LAST UPDATED: 26 SEPTEMBER 2026
This Privacy Policy describes how Lovelace ("we", "us", "our"), a Posada.io product, processes personal data in connection with our dating application. Our platform is built on privacy-enhancing technologies including zero-knowledge proofs, decentralized identity, and blockchain infrastructure.
1. Controller & Contact
Controller: Lovelace / POSADA.IO
Privacy & support: support@posada.io
2. Purposes of Processing
- Account Creation & Privacy-Preserving Verification: Creating your account and verifying your age and identity using zero-knowledge proofs and decentralized credentials.
- Proof of Human: Ensuring each account represents a unique real person through on-device face analysis (MobileFaceNet). A mathematical face embedding vector is stored server-side for uniqueness comparison — not a photo.
- Matchmaking & Communication: Enabling matches based on user-defined preferences, real-time messaging, and safety features.
- Service Operation: Maintaining security, preventing fraud, and improving reliability through crash reporting (technical data only).
3. Legal Basis
- Contract (Article 6(1)(b) GDPR): To provide the core dating service you request.
- Legitimate Interests (Article 6(1)(f) GDPR): For security, fraud prevention, and service improvement.
- Consent (Article 6(1)(a) GDPR): For optional features, which you can withdraw at any time.
4. What We Collect and Where It Lives
We minimize data collection by design. Here is an honest accounting of what our server holds today and what stays on your device.
Data that NEVER reaches our server
- Identity document images — scanned on-device only, never transmitted
- Date of birth — extracted on-device for ZK proof generation, then immediately discarded
- Facial comparison between your selfie and ID photo — runs on-device via ML Kit
- DID private keys — generated and stored in your device's secure keystore via Identus Edge Agent
- Verifiable credentials — issued over DIDComm and stored on your device
Data our server holds today
| DATA CATEGORY | WHAT WE STORE | WHY |
|---|---|---|
| Account data | Email address, display name | Authentication, identification |
| Profile preferences | Gender, religion, language, culture, orientation (all optional) | Matchmaking |
| Location | Approximate city-level location | Distance-based matching. We do not store or transmit exact GPS coordinates. |
| Face embedding | A 192-dimension MobileFaceNet embedding. This is biometric-derived data under GDPR/LGPD. | Designed to enforce one-person-one-account. Non-reversible — not designed to be reversible and cannot be practically reconstructed into a facial image. Stored server-side for comparison against new registrations. |
| Profile photos | Photos you voluntarily upload for your dating profile | Displayed to other users as part of the dating service |
| Chat messages | Message content and timestamps | Delivery and conversation history. Encrypted in transit via TLS. |
| DID reference | Your public DID identifier and credential ID | Linking your device identity to your account |
| Reward balances | Sparrow balance (in-app points). $LILY is not used in the app. | Reward tracking |
| Crash reports | Technical error data via Sentry: stack traces, device info, screen navigation. User ID attached for debugging. No message content, no profile data, no photos. | Stability and bug resolution. PII scrubbing applied. Retained 90 days. |
What changes after Lovelace production launch on Cardano mainnet
- Profile data and chat messages will migrate to Iagon decentralized encrypted storage — designed so that we do not have access to decrypted content
- Payments will move to Hydra L2 channels on Cardano
- ZK verification will migrate to Midnight for on-chain privacy-preserving proofs (dependent on Midnight mainnet readiness)
Until these migrations are complete, the data listed above is stored on secured infrastructure (Hetzner VPS, PostgreSQL, TLS encryption in transit).
5. Zero-Knowledge Age Verification
The verification process has distinct on-device and server-side stages:
On-device (works without network connectivity):
- Your camera scans your identity document via ML Kit MRZ reader
- Date of birth is extracted from the MRZ data
- A Halo2 zero-knowledge proof is generated proving you are 18 or older
- The raw date of birth is immediately discarded from device memory
Server-side (requires network connectivity):
- The proof — not your date of birth — is transmitted to our server
- Our server mathematically verifies the proof
- Your account is marked as age-verified
You can verify the on-device nature of the scan and proof generation by enabling airplane mode before scanning. Document scanning and proof generation complete without network access. Final server verification occurs when connectivity is restored.
6. Decentralized Identity (Identus)
Your device creates a Decentralized Identifier (DID) using the Hyperledger Identus Edge Agent SDK. This is a cryptographic keypair generated and stored on your device. The DID itself is a cryptographic identifier and does not contain personal data, but because it is associated with your account, it may constitute personal data under GDPR. The DID is registered with our backend to establish a secure DIDComm connection via our Cloud Agent. Verifiable credentials (such as your age verification) are issued over this connection and stored on your device — not our server. We store only the public DID identifier and credential ID reference.
