Privacy Policy

Last updated: July 27, 2026

50/50 is a dating app where both people put in half. This policy explains, in plain English, what we collect, why we collect it, how we protect it, and the control you have over it. We've tried to describe what the app actually does today, not a generic template and not features we only intend to build.

50/50 is for adults. The app is not directed to children, and you must be 18 or older to create a profile and enter the pool. We enforce this with a hard birthdate check during onboarding. The App Store age rating is 17+.

Who we are

50/50 is an independent product operated by Luminous Peak LLC, the company behind 5050dating.org. That company is the business responsible for the personal information described here. Our contact details are in Contact at the bottom of this page.

The short version

  • We collect what the app needs to work. The main categories are your sign-in identity, your profile, your photos, your verification selfies, your messages, your date plans if you use them, your purchase records if you buy anything, a device token for notifications, and the ordinary technical data any server sees, including the IP address your device connects from. The sections below walk through each one.
  • We do not run ads, and we do not use third-party ad networks, analytics SDKs, or tracking tools. We do not sell your data, and we do not share it with data brokers.
  • Your verification selfies are compared by a human being to your profile photos, by eye, for verification only. No software looks at the face in them. We never generate or store a faceprint or any biometric template.
  • You can delete your account, and the data tied to it, from inside the app at any time.

What we collect and why

Sign-in identity

You sign in with Sign in with Apple or Google. From that, we receive and store a stable account identifier and, when provided, your email address and name. If you use Sign in with Apple, your email may be an Apple private-relay address, or may not be shared at all. That's fine, and the app still works. We use this identity only to create and secure your account and to sign you in.

Birthdate

We collect your birthdate once, during onboarding, and it is put to three uses. It enforces the 18+ requirement. Your age is worked out from it and shown on your profile to other users: that is the "Alex, 24" on your card. And it decides which age-range filters you fall inside, so it affects whose deck you appear in. Other people see the age; they never see the birthdate itself, which stays on our side. Your birthdate is set a single time and cannot be changed afterward.

Profile

We collect the profile you build, which may include:

  • Your first name.
  • Your gender and who you're interested in.
  • Your written prompt answers.
  • An optional height.
  • Your campus.
  • A coarse location: your city and rounded coordinates. When you tap to share your location, your phone takes a normal GPS reading and sends it to our API, which rounds it to roughly a kilometer before saving it. The full-precision reading is never written to our database, and no screen in the app shows the distance between you and anyone else.
  • Your matching preferences (such as who you're interested in and an age range).

Note on sensitive data: because "interested in" can reveal sexual orientation, we treat it as sensitive information. We collect it for one reason (to match you with people) and for nothing else.

Photos

You upload profile photos (between two and six). These are stored privately and are shown to other users as part of your profile inside the app.

Profile photos go through an automated explicit-content check. When that check is switched on, a copy of the photo you just uploaded is sent to Microsoft Azure AI Content Safety, a third-party service acting for us, which rates the picture for sexual, violent, self-harm and hateful content. What comes back to us is those four severity scores and nothing else. A high score hides the photo until a person reviews it; a middling one leaves it visible but puts it in front of a person. The check happens after your upload finishes and never blocks it, and while it is switched off no photo leaves our own storage for it. This is content rating, not face recognition. It does not detect, measure, or match a face, and it is never run on your verification selfies.

Verification selfies

To keep the pool real and reduce fake profiles and catfishing, we ask you to take a live selfie with your front camera during onboarding. Before you take it, we show you a consent screen explaining what it's for, who sees it, how long we keep it, and that the comparison is done by a human only. How we use it:

  • An administrator visually compares your selfie to your profile photos, by eye, to confirm you're a real person who matches your photos.
  • You get up to three verification attempts, and we keep each one you submit. If an administrator can't confirm a selfie, that selfie is not thrown away. It is kept with the reason it was turned down, and your next attempt is stored alongside it. So an account can end up holding as many as three selfies, not one. After the third, no further attempts can be submitted.
  • We never generate, derive, or store a faceprint, face-geometry template, or any other biometric identifier from your selfie. The comparison is manual and human only. This is a deliberate design and legal choice: your selfie is treated as a photograph, not as biometric data.
  • Your selfies are stored as private, encrypted objects. No other user can ever see one, and they are never sent to an outside service for any kind of automated check.
  • We delete them when you delete your account, along with the rest of your images: every selfie you submitted, approved or rejected. That is the deletion that exists today, and it is the one the in-app consent screen describes. Until then they stay in our private storage. If that ever changes, this page changes with it.

