Privacy Policy
Last updated: 15 September 2026 Version: 1.10
English translation. This document is a translation of the Italian privacy policy (
PRIVACY_POLICY.md), which is the authoritative text. In case of any discrepancy between the two versions, the Italian version prevails. Both versions describe exactly the same processing operations.
Contents
- Who we are (Data Controller)
- What this notice covers
- What data we process
- Special categories of data ("sensitive data")
- Purposes and legal bases
- Mandatory and optional data
- Location: how it works and how we protect it
- Photos, verification documents and social handles
- Messages and chats (automatic translation disabled)
- Moderation, safety and automated decisions
- Who we share data with (processors)
- Where data is processed and transfers outside the EU
- How long we keep data
- Your rights
- Deleting your account
- Minimum age (18) and protection of minors
- Data security
- Notifications
- SDKs and technical components (no advertising or profiling)
- Complaint to the supervisory authority
- Changes to this notice
- Contact
1. Who we are (Data Controller)
The controller of the personal data collected through the Attimi app (Android package com.attimi.app, iOS app app.attimi) is:
- Mirco Orecchini (natural person — independent developer)
- Address: Via Pietrafitta 53, 47842 San Giovanni in Marignano (RN), Italy
- Privacy contact email: privacy@attimi.app
The controller is established in Italy (EU): no representative under Article 27 GDPR is required. No DPO has been appointed at this time; the controller will assess whether an appointment is mandatory (Article 37 GDPR) in light of the processing of special categories of data combined with location data, and will update this notice accordingly. For any question you can write to privacy@attimi.app.
2. What this notice covers
Attimi is a dating app for finding people who are available "right now" nearby. When you turn on "I'm available", your profile becomes visible to other compatible users within the radius you set, for a limited time (1 hour by default), after which your availability expires on its own.
This notice covers the Attimi app for Android and iOS and the connected backend services. It is available in Italian, English, Spanish, French and German, accessible before registration and from within the app; if the versions differ, the Italian text prevails.
3. What data we process
3.1 Account
Email, nickname (unique public name), language. Authentication is handled by Supabase Auth, and you can create your account and sign in through three routes: with email + password, with "Continue with Google" (Android and iOS) or with "Continue with Apple" (iOS only). With email + password, the password is stored only as a hash (a fingerprint from which the password cannot be recovered) and is never visible to the controller. If you do not confirm your address, we resend the confirmation email up to 3 times within the following 7 days, and the incomplete sign-up is deleted automatically 30 days later (section 13).
Signing in with Google or Apple. Your phone shows Google's or Apple's own panel; the app receives an identity token signed by the provider and hands it to Supabase Auth, which verifies it and opens the session. From Google we use and store only your email address, already verified by Google: the name and photo of your Google profile are not stored. From Apple we request only your email, not your name. If you choose Apple's "Hide My Email", we receive and store an Apple relay address (ending in @privaterelay.appleid.com) and our emails — only service emails: password reset, confirmation of account deletion — reach you through Apple's relay; for this purpose we registered our sender domain attimi.app and the address noreply@attimi.app with Apple. Accounts created with Google or Apple have no password: you can set one later with "Forgot password?". Signing in with Google or Apple inevitably means that Google or Apple learn that you signed in to Attimi, a dating app: their own privacy policies apply to that step (section 11). If an Attimi account with the same verified email already existed, the Google or Apple sign-in is linked to that same account (one account, two ways in); if that account had never confirmed its email, from that moment the email + password login no longer works until you set a password with "Forgot password?". The consents requested at sign-up (18+, privacy notice and terms, special category data) are asked in the app before the account is created with Google or Apple — or, if you enter from the login screen without ever having given them, in a dedicated step right after — and are recorded in the same way.
3.2 Profile
Sex/gender, age range, bio (max 100 characters), photos (up to 5), optional social handles (Instagram/TikTok/Facebook).
