»
20. Changes to This Policy
We may amend this Policy at any time. Material changes will be notified by email, in-app notice, or prominent posting, at least where required by law, before taking effect. The Effective Date above reflects the latest revision. Changes apply prospectively only. If a change would permit a materially new use or disclosure of personal data collected before the change — in particular any new use of special category or biometric data — we will not apply it to previously collected data without obtaining fresh consent or another valid legal basis. Continued use of the Service after the effective date of a revised Policy constitutes acknowledgment of the revised Policy. We recommend you review this page periodically. Prior versions are available on request via [email protected].
21. Governing Law
This Policy and any non-contractual obligations arising out of or in connection with it are governed by the laws of England and Wales, and the courts of England and Wales shall have jurisdiction, without prejudice to mandatory consumer and data protection rights (including rights of forum) available to you under the law of your country of residence.
22. Complaints and Contact
- Email: [email protected]
- Mail: Glambu Limited, 3rd Floor Suite 207, Regent Street, London, W1B 3HH, United Kingdom
- Data Protection queries: [email protected] (Attn: Data Protection)
You may request a paper copy of this Policy at any time via the addresses above.
You have the right to lodge a complaint with the UK Information Commissioner’s Office (https://www.ico.org.uk) or your local supervisory authority. We would appreciate the opportunity to address your concerns first.