Messages

When you match and chat, we store your messages so the conversation works across your devices. Message contents are encrypted at rest (ChaCha20-Poly1305). We can access message contents only in two situations: to deliver the conversation to you and your match, and, for an administrator working a specific abuse report, as part of reviewing that report, which writes an internal audit record. We do not browse conversations.

Dates and plans

If you and your match use the date planner, we store what the two of you put into it:

  • Your availability, meaning the rough day parts (morning, afternoon, evening, late) you mark as workable for a specific match. We use it only to show the two of you where your answers overlap. It is never combined across matches, never shown to anyone outside the pair, and never used to order your deck.
  • The plan itself, meaning the place (either one from our suggested campus list or a place you type in yourself), the start time, and any note you write. The note is free text, so whatever you put in it is what we store.
  • Your private "again?" answer. After a date, each of you is asked privately whether you'd see the other person again. Your answer is only ever revealed if both of you said yes. A "no" and never answering at all are deliberately built to look identical to the other person: there is no "they declined", no "they answered", and no waiting indicator, ever. This is an intimate piece of information and we treat it that way: it is deleted outright when you delete your account.

Nothing in the planner is a booking. We don't reserve anything, take no payment for a venue, and earn nothing from any place we suggest.

Purchases and subscriptions

If you buy a paid plan or a paid one-time feature, we store a record of that entitlement: which product it is, how it was granted, when it started, when it expires, and whether it was later revoked or refunded. When a purchase is made through the App Store, that record includes Apple's transaction identifier so the same purchase can't be credited twice.

We do not receive or store your card number, bank details, or billing address. Payment is handled entirely by Apple; we only ever see that a purchase happened. Note that purchase records are one of the few things that outlive account deletion; see "Data we keep for safety" below.

How you use the app

To run the daily deck and the matching loop, we record your likes and passes, which profiles you've already been shown, when each match was revealed to you, and whether you answered a new match inside the reply window. The reply-window outcomes are what produce the reply-rate figure described under "Who can see what" below.

These do not all go the same way when you delete your account, so we want to be exact about it. Your likes and passes, and the record of which profiles you were shown, are deleted, along with the stored reply-rate figure itself. The reply-window and reveal timestamps are not. A reply window still running when you delete is closed and discounted, counting for or against nobody; a window that had already finished keeps its result, and the timestamp of when each match was revealed is kept as it is. Both stay attached to the match they belong to. They hold timings and an outcome, with no name, no photo, and no message text, and they are described again under "Data we keep for safety" below.

Notifications

If you allow notifications, we store a device push token so we can send you app notifications (for example, that a match of yours is ready to be revealed, or that you have a new message). If Apple tells us the token no longer works, we mark it as out of use and stop sending to it. We keep the record rather than erasing it, so a retired token leaves an auditable trace instead of silently vanishing. If the same device registers again, that record is reactivated. Your device tokens are deleted when you delete your account.

Reports and safety records

If you report another user, we keep the report, including any message excerpt you choose to attach, so we can act on it and maintain a safety record. This is described further under "Data we keep for safety" below.

Technical data and server logs

Like any app that talks to a server, 50/50 sees the IP address your device connects from, because that is how a reply reaches your phone at all. Here is what happens with it:

  • Request logs. Our API logs the requests it serves, and those log lines include the IP address the request came from along with the method and path. This is ordinary operational logging: we use it to see errors and to investigate abuse.
  • Rate limiting. We cap how often the same caller can hit sensitive endpoints, so that one script can't flood them. Most caps are counted against your account. Some are counted against the IP address instead: signing in, creating an account, refreshing a session, and submitting your birthdate during setup all work that way, because the point there is to stop somebody signing up or guessing in bulk from one place. Those counters live in the API's memory, are not written to our database, and are lost whenever the service restarts.

Beyond those two uses, we don't do anything with your IP address: we don't attach it to your profile and we don't use it to build a location or an advertising profile. As the app works today, no IP address is written into our database at all. To be exact rather than sweeping about that: our database design contains one unused column meant to hold an IP address, belonging to a phone sign-in method we have not built and never write to. If that ever goes live, this page changes with it.

On log retention we would rather be plain than reassuring: we have not set a retention period of our own, so request logs persist for as long as our hosting provider keeps them.