3.3 Preferences and privacy settings
Preferred gender, preferred age range, search radius (1–200 km), availability duration, photo visibility (always / after the chat / never), "don't receive messages while I'm offline" (people you already chat with cannot message you while you are not available), "don't keep chats".
3.4 Location
GPS coordinates read only at the moment you turn on your availability. Your exact position is never stored on the server: the ±300 m random blurring is applied before anything is written, so our database only ever holds approximate coordinates. Search uses those and always shows an approximate distance (e.g. "~2.3 km"). See section 7.
3.5 Messages
Text content of messages, read status, date/time, sender, reference to the match. Automatic translation is currently disabled (see section 9): no message text is sent to third-party translation services.
3.6 Age/identity verification (feature currently suspended — section 16)
When enabled: an image of an identity document and a selfie.
3.7 Safety and moderation
Reports (reason, description, status), blocks against other users, any ban status and reason. If a report is made from inside a conversation, also a copy of the latest messages of that conversation (at most 200), taken at the moment of the report and kept only for moderation (sections 9, 10 and 13).
3.8 Technical and diagnostic data
Account creation date and last activity; crash reports with technical context about the device/app (via Sentry, configured not to send email addresses or IP addresses by default). For 30 days, the technical log of notifications: to whom, when, of what type and with what outcome each alert was sent and, if it was not sent, why — never the text of the alert (section 18).
3.9 Payments
No data. Payment features (Stripe) are prepared in the code but disabled: the app is free. If they are enabled in the future, this notice will be updated before any payment data is collected.
4. Special categories of data ("sensitive data")
By its very nature, a dating app can reveal or allow inferences about sexual orientation: in particular the combination of your gender and your gender preference ("opposite sex" / "same sex" / "any"), used to suggest compatible profiles to you. Photos can also indirectly reveal special category data. When it is re-enabled, verification through a document plus a selfie may involve the processing of biometric data.
This data falls within the special categories under Article 9 GDPR. It is collected in the context of your voluntary use of the service and your acceptance of this notice at registration. As an improvement, we are preparing separate, granular in-app consent forms for location and for special category data, distinct from acceptance of the Terms. You may at any time choose not to provide this data (forgoing the related features) and delete your account (sections 14–15).
5. Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Account and authentication | Email (typed by you, or passed on by Google/Apple, or an Apple relay address), nickname, language | Contract (Art. 6.1.b) |
| Profile and matching by gender/age | Gender, age, bio, photos, preferences | Contract (Art. 6.1.b); photos: consent (Art. 6.1.a) |
| "I'm available" and nearby search | Location | Consent to the location permission (Art. 6.1.a) + contract (Art. 6.1.b) |
| Matching that reveals orientation | Gender + gender preference | Consent (Art. 9.2.a) in the context of voluntary use of the service |
| Chat between matched users | Messages | Contract (Art. 6.1.b) |
| Notifications | Notification permission | Consent (Art. 6.1.a) |
| Technical log of notifications (section 18) | Recipient, date and time, type of alert, sending outcome, reason for a non-sent alert | Legitimate interest (Art. 6.1.f): understanding why an alert did not arrive |
| Moderation, safety, anti-prostitution, bans | Reports, blocks, copy of the messages of the reported conversation (section 9) | Legitimate interest (Art. 6.1.f); for minors/prostitution also legal obligation (Art. 6.1.c) |
| Age/identity verification (when active) | Document + selfie | Consent (Art. 9.2.a) and/or legal obligation (Art. 6.1.c) |
| Crash diagnostics | Technical data | Legitimate interest (Art. 6.1.f) |
| Customer support | Messages sent to support | Contract/legitimate interest (Art. 6.1.b/f) |
6. Mandatory and optional data
- Mandatory in order to use the service: email, nickname, gender, age range and, for the core feature, the location permission.
- Optional: bio, photos beyond the first one, social handles. Not providing them does not prevent you from using the app.
