Skip to content
All legal documents

Legal

Privacy policy

DateSMP is a dating service, which means almost everything it holds about you is personal and some of it is sensitive. This is the whole of what we keep, why we are allowed to, and what you can make us do about it.

Last updated 1 September 2026.

DateSMP has not launched publicly yet.

The operating business is being registered with the Dutch Chamber of Commerce, so this document does not yet name it. Everything else here is accurate and applies to the service as it runs today. The identifying details land on the legal information page the moment the registration completes.

The short version

  • We hold what you put on your profile, who you matched with, what you said to them, and what happened on your dates. That is the service; there is no way to run it without.
  • We do not sell data, do not run advertising, and have no advertising trackers. There is one third-party analytics product, Google Analytics, and it does not load at all unless you allow it. We also count what happens on DateSMP ourselves, in a form that is not attached to your name.
  • Voice on a date is a direct connection between the two devices where one can be made, and is never recorded. Where a network refuses a direct connection it is relayed, encrypted, by a server that cannot hear it.
  • You can export or delete everything from inside your account, and deletion is real deletion rather than a hidden flag.

Who is responsible

The data controller, the party that decides what is collected and why, is:

Trade name
Not yet registered: the trade name
Legal form
Not yet registered: the legal form
Responsible person
Not yet registered: the name of the sole trader
Chamber of Commerce
Not yet registered: the KVK number
VAT identification
Not yet registered: the btw-id
Address
Not yet registered: the registered address

Data protection questions go to privacy@datesmp.com. We are not large enough to be required to appoint a Data Protection Officer and have not appointed one; that address reaches the person who can act.

What we hold

What you give us

  • Your account. Email address, first name, date of birth, and the town you chose. The date of birth is kept rather than only your age, because an age that never changes is a birthday nobody has.
  • Your profile. Photographs, a bio, what you are looking for, interests, playstyles, prompt answers and the optional questions: height, drinking, smoking, children, star sign and the rest.
  • Your preferences. Who you want to be shown, the distance and age range you set, and your privacy switches.
  • Your Minecraft account, if you link one: the username and UUID. We never see your Microsoft or Mojang credentials, linking works by typing a code the server shows you in game.

What the service produces

  • Decisions. Every like and pass, kept so the deck does not show you the same person twice and so you can undo one.
  • Matches and messages. The conversation, its reactions, and when each message was read if you have receipts switched on.
  • Dates. Invitations, what you agreed to play, when the date ran, how long it lasted and the private feedback you left afterwards.
  • Reports and moderation. What was reported, by whom, and what a moderator decided.
  • Technical records. Session cookies, push subscriptions if you enable notifications, and server logs. Logs contain IP addresses and are kept short.

Special category data

Under article 9 of the GDPR, data revealing sexual orientation is a special category requiring stronger protection. Who you are interested in meeting is exactly that, and so, in practice, is your dating history. We hold it on the basis of your explicit consent, given when you fill it in, and you can withdraw that consent by changing or clearing the field, at which point you stop being matched, because there is nothing left to match on.

What we count about how DateSMP is used

Separately from your profile and your conversations, we keep a record of what happens on DateSMP so we can tell whether it works: how many people signed up, how many matched, how many got as far as a date in Minecraft, which activities people play, and where in the flow people give up.

These records are not attached to your name. Each one carries a code derived from your account id rather than the id itself, so the record says “somebody completed a date” and not who. They never contain a message, a photograph, an email address, a password, or anywhere more precise than the country. What an entry may carry is fixed in advance: a step of a flow, an activity name, a length in minutes, and nothing typed by anybody.

We do this on the basis of our legitimate interest in operating and improving the service. Nothing is stored on or read from your device for it, which is why it is not part of the cookie banner, and it goes to no third party. The detailed records are deleted after ninety days, leaving only daily totals, and deleting your account deletes yours immediately.

Why we are allowed to hold it

Running the service
Contract. Your account, profile, matches, messages and dates. Without these there is no service to perform.
Orientation and dating history
Explicit consent (art. 9(2)(a)). Withdrawable at any time by editing your profile.
Safety and moderation
Legitimate interests. Keeping adults safe from harassment and keeping minors off an 18+ service. We think any member would expect this, and a service that could not act on reports would not be one worth using.
Age assurance
Legal obligation and legitimate interests. DateSMP is 18+ and we are required to take that seriously. We keep your date of birth, the fact and version of your 18+ confirmation, and, on a phone, whether your App Store or Google Play account is an adult account. That last one is a yes, a no, or an age band; never a date of birth, never a document, and never a face.
Push notifications
Consent. Granted when you turn them on, withdrawn when you turn them off.
Analytics
Consent. Off until you allow it in the cookie banner, and withdrawable at any time from the cookie policy. Nothing is loaded before you agree.
Security logs
Legitimate interests. Detecting abuse, debugging failures, and keeping the service running.

Who else touches it

We do not sell data and we do not share it for anybody else's marketing. These processors handle it on our instructions, under contract:

Google (Firebase)
Authentication, the database, and photo storage. Processed in the EU where the service offers it. Google Ireland Limited, with standard contractual clauses for anything that leaves the EEA.
Vercel
Hosting for the website and the API. Requests are served from EU regions.
Push services
Apple, Google and Mozilla deliver notifications to your device. Our web notifications carry no content: the push is an empty signal and your browser fetches the text from us, so a push service never learns what the notification says.
Expo
Delivers notifications to the phone app. A notification's title and body pass through it.
Google (Analytics)
Only if you allow analytics. It receives which pages you opened and a truncated IP address, never your name, your email, your messages or who you matched with. Refuse it and nothing is sent, because the script is never fetched.
Mojang (Microsoft)
When your Minecraft character is shown, our server asks Mojang for your skin using the UUID of the account you linked, and sends the picture on to whoever is looking. Mojang is where that account already lives, so this tells them nothing they did not know, and because the request comes from us, nobody learns who is looking at whom and your viewers' addresses never reach them. We do not use a third-party skin renderer.
Minecraft servers
Operated by us. Your Minecraft username and UUID are visible to whoever you are on a date with, as they would be on any server.
Payment providers
If you donate, the provider handles the payment and we never see your card. Their privacy policy governs what they keep.

