Privacy Policy

Last updated: Sep 02, 2026

The following information explains the nature, scope, and purposes of the collection and use of personal data when you use this website and our app, as well as your rights.

I. Controller responsible for data processing (hereinafter: “we”)

Kibaki GmbH
Jülicher Str. 48
41464 Neuss
Germany

Data Protection Officer: DLC B2P UG (haftungsbeschränkt), Gerhardt-Hauptmann-Str. 49b, 51379 Leverkusen. For data protection enquiries, please contact: datenschutz@kibaki.com

Further details and contact options can be found in our Site Notice (Imprint).

II. Personal data, purposes of processing, and legal bases

Personal data means any information relating to an identified or identifiable natural person (hereinafter “data subject”). A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more special characteristics expressing the identity of that natural person.

Personal data is processed on our website and when using our app where this is necessary for the following purposes:

  • based on your wish and consent given (legal basis: Art. 6(1)(1)(a), Art. 9(2)(a) GDPR),
  • for the use of the website and our app (legal basis: Art. 6(1)(1)(b) GDPR),
  • to safeguard our interest in improving the user experience, promoting our services, and/or maintaining the security of use (legal basis: Art. 6(1)(1)(f) GDPR),
  • for the use of the services offered on the website and in our app, as well as for pre-contractual measures, in particular for your inquiries (legal basis: Art. 6(1)(1)(a) and/or Art. 6(1)(1)(b) GDPR, Art. 9(2)(a) GDPR),
  • for concluding and performing a contract (legal basis: Art. 6(1)(1)(b) GDPR, Art. 9(2)(a) GDPR), and/or
  • to fulfill a legal obligation to which we are subject (e.g., tax law or data protection requirements and retention obligations, legal basis: Art. 6(1)(1)(c) GDPR).

Further details on the processing of data can be found below under the corresponding headings:

1. Access data / server log files

When you visit our website, the servers of our website host automatically store the information that your browser sends, known as server log files. You can find further information from our host here: the AWS Privacy Notice.

This information includes:

  • Referrer (previously visited website)
  • Requested website or file
  • Browser type and browser version
  • Operating system used
  • Amount of data transferred
  • Device type used
  • Time of access
  • IP address in anonymized form (e.g., by truncating the last digits, so that no conclusions can be drawn about individuals)

The temporary processing of this data by the system is necessary to enable the website to be delivered to your device. For this purpose, the IP address in particular must be processed. This data is not merged with other data sources. The information is used exclusively to monitor our own website traffic and to maintain the technical operation of our host’s servers and network, including abuse prevention. The data is automatically deleted after 7 days. The legal basis is our legitimate interest in monitoring and maintenance as well as abuse prevention as described, Art. 6(1)(1)(f) GDPR.

2. Cookies

Our website uses technically necessary cookies to provide the basic functions of the website. Other technologies such as local storage or similar storage techniques are not used unless expressly mentioned below or in our consent management tool. Otherwise, we only use functional cookies so that we can provide you with the requested services and functions, § 25(2)(2) German Telecommunications Digital Services Data Protection Act (TDDDG), Art. 6(1)(1)(f) GDPR.

Insofar as you give consent for optional services and non-essential cookies, the legal basis is § 25(1) TDDDG, Art. 6(1)(1)(a) GDPR (consent). You can obtain further information on the cookies, local storage, and services used at any time from our consent management tool and revoke your consent freely and without disadvantage at any time with effect for the future. However, please note that our website may not always function as intended without the cookies used.

Most browsers also offer an option to restrict or completely prevent the storage of cookies. However, please note that the use and, in particular, the convenience of use will be limited without cookies.

3. Consent management with Consentmanager

To manage your consent when using our website, we use the tool consentmanager AB, Haltegelvägen 1b, 72348 Västeras, Sweden (https://www.consentmanager.net/). consentmanager AB is hosted on our own servers, so no data is transferred directly to the servers of consentmanager AB. The processing of the data collected by the tool (e.g. your consent decisions) takes place exclusively locally on our systems. No connection is established to the servers of consentmanager AB. The legal basis is our legitimate interest in the ability to manage consent, Art. 6(1)(1)(f) GDPR. In addition, we may be legally obliged to obtain consent and to be able to demonstrate it, cf. Art. 6(1)(1)(c) GDPR as well as GDPR and/or TDDDG respectively.