7. Location: how it works and how we protect it
Location is designed according to privacy by design (Article 25 GDPR):
- Point-in-time reading, not continuous: your position is read only when you turn on your availability, with "balanced" accuracy. No background tracking. The permission requested is "while using the app" (never "always"/background).
- ±300 m obfuscation: at the moment of activation the server generates blurred coordinates with random noise.
- Your exact position is never stored: blurring happens before anything is written, so your precise location never enters the database, not even briefly. Our storage holds only blurred coordinates; nearby search uses those and always returns an approximate distance. The columns that once held exact coordinates, and their history, were deleted on 6 August 2026.
- User control: you can choose not to turn on your availability, turn it off, or revoke the location permission from your device settings.
Blurred coordinates are still personal data and are not treated as anonymous data: blurring reduces the risk, it does not make the data anonymous.
8. Photos, verification documents and social handles
Photos. Up to 5 images, stored in a storage bucket ("avatars") with no public file listing and with write access limited to your own folder. You control their visibility (always / after the chat / never). Photos may indirectly reveal special category data.
Social handles. Optional; they link your Attimi profile to external profiles and may make re-identification easier.
Verification documents (feature suspended). When re-enabled, document and selfie will be uploaded to a private bucket ("verifications") with write access only to your own folder, no client-side read access, accessible only to administrators.
9. Messages and chats (automatic translation disabled)
Messages with matched users are stored on the backend for as long as the conversation exists. They are deleted in three cases:
- when you or the other person delete the conversation from the chat list: the conversation and its messages are removed from the server immediately;
- when you or the other person have turned on the "don't keep chats" option: in that case the entire conversation is deleted as soon as neither of you is available any more (checked every 10 minutes);
- when you or the other person delete your account: the conversation's messages are removed by cascade.
Deleting a conversation is always symmetrical: when one of these cases occurs the conversation disappears for both participants, not only for the person who acted, and it cannot be recovered. This is a deliberate choice protecting the confidentiality of both parties: neither of you keeps a copy of the other's messages. It follows that a decision by the other person can delete messages you could still see; the app tells you with a notice, without revealing who acted or which of the three cases occurred.
If none of these three cases occurs, messages remain stored. Availability, match and message data also travels to authorised clients through Supabase's realtime channel (in the EU).
One exception, from 4 September 2026: reports. When one of the two participants reports the other from inside a conversation, or the automatic filter in section 10 blocks a message, the server copies at that very moment the latest messages of that conversation (at most 200, from both participants) and keeps them separately, for moderation only. The conversation still disappears in the three cases above, for both of you; the copy does not. The copy is not visible to either user, nor to any other user: only the Controller reads it, in the moderation queue, to decide on the report. It is deleted automatically 90 days after the report is closed, or earlier, together with the report itself, and in any case within 12 months of the report (section 13). Without this copy, moderators would face — as actually happened during testing — a report with not a single message left to read.
Automatic translation: currently DISABLED. At this stage no message text is sent to third-party translation services. The feature is built but switched off; it will only be re-enabled in the future with a compliant provider and plan (with adequate handling of the texts), and this notice will be updated before any messages are sent to third parties.
10. Moderation, safety and automated decisions
To protect the community we apply measures that involve some automated decisions (Article 22 GDPR):
- Anti-prostitution filter: an automatic keyword-based check (IT/EN) may prevent a message containing certain terms from being sent; in that case the message is not saved. It is a "best-effort" check on the app side.
- Automatic ban on reports: at 3 distinct reporters the account goes under review; at 5 it may be suspended automatically. From 4 September 2026, to prevent report flooding: only one open report per reporter–reported pair counts, and only reports made by accounts that, at the time of the report, were more than 24 hours old count.
- Evidence for moderation: when you report someone from a conversation, or the filter blocks a message, a copy of the latest messages of that conversation is kept (section 9), readable only by the Controller in the moderation queue. This is not an automated decision: a person decides on the report by reading that copy.
