Velvet Ties is a curated, human-matchmaker-led dating service. This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the choices you have. It applies to the Velvet Ties mobile app, the velvetties.com website, and any related services (collectively, the “Service”).
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
1. Who we are
“Velvet Ties”, “we”, “us”, and “our” refers to Velvet Ties, the data controller for the personal information described in this policy. You can reach us at privacy@velvetties.com for any privacy-related request.
2. What we collect
We collect the minimum personal information required to run a human-curated matchmaking service. Specifically:
Information you give us directly
- Identity & contact: full name, email, phone number, date of birth, city, profession.
- Profile content: photos you upload, bio text, interests, orientation, pronouns, gender identity, relationship structure (monogamous, non-monogamous), and matchmaking questionnaire answers.
- Sensitive preferences: dating intentions (wanting kids, marriage), dealbreakers, ideal-partner description, and sexuality/kink preferences if you choose to share them. These fields are encrypted at rest and only revealed to another user if and when you both accept a curated match.
- Event Media. If you attend a Velvet Ties in-person event, we collect photographs, video, audio, and statements captured at that event, including your name, image, likeness, voice, and appearance. This is captured by us or by photographers and videographers acting for us, and may include Event Media you or another attendee shares with us. Unlike everything else described in this policy, Event Media is intended for public use — see Section 4 and the Event photography and likeness release.
- Safety information: emergency contact details, SOS check-in configuration, and location data you share when you explicitly trigger a safety check-in. We do not passively track your location.
- Payment information: Velvet Ties uses Stripe to process payments. We receive a confirmation that a payment succeeded and the last four digits of the card; we do not store your full card number.
- Communications: messages you send to other members through the app, and messages you send to our matchmakers or support team.
Information we collect automatically
- Device & usage: device type, OS version, app version, approximate time zone, and the actions you take in the app (screens viewed, matches accepted/passed). We use this to debug, improve the service, and keep you safe.
- Log data: standard HTTP access logs (IP address, user agent, request path, timestamp). IP addresses are used only for rate limiting, fraud detection, and coarse-grained region detection.
Information from third parties
- BAI vetting service: if you applied through our upstream vetting partner (BAI), we receive your application answers, Instagram verification result, and any AI-generated personality notes from that process. This information is stored as part of your applicant record.
- AWS Rekognition (selfie verification): when you verify your identity, we use AWS Rekognition to compare your verification selfie against your profile photos to confirm you are the same person. The images are sent to AWS for that face comparison only; AWS does not retain them after analysis. Separately from this identity check, the photos you upload — and photos from an Instagram account you choose to connect — are reviewed both by our human matchmakers and by the automated matchmaking systems described in Section 3, to help build your match profile. Photo analysis produces only descriptive signals used for matchmaking and to help draft your profile bio for your review; we do not use it to identify you elsewhere on the internet.
3. How we use your information
We use the information above for the following purposes:
- Matchmaking. Our human matchmakers and our matching engine use your profile, preferences, and matchmaking questionnaire to surface candidates the matchmaker reviews and may approve as introductions for you. The score the engine produces is decision support for the matchmaker — not a guaranteed prediction of relationship outcome. You see only the introductions the matchmaker explicitly approves.
- Inferred trait analysis.We use large-language- model (LLM) providers — currently OpenAI Inc. and Anthropic PBC — under contracts that prohibit training on your data and require deletion within 30 days, to extract structured trait signals (communication style, values, conflict style, attachment indicators) from your matchmaking-questionnaire responses and, if you opt into the optional clone-persona feature (not yet shipped), from documents you choose to upload to the app. These inferences are reviewed by our human matchmakers and are not shared with other members. You can opt out per-category — see Section 13 (“User-uploaded documents and inferred profiles”).
- Event Media — marketing, promotion, and documenting the community. We publish photographs, video, audio, and statements captured at our in-person events on Instagram and other social platforms, on the Velvet Ties app and website, and in marketing, advertising, promotional, editorial, press, newsletter, and pitch or investor materials. The purpose is to show prospective and current members what our events are actually like, and to promote Velvet Ties and future events. Legal basis: where UK/EU data-protection law applies, we rely on your consent, given under the Event photography and likeness release when you register for or enter an event; you can withdraw it at any time under Article 7(3) and we will stop further use going forward. Elsewhere we rely on that release as your agreement. Withdrawal is not retroactive and cannot recall what is already published or reshared by others.
