What changed in version 3.4 (11 October 2026)
- You must now be at least 18 to use KF.Social (Sections 3 and 15).
- How we suggest people to meet: the main factors, the "New here" label, the daily limit on how often anyone is shown, and the records we keep for 180 days to check suggestions work (Section 3).
- Location: approximate device location, your connection's country, travel, "On the move", Premium Explore and the "Arriving" label (Section 3), and MaxMind and Mapbox (Section 9).
- A new, optional and private "open to dating" preference, which is special category data and needs your explicit consent (Section 5.3).
- The profile photo requirement, sending limits, telling friends about a new photo or bio, and location reminders (Sections 3, 8 and 13).
- How long we keep each of these (Section 11).
- We removed the description of AI post understanding and translation, because we do not run them (Section 3).
This Privacy Policy explains how KaneFilous Limited, as the data controller, collects, uses, shares, and protects your personal data when you use KF.Social. KF.Social is a social app for making friends and meeting people, with a feed, private messaging, interest communities, and in-person meetups. It explains our data practices and your rights under applicable data protection law, including the EU GDPR and, where applicable, UK data protection law.
1. About This Policy
This Privacy Policy applies to the website kf.social and the KF.Social apps for iOS, Android, and the web (together, the "Service"). It describes what personal data we collect, why we collect it, the lawful basis on which we process it, who we share it with, and your rights.
KaneFilous Limited is the data controller responsible for your personal data. If you have any questions about this policy or our data practices, you can contact us at privacy@kf.social.
2. Data Controller
The data controller for your personal data is KaneFilous Limited, a company registered in Ireland, which operates KF.Social. You can reach our privacy team at privacy@kf.social. Live location sharing, identity verification, dietary information and the optional dating preference involve more sensitive data and are covered separately in Sections 4 and 5.
3. What Data We Collect and Why
We collect different types of personal data depending on how you use the Service. Each category below sets out what we collect, the purpose, and our lawful basis for processing under GDPR. Special category data, meaning biometric identity-verification data, the dietary and allergy information you can provide for Dinners, and a dating preference if you choose to give one, is covered separately in Section 5, and live location sharing in Section 4.
Account and identity
We collect your name or display name, email address, and profile details such as your photo and bio. We also process your date of birth, age eligibility, chosen gender, interests, city or area, relationship and discovery preferences where you provide them, such as what you are looking for on KF.Social, the age range of people you would like to meet, who you are most comfortable meeting, the evenings you are usually free and your conversation style (these are never shown on your profile), and records of the terms, privacy notice and consent choices presented to you. When you sign up, you confirm you are at least 18. Your profile needs a photo of you before other members can find you in suggestions or before you can send friend requests or Super Waves; we tell you in the app before this applies to an existing account. Photos go through the automated moderation described below; we do not use face recognition to check that a photo shows you. Required account and booking fields are marked when collected; without them we may be unable to create your account, confirm eligibility or fulfil a booking. Optional profile information is not required to use the basic service. Lawful basis: performance of our contract with you to provide your account, and our legitimate interests in operating a safe service.
Sign-in providers
You can sign in with an email one-time passcode, Sign in with Apple (including Hide My Email, where Apple gives us a private relay address rather than your real email), Google Sign-In, or a passkey. We process the identifiers these methods return so we can authenticate you. Some links we send include a secure magic-link token that signs you in. Lawful basis: performance of our contract with you.
Content you create
We process the posts, comments, reactions, hashtags, mentions, and stories you share on the feed, and your direct messages, including text, voice notes, photos and video, and disappearing messages. We handle metadata for voice and video calls (such as who called whom and call duration) to connect and deliver calls; call audio and video are not recorded by us. We also process media you upload and the visibility level you choose for your content. Lawful basis: performance of our contract with you.
Clubs
When you join or are invited to a Club (an interest community, called a Gem in earlier versions of this policy), we process your membership, community posts, and community chat, and, where you use them, short-code invite links. Lawful basis: performance of our contract with you.
Dinners and in-person events
When you host or join a Dinner, we process your event participation, join and cancellation status, and the venue details shared with confirmed guests. If you provide dietary or allergy information for a Dinner, it is special category data and is handled as described in Section 5. Lawful basis: performance of our contract with you.
Bookings and payments
When you book a seat at a Dinner we record the booking and the Matching Fee. Payment is processed by Stripe: your card details are entered directly into Stripe's payment interface on your device and never touch our systems. We store booking and payment references, amounts, currency, payment and refund status, and records needed for reconciliation and support. For web subscriptions and other Stripe checkout features, we also process customer and subscription references, purchase history, and the billing or invoice information returned for that transaction. Stripe may collect contact, payment, billing and fraud-prevention information directly. We do not store full card numbers or card security codes. Lawful basis: performance of our contract with you, and our legal obligations to keep financial records.
