Ally
Back to Ally

Your data, explained

Privacy Policy

This policy explains what Ally collects, why it is needed, how AI and matching use it, who receives it, and the controls available to you.

Effective and last updated: July 26, 2026

On this page

1. Who we are and what this policy covers2. Information we process3. Where information comes from4. Why we use information and our legal bases5. AI, profiling, and matching6. What another user can see7. Service providers and disclosures8. International transfers9. Retention and deletion10. Your privacy rights11. Age restriction and children12. Security, changes, and contact

1. Who we are and what this policy covers

Ally is operated by James VANHECKE. For European data-protection law, the operator is the controller of the personal data described in this policy.

Postal contact: 115 rue du Faubourg Poissonnière, 75009 Paris, France. Telephone: +32 466 09 70 18.

This policy covers the Ally mobile application, dearally.app, the Ally assistant, matchmaking, date planning, support, and connected services. It does not govern third-party services that publish their own privacy notices.

2. Information we process

The information Ally processes depends on the features you choose to use.

  • Account and identity: email address, authentication provider, first and last name, date of birth, age, sex, city, and country.
  • Profile and preferences: relationship goals, people you are attracted to, age and distance preferences, dating cadence, availability, budget, travel and transport constraints, and narrative summaries about personality, lifestyle, relationships, physical attributes, date style, food, future plans, habits, and boundaries.
  • Sensitive information you choose to provide: sexual orientation or attraction, religious or spiritual beliefs, political opinions, intimate or physical preferences, attraction-reference images, and information that may reveal health or intimate life.
  • Private location reference: latitude and longitude used to filter distance and plan practical venues. This reference is not shown to other users.
  • Content and media: profile photos, optional attraction-reference images, messages with Ally, voice recordings submitted for transcription, temporary date-verification videos, messages in an accepted date chat, feedback, and support communications.
  • Matching and date activity: compatibility evaluations, opportunities, responses, rejection explanations, venue proposals, availability, reports, blocks, and safety records.
  • Connected services: calendar connection status, authorization tokens, availability windows, and events Ally is allowed to read or create; notification permission and push-delivery identifiers.
  • Subscription and technical data: product, entitlement and renewal status from RevenueCat and the app stores; IP address, device and app information, timestamps, security logs, audit events, errors, and service usage.

3. Where information comes from

  • Directly from you during account creation, onboarding, conversations, profile editing, reports, and support.
  • From device features and permissions you choose to enable, such as location, microphone, photos, notifications, and calendar access.
  • From Apple, Google, Facebook, RevenueCat, calendar providers, and other services you connect.
  • From Ally’s analysis of your answers and activity, including summaries, confidence indicators, compatibility factors, and inferred preferences.
  • From another matched user when their response or shared date logistics concern you.

4. Why we use information and our legal bases

  • Provide the service and perform our contract: create your account, build your profile, operate Ally, find potential matches, plan dates, manage subscriptions, and answer support requests.
  • Your explicit consent: use sexual orientation or attraction, religious or spiritual beliefs, political opinions, and intimate or physical preferences for compatibility analysis and matching. Ally asks for a separate choice for each category and records the privacy-notice and purpose version attached to that choice.
  • Our legitimate interests: secure and improve the service, prevent fraud and abuse, measure reliability, debug errors, and maintain limited internal records, where those interests do not override your rights.
  • Legal obligations and substantial public interests: respond to lawful requests, protect users, preserve evidence of serious abuse, and report child sexual abuse material or imminent threats when required.

Sensitive matching consent is not required merely to create or keep an account. You may refuse or later withdraw any category in Settings. Withdrawal stops future matching use and deletes the corresponding profile summaries, preferences, and attraction-reference images. Sexual-orientation or attraction information is necessary to determine eligible dating candidates, so Ally cannot create new matches without consent for that category. Other declined categories are excluded from matching without preventing account access.

5. AI, profiling, and matching

You are interacting with an AI assistant. Ally uses language models to understand answers, maintain profile summaries, ask follow-up questions, explain potential compatibility, classify feedback, and support date planning. Deterministic rules and AI-assisted evaluations may rank candidates and generate a compatibility percentage.

