Last updated: June 2026
The data controller under GDPR is:
talkbeforedate
KB-Bit Systems UG (haftungsbeschränkt)
Karolingerstr. 20
67354 Römerberg
Germany
privacy [at] talkbeforedate.de
At a glance — required vs. voluntary data:
Registration (Art. 6(1)(b) GDPR — contract performance):
Email address, password hash (never in plaintext), timestamps of Terms and Privacy Policy consent.
Profile data (Art. 6(1)(b) GDPR):
Display name, bio, birth month and year (not the exact day — data minimisation per Art. 5(1)(c) GDPR), city, optional photos, audio intro.
Special categories — gender & dating preferences (Art. 9(2)(a) GDPR — explicit consent):
Gender and dating preference data may allow inferences about sexual orientation and therefore constitute special categories of personal data under Art. 9 GDPR. This data is processed exclusively to provide the dating service. You provide it voluntarily; without it the core app functionality is not available. We obtain this consent explicitly at registration via a separate, non-pre-checked checkbox (Art. 9(2)(a) GDPR). You can withdraw it at any time with effect for the future; since the dating service cannot be provided without this data, withdrawal is effected by deleting your account.
Photo verification — biometric processing (Art. 9(2)(a) GDPR — explicit consent):
The optional photo verification requires a live selfie with a random hand gesture. The photo may contain biometric features (facial characteristics) and is therefore treated as a special category under Art. 9 GDPR. The selfie is first pre-checked automatically by an AI system. This currently runs exclusively locally on our own servers. No transmission to external AI services takes place. Should we use external AI services in future, we will inform you in advance and update this policy accordingly. If the additional automatic image comparison is active, a system running locally on our servers compares the verification selfie with your main profile photo to check whether both show the same person (biometric similarity comparison). Mathematical feature vectors are computed from both images for this comparison only and are not stored permanently; only the similarity score is stored. This result, too, is solely a suggestion — the decision is made by a human. The AI result is solely a suggestion; the binding decision is always made by a team member. No fully automated decision-making within the meaning of Art. 22 GDPR takes place. The selfie is deleted immediately after the admin decision. Unreviewed verifications are automatically rejected and the selfie deleted after 30 days. We obtain your explicit consent to this processing immediately before the photo verification starts; participation is entirely voluntary.
Profile data — visibility to other users (Art. 6(1)(b) GDPR):
Display name, bio, age, city, photos and audio intro are visible to other logged-in users — that is the purpose of the dating service. Non-public fields (email address, password hash, payment data) are never visible to other users.
Location data (Art. 6(1)(b) GDPR):
You enter your city as a text field. To calculate distances for matching, we derive geographic coordinates (latitude/longitude, WGS84) from that city name — exclusively via the public geocoding serviceNominatim by the OpenStreetMap Foundation (UK). Only the city name is transmitted; no GPS position or other personal data is sent. We do not request or store GPS data from your device.
Communication (Art. 6(1)(b) GDPR):
Messages are stored encrypted on our servers (AES-256). Encryption and decryption happen server-side; our systems process message content automatically only for delivery and display. Our team only reviews content where necessary to investigate a reported violation or as required by law. Call metadata (time, duration) is stored without content; we do not record call audio or video.
Safety check-in / sharing with a trusted contact (Art. 6(1)(b) and (f) GDPR):
If you use the "Share meeting" feature before a meeting, you voluntarily provide the contact details (email address, optionally phone number) of a trusted contact you choose. We process this data solely to send that person the meeting information you share (your display name, location, time, and your check-in status) — by email or, where enabled, by SMS. You confirm that you have informed that person about this disclosure beforehand. The trusted contact's details are used only for this purpose and deleted once the shared meeting expires or is revoked.
Security & fraud prevention (Art. 6(1)(f) GDPR — legitimate interest):
Hashed IP addresses (no plaintext), device fingerprint hash for fraud and spam detection.
Private photo protection / pseudonymous viewer identifier (Art. 6(1)(a) and (f) GDPR — consent + legitimate interest):
If you enable the optional "Private photo protection" feature in settings, your private profile photos are marked with an invisible pseudonymous identifier. This identifier is a truncated SHA-256 hash of the internal user ID of the person viewing the photo — not a real name, email address, or any directly identifying information. The hash is a one-way function; no person can be identified from the identifier alone. Resolving the identifier to a person is only possible internally as long as the relevant user ID exists in our systems (up to 30 days after account deletion, after which it is permanently deleted). This processing serves the legitimate interest of being able to trace and address unauthorised sharing of private photos (Art. 6(1)(f) GDPR). You can disable the feature at any time in settings; existing photos will then be served without the identifier.
