Privacy Policy
1. Introduction
Rated Dating LLC (“Company,” “we,” “us,” or “our”) operates the Rated mobile application and website at ratedapp.com (collectively, the “Service”). Rated is an AI-powered facial scoring and self-discovery platform — not a traditional matchmaking or messaging service. This Privacy Policy explains how we collect, use, disclose, and protect your information.
Critical Notice — Biometric and Facial Data
Rated’s core feature analyzes your facial photographs using artificial intelligence. This constitutes collection and processing of biometric identifiers and biometric information under the laws of multiple U.S. states and international jurisdictions. Please read this entire Policy before submitting any image or using the scoring feature.
By accessing or using the Service, you acknowledge you have read, understood, and agreed to the practices described here. If you do not agree, do not use the Service.
2. What Information We Collect
2.1 Biometric Data and Facial Images
When you use our AI scoring feature, we collect:
- Facial photographs you submit through the app or website
- Facial geometry and biometric measurements derived from your images (nodal points, facial proportions, spatial feature relationships)
- AI-generated scores, ratings, and self-discovery insights derived from your facial data
- Metadata associated with submitted images (timestamp, submission method)
These constitute biometric identifiers and biometric information as defined under applicable law, including the Illinois Biometric Information Privacy Act (BIPA), Texas Capture or Use of Biometric Identifier Act (CUBI), and the biometric provisions of comprehensive privacy laws enacted in 20+ U.S. states as of 2026.
We do not use facial images or biometric data to infer race, ethnicity, religion, political views, sexual orientation, or any other protected characteristic. Our scoring is limited to aesthetic and compositional facial analysis you explicitly request.
2.2 Account and Identity Information
- Full name or display name
- Email address
- Phone number (used to link web purchases to in-app unlocks — see Section 3.2)
- Date of birth (to verify you are 18 years of age or older, and to comply with applicable age verification laws)
- Password (stored using one-way cryptographic hashing — never stored in plain text)
- Profile settings and preferences
2.3 Payment and Transaction Data
- Purchase history and order IDs
- Payment method type (card brand, last four digits) — we do not store full card numbers, CVVs, or bank account details
- Shopify checkout data for purchases made at ratedapp.com
- Apple App Store in-app purchase receipts and transaction identifiers
- Google Play in-app purchase receipts and transaction identifiers
- Phone number used to match web purchases to your in-app account and unlock features
2.4 Device, Technical, and Usage Data
- Device type, manufacturer, model, and operating system version
- IP address and coarse geolocation (city/region — not precise GPS location unless you grant permission)
- Mobile advertising identifiers (IDFA, GAID) where permitted by your device settings
- App version, session duration, features accessed, crash reports, and diagnostic logs
- Push notification tokens
2.5 Communications
- Messages and attachments you send to our support team
- Feedback, survey responses, and app store reviews you direct to us
- Records of your consent and opt-in/opt-out preferences
2.6 Information from Third-Party Sign-In
If you sign in using Apple ID or Google, we receive only your name and email address. We never receive your Apple or Google account passwords.
3. How We Use Your Information
3.1 Providing and Delivering the Service
- Analyze your facial images and generate AI-based scores and self-discovery insights
- Create and manage your account
- Deliver features, content, and unlocks you have purchased
- Display your scoring history and saved results within your account
3.2 Purchase Linking — Phone Number
We use your phone number as a linking identifier to connect purchases made through Shopify on ratedapp.com to your in-app account, triggering feature unlocks across our web and mobile platforms. This linking is a core function of the Service.
3.3 Safety, Security, and Fraud Prevention
- Verify that users are 18 years of age or older
- Detect and prevent unauthorized access, fraud, abuse, and violations of our Terms
- Comply with obligations under Google Play’s Child Safety Standards and Apple’s App Store Review Guidelines
- Report child sexual abuse material (CSAM) to the National Center for Missing & Exploited Children (NCMEC) as required by 18 U.S.C. § 2258A
3.4 Communications
- Send transactional messages (receipts, account alerts, security notifications, unlock confirmations)
- Respond to your support and legal requests
- Send marketing communications only if you have opted in — opt out at any time (see Section 10)
3.5 SMS / Text Messaging
We use your mobile phone number to send one-time passcodes (OTP) for account verification. Mobile opt-in data and your phone number will not be shared with third parties or affiliates for marketing or promotional purposes. For full details including message frequency, data rates, opt-out instructions, and carrier liability, see our dedicated SMS Messaging Policy.
