Privacy Policy
Last updated: 11 September 2026
Data controller
Birch Bark Incense Inc. (federally incorporated in Canada; registered office 67 Third Avenue, Wawa, Ontario, P0S 1K0) is the data controller for personal information processed through Big Screen Soulmates. Our Privacy Officer is Brian Harbord, reachable at support@bigscreensoulmates.com.
What we collect
- Account: email address, password (hashed) or OAuth identifier (Google/Apple)
- Identity: date of birth (used to compute age and enforce 18+), display name
- Profile: gender, who you're seeking, bio, favourite films, relatable characters, actor you resemble
- Photos and biometric-derived data: your profile photo and the pose-matched verification selfies you submit (verification asks for two different prompted poses), plus a SHA-256 hash of each image used solely to detect re-use of the same photo across accounts. Your profile photo is the first verification selfie, so it is visible to other signed-in members; the second pose photo is visible only to you and our moderators. Every submitted selfie is screened by an automated content-safety model before a moderator sees it (see "Automated photo screening" below). We do not build a facial-recognition template, do not run face-matching against any external database, and do not use the selfie for advertising or profiling.
- Verification anti-abuse data: the IP address a verification submission comes from, and the number and timing of your submissions. This is used only to rate-limit verification and detect multi-account abuse.
- Location: your country, and (only when you use "Use precise location") your city and state/province. We ask your browser for your device location and compare the resulting country with the country of your network (IP) address. A mismatch — the usual signature of a routed or spoofed connection — does not block your account: we show you a banner explaining the conflict and pause your profile from appearing in other members' "same country only" results until the checks agree. Your country is detected automatically and re-checked each time you open your profile page or Discover; you cannot type it in yourself. Location is only read at those moments while the app is open and is never tracked in the background, and your city is hidden from other members unless you turn on "Show my city and state/province to other users". Separately, you can switch on "Use precise location" in your profile: this stores one approximate coordinate (rounded to roughly a 1 km grid) so you can filter Discover to members within 100 km. That coordinate is used only for that pass/fail check on our servers — no distance is ever calculated for, shown to, or sent to other members — and switching the option off deletes it immediately.
- Activity: likes, passes, matches, text messages, movie-night and video-call invites, unmatches, reports and blocks you make (including reports of individual messages), and your Discover preferences (such as verified-only or shared-favourite settings)
- Privacy and notification settings: whether incognito mode is on, whether you have match, message and like notifications enabled, and which individual conversations you have muted. These are used only to decide who can see you and what we send you — they are never shown to other members.
- Referrals: your referral code and the accounts that signed up with it, used to grant free-messaging bonus days
- Feedback: anything you submit via the Feedback tab
Special-category and sensitive data
Using a dating service may imply information about your sexual orientation. Where GDPR/UK GDPR applies we treat this as special-category data (Article 9) and process it only on the basis of your explicit consent, which you give by creating a profile and choosing who you are seeking. The verification selfie and its hash are treated as sensitive personal information under Quebec Law 25 and, where applicable, as biometric information under laws such as the Illinois Biometric Information Privacy Act (BIPA) and Texas CUBI; we process them only to verify that a live person controls the account, retain them under the schedule below, and never sell, lease, trade, or share them for profit. You can withdraw consent at any time by deleting your account.
How we use it
To create your account, verify age and country, show compatible people, enable messaging, moderate the community, and improve the product. We do not sell your personal data, do not "share" it for cross-context behavioural advertising, and do not use it for advertising or automated decision-making that produces legal or similarly significant effects.
Automated photo screening
When you submit verification selfies, the images are sent to an AI content-safety model (Google Gemini, accessed through the Lovable AI gateway) that checks whether the photo contains a real, visible human face and whether it breaks our content rules — nudity, sexual content, violence, or hate imagery. Explicit photos are rejected automatically and never become your profile photo. Ambiguous results — for example an obscured face or a pose that does not match the prompt — put your photo on hold: it is hidden from Discover while a human moderator makes the final decision, and you can still browse and use the rest of the app.