What we do NOT do

  • No advertising. We show no ads and run no paid-ad tracking. Growth is word of mouth, not paid acquisition.
  • No third-party analytics or crash-reporting SDKs in this version of the app.
  • No selling or sharing of your personal data with data brokers or advertisers.
  • No faceprints or biometric templates, ever, by any part of the app. Nothing we run detects faces, compares one face to another, or estimates an age from a picture. Verification is a person looking at two images.
  • No precise location in our database. Coordinates are rounded to roughly a kilometer before they are saved, and no screen shows the distance between people.
  • No payment details. We never receive or store your card or bank information.
  • No outside use of your images beyond one check. Your photos and selfies live in our private file storage and are shown inside the app. The only place an image of yours is sent beyond that is the explicit-content check described under "Photos", and that applies to profile photos only, returns category severity scores, and is never run on a verification selfie.

Cookies and web tracking

The 50/50 mobile app does not use advertising or tracking cookies. Neither does our marketing website (5050dating.org): there is no ad-network pixel on it, no analytics product, and nothing that follows you to other sites. It is a small site, but it is not inert, so here is the honest inventory of what it does:

  • The waitlist form. When you submit it, we store a record holding the email address you typed, which form on the page you used, and the date and time you first signed up. We keep it in our hosting provider's key-value storage, with no expiry, and we use it to contact you about early access. Submitting the same address again updates that record instead of adding a second one, and keeps the original signup time.
  • A confirmation email. When email delivery is configured, a first-time signup sends one confirmation message through our email provider, which necessarily receives your address in order to deliver it. Re-submitting an address already on the list sends nothing.
  • Abuse counters keyed to your IP address. So that a script can't hammer the signup form or grind at the password on our internal waitlist export, the site keeps short-lived counters keyed to the visitor's IP address. Each one records how many attempts came from that address in the current hour and nothing more, it is stored apart from the waitlist records and is never joined to your email, and it deletes itself within a couple of hours.
  • A bot check, when it is switched on. The signup form is wired for Cloudflare Turnstile, which asks Cloudflare to judge whether a submission came from a person. It runs only when we have configured it, and while it is off nothing is sent to Cloudflare for it. When it is on, your IP address and the signals Turnstile collects in your browser go to Cloudflare for that check.
  • Web fonts. The site's typefaces are loaded from Google Fonts, so opening a page on 5050dating.org, this one included, makes a request to Google that necessarily carries your IP address and browser details.

How we protect your data

  • Your device never talks to our database. The app only talks to our API over an encrypted (TLS) connection, and our API is the only thing that can reach the database. There is no public, internet-reachable database.
  • Photos and selfies are private. They're stored as private objects and are served only through short-lived, signed links generated per request, never a permanent public URL. Verification selfies have no user-facing view path at all; only administrators can see them, and only for review.
  • Messages are encrypted at rest with a server-held key that never reaches your device.
  • Sensitive tokens are never stored in the clear. Sign-in refresh tokens and one-time codes are stored only as hashes.
  • All traffic uses TLS. Nothing sensitive travels unencrypted.

Who can see what

  • Other users see the profile card the app builds for you. It carries your photos, your first name, your age, your campus, your city, your height, your prompt answers, and a Verified badge. Your name and age are shown together, as "Alex, 24". We show the age worked out from your birthdate, never the birthdate itself. Optional details you haven't set, such as your height, are simply left off the card.
  • Your gender is not one of the fields printed on that card. We use it, together with who you said you're interested in, to decide whose deck you appear in, so people can still infer it from the fact that you were shown to them.
  • Other users also see how responsive you are. Your profile card shows a reply-rate percentage: how often you answered a new match's first message inside the reply window. Until you've had at least three reply windows finish, people see a "New" badge instead of a number. This is a figure calculated about you and shown to people you haven't matched with yet, so we want to be explicit about it. It counts first messages only; nothing you do in the date planner ever affects it.
  • Your matches can read the messages you exchange with them.
  • Administrators can see a verification selfie you submitted next to your profile photos for verification, and can access a reported conversation when working an abuse report. Both of these are limited, purpose-specific paths, not open browsing.
  • Service providers process data on our behalf to operate the service; they are not given your data for their own purposes. They include the cloud host our database runs on, the private file storage that holds your images, the content-safety service that rates uploaded profile photos described under "Photos" above, Apple (for delivering push notifications and for processing App Store purchases), and an alerting service that pings us when something is waiting for review. Those alerts are short. They say what kind of thing is waiting (the category a report was filed under, chosen from a fixed list of reasons, or the rating that flagged a photo), and the photo one also carries the internal record numbers for the user and the photo. None of them carries your name, your photos, your message text, or the note or excerpt someone attached to a report.