4. Contact via email or by other means

If you send us inquiries via email, contact form, or by other means, your details from this, including the data you provide there (e.g., name, email address, telephone, message content), will be processed for the purpose of handling the inquiry and in the event of follow-up questions.

The legal basis is Art. 6(1)(1)(b) GDPR and/or, in the case of consent, Art. 6(1)(1)(a) GDPR.

5. Registration

To use our services in full, registration and the creation of a user account are required. During registration, we process the following data:

  • Name, email address, and, where applicable, telephone number
  • Authentication data
  • Profile information
  • Profile photos
  • Location data
  • Filter preferences
  • Device identifiers (device token for push notifications)

Special categories of personal data: When using our services, special categories of personal data within the meaning of Art. 9(1) GDPR may be processed, in particular information on sexual orientation and sexual preferences, and gender identity. The legal basis for processing is Art. 9(2)(a) GDPR (consent). Consent can be revoked at any time with effect for the future. These personal data will then no longer be processed, unless another legal basis exists. Otherwise, the legal basis is Art. 6(1)(1)(b) GDPR.
If you choose an event-only profile, we do not collect any filter preferences or extended profile information. The legal basis for processing in this case is also Art. 6(1)(1)(b) GDPR.

6. Identity Verification

To keep our platform secure, we carry out a self-image identity verification. Users are shown a random pose to imitate in a photo, which is then uploaded.

Users can choose an automated check. In this case, a match and authenticity assessment is carried out by an artificial intelligence. The artificial intelligence can approve verifications but cannot finally reject them. In this process, biometric data may be processed for identification and authentication. If there is no match, the identification procedure is reviewed by a human. For the photo verification we use the services of Amazon Web Services Inc. (AWS), Amazon Bedrock, 410 Terry Avenue North, Seattle, WA 98109-5210, USA. Further information: AWS Privacy Notice

The location of processing is the European Union. Insofar as a third country transfer occurs in individual cases, the transfer is based on the adequacy decision for EU-US data transfers, the Data Privacy Framework. AWS is certified under the Data Privacy Framework.

The legal basis for processing is Art. 6(1)(1)(a) GDPR, Art. 9(2)(a) GDPR, and Art. 22(2)(c) GDPR. You can withdraw your consent at any time with effect for the future.

Alternatively, users can choose a human review directly as part of the identification procedure. In the case of human verification, the uploaded photos are checked by our staff to verify the match. No biometric features are extracted. The legal basis for processing is then Art. 6(1)(1)(b) GDPR (contract performance) as well as our legitimate interest in preventing (identity) fraud and abuse, Art. 6(1)(1)(f) GDPR.

Photo quality check: When you add photos to your profile, each photo is automatically analysed once to check that it is a genuine photograph and that your face is visible and not substantially obscured.
This is a detection check only: it establishes that a face is present, not who the person is. No facial features are extracted, no biometric template is created, and the photo is not compared with any other image or database. This analysis is carried out on our own infrastructure in the European Union. The legal basis is Art. 6(1)(1)(b) GDPR (contract performance) and our legitimate interest in preventing fake profiles and misuse, Art. 6(1)(1)(f) GDPR.

7. Authentication

We offer various authentication and login options:

  • Phone one-time password login: If you wish to log in with your telephone number, we will send you a one-time 6-digit code via text message (SMS). You enter this code in the app to confirm your identity. The code is valid for only 5 minutes and can only be used once. For sending one-time password codes, we use the service of Infobip d.o.o., Istarska 157, 52215 Vodnjan, Croatia. Further information: https://www.infobip.com/policies/privacy-notice
  • Login via Apple or Google: You can log in to us with your existing Apple or Google account. Further information: https://www.apple.com/legal/privacy, https://policies.google.com/privacy

The legal basis for processing is Art. 6(1)(1)(b) GDPR (contract performance) and Art. 6(1)(1)(f) GDPR (legitimate interest in the security of verification).

8. Moderation

We use automated procedures to moderate content in order to ensure the security of our platform and to prevent violations of our Terms of Use. This includes in particular checking uploaded photos for illegal or inappropriate content (e.g. violence, NSFW content, or hate speech). Moderation serves to pre-screen and flag potentially illegal content. Final decisions on the deletion or blocking of content are made by a human. The artificial intelligence analyzes the content of the uploaded photos for violations of our Terms of Use. No evaluation for the unique identification of natural persons takes place. For content analysis we use the service of Amazon Web Services Inc. (AWS), Amazon Bedrock, 410 Terry Avenue North, Seattle, WA 98109-5210, USA. Further information: AWS Privacy Notice

The location of processing is the European Union. Insofar as a third country transfer occurs in individual cases, the transfer is based on the adequacy decision for EU-US data transfers, the Data Privacy Framework. AWS is certified under the Data Privacy Framework.