The model's verdict and a short reason are stored with your verification record so moderators can review them. Screening images are not used to train the model and are not retained by the provider for that purpose. No account is closed by AI alone — a person reviews every hold and every appeal, and you can email us to contest a decision.
Cookies and local storage
We use a small number of first-party cookies and browser local storage entries strictly to keep you signed in, remember your preferences (e.g. cookie choice, referral code), and secure the session. We do not use advertising cookies, third-party analytics trackers, or cross-site tracking. A consent banner is shown on your first visit to the website; the native mobile app stores only the sign-in session and local preferences, so no cookie banner is shown there. You can change or withdraw your choice at any time:
Who we share it with (subprocessors)
- Other users: your profile, photos, and messages are visible to people you match with or appear to in Discover. If you like someone, your profile (including your photo, unblurred) appears in their Likes tab under "Likes received", even before they like you back. Unmatching hides the conversation but the underlying like record is kept.
- Demo profiles: the app contains a small number of clearly labelled demo/test profiles (marked with a "Demo" badge) used for app store review and product testing. They are not real people and no personal data of yours is shared with them beyond what any member would see.
- Lovable — application hosting, server functions, and managed backend (which, in turn, uses Supabase for database, authentication, and photo storage in US & EU regions)
- Cloudflare, Inc. — DNS, DDoS protection, and the serverless Workers runtime that executes our server functions
- Google LLC & Apple Inc. — optional OAuth sign-in only if you use those buttons
- ipwho.is, ipapi.co, and geojs.io — IP-to-country lookup, tried in turn if one is unavailable (only your IP address is sent)
- BigDataCloud — reverse geocoding of coordinates to country/city (only coarse coordinates are sent)
- Google LLC (Gemini, via the Lovable AI gateway) — automated safety screening of verification selfies; the image and its pose prompt are sent, and the result is not used to train the model
- OMDb API — public film metadata (no personal data sent)
- In-app purchases only: if you subscribe inside our mobile app, your app store processes the payment and shares a subscription status token with us. We do not receive or store your card details. No payments are collected on the website.
A current list of subprocessors is maintained on this page; material changes are announced in-app before they take effect.
Retention and deletion
- Active account: we keep your data for as long as your account is active.
- Paused account: your data is preserved but hidden from Discover and Matches until you unpause it.
- Deletion: you can delete your account from the Your account tab under Account controls at any time. In normal circumstances deletion happens immediately and cannot be undone — there is no grace period and no recovery window. Your login, profile, photos, favourites, likes, matches, messages, verification records, blocks, feedback and referral rows are removed from our production database at once. One exception: if there is an unresolved safety report about your account, the account is closed and hidden from everyone straight away, and the data is erased once moderators finish their review — in all cases within 7 days. You are told this on screen when it applies.
- Verification anti-abuse data: the submission IP address recorded with a verification request is kept with that request (see below). Rate-limiting counters (which action, when, by which account — no IP) are kept for 7 days, then deleted.
- Messages: messages you exchange with a match are retained for the life of that match. When either party unmatches, the messages become inaccessible to both parties; when either party deletes their account, the conversation is removed immediately as part of that deletion.
- Verification selfies: your approved selfie is kept as your profile photo while your account exists; the second pose stays private to you and moderators. Rejected and superseded selfies (and their records) are kept for up to 90 days after the decision so we can investigate appeals and repeat abuse, then automatically deleted. All verification images and records are deleted immediately when you delete your account, except the SHA-256 hash used to prevent re-use of the same image.
- Moderation evidence: when a message is reported or automatically flagged, a copy of the relevant conversation is archived for moderator review and kept for up to 365 days, then deleted. This archive is accessible only to moderators and is retained even if the underlying conversation is removed.
- Reported messages: when you report an individual message, a copy of that message is stored with the report under the same 365-day moderation retention above, so the evidence survives if the sender later deletes or unmatches. The person you reported is not told who reported them.
- Audit and safety logs: the administrative audit log (moderation actions, verification decisions, role grants) is retained for 24 months, then deleted.
- Backups: encrypted database backups roll off within 30 days, after which no copy of your data remains.
- Legal holds: in the narrow case of an active safety investigation or a legal obligation, we may retain the minimum records necessary to comply, and delete them once the obligation ends.
- Reports about you: reports filed by other users about your conduct may be retained after your account is deleted for community-safety purposes, without your name or contact details.
Your rights
You can access, correct, export, or delete your data from within the app. The Your account tab includes an Export my data button that builds a JSON file of the personal information associated with your account (GDPR Article 20 portability): your profile, favourites, likes sent and received, matches, messages you sent, verification records, blocks you made, feedback, referrals and devices. The file is stored in a private storage bucket and handed to you as a single download link that expires one hour after it is created; the link is only shown to you, and the stored copy is deleted after it expires or when you request a new export. Because an export can contain private conversation content, we warn you before you download it — keep the file somewhere only you can reach, and delete it when you are done. For the protection of others, the export does not include reports or blocks that other members have made about you, or internal moderation notes and audit-log entries about your account; you can still request access to that information by contacting our Privacy Officer, and we will provide it to the extent it can be disclosed without identifying the reporting member. If you are in Canada, you have the right under PIPEDA (and, in Quebec, under the Act respecting the protection of personal information in the private sector, as amended by Law 25) to access and correct your personal information, to withdraw consent, and to request data portability; you may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'accès à l'information. If you are in EU/UK, you also have the right to restrict processing, object to processing, and lodge a complaint with your national data protection authority. If you are in California, you have the right to know, delete, correct, and opt out of sale/sharing (we do not sell or share personal information for cross-context behavioural advertising). If you are in Illinois or Texas, you have the rights described in BIPA and CUBI in relation to biometric identifiers, including the right to know what we retain and to have it destroyed on request. For any request, contact our Privacy Officer (see Contact below).
EU / UK representative and DSA point of contact
We do not currently maintain a physical establishment in the European Union or United Kingdom. Users in the EU, EEA, or UK may contact us for GDPR/UK GDPR matters, and for matters under the EU Digital Services Act (DSA), at support@bigscreensoulmates.com, which serves as our single point of contact for users and authorities. Where the appointment of an Article 27 GDPR representative or an EU/UK DSA legal representative becomes required, we will appoint one and publish their contact details on this page.
Security
Passwords must be at least 10 characters and include a mix of character types, and are checked against known breached-password lists at signup. Data in transit uses TLS. Data at rest is stored on encrypted infrastructure with row-level security. Photos are served via short-lived signed URLs. Passwords are hashed with a modern algorithm; we never see them in plaintext. Your Your account tab includes a Sign out everywhere control that ends every active session on your account, including the one you are using, so you can recover access if you signed in on a device you no longer control; we recommend changing your password afterwards. Accounts are limited to three signed-in devices at a time. We are not immune to breaches; do not share information you would not want another user to see.
Children
The service is 18+ only. We do not knowingly collect data from anyone under 18. If we learn we have, we delete it immediately and, where an incident involves child sexual exploitation content, report to NCMEC (US) or the equivalent authority in the applicable jurisdiction as required by law.
International transfers
Big Screen Soulmates is operated from Canada. Our infrastructure providers (see subprocessors above) operate data centres in Canada, the United States, and the European Union, so your personal information may be stored or processed outside your province or country of residence and may be accessible to law enforcement or national-security authorities under the laws of those jurisdictions. Where transfers occur, we rely on the transfer mechanisms our providers offer (standard contractual clauses, adequacy decisions, or equivalents).
Changes
We may update this policy from time to time. Material changes will be surfaced in the app before they take effect.
Contact
Big Screen Soulmates is operated by Birch Bark Incense Inc., a corporation incorporated under the Canada Business Corporations Act, with its registered office at 67 Third Avenue, Wawa, Ontario, P0S 1K0, Canada.
For privacy questions, or to exercise any of the rights described above, contact our Privacy Officer:
- Privacy Officer: Brian Harbord
- Email: support@bigscreensoulmates.com
- Mail: Birch Bark Incense Inc., Attn: Privacy Officer, 67 Third Avenue, Wawa, ON P0S 1K0, Canada
You may also submit privacy requests through the Feedback tab inside the app.