Draft — not legal advice — version 0.1, 22/09/2026
Kesem — Privacy Policy
This policy explains what personal data Kesem collects, why we collect it, who processes it, how long we keep it, and what rights you have. Biometric data (your face scan) is covered in more detail in the separate Biometric Policy.
PP-1 · Who is responsible for your data
- Controller: Yosef Haim Davidovitz, an individual in Israel, who operates Kesem.
- Postal address: 131 Lachish Boulevard, Kiryat Gat, Southern District 8204857, Israel
- Privacy contact: privacy@kesemdating.com. The operator is the privacy contact. There is no external data protection officer at this time; one will be appointed before Kesem is marketed widely.
- Kesem is not offered in the European Union, Norway, Iceland, Liechtenstein or the United Kingdom. Registration is not possible from the US states of Illinois, Texas and Washington.
PP-2 · What data we collect
| Category | What exactly | Where it comes from |
|---|---|---|
| Sign-in | Apple or Google account ID; the email address your Apple or Google account gives us | Apple or Google, when you sign in |
| Profile | First name, date of birth (others see only your age), gender, "looking for", bio, height, smoking, children, languages | You |
| Photos | Your profile photos. Automatic moderation results for each photo (content labels, whether a face was found, match with your face scan). A "PDQ" fingerprint that detects duplicate photos | You; our moderation |
| Biometric | A face template and a scan image from a live face scan, and the liveness result | You (face scan) — see the Biometric Policy |
| Phone | Your phone number (stored encrypted), SMS verification status | You |
| Location | The device location (coordinates), city and country. Coordinates never leave our server: other members see a rounded distance (at least 5 km), and a city name only when both of you are in Israel. With "Virtual location", a city that you choose | Your device (with your permission); you |
| Activity | Likes and passes, matches, how often your profile was shown, your filters, blocks | Your use of the app |
| Messages | Chat messages, and whether they were delivered and read | You and the people you chat with |
| Safety | Reports you make or receive, the evidence attached to a report (the last 50 messages of that chat), sanctions, appeals, risk signals | You, other members, our team |
| Support | Your support requests and our answers | You |
| Device and security | An installation ID, Android ID and platform attestation results (Play Integrity / App Attest / DeviceCheck), stored only as hashes. IP address and sign-in logs, device model, operating system, app version | Your device |
| Notifications | Push token, your notification preferences | Your device; you |
| Usage analytics | Events about how the app is used (for example "registration completed"), linked to a pseudonymous ID and not to your name | Our server |
| Crash reports | Technical error reports with no personal data (no name, no photos, no screenshots) | The app |
| Age check | If you are under 18: your declared date of birth and hashed identifiers, used to keep the block in place | You |
We do not collect fingerprints, voice, contacts, your photo library (only the photos you choose), payment details, or advertising IDs. The app has no advertising and no third-party tracking.
PP-3 · Why we use it, and on what legal basis
We apply these legal bases in every country where we operate: as a standard of good practice, and where local law requires a legal basis.
| # | Purpose | Data | Legal basis |
|---|---|---|---|
| 1 | Account and sign-in, one account per person | Sign-in, device and security | Contract (providing the service); legitimate interest (security, fraud prevention) |
| 2 | Profile, matching and display | Profile, photos, location, activity | Contract |
| 2a | Matching by "looking for" | "Looking for" | Your explicit choice (explicit consent): see PP-4 |
| 3 | Keeping minors out | Date of birth, age-check data | Legal obligation and legitimate interest (child protection) |
| 4 | Face verification: real person, photos match you, preventing banned people from returning | Biometric | Explicit consent: see the Biometric Policy |
| 5 | Photo moderation and duplicates | Photos | Contract; legitimate interest (safety) |
| 6 | Phone verification, one account per number | Phone | Contract; legitimate interest (fraud prevention) |
| 7 | Distance and city | Location | Contract |
| 8 | Chat | Messages | Contract |
| 9 | Safety: reports, blocks, sanctions, appeals, risk score | Safety, messages attached to reports | Legitimate interest (the safety of members); legal obligation where it applies |
| 10 | Push notifications | Notifications | Contract; your operating system permission |
| 11 | Usage analytics | Usage analytics | Legitimate interest (improving the app). You can object at any time: see PP-10 |
| 12 | Error monitoring | Crash reports | Legitimate interest (stability) |
| 13 | Support and appeals | Support | Contract |
| 14 | Backups | All of the above, encrypted | Legitimate interest (disaster recovery) |
We do not sell your data, share it for advertising, or use it for profiling beyond what this table describes.