- If you delete your account, the reports you made remain in the moderation queue, no longer linked to your profile, so that a report does not vanish together with the person who made it (section 15).
- Blocks: you can block other users, with mutual exclusion from search and messaging.
You have the right to human intervention, to express your point of view and to contest a decision by writing to privacy@attimi.app.
11. Who we share data with (processors)
We do not sell your data. Some providers process it on our behalf (processors under Article 28 GDPR), only as far as necessary:
| Provider | Data | Purpose | Location |
|---|---|---|---|
| Supabase | All app data (profile, auth, coordinates, messages, photos/documents, reports, blocks) | Backend hosting (database, auth, storage, realtime) | EU — Frankfurt (Germany) |
| Crisp | Support messages + technical session data | In-app support chat | EU (France) |
| Sentry | Crash reports with technical context (no email/IP by default) | Crash diagnostics | EU (Germany) |
| Expo | Notification and build infrastructure (EAS) | Notifications/builds | Outside the EU (USA) |
| DeepL | No data at present (translation disabled) | Translation (switched off) | EU (Germany), if re-enabled |
| Stripe | No data at present (payments disabled) | Payments (switched off) | Outside the EU (USA/Ireland), if enabled |
Sign-in providers: independent controllers, not processors. If you choose "Continue with Google" or "Continue with Apple", the sign-in step is carried out by Google LLC and Apple Inc., which act for their sign-in service as independent controllers and not on our behalf: they learn that you signed in to Attimi and process that step under their own privacy policies — Google Privacy Policy, Apple Privacy Policy. From them we receive only your email address (section 3.1); we do not send them any other data from your profile (if you use Apple's relay, only our service emails pass through Apple).
| Provider | Data | Role | Location |
|---|---|---|---|
| Google LLC | The fact that you sign in to Attimi; passes your verified email on to us | "Continue with Google" — independent controller | Outside the EU (USA), certified under the EU–US Data Privacy Framework |
| Apple Inc. | The fact that you sign in to Attimi; passes your email or relay address on to us, and forwards our service emails if you use "Hide My Email" | "Continue with Apple" — independent controller | Outside the EU (USA), certified under the EU–US Data Privacy Framework |
12. Where data is processed and transfers outside the EU
Primary data is processed in the EU (Supabase in Germany; Sentry in Germany; Crisp in France). The authentication session is also stored locally on your device (app storage).
Transfers outside the EU: the Expo infrastructure (notifications/builds) is in the USA; Stripe (USA/Ireland) is relevant only if payments are enabled. For such transfers, appropriate safeguards (Articles 44–49 GDPR) are provided by Standard Contractual Clauses (SCCs) and/or certification under the EU–US Data Privacy Framework. If you sign in with "Continue with Google" or "Continue with Apple", the sign-in step is processed by Google LLC and Apple Inc. as independent controllers (section 11), including on servers in the USA: both companies are certified under the EU–US Data Privacy Framework. You may request a copy at privacy@attimi.app.