Payments (Art. 6(1)(b) GDPR):
Payments processed by Stripe. We do not store card data — only order status and amount. Stripe's privacy policy applies: stripe.com/privacy.
Push notifications (Art. 6(1)(a) GDPR — consent):
If you enable push notifications, a device token is transmitted via Firebase Cloud Messaging (Google LLC, USA) and stored on our servers. You can disable push notifications at any time in the app settings or your device's system settings.
Error monitoring (Art. 6(1)(f) GDPR — legitimate interest):
We use GlitchTip (self-hosted on our STRATO servers in Germany) to detect and fix technical errors. Error reports may contain device-related information; personal data such as email addresses is automatically pseudonymised before processing. Logs are automatically deleted after 30 days.
Website statistics (Art. 6(1)(f) GDPR — legitimate interest):
For anonymous usage statistics we use Umami Analytics (self-hosted on our servers). Umami sets no cookies and stores no personal data; only aggregated, non-identifiable metrics are collected (page views, session duration). No data is shared with third parties.
Campaign attribution (Art. 6(1)(f) GDPR — legitimate interest):
If you open the app via an advertising or campaign link, we evaluate the campaign parameters contained in the address (e.g. utm_source, utm_campaign) to measure which channels lead users to register with us. This evaluation serves solely our own reach and performance measurement; no personal advertising profiles are created and no data is shared with advertising networks.
Active accounts: data retained until account deletion.
After deletion: anonymised within 24 hours; fully deleted within 30 days. Stripe transaction data is retained per statutory requirements (10 years under German tax law) but decoupled from the user record thereafter.
Messages: on account deletion, all sent message content from the deleted account is immediately and irreversibly wiped (encrypted content overwritten, voice messages deleted). The conversation partner sees the message as deleted. Messages received from other users in your chats remain visible to those senders.
Photo verification selfie: deleted immediately after the admin decision. Unreviewed verifications are auto-rejected and the selfie deleted after 30 days. The similarity score produced by the face-match comparison remains with the verification record and follows the same deletion schedule as the rest of the account (see "After deletion" above); the underlying feature vectors are not stored in the first place.
Pseudonymous viewer identifier (private photo protection): the internal user ID that could be used to resolve an identifier is permanently deleted no later than 30 days after account deletion. After that point the identifier in the photo can no longer be linked to any person.
Push token: deleted immediately on deactivation or account deletion.
Error logs (GlitchTip): automatically deleted after 30 days.
Umami statistics: aggregated, no personal data, no deletion deadline required.
We share data only where necessary for contract performance or technical reasons:
GlitchTip (error monitoring) and Umami (statistics) run on our own STRATO servers in Germany — no data is transmitted to external third parties.
No sharing with advertising networks. No sale of data.
Contact: privacy [at] talkbeforedate.de
We use only technically necessary storage:
We set no tracking or advertising cookies. No Google Analytics, no Facebook Pixel. For anonymous website statistics we use cookieless Umami Analytics (self-hosted) — no personal data is collected and no browser fingerprinting is performed.
Since these statistics rely on our legitimate interest (Art. 6(1)(f) GDPR), you can object to this processing at any time (Art. 21 GDPR) — free of charge and without giving a reason. Your objection takes effect immediately and applies to this browser until you withdraw it:
All transmissions are encrypted via TLS. Passwords are hashed with Argon2id. Messages are stored encrypted (AES-256, server-side encryption). Calls are routed anonymously through our servers — no phone number is transmitted. IP addresses are stored only as hashes (never in plaintext).
The app requests the following device permissions only when you use a feature that needs them:
We do not request GPS or location access — your city is processed solely as the text you enter (see section 2, "Location data"). You can revoke any permission at any time in your device's system settings; the corresponding feature will then be unavailable.
The app is exclusively for persons aged 18 and over. By registering you confirm you are at least 18 years old.
For material changes we will notify registered users by email and request renewed consent. The date of the last update is shown at the top of this page.