Kesem

Draft — not legal advice — version 0.1, 22/09/2026

Kesem — Privacy Policy

This policy explains what personal data Kesem collects, why we collect it, who processes it, how long we keep it, and what rights you have. Biometric data (your face scan) is covered in more detail in the separate Biometric Policy.

PP-1 · Who is responsible for your data

PP-2 · What data we collect

CategoryWhat exactlyWhere it comes from
Sign-inApple or Google account ID; the email address your Apple or Google account gives usApple or Google, when you sign in
ProfileFirst name, date of birth (others see only your age), gender, "looking for", bio, height, smoking, children, languagesYou
PhotosYour profile photos. Automatic moderation results for each photo (content labels, whether a face was found, match with your face scan). A "PDQ" fingerprint that detects duplicate photosYou; our moderation
BiometricA face template and a scan image from a live face scan, and the liveness resultYou (face scan) — see the Biometric Policy
PhoneYour phone number (stored encrypted), SMS verification statusYou
LocationThe device location (coordinates), city and country. Coordinates never leave our server: other members see a rounded distance (at least 5 km), and a city name only when both of you are in Israel. With "Virtual location", a city that you chooseYour device (with your permission); you
ActivityLikes and passes, matches, how often your profile was shown, your filters, blocksYour use of the app
MessagesChat messages, and whether they were delivered and readYou and the people you chat with
SafetyReports you make or receive, the evidence attached to a report (the last 50 messages of that chat), sanctions, appeals, risk signalsYou, other members, our team
SupportYour support requests and our answersYou
Device and securityAn installation ID, Android ID and platform attestation results (Play Integrity / App Attest / DeviceCheck), stored only as hashes. IP address and sign-in logs, device model, operating system, app versionYour device
NotificationsPush token, your notification preferencesYour device; you
Usage analyticsEvents about how the app is used (for example "registration completed"), linked to a pseudonymous ID and not to your nameOur server
Crash reportsTechnical error reports with no personal data (no name, no photos, no screenshots)The app
Age checkIf you are under 18: your declared date of birth and hashed identifiers, used to keep the block in placeYou

We do not collect fingerprints, voice, contacts, your photo library (only the photos you choose), payment details, or advertising IDs. The app has no advertising and no third-party tracking.

PP-3 · Why we use it, and on what legal basis

We apply these legal bases in every country where we operate: as a standard of good practice, and where local law requires a legal basis.

#PurposeDataLegal basis
1Account and sign-in, one account per personSign-in, device and securityContract (providing the service); legitimate interest (security, fraud prevention)
2Profile, matching and displayProfile, photos, location, activityContract
2aMatching by "looking for""Looking for"Your explicit choice (explicit consent): see PP-4
3Keeping minors outDate of birth, age-check dataLegal obligation and legitimate interest (child protection)
4Face verification: real person, photos match you, preventing banned people from returningBiometricExplicit consent: see the Biometric Policy
5Photo moderation and duplicatesPhotosContract; legitimate interest (safety)
6Phone verification, one account per numberPhoneContract; legitimate interest (fraud prevention)
7Distance and cityLocationContract
8ChatMessagesContract
9Safety: reports, blocks, sanctions, appeals, risk scoreSafety, messages attached to reportsLegitimate interest (the safety of members); legal obligation where it applies
10Push notificationsNotificationsContract; your operating system permission
11Usage analyticsUsage analyticsLegitimate interest (improving the app). You can object at any time: see PP-10
12Error monitoringCrash reportsLegitimate interest (stability)
13Support and appealsSupportContract
14BackupsAll of the above, encryptedLegitimate interest (disaster recovery)

We do not sell your data, share it for advertising, or use it for profiling beyond what this table describes.

