KindrdJoin Kindrd
← All posts

Privacy isn't a setting. For us it's the architecture.

18 July 2026 · 6 min read

Most privacy features are written for a regulator. They're a page of toggles, a cookie banner, a policy in a font nobody reads. They answer the question "are we compliant?"

That's the wrong question for a queer dating app. The right one is: who specifically could hurt this person with this data, and what have we made impossible?

Because on an app like this the adversary isn't abstract. It's a colleague. A landlord. A family member who suspects. Someone in a small town where there are four other queer people and everyone knows the same four. "Anonymised" doesn't mean anything against an adversary who only needs to narrow it down to one.

What that changes in practice

  • Distance is city-level, never precise. A lot of apps show how many hundred metres away someone is. Two or three readings of that number is enough to find a flat. We show the city centre distance and nothing finer. It is a worse feature and a better answer.
  • You can hide any part of your identity and still be matched on it. Being trans, or ace, or bi shouldn't be a choice between "invisible" and "exposed to everyone." The matching uses what you tell us; the profile shows only what you choose. Those are two different questions and most products conflate them.
  • Notifications never show a name or a message on a lock screen. The most common way an app outs someone isn't a data breach. It's a phone face-up on a kitchen table.
  • A discreet mode that actually means discreet. You can browse and reach out first without appearing in anyone else's daily set. Not a paid tier. A safety feature.
  • Text-only chat. No image sending. It removes an entire category of harassment before it can happen, and it costs us a feature people ask for.
  • The thing about safety features

    Nearly all of them are worse products in the narrow sense. Precise distance is more useful than city distance. Photos in chat are nicer than no photos. Rich notifications are more engaging than vague ones.

    Every one of those trade-offs is a small tax on the experience of people who are already safe, paid so that someone who isn't safe can use the app at all. We think that's the correct way round. A product that works beautifully for people with nothing to lose and dangerously for everyone else isn't finished.

    What we can't promise

    We can't make the internet safe, and we won't pretend to. Anyone can screenshot. Anyone can lie about who they are. What we can do is refuse to be the thing that hands over the detail that turns a suspicion into a certainty — and be specific with you about where that line is, rather than hiding behind the word "encrypted."

    Privacy as a setting is something you have to find. Privacy as architecture is something you don't have to think about, because the dangerous version was never built.

    Dating built on alignment, not volume

    The whole LGBTQ+ spectrum, a few genuinely compatible people a day, and matching and messaging free forever.

    Join Kindrd — freeRead the guides

    Keep reading

    Why we built a dating app that wants you to leave

    The business model problem nobody in dating wants to say out loud.

    On being seen

    The difference between being allowed in and being built for.