Privacy Policy
Effective date: 19 August 2026
This Privacy Policy explains how Magic Moments ("we", "us", "our") collects, uses, stores, and shares personal information when you use the Magic Moments mobile application and related services (the "Service"). Magic Moments is a location-aware social app for meeting people nearby. The Service is for adults only (18+).
1. Data We Collect
- Account & identity: email address, password (stored only as a hash), name, and date of birth (used to verify you are 18+ and for age-based matching), plus your app language.
- Profile & preferences: bio; gender identity; who you are interested in; dating intention; relationship style; lifestyle details (smoking, drinking, activity level, pets); interests; languages; and your preferred age range. You control whether some of these are shown on your profile.
- Photos, video & audio: profile photos, short profile videos, and voice recordings you send as Whispers or in chat, plus a verification selfie if you choose to get verified.
- Location data: your device location, used to show you people and events nearby. See section 7.
- Social & interaction data: your likes/passes, matches, conversations (text, image, video and voice messages), Whisper threads, profiles you viewed and who viewed you, and event participation and check-ins.
- Purchases: records of in-app purchases of "hearts", your heart transaction history, and your subscription/boost status. Payments are handled by Apple or Google — we receive purchase receipts, not your payment-card details.
- Device & technical data: push-notification token, device platform, and app diagnostics / error reports.
- Safety & moderation data: reports you file or that concern you (including any evidence images), blocks, and moderation decisions.
- Logs & security: authentication tokens and security logs. We record the IP address and device/browser identifier (user-agent) when you upload a photo, video or voice recording, and for administrative actions on our systems. Upload records are kept only as long as the media itself, unless the law requires us to preserve them (see section 9).
2. Special-Category Data
Some information you may add to your profile — in particular who you are interested in (which can reveal your sexual orientation), and lifestyle details — is treated as special-category data. We process it only where you have chosen to provide it, to operate the matching features you request. You can edit or remove this information at any time, and you can hide gender identity, dating intention, and lifestyle from your profile using the visibility toggles in the app.
3. Why We Use Data
- Provide the core features — nearby discovery, Whisper, matching, chat, events, and notifications.
- Authenticate you and keep accounts secure.
- Deliver location-aware experiences and compatibility-based matching.
- Process purchases of hearts and manage subscriptions and boosts.
- Keep the community safe — verification, moderation, and preventing abuse, fraud and harassment.
- Send you service and, where you allow it, marketing or re-engagement notifications.
- Comply with legal obligations and enforce our Terms.
4. Legal Bases (EEA/UK)
- Contract: to provide the Service you sign up for.
- Consent: for precise location, push notifications, marketing messages, and special-category profile data.
- Legitimate interests: security, moderation, fraud prevention and product integrity.
- Legal obligation: regulatory compliance and lawful requests.
5. Sharing of Data & Service Providers
We do not sell your personal data. We share it only as needed to run the Service. The processors below act on our instructions under data processing agreements:
| Provider | Purpose | Data | Region |
|---|---|---|---|
| Fly.io | Application hosting | All data in transit through the app | Frankfurt, Germany |
| Neon | Database | Account, profile, matches, messages, location | EU (Frankfurt) |
| Cloudflare R2 | Media storage | Photos, videos, audio, verification selfies | European Union |
| Cloudflare | DNS, CDN, security/WAF | Connection metadata, IP addresses | Global edge |
| Upstash | Cache & job queues | Session and queue data, transient | EU (Frankfurt) |
| Amazon Web Services | Automated content moderation (Rekognition) | Images and sampled video frames you upload | Frankfurt, Germany |
| Microsoft | Detection of known child sexual abuse material (PhotoDNA) | No images. Only an irreversible numeric fingerprint (“hash”) computed on our own servers | European Union |
| Resend | Email delivery | Email address, message content | EU (Ireland) |
| Sentry | Error monitoring | Diagnostics, error reports | European Union |
| Expo | Push notifications | Push token, notification content | See transfers below |
| Apple, Google | In-app purchases, push delivery | Purchase receipts, push token | Global |
We also share data with other users — only what a feature requires, such as your profile to people nearby or your messages within a match — and with authorities where required by law or to protect users.
Location and matching run on our own infrastructure using PostGIS. We do not send your location to a third-party mapping service, and your media is stored privately and served only through short-lived links.
6. International Transfers
We host the Service in the European Union: the application runs in Frankfurt, and the database, media storage, caching, email delivery, error monitoring and automated moderation are all EU-region. Your profile, messages, media, email and location data therefore stay within the EU in normal operation.
The exceptions are push notifications and in-app purchases, which necessarily involve Apple, Google and Expo, and Cloudflare's globally distributed edge network. Where those transfers occur we rely on appropriate safeguards, principally the European Commission's standard contractual clauses.