PP-4 · Sensitive data

PP-5 · Automated decisions

Some decisions are automated: photo moderation, face-scan results, and actions triggered by risk signals (lower visibility, a new face scan, or a temporary suspension until review). Every automated sanction opens a task for a person to review. A permanent ban is always decided by a person. A match with the banned-faces list never blocks you automatically; a person reviews it. The decision message tells you whether the decision was automated, and you can appeal it (see the Terms, TOS-8 and TOS-9).

PP-6 · Who processes your data (recipients)

We use these service providers ("processors"). They process data only on our instructions, under a data processing agreement.

ProviderWhat forDataWhere data is stored
SupabaseDatabase, sign-in, file storage, server functions, real-time chatAll account data, including encrypted scan imagesFrankfurt, Germany (EU)
Amazon Web ServicesRekognition (photo moderation, face comparison), Face Liveness (live scan), KMS (encryption keys)Photos, face templates, scan imagesIreland (EU). AWS is opted out of using this content to improve its services
TwilioSMS verificationPhone number, verification code, IPUnited States
Google (Firebase)Sign in with Google, Play Integrity, push notifications (FCM)Google account token, device attestation, push tokenGlobal
AppleSign in with Apple, App Attest, DeviceCheckApple account token, attestationGlobal
PostHogUsage analyticsPseudonymous eventsEU
SentryError monitoringError reports with no personal dataEU (Germany)
HetznerBackupsEncrypted database backupsGermany
ResendOperational alerts to the operatorNo personal data of membersUnited States

Our team (the operator and any moderators) sees only what their role needs. For example, only the owner or an administrator may view a scan image, must give a reason, and each view is logged. We disclose data to authorities only when the law requires it, or to protect someone's life or safety. We report child sexual abuse material to the authorities (see the Child Safety Standards).

PP-7 · International transfers

Most data is stored in the EU (Germany and Ireland). Some providers are US companies, or process data outside the EU: Twilio (phone numbers, in the US), Google, Apple and Resend. These transfers are covered by the providers' data processing agreements, including the EU Standard Contractual Clauses and, where relevant, the EU-US Data Privacy Framework. The operator is in Israel. The European Commission has recognised Israel as providing adequate protection.

PP-8 · How long we keep data

DataHow long
Profile, photos (approved), phone, activity, active chats, support, reports, sanctions, appealsWhile the account exists. After you request deletion: 30 days (the restoration window), then deleted
Face template and scan image2 years from the scan; 7 days if you leave registration after the scan; deleted at once if you withdraw consent (with a backup deletion job within 30 days); in any case no later than 3 years after your last activity
Face template of a permanently banned account3 years from the ban
Phone and device identifiers of a permanently banned accountOnly as hashes, 5 years from the ban
Chat and match after an unmatch90 days
Rejected photos30 days
Photo fingerprints (PDQ)Deleted with the account (30 days after the deletion request)
LocationReplaced at each update; deleted with the account
IP, sign-in and SMS logs; released devices90 days
Age-check record (under 18)30 days
Registration stopped because of the regionAccount data 7 days; the attempt record (region only, no location) 30 days
Data export file7 days
Evidence in a report that is still open when an account is deletedUntil the report is closed, +30 days
Staff audit log and biometric access log3 years
Other operational logs1 year
Usage analyticsRemoved from our server once sent; kept at PostHog for 1 year
Crash reports30 days (Sentry plan)
Backups30 days (rolling, encrypted)

PP-9 · Security

Here is how we protect your data. Data is encrypted in transit and at rest. The phone number is encrypted in its column. Scan images are encrypted with a separate key (AWS KMS). Backups are encrypted, and the private key is kept offline. The app cannot read database tables directly. Staff sign in with two-factor authentication. Every staff action is logged. If a security incident puts you at high risk, we will tell you and the competent authority as the law requires.

PP-10 · Your rights and how to use them

You have the right to:

For anything else, write to privacy@kesemdating.com or use the in-app support form (category "Privacy and data"). We answer within 30 days. We may ask you to confirm your identity, usually by signing in.