Device, notifications, and technical data
We process device and push notification tokens, app version, and basic technical logs needed to deliver notifications, keep the Service secure, and diagnose problems. Lawful basis: performance of our contract with you and our legitimate interests in security and reliability.
Usage and analytics
We use PostHog (EU-hosted) for product analytics and Sentry for crash and error diagnostics. Analytics events can include account, installation, session and booking identifiers as well as device and interaction information. Identifiers are personal data even when they do not contain a name or email; our filters reduce the data sent but do not make every event anonymous. Section 7 explains analytics and campaign measurement. Lawful basis: your consent for optional product analytics on our website and in our apps, and for advertising measurement; our legitimate interests in crash diagnostics and in proportionate server-side measurement of the Service (such as counting bookings and payments). Consent to optional analytics or advertising is separate from accepting our Terms. On the website, Cookie settings lets you choose product analytics and advertising measurement separately. In the current versions of our apps, product analytics is off until you allow it: we ask once after you sign in, and you can change your choice at any time in Privacy settings. Crash diagnostics are needed to keep the apps working and are not part of that choice.
Communications
We send transactional emails and push notifications (such as sign-in codes, reminders, and safety messages) and, if you opt in, optional marketing. Lawful basis: performance of our contract for transactional messages, and your consent for marketing.
Safety and reports
If you report content or a person, or block someone, we process that report, block, and moderation data to keep the Service safe. To apply the sending limits in our Terms, we count the friend requests a free account sends in a rolling 24 hours; the count is kept only for that window. Lawful basis: our legitimate interests in running a safe service and complying with our legal obligations, including under the Digital Services Act.
Discovery, recommendations and matching
We suggest people you might like to meet, and Clubs, Plans and posts you might enjoy. We use your interests, profile and location preferences, connections, interactions, dismissals, availability and previous participation to do this, and we store inferred interests, recommendation and interaction records, and matching or compatibility results. Suggestions affect what you see and which introductions we offer; they are not a guarantee of compatibility.
How we suggest people. We look at: what you and they are looking for; the evenings you are both usually free; the interests you share (rarer shared interests count for more); whether each of you is inside the other's preferred age range; your conversation and group-energy style; mutual friends and whether you have been at a Plan with a friend of theirs; how recently each of you used KF.Social; and how complete each profile is. We work these out in both directions, so a suggestion has to suit both people. Where you are, relative to them, decides which group they appear in ("Near you", "In your area", "Visiting your area", "Further away"); we never show distances in kilometres or miles. Someone who joined in the last week may be shown a little higher and marked "New here". If you tell us who you are most comfortable meeting, we only suggest people that fits, and only suggest you to people whose choice includes you. We never suggest people who are under 18, people you have blocked or who blocked you, or people you already know or have passed on. We limit how often any one person is shown each day so that suggestions are shared fairly. The reasons shown on a suggestion come only from the factors that actually counted. If you choose to tell us privately that you are open to dating, Section 5.3 explains how that is used. Our Digital Services Act page summarises these main factors.
Suggestion records. To check whether suggestions work, we record which people were shown to you and what happened next (for example a dismissal, an opened profile, a friend request or Super Wave and its reply, a chat, or both of you attending the same Plan). We keep these records for 180 days. They never include a dating preference or a distance. If you delete your account, your identifier in these records, including in other members' records of seeing you, is replaced with a random code that is not linked to your account, and the records are deleted when their 180 days end. Your own records are included in your data export.
You can change the preferences available in Edit profile and Settings at any time, and object to processing based on legitimate interests by contacting privacy@kf.social. We do not use suggestions to make decisions that have legal or similarly significant effects on you.
Lawful basis: providing the introductions and discovery features you ask for (performance of our contract), and our legitimate interests in making suggestions relevant, fair and safe, preventing unwanted contact, and measuring whether suggestions work. We do not treat inferred sensitive interests as permission to process special category data.
Location and maps
We use location to show you people and Plans near you and to show you to people near you. Live location you choose to share in a chat is different and is described in Section 4.
- Where you are based. You choose a city or area, or confirm one we suggest. We store it as an area (a neighbourhood, town or city), never a street address or an exact point. Other members see a description relative to them, such as "Near you" or "In your area" with the name of the area, never your exact location or a distance.