7. Location Data
- Collection: we collect your device location to find people and events near you and to calculate distances.
- What others see: your exact position is never shown to other users. On the map your location is deliberately blurred by a random offset, and elsewhere only an approximate distance is shown.
- Background use: if you enable it, background location is used only to auto check-in when you arrive at an event. You can turn location off at any time in your device settings; some features will then be unavailable.
8. Data Retention
We keep your personal data while your account is active and as needed to provide the Service. When you delete your account, we delete your account, profile, media, matches, chats, whispers and related personal data.
Beyond that, an automated job runs nightly and enforces the periods below. Data older than its period is deleted permanently and cannot be recovered.
| Data | Retention |
|---|---|
| Account, profile and profile media | While your account exists |
| Messages in an active match | While you remain matched |
| Messages after you unmatch | 30 days, then the conversation and its media are deleted |
| Your last known location | Deleted after 90 days of inactivity |
| Notifications | 90 days |
| Usage and analytics events, profile views | 90 days |
| Expired magic moments | 90 days |
| Expired login and verification tokens | 30 days after expiry |
| Reports, moderation decisions and related evidence | Up to 12 months, longer where an investigation or the law requires |
| Administrative security logs | 24 months |
| Purchase and heart-transaction records | Up to 10 years, as Austrian tax and accounting law requires |
Two things we deliberately keep. If you unmatch someone, we retain a minimal record that the two of you were matched — with no message content — so that person is not shown to you again. Blocks are kept permanently for the same reason. We also keep anonymous, aggregated statistics (such as daily active-user counts) that cannot be linked back to you.
9. Content Moderation, Illegal Content and Appeals
Automated moderation. Photos and videos you upload are scanned automatically before they become visible, using Amazon Rekognition. Media identified as containing explicit nudity or sexual activity is rejected and never shown to other users; borderline results are held for a human to review. This is an automated decision that affects whether your content appears, so you always have the right to ask a person to review it — see appeals below. Audio is not scanned automatically.
Detection of child sexual abuse material. Separately, every photo and video is checked against a database of known child sexual abuse imagery using Microsoft PhotoDNA. The check works on an irreversible numeric fingerprint of the image, computed on our own servers — the image itself is never sent to Microsoft, and the fingerprint cannot be turned back into a picture. We do this to comply with our legal obligations and to protect children.
If content matches, we preserve it and the associated account records as evidence, suspend the account, and report to the competent authorities. In those cases we cannot always tell you what has happened or why, because doing so could obstruct the investigation of a serious crime — the Digital Services Act permits this exception to the explanation we would otherwise owe you.
Reporting illegal content. You can report a profile, message or piece of content from within the app, or email [email protected]. We confirm receipt, review the report, and tell you the outcome.
If we act against your content or account, we will tell you what we did, why, and whether the decision was reached automatically or by a person.
Appeals. If you believe a decision was wrong, reply to the notice or email [email protected] within six months, describing what was removed and why you disagree. A person who was not involved in the original decision will review it, and we will tell you the result. You may also refer the matter to an out-of-court dispute settlement body, or to a court, under Article 21 of the Digital Services Act.
Point of contact. For users and for authorities under Articles 11 and 12 of the Digital Services Act, our single point of contact is [email protected]. We accept communication in English and German.
10. Your Rights
Depending on your jurisdiction, you may have rights to:
- Access, correct, delete, or export your data (the app offers a data export).
- Restrict or object to certain processing.
- Withdraw consent where processing relies on consent.
- File a complaint with a supervisory authority.
11. How to Delete Your Data
You can delete your account and data at any time in the app (Profile → Delete account), through our web deletion form, or by emailing [email protected] from your account email address.
12. Children
The Service is intended only for adults (18+). We do not knowingly allow anyone under 18 to create an account, and age is checked at sign-up.
13. Security
We apply technical and organizational safeguards, including encryption in transit, hashed passwords, private media storage accessed only through time-limited links, access controls, and abuse-prevention and moderation systems. No system is 100% secure.
14. App Permissions (Mobile)
- Location (foreground, and optional background): nearby discovery and event auto check-in.
- Camera & photos: profile photos/videos and verification selfies.
- Microphone: voice Whispers and voice messages.
- Notifications: matches, messages, whispers, nearby moments, events and safety updates.
15. Contact
Privacy inquiries: [email protected]
Controller: rockNdevel GmbH, Webgasse 29/24, 1060 Vienna, Austria. See our Legal Notice for full company details.
16. Changes to This Policy
We may update this policy. We will revise the effective date and provide in-app or website notice where required.