The legal basis for processing is Art. 6(1)(1)(f) GDPR (legitimate interest in the security of the platform and compliance with our Terms of Use, as well as protecting users from illegal and inappropriate content).

9. Location data

We use location data to show you profiles and events tailored to your location. You can allow or revoke this function at any time in the settings of the mobile app or your operating system. Otherwise, your location is only transmitted to us when you use functions in the app that we can only offer if we know your location, or when it is necessary for the app to function. For location determination and pre-filling of the telephone number country codes, we use the services of MaxMind Inc., 51 Pleasant Street #1020, Malden, MA 02148. MaxMind is certified under the Data Privacy Framework. The third-country transfer is based on the adequacy decision. Further information: https://www.maxmind.com/en/privacy-policy

The legal basis for processing is Art. 6(1)(1)(a) GDPR (consent).

10. Matching algorithm

Our services use a matching algorithm to display suitable profiles and events. Users are assigned a value between 0 and 100 based on activity/recency, distance, profile quality, overlaps, new users, and premium boosts, where 100 means a high presumed match. The value determines the order in which profiles are displayed. A higher score means that a profile is more likely to match your preferences. This serves to make your search for suitable partners more effective. The following data is processed here:

  • Profile information and preferences
  • Location data (distance calculation)
  • Activity data and recency
  • Filter settings and “must-have” categories
  • Interactions with other profiles
  • Profiles already seen

The creation of partner suggestions in this way constitutes a form of scoring within the meaning of Art. 4(4) GDPR. The partner suggestions have no legal effect or similarly significant legal impairment within the meaning of Art. 22 GDPR. You can also influence the matching via your profile settings and filter settings.

The legal basis for processing is Art. 6(1)(1)(a) GDPR (consent). You can revoke your consent at any time with effect for the future. After revocation, you will continue to receive partner suggestions based on distance; however, these will otherwise no longer be personalized to your preferences. Your personal data will likewise no longer be processed in order to suggest your profile to other users in a personalized way. The legal basis for this processing is Art. 6(1)(1)(b) GDPR.

11. Chat function

Our chat functionality enables the direct exchange of messages with other users. This involves processing data such as message content, voice messages and image messages, send and receive timestamps, read receipts, online status, and chat metadata. Messages are encrypted in transit (TLS) and encrypted at rest. Messages are not end-to-end encrypted, as this is necessary to enable content moderation and to ensure the safety of our community.

The legal basis for processing is Art. 6(1)(1)(b) GDPR (contract performance).

12. Voice and video calls

You can make voice and video calls with other users via our service. We process personal data such as call metadata, call status, and presence data. The audio and video data are transmitted directly between the users’ devices.

The legal basis for processing is Art. 6(1)(1)(b) GDPR (contract performance) as well as Art. 6(1)(1)(a) GDPR (consent to the use of camera and microphone).

13. Push notifications

We send you push notifications to inform you about new matches, incoming messages, or other activities relating to your profile. For this purpose, we process your device tokens and notification settings. To deliver push notifications, we use Expo, a service provided by 650 Industries, Inc., P.O. Box #205, Burlingame, CA 94011, USA. Expo in turn uses Firebase Cloud Messaging (FCM, Google) for Android and the Apple Push Notification service (APNs) for iOS as sub-processors. Expo is certified under the EU-US Data Privacy Framework; any third-country transfer is based on the adequacy decision. Further information: https://expo.dev/privacy The legal basis is Art. 6(1)(1)(a) GDPR (consent). You can revoke your consent at any time with effect for the future.

The legal basis is Art. 6(1)(1)(a) GDPR (consent). You can revoke your consent at any time with effect for the future.

14. Reporting function

We offer a reporting function so that content and other users can be reported. We process the reason for the report and the report content, the reported content and users, and any contact details provided.

The legal basis is Art. 6(1)(1)(c) GDPR (legal obligation under the Digital Services Act) as well as Art. 6(1)(1)(f) GDPR (legitimate interest in the security of the platform).

15. Features and payment service providers

We offer various features, such as virtual gifts or premium subscriptions, which can be used optionally. We process transaction details and billing data here.

