Lovelace
← Back to Lovelace

Privacy Policy — Lovelace

Last updated: March 2026

This Privacy Policy describes how Lovelace ("we", "us", "our"), a Posada.io product, processes personal data in connection with our dating application. Our platform is built on privacy-enhancing technologies including zero-knowledge proofs, decentralized identity, and blockchain infrastructure.

1. Controller & Contact

Controller: Lovelace / POSADA.IO

Privacy inquiries: privacy@posada.io

Support: support@posada.io

2. Purposes of Processing

3. Legal Basis

4. What We Collect and Where It Lives

We minimize data collection by design. Here is an honest accounting of what our server holds today and what stays on your device.

Data that NEVER reaches our server

Data our server holds today

Data CategoryWhat We StoreWhy
Account dataEmail address, display nameAuthentication, identification
Profile preferencesGender, religion, language, culture, orientation (all optional)Matchmaking
LocationApproximate city-level locationDistance-based matching. We do not store or transmit exact GPS coordinates.
Face embeddingA normalized geometric vector (~280 dimensions) derived from facial contour points. This is biometric-derived data under GDPR/LGPD.Designed to enforce one-person-one-account. Non-reversible — not designed to be reversible and cannot be practically reconstructed into a facial image. Stored server-side for comparison against new registrations.
Profile photosPhotos you voluntarily upload for your dating profileDisplayed to other users as part of the dating service
Chat messagesMessage content and timestampsDelivery and conversation history. Encrypted in transit via TLS.
DID referenceYour public DID identifier and credential IDLinking your device identity to your account
Reward balances$LILY token balance (simulated during beta)Reward tracking
Crash reportsTechnical error data via Sentry: stack traces, device info, screen navigation. User ID attached for debugging. No message content, no profile data, no photos.Stability and bug resolution. PII scrubbing applied. Retained 90 days.

What changes after Lovelace production launch on Cardano mainnet

Until these migrations are complete, the data listed above is stored on secured infrastructure (Hetzner VPS, PostgreSQL, TLS encryption in transit).

5. Zero-Knowledge Age Verification

The verification process has distinct on-device and server-side stages:

On-device (works without network connectivity):

  1. Your camera scans your identity document via ML Kit MRZ reader
  2. Date of birth is extracted from the MRZ data
  3. A Halo2 zero-knowledge proof is generated proving you are 18 or older
  4. The raw date of birth is immediately discarded from device memory

Server-side (requires network connectivity):

  1. The proof — not your date of birth — is transmitted to our server
  2. Our server mathematically verifies the proof
  3. Your account is marked as age-verified

You can verify the on-device nature of the scan and proof generation by enabling airplane mode before scanning. Document scanning and proof generation complete without network access. Final server verification occurs when connectivity is restored.

6. Decentralized Identity (Identus)

Your device creates a Decentralized Identifier (DID) using the Hyperledger Identus Edge Agent SDK. This is a cryptographic keypair generated and stored on your device. The DID itself is a cryptographic identifier and does not contain personal data, but because it is associated with your account, it may constitute personal data under GDPR. The DID is registered with our backend to establish a secure DIDComm connection via our Cloud Agent. Verifiable credentials (such as your age verification) are issued over this connection and stored on your device — not our server. We store only the public DID identifier and credential ID reference.

7. Face Embedding & Proof of Human

To help enforce one-person-one-account, we extract a face embedding from your selfie during verification.

What a face embedding is: A list of approximately 280 numbers representing the mathematical geometry of your face — distances between features, proportional relationships, contour shapes. It is computed on your device by ML Kit and then sent to our server for comparison.

What a face embedding is NOT: It is not a photo. It is not designed to be reversible and cannot be practically reconstructed into a facial image. It cannot identify you in a crowd or be used for surveillance purposes.

Legal classification: Under GDPR and LGPD, a face embedding is considered biometric-derived data because it is derived from facial features. We treat it accordingly — it is collected only with your consent during the verification process, stored with access controls, and permanently deleted when you delete your account. Our server maintains a database of these embeddings for comparison purposes. We process this data under GDPR Article 9(2)(a) (explicit consent) and LGPD Article 11.

The embedding is compared server-side against existing users using cosine similarity. If a match is found above our confidence threshold, the new account is rejected as a duplicate. This is a probabilistic biometric matching system that significantly raises the barrier to multi-account abuse.

If you delete your account, your embedding is permanently deleted.

Note: The "no photo stored" commitment applies to the identity verification and anti-duplicate system. As a dating app, Lovelace stores profile photos that you voluntarily upload for display to other users.

8. What We NEVER Do

9. Data Retention

We retain personal data only as long as your account is active. You can delete your account via app settings. This removes from active systems:

Residual data in server backups is purged within 30 days of account deletion. Crash reports via Sentry are retained for 90 days and then automatically deleted.

Data already recorded on the Cardano blockchain (such as token transactions) cannot be removed due to the immutable nature of blockchain technology.

10. Data Sharing & Processors

We share data only with the following, under strict contractual obligations:

ProviderPurposeData Involved
SentryCrash reportingTechnical error data only. No personal content.
Google ML KitFace detectionConfigured for on-device processing only. No data is transmitted to Google.
Hyperledger IdentusDID and credential infrastructureOpen source protocol. DID operations.
HetznerServer hostingInfrastructure provider.
Transak / MoonPay (future)Fiat on-rampPCI-DSS compliant payment processing. We receive confirmation only.

We do not use advertising networks, data brokers, or behavioral analytics services.

11. International Data Transfers

When personal data is transferred outside the EU/EEA to a country without an adequacy decision, we ensure safeguards such as EU Standard Contractual Clauses (SCCs).

12. Your Rights (GDPR & LGPD)

Under applicable data protection laws (including the EU GDPR and Brazil's LGPD), you have the right to:

Contact: privacy@posada.io

Rights to erasure do not apply to data immutably recorded on a public blockchain.

LGPD Notice: For users in Brazil, our legal basis for processing includes consent (Art. 7, I), contract performance (Art. 7, V), and legitimate interests (Art. 7, IX) under the LGPD. You may contact Brazil's Autoridade Nacional de Proteção de Dados (ANPD) to file a complaint.

13. Security & Authentication

14. Apple App Store Disclosures

We comply with Apple's App Tracking Transparency framework.

15. Children

Lovelace is for users aged 18 and older only. Age is cryptographically verified during signup using zero-knowledge proofs. We do not knowingly collect data from anyone under 18.

16. Changes to This Policy

We will notify users in-app of any material changes to this privacy policy.

17. Contact & Complaints

Privacy: privacy@posada.io

Support: support@posada.io

You have the right to lodge a complaint with your local Data Protection Authority.

© 2026 Posada.io / Lovelace