- Approximate device location. If you allow it in your device settings, the app uses your approximate location while you use it. Your phone turns it into an area of a few kilometres before it is sent; we never receive or store your exact coordinates from this feature. We use it to confirm where you are based, to notice when you travel or move, and, if you turn on travel mode, to show you in the city you are in. We check it at most once every 15 minutes. It is only used for members we can confirm are 18 or over. You can turn it off at any time in your device settings and type your city instead.
- Your connection's country and city. We read the country your connection comes from on each request and keep only the two-letter country code, not your IP address. Your home, a change of country, and a trip abroad taking effect must match that country; this stops accounts placing themselves in another country. When device location is off, we may use the approximate city of your connection to ask whether you are in that city; we never move you without your answer. We look up connection locations with a MaxMind database that runs on our own servers; no data is sent to MaxMind.
- Travel. When you travel, we ask whether to show you to people where you are. If you say yes, people in that city see you as "Visiting your area", without dates, and people at home stop seeing you until you are back. With travel mode on, we follow you from city to city after you have stayed about 12 hours. If you say you are always on the move, you have no home base and others see "On the move". You can plan a trip in advance; it takes effect once you use KF.Social from that country during the trip.
- Premium Explore. Premium members can browse people in another city before a trip. If a Premium member has planned a trip, people in that city may see them as "Arriving" with the day, in the three days before the trip, and people they say hello to there may see "Coming to" that city with the date.
- Address and map lookups. Mapbox processes the place names you search for and approximate area points to find places and name areas; we keep the resulting place names and area centre points on your account. Apple Maps or Google Maps may process requests when their maps are displayed.
Lawful basis: providing the location features you ask for (performance of our contract); your consent, given through your device's permission, for reading approximate device location; and our legitimate interests in keeping each account's country accurate and preventing misuse.
Media processing and safety
Our AWS services process uploaded images, video, audio and documents to store and deliver them, create previews and accessible descriptions, recognise objects and visible text, and detect potentially prohibited content. We may retain originals, processed copies, extracted text, labels and moderation results. Private messages are not end-to-end encrypted: our systems process message content and attachments to deliver the Service, and automated safety screening and authorised review may apply.
Lawful basis: providing requested media and messaging features, and our legitimate interests in accessibility, search, abuse prevention and user safety, and our legitimate interests in helping people find relevant content, together with legal obligations where applicable. Automated screening can restrict an upload or trigger review; you can challenge a moderation or account decision through the complaints route. Verification decisions are described in Section 5.
Waitlists, invitations and external bookings
We record your chosen city, event or date, contact or account details, interest and waitlist status, invitations, referrals and notification preferences when you ask to hear about availability. A waitlist request does not reserve a paid seat or subscribe you to unrelated marketing. Where you book through Eventbrite, we receive order and attendee information, including name, email, booking status and checkout answers such as age eligibility and recorded terms/privacy acknowledgements, to fulfil and support the booking. We may create the account and booking records needed to provide the service you bought.
Lawful basis: taking steps at your request and performing the booking or notification service, and consent for separate optional marketing. Eventbrite also processes information under its own privacy notice.
Support
We retain enquiries, complaints, correspondence and relevant account or transaction history to respond and resolve problems. Lawful basis: performance of our contract where the enquiry concerns the service you receive, and our legitimate interests in providing support and resolving complaints.
4. Live Location Sharing in Chat
You can choose to share your live, precise location inside a direct message. This is always started by you: it is off by default, you pick who you share with, and you can stop sharing at any time. We send live location updates while a sharing session is active, to show them to the people you chose in that chat. The retention of session records and location messages is explained below.
Lawful basis: your consent, which you give by starting a location share and can withdraw at any time by stopping it. Stopping a live share stops subsequent updates. The live-session record is scheduled to expire six hours after its scheduled end, with asynchronous database cleanup afterwards. A location you send as a chat message, and the location card associated with a share, can remain in the conversation until removed under the messaging retention rules. This is separate from location used for nearby discovery and is not permission to use precise location for advertising.
5. Special Category Data: Identity Verification, Dietary Information and Dating Preference
Three kinds of data we process are special category data under GDPR Article 9: the biometric data used for optional identity verification; the dietary and allergy information you can provide for Dinners, which can reveal health or religious details; and, if you choose to tell us, whether you are open to dating and who you would like to date, which can reveal your sexual orientation. We process each of them only with your explicit consent (Article 9(2)(a)).
Content you choose to share may also reveal sensitive information such as health, beliefs or sexual orientation. Share it only with an appropriate audience and avoid posting sensitive information about other people without an appropriate basis. Making a post does not provide blanket consent for unrelated sensitive-data processing.
