Skip to content
twoDate
ENNL
  • How it works
  • The app
  • FAQ
  • Support
Download the app

Our policies

Privacy policy

How twoDate uses your personal data, why it is needed and the choices you have about your account, shared content and optional analytics.

Last updated: 10 September 2026

On this page

    Have a question?

    We're here to help.

    Get in touch

    1. Who is responsible?

    This privacy policy applies to the twoDate app, its API and this website. The controller responsible for processing personal data is:

    twoScript vof
    Osakastraat 10
    3047 AK, Rotterdam
    Nederland

    Chamber of Commerce: 92525989

    For privacy questions or a request about your personal data, email info@twodate.app.

    2. What data do we use?

    You decide which ideas, photos and other content to save. Your name, email address and a password are needed to create an account. Your password is stored as a secure hash.

    Data Purpose and legal basis
    Name, email address, password hash, account ID, verification status and, optionally, date of birth and profile photo Providing and managing your account, verifying your identity for account actions and displaying your profile. Performance of our contract.
    Invitation code, connection and preferences Connecting you to your partner and providing your shared space. Performance of our contract.
    Ideas, titles, descriptions, ratings, schedules, notes, photos and locations you save Saving and displaying your plans and memories. Performance of our contract.
    Sign-in sessions, security tokens, IP addresses and technical logs Securing the service, limiting abuse and resolving faults. Performance of our contract and our legitimate interest in a secure, working service.
    Push token and notification preference Delivering notifications when you allow them. Permission for notifications on your device.
    Usage statistics and technical data through Firebase Analytics Understanding how the app is used, only with your voluntary consent.
    Your email address and the content of a support or privacy request Answering your question, supporting the service and meeting our legal obligations for privacy requests.

    Relationship information and personal notes or photos can be sensitive. We ask you not to include information about health, sexual orientation or other special categories of personal data. Only add data and images you are entitled to share, and respect other people’s privacy.

    3. What can your partner see?

    Once connected, you both have access to your shared ideas, ratings, schedule, memories, photos and saved places. Your partner can see your name and profile photo. Only share your invitation code with the person you want to use this space with.

    The API checks the sign-in session and connection before making private content or photos available. There is no public directory of couples’ profiles. Staff and technical suppliers may need access for support, security or administration. This version does not provide end-to-end encryption.

    4. Photos, location and notifications

    You choose which photo to upload. The app reduces photo sizes before sending them, and the API creates optimised versions. For new uploads, the API removes embedded metadata, including EXIF data. Older files may still contain this data.

    With your permission, you can centre the map on your current location. The app does not send this device location to our API or store it with your account. It does not request background location access. Coordinates you save with a date are stored and shared with your partner.

    Mapbox receives map requests for the visible area and technical connection data when you open maps. Use the information button on the map to see attribution and available privacy settings.

    If you allow notifications, we link a push token to the session on your device. Expo and the push services from Apple or Google use this for notifications about your partner’s ratings. Depending on your device settings, notifications may appear on your lock screen. You can withdraw permission in those settings. Signing out revokes the session link; without internet access, that request follows when the connection is restored.

    5. Optional usage statistics

    Firebase Analytics is off by default on a new installation. Under Profiel > Help twoDate verbeteren (Profile > Help improve twoDate), you can give and withdraw consent. Your choice applies to this app on this device, including after you sign out.

    With consent, we measure fixed screen names, whether an idea is created and whether a rating is saved. Google also receives technical app and device data and a random app installation identifier, and may infer an approximate region. This data is not completely anonymous.

    We do not send account IDs, names, email addresses, titles, notes, photos, scores or saved coordinates to Analytics. Advertising identification and ad personalisation are disabled.

    Turning analytics off stops collection and clears local Analytics data and the installation identifier. This does not delete statistics already sent to Google. Retention period: Two months for user and event data subject to the Analytics retention setting. New activity does not extend this period. Expired data is deleted during monthly processing. This setting does not apply to standard reports with aggregated data..

    6. Who receives data?

    Alongside your connected partner, we use suppliers to operate the service. Where they act as processors on our behalf, processing agreements are required. The relevant services are:

    • Our hosting, storage and email suppliers: twoDate is provided and technically managed by twoScript VOF. Our website, API, database, and uploaded photos are hosted on a server managed by us at vBoxx in the Netherlands. We also send and receive email through our own email system on this server..
    • Mapbox for maps. See Mapbox’s privacy information.
    • Expo, Apple Push Notification service and Google’s Firebase Cloud Messaging for push notifications. See Expo, Apple and Google.
    • Google Analytics for Firebase, only with consent, for the statistics described above. See Firebase and privacy.

    Data may also be disclosed where a legal obligation or an authorised request from a public authority requires it. This version of the twoDate app contains no advertising network.