13. How long we keep data
| Data | Retention |
|---|---|
| Account and profile | Until the account is deleted |
| Sign-up never confirmed (confirmation email not opened) | 30 days from sign-up, then deleted automatically every night, together with the confirmation resends |
| Availability session and blurred coordinates (exact ones are not stored) | The session expires on its own (from 30 minutes to 6 hours, your choice) and is deactivated within a few minutes. The blurred coordinates are cleared 30 days after the end of the session, every night; only the date and duration of the session remain, until the account is deleted |
| Messages | Kept for as long as the conversation exists. Deleted — for both participants — when you or the other person delete the conversation (removed from the server immediately), when the "don't keep chats" option is active for at least one of you (as soon as neither is available), or when either of you deletes their account. Exception: the moderation copy of a reported conversation, see the "Reports/moderation" row |
| Photos | Until the account is deleted |
| Verification documents (if active) | In the private bucket until review/account deletion |
| Reports/moderation | For as long as necessary for safety; deleted with the account of the reported person. If the reporter deletes their own account, the report stays in the queue, no longer linked to their profile. The copy of the messages attached to a report (section 9) is deleted automatically 90 days after the report is closed, or earlier, together with the report, and in any case within 12 months of the report |
| Crash logs | According to Sentry's retention policy |
| Technical log of notifications (to whom, when, type of alert, sending outcome as reported by Expo and, if the alert was not sent, the reason: permission denied, "Never" or "Only while I'm available" setting, suspended account — never the text of the alert; section 18) | 30 days, then deleted automatically; deleted immediately together with the account |
| Administrative access log (every reading of data from the Controller's panel is recorded: who, what, when) | 12 months, then deleted automatically every night |
Some copies may persist temporarily in technical backups, removed according to rotation cycles.
14. Your rights
Under Articles 15–22 GDPR you have the right to: access, rectification, erasure, restriction, portability, objection to processing based on legitimate interest, withdrawal of consent, and not to be subject to significant automated decisions without human intervention (section 10).
You can exercise them from within the app (where available) or by writing to privacy@attimi.app. We will reply within one month (Article 12.3 GDPR), a deadline that may be extended in complex cases.
15. Deleting your account
You can delete your account and data yourself through "Delete account" in your profile (with double confirmation). Deletion removes your profile and, by cascade, the connected data (photos, messages, sessions with coordinates, blocks, reports received, verification requests) and the authentication user. The same applies to accounts created with Google or Apple: the authentication user is deleted together with the linked identity. We do not revoke the token on Apple's side: if you wish, you can remove Attimi from the "Sign in with Apple" list in your iPhone settings; likewise, in your Google account settings you can see and remove Attimi's access.
The reports you made remain in the moderation queue, no longer linked to your account, together with the attached copy of the messages (section 9): otherwise deleting an account would be enough to make a report disappear. Once decided, the report stays archived (closed) for as long as the reported person's account exists, as in the table in section 13; the copy of the messages is deleted 90 days after closure.
Deletion is also available via the web, without needing to log in or reinstall the app, at https://www.attimi.app/delete-account (or by writing to privacy@attimi.app).
Some information may persist for a limited period in backups, or be retained where necessary to comply with legal obligations or to establish, exercise or defend a legal claim (e.g. handling reports of abuse).
16. Minimum age (18) and protection of minors
Attimi is restricted to adults (18+). Use by minors is prohibited.
- At sign-up, an explicit confirmation of being at least 18 and acceptance of this notice are required (mandatory checkbox).
- Age verification through an identity document is temporarily suspended; at this stage we rely on self-declaration and moderation (including a report category for "minor"). A plan to re-enable document verification is in place.
- If we detect, or receive a credible report, that a user is a minor, we remove the account and the data.
- As a social/dating app we adhere to child safety (CSAE) standards, with in-app reporting and a point of contact: childsafety@attimi.app.
17. Data security
We apply appropriate technical and organisational measures (Article 32 GDPR), including:
- Row Level Security (RLS) on all tables: everyone accesses only their own data;
- exact position never stored: the ±300 m obfuscation is applied server-side before writing, and no column in the database holds exact coordinates; nearby search goes through a dedicated function that uses only the blurred coordinates and returns an approximate distance;
- private "verifications" bucket for documents (admins only); "avatars" bucket with no public listing and write access limited to your own folder;
- authorisation checks in server functions (caller identity = user; operations on chats/matches restricted to participants); the anonymous role revoked from application functions;
- secrets and API keys kept server-side, never bundled in the app;
- no password for accounts created with Google or Apple: the provider's identity token is verified by Supabase Auth at sign-in and is not kept;
- encryption in transit (HTTPS/TLS) for all communications;
- Sentry with
sendDefaultPii:false(no email/IP by default); - automatic retention: availability sessions expire on their own and their blurred coordinates are cleared after 30 days; conversations delete themselves when the "don't keep chats" option is on; complete deletion of data on request.
