Privacy, in plain language

Privacy, in plain language.

We’re not Grindr. We’re not Feeld. We don’t sell your data and we never will. Here’s exactly what Vandal stores, what it refuses to, and how to ask us to delete any of it.

Last updated July 2026

The honest list

What we collect, and why we need each line

Most privacy policies bury the answer under a thousand words of legalese. Here’s the short version: we keep the minimum we need for the product to work, and nothing else. Everything below lives in our database the moment you create an account, join the waitlist, or open the app.

We DO collect

  • Account: your email, a hashed password, a display-name seed (the part of your email before the @), and a role flag for moderation.
  • Session: a session token, expiry, IP address, and user-agent — the same stuff every login system needs to keep you signed in.
  • Profile: the display name, bio, relationship structure, alias, photo URL, anonymity toggles, and the city you typed in.
  • Tags: the subculture tags you picked (or wrote in) so we can match you to people in overlapping scenes.
  • Threads & messages: a 1:1 thread per match, plus the message bodies you send inside it.
  • Swipes: a single per-pair like-or-pass decision — no cross-profile swipe history.
  • Waitlist (pre-account): your email, optional city, the subculture tags you chose, and an optional "other" write-in.

We DON'T collect

  • Phone numbers. There’s no SMS path into Vandal.
  • Social-provider tokens. We don’t ask Google, Apple, Facebook, or anyone else to vouch for you.
  • Precise GPS or background location. We don’t request it and we couldn’t store it if we did.
  • Advertising IDs (IDFA, GAID, or anything that lets an ad network follow you between apps).
  • Third-party cookies or cross-site pixels. None.
  • Read receipts, typing indicators, or "last seen" timestamps. Your messages stay quiet.
  • Contact lists, address books, photo libraries, or device identifiers we didn’t ask for.
  • Voice prints, face prints, or any biometric you didn’t upload yourself as a profile photo.
What we refuse

What we DON'T collect

This part is the point. The list below is the difference between Vandal and the apps we’re not. We won’t ask for these things and we won’t quietly store them in the background.

If you spot anything else we’re collecting that isn’t listed on this page, that’s a bug — email us and we’ll fix it and publish a postmortem.

Your control

How anonymity works

Anonymity on Vandal isn’t a single switch — it’s five, each doing a different job. None of them are on by default. You choose. You can change any of them at /matches/edit whenever you want.

What each toggle actually does

All five are off by default — except city, which is always stored as the string you typed, never as coordinates. Turn them on at /matches/edit.

Anonymous mode (isAnonymous)

When this is on, your profile is only reachable through subculture tag overlap — your display name stays hidden from the matches feed, and you appear as an alias. Turn it off and you show up the way you set up your profile at /matches/edit.

Hide face photo (hideFacePhoto)

Your face photo is replaced with a placeholder graphic in the swipe deck. Once you match with someone, you can ask them to share an unblurred face — or send one of yours. Face stays yours until you say otherwise.

Blur photos by default (photoBlur)

Photos you upload are blurred in every pre-match surface until a reciprocal like happens. We don’t unblur on a one-sided pass — both sides have to want to see each other first.

Alias instead of real name (alias)

Pick a handle. Your alias is what other people see in messages and match cards. Your real name (if you ever gave us one) is only used for your login and never displayed.

City-level only — no precise location

We store the city you typed in at signup, never your device GPS, IP-derived coordinates, or background location. We don’t ask for location permission. We couldn’t build a "people nearby" heatmap if we tried.

Retention & deletion

Your data, your call

Close your account and we delete your profile, threads, messages, swipes, and sessions. Your email and password hash go with it. We keep a tombstone row (anonymized id + the word “banned”) so we don’t accidentally re-create your account from a stale cookie — that row has no email, no name, no messages, and no way to reach you.

Waitlist entries stay until you ask us to remove them or until we launch the matching service in your region, whichever comes first. If we don’t ship to your city in the next 12 months, we’ll purge waitlist rows tied to it and tell you before we do.

We don’t ship a half-functional “Download my data” button yet. We’d rather do it right than ship a broken export and call it a feature. Until we do, the email address below is the way to ask.

Cookies & analytics

Cookies & analytics — the short version

We don’t set any third-party cookies. There are no ad pixels, no Facebook SDK, no cross-site trackers. The only thing the platform drops on you is a single anonymous visitor ID in localStorage(a UUID we generate — not tied to your email, IP, or profile), used to count page views so we can tell whether the homepage is broken. That’s it.

No third-party analytics SDK runs in your browser. No data leaves this app for advertising networks. If we ever change that, this page is the first place we’ll publish it.

Get in touch

Talk to a human

Data questions, deletion requests, takedowns, “hey, your app is doing a weird thing” — write to us. We read every message.

Email vandal-2@polsia.app

We’ll acknowledge within a week and act on data-rights requests within 30 days, usually faster.

The bottom line

If we’re not willing to print it here, we’re not willing to do it.

That’s the contract. Vandal is a dating app, not a data business — and we wrote this page to prove it. — Date outside the lines. A dating app for people who don't fit the algorithm.