5.1 Identity verification (biometric data)
Identity verification is optional. It only adds a verified badge, and choosing not to verify costs you nothing else. Before verification starts, the app shows a short notice and asks for your explicit consent, and we record the notice version and time. If you opt in, we process:
- Your government identity document and the data read from it, including its machine-readable zone (MRZ), such as your name, date of birth, document number, and expiry date
- A selfie or face-liveness capture, from which biometric features are derived to confirm that the document belongs to you
We use this data only to verify your identity and, if successful, to add a verified badge to your profile. We run checks for uniqueness (to prevent one identity being used for multiple accounts) and name-binding and expiry (to confirm the document is valid and matches your account).
How the check is made. By default the check is automated: the app compares your selfie with the photo on your document. A person on our team checks it instead if the automated check fails and you ask for a person to look at it, or if you cannot take a selfie (choose "Can't take a selfie?" in the app). A person checks your document only: no selfie is used and no face record is made. The automated check keeps a biometric face record when it succeeds, as described under Retention below.
Retention. Raw document and selfie images are scheduled for deletion after a final decision; a case waiting for a person's check may keep them until that check is finished. A verification completed by a person keeps no face template. The raw-image store also has a 30-day expiry rule and a seven-day expiry for superseded object versions. A successful automated verification keeps a biometric face template in AWS Rekognition to re-check your identity and to prevent duplicate or fake accounts, together with verification status, document type/country, a salted duplicate-check hash, scores and decision records. We keep the face template until you withdraw your consent or delete your account. After a final decision, we remove raw extracted document numbers, names and MRZ identity fields from the verification record; a case still awaiting review may need those fields until a decision is made. A template is biometric personal data, not an anonymous badge.
Withdrawing consent. You can withdraw your biometric consent at any time by contacting privacy@kf.social. We then stop biometric processing for your account and delete your face template; your verified badge and features that depend on verification may be removed. Deleting your account also deletes your face template and verification data. Withdrawal does not affect the lawfulness of processing before it. A retained safety or legal record requires its own applicable basis and is never used for continued biometric matching.
Workflow and diagnostic copies. The AWS workflow that runs a verification keeps an execution history, which can contain references to the images and the details read from the document, for up to 90 days after the workflow finishes; diagnostic logs follow the log-retention periods in Section 11. Deleting the source images does not immediately remove these copies. Access to them is restricted, they are not used for any other purpose, and they expire automatically.
Lawful basis: your explicit consent (Article 9(2)(a)) for the biometric processing, and our legitimate interests in preventing fraud and duplicate accounts for the underlying identity check.
5.2 Dietary and allergy information for Dinners
Providing dietary or allergy information for a Dinner is entirely optional. Because it can reveal details about your health or religious beliefs, we treat it as special category data and process it only with your explicit consent.
- The information you provide can be saved in your account dietary preferences and as a separate snapshot on a booking or waitlist entry. It is used to plan relevant dinners. Updating your saved preferences does not necessarily change an existing booking snapshot; contact us to correct or remove older copies.
- Authorised staff can access booking requirements and summaries, including severe-allergy notes, for dinner planning. We do not publish your individual dietary record to other guests. At the venue, everyone orders for themselves: tell the venue about your allergies directly and do not rely on our record as confirmation that a meal is safe.
- You can view, edit, or delete this information, and you can withdraw your consent at any time. Withdrawing consent does not affect processing carried out before withdrawal, but it may mean we are less able to plan around a specific requirement.
Lawful basis: your explicit consent (Article 9(2)(a)).
5.3 If you tell us you are open to dating (optional)
KF.Social is for making friends. Members who are single can privately tell us they are open to dating and who they would like to date (women, men or anyone). Together with your gender, this can reveal your sexual orientation, so we treat it as special category data. Saying nothing, or saying no, changes nothing else about how you use KF.Social.
- What we keep: whether you are open to dating, who you would like to date, the version of the consent you gave and when you gave it.
- How we use it: only to change the order of suggestions slightly, from the next day, between two members who have both said they are open to dating and who each fit the other's answer. It is applied when suggestions are shown to you and is not stored with them. It never filters anyone out and never tells anyone that someone is interested in them.
- Who can see it: nobody. No other member sees it. It is never shown on your profile, never shown as a reason on a suggestion, never used to seat people at Plans, never written into our suggestion records or logs, and never sent to analytics, advertising or AI services. Only the part of our systems that orders suggestions can read it; our staff analytics access cannot. You can see your own answer in the app.
- Adults only: only members we can confirm are 18 or over from their date of birth can turn it on.