AI output can be incomplete, biased, or wrong. A compatibility score is an estimate, not a fact or guarantee. Ally does not make a decision that produces legal or similarly significant effects without meaningful user choice. You decide whether to accept, reject, report, block, or meet another person.

More detail is available in the AI & Matching Transparency Notice.

6. What another user can see

A matched user may see the public profile information and photos made available for the match, compatibility explanations, and the shared venue, time, and logistics of a date proposal. When both participants accept a date, each participant may also see the other participant’s submitted date-verification video and messages in the time-limited date chat.

Ally does not disclose your email, phone number, password, private conversations with Ally, private physical-attraction preferences, calendar contents, calendar tokens, or exact home, work, or matching-reference location to another user. If both users choose to exchange contact details themselves, that exchange is outside Ally’s private-data controls.

7. Service providers and disclosures

We disclose information only as needed to operate the service, follow your instructions, protect people, or comply with law. Providers are required by contract or applicable law to protect the data they process.

  • Supabase for authentication and database infrastructure.
  • Railway for backend hosting and Vercel for website hosting.
  • Amazon Web Services for encrypted object storage of profile and reference images.
  • OpenAI for language, embedding, and transcription features; LangSmith for sanitized AI observability when enabled.
  • Google Maps Platform for geocoding, travel distance, venue search, and place details.
  • Google, Microsoft, Apple, and Expo for connected calendars, device permissions, and notification delivery where used.
  • RevenueCat, Apple App Store, and Google Play for subscription entitlement and purchase administration. Ally does not receive your full payment-card details.
  • Professional advisers, authorities, and safety organizations where disclosure is legally required or reasonably necessary to protect rights and safety.

Ally does not sell personal information and does not share it for cross-context behavioral advertising.

8. International transfers

Some providers process data in the United States or other countries. Where European or UK transfer rules apply, we use an adequacy decision, the EU Standard Contractual Clauses, the UK Addendum or International Data Transfer Agreement, or another lawful safeguard. You may request information about applicable safeguards from privacy@dearally.app.

9. Retention and deletion

We may retain a minimal suppression record after deletion to respect blocks, prevent fraud, and avoid recreating unsafe pairings. We will explain any material exception when responding to a deletion request.

  • Account, profile, preference, conversation, media, and active matching data are generally kept while your account is active and removed or anonymized after account deletion, unless retention is required for a reason below.
  • Subscription, consent, transaction, and contractual records may be retained for the period required to establish or defend legal claims and meet accounting or consumer-law duties.
  • Reports, blocks, fraud indicators, and serious safety evidence may be retained for up to five years, or longer where law enforcement, litigation, or a legal duty requires it.
  • Operational and security logs are normally retained for up to twelve months. Encrypted backups may persist for up to ninety additional days before being overwritten.

10. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, object, withdraw consent, obtain a portable copy, or appeal a privacy decision. European users may complain to their local supervisory authority; in France, this is the CNIL.

Residents of US states with applicable privacy laws may request access, correction, deletion, or portability and may appeal a denied request. Ally does not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising. We will not discriminate against you for exercising a privacy right.

Send a request from the email linked to your account to privacy@dearally.app. We may verify your identity before acting. We normally answer within one month for European requests and within the period required by applicable US law.

11. Age restriction and children

Ally is a dating service for adults aged 18 or older. We do not knowingly allow minors to create accounts or intentionally collect their data. If you believe a minor is using Ally, contact safety@dearally.app immediately.

12. Security, changes, and contact

We use access controls, encryption in transit, restricted service credentials, row-level database controls, private storage, logging redaction, and monitoring appropriate to the nature of the service. No system is completely secure; report a suspected incident to privacy@dearally.app.

We may update this policy when the service or law changes. Material changes will be presented in the app or by another appropriate notice before they take effect.

Contact usAsk a privacy question
privacy@dearally.app
Related policies
TermsSafetyAccount deletionAI transparencyCookiesLegal notice
© 2026 Ally