- Account management. Creating, maintaining, and securing your account; processing payments; sending service messages (match deliveries, safety check-in nudges, billing receipts).
- Safety and trust. Verifying you are a real person, human review of photos and bio content, preventing abuse, and powering features like the in-app SOS button.
- Legal and compliance. Responding to legal requests, enforcing our Terms, and complying with applicable law.
- Product improvement. Aggregate, anonymized usage analytics to improve the service. We do not train any third-party model on your personal data.
5. Sensitive data: encryption and limited access
We treat your sexuality, kink preferences, free-text matchmaking answers, and free-text accessibility notes as sensitive personal data. These fields are encrypted at rest in our database using per-field application-layer encryption. They are never returned by any public API endpoint. They are decrypted only when you view your own profile, when our matchmakers review your profile for curation, or when both you and a matched member have accepted a match and chosen to share.
We do not use sensitive preferences to train machine learning models, and we do not share them with advertising networks or data brokers.
6. How long we keep your data
We keep personal information only as long as needed to:
- Operate your account while it's active.
- Comply with legal obligations (e.g. tax records for payment history).
- Resolve disputes and enforce our agreements (e.g. abuse reports).
When you delete your account, we delete or anonymize your personal information within 30 days, except for (a) records we are legally required to retain (which are kept in locked, limited-access storage) and (b) user-uploaded documents described in Section 13 (retained while your account is active and the corresponding consent toggle is on). Sensitive fields (kink preferences, sexuality free text, accessibility notes) are deleted immediately on account deletion. Provenance records that link a trait inference to the source signal (revision logs) are pseudonymized rather than hard-deleted so we can answer regulator audits about how a score was produced; nothing user-identifiable remains in those records.
Event Media is the exception to all of the above. We retain Event Media for as long as it serves the purpose it was captured for — promoting Velvet Ties and documenting our events — and we review published Event Media at least annually, removing material that is no longer used for that purpose. Unpublished Event Media (outtakes, duplicates, unusable frames) is deleted within 12 months of the event. Material that has become part of the published record — a press feature, a printed piece, an archived campaign — is kept indefinitely, because retracting it is not something we are able to do.
Retention is a separate question from the licence. The licence you grant under the Event photography and likeness release is perpetual, which is what lets us keep using Event Media; the criteria above are what govern how long we actually hold it. Deleting your account does not retract Event Media we have already published, and we cannot recall what has been printed, distributed, or reshared by other people. You can ask us to stop using a specific piece of Event Media going forward at dg@velvetties.com; we consider every request in good faith and honor it where reasonably practicable. Where applicable law gives you a right we cannot ask you to waive — for example withdrawing consent under UK/EU GDPR Article 7(3), or a statutory objection or restriction right — we stop further use going forward rather than treating the request as discretionary. Withdrawal is not retroactive and cannot recall what is already published or reshared by others.
User-uploaded documents (the optional clone-persona feature) have their own retention schedule — see Section 13.
7. Your rights
Depending on where you live, you may have the following rights:
- Access. Request a copy of the personal information we hold about you.
- Correction. Ask us to fix information that is wrong or incomplete.
- Deletion. Ask us to delete your personal information. Event Media is treated differently: see Section 6 and Terms §7b. We stop further use on request where the law gives you a right we cannot ask you to waive (for example withdrawing consent under UK/EU GDPR Article 7(3)), but we cannot recall Event Media already published or reshared by others.
- Export (portability). Ask for a machine- readable copy of the information you provided.
- Objection / restriction. Ask us to stop or limit certain uses of your information.
- Withdraw consent. Where we rely on your consent, withdraw it at any time.
To exercise any of these rights, email privacy@velvetties.com from the email on your account. We will respond within 30 days. California residents: we do not sell personal information and will honor verified “do not sell or share” requests. European Economic Area and UK residents: you can also lodge a complaint with your local data protection authority.
8. How we protect your information
We protect your data through:
- TLS encryption in transit for every request.
- Application-layer encryption at rest for sensitive fields (kink preferences, sexuality free text, accessibility notes, matchmaking transcript).
- Role-based access controls on our database and internal tools.
- Rate limiting and automated abuse detection on every mutating endpoint.
- Logging and monitoring that redact personally identifiable information.
No system is perfectly secure. If we ever discover a data breach that affects your personal information, we will notify you and the appropriate authorities as required by law.