- Your choice: we only use it with your explicit consent, which the app asks for separately from our Terms and this Policy, with a box you tick yourself. You can withdraw it at any time in Edit profile by turning "Open to dating" off, and your answer is then deleted straight away. Turning it off always works, including if the option is no longer offered to you. If you cannot reach the setting, for example on the web, email privacy@kf.social and we will delete it. Deleting your account also deletes it. Withdrawal does not affect use before it.
- Retention: until you turn it off or delete your account. A deleted answer can remain in encrypted database backups for up to 35 days before it is overwritten, and is never used from those backups.
- Safety: you can report unwanted romantic or sexual advances. If a report is upheld, the member can no longer use this option.
Lawful basis: your explicit consent (Articles 6(1)(a) and 9(2)(a)).
6. Cookies and Similar Technologies
Cookies, local storage, mobile SDKs and similar technologies can store or access information on your device. Essential technologies support sign-in, security, requested preferences and your privacy choices; they are always on because the Service cannot work without them. Optional analytics and advertising technologies run only if you allow them. Accepting our Terms is not that choice.
On our website, a banner asks whether you allow optional cookies: Accept allows both analytics and advertising measurement, Reject allows neither, and Cookie settings lets you choose each one separately. You can change or withdraw your choice at any time using , which is also linked at the bottom of every page. Rejecting optional cookies does not stop you booking or using the Service. In our apps, product analytics is a separate choice that you can change in Privacy settings. Device permissions and app-store tracking permissions are separate from website cookie choices. You can also contact our privacy team to object to analytics or for help withdrawing consent.
| Technology | Purpose and data | Duration or control |
|---|---|---|
| Session, authentication and privacy-choice storage | Sign-in/session credentials, security checks, requested preferences and consent records. Includes COOKIE_CONSENT, KF_ANALYTICS_CONSENT_V1 and KF_GOOGLE_ADS_CONSENT_V1 on the website. | Session credentials expire or are revoked; website choice cookies last up to one year unless replaced or cleared. |
| PostHog cookies/local storage and mobile SDK storage | Visitor, account, installation and session identifiers; feature usage, performance and campaign information. Website analytics, and analytics in the current versions of our apps, start only after you allow product analytics. | Persistent identifiers remain until expiry, reset or clearing. Withdrawing analytics consent on the website clears PostHog's website storage. |
| Awin affiliate storage, MasterTag and visit records | Affiliate click references (awc/kf_awc) and transaction attribution, only after you allow advertising measurement. If you arrive from an affiliate link before choosing, the click reference is held in your browser tab's session storage and is recorded only if you then allow advertising measurement; if you reject it, it is discarded. When recorded, we also briefly keep a record of the visit, including your IP address, so our apps can credit the affiliate if you sign up in the app shortly afterwards. If you then install our Android app from our download page, the click reference is also passed to Google Play in the install referrer for the same purpose. Our download page asks for your choice before sending you to an app store when you arrive from an affiliate link. | Affiliate cookies last up to 30 days (older cookies can remain until their original expiry or until cleared). Rejecting or withdrawing advertising measurement clears our affiliate cookies. Visit records expire after one hour. Affiliate transaction records are kept for commission reconciliation and our financial records. |
| Meta, Reddit, TikTok and Google Ads tags, where enabled | Page/referrer URLs, IP and browser/device information, advertising/click identifiers, interactions, signup and booking events, transaction references, value and currency, only after you allow advertising measurement. Providers may associate these with information they already hold. | Provider-controlled cookie and event retention varies by network and settings. Removing our cookies does not delete records already received by a provider; use the provider controls or contact us about your rights. |
| Campaign and conversion-deduplication storage | Campaign source labels and records that prevent counting the same booking more than once. | Website campaign cookies last 30 days; local conversion records remain until cleared or reset. |
7. Analytics and Marketing Measurement
Product analytics. With your consent, PostHog receives selected page and screen views, interactions, feature and experiment assignments, device/app information and account or installation identifiers. On our website and in the current versions of our apps, PostHog starts only after you allow product analytics. Separately, our servers record events such as bookings, purchases, refunds and subscription outcomes, for which we rely on legitimate interests. We use PostHog's EU-hosted service. We minimise direct identifiers and filter sensitive fields, but pseudonymous IDs, event histories and linked purchases remain personal data.
How you use the app. To order your feed and time notifications, we record which posts were shown to you, roughly how long you looked at them, whether you watched videos, opened links or notifications, or hid posts. This is first-party information used only for KF.Social features and kept for up to 13 months. You can turn off personalisation in Settings, which gives you a time-ordered feed and fixed notification times. The records we keep about the people suggested to you are described in Section 3 (Discovery, recommendations and matching).