We use the following payment service providers:

  • Apple In-App Purchase, Apple Inc., One Apple Park Way, Cupertino, CA 95014, USA. For users in the EU or EEA, Apple Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, is responsible.
  • Google Play Billing, Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA. For users in the EU or EEA, Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, is responsible.

The selected payment service receives the information you provide as part of the payment. This usually includes your name, your payment data, the order number, and the transaction amount, as well as any additional information depending on the provider. For data processing as part of payment processing, the respective payment service provider is the responsible party.

The legal basis for processing is Art. 6(1)(1)(b) GDPR (pre-contractual measure, contract performance) as well as Art. 6(1)(1)(c) GDPR (statutory retention obligations). We ourselves receive information so that we can record, confirm, and execute your order via our platform. Your data is stored by us until the payment processing is complete and in compliance with any statutory retention obligations. This also includes the period required for processing refunds, receivables management, and fraud prevention.

16. Other integration of third-party services and content

It may happen that third-party content and services are integrated or loaded within our offering. With regard to our website, this always requires that the providers of this content perceive the users’ IP address, as they could not send the content to the respective user’s browser without it. We endeavor to use only content whose respective providers use the IP address solely for delivering the content.

Content Management System (WordPress)

Our website is operated with the WordPress content management system, developed by Automattic Inc., 60 29th Street #343, San Francisco, CA 94110, USA (https://wordpress.org). The processing of personal data takes place locally on our servers at our hosting provider. No personal data is transmitted directly to Automattic Inc. unless this is required by the use of certain WordPress plugins. The legal basis is Art. 6(1)(1)(f) GDPR (legitimate interest in the efficient management and provision of our website content).

Google Analytics

This website uses functions of the web analysis service Google Analytics. The provider is Google Ireland Limited (“Google”), Gordon House, Barrow Street, Dublin 4, Ireland. Google Analytics uses technologies that enable the recognition of users for the purpose of analyzing user behavior (e.g., cookies or device fingerprinting). IP anonymization is activated, so that your IP address is truncated within the EU/EEA before further processing. Google is certified under the Data Privacy Framework, and any third-country transfers are based on the adequacy decision.

The legal basis is Art. 6(1)(1)(a) GDPR (consent) and § 25(1) TDDDG. You can revoke your consent at any time via our consent management tool. Further information can be found in Google’s privacy policy: https://policies.google.com/privacy

Google Tag Manager

We use the Google Tag Manager, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. The Google Tag Manager enables us to manage website tags via an interface. The legal basis is Art. 6(1)(1)(a) GDPR (consent). You can revoke your consent at any time via our consent management tool. Further information can be found in Google’s privacy policy: https://policies.google.com/privacy

Content Delivery Network (CDN)

We use the Content Delivery Network (CDN) of Cloudflare, Inc., 101 Townsend St, San Francisco, CA 94107, USA (https://www.cloudflare.com). A content delivery network is a network of regionally distributed servers connected via the internet, used to deliver content, in particular media files, scripts, and stylesheets. This allows us to display our content faster and more reliably on our website and to optimize the user experience. The following categories of data are processed: IP address, timestamp, time and date, user agent, visited website, amount of data transferred. Legal basis: Art. 6(1)(1)(f) GDPR (legitimate interest in a performant provision of the website). The data transfer to the US is based on the EU-US Data Privacy Framework (https://www.dataprivacyframework.gov). Further information can be found in Cloudflare’s privacy policy: https://www.cloudflare.com/privacypolicy/.

Social media and other platforms

We use social media platforms to safeguard our legitimate interest in presenting and promoting our services and products there, Art. 6(1)(1)(f) GDPR. You can find the legal bases for the data processing of the respective social media platform providers in the privacy notices linked below:

When you click on a social media icon on our site, you leave our website or app and a connection is established with these third-party providers. Please note that data may be processed outside the European Union in this context. If you wish to exercise your data subject rights, it is most effective to assert these with the respective platform provider. However, if you wish to exercise rights in relation to our profiles, you can of course also contact us.

III. Recipients of personal data and third-country transfers

Personal data is disclosed to the following categories of recipients:

Our employees and our processors to the extent necessary, in particular the website and hosting provider of our website, Amazon Web Services (AWS), and, where applicable, its respective sub-processors, depending on the service you use, as well as, when using the service, individually named service providers, see above under II. In addition, we use Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA, as a content delivery network and for security purposes; the data transfer to the US is based on the standard contractual clauses of the European Commission.