3.6 Legal Compliance
- Comply with applicable laws, regulations, court orders, and lawful governmental requests
- Enforce our Terms and Conditions
- Establish, exercise, or defend legal claims
3.7 Service Improvement
- Use aggregated, de-identified, and anonymized data to understand usage patterns and improve the Service
- Debug and resolve technical issues
4. How We Share Your Information
We do not sell your personal information or biometric data. We do not share for cross-context behavioral advertising. We share only as described below.
4.1 AI Processing Partner — OpenAI
Our facial scoring feature is powered by OpenAI’s API. When you submit an image for scoring:
- Your image is transmitted over an encrypted TLS connection to OpenAI’s servers for real-time processing
- OpenAI processes your image under their API Data Processing Addendum; they are contractually prohibited from using API inputs to train their general-purpose models
- We have a Data Processing Agreement (DPA) with OpenAI governing this processing
- OpenAI’s privacy practices are available at openai.com/privacy
4.2 Payment Processors
We do not receive or store full payment card numbers from any of these processors.
4.3 Service Providers (Processors)
We engage vetted vendors under confidentiality and data processing agreements, including:
- Cloud hosting and infrastructure providers
- Customer support and ticketing platforms
- Analytics providers (using de-identified data only)
- Email and SMS delivery services
- Security monitoring and fraud detection services
These vendors may only process your data as directed by us and for the purposes described in this Policy.
4.4 Business Transfers
If Rated Dating LLC is involved in a merger, acquisition, asset sale, or restructuring, your information may transfer to the successor entity. We will notify you by email and/or in-app notice at least 30 days before any such transfer, and the successor will be bound by the terms of this Policy or a materially equivalent policy.
4.5 Legal Disclosures
We may disclose your information when required by law, legal process, or governmental authority, or when we believe in good faith that disclosure is necessary to: (a) comply with a legal obligation; (b) protect our rights or property; (c) prevent imminent harm; or (d) protect the safety of users or the public.
4.6 CSAM Reporting
We are required by federal law (18 U.S.C. § 2258A) to report any apparent child sexual abuse material to NCMEC. We cooperate fully with law enforcement in any related investigation.
5. Biometric Data — Enhanced Protections
5.1 Explicit Consent
We obtain your explicit, informed consent before processing your biometric data. You provide this consent each time you submit an image using the scoring feature. You may withdraw consent at any time by deleting your account (Section 10.3).
5.2 No Sale or Profit from Biometric Data
We never sell, lease, trade, or otherwise profit from your biometric identifiers or biometric information. No biometric data is disclosed to any third party except to OpenAI for real-time scoring delivery, and to law enforcement or regulatory authorities as required by law.
5.3 Storage Limitations
- Raw facial images submitted for scoring are transmitted to OpenAI for real-time processing and are not stored on our servers long-term beyond the duration required to complete the transaction, except where you explicitly save results to your profile
- Derived scores and insights (which do not contain your raw image) are stored in your account until you delete them or your account
- Maximum retention for biometric identifiers: 3 years from your last interaction with the Service, or sooner as required by applicable law
5.4 Security Measures for Biometric Data
- All biometric data is encrypted in transit using TLS 1.2 or higher
- Stored biometric-derived data is encrypted at rest using AES-256 or equivalent
- Access to biometric data is restricted to personnel with a documented business need
- We conduct regular security assessments of systems that process biometric data
5.5 U.S. State Biometric Rights
As of June 2026, 20+ U.S. states have comprehensive privacy laws that treat biometric data as sensitive personal information. The most protective state law applicable to you may govern your rights.
Illinois (BIPA — 740 ILCS 14): You have the right to receive written notice of biometric data collection (this Policy constitutes such notice); receive a written policy on retention and destruction (Section 5.3); prevent sale of your biometric data; and bring a private right of action for violations.
Texas (CUBI — Tex. Bus. & Com. Code § 503.001): We have obtained your consent prior to collection and will not sell your biometric identifiers.
Washington, Maryland, Connecticut: We comply with applicable biometric privacy requirements and do not sell biometric data.
California (CCPA/CPRA): Biometric data is “sensitive personal information” under California law. Your rights are detailed in Section 11.