Session replay and heatmaps. These are switched off on our website and in our apps. We previously used session replay to diagnose usability problems; recordings made before it was switched off are kept for no more than 30 days and then deleted.
Diagnostics. Sentry receives crash/error reports, technical context, performance information and selected activity breadcrumbs. An account identifier can link diagnostics to product analytics so we can investigate a problem. We filter credentials and sensitive values, but diagnostic data is not anonymous.
Advertising and affiliate measurement. With your consent to advertising measurement, we use Meta, Reddit, TikTok and Google Ads where configured to measure our own campaigns, and Awin to credit the affiliate partners who introduce new members. We record an Awin click reference, and pass it to an app store as an install referrer, only after you allow advertising measurement on our website. If you sign up and book after arriving through an affiliate link with that choice made, we report the booking reference, sale amount, currency and whether you are a new customer to Awin, including by a server-to-server request, so the partner can be paid commission. Advertising providers may act as separate controllers for their own processing under their notices.
Google Ads conversion measurement. With your consent to advertising measurement, the tag runs on public booking pages and may send the current page URL, referring page, and advertising click information; page URLs can include query parameters. After payment it may also send the booking reference, amount and currency. Our configured booking event does not send names, emails, phone numbers or hashed contact details; enhanced conversions and remarketing are not enabled for this tag.
Lawful bases and choices. We rely on your consent for optional product analytics and advertising measurement on our website and in our apps, and on legitimate interests for crash diagnostics and server-side measurement of the Service. Marketing email consent is separate. You may withdraw consent or object to legitimate-interest processing as described in Section 12. We do not sell your personal data; we share the data described above with analytics and advertising providers only for the purposes described.
8. Communications
We send transactional emails and push notifications that are necessary to provide the Service, such as sign-in codes, activity you have asked to be notified about, and safety messages. You can control push notifications in your device settings.
We may notify you when friends or Clubs you belong to share something, by push notification or a catch-up email, and we choose the time we think you are most likely to want it based on when you usually use KF.Social. You can switch each kind off in Settings, choose a daily or weekly catch-up email, and unsubscribe with one click from any email.
We may tell your friends when you add a new profile photo or update your bio, and show "New photo" or "New bio" on your profile for a week, unless you turn off "Let my friends know" in Settings › Privacy or Edit profile. You can also choose not to hear about your friends' updates. We never tell anyone about your location, your travel, what you are looking for or a dating preference. If you have not set where you are based, we may send up to two reminders. If you travel or are always on the move, we may send a short morning notice inviting you to see who is around, at most once every three days; it never names anyone.
With your consent, we also send optional marketing from our kf.social domain about KF.Social. You can withdraw that consent at any time using the unsubscribe link in any marketing email or in Settings. We do not sell or share your contact details for third-party marketing.
9. Who We Share Data With
We share personal data with the recipients below for the service, safety, analytics and advertising purposes described in this policy. We do not sell your personal data.
| Recipient | Purpose |
|---|---|
| Amazon Web Services (AWS) | Hosting, databases, caches, queues, media storage and delivery, logs, email delivery (SES), voice/video calling (Chime), image/video safety and recognition (Rekognition), document reading (Textract), and biometric verification. Core production storage is in Frankfurt. Document reading can send identity-document images to AWS in the United States; global delivery, calling and provider support can involve other locations. |
| Stripe | Booking payments and web billing, subscriptions, receipts, refunds and fraud prevention. Receives payment, contact/billing and transaction information needed for the selected checkout; returns payment/customer/subscription references and status. |
| PostHog (EU) | EU-hosted product and server-event analytics and feature flags; pseudonymous identifiers and usage/device data as described in Section 7. Session replay and heatmaps are switched off. |
| Apple and Google | Sign-in (Sign in with Apple, Google Sign-In), push notification delivery, and app subscriptions and in-app purchases (Premium and Super Waves). |
| Sentry | Crash, error and performance monitoring; technical context, filtered breadcrumbs and account identifiers. Filters reduce personal data but do not remove every identifier. |
| Meta, TikTok, and Reddit | Advertising pixels on our website, where enabled, for campaign and conversion measurement, only after you allow advertising measurement. Receives device, page and interaction/conversion information as described in Section 7. |
| Google Ads | Consent-gated conversion measurement on public booking pages. The tag may send the booking page URL, referring page, and advertising click information; after successful payment it may also send a booking reference, amount, and currency. We do not send direct contact details or use the tag for remarketing or enhanced conversions. |
| Awin | Affiliate attribution and commission reconciliation, including click and booking references, amount, currency and customer/transaction status. Click references are recorded only after you allow advertising measurement. |
| Mapbox | Place search and location lookup (geocoding) for choosing where you are based, trips, Explore and Plans. Receives the place names you type, approximate area points and technical request data; we keep the place names and area centre points it returns. |
| Apple Maps and Google Maps | Map display in the apps. Map requests and technical request data depend on the platform. |
| MaxMind | Provides an IP-to-location database that we run on our own servers. We do not send your data to MaxMind. |
| Eventbrite | External ticketing and order fulfilment. We receive attendee/contact details, checkout answers, consent records and booking/payment status for bookings made there. |
| People you interact with; authorised staff and advisers | Your chosen audiences receive shared content and relevant profile/event information. Staff and contracted support, legal or accounting advisers receive information needed for their role, subject to access and confidentiality controls. |
We may also disclose personal data where required by law, to enforce our terms, or to protect the rights, safety, and security of our users, the public, or KaneFilous Limited.
