This is the privacy policy in force for Kindrd today, and it describes how the product actually works. We keep it under review as the product changes, and we will post any material update here.

Privacy Policy

Last updated: 10 August 2026

Kindrd is a relationship-first dating service for LGBTQ+ people. This policy explains what personal data we collect, why, how we protect it, and the rights you have over it. We take particular care with data about your gender identity and sexual orientation, which the law treats as special-category (sensitive) data.

Who we are

Kindrd ("we", "us") is an independent service operated from the United Kingdom by Bradley Johnston, trading as Kindrd, who is the data controller for the personal data described here. A postal address for formal correspondence is available on request. For any privacy question, to exercise your rights, or to raise a concern, contact us at hello@kindrdlove.app. We are not required to appoint a Data Protection Officer; privacy questions are handled directly by the operator of the service.

The data we collect

  • Account data: your email address, a securely hashed password (we never store your password in readable form), and your date of birth, which we use only to confirm you are 18 or older.
  • Special-category identity data: your gender identity, who you are seeking, your sexual orientation, and pronouns. We process this only with your explicit consent, given at sign-up, and only to match you and to show the parts of your profile you choose to make visible.
  • Profile content: your display name, bio, city (optional), interests, prompt answers, and photos you upload.
  • Activity data: likes and passes, matches, messages you send, profiles you view, and blocks or reports you make, so the service can function and stay safe.
  • Technical data: a single first-party session cookie to keep you signed in, and your IP address transiently for security and abuse-prevention (rate limiting). We do not use advertising or third-party tracking cookies.

Why we use it, and our legal bases

  • To provide the service (accounts, discovery, matching, messaging): performance of our contract with you.
  • To process your identity data for matching: your explicit consent, which you can withdraw at any time.
  • To keep people safe (moderation, blocking, reporting, anti-abuse): our legitimate interest in a safe community, and compliance with legal obligations.
  • To safeguard people from harm (investigating serious reports, preserving evidence, referring trafficking and child-protection cases): compliance with a legal obligation and the substantial public interest in safeguarding, which is also the condition that lets us process special-category data for this purpose without your consent.
  • To contact you about your account (verification, password reset, essential notices): performance of our contract.

How your data is protected

Data is encrypted in transit (HTTPS everywhere). Passwords are hashed with a strong, salted algorithm. Photos are kept in a private store and served only through short-lived signed links, never publicly listed. Access to production data is limited and server-side only; your identity data is never exposed to other users beyond the display fields and visibility you choose. We enforce a strict content-security policy and standard security headers.

Who we share it with

We do not sell your data and we do not share it for advertising. We use a small number of service providers (processors) strictly to run the service: an application hosting provider (Vercel), a cloud database and file storage host, an email delivery provider (for verification and password-reset emails), and a rate-limiting service. Each processes data only on our instructions. Some providers may process data outside your country; where they do, appropriate safeguards apply.

Our hosting provider also supplies the page-view and performance measurement we use to see which pages are slow and which are used: it counts page views and load timings in aggregate. It sets no cookie, builds no cross-site profile of you, and is not used for advertising.

How long we keep it, and what deletion does not erase

We keep your account data for as long as your account is active. When you delete your account from Settings, we permanently remove your personal data — your profile, your identity data, your messages and your photos, including the underlying image files in storage — and we cancel and delete your billing record with our payment processor. This is a real deletion, not a hidden archive, and it is immediate.

There is one deliberate exception, and it exists to protect other people. Deleting your account does not delete a safety record about you. Where information is needed as evidence, we retain a limited record beyond account deletion in each of these cases:

  • Serious safety reports. A report made about you survives your deletion. The report keeps the reason, any detail the reporter gave, the reported content, and the date; the link to your account is severed so the record is no longer attached to an identified living profile, but the case remains reviewable by a moderator. A report you made about someone else also survives your deletion, so that closing your account cannot be used to erase a case against another person.
  • Active investigations. Where an account is under moderation review, or is the subject of an active law-enforcement or child-protection matter, we preserve the relevant account data, content and access logs until that matter is resolved — including where deletion is requested after the matter has begun.
  • Preservation requests. Where a law-enforcement agency has asked us in writing to preserve an account, we preserve it for 90 days, renewable on request, whether or not the user asks us to delete it in the meantime.
  • Child sexual abuse material and trafficking. Where we identify CSAM or conduct indicating trafficking or the sexual exploitation of a child, we preserve the material and the associated account data as required by law and report it to the appropriate authorities. This retention cannot be overridden by a deletion or erasure request.
  • Bans and re-registration. When we permanently ban an account, we keep a minimal record sufficient to recognise and refuse that person if they return. Without it, a banned user could erase their ban simply by deleting their account.
  • Legal, tax and accounting obligations. Payment and transaction records are kept for the period UK law requires, independently of your account.

These records are kept to the minimum needed for the purpose, are held separately from the live product and are not used for matching, marketing, or profiling. Once the purpose ends — the case is closed, the preservation period lapses, the limitation period expires — the record is deleted on the same schedule as everything else. Short-lived security tokens and stale non-essential signals are cleared automatically.

In data-protection terms, this is the limit the law itself places on the right to erasure: UK GDPR Article 17(3) permits us to keep personal data where it is necessary for compliance with a legal obligation, for reasons of substantial public interest, or for the establishment, exercise or defence of legal claims. Safeguarding people from sexual exploitation and trafficking is exactly that.

Law enforcement and legal requests

We may disclose personal data to law enforcement, courts, regulators, or child-protection organisations where we are required to by valid legal process, or where we believe in good faith that disclosure is necessary to prevent an imminent risk of death or serious physical injury, or to report the sexual exploitation of a child. We do not give any authority bulk or standing access to Kindrd, and we assess every request on its own terms and refuse those that are overbroad or lack a proper legal basis.

Where the law allows it, we will tell you before disclosing your data so you have a chance to object. We will not tell you where we are legally prohibited from doing so, where there is an emergency risk to life, or where notice would put a child at risk or prejudice an investigation into trafficking or CSAM. Our Law Enforcement Guidelines set out the full process, including what we hold, how requests are made, and how emergency disclosures and preservation requests are handled.

Your rights

Wherever the law provides them, you can:

  • Access and export your data (Settings has a one-click download of everything we hold about you).
  • Correct your profile at any time from Edit profile.
  • Delete your account and data permanently from Settings, subject only to the safety and legal exceptions described above.
  • Withdraw consent to identity-data processing (this means closing your account, since matching depends on it).
  • Object or restrict certain processing, and lodge a complaint with your local data-protection authority — in the UK, the Information Commissioner's Office at ico.org.uk.

We answer rights requests within one month. If we have to refuse part of a request because of the safety or legal exceptions above, we will tell you which part and why, unless telling you would itself defeat the purpose of the exception.

Age, and protecting children

Kindrd is strictly for adults aged 18 and over. We do not knowingly allow anyone under 18 to use the service, and we close any account we believe belongs to a minor. If we become aware that we hold data about a child, we delete it, except where we are required to preserve it and report it as part of a child-protection referral.

We operate a zero-tolerance policy on child sexual abuse material and on the sexual exploitation or trafficking of any person, set out in our Terms of Service and our Law Enforcement Guidelines.

Cookies and what your device stores

We use one essential first-party cookie to keep you signed in, and your browser's local storage to remember your light or dark theme. We do not use tracking or advertising cookies, so there is no consent banner to click through.

Your browser stores more than the theme for us, and all of it stays on your device — we never receive it. It keeps drafts so you don't lose work: an unfinished post or story, including any picture you added that hasn't uploaded yet, and a part-completed sign-up form. It also keeps your recent searches, so they can be offered back to you, and small preferences such as which nudges you have dismissed and which camera you last used. Nothing here is sent to us or to anyone else. Clearing your browser's site data for Kindrd removes all of it; post and story drafts are additionally cleared on their own when you sign out or a different account signs in on that browser.

Changes to this policy

If we make material changes, we will update the date above and, where appropriate, notify you. Continued use after an update means you accept the revised policy.