Privacy Policy
What we collect to verify members and keep TwoTide safe, why we need it, who we share it with, and how you stay in control.
The short version
- We collect what we need to verify that you are who you say you are, keep members safe, and help you meet someone.
- Your ID and face scan are checked by our identity-verification partner, only with your consent, and kept only as long as needed.
- We never sell your personal information, and we don’t use advertising or tracking cookies.
- You can download your data (ready within 48 hours) or delete your account (7-day grace period) at any time.
- Live streams are kept for 30 days. Video calls are never recorded.
1. About this policy
This policy explains how Counsel to confirm: legal entity name and address (“TwoTide”, “we”) collects, uses, shares and protects personal information when you visit twotide.com, use our apps, apply for membership or take part in TwoTide Live. We are responsible (the “controller”) for that information.
It should be read with our Terms of Membership and our Cookie Notice.
2. What we collect
TwoTide is a verified service, so we collect more than a typical app, and we’re careful with it.
| Information | What it includes | Where it comes from |
|---|---|---|
| Application details | Name, date of birth, gender, who you’re interested in, city, relationship intent, phone number, email address, and the version of our terms you accepted. | You |
| Phone line type | Whether your number is mobile, landline or internet-based (VoIP), and the carrier. Internet numbers get extra review. | Our SMS provider’s carrier lookup |
| Social accounts | For each account you connect (at least three of Facebook, Instagram, TikTok and X): the platform, your account ID and username, and basic signals like account age. We never post for you or read your private messages. | The platform, when you sign in with it |
| Government ID and face data | Images of your ID, the details on it (such as name, date of birth, document type, number and expiry), live selfie images, and the result of a face match and liveness check. See the biometric notice below. | You, via our identity-verification partner |
| Video selfie | A short video of you following random gestures, the gestures shown, and the check result. Repeated every 6 months. | You |
| Profile | Photos, prompts and answers, preferences (such as age range), and settings like hiding your distance or incognito. | You |
| Activity and messages | Likes, matches, messages, blocks, reports you make or receive, and safety signals our scam guard attaches to messages. | You and other members |
| Live and calls | Live stream recordings (kept 30 days), comments, gifts and tickets. For video calls, only who called whom, when and for how long: calls themselves are never recorded. | You and other members |
| Payments | Your plan, amounts, dates and payment status. Card details go straight to our payment processor; we don’t receive or store your full card number. | You, via our payment processor, or Apple/Google |
| Device and usage | IP address, device and browser type, app version, push-notification token, sign-in times, pages and features used, and approximate location derived from your IP address. We use device and network signals to spot duplicate accounts and location mismatches. | Your device |
| Conversations with us | Emails and support requests, and for Elite members, messages with and notes kept by your advisor. | You and our team |
Some of this is sensitive: your ID and face data, and who you’re interested in, which may reveal your sexual orientation. We use sensitive information only to provide the Service and keep it safe, never to advertise to you. Counsel to confirm: sensitive-data consent requirements under state privacy laws for “interested in” and similar fields
3. How and why we use it
- Verifying you: confirming your identity and age, that your photos are you, and that you haven’t been banned before.
- Keeping members safe: screening messages for scam patterns, holding back links in new conversations, detecting duplicate or fake accounts, reviewing reports, and enforcing our Community Guidelines.
- Running TwoTide: showing your profile, suggesting daily matches, delivering messages, calls and Live, and sending notifications.
- Payments: charging the application fee, memberships, tokens and tickets, and handling refunds.
- Talking to you: sign-in codes, account and safety notices, report updates and, if you choose, news from TwoTide.
- Improving the Service: understanding which features work, fixing problems and making matches better.
- Legal reasons: meeting legal obligations, responding to lawful requests, and protecting our rights and our members.
Automated decisions
Some safety steps are automatic. For example, a second request for money in chat pauses the sender’s account, and three independent reports can pause an account, both until a person reviews it. Verification checks are scored automatically, but a person reviews every application before anyone is approved. You can ask for any automated decision about you to be reviewed by a person.
Legal bases (if you’re in the UK or European Economic Area)
We rely on: performing our contract with you (running your membership); our legitimate interests in keeping TwoTide safe and improving it; your consent (for biometric data and optional marketing, which you can withdraw); and legal obligations. Counsel to confirm: whether TwoTide targets the UK/EEA at all at launch; if so, a full lawful-basis table
4. Biometric data notice
To confirm that the person applying matches their ID, and to stop fake and repeat accounts, we and our identity-verification partner use facial geometry taken from your ID photo, your live selfie and your video selfies (“biometric data”). This includes a liveness check that makes sure a real, present person is in front of the camera.
- Consent first. We ask for your express written consent in the app before any biometric data is collected. If you don’t consent, you can’t complete verification, and so can’t become a member.
- One purpose. We use biometric data only to verify your identity, re-verify you every 6 months, and prevent fraud and banned members rejoining.
- Never sold. We never sell, lease, trade or otherwise profit from biometric data.
- Limited sharing. We disclose it only to our verification partner, who processes it on our behalf under contract, or where the law requires it, or with your consent.
