Privacy Policy

Effective date: 19 August 2026

This Privacy Policy explains how Magic Moments ("we", "us", "our") collects, uses, stores, and shares personal information when you use the Magic Moments mobile application and related services (the "Service"). Magic Moments is a location-aware social app for meeting people nearby. The Service is for adults only (18+).

1. Data We Collect

2. Special-Category Data

Some information you may add to your profile — in particular who you are interested in (which can reveal your sexual orientation), and lifestyle details — is treated as special-category data. We process it only where you have chosen to provide it, to operate the matching features you request. You can edit or remove this information at any time, and you can hide gender identity, dating intention, and lifestyle from your profile using the visibility toggles in the app.

3. Why We Use Data

4. Legal Bases (EEA/UK)

5. Sharing of Data & Service Providers

We do not sell your personal data. We share it only as needed to run the Service. The processors below act on our instructions under data processing agreements:

ProviderPurposeDataRegion
Fly.ioApplication hostingAll data in transit through the appFrankfurt, Germany
NeonDatabaseAccount, profile, matches, messages, locationEU (Frankfurt)
Cloudflare R2Media storagePhotos, videos, audio, verification selfiesEuropean Union
CloudflareDNS, CDN, security/WAFConnection metadata, IP addressesGlobal edge
UpstashCache & job queuesSession and queue data, transientEU (Frankfurt)
Amazon Web ServicesAutomated content moderation (Rekognition)Images and sampled video frames you uploadFrankfurt, Germany
MicrosoftDetection of known child sexual abuse material (PhotoDNA)No images. Only an irreversible numeric fingerprint (“hash”) computed on our own serversEuropean Union
ResendEmail deliveryEmail address, message contentEU (Ireland)
SentryError monitoringDiagnostics, error reportsEuropean Union
ExpoPush notificationsPush token, notification contentSee transfers below
Apple, GoogleIn-app purchases, push deliveryPurchase receipts, push tokenGlobal

We also share data with other users — only what a feature requires, such as your profile to people nearby or your messages within a match — and with authorities where required by law or to protect users.

Location and matching run on our own infrastructure using PostGIS. We do not send your location to a third-party mapping service, and your media is stored privately and served only through short-lived links.

6. International Transfers

We host the Service in the European Union: the application runs in Frankfurt, and the database, media storage, caching, email delivery, error monitoring and automated moderation are all EU-region. Your profile, messages, media, email and location data therefore stay within the EU in normal operation.

The exceptions are push notifications and in-app purchases, which necessarily involve Apple, Google and Expo, and Cloudflare's globally distributed edge network. Where those transfers occur we rely on appropriate safeguards, principally the European Commission's standard contractual clauses.

7. Location Data

8. Data Retention

We keep your personal data while your account is active and as needed to provide the Service. When you delete your account, we delete your account, profile, media, matches, chats, whispers and related personal data.

Beyond that, an automated job runs nightly and enforces the periods below. Data older than its period is deleted permanently and cannot be recovered.

DataRetention
Account, profile and profile mediaWhile your account exists
Messages in an active matchWhile you remain matched
Messages after you unmatch30 days, then the conversation and its media are deleted
Your last known locationDeleted after 90 days of inactivity
Notifications90 days
Usage and analytics events, profile views90 days
Expired magic moments90 days
Expired login and verification tokens30 days after expiry
Reports, moderation decisions and related evidenceUp to 12 months, longer where an investigation or the law requires
Administrative security logs24 months
Purchase and heart-transaction recordsUp to 10 years, as Austrian tax and accounting law requires

Two things we deliberately keep. If you unmatch someone, we retain a minimal record that the two of you were matched — with no message content — so that person is not shown to you again. Blocks are kept permanently for the same reason. We also keep anonymous, aggregated statistics (such as daily active-user counts) that cannot be linked back to you.

9. Content Moderation, Illegal Content and Appeals

Automated moderation. Photos and videos you upload are scanned automatically before they become visible, using Amazon Rekognition. Media identified as containing explicit nudity or sexual activity is rejected and never shown to other users; borderline results are held for a human to review. This is an automated decision that affects whether your content appears, so you always have the right to ask a person to review it — see appeals below. Audio is not scanned automatically.

Detection of child sexual abuse material. Separately, every photo and video is checked against a database of known child sexual abuse imagery using Microsoft PhotoDNA. The check works on an irreversible numeric fingerprint of the image, computed on our own servers — the image itself is never sent to Microsoft, and the fingerprint cannot be turned back into a picture. We do this to comply with our legal obligations and to protect children.

If content matches, we preserve it and the associated account records as evidence, suspend the account, and report to the competent authorities. In those cases we cannot always tell you what has happened or why, because doing so could obstruct the investigation of a serious crime — the Digital Services Act permits this exception to the explanation we would otherwise owe you.

Reporting illegal content. You can report a profile, message or piece of content from within the app, or email [email protected]. We confirm receipt, review the report, and tell you the outcome.

If we act against your content or account, we will tell you what we did, why, and whether the decision was reached automatically or by a person.

Appeals. If you believe a decision was wrong, reply to the notice or email [email protected] within six months, describing what was removed and why you disagree. A person who was not involved in the original decision will review it, and we will tell you the result. You may also refer the matter to an out-of-court dispute settlement body, or to a court, under Article 21 of the Digital Services Act.

Point of contact. For users and for authorities under Articles 11 and 12 of the Digital Services Act, our single point of contact is [email protected]. We accept communication in English and German.

10. Your Rights

Depending on your jurisdiction, you may have rights to:

11. How to Delete Your Data

You can delete your account and data at any time in the app (Profile → Delete account), through our web deletion form, or by emailing [email protected] from your account email address.

12. Children

The Service is intended only for adults (18+). We do not knowingly allow anyone under 18 to create an account, and age is checked at sign-up.

13. Security

We apply technical and organizational safeguards, including encryption in transit, hashed passwords, private media storage accessed only through time-limited links, access controls, and abuse-prevention and moderation systems. No system is 100% secure.

14. App Permissions (Mobile)

15. Contact

Privacy inquiries: [email protected]

Controller: rockNdevel GmbH, Webgasse 29/24, 1060 Vienna, Austria. See our Legal Notice for full company details.

16. Changes to This Policy

We may update this policy. We will revise the effective date and provide in-app or website notice where required.