DateDetect — Privacy Policy
Effective: 19 August 2026 · Last updated: 17 September 2026
1. Who we are
DateDetect is operated by Dani DI LTD, 16 Manford Cross, London, United Kingdom ("we", "us"). We are the data controller for the personal data described here.
Contact: info@datedetect.com
Because we are established in the United Kingdom and offer this service to people in the European Union, both the UK GDPR and the EU GDPR apply to us.
EU representative (Art. 27 EU GDPR): being appointed. Until then, EU users may contact us directly at info@datedetect.com or complain to their national supervisory authority.
You may complain to the UK Information Commissioner's Office (ico.org.uk). If you are in the EU, you may instead complain to the supervisory authority in the country where you live or work.
2. What DateDetect does
You give us a conversation you have had with someone you met online, optionally answer questions about it, and we return a risk assessment describing patterns associated with romance and investment scams. We produce an assessment of the material you provide. We do not investigate people, and we do not tell you that anyone is a criminal.
3. The data involved
Data about you
- Account: email address, password (stored hashed by our authentication provider), account creation and sign-in times.
- Check metadata: date, risk band, which pattern identifiers matched, the platform you named, roughly how long you had been talking, whether you indicated money had already been sent, and processing time.
- The label you optionally give a check to remember which conversation it was.
- Technical data required to serve the site.
Data you upload
- Screenshots, pasted text, or chat export files containing your conversation.
- Optionally, up to three profile photos of the other person.
- Optional answers to our questions and free-text observations.
- Optionally, the name or address of a trading platform or app.
Data about the other person
Your conversation necessarily contains their messages, may contain their photographs, and may contain details about their life. Section 6 explains our position on this.
4. What we keep, and for how long
This is the part that matters most, so it is stated plainly.
| Data | Retention |
|---|---|
| Uploaded screenshots and files | Deleted immediately after the analysis reads them. Never retained. |
| Profile photos of the other person | Sent to the two photo-check providers named in section 8, then deleted. Never retained by us. |
| Extracted conversation text | Held in memory during processing only. Never written to our database. |
| Your finished report | Kept in your account for 30 days, then automatically deleted. You can delete it sooner at any time. |
| Check metadata (band, pattern identifiers, platform, timings) | Retained without conversation content, for service statistics and to improve detection. |
| Account data | Until you delete your account. |
Our database has no field capable of storing conversation content. This is a design constraint, not a policy promise: the columns do not exist.
Your report does contain short quotations from the conversation, because a finding without its evidence is not useful. Only you can read it. It is deleted after 30 days.
5. Why we process it, and on what legal basis
| Purpose | Data | Legal basis |
|---|---|---|
| Producing your risk assessment | Everything you upload | Performance of a contract with you (Art. 6(1)(b)) |
| Processing the other person's data within it | Their messages and any photographs | Legitimate interests — fraud prevention (Art. 6(1)(f)) |
| Checking profile photos you add | The other person's photos, and public page names found alongside them | Legitimate interests — fraud prevention (Art. 6(1)(f)) |
| Keeping your account and check history | Account and metadata | Contract (Art. 6(1)(b)) |
| Improving detection accuracy | Aggregated metadata only, no content | Legitimate interests (Art. 6(1)(f)) |
| Security, abuse prevention, legal compliance | Technical and account data | Legitimate interests; legal obligation |
We do not use your data for advertising, do not sell it, and do not build profiles of the people you ask about.
6. The other person in your conversation
They did not consent, and we will not be able to contact them.
We rely on legitimate interests — preventing fraud against you, which data protection law recognises as a legitimate interest. We have carried out and documented a balancing assessment. Our position rests on the following limits, which we apply in every case:
- We do not retain their messages or photographs.
- We do not keep a database of people who have been assessed. No name, handle, or face is stored.
- We do not share our findings with anyone but you.
- We do not try to find out who they are, and we run no facial recognition.
- Our reports state explicitly when the material does not establish that the person did anything wrong.
If you add their profile photos, we check whether a photo shows signs of being AI-generated and whether the same photo appears elsewhere on the public web. Where it appears on a public social or dating profile, we read the name shown on that page for one purpose only: to tell whether a single photo is being presented under different names, which is a common sign of a stolen photo. Those names are held in memory during the analysis, are never written to our database, and are never shown in your report. Your report may say that a photo appears elsewhere and on what kind of site.
We do not notify them, relying on the exemption where notification would require disproportionate effort — we hold no means of contacting them and would have to retain their data to do so, which would be worse for their privacy than deleting it.
If you are the other person and believe your data was processed, contact us. In almost all cases nothing about you remains: uploads are deleted at once, and reports expire after 30 days.
7. Sensitive content
Conversations can contain intimate, medical, religious, or political material. We do not seek it, do not analyse it as such, and do not record it. It is deleted with everything else once the analysis completes.