Beyond this, the personal data concerning you will not be passed on to third parties without your express consent, unless we are legally obligated to do so or the data transfer is absolutely necessary for the performance of a contractual relationship.

A third-country transfer is generally not intended, but see above. A third-country transfer may be considered when using the following services: Apple, Google, Expo, MaxMind, Amazon Web Services, Cloudflare, see above under II.

This may give rise to risks because, for example, the enforcement of your rights could be made more difficult, particularly in the US due to differing data protection standards. The data transfer is based on the EU-US Data Privacy Framework or standard contractual clauses, as described for the respective services. Service providers who process personal data on our behalf in a third country are only used if an “adequacy decision” of the European Commission (Art. 45 GDPR) exists, “appropriate safeguards” (Art. 46 GDPR) or “standard data protection clauses” (Art. 46(2)(c) GDPR) have been agreed, and/or “binding corporate rules” (Art. 47 GDPR) exist at the recipient.

IV. Duration of storage

We delete personal data once the purpose has been achieved and the legal basis no longer applies, and in the absence of a retention obligation.

Stored server log files and IP addresses are automatically deleted by our host after 7 days.

Session cookies are also automatically deleted after the end of the session. In addition, cookies with an expiry date are stored on your device, and you also have control over the use and deletion of cookies (see above).

Personal data from your inquiries via email, contact form, or by other means will be processed until your inquiry has been fully processed and completed. The data will then be deleted if there is no legal retention obligation. Please note that, due to a legal transaction with you, commercial and tax law retention obligations of at least six (§ 257 HGB) or ten (§ 147 AO) years may apply to certain data.

Personal data from the verification process will be deleted after completion of the verification, unless a retention obligation exists.

If you delete your account, your associated personal data (profile data, location data, preferences and filter settings, device token) will be deleted. Otherwise, the following applies:

  • Chat messages and interactions are anonymized: a so-called “tombstone entry” (e.g., “deleted user”) is retained for the deleted account, which no longer contains any personal data. Identifying features are removed from messages.
  • Data from transactions (e.g., billing data) are stored in accordance with statutory retention obligations (§ 257 HGB, § 147 AO) for six to ten years and then deleted, unless there is another legal basis (e.g., consent).

Data may also be retained insofar as this is necessary for the assertion, exercise, or defense of legal claims. Otherwise, we check on an annual basis whether data can be deleted.

V. Provision of personal data and rights of data subjects

You are not legally obliged to provide personal data. However, the provision may be necessary for concluding a contract or for functions of the service. If not provided, a contract or function may not be able to be offered.

Fully automated decisions: In the case of the optional AI-supported identity verification, the artificial intelligence can automatically approve or flag for human review, but never automatically reject. You have the right and the option to directly request a human review.

The rights of data subjects arise in particular from Art. 15 to 23 and Art. 77 GDPR as well as from §§ 32 to 37 of the new German Federal Data Protection Act (BDSG).

With regard to the personal data concerning you, you have the right, subject to the statutory requirements, to:

  • Access, Art. 15 GDPR,
  • Rectification, Art. 16 GDPR,
  • Erasure, Art. 17 GDPR,
  • Restriction of processing, Art. 18 GDPR,
  • Data portability, Art. 20 GDPR.

If you have given consent to the processing of personal data, you have the right of revocation, Art. 7 GDPR, with effect for the future. The lawfulness of the processing carried out on the basis of the consent until revocation remains unaffected.

You also have the right to object, Art. 21 GDPR, to the processing of personal data; see further information under VI.

Please direct all inquiries, requests, and communications to us; see above under I.

If you believe that the processing of the personal data concerning you violates data protection law, you always have the right to lodge a complaint with the competent supervisory authority, cf. Art. 77 GDPR. The supervisory authority responsible for us is: Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2-4, 40213 Düsseldorf, https://www.ldi.nrw.de.

VI. Information about the right to object under Art. 21 GDPR

1. You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you which is carried out on the basis of Art. 6(1)(1)(f) GDPR (data processing based on a balancing of interests). If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing serves the assertion, exercise, or defense of legal claims.

2. If personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of data concerning you for such marketing. If you object to processing for direct marketing purposes, we will no longer process your personal data for these purposes.

The objection can be made in any form and should preferably be addressed to us; see above under I.