Dimples Privacy Policy

Last updated: 23 September 2026 Effective: on first public release of Dimples 1.0


Who we are

Dimples is a dating app operated by AGENTIQFLOW LLC ("Dimples", "we", "us"). AGENTIQFLOW LLC is the data controller for the personal information described in this policy.

Contact for privacy questions, data requests, and complaints: support@agentiqflow.ai

Dimples is for people aged 18 and over only. We do not knowingly collect information from anyone under 18. See "Children" below.


The short version


1. Information you give us

Account and sign-in

Depending on how you sign in, we receive and store:

Sign-in method What we receive
Phone number Your phone number in international format. A one-time 6-digit code is sent to it by SMS.
Sign in with Apple The identifier Apple issues for you, and the name and email address you choose to share (Apple lets you hide your real address behind a relay address; if you do, we only ever see the relay).
Google Your Google account identifier and the email address on that account.

We never receive or store your Apple or Google password. We do not store SMS codes after they are used.

Your profile

You choose what to put here. We store:

Some of these — religion, political outlook and ethnicity in particular, together with your smoking, drinking and cannabis answers, and the fact that you are using a dating app at all — are treated as special category / sensitive personal data under GDPR and comparable laws. You provide them voluntarily and we process them on the basis of your explicit consent, given when you choose to fill them in. You can remove any of them at any time by editing your profile, and you can withdraw consent entirely by deleting your account.

Voice intro (optional)

You may record one short voice intro, up to about 20 seconds, which is stored as an audio file and played by people who view your profile. It is entirely optional; you can delete it at any time from Edit Profile, and deleting your account deletes it with everything else.

We do not listen to it, and we do not screen what you say. Voice intros are checked automatically only for file size and format — there is no transcription and no automated review of the content. This is different from photos, which are screened for unsafe content before anyone sees them. Voice intros are moderated reactively: if someone reports a recording and we agree it breaks our rules, we remove it everywhere at once and may ban the account. If you would rather not publish audio, simply do not record one.

Your preferences

Minimum and maximum age, maximum distance, which genders you want to see, and any optional attribute filters you set.

Verification selfie (optional)

If you choose to verify your profile, we ask for a selfie. It is compared automatically against your existing profile photos to check that they are the same person (see "Automated photo checks" below).

Your verification selfie is never shown to other users. It is stored in a private area of your own folder and no other account can access it.

What you send to other people


2. Information we collect automatically

Precise location

With your permission, we collect your device's precise location (latitude and longitude) and store it as a single point on your profile, along with the time it was last updated.

Push notification token

If you allow notifications, we store a push token issued by Expo's push service for your device, so we can tell you about new matches and messages. It is kept in a separate, private table that no other user can read. Turn notifications off in your device settings and we stop sending them.

Usage records needed to run the service

What we do not collect

We want to be specific, because most dating apps cannot say this:


3. Automated photo checks

This matters, so it gets its own section.

Every profile photo you upload is scanned automatically before it can be shown to anyone. The image is sent to Amazon Rekognition, a service operated by Amazon Web Services, which returns labels indicating adult, suggestive, violent or otherwise unsafe content.

Automated screening rejects explicit nudity, violent or visually disturbing imagery, and hate symbols; images it cannot categorise confidently are held as pending for a person to look at, and ordinary swimwear or a drink in the picture are not on their own grounds for rejection.

If you submit a verification selfie, the selfie and up to three of your approved profile photos are sent to Amazon Rekognition's face comparison service to measure whether they show the same person. We store the resulting decision (approved or rejected) and a similarity score. We do not build or keep a face template or biometric identifier for identification purposes, we do not use it to recognise you anywhere else, and we do not share it with anyone.

Human review. Automated screening is not the only check. Reports filed by users, and accounts flagged by them, are reviewed by a person on our team through an internal moderation console. A reviewer can see reported profiles, their photos, their voice intro, their account status, and the email address or phone number the account signed up with, in order to act on a report, and can ban an account. Every moderation action a reviewer takes is written to an internal audit log.

Your rights around automated decisions. Photo approval and verification decisions are made automatically. If a photo or a verification is rejected and you believe that is wrong, email support@agentiqflow.ai and a person will look at it. You have the right to that human review, to express your point of view, and to contest the decision.


4. How your information is used

We use your information to:

Legal bases (GDPR). Where GDPR applies, we rely on:

Purpose Legal basis
Running the app and providing matches, chat and profile features Performance of a contract (our Terms)
Optional sensitive profile fields (religion, political outlook, ethnicity, and the smoking/drinking/cannabis answers), and dating-app use generally Your explicit consent
Location processing Your consent (device permission), and performance of the contract
Photo moderation, verification, safety, anti-abuse, banning Legitimate interests in keeping users safe, and our legal obligations for user-generated content
Push notifications Your consent (device permission)
Billing and subscription management Performance of a contract

5. Who your information is shared with

Other users

Other users of Dimples can see: your display name, your age, your approximate distance from them, your photos that passed moderation, your bio and prompt answers, any optional attributes you filled in, and whether you carry a verification badge. People you match with can additionally see your messages.