Please do not upload intimate images. If you are being threatened with the release of intimate images, our questions let you report that without providing any such image, and our report will point you to appropriate support.
8. Who processes data for us
- Supabase — database and authentication, hosted in the European Union (Frankfurt).
- Lovable — builds and hosts the application, sends account emails, and routes our requests to the AI models.
- Cloudflare — runs the application servers on Lovable's behalf.
- Google (Gemini models, accessed through Lovable) — the analysis itself. Content is processed to produce your result.
- Google Cloud Vision — only when you add profile photos: checks whether a photo appears elsewhere on the web. This runs on Google's global infrastructure and may take place outside the UK and EEA.
- Hive (United States) — only when you add profile photos: checks a photo for signs of AI generation.
- Stripe — processes payments. Stripe sells credits to you as merchant of record, so it is also an independent controller of the payment data it collects, under its own privacy policy. We never see your full card details.
- A public domain-registration lookup service — only when you supply a platform address, and only that address is sent.
Each provider acting on our behalf does so under a data-processing agreement.
International transfers. We are in the UK; our database is in the EU (Frankfurt), a transfer covered by the UK's adequacy regulations. Some providers above, including Google, Hive and Stripe, may process data in the United States or elsewhere outside the UK and EEA. For those transfers we rely on the applicable adequacy decision or framework certification, or on standard contractual clauses together with the UK International Data Transfer Addendum.
Cookies and analytics
We use cookies that are strictly necessary to keep you signed in. We use Google Analytics only on our home page, affiliate programme page, privacy policy and terms pages — never on the check, report, pricing or account pages. Analytics cookies are set, and Google Analytics is loaded, only if you accept them. Accepting and rejecting are equally easy, and you can change your choice at any time with "Cookie preferences" at the bottom of every page. The referral cookie is described in section 11.
9. Your rights
Access, rectification, erasure, restriction, objection, portability, and withdrawal of consent where consent applies. You can delete any individual report, or your entire account and all its history, from your account page — this is immediate and permanent. For anything else, write to info@datedetect.com; we respond within one month.
10. Security
Data in transit is encrypted. Reports are protected by database-level access rules so that only the account that created them can read them through the service. Our administrative tools do not display report contents, and administrative statistics are drawn only from data with no conversation content in it. Direct database access is restricted to the operator and used only for maintenance and security.
11. If you join the affiliate programme
This section applies only to people who apply to promote DateDetect. It does not affect anyone who simply uses the service.
What we collect
Your name or brand, your account email address, the country where you are taxed, and the text of your application — the description of your audience, the channels you intend to use, and any website you give us. Once you are approved, the payout method you choose: a PayPal or Wise email address, or for bank transfers the account holder's name and address, bank name and country, account number or IBAN, SWIFT/BIC and any routing code. We also keep the version of the affiliate terms you accepted and when, and the record of commission earned, reversed and paid.
Why we may process it
Performance of a contract. Your affiliate agreement with us cannot be operated without this data: we cannot assess an application, attribute a referral, calculate commission or pay you without it. Where we are required to keep financial records, the basis is our legal obligation to do so.
How payout details are protected and shared
Payout details are encrypted before they are stored, with a key held outside our database. Only an administrator signed in with two-factor authentication can view them, only to make a payment, and every viewing is logged. They are shared only with the payment provider used to pay you — PayPal, Wise or our bank — which processes them under its own terms and may carry out its own sanctions and fraud checks.
How long we keep it
Longer than we keep anything else. Records of commission and payouts are financial records and are kept for six years from the end of the financial year they relate to, as UK law requires — including after you close your account, when your application text is erased but those records remain. Your payout details are deleted when you remove them or close your account. A rejected application, and any affiliate account that never earned commission, is deleted on request.
The referral cookie
When someone follows an affiliate’s referral link we set a first-party cookie named dd_ref. It contains a referral code and nothing else — no identifier for the visitor, no tracking across other sites, and no data shared with any third party. It lasts 60 days, and it is deleted the moment the visitor creates an account, at which point the referral has either been recorded or discarded.
It is set only when someone actively follows a referral link. Arriving at DateDetect any other way never sets it.
What an affiliate never sees
Referral tracking never links an affiliate to any user’s identity, analysis or result. An affiliate is shown aggregate counts and totals by day, and nothing else. They are not told who signed up through their link, what anyone uploaded, what patterns were found, or what any assessment concluded — not on request and not in any report. The restriction is enforced in our code, not left to policy. Payout statements group commission by day and contain no information about who made a purchase.
12. Children
DateDetect is for adults. You must be 18 or older. We do not knowingly process the data of anyone under 18.
13. Changes
We will post any changes here and update the date above. Material changes will be notified by email.