How long we keep your data

  • Account and profile data: kept while your account exists.
  • Photos: kept while your account exists.
  • Verification selfies: every selfie you submitted, including any that were turned down, is kept while your account exists and deleted when you delete your account.
  • Messages: kept for the life of a match.
  • Likes, passes, and the profiles you were shown: kept while your account exists, and deleted when you delete it.
  • Reply-window and reveal timestamps: kept for as long as the match they belong to. A window still open when you delete your account is closed and discounted; one that had already finished keeps its result, and the reveal timestamps are kept as they are.
  • Availability and "again?" answers: kept while your account exists, and deleted outright when you delete it.
  • Date plans: a plan belongs to both of you, so the place and time of a past date stay attached to that match. If you delete your account, any plan still open is cancelled and the note you wrote on it is erased.
  • Push tokens: kept while your account exists. When Apple tells us a device token is dead, we mark it as out of use and stop sending to it, but we keep the row; if the same device registers again, that row is simply reactivated. Your device tokens are deleted outright when you delete your account.
  • Sign-in tokens: kept while your account exists. A refresh token is stored only as a hash, carries a 30-day expiry, and is marked revoked when it is rotated, when you sign out, or when we revoke a whole chain after a suspicious reuse. We want to be plain here rather than reassuring: we run no job that sweeps up expired or revoked rows, so those hashes stay until you delete your account, which deletes them.

Data we keep for safety

To keep the community safe, to keep our books straight, and because some records belong to a match rather than to one person, a small amount of data intentionally outlives account deletion:

  • Abuse reports (and any attached message excerpt) are retained as a safety and audit record. If you delete your account, we strip the identifying details from your account record, but the record itself remains as the anchor those reports are attached to. It no longer carries your name, email, sign-in identifiers, campus, or birthdate, but it is a stand-in for your old account rather than a truly anonymous one.
  • Ban records. If an account has been banned, we keep a one-way hashed record of its sign-in identifiers, so that person can't simply delete the account and re-register to get around the ban. We store only the hash, never the raw identifier. A suspension is not recorded this way: deleting your account while it is suspended does not put your sign-in identifiers on that list.
  • Purchase records. If you ever bought something, that entitlement record is kept and marked as ended rather than deleted, including the App Store transaction identifier. We keep it so refunds, chargebacks and billing questions can still be traced afterwards.
  • When you delete your account, a revealed conversation you were part of ends visibly for the other person, and its encrypted messages may be retained as evidence tied to that closed match.
  • Reply-window and reveal timestamps. For each match, when the reply clock opened, whether it was answered in time, and when that match was revealed. They carry no name, photo, or message text, but they stay attached to the match and, through it, to the same stand-in account record described above, so they are not cut loose from you.

Your choices and rights

  • Delete your account. In the app, open the Profile tab and tap Delete account at the bottom. This removes your photos, your verification selfies, your profile, preferences, any match that hadn't been revealed yet, your likes and passes, your saved availability, and your private "again?" answers; cancels any date plan still open and clears the note you wrote on it; and strips the identifying details from your account record. What it does not remove is set out under "How long we keep your data" and "Data we keep for safety" above; read those before you tap it.
  • Edit your profile at any time from inside the app.
  • Access, correct, or delete your data by request. Email or write to us using the details in Contact below; that section also explains how we verify a request and how long we take to answer.
  • Permissions. Camera, notifications, and location are each requested with a clear prompt, and you can change them in your device settings at any time. Notifications are optional, and the app works without them. Location is required to finish setting up your account, because matching is built around who is near you; you can't skip that step. What we save from it is only the rounded, roughly kilometer-level position described above.

Depending on where you live, you may have additional rights over your personal data (such as access, correction, or deletion). To exercise any of them, use the contact details below. We will never charge you for making a request, and we will never give you a worse experience on 50/50 because you made one.

Children

50/50 is for adults only. It is not intended for anyone under 18, and we do not knowingly collect data from anyone under 18. If we learn that an account belongs to someone under 18, we remove it.

Changes to this policy

If we change how we handle your data, we'll update this page and revise the "Last updated" date above. Material changes will be communicated in the app.

Contact

Questions, requests, or concerns about this policy or your data go to the designated contact for 50/50:

Luminous Peak LLC
Email: [email protected]

How to exercise your access, correction, or deletion rights. Email [email protected] from the address on your account, and tell us which one you want: a copy of the personal information we hold about you, a correction to something that's wrong, or deletion of your data. So we don't hand your data to someone pretending to be you, we will ask you to confirm the request from your account before we act on it. We aim to acknowledge every request within 10 days and to answer it within 45 days. If a request is genuinely complicated we may take up to 45 more days, and we'll tell you why before we do. If we can't do part of what you asked, we'll tell you which part and the reason.

You don't have to write to us to delete your account: you can do it yourself at any time from the Profile tab in the app. For everything else, see our support page, our safety page, and our community guidelines.