PP-11 · Device identifiers, notifications and analytics

PP-12 · Children

Kesem is for adults only (18+). We block registration when the date of birth shows someone under 18, and we keep the block. If you believe a minor is using Kesem, report the profile with the reason "minor", or write to safety@kesemdating.com.

PP-13 · Changes

We will publish any update here with a new version number and date. If a change is material, we will also tell you in the app before it takes effect.

PP-14 · Contact

Privacy: privacy@kesemdating.com · Support: support@kesemdating.com · Post: Yosef Haim Davidovitz, 131 Lachish Boulevard, Kiryat Gat, Southern District 8204857, Israel.

PP-15 · Summary table — for the Google Play Data safety form and Apple App Privacy

Machine-checkable. One row per data type. "Shared" = No in every row, because every recipient is a service provider acting for us, which the store definitions exempt. "Optional" = the member can use Kesem without providing it. The categories in brackets are the store category names.

Data typeCollectedSharedPurposeOptionalRetention
Name — first name (Personal info → Name)YesNoApp functionalityNoAccount + 30 days
Email address from Apple/Google sign-in (Personal info → Email address)YesNoApp functionality; Account managementNoAccount + 30 days
User IDs — account ID, Apple/Google subject (Personal info → User IDs)YesNoApp functionality; Account management; Fraud prevention, securityNoAccount + 30 days
Phone number (Personal info → Phone number)YesNoAccount management; Fraud prevention, securityNoAccount + 30 days; banned: hash 5 years
Date of birth / age (Personal info → Other info)YesNoApp functionality; Fraud prevention, securityNoAccount + 30 days; under 18: 30 days
Gender (Personal info → Other info)YesNoApp functionalityNoAccount + 30 days
"Looking for" (Personal info → Sexual orientation)YesNoApp functionalityNoAccount + 30 days
Bio, height, smoking, children, languages (Personal info → Other info)YesNoApp functionalityYesAccount + 30 days
Precise location (Location → Precise location)YesNoApp functionalityNoReplaced at each update; deleted with the account
Approximate location: city, country, virtual-location city (Location → Approximate location)YesNoApp functionalityNoDeleted with the account
Photos (Photos and videos → Photos)YesNoApp functionality; Fraud prevention, securityNoAccount + 30 days; rejected 30 days
Face template and scan image (Personal info → Other info / Apple: Sensitive info)YesNoFraud prevention, securityNo2 years; 7 days if abandoned; banned 3 years; at most 3 years after last activity
Chat messages (Messages → Other in-app messages)YesNoApp functionalityNoAccount + 30 days; after unmatch 90 days
Likes, passes, matches, filters, blocks (App activity → App interactions)YesNoApp functionalityNoAccount + 30 days
Reports, appeals, support requests (App activity → Other user-generated content)YesNoApp functionality; Fraud prevention, securityYesAccount + 30 days; open report + 30 days
Usage events (App activity → App interactions)YesNoAnalyticsYes (can be switched off)Deleted from our server once sent; PostHog 1 year
Crash logs (App info and performance → Crash logs)YesNoAnalytics (app stability)No30 days
Diagnostics: device model, OS, app version (App info and performance → Diagnostics)YesNoAnalytics (app stability); Fraud prevention, securityNo90 days (logs)
Device IDs: installation ID, Android ID hash, attestation, push token (Device or other IDs)YesNoApp functionality; Fraud prevention, securityNoAccount + 30 days; logs 90 days; banned: hash 5 years
IP address (Device or other IDs)YesNoFraud prevention, securityNo90 days

Store-form answers that follow from this policy: data is encrypted in transit: Yes · users can request deletion: Yes (in the app and on the web) · data sold: No · used for tracking (Apple): No · linked to identity (Apple): Yes for all rows, except crash logs (Not linked).


Sources

No third-party template text was used. The structure follows the official checklists listed below. Policies of other dating apps were not used.