We will also disclose data where the law requires it, or where it is necessary to prevent serious harm to somebody. Both are rare and both are logged.

Voice

Voice on a date is a direct connection between the two devices wherever one can be made. The audio is never recorded, by us or anybody else. Two qualifications, because “peer to peer” is not the whole truth: some home networks refuse a direct connection, and the call is then relayed through a server so it can happen at all. The relay carries the audio without being able to hear it, because the encryption is between the two devices and the relay holds no key. And working out whether a direct connection is possible uses a public STUN server, which sees the network address of each side and nothing else. Setting up that connection requires each side to learn the other's network address, which is inherent to how the technology works and is the one thing voice reveals that text does not. Your microphone stays off until the server confirms you are both inside the world, and switches off again the instant either of you leaves.

How long we keep it

Your account and profile
Until you delete it, or until it has gone unused for two years. A dormant account is warned first and deleted thirty days later if nobody signs in; signing in once stops it. That runs on a schedule rather than when somebody remembers, and the deletion is the same one the Delete account button performs.
Photos
With your profile, until you delete the photo or the account. Every photo is looked at by one of our moderators before anyone else can see it: a rejected one is hidden from everybody and only you and the moderators can still see it.
Messages
For as long as the match exists. Unmatching deletes the conversation for both of you.
Dates and feedback
Kept while your account exists, because your own history is part of the product.
Likes and passes
Until you delete your account, so the deck does not repeat itself.
Reports
Kept for two years after they are resolved, and kept even if the reported account is deleted. A safety record that vanishes when somebody deletes and re-registers is not a safety record.
Usage records
Ninety days for the detailed entries, then only daily totals, which count people rather than name them. Yours are deleted with your account.
Server logs
Thirty days.
Donation records
Seven years. Dutch tax law requires it and we have no discretion about it.

Your rights

The GDPR gives you the following, and you exercise them by writing to privacy@datesmp.com or by using the controls in your account. We answer within one month.

  • Access. A copy of everything we hold about you, from Account → Download your data, as a file, without having to ask.
  • Rectification. Most of it you can correct yourself; write to us for the rest.
  • Erasure. Delete your account from Account → Delete account. It removes your profile, photographs, messages, matches and decisions. Reports about you are kept, as above.
  • Portability. The same download is structured JSON, which is what this right asks for. It leaves out messages other people wrote to you and other members' profiles: the right of access is to your data, and it stops where it would hand over somebody else's.
  • Objection and restriction. Against anything we do on the basis of legitimate interests.
  • Withdrawing consent. At any time, without affecting what was lawful before you withdrew it. The explicit consent covering who you are looking to meet is withdrawn from Account → Matching data, and we delete that answer with it.
  • Complaint. To the Autoriteit Persoonsgegevens, or to the authority where you live.

Automated decisions

Who appears in your deck is chosen automatically from your preferences, your location and who you have already answered. It has no legal effect on you and produces nothing you cannot change by changing your preferences, so it is not the kind of automated decision-making article 22 restricts. Nobody is ranked, scored or hidden by anything they paid for.

Every photograph is approved or refused by a person rather than by a classifier, and a report is always read by a person before anybody acts on it. That is slower than the alternative and it is the reason a new photo does not appear instantly.

Four things do happen without a person, and because they can stop you using your account we would rather list them than describe moderation as entirely human:

  • Entering a date of birth under 18 puts the account on hold immediately, before the date is stored.
  • If your phone's App Store or Google Play account tells us it belongs to a minor, the account is put on hold.
  • Enough separate people reporting an account as under 18 puts it on hold pending review.
  • An account nobody has signed in to for two years is warned and then deleted thirty days later. Signing in once stops it.

In each case the effect is a hold rather than a decision: nothing is deleted, and a person reviews it and can lift it. You have the right to that human review, to hear the reason, and to contest it, and the way to use that right is to write to support@datesmp.com. We hold to the 18+ rule because the alternative is a dating service with children on it, and we would rather occasionally inconvenience an adult who mistyped a year.

Children

DateSMP is strictly for adults aged 18 and over. We do not knowingly hold data about anybody younger. A report that an account belongs to a minor locks it immediately while it is reviewed, and a confirmed one is deleted. If you believe a child is using DateSMP, tell us at safety@datesmp.com and we will act the same day.

Security

  • Everything is served over TLS, and passwords do not exist, sign-in is an email link.
  • Your session lives in a cookie your browser will not let a script read, which is what stops a cross-site scripting bug becoming an account takeover.
  • Photographs are served from signed URLs that expire.
  • Access to production data is limited to the people who operate the service, and every one of them is the same person today.

No service is perfectly secure. If you find a hole, write to safety@datesmp.com and we will thank you properly.

Changes

When this policy changes materially we will tell you in the app before the change takes effect, rather than quietly editing the page and moving the date. The current version is always here, and every other document is one page away.

Questions about this document go to privacy@datesmp.com. Everything else is on the contact page.