In the event of a data breach posing a risk to your rights, we will notify the Italian Data Protection Authority within 72 hours (Article 33) and, in high-risk cases, inform the data subjects (Article 34).
18. Notifications
The app can show you notifications (new chat request, acceptance, expiry, new message) subject to your consent to the relevant system permission (through the Expo infrastructure). You can turn them off at any time from your device or app settings.
To be able to understand why an alert did not arrive, the server records for 30 days to whom, when, of what type and with what outcome each alert was sent and, if it was not sent, why (permission not granted, "Never" or "Only while I'm available" setting, suspended account) and whether it fell in the night-time quiet band (section 13): never the text of the alert, which is not stored anywhere. The outcome is Expo's reply (alert accepted or rejected), not a confirmation that the phone displayed it. Only the Controller reads this technical log, from the administration panel; its basis is our legitimate interest in making alerts work (section 5), and it is deleted together with the account.
19. SDKs and technical components (no advertising or profiling)
The app does not use advertising profiling cookies or marketing/tracking SDKs. It uses technical components: Sentry (crash diagnostics, no email/IP by default), Crisp (support chat loaded in a WebView; support messages are processed by Crisp), the Expo notification infrastructure and the Google and Apple sign-in libraries, used only for the "Continue with Google" / "Continue with Apple" buttons (section 3.1). Your login session is stored locally on your device to keep you signed in.
20. Complaint to the supervisory authority
If you believe the processing infringes the GDPR, you may lodge a complaint (Article 13.2.d):
Garante per la protezione dei dati personali — Piazza Venezia 11, 00187 Rome, Italy — Switchboard +39 06 696771 — certified email protocollo@pec.gpdp.it — www.garanteprivacy.it. You may also contact the authority of the EU country where you live or work.
21. Changes to this notice
We may update this notice to reflect changes to the service or to the law (e.g. enabling translation with a compliant provider, enabling payments, or enabling identity verification). In case of material changes we will inform you through the app and/or by email. The date and version are shown at the bottom.
22. Contact
- Controller: Mirco Orecchini
- Email: privacy@attimi.app
- Account deletion via the web: https://www.attimi.app/delete-account
Attimi — privacy notice. Last updated: 15 September 2026 — Version 1.10. Android app package: com.attimi.app — iOS app: app.attimi.
Version 1.10 changes (15 September 2026): two new ways to sign in, declared before being switched on: "Continue with Google" (Android and iOS) and "Continue with Apple" (iOS only), alongside email + password, which always remains available and which nobody is required to replace. Section 3.1 says what we receive from the provider (only your email address, already verified; from Apple, if you choose "Hide My Email", a relay address), what we do not store (profile name and photo), that these accounts have no password, how an existing account with the same email is linked and when the consents are asked; section 5 mentions the email passed on by the provider; sections 11 and 12 add Google LLC and Apple Inc. as independent controllers of the sign-in step, with servers also in the USA (EU–US Data Privacy Framework certification); section 15 says that deletion is the same and how to remove Attimi from "Sign in with Apple"; section 17 that the provider's token is verified and not kept; section 19 mentions the sign-in libraries; section 13 updates the maximum length of an availability session, now up to 6 hours. No new purpose, no new retention period, no advertising, no data sold.
Version 1.9 changes (14 September 2026): no new processing, five clarifications. Section 2 now says that the notice is also available in Spanish, French and German (the Italian text prevails); section 3.1 says that the password is stored as a hash, not "in encrypted form"; section 3.3 quotes the two options with the names they have in the app ("don't receive messages while I'm offline", "don't keep chats") and clarifies that the first one blocks messages while you are the one who is not available; in the table of section 13 the cross-reference to the "Reports/moderation" row now uses the row's actual name. In section 16 the child safety (CSAE) point of contact is childsafety@attimi.app, the same as on the website's legal page (before: privacy@attimi.app).