PP-4 · Sensitive data
- Biometric data is sensitive data. We collect it only with your explicit consent, and we use it only for the three purposes listed in the Biometric Policy.
- "Looking for" may reveal your sexual orientation, so we treat it as sensitive data. It is used only for matching. It is not sent to usage analytics and not shared with anyone. We process it because you choose to fill it in. You can change it in your profile.
- Your photos may reveal other sensitive details by chance. We use photos only for display, moderation and face matching.
PP-5 · Automated decisions
Some decisions are automated: photo moderation, face-scan results, and actions triggered by risk signals (lower visibility, a new face scan, or a temporary suspension until review). Every automated sanction opens a task for a person to review. A permanent ban is always decided by a person. A match with the banned-faces list never blocks you automatically; a person reviews it. The decision message tells you whether the decision was automated, and you can appeal it (see the Terms, TOS-8 and TOS-9).
PP-6 · Who processes your data (recipients)
We use these service providers ("processors"). They process data only on our instructions, under a data processing agreement.
| Provider | What for | Data | Where data is stored |
|---|---|---|---|
| Supabase | Database, sign-in, file storage, server functions, real-time chat | All account data, including encrypted scan images | Frankfurt, Germany (EU) |
| Amazon Web Services | Rekognition (photo moderation, face comparison), Face Liveness (live scan), KMS (encryption keys) | Photos, face templates, scan images | Ireland (EU). AWS is opted out of using this content to improve its services |
| Twilio | SMS verification | Phone number, verification code, IP | United States |
| Google (Firebase) | Sign in with Google, Play Integrity, push notifications (FCM) | Google account token, device attestation, push token | Global |
| Apple | Sign in with Apple, App Attest, DeviceCheck | Apple account token, attestation | Global |
| PostHog | Usage analytics | Pseudonymous events | EU |
| Sentry | Error monitoring | Error reports with no personal data | EU (Germany) |
| Hetzner | Backups | Encrypted database backups | Germany |
| Resend | Operational alerts to the operator | No personal data of members | United States |
Our team (the operator and any moderators) sees only what their role needs. For example, only the owner or an administrator may view a scan image, must give a reason, and each view is logged. We disclose data to authorities only when the law requires it, or to protect someone's life or safety. We report child sexual abuse material to the authorities (see the Child Safety Standards).
PP-7 · International transfers
Most data is stored in the EU (Germany and Ireland). Some providers are US companies, or process data outside the EU: Twilio (phone numbers, in the US), Google, Apple and Resend. These transfers are covered by the providers' data processing agreements, including the EU Standard Contractual Clauses and, where relevant, the EU-US Data Privacy Framework. The operator is in Israel. The European Commission has recognised Israel as providing adequate protection.