- Retention and destruction. Verification media and any face templates are kept only as long as needed for the purpose they were collected for, and permanently destroyed after that, and in any case within Counsel to confirm: period — no later than 3 years after your last interaction with TwoTide (Illinois) and generally within 1 year after the purpose ends (Texas), whichever comes first.
- Protected. We store and transmit biometric data using a reasonable standard of care, at least as protective as for our other most sensitive information.
Consent statement (shown in the app, and recorded with its version, before the application fee): “I agree that TwoTide and its identity-verification partner may collect, store and use biometric identifiers and information from my ID photo, live selfie and video selfies to verify my identity and prevent fraud, as described in the Biometric data notice. I understand it will be destroyed when no longer needed for that purpose, and no later than the period stated there.”
Counsel to confirm: final consent wording and flow for Illinois (BIPA), Texas (CUBI), Washington (RCW 19.375 and the My Health My Data Act), Colorado and other states; whether we or only our partner hold face templates; the public retention schedule
6. Your rights and choices
Wherever you live, you can:
- Access and download your data. Request a copy from Settings → Download my data. It’s ready within 48 hours, and the link works for 7 days.
- Delete your account. From Settings → Delete account. Your profile is hidden straight away, and everything is erased after a 7-day grace period, except the limited records described under How long we keep it.
- Correct your information. Edit your profile any time. To change verified details like your name or date of birth, email us; we may ask you to verify again.
- Withdraw consent. For marketing, at any time. Withdrawing biometric consent means you can no longer stay verified, so your membership would end.
- Control notifications in Settings, and unsubscribe from marketing emails using the link in each one.
- Opt out of the sale or sharing of your data, and limit the use of sensitive information. We don’t sell or share personal information for advertising and only use sensitive information to run and protect the Service, so there’s nothing to opt out of, but you can still ask us to confirm it.
Depending on where you live (for example California, other US states, the UK or the EEA), you may also have the right to know more about how we process your data, to object to or restrict processing, and to appeal our response to your request. We won’t treat you differently for using your rights.
If you can’t use Settings, email [email protected]. We’ll confirm it’s you by sending a code to the email on your account, and reply within the time the law requires (for example 45 days in California, one month in the UK and EEA). An authorised agent can make a request for you with your signed permission. Counsel to confirm: state appeal process wording; whether a toll-free number is required
Download my data and Delete account are being added to Settings. Until they appear, email [email protected] and we’ll do it for you within the same timeframes.
7. How long we keep it
We keep personal information only as long as we need it for the purposes above. In particular:
| Information | How long |
|---|---|
| Account, profile and preferences | While your account exists, then erased after the 7-day deletion grace period. |
| Messages | While your account exists. When you delete your account, the messages you sent are erased too, except any linked to a report, which we keep as safety records. |
| ID images and live selfie images | Deleted by our verification partner once the check is complete. We keep only the result. Counsel to confirm: maximum period, per the partner contract |
| Verification results | While your account exists, and afterwards for Counsel to confirm: period as a safety record. |
| Video selfies | Until replaced by your next re-verification, and no longer than Counsel to confirm: period. |
| Live stream recordings | 30 days, then deleted, unless needed for a specific open report or legal matter. |
| Video calls | Never recorded. Call records (who, when, how long): Counsel to confirm: period. |
| Payment records | As long as tax and accounting law requires. Counsel to confirm: period, typically 7 years |
| Safety records | Reports, warnings, suspensions, bans and related messages are kept after an account is deleted, for as long as needed to protect members and meet legal obligations. Counsel to confirm: period |
| Banned-identity fingerprint | If you’re banned, we keep a one-way fingerprint of identity details (such as name, date of birth or ID document number) so you can’t rejoin. Counsel to confirm: period, and whether indefinite retention is justified |
| Data exports | The download link expires after 7 days and the file is then deleted. |
| Backups and logs | Overwritten on a rolling basis within Counsel to confirm: period. |
8. How we protect it
We encrypt data in transit and encrypt verification documents in storage. Staff access is limited by role and logged, and staff sign in with one-time codes. We test our security regularly, including independent penetration testing, and have a documented incident-response plan. If a breach affects you, we’ll tell you and the relevant authorities as the law requires, including within 72 hours where that applies.
No system is perfectly secure, so please keep your email account safe: it’s how you sign in to TwoTide.
9. Children
TwoTide is only for adults aged 18 and over, and we confirm age from a government ID before anyone can join. We don’t knowingly collect information from anyone under 18. If we learn that we have, we delete it and close the account. If you think someone under 18 is using TwoTide, please report it in the app or email [email protected].
10. International transfers
TwoTide is based in the United States and your information is stored and processed there, and wherever our service providers operate. If you use TwoTide from outside the US, we protect transfers with appropriate safeguards, such as standard contractual clauses. Counsel to confirm: transfer mechanisms, and whether a UK/EU representative is required
11. Changes to this policy
When we change this policy, we’ll update the date at the top. If a change is material, we’ll tell you by email or in the app before it takes effect and, where the law requires, ask for your consent again.
12. Contact us
Privacy questions and requests: [email protected]. Everything else: [email protected].
Data protection contact: Counsel to confirm: name or role of the data protection contact (and DPO, if one is required), and postal address. If you’re in the UK or EEA, you can also complain to your local data protection authority.
To report a safety concern, use the report button in the app or visit the Safety center.