    7. Processing outside the EEA

    In addition to our own server in the Netherlands, twoDate uses third-party services for maps, push notifications, and voluntary usage statistics. Mapbox provides the maps. Expo, the Apple Push Notification Service, and Google Firebase Cloud Messaging provide push notifications. Google Analytics for Firebase processes usage statistics when you give your consent.
    These services may process personal data outside the European Economic Area, including in the United States. Depending on the feature used, this includes technical connection data, map and location data, device and installation data, push tokens, and data required for delivering notifications. Our own Analytics events do not contain names, email addresses, account IDs, photos, notes, saved locations, or rating scores.
    Mapbox, Expo, and Google describe their participation in the EU–US Data Privacy Framework in their published privacy policies. In addition, standard contractual clauses may apply. Apple describes standard contractual clauses for the international transfer of personal data from the EEA. You can request more information about the applicable safeguards via our privacy contact address.

    Translated with DeepL.com (free version)

    8. How long is data kept?

    Account details and active shared content are retained to keep your account and space available. The following periods and criteria apply to deletion and exceptions.

    Data retention

    Your uploads
    When you delete a photo, it becomes immediately inaccessible via twoDate. The file and its associated thumbnails will be deleted from active storage within 30 days at the latest. This also applies to your own uploads when you delete your account. Any copies in backups are subject to the backup retention period described separately.
    Shared text in the closed archive
    When a connection is closed, shared ideas, plans, memories, notes, and saved locations are stored in a closed archive. This content is no longer accessible through the app and is not shared with a new partner. Deleting an account does not completely remove this shared archive. Any remaining content may still contain personal data. There is currently no automatic deletion period set for closed pairing archives. For a request regarding personal data in this archive, please contact us via our privacy email address.
    Backups
    Backups are used to restore service following a system failure or data loss and are retained for up to 14 days after creation. Deleted personal data may still appear in a backup until that backup expires. This data is not used for any other purposes. During restoration, we reapply any previous deletions before the restored data becomes available.
    Technical logs
    We use technical log data to investigate malfunctions and monitor the operation and security of twoDate. The API logs which API endpoints are accessed, the type of request, the result, and the processing time. The content of requests and query parameters are not included in these request logs. In the event of a failed email delivery, we log technical error information. Email addresses, login credentials, confirmation codes, and links are omitted or masked in this process.

    Read the privacy policy.

    Support and privacy requests: When you contact us, we retain your contact information and correspondence in order to process your request. Regular support correspondence is deleted no later than 30 days after it has been processed. For privacy requests, we retain the necessary data for 14 days after processing in order to document how we handled the request..

    Confirmation codes for account actions are valid for 30 minutes. A code expiring does not mean that all technical records of that action are immediately erased.

    9. Account deletion

    You can delete your account from your profile or through our public deletion page. Your personal data is erased or replaced, personal scores are cleared and sessions are revoked. Your uploads become inaccessible and are then cleaned up. Your connection closes for both partners. Your partner’s account continues to exist.

    The current version retains shared text and technical references in the closed archive. This content may contain personal data and is not necessarily anonymous. A new connection cannot access it. See the retention information above and contact us about requests concerning remaining personal data. Deleting an account does not erase copies someone previously saved outside the service.

    See the account deletion steps

    10. Your rights

    You can request access, correction, deletion and restriction of processing. Where applicable, you can request data portability and object to processing based on a legitimate interest. You can withdraw consent at any time; this does not make processing before withdrawal unlawful.

    Email your request to info@twodate.app. We normally respond within one month. If a request is complex and takes longer, we will explain why within that month. Sometimes we need to verify your identity first. We will not ask for more information than necessary.

    You can also complain to the Dutch Data Protection Authority or the competent supervisory authority in your country of residence. We do not make solely automated decisions that have legal or similarly significant effects on you. The shared rating labels only help organise ideas.

    11. Website and security

    The twoDate theme loads fonts, images and scripts from this website and adds no analytics or advertising cookies. Hosting and WordPress may process technical request data; signing in to WordPress uses functional cookies. The website does not receive your twoDate password or deletion code: account deletion runs through the app service.

    We use measures including access controls, hashed passwords and secure connections to protect data. Never give your password or confirmation codes to anyone else. If you suspect misuse, contact info@twodate.app.

    12. Age and changes

    twoDate is intended for people aged 18 and over. Tell us if you believe a younger child has an account so we can investigate. This age limit does not mean every user’s age is checked in advance.

    We update this policy when the service or data processing changes. The date above shows the latest revision. We will inform you appropriately about material changes and ask for consent again where necessary.

    twoDate

    From idea to date

    Save ideas and choose your next date together.

    Explore twoDate

    • How it works
    • The app
    • Download the app
    • FAQ

    Here to help

    • Support & contact
    • Delete account
    • Safety & conduct

    Good to know

    • Privacy policy
    • Terms and conditions
    • Cookies
    • Email us

    © 2026 twoDate · twoScript vof

    Made with care by twoScript