10. International Data Transfers
Your personal data is primarily stored and processed in the European Union. Some providers, such as Stripe (payments), Apple and Google (sign-in, push, and in-app purchases), Mapbox (place search), and the marketing-pixel partners described above, may process data outside the European Economic Area (for example, in the United States). Where personal data is transferred outside the EEA, we rely on appropriate safeguards, including the EU Standard Contractual Clauses (SCCs) and, where applicable, an adequacy decision or a recipient's applicable certification under the EU-US Data Privacy Framework. For transfers subject to UK rules, an applicable UK adequacy arrangement or UK-approved contractual safeguard is required. EU hosting alone does not rule out access from other countries. You can request information about the safeguard for a particular recipient, or a copy subject to necessary redactions, at privacy@kf.social.
11. Data Retention and Account Deletion
We keep your personal data only for as long as necessary for the purposes set out in this policy, or as required by law. In general:
- Account, content, recommendations and preferences: retained while needed to provide the feature or while your account/content remains active. Deletion requests must also account for originals, resized media, extracted text and derived records; another person's copy of shared content is separate.
- Verification: raw images, templates and decision records have different purposes and retention, described in Section 5. Deleting a source image does not itself erase a face template; the template is deleted when you withdraw biometric consent or delete your account.
- Dietary information: saved preferences and booking snapshots are separate records. You can request removal of both; financial record retention does not by itself justify keeping allergy details.
- Live location: live-session records have a six-hour expiry grace after the scheduled end; chat location messages follow conversation retention (Section 4).
- Where you are based and travel: where you are based is kept while your account is active; a trip ends at most 30 days after it starts; an automatic move can be undone for 24 hours, after which the previous place is no longer kept. The country of your connection is checked on each request and not stored beyond your account's current country.
- Dating preference: until you turn it off or delete your account, then deleted at once; encrypted database backups can hold it for up to 35 days (Section 5.3).
- Suggestion records: 180 days. On account deletion your identifier in them is replaced with a random code that is not linked to your account (Section 3).
- Sending limits: the count of friend requests sent is kept for a rolling 24 hours.
- Operational storage: raw media uploads generally have a one-day lifecycle, original uploaded videos seven days, and generated account exports 14 days. These periods are expiry targets; asynchronous cleanup may take additional time.
- Logs and notifications: service, access and diagnostic logs expire automatically after a fixed period of no more than 90 days; most application logs are kept for 30 days. Notification/activity records generally have a 90-day expiry.
- Safety and compliance records: selected enforcement, report, moderation and deletion/audit records use a seven-year retention period to evidence actions and handle disputes or legal claims. We remove or pseudonymise fields where appropriate; pseudonymised records are still personal data. Certain ban-prevention identifiers are kept for the remaining restriction period or five years for a permanent ban.
- Restricted moderation evidence: the evidence store has a 90-day retention protection and a 100-day lifecycle target, with separate expiry of older object versions. A valid legal hold or preservation requirement can extend retention. This is separate from the longer-lived record of the moderation decision.
- Payment, subscription and business records: retained for the applicable accounting/tax period and as needed to resolve refunds, disputes or legal claims. Account closure does not erase records a payment or ticketing provider must retain under its own obligations.
- Analytics, replay and attribution: session recordings made before replay was switched off are deleted after 30 days. Other analytics and attribution retention depends on the record's purpose and the provider's configured period. Cookie expiry does not erase server-side events or affiliate transaction history. You can ask us for the applicable period and request erasure or object to continued processing.