All other states: We extend the core protections of this Section (notice, consent, no sale, retention limits, deletion rights) to all users regardless of state of residence, as a matter of Company policy.
6. EU AI Act Compliance (EEA, UK, and International Users)
6.1 Our AI System Classification
We have assessed our AI scoring system against EU AI Act requirements. Our system:
- Does not constitute a prohibited biometric categorization system, as it does not infer or categorize users based on race, ethnicity, political opinions, religious beliefs, trade union membership, sexual orientation, or other protected sensitive attributes
- Does not constitute a real-time remote biometric identification system
- Is not an emotion recognition system
- Is used only at the explicit request of the user, with informed consent, for personal self-discovery purposes
6.2 GDPR Compliance (EEA, UK, Switzerland)
If you are located in the European Economic Area, United Kingdom, or Switzerland, the following applies in addition to the rest of this Policy.
Your GDPR Rights: Access, rectification, erasure, restriction of processing, data portability, objection to legitimate-interest processing, and withdrawal of consent at any time without affecting prior lawful processing.
Data Transfers: Your data may be transferred to the United States. We rely on Standard Contractual Clauses (SCCs, 2021 Commission Decision) as our transfer mechanism.
Supervisory Authority: You have the right to lodge a complaint with your local EU/EEA/UK data protection supervisory authority.
7. Data Retention
8. Children’s Privacy and Age Verification
The Service is exclusively for users 18 years of age or older. We do not knowingly collect personal information from anyone under 18. If we discover that a user under 18 has created an account or submitted images, we will immediately delete all associated data and terminate the account. If you believe a minor has accessed the Service, contact us immediately at safety@ratedapp.com.
9. Cookies and Tracking
Our website (ratedapp.com) uses cookies and similar technologies for session management, Shopify checkout functionality, site analytics, and remembering your preferences. You can control cookies through your browser settings. For full details, see our Cookie Policy.
10. Your Rights and Choices
10.1 Access and Portability
Request a copy of your personal data: email privacy@ratedapp.com with subject “Data Access Request.” We will respond within 45 days and provide data in a commonly used, portable format.
10.2 Correction
Update most account information directly in app settings. For data you cannot update yourself, contact us.
10.3 Deletion
Delete your account in app settings (Account › Delete Account). Upon deletion: account and profile data are deleted within 30 days; stored facial images and biometric-derived data are deleted within 30 days; transaction records are retained 7 years for legal compliance.
10.4 Opt-Out of Marketing
Opt out via the unsubscribe link in any marketing email, notification settings in the app, or by emailing privacy@ratedapp.com. This does not affect transactional communications.
10.5 Withdraw Biometric Consent
Withdrawing consent for biometric processing means you will no longer be able to use the AI scoring feature. To withdraw, delete your account or contact privacy@ratedapp.com.
11. California Residents — CCPA/CPRA
11.1 Categories Collected (Past 12 Months)
- Identifiers (name, email, phone number, IP address, device IDs)
- Biometric information (facial images, geometry, AI scores) — Sensitive Personal Information
- Commercial information (purchase history, unlocks)
- Internet/electronic activity (app usage, features accessed)
- Inferences (self-discovery scores and insights)
11.2 Your Rights
- Right to Know what we collect, use, and disclose
- Right to Delete personal information, subject to legal exceptions
- Right to Correct inaccurate personal information
- Right to Opt-Out of Sale or Sharing — we do not sell or share for cross-context behavioral advertising
- Right to Limit Use of Sensitive Personal Information — you may limit processing of biometric data to what is necessary to deliver the Service
- Right to Non-Discrimination — we will not discriminate against you for exercising CCPA/CPRA rights
11.3 Submitting Requests
Contact: privacy@ratedapp.com — Subject line: “CCPA Rights Request.” We will verify your identity and respond within 45 calendar days.
12. Security
We implement administrative, technical, and physical safeguards including:
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption for sensitive data at rest
- Role-based access controls
- Multi-factor authentication for administrative access to production systems
- Regular penetration testing and vulnerability assessments
- Incident response plan with breach notification procedures
13. Contact Us
14. Changes to This Policy
When we update this Policy, we will update the “Last Updated” date and notify you via email and/or prominent in-app notice at least 30 days before material changes take effect. For changes to biometric data processing, we will obtain fresh explicit consent before applying new practices.