If you use Double date, your pair partner can see that you are paired, and your pair is shown to other pairs in the double-date deck with the same profile information listed above. When your pair matches another pair, all four people can see each other's messages in that group chat.

They cannot see: your phone number, your email address, your exact date of birth, your coordinates, your push token, your verification selfie, your subscription status, or anything you have reported.

Service providers

We use a small number of companies to run the service. They process data on our instructions and are not permitted to use it for their own purposes.

Provider What they handle Where
Supabase Hosting, database, authentication, photo storage, realtime chat United States
Amazon Web Services (Rekognition) Automated photo screening and verification face comparison United States
Expo (Expo Application Services) Delivery of push notifications United States
Resend Sending the optional email digest about activity you missed United States
Twilio Sending your SMS sign-in code United States
Apple, Google Sign-in, app distribution, and in-app purchase processing United States

Apple and Google process your payment. We never see or store your card details. Which subscription or pack you bought, and when a subscription expires, is recorded on our own purchase server after Apple or Google confirms the purchase.

Legal and safety

We may disclose information where we are legally required to, or where we reasonably believe it is necessary to investigate fraud or abuse, to enforce our Terms, or to protect someone from serious harm.

Business transfers

If AGENTIQFLOW LLC is acquired or merged, your information may transfer as part of that transaction. You would be told before it happened, and any new owner would be bound by this policy or you would be given the chance to delete your account first.

What we never do

We do not sell your personal information, and we never have. We do not share it for cross-context behavioural advertising. We do not sell or share location data with anyone. Under the CCPA/CPRA definitions of "sell" and "share", we do neither.


6. International transfers

We are based in the United States and our providers are based in the United States. If you use Dimples from outside the US, your information will be transferred to and stored in the US. Where required for transfers out of the UK, EEA or Switzerland, we rely on the European Commission's Standard Contractual Clauses with our providers.


7. How long we keep things

Data Retention
Profile, photos, preferences, matches, messages Until you delete your account
Swipe history Until you delete your account (it is what stops the same person reappearing)
Verification selfies and their decisions Until you delete your account
Push token Until you delete your account or turn notifications off
Reports you filed, and reports about you Deleted with your account, except that a record of a moderation decision (for example a ban) is kept without your profile data, so that a banned user cannot simply come back
Internal rate-limit counters A per-day count of automated requests made for your account. It holds no content — just your account identifier, a date and a number — and is operational accounting rather than a record of what you did
Backups Deleted data may persist in encrypted backups for a short period before those backups roll over

8. Your rights and how to use them

Deleting your account — you can do this yourself, right now

Settings → Delete account. It asks you to confirm, and then permanently deletes your profile, photos, voice intro, matches, messages, swipes, preferences, blocks, reports, subscription record, boosts and verification submissions.

You do not have to email us, justify it, or wait.

If you cannot sign in, the same instructions — and the email route for getting an account deleted when you have lost access to it — are published on a public web page you can reach without an account: https://agentiqflow.ai/dimples/delete-account. You can also email support@agentiqflow.ai from the address on your account and ask us to delete it; we verify the request really comes from you and complete it within 30 days.

Other rights

Depending on where you live, you have some or all of the following rights. GDPR gives them to people in the UK, EEA and Switzerland; the CCPA/CPRA and similar US state laws give comparable rights to residents of California and other states.

To exercise any of these: email support@agentiqflow.ai from the email address on your account, or tell us the phone number you signed up with. We will respond within 30 days (45 days for CCPA requests, extendable once where the law allows). We may need to verify that the request really comes from you before we act on it — for an account we can only identify by phone number, that means sending a code to it.

You may use an authorised agent to make a CCPA request on your behalf; we will ask for proof of authorisation.

Complaints

If you are in the UK or EEA and think we have handled your data badly, you can complain to your national data protection authority. We would rather you told us first: support@agentiqflow.ai.


9. Security

No system is perfectly secure. If we discover a breach affecting your personal data, we will notify you and the relevant regulators as required by law.


10. Children

Dimples is strictly 18+. You must confirm your date of birth to create a profile, and the requirement is enforced by our servers, not just by the app — an account with a date of birth under 18 years ago cannot be created at all.

We do not knowingly collect information from anyone under 18. If you believe a minor is using Dimples, report the profile in the app or email support@agentiqflow.ai and we will remove the account and its data.


11. Changes to this policy

If we change this policy materially, we will update the date at the top and tell you in the app before the change takes effect. Continuing to use Dimples after that means you accept the updated policy.


12. Contact

AGENTIQFLOW LLC (a Michigan limited liability company) Email: support@agentiqflow.ai Postal address: available on request by email.