Account deletion. Request deletion in Settings or contact privacy@kf.social. There is a seven-day period in which you can cancel the request before deletion starts. We then delete, redact or pseudonymise your records as appropriate, including your identity-verification data and any face template, normally within 30 days, subject to lawful exceptions. Open transactions or disputes may require resolution, but they do not remove your right to make an erasure request or receive an explanation.
Backups and copies. Core database point-in-time recovery currently covers up to 35 days. Superseded media versions commonly expire after 30 days, with shorter rules for verification and view-once media. These are separate from active-record deletion and from any necessary legal hold. Retained material is not available for ordinary continued use after deletion; a restoration must reapply deletion instructions. People who received content may have saved their own copies.
12. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of access: request a copy of the personal data we hold about you
- Right to rectification: request correction of inaccurate or incomplete data
- Right to erasure: request deletion of your personal data
- Right to data portability: request your data in a structured, commonly used, machine-readable format
- Right to restriction: request that we limit how we process your data
- Right to object: object to processing based on our legitimate interests
- Right to withdraw consent: where processing is based on consent (including identity verification, dietary information, a dating preference, approximate device location, live location, marketing, app analytics and cookies), withdraw it at any time without affecting prior processing
You can exercise many of these rights directly in Settings, including editing your profile and deleting your account. For anything else, contact us at privacy@kf.social. We normally respond within one month; where the law permits an extension for a complex or numerous request, we explain it within that first month. We may ask for proportionate identity verification. Rights can be subject to lawful exceptions and protection of other people's rights. You have the right to have an automated decision checked by a person, to express your view and to challenge it, where the applicable legal protections apply. For example, if the automated identity check fails, you can ask for a person on our team to check it. Objection to direct marketing can be made at any time.
Complaints
You can complain to the Irish Data Protection Commission (DPC), at www.dataprotection.ie, if you are unhappy with how we handle your data. If you are elsewhere in the EU, you may also complain to your local data protection authority. UK users can complain to the Information Commissioner's Office (ICO). You do not have to complain to us first. We would welcome the chance to address your concerns first, so please consider contacting us before you do.
13. Profiles, Search and Content Visibility
KF.Social includes social features such as profiles, posts, and communities. Some profile information, such as your display name and photo, is visible to other people so they can recognise you.
In suggestions and on your profile, other members can also see a description of where you are relative to them (never a street or a distance), whether you joined in the last week ("New here"), whether you recently changed your photo or bio, and, while you travel with your permission, "Visiting your area" or "On the move". If you are a Premium member with a planned trip, people in that city may see "Arriving" as described in Section 3. Your date of birth, the age range and people you prefer to meet, your free evenings and any dating preference are never shown.
To help people find each other, profiles are indexed for profile discovery and search within the Service. You control the visibility of your posts using the visibility level you set for each one:
- Public: visible to other people on the Service, and may appear on a public web page on kf.social that search engines such as Google can index. You can stop your public posts appearing in search engines in Settings › Privacy › "Show my public posts in search engines". Friends-only and private posts never appear on public pages.
- Friends: visible only to people you are connected with
- Private: visible only to you
When you delete a post, change it to Friends or Private, or delete your account, its public page is removed within minutes; search engines may take longer to update their results.
Reports, blocks, identity-verification data and individual dietary records are not public profile information. Authorised safety/support staff and relevant service providers may process them, and disclosure may be required by law. We protect reporter and third-party privacy when responding to access requests and appeals.
14. Security
We use appropriate technical and organisational measures to protect your personal data, including encryption in transit, secure storage of credentials on your device (the iOS Keychain and Android Keystore), restricted internal access, error monitoring with filters intended to minimise sensitive fields, and payment handling by Stripe so that card details never touch our systems. No system can be guaranteed completely secure, but we work to protect your data and to respond promptly to any incident.
15. Children
You must be at least 18 to use KF.Social. The Service is not directed at anyone under 18, and we do not knowingly collect personal data from them. Accounts whose date of birth shows the holder is under 18 are never shown to other members in suggestions or search, and cannot use location prompts or the dating preference. If you believe someone under 18 has an account, contact us at privacy@kf.social and we will take steps to remove it and delete their data.
16. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will let you know by email or through the Service, and the app and website will ask you to review and accept the updated policy the next time you sign in or open KF.Social. The effective date shown at the top of this page tells you when the current version took effect.
17. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, you can reach us through the following channels:
- Privacy enquiries: privacy@kf.social
- Data controller: KaneFilous Limited, 60 Merrion Square South, Dublin 2, D02 HE24, Ireland
- Supervisory authority: Irish Data Protection Commission, www.dataprotection.ie
Version 3.4. Effective 11 October 2026. KF.Social is operated by KaneFilous Limited, a company registered in Ireland.