PRIVACY POLICY
This policy explains what personal data we process when you use the OnlyMens app and onlymens.net, why we process it, and how you can exercise your rights.
Last updated: [effective date]
1. Controller
The controller is [company name] ([trade registry no]), [address]. For data protection requests: [DPO / privacy contact] — [DPO email]. General support: [support email].
2. Data we process
To provide the service we process the following categories:
- Account data: phone number, email address, the identifier returned by Apple or Google if you sign in with them, date of birth, gender.
- Profile data: name, photos, bio, occupation, interests and other fields you fill in.
- Verification data: selfie and pose challenge images and the verification result derived from them. This is biometric (special category) data and is processed only with your explicit consent.
- Location data: approximate location for the distance filter, at the precision you allow.
- Communications: in-app messages, reports and support correspondence.
- Usage and device data: session records, IP address, device model, operating system, app version, crash and error logs, push notification tokens.
- Payment data: subscription status and transaction identifiers from the App Store or Google Play. We never see or store card details.
3. Purposes
- Creating your account, signing you in and delivering the service.
- Showing, filtering and ranking profiles in discovery.
- Preventing fake and impersonating accounts through selfie verification.
- Reviewing reports, preventing abuse and fraud, keeping the platform safe.
- Running subscriptions and keeping billing records.
- Sending notifications and answering support requests.
- Measuring, debugging and improving the service.
- Meeting legal obligations and responding to legal claims.
4. Legal bases
We rely on the following bases under GDPR Art. 6 (and the equivalent provisions of Turkish KVKK Art. 5): performance of a contract (running your account and the service), legal obligation (statutory retention and reporting duties), legitimate interests (security, abuse prevention, product improvement) and consent (biometric verification data, precise location and marketing messages).
You can withdraw consent at any time; withdrawal does not affect processing carried out before it. If you withdraw verification consent your verified badge and the features that depend on it are removed.
5. Visibility and sharing rule
The core product rule is part of your privacy: women's profiles are never shown to men in discovery, search or suggestions. A man sees only the woman who wrote to him, and only inside that conversation. Profile views are shown to men as a count only, never as an identity or a photo.
6. Service providers
We work with a small set of processors: cloud hosting and database, object storage (photos), SMS and email delivery, push notifications, face verification, error and performance monitoring, and payment validation (Apple and Google). Each provider receives only the data it needs and is bound by contract. You can request the current list at [support email].
7. International transfers
Some providers are located outside your country. Such transfers rely on appropriate safeguards, such as the European Commission's standard contractual clauses and the conditions of KVKK Art. 9. Contact [DPO email] for details or a copy of the safeguards.
8. Retention
- Account and profile data: while your account is open; deleted or anonymised within [deletion window] after a deletion request.
- Verification images: deleted within [verification retention] after the result is produced; the result itself (pass/fail) is kept with the account.
- Messages: while your account is open; removed on your side when you delete them.
- Report, moderation and safety records: [safety retention], to prevent repeat abuse.
- Payment and invoicing records: the period required by law ([financial retention]).
- Technical logs: [log retention].
9. Your rights
You have the right to access, rectify and erase your data, to restrict or object to processing, to data portability, and not to be subject to solely automated decisions with legal effects. Send your request to [DPO email]; after verifying your identity we will respond within [response time]. You may also lodge a complaint with your supervisory authority (in Türkiye, the Personal Data Protection Authority).
10. Security
We encrypt data in transit and at rest, restrict access with role-based permissions, and write every admin action to an audit log. No system is perfectly secure; in the event of a breach we will notify you and the competent authority within the period required by law.
11. Cookies and similar technologies
On onlymens.net we use only the strictly necessary cookies and local storage required for the site to work. We do not use advertising or third-party tracking cookies. If that changes we will update this section and ask for consent where required.
12. Children
OnlyMens is for adults aged 18 and over. Accounts found to belong to minors are closed and the data deleted. If you believe such an account exists, report it to [support email].
13. Changes
We may update this policy. For material changes we will notify you in the app or by email. The effective date is shown at the top of this page.