7. Face Embedding & Proof of Human
To help enforce one-person-one-account, we extract a face embedding from your selfie during verification.
What a face embedding is: A list of 192 numbers produced from your selfie by a MobileFaceNet model. It is computed on your device and then sent to our server for comparison.
What a face embedding is NOT: It is not a photo. It is not designed to be reversible and cannot be practically reconstructed into a facial image. It cannot identify you in a crowd or be used for surveillance purposes.
Legal classification: Under GDPR and LGPD, a face embedding is considered biometric-derived data because it is derived from facial features. We treat it accordingly — it is collected only with your consent during the verification process, stored with access controls, and permanently deleted when you delete your account. Our server maintains a database of these embeddings for comparison purposes. We process this data under GDPR Article 9(2)(a) (explicit consent) and LGPD Article 11.
The embedding is compared server-side against existing users using cosine similarity. If a match is found above our confidence threshold, the new account is rejected as a duplicate. This is a probabilistic biometric matching system that significantly raises the barrier to multi-account abuse.
If you delete your account, your embedding is permanently deleted.
8. What We NEVER Do
- We never store identity document images
- We never store your date of birth
- We do not sell, share, or monetize your data. If this ever changes, we will notify you in advance and require your explicit consent.
- We never use advertising SDKs, behavioral analytics, or tracking services. We use Sentry for technical crash diagnostics only — this is not behavioral analytics.
- We never use the IDFA or any cross-app tracking frameworks
- We never access your contacts, call logs, browsing history, or other device data
9. Data Retention
We retain personal data only as long as your account is active. You can delete your account via app settings. This removes from active systems:
- Profile data
- Face embedding vector
- Chat messages
- DID registration reference
- Profile photos
- All associated personal data
Residual data in server backups is purged within 30 days of account deletion. Crash reports via Sentry are retained for 90 days and then automatically deleted.
Data already recorded on the Cardano blockchain (such as token transactions) cannot be removed due to the immutable nature of blockchain technology.
10. Data Sharing & Processors
We share data only with the following, under strict contractual obligations:
| PROVIDER | PURPOSE | DATA INVOLVED |
|---|---|---|
| Sentry | Crash reporting | Technical error data only. No personal content. |
| Google ML Kit | Face detection | Configured for on-device processing only. No data is transmitted to Google. |
| Hyperledger Identus | DID and credential infrastructure | Open source protocol. DID operations. |
| Hetzner | Server hosting | Infrastructure provider. |
| Transak / MoonPay (future) | Fiat on-ramp | PCI-DSS compliant payment processing. We receive confirmation only. |
We do not use advertising networks, data brokers, or behavioral analytics services.
11. International Data Transfers
When personal data is transferred outside the EU/EEA to a country without an adequacy decision, we ensure safeguards such as EU Standard Contractual Clauses (SCCs).
12. Your Rights (GDPR & LGPD)
Under applicable data protection laws (including the EU GDPR and Brazil's LGPD), you have the right to:
- Access your personal data and obtain confirmation of processing
- Correct incomplete, inaccurate, or outdated data
- Delete or anonymize unnecessary or excessive data
- Restrict or object to processing
- Data portability — receive your data in a structured, machine-readable format (in-app "Export my data" feature)
- Withdraw consent at any time, without affecting prior lawful processing
- Information about sharing — know which third parties have access to your data
Contact: support@posada.io
Rights to erasure do not apply to data immutably recorded on a public blockchain.
13. Security & Authentication
- Authentication: Email and password-based login. Passwords are hashed using industry-standard algorithms and never stored in plaintext. The Identus DID provides an additional cryptographic identity layer but does not replace password authentication.
- All data in transit encrypted via TLS/HTTPS
- Database stored on secured infrastructure. Face embeddings are encrypted at rest.
- API communication uses HTTPS exclusively
- Strict principle of least privilege for server access
- Sentry crash reporting configured with PII scrubbing
- Continuous monitoring via server logging
14. Apple App Store Disclosures
- Data Used to Track You: None. We do not track users across apps or websites.
- Data Linked to You: Contact info (email), identifiers (user ID, wallet address), usage data (app interactions).
- Data Not Linked to You: Diagnostics (crash logs, performance data).
- Data Not Collected: Financial information, health data, browsing history, search history.
We comply with Apple's App Tracking Transparency framework.
15. Children
Lovelace is for users aged 18 and older only. Age is cryptographically verified during signup using zero-knowledge proofs. We do not knowingly collect data from anyone under 18.
16. Changes to This Policy
We will notify users in-app of any material changes to this privacy policy.
17. Contact & Complaints
Privacy & support: support@posada.io
You have the right to lodge a complaint with your local Data Protection Authority.