9. Children
Velvet Ties is for adults only. You must be at least 18 years old (or the age of majority in your jurisdiction, if higher) to create an account. We do not knowingly collect personal information from anyone under 18. If you believe a minor has given us personal information, please email privacy@velvetties.com and we will delete it immediately.
10. International transfers
Velvet Ties is based in the United States. Our service providers are based in the United States. If you access the Service from outside the United States, your account information will be transferred to and processed in the United States.
The optional clone-persona feature (see Section 13) is available to declared US residents at launch. Where required by law for any future EU/UK rollout we will put appropriate safeguards in place — including the EU Standard Contractual Clauses (Commission Decision 2021/914, Module 2 controller-to-processor) plus a Schrems II transfer impact assessment, and the UK International Data Transfer Addendum where applicable.
11. Changes to this policy
We may update this policy from time to time. When we do, we will change the “Last updated” date at the top and, for material changes, notify you in-app or by email before the change takes effect. Your continued use of the Service after changes take effect means you accept the updated policy.
12. Contact us
Questions, requests, or complaints about this policy or your personal information:
Velvet Ties
privacy@velvetties.com
13. User-uploaded documents and inferred profiles
This section describes the optional “clone-persona” feature, which is currently in development and not yet active for any member. It is published here so that, when the feature launches, the disclosure precedes any data collection.
What is clone-persona?
You can choose to upload personal writing samples — journal entries, emails you’ve written, essays, anything text — for our matching engine to analyze. Velvet Ties uses the content you upload to infer a small set of trait labels about your communication style, attachment patterns, conflict style, and other matchmaker-relevant signals. These inferences are used by our human matchmakers to inform introduction decisions. You receive a user-facing summary of the communication-style traits inferred from your own uploads so you can see what the system is reading from them.
Velvet Ties does not read your email, social-media accounts, or any third-party platform. The only content we analyze for clone-persona is documents you explicitly upload through the app.
Granular consent
Uploading a document is opt-in via three independent toggles, each defaulting to OFF:
- Extract communication-style traits from your uploaded text.
- Extract intimacy / orientation / attachment-style traits. This is special-category data under GDPR Article 9 and sensitive personal information under California CPRA. We require an explicit, separate opt-in for this category.
- Include these inferences in pair-simulation results surfaced to your curator.
Each toggle stores its own consent record. Withdrawing any toggle triggers a re-extraction job that drops the corresponding signals. You can also delete an individual uploaded document at any time and it is removed from active scoring within 24 hours.
What content you should and shouldn’t upload
Upload onlycontent you wrote yourself, or content you have permission to share. Do not upload other people’s emails or messages without their consent. Do not upload documents containing third parties’ sensitive personal information (medical records of others, legal documents involving others, etc.). When you upload a document you confirm that you have the authority to share its contents with Velvet Ties.
How we process uploads
Uploads are stored encrypted at rest. We extract structured trait signals using LLM subprocessors (OpenAI Inc. and Anthropic PBC), whose default API contracts prohibit training on your data and automatically delete inputs after a maximum 30-day abuse-monitoring window. We do not use uploaded content to train generalized AI/ML models. We do not allow humans to read your uploads except (i) you and our matchmaker, (ii) for security purposes such as investigating abuse, or (iii) to comply with applicable law.
Automated decision-making and human review
The pair-simulation output influences the introductions a human matchmaker considers, but every introduction is decided by a human, not by the algorithm. The matchmaker records their pre-algorithm decision before reviewing the simulation score. You may withdraw your consent for automated profiling at any time (which disables the clone feature for your account but does not require you to delete your account).
Retention
Uploaded documents are retained while your account is active and the corresponding consent toggle is on. Inferred trait labels are retained while your account is active. On account deletion or feature disconnect we delete uploaded documents and persona snapshots; pseudonymized provenance records that link a trait inference to its source signal are kept rather than hard-deleted so we can answer regulator audits about how a given score was produced. None of those records contain user-identifiable content after deletion.
Right to limit use of sensitive personal information
You may at any time exercise your right under California CPRA §1798.121 to limit our use of your sensitive personal information. Email privacy@velvetties.com with the subject “Limit Use of My Sensitive Personal Information” and we will action your request within 15 business days. Automated honoring of the Sec-GPC: 1 Global Privacy Control browser signal will be implemented before clone-persona launches.