PP-8 · How long we keep data
| Data | How long |
|---|---|
| Profile, photos (approved), phone, activity, active chats, support, reports, sanctions, appeals | While the account exists. After you request deletion: 30 days (the restoration window), then deleted |
| Face template and scan image | 2 years from the scan; 7 days if you leave registration after the scan; deleted at once if you withdraw consent (with a backup deletion job within 30 days); in any case no later than 3 years after your last activity |
| Face template of a permanently banned account | 3 years from the ban |
| Phone and device identifiers of a permanently banned account | Only as hashes, 5 years from the ban |
| Chat and match after an unmatch | 90 days |
| Rejected photos | 30 days |
| Photo fingerprints (PDQ) | Deleted with the account (30 days after the deletion request) |
| Location | Replaced at each update; deleted with the account |
| IP, sign-in and SMS logs; released devices | 90 days |
| Age-check record (under 18) | 30 days |
| Registration stopped because of the region | Account data 7 days; the attempt record (region only, no location) 30 days |
| Data export file | 7 days |
| Evidence in a report that is still open when an account is deleted | Until the report is closed, +30 days |
| Staff audit log and biometric access log | 3 years |
| Other operational logs | 1 year |
| Usage analytics | Removed from our server once sent; kept at PostHog for 1 year |
| Crash reports | 30 days (Sentry plan) |
| Backups | 30 days (rolling, encrypted) |
PP-9 · Security
Here is how we protect your data. Data is encrypted in transit and at rest. The phone number is encrypted in its column. Scan images are encrypted with a separate key (AWS KMS). Backups are encrypted, and the private key is kept offline. The app cannot read database tables directly. Staff sign in with two-factor authentication. Every staff action is logged. If a security incident puts you at high risk, we will tell you and the competent authority as the law requires.
PP-10 · Your rights and how to use them
You have the right to:
- access your data, and receive a copy: in the app, "Export my data" (a file you can download for 7 days; one export per day);
- correct your data: edit your profile in the app, or write to us (some fields are locked, such as the date of birth);
- delete your account: in the app ("Delete account") or on the web at https://kesemdating.com/account-deletion;
- withdraw biometric consent: Settings → Privacy → "Withdraw face scan consent";
- object to usage analytics: Settings → Privacy → "Share usage data" (turn it off). Nothing else changes in the app, and any events not yet sent are discarded;
- restrict or object to other processing, and port your data, where the law gives you these rights;
- complain to a data protection authority. In Israel, this is the Privacy Protection Authority (https://www.gov.il/he/departments/the_privacy_protection_authority).
For anything else, write to privacy@kesemdating.com or use the in-app support form (category "Privacy and data"). We answer within 30 days. We may ask you to confirm your identity, usually by signing in.
PP-11 · Device identifiers, notifications and analytics
- The device identifiers in PP-2 are used only for security and for "one account per device". They are never used for advertising. We store only hashes.
- Push notifications are sent only if you allow them in your operating system. You can choose which notifications to receive in Settings. Marketing notifications are off by default.
- Usage analytics are sent from our server only (there is no analytics SDK in the app), with a pseudonymous ID. They never include "looking for", messages, photos or biometric data.
PP-12 · Children
Kesem is for adults only (18+). We block registration when the date of birth shows someone under 18, and we keep the block. If you believe a minor is using Kesem, report the profile with the reason "minor", or write to safety@kesemdating.com.
PP-13 · Changes
We will publish any update here with a new version number and date. If a change is material, we will also tell you in the app before it takes effect.
PP-14 · Contact
Privacy: privacy@kesemdating.com · Support: support@kesemdating.com · Post: Yosef Haim Davidovitz, 131 Lachish Boulevard, Kiryat Gat, Southern District 8204857, Israel.
PP-15 · Summary table — for the Google Play Data safety form and Apple App Privacy
Machine-checkable. One row per data type. "Shared" = No in every row, because every recipient is a service provider acting for us, which the store definitions exempt. "Optional" = the member can use Kesem without providing it. The categories in brackets are the store category names.
| Data type | Collected | Shared | Purpose | Optional | Retention |
|---|---|---|---|---|---|
| Name — first name (Personal info → Name) | Yes | No | App functionality | No | Account + 30 days |
| Email address from Apple/Google sign-in (Personal info → Email address) | Yes | No | App functionality; Account management | No | Account + 30 days |
| User IDs — account ID, Apple/Google subject (Personal info → User IDs) | Yes | No | App functionality; Account management; Fraud prevention, security | No | Account + 30 days |
| Phone number (Personal info → Phone number) | Yes | No | Account management; Fraud prevention, security | No | Account + 30 days; banned: hash 5 years |
| Date of birth / age (Personal info → Other info) | Yes | No | App functionality; Fraud prevention, security | No | Account + 30 days; under 18: 30 days |
| Gender (Personal info → Other info) | Yes | No | App functionality | No | Account + 30 days |
| "Looking for" (Personal info → Sexual orientation) | Yes | No | App functionality | No | Account + 30 days |
| Bio, height, smoking, children, languages (Personal info → Other info) | Yes | No | App functionality | Yes | Account + 30 days |
| Precise location (Location → Precise location) | Yes | No | App functionality | No | Replaced at each update; deleted with the account |
| Approximate location: city, country, virtual-location city (Location → Approximate location) | Yes | No | App functionality | No | Deleted with the account |
| Photos (Photos and videos → Photos) | Yes | No | App functionality; Fraud prevention, security | No | Account + 30 days; rejected 30 days |
| Face template and scan image (Personal info → Other info / Apple: Sensitive info) | Yes | No | Fraud prevention, security | No | 2 years; 7 days if abandoned; banned 3 years; at most 3 years after last activity |
| Chat messages (Messages → Other in-app messages) | Yes | No | App functionality | No | Account + 30 days; after unmatch 90 days |
| Likes, passes, matches, filters, blocks (App activity → App interactions) | Yes | No | App functionality | No | Account + 30 days |
| Reports, appeals, support requests (App activity → Other user-generated content) | Yes | No | App functionality; Fraud prevention, security | Yes | Account + 30 days; open report + 30 days |
| Usage events (App activity → App interactions) | Yes | No | Analytics | Yes (can be switched off) | Deleted from our server once sent; PostHog 1 year |
| Crash logs (App info and performance → Crash logs) | Yes | No | Analytics (app stability) | No | 30 days |
| Diagnostics: device model, OS, app version (App info and performance → Diagnostics) | Yes | No | Analytics (app stability); Fraud prevention, security | No | 90 days (logs) |
| Device IDs: installation ID, Android ID hash, attestation, push token (Device or other IDs) | Yes | No | App functionality; Fraud prevention, security | No | Account + 30 days; logs 90 days; banned: hash 5 years |
| IP address (Device or other IDs) | Yes | No | Fraud prevention, security | No | 90 days |
Store-form answers that follow from this policy: data is encrypted in transit: Yes · users can request deletion: Yes (in the app and on the web) · data sold: No · used for tracking (Apple): No · linked to identity (Apple): Yes for all rows, except crash logs (Not linked).
Sources
No third-party template text was used. The structure follows the official checklists listed below. Policies of other dating apps were not used.
- ICO, "The right to be informed" (checklist of privacy information): https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/individual-rights/the-right-to-be-informed/ (checked 22/09/2026)
- Article 29 WP / EDPB, Guidelines on transparency (WP260 rev.01): https://ec.europa.eu/newsroom/article29/items/622227 (checked 22/09/2026)
- EDPB, Guidelines 05/2020 on consent: https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-052020-consent-under-regulation-2016679_en (checked 22/09/2026)
- Israel Privacy Protection Authority (Amendment 13, DPO guidance of 14/07/2026, stored as
legal/sources/ppa-dpo-guidance-2026-07-14.pdf): https://www.gov.il/he/departments/the_privacy_protection_authority (gov.il blocks automated fetching; verify manually) - Google Play, Data safety section: https://support.google.com/googleplay/android-developer/answer/10787469 (checked 22/09/2026)
- Apple, App Review Guideline 5.1.1(i) and (v): https://developer.apple.com/app-store/review/guidelines/ (checked 22/09/2026); App Privacy details: https://developer.apple.com/app-store/app-privacy-details/
- European Commission adequacy decision for Israel (2011/61/EU): https://eur-lex.europa.eu/eli/dec/2011/61/oj
- Internal:
legal/ROPA.md(rows 1–17),legal/VENDORS.md,legal/DEVICE-IDS-ANALYTICS.md,planning/SCHEMA-DRAFT.md§14, DECISIONS T-20, T-27, T-28, T-72, T-79, T-84, T-85, P-1–P-4, P-13, V-13