Version 1.8 changes (4 September 2026, late evening): two retention periods not declared before. Sign-ups never confirmed (the confirmation email is resent up to 3 times within 7 days) are deleted 30 days after sign-up (sections 3.1 and 13); the administrative access log (every reading from the Controller's panel is recorded) is kept for 12 months (section 13). Both deletions are automatic, every night.
Version 1.7 changes (4 September 2026, evening — corrections after the internal review): section 2 says that this notice covers the app for Android and for iOS; section 5 gives the technical log of notifications a legal basis (legitimate interest), and sections 3.8, 13 and 18 say in full what it contains (including the reason for a non-sent alert and the quiet band) and that the outcome is Expo's reply, not delivery to the phone; section 9 and the table in section 13 say that a deleted conversation disappears from the server immediately, not "within 24 hours"; the blurred coordinates of availability sessions are now cleared 30 days after the session (sections 13 and 17): before, they stayed until the account was deleted. No new processing operation, no new recipient.
Version 1.6 changes (4 September 2026): a technical log of notifications, declared before use (sections 13 and 18). For every alert the server tries to send, it records for 30 days to whom, when, of what type and with what outcome — never the text of the alert, which has no place to be written at all. It serves to answer anyone who says "I don't get notifications" and to verify sending tests. No new recipient: Expo already received the same alerts. Deleted with the account.
Version 1.5 changes (4 September 2026): a new processing operation, declared before use. When a conversation is reported (by a participant, or by the automatic filter), the server copies its latest messages — at most 200 — and keeps them separately for moderation only, until 90 days after the report is closed, and in any case within 12 months (sections 3.7, 5, 9, 10, 13 and 15). Until now a reported conversation could vanish before being read, leaving moderators with an empty report. Three related clarifications: the reports you made stay in the queue even if you delete your account (sections 10 and 15); automatic suspension counts distinct reporters whose account is older than 24 hours, and one open report per pair (section 10); no new recipient, no data sent to third parties.
Version 1.4 changes (13 August 2026): the description of location handling in sections 3.4, 7, 13 and 17 was corrected. Earlier versions stated that the server stored "both the real coordinates and a blurred version". That stopped being true on 6 August 2026: since that date the ±300 m blurring is applied BEFORE anything is written, the columns that held exact coordinates were deleted along with their history, and no column in the database holds a precise position any more. The notice therefore described LESS protection than the service actually provides. No change to the processing: only the description changed, and it now matches how the service is built. No new purpose, no new recipient, no new data collected.
Version 1.3 changes (12 August 2026): the notice at the foot of the document describing it as a technical draft was removed. No change to the processing: purposes, legal bases, recipients, retention periods and rights are identical to version 1.2. The English translation of this notice — already announced in section 2 — was published at the same time; in case of discrepancy the Italian text prevails.
Version 1.2 changes (4 August 2026): section 9 and the corresponding row of the retention table were clarified. The text used to say "when you have turned on the 'don't keep chats' option" and "when you delete the conversation", implying that only your own choices counted. In reality, deleting a conversation is symmetrical: it applies to both participants and can also be triggered by the other person (deleting the chat, the "don't keep chats" option being active for even one of the two, deleting their account). This is a deliberate choice protecting the confidentiality of both parties. No change in behaviour: the app has always worked this way, only the description changed. No new processing, no new purpose, no new recipient.
Version 1.1 changes (30 July 2026): section 9 and the retention table in section 13 were corrected. Version 1.0 stated that messages "self-delete 24 hours after the match expires": in actual operation this does not happen automatically, because since chat approval was disabled matches no longer move to the "expired" state on their own. The text now describes the